On many small networks, everything shares the same space: the nurse station computers, the EHR printers, the smart TVs in resident rooms, the cameras, a vital-signs monitor and the visitor's phone connected to guest Wi-Fi. This is called a flat network, and it is convenient until something goes wrong. A single compromised device can then reach almost everything else.
Network segmentation divides the network into zones so that problems stay contained. It is one of the most valuable infrastructure improvements a care facility can make, and it is more achievable than many people think.
Segmentation uses features built into business-grade switches, firewalls and wireless systems. The most common tool is the VLAN, a virtual network that keeps groups of devices logically separate even though they share the same physical equipment. A firewall then controls what traffic is allowed between zones.
The idea is simple: devices should be able to reach only what they truly need.
Resident and guest devices are unmanaged. You cannot control their software, updates or habits.
Medical and building devices are often hard to patch and may run older software.
Clinical systems hold electronic PHI, which the HIPAA Security Rule requires you to protect with access controls and transmission security.
Ransomware often spreads sideways across a network. Segmentation slows or stops it.
Exact design depends on your facility, but many organizations start with these:
Computers, laptops and servers used for daily work and for access to the EHR. This is the most protected zone with strong authentication and endpoint security.
Infusion pumps, monitors, lab equipment and other connected devices, grouped by function where practical. These often cannot be patched quickly, so tight firewall rules matter. Work with each manufacturer to understand required connections.
Cameras, door access, HVAC controls, nurse call and fire panels. These devices are frequent targets and should not be able to reach clinical systems.
Phones are often placed on a separate network to prioritize call quality and reduce exposure.
Completely isolated from internal networks, with access only to the internet. Consider client isolation so devices on this network cannot see one another.
A restricted zone used by IT to manage switches, firewalls and access points.
Start with a default-deny stance: block traffic between zones unless there is a documented reason to allow it. Examples of allowed traffic might include a nurse call server talking to a specific application, or a printer being reachable from staff computers only. Document each rule, its purpose and its owner.
Segmenting an existing network can break things if done hastily. A careful approach includes:
Inventorying all devices and what they communicate with.
Starting with the easiest wins, such as isolating resident and guest Wi-Fi.
Moving devices in small groups during maintenance windows.
Testing critical workflows after each change.
Keeping a rollback plan.
Communicating with staff about expected downtime.
Segmentation needs equipment that supports it. Consumer-grade routers often do not. Confirm that your switches support VLANs, that your firewall can enforce rules between zones and that your wireless access points can broadcast multiple networks mapped to different VLANs.
Keep an up-to-date asset list so new devices land in the right zone.
Review firewall rules regularly and remove ones that are no longer needed.
Log traffic between zones, and alert on unusual attempts.
Update firmware on switches and firewalls.
Creating VLANs without firewall rules, which separates the traffic only on paper.
Allowing broad any-to-any rules for convenience.
Forgetting that vendors may require remote access to devices, and leaving that access always on.
Not documenting the design, so only one person understands it.
It works best alongside patching, strong authentication, monitoring and backups. Think of it as limiting the blast radius when something goes wrong.
Which zones do we have, and what is in each?
Can resident Wi-Fi reach any internal system?
How are medical and building devices isolated?
Who reviews firewall rules, and how often?
UnityCare IT designs and implements segmented networks for healthcare and senior-living facilities, with testing built around care schedules. If your network is still flat, we can help you plan a practical first phase.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172