If you have ever worked in a building with secured areas, you already understand network segmentation. Not everyone who enters the lobby can walk into the medication room, the records office or the server closet. Doors and badges limit who can reach what, so one unlocked entrance does not give access to everything.
A flat network, where every device can talk to every other device, is like a building with no interior doors. A single infected laptop, a hacked camera or a visitor's compromised phone can reach everything else. Segmentation adds the interior doors.
Segmentation divides a network into separate zones and controls the traffic between them. Technically this is done with VLANs on switches and rules on a firewall. From a management viewpoint, the key idea is simple: group devices by purpose and trust level, then allow only the connections that are needed.
It limits the spread of an attack. Ransomware often moves sideways from the first infected machine to servers and other computers. Segmentation can slow or stop it.
It protects devices that cannot protect themselves. Older medical devices, cameras and building controls often cannot be patched, so isolating them lowers risk.
It keeps guests away from internal systems. Visitors and residents can use the internet without touching your clinical network.
It supports compliance. HIPAA's Security Rule calls for access controls and protection of ePHI, and segmentation is a common technical way to implement them. The proposed Security Rule update that HHS published in January 2025 also discusses network segmentation, though that proposal is not final.
It makes troubleshooting and monitoring easier, because traffic patterns are clearer.
A small or mid-size organization does not need dozens of segments. A good starting design might include:
Staff and clinical workstations: computers and tablets used for charting and administration.
Servers and critical systems: any on-site servers, with tightly controlled access.
Medical and clinical devices: monitors, carts and other equipment, grouped according to vendor guidance.
Building systems: door access, HVAC, cameras, nurse call and wander management, which are often managed by outside vendors.
Phones: voice over IP phones often benefit from their own segment.
Resident and guest Wi-Fi: internet-only, with no route to internal zones.
Management network: for network equipment settings, restricted to IT.
The logic is generally to deny by default and allow only what is needed. For example:
Guest Wi-Fi can reach the internet, nothing else
Staff workstations can reach the EMR and file servers, but not camera systems
Camera systems can talk to their recorder, not to the staff network
Vendors reach only the devices they support, and only when needed
Servers can receive requests from authorized workstations but cannot initiate connections to the internet unless they need updates
Writing these rules in plain language first, before they are configured, is useful. It forces a conversation about what really needs to talk to what.
Segmentation done carelessly can disrupt care. A cautious approach:
Inventory devices and connections. You cannot isolate what you have not found.
Begin with the easy wins. Separate guest and resident Wi-Fi from internal networks first, if not already done.
Move groups one at a time, starting with lower-risk categories such as cameras or printers, and test.
Monitor and adjust. Log blocked traffic to learn what legitimate connections you missed.
Use maintenance windows for changes, with a rollback plan and clinical leaders informed.
Document everything, including a simple diagram.
Creating zones but allowing all traffic between them, which provides little protection
Forgetting vendor remote access paths that bypass the rules
Skipping documentation so nobody remembers why a rule exists
Not testing after changes
Treating it as a one-time project instead of maintaining it as devices change
Ask your IT provider: "If one computer on our staff network were infected tonight, what else could it reach?" If the answer is "everything," segmentation deserves a place in your budget plan.
UnityCare IT designs and implements segmentation for healthcare facilities, working carefully around clinical operations and vendor requirements. If you would like a plain-language review of your current network layout, we are happy to start there.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172