Many small facilities run everything on one flat network. The EHR workstation, the resident's tablet, the smart TV, the IP camera, the thermostat and the infusion pump share the same space and can all, in principle, reach each other. If any one of them is compromised, the attacker has a short walk to the rest.
Network segmentation breaks that single space into smaller zones with controlled paths between them. It is one of the most effective structural improvements you can make, and it does not require replacing everything.
In plain terms, you divide the network into separate groups, usually called VLANs, and use a firewall or switch rules to decide what traffic can pass between them. A device in the guest zone can reach the internet but not your file server. A security camera can talk to its recorder but not to a nurse's workstation.
Staff computers that access the EHR, email and file shares. This is your most sensitive zone.
File servers, local application servers and backup systems, with tightly limited access.
Patient monitors, infusion pumps, lab equipment, imaging devices and similar equipment. Many run old software that cannot be patched easily, so isolation is the main protection. Follow manufacturer guidance, and talk to biomedical or clinical engineering staff before making changes, since some devices have specific connectivity requirements.
Thermostats, door controllers, cameras, elevators and nurse call systems. Vendors often need remote access to these, which is another reason to isolate them.
Internet only, with no route to internal systems. Consider client isolation so devices on this network cannot see one another.
A small, locked-down zone used by IT staff to manage switches, firewalls and access points.
List every device type and what it needs to talk to. This inventory helps your HIPAA risk analysis too.
Start with a rule of default deny between zones, then allow only specific needs. For example, allow workstations to reach the EHR vendor's addresses, and allow a camera recorder to receive from cameras.
Managed switches and a business-grade firewall are required. Unmanaged switches cannot create VLANs.
Move the least critical zone first, such as guest Wi-Fi, then building systems, then medical devices, and finally the staff network. Test after each step.
Keep a diagram and a rule list. Review firewall logs for blocked attempts, which can reveal both misconfiguration and suspicious behavior.
Moving a medical device without checking whether it depends on a particular network setup
Creating exceptions that quietly undo the design, such as allowing "any to any" to fix a problem fast
Forgetting vendor remote access, which should be controlled, logged and time-limited
Skipping change documentation so nobody remembers why a rule exists
Leaving default passwords on switches and access points
Segmentation also improves reliability. A noisy device or a misconfigured smart TV in one zone is less likely to disrupt clinical systems. Troubleshooting becomes easier because you know where traffic should and should not travel.
For many facilities, existing equipment can be reconfigured with some planning. Where it cannot, upgrading to managed switches and a proper firewall is often a modest investment compared with the consequences of a network-wide incident. Ask for a plan that sequences work so that spending is spread out.
UnityCare IT designs and implements segmented networks for care facilities, coordinating with your vendors and clinical staff so nothing important breaks. If your network is a single flat space today, we can assess it and propose a staged plan.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034