Network Segmentation for Medical Devices, Staff and Guest Wi-Fi

On a flat network, every device can talk to every other device. The nurse's laptop, the resident's smart TV, the old infusion pump, the front-desk printer, the security camera and the server holding your records all share the same space. If any one of them is compromised, an attacker may be able to move freely to the rest.

Network segmentation breaks that single space into smaller zones with rules about what can talk to what. It is one of the most effective and least glamorous protections available, and it is well within reach of a small or mid-size facility.

Why segmentation matters in care settings

Care environments carry an unusual mix of equipment:

Business computers and servers running modern software

Clinical devices that may run old operating systems that cannot be patched

Building systems such as cameras, door controls, nurse call and HVAC

Guest and resident devices that you do not manage at all

Vendor equipment that outside companies maintain remotely

Many of these devices cannot run security software. Segmentation lets you protect them by controlling their network access instead.

The zones most facilities need

Staff and clinical workstations

Managed computers, laptops and tablets used for EHR and email. These get the strongest controls and carry the most sensitive access.

Servers and critical systems

Servers, backup systems and management tools in their own zone, reachable only by the systems and people that need them.

Medical and IoT devices

Infusion pumps, monitors, wander-management systems, cameras and printers. Many of these should reach only specific destinations, such as a vendor's cloud service or one internal server, and nothing else.

Building systems

Nurse call, door access, HVAC and fire systems. Often maintained by outside contractors, so their access should be tightly limited and logged.

Resident and guest Wi-Fi

An internet-only network with no path to any internal system. Many facilities also apply bandwidth limits so streaming does not slow clinical traffic.

Vendor access

A separate, monitored path for outside technicians, ideally with MFA, time-limited access and logging.

How segmentation is done

Segmentation uses VLANs (virtual local area networks) on managed switches and wireless controllers, plus firewall rules between them. A VLAN separates traffic logically even when devices share the same physical equipment. The firewall then decides what is allowed to cross between zones. The default posture should be to deny traffic between zones unless there is a documented reason to allow it.

A practical starting plan

Inventory devices. You cannot protect what you do not know about. Walk the building and pull lists from your switches and wireless system.

Group devices by function and risk, using the zones above as a starting point.

Start with the easiest, highest-value split: guest and resident Wi-Fi separated from everything else.

Next, isolate medical and building devices, one group at a time, and test each one with the vendor or clinical team before and after.

Write firewall rules based on what each group needs, such as "cameras may reach the video recorder and nothing else."

Log traffic that is blocked between zones. It will reveal both misconfigurations and suspicious behavior.

Review the rules at least annually and whenever you add new systems.

Pitfalls to watch for

Breaking something that clinical staff depend on. Always plan changes with nursing leadership, schedule them for low-activity windows and have a rollback plan.

Allowing "any to any" rules as a shortcut, which defeats the purpose

Forgetting vendor remote access, which can bypass your segmentation

Leaving old devices on the main network because no one knows what they do

Assuming segmentation replaces patching and monitoring. It limits damage but does not stop every attack.

Segmentation and HIPAA

The Security Rule requires access controls and transmission security measures, and a risk analysis that considers where ePHI lives and who can reach it. Segmentation is a practical safeguard that supports those requirements, and it also reduces the number of systems affected if something goes wrong, which can narrow the scope of a breach investigation.

Equipment you need

You do not need exotic gear. Most business-grade managed switches, firewalls and wireless systems support VLANs and inter-zone rules. If your current equipment is consumer-grade or very old, segmentation can be a good reason to upgrade.

Next steps

UnityCare IT designs and implements segmented networks for care facilities and clinics, working around your clinical schedule and your vendors. If you would like to see how your current network is laid out and where a few changes could make a big difference, we can start with a network map and a short report.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034