Many care facilities grew their networks one device at a time. A new camera system arrived, then a nurse call upgrade, a wireless thermostat and a guest Wi-Fi for families. Often everything ended up plugged into the same flat network, where every device can talk to every other device. It works, until something goes wrong.
If an attacker compromises one weak device, such as a camera with a default password, a flat network lets them move toward your EHR server and file shares. Network segmentation is the practice of dividing a network into smaller zones, with rules about what can pass between them. It is one of the most effective ways to limit the damage of a single failure.
Think of your building. Staff offices, medication rooms and resident rooms are separated by doors and locks, and not everyone has every key. Segmentation does the same for your network. Each zone gets its own address range, often implemented as a VLAN, and a firewall or switch rules decide which zones may communicate and how.
Contain attacks. Ransomware that lands in one zone has a harder time spreading to others.
Protect sensitive systems. Your EHR and file servers can sit in a restricted zone.
Isolate risky devices. Cameras, smart TVs and older equipment often cannot be patched or secured well, so isolating them reduces exposure.
Improve performance. Streaming and guest traffic do not compete with clinical systems.
Support compliance. The HIPAA Security Rule includes access control and transmission security safeguards, and segmentation helps you demonstrate that access to electronic protected health information is limited.
Every facility is different, but a common structure includes:
Staff and clinical workstations: devices that access resident records
Servers and critical systems: EHR components, file servers, domain controllers
Voice and phones: keeps call traffic prioritized and separate
Nurse call and life-safety systems: isolated, with only the connections the vendor requires
Security cameras and access control: separate zone, with limited access for those who manage them
Building systems: HVAC, lighting, elevators and similar controls
Medical and monitoring devices: restricted communications to required systems only
Guest and resident Wi-Fi: internet-only, completely separated from internal systems
Management network: for administering switches, firewalls and access points
Segmentation only helps if rules are thoughtful. Start from a default of denying traffic between zones, then allow what is needed:
Staff workstations may reach the EHR, but not the camera management network
Cameras may send video to the recorder, but not browse the internet freely
Guest Wi-Fi may reach the internet only
Nurse call equipment may talk to its server and approved vendor remote access, nothing else
Document each rule and the business reason for it, so future staff and auditors understand it.
Some systems, especially nurse call, building controls and medical devices, are installed and supported by outside vendors who may need remote access. Before you segment:
Ask each vendor which ports, addresses and connections their system requires
Replace shared remote access tools with managed, logged and approved methods
Confirm they will not need flat access to the whole network
Schedule changes carefully and test after each move
Changing a nurse call or door system during a busy shift is not wise. Plan cutovers with clinical leaders and have a rollback plan.
A full redesign can feel overwhelming. A staged approach lowers risk:
Separate guest Wi-Fi from internal networks first
Move cameras and building systems into their own zones
Isolate servers and apply stricter rules
Segment medical devices and nurse call with vendor input
Review and tighten rules over time
You need switches that support VLANs, a firewall capable of controlling traffic between zones, and enough capacity to inspect that traffic without slowing it. Consumer-grade routers usually fall short of this. Make sure your equipment is supported and receives security updates.
Networks change. New devices appear, vendors come and go, and exceptions pile up. Review firewall rules at least twice a year, remove unused ones and verify that new devices land in the correct zone.
Segmentation done well protects residents and keeps operations steady, but it takes careful planning to avoid disrupting care. UnityCare IT can map your current network, propose a zone design and manage the rollout in phases that fit your schedule.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172