Imagine a single hallway in a building with no doors. Anyone who walks in can reach every room. A flat computer network works much the same way: every connected device can talk to every other device. In a nursing home or assisted living community, that might mean a visitor's phone, a resident's tablet, a medication cart, a nurse-call system and a server holding resident records all sit on the same network.
Network segmentation puts doors and locks in that hallway. It is a common recommendation in healthcare security guidance, and the proposed HIPAA Security Rule update from January 2025 discusses it as well, though that proposal is not final.
Segmentation divides a network into separate zones, often using virtual LANs (VLANs), with a firewall or router controlling what traffic may pass between them. Devices in one zone can only reach what they need in another.
Limits the spread of malware. If one device is infected, the damage is confined.
Protects older devices. Many medical and building systems cannot be patched easily or run older software. Isolating them reduces exposure.
Keeps guests away from internal systems. Residents, families and vendors can use the internet without any path to your servers.
Improves performance. Cameras, streaming devices and guest traffic do not compete with clinical systems.
Supports incident response. You can isolate a zone quickly without shutting down the entire facility.
Staff and business office: Facility-owned computers, printers and file servers.
Clinical systems: Workstations, medication carts and devices that connect to the EHR.
Medical and monitoring devices: Equipment such as vitals monitors, and telehealth carts, where applicable.
Building systems: Nurse call, door access, HVAC controls, cameras and alarm panels.
Voice and phones: VoIP phones, which benefit from their own network for quality.
Guest and resident Wi-Fi: Internet access only.
Management: Network gear and administrator tools, tightly restricted.
You do not need seven zones on day one. Many small facilities start with three: staff, building and medical devices, and guest.
You cannot segment what you cannot see. List everything connected, including printers, cameras, TVs, thermostats and anything resident-owned that connects to the staff network.
For each group, ask who needs to talk to whom. A medication cart needs the EHR and a printer; it does not need the camera system.
Start with "deny by default," then allow only what is required. Document each rule and its purpose.
Schedule changes during low-impact windows. Move one group at a time, test, and keep a rollback plan. Notify staff in advance about possible short interruptions.
Review firewall logs for blocked traffic that reveals legitimate needs you missed, and for unusual attempts that indicate problems.
Creating separate VLANs but allowing all traffic between them, which provides little benefit
Forgetting wireless: segmentation must extend to Wi-Fi networks
Leaving default passwords on network equipment
Putting guest Wi-Fi on the same network as staff for convenience
Failing to document rules, which makes troubleshooting a guessing game
Ignoring vendor remote access, such as a camera company that connects to its own equipment
Some medical devices and building systems have vendor requirements about network placement. Check with the manufacturer before moving them, and ask what ports and addresses they need.
If you can only do one thing this quarter, separate guest and resident Wi-Fi from everything else, then isolate building systems and cameras. Those two steps remove a lot of exposure with relatively little disruption.
UnityCare IT designs and implements segmented networks for long-term care and senior-living facilities, with careful testing so care is not interrupted. If your network is flat or you are not sure, we can map it and propose a phased plan.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172