Network Segmentation: Keeping Medical Devices Away From Office PCs

On many small healthcare networks, everything sits on a single flat network. The business office computers, nurse station workstations, printers, security cameras, medication dispensing equipment, resident Wi-Fi and the thermostat controller can all talk to each other. That is convenient for setup, but it means that one infected laptop or one compromised camera can potentially reach everything else. Network segmentation is the practice of dividing a network into zones and controlling the traffic between them.

Why segmentation matters in care settings

Limits ransomware spread. If malware lands on an office PC, segmentation can keep it from reaching clinical servers and devices.

Protects fragile devices. Many medical and building devices run old or unpatchable software. They cannot always be updated, so isolating them is the compensating control.

Separates untrusted traffic. Resident and guest Wi-Fi should have no path to staff systems.

Supports compliance. The HIPAA Security Rule expects safeguards that restrict access to ePHI to authorized users and systems, and segmentation is a recognized technical measure.

Improves performance and troubleshooting. Streaming video in resident rooms will not compete with clinical traffic.

Common zones for a care facility

The right layout depends on the size and complexity of the facility. A practical set of zones might include:

Staff and clinical workstations, which access the EMR and email.

Servers and core systems, if you host any locally, with tightly limited access.

Medical and monitoring devices, such as vital sign monitors, infusion equipment, dispensing systems or lab devices where applicable.

Building systems, including cameras, door access, HVAC, nurse call, fire panels and elevators.

Phones and voice, often on a separate network for quality reasons.

Printers and scanners, which can be a weak point if left wide open.

Resident and guest Wi-Fi, internet access only.

Management network, reserved for administrators to configure network gear.

Smaller facilities might combine some zones. The principle is to separate things that should not need to talk to each other.

How it is done

Segmentation is usually implemented with VLANs on managed switches and wireless access points, combined with firewall rules that control what traffic is allowed between VLANs. The key idea is that devices in one VLAN cannot reach another unless a rule explicitly permits it.

A sound approach follows these steps:

Inventory devices. You cannot segment what you do not know about. Document every device, its purpose, its vendor and what it needs to communicate with.

Define zones and rules. For each zone, decide what traffic is required, such as the EMR workstation needing to reach the internet and a print server, and block everything else by default.

Talk to vendors. Medical device and building system vendors can tell you what network access their equipment needs. Some vendors manage devices remotely, which you should control carefully.

Implement in stages. Move low-risk zones first, such as guest Wi-Fi, then more complicated ones.

Test during a quiet window. Confirm that clinical workflows still work, including printing, scanning and device data feeds into the EMR.

Monitor and log blocked traffic. Logs help you tune rules and spot suspicious attempts.

Pitfalls to avoid

Overly broad rules. An allow-all rule between zones defeats the purpose.

Forgetting vendor remote access. Maintenance connections are a common route for intruders. Require MFA and limit access to the specific device.

No documentation. Without a network diagram and rule list, the next technician will struggle and may undo your work.

Breaking clinical workflows. Involve nursing leadership in testing, and have a rollback plan.

Treating segmentation as a replacement for patching. It reduces exposure, but does not remove the need for updates and monitoring.

Special note on medical devices

Devices that connect to the network for data or maintenance should be placed in their own segment with the narrowest possible access. Ask the manufacturer about supported configurations, available security patches and end-of-support dates. The FDA publishes cybersecurity guidance for medical device manufacturers, and some vendors provide security documentation you can request.

Starting small

Even a basic first step, separating guest Wi-Fi and moving cameras and building systems to their own segment, delivers real protection. A more complete plan can follow. UnityCare IT designs and implements segmented networks for care facilities and can start with a device inventory and a simple diagram of your current layout.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034