Network Segmentation for Nurse Call, Cameras and EHR

Many care facilities grew their networks one device at a time. A new camera system arrived, then a nurse call upgrade, a wireless thermostat and a guest Wi-Fi for families. Often everything ended up plugged into the same flat network, where every device can talk to every other device. It works, until something goes wrong.

If an attacker compromises one weak device, such as a camera with a default password, a flat network lets them move toward your EHR server and file shares. Network segmentation is the practice of dividing a network into smaller zones, with rules about what can pass between them. It is one of the most effective ways to limit the damage of a single failure.

What Segmentation Means in Plain English

Think of your building. Staff offices, medication rooms and resident rooms are separated by doors and locks, and not everyone has every key. Segmentation does the same for your network. Each zone gets its own address range, often implemented as a VLAN, and a firewall or switch rules decide which zones may communicate and how.

Why It Matters for Care Providers

Contain attacks. Ransomware that lands in one zone has a harder time spreading to others.

Protect sensitive systems. Your EHR and file servers can sit in a restricted zone.

Isolate risky devices. Cameras, smart TVs and older equipment often cannot be patched or secured well, so isolating them reduces exposure.

Improve performance. Streaming and guest traffic do not compete with clinical systems.

Support compliance. The HIPAA Security Rule includes access control and transmission security safeguards, and segmentation helps you demonstrate that access to electronic protected health information is limited.

A Sensible Zone Layout

Every facility is different, but a common structure includes:

Staff and clinical workstations: devices that access resident records

Servers and critical systems: EHR components, file servers, domain controllers

Voice and phones: keeps call traffic prioritized and separate

Nurse call and life-safety systems: isolated, with only the connections the vendor requires

Security cameras and access control: separate zone, with limited access for those who manage them

Building systems: HVAC, lighting, elevators and similar controls

Medical and monitoring devices: restricted communications to required systems only

Guest and resident Wi-Fi: internet-only, completely separated from internal systems

Management network: for administering switches, firewalls and access points

Writing the Rules

Segmentation only helps if rules are thoughtful. Start from a default of denying traffic between zones, then allow what is needed:

Staff workstations may reach the EHR, but not the camera management network

Cameras may send video to the recorder, but not browse the internet freely

Guest Wi-Fi may reach the internet only

Nurse call equipment may talk to its server and approved vendor remote access, nothing else

Document each rule and the business reason for it, so future staff and auditors understand it.

Work With Your Vendors

Some systems, especially nurse call, building controls and medical devices, are installed and supported by outside vendors who may need remote access. Before you segment:

Ask each vendor which ports, addresses and connections their system requires

Replace shared remote access tools with managed, logged and approved methods

Confirm they will not need flat access to the whole network

Schedule changes carefully and test after each move

Changing a nurse call or door system during a busy shift is not wise. Plan cutovers with clinical leaders and have a rollback plan.

Do It in Phases

A full redesign can feel overwhelming. A staged approach lowers risk:

Separate guest Wi-Fi from internal networks first

Move cameras and building systems into their own zones

Isolate servers and apply stricter rules

Segment medical devices and nurse call with vendor input

Review and tighten rules over time

Hardware Considerations

You need switches that support VLANs, a firewall capable of controlling traffic between zones, and enough capacity to inspect that traffic without slowing it. Consumer-grade routers usually fall short of this. Make sure your equipment is supported and receives security updates.

Maintain It

Networks change. New devices appear, vendors come and go, and exceptions pile up. Review firewall rules at least twice a year, remove unused ones and verify that new devices land in the correct zone.

Getting Started

Segmentation done well protects residents and keeps operations steady, but it takes careful planning to avoid disrupting care. UnityCare IT can map your current network, propose a zone design and manage the rollout in phases that fit your schedule.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172