Network Segmentation in Plain English for Administrators

If you have ever worked in a building with secured areas, you already understand network segmentation. Not everyone who enters the lobby can walk into the medication room, the records office or the server closet. Doors and badges limit who can reach what, so one unlocked entrance does not give access to everything.

A flat network, where every device can talk to every other device, is like a building with no interior doors. A single infected laptop, a hacked camera or a visitor's compromised phone can reach everything else. Segmentation adds the interior doors.

What Segmentation Actually Is

Segmentation divides a network into separate zones and controls the traffic between them. Technically this is done with VLANs on switches and rules on a firewall. From a management viewpoint, the key idea is simple: group devices by purpose and trust level, then allow only the connections that are needed.

Why It Matters

It limits the spread of an attack. Ransomware often moves sideways from the first infected machine to servers and other computers. Segmentation can slow or stop it.

It protects devices that cannot protect themselves. Older medical devices, cameras and building controls often cannot be patched, so isolating them lowers risk.

It keeps guests away from internal systems. Visitors and residents can use the internet without touching your clinical network.

It supports compliance. HIPAA's Security Rule calls for access controls and protection of ePHI, and segmentation is a common technical way to implement them. The proposed Security Rule update that HHS published in January 2025 also discusses network segmentation, though that proposal is not final.

It makes troubleshooting and monitoring easier, because traffic patterns are clearer.

A Sensible Set of Zones for a Care Facility

A small or mid-size organization does not need dozens of segments. A good starting design might include:

Staff and clinical workstations: computers and tablets used for charting and administration.

Servers and critical systems: any on-site servers, with tightly controlled access.

Medical and clinical devices: monitors, carts and other equipment, grouped according to vendor guidance.

Building systems: door access, HVAC, cameras, nurse call and wander management, which are often managed by outside vendors.

Phones: voice over IP phones often benefit from their own segment.

Resident and guest Wi-Fi: internet-only, with no route to internal zones.

Management network: for network equipment settings, restricted to IT.

Rules Between the Zones

The logic is generally to deny by default and allow only what is needed. For example:

Guest Wi-Fi can reach the internet, nothing else

Staff workstations can reach the EMR and file servers, but not camera systems

Camera systems can talk to their recorder, not to the staff network

Vendors reach only the devices they support, and only when needed

Servers can receive requests from authorized workstations but cannot initiate connections to the internet unless they need updates

Writing these rules in plain language first, before they are configured, is useful. It forces a conversation about what really needs to talk to what.

How to Start Without Breaking Things

Segmentation done carelessly can disrupt care. A cautious approach:

Inventory devices and connections. You cannot isolate what you have not found.

Begin with the easy wins. Separate guest and resident Wi-Fi from internal networks first, if not already done.

Move groups one at a time, starting with lower-risk categories such as cameras or printers, and test.

Monitor and adjust. Log blocked traffic to learn what legitimate connections you missed.

Use maintenance windows for changes, with a rollback plan and clinical leaders informed.

Document everything, including a simple diagram.

Common Mistakes

Creating zones but allowing all traffic between them, which provides little protection

Forgetting vendor remote access paths that bypass the rules

Skipping documentation so nobody remembers why a rule exists

Not testing after changes

Treating it as a one-time project instead of maintaining it as devices change

A Question for Your Team

Ask your IT provider: "If one computer on our staff network were infected tonight, what else could it reach?" If the answer is "everything," segmentation deserves a place in your budget plan.

How UnityCare IT Helps

UnityCare IT designs and implements segmentation for healthcare facilities, working carefully around clinical operations and vendor requirements. If you would like a plain-language review of your current network layout, we are happy to start there.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172