Network Segmentation for Medical Devices, Nurse Call and Cameras

Walk through a typical care facility and count the devices that connect to the network: workstations, medication carts, printers, nurse call controllers, security cameras, door access panels, thermostats, smart TVs, vital-sign monitors, and staff and guest phones. On many small networks, nearly all of them share one flat network. That means a problem on any one device, such as a compromised camera or an infected guest laptop, can potentially reach everything else.

Segmentation fixes this by dividing the network into separate zones with rules about what may talk to what. It is one of the most effective infrastructure improvements a facility can make.

Why Flat Networks Are Risky

Malware spreads easily. Ransomware that lands on one workstation can scan and attack others on the same network.

Old or unpatched devices are exposed. Many connected devices cannot be updated easily and may run outdated software for years.

Guests and residents share space with clinical systems. Personal phones and tablets are unmanaged and may be infected.

Troubleshooting is harder. A noisy device can slow everything.

What Segmentation Looks Like

Segments are usually built with VLANs, which are logical networks on the same physical switches, combined with firewall rules between them. A practical design for a care facility might include:

Staff and clinical network. Workstations, laptops and carts that access the EHR and business systems.

Servers and critical systems. On-premises servers, backup systems and management tools, with tightly limited access.

Medical and connected devices. Equipment that stores or transmits resident data or depends on network connection.

Building systems. Cameras, door access, HVAC and nurse call, where the vendor's remote access can be isolated.

Voice. Phones, often on their own segment for quality and security.

Guest and resident Wi-Fi. Internet-only, completely separate from internal systems.

Management network. Access to switches, firewalls and access points, restricted to administrators.

Your size and equipment determine how many segments make sense. Three or four well-built segments are much better than one flat network.

Set the Rules Between Segments

Segmentation only works if traffic between zones is controlled. Start with a default approach of denying traffic between segments, then allow what is needed. Examples:

Staff network can reach the EHR and printers, but guest Wi-Fi cannot reach either

Cameras can send video to the recorder but cannot browse the internet or reach workstations

Vendors who maintain building systems reach only their equipment, and only when needed

Servers accept connections only from the segments and ports that require them

Document each rule and the reason for it.

Special Considerations for Nurse Call and Life-Safety Systems

Nurse call, fire alarm interfaces and similar systems are important to resident safety. Before moving them to a new segment, coordinate with the vendor and test thoroughly. Changes made without understanding how the system communicates can cause outages. Plan changes during a maintenance window and have a rollback plan.

Handle Legacy and Vendor-Managed Devices

Some devices cannot be secured on their own. Place them in an isolated segment, restrict internet access to only what the vendor requires, and review vendor remote access practices. Ask vendors about their update schedule and support life. Include end-of-support dates in your technology planning.

Plan the Transition

Segmentation is easier on a new network than a live one. For an existing facility:

Inventory every connected device and its purpose.

Group devices by function and risk.

Design segments and rules on paper.

Confirm switches, firewalls and access points support the design.

Move low-risk groups first, such as guest Wi-Fi.

Test each move, then migrate clinical groups in stages.

Monitor for broken workflows and adjust.

Involve clinical staff in testing, because they will notice problems first.

Monitor and Maintain

Segmentation drifts over time as people add devices and make exceptions. Review firewall rules at least annually, remove unused rules, and keep your device inventory current. Logging traffic between segments can reveal unusual behavior, such as a camera trying to reach a workstation.

Connection to Compliance and Frameworks

The HIPAA Security Rule expects reasonable safeguards for the confidentiality, integrity and availability of electronic protected health information. Network segmentation is a commonly recommended practice in the HHS 405(d) Health Industry Cybersecurity Practices and in NIST guidance. It also limits the scope of an incident, which can reduce the cost and complexity of response.

How UnityCare IT Can Help

UnityCare IT designs and supports segmented networks for long-term care and clinic environments. If you suspect your network is flat, we can map your devices, recommend a practical segment design and help you roll it out without disrupting care.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172