Why hospital network segmentation projects stall and what that means for patient safety

In a hospital, a security incident is never just an IT problem. When systems go down, patients and caregivers feel the difference. That’s why the measure of hospital cybersecurity isn’t whether the security team stops every intrusion. No team does. The measure is whether one compromised device stays one compromised device, or becomes an event the whole hospital feels. 

That discipline is called containment: limiting which devices on a hospital network are allowed to communicate with each other, so a laptop with malware can’t reach an infusion pump and a compromised building controller can’t touch the electronic health record. Network segmentation is the general practice of dividing a hospital network into zones. Microsegmentation is the finer-grained form of network segmentation that applies rules to each individual device rather than to a whole zone. The terminology matters less than the idea: every fire door in a hospital exists for the same reason. 

Nearly every health system has started a segmentation project. Far fewer have finished one. In a HIMSS Market Insights survey that Elisity and Carahsoft commissioned, 40% of senior leaders at larger health systems named fear of disrupting clinical workflows as the top barrier to implementing it.  

Containment is a patient safety control 

Most hospital networks grew flat because flat was fast. Devices joined, clinics were acquired, new buildings came online and everything could reach everything because that was the path of least resistance. That design served a simpler era of connected care. A mid-size hospital now runs thousands of connected devices, from infusion pumps to imaging to building controls and they still share a network that was never built to hold a failure locally. 

On a flat network, an incident anywhere is potentially an incident everywhere. That’s what makes containment more than a technical preference. It belongs in the same conversation as medication safety and staffing coverage, because what it protects is continuity of care. 

What makes hospital microsegmentation projects stall 

Segmentation projects rarely fail loudly. They stall quietly and usually for one of five reasons. 

They’re treated as network re-architecture. The traditional path runs through VLANs, firewall rule sets and re-addressing. It’s slow, disruptive work and hospital networks change faster than the redesign can keep up. A VLAN says where a device plugged in, not what it is, so door controls, ultrasound machines and EMR workstations end up sharing one zone. 

They stop just before enforcement. Nobody wants to be the person whose new policy took a clinical system offline at 2 a.m. Without a safe way to test what a rule will do before it’s live, policies sit in draft and the project quietly runs out of road. 

No one owns it end to end. Segmentation lands across three groups: the network team that owns the switches, the security team that owns the policy and clinical engineering that owns the devices. That’s a structural gap, not a failing of any team. In the same HIMSS survey, 34% of healthcare leaders cited insufficient internal staff or specialized security resources as a major barrier. When ownership of each phase isn’t assigned up front, the project doesn’t get vetoed. It gets deferred, one handoff at a time. 

The map was never right. Most health systems don’t have an accurate picture of what’s on the network and the inventory they do have usually covers IT assets rather than biomedical and IoT equipment. Then it ages out in weeks as devices move, get replaced, or connect for the first time. Policy built on a partial map fails on the real network. 

They assume software agents. A large portion of a hospital’s connected equipment, from imaging systems to lab analyzers to building controls, can’t take a security agent at all. A strategy that starts with “install something on every endpoint” excludes the devices that concern clinical engineering most. 

None of these are failures of intent or effort. They’re failures of approach and of ownership. 

What the projects that finish do differently 

In the deployments we’ve supported, the health systems that get to enforcement tend to share a few habits. They write policy around identity rather than location, so a rule describes what a device is and what it should talk to and survives when the device moves. Visibility comes first, before enforcing a single boundary: a live, continuously updated picture of the connected devices on the network. Nothing gets enforced until it has been simulated against production traffic. And the work is anchored to one clinical use case with a named owner, rather than the whole enterprise at once, so there’s something contained and working to show before the next budget cycle opens. 

Proof that finishing is possible 

St. Luke’s University Health Network, a 15-hospital system across eastern Pennsylvania and New Jersey with 350 physician practices and 85,000 devices on its network, has described completing its major segmentation buckets in roughly 46 days, following about a month of infrastructure preparation, with minimal downtime and without installing agents or buying new hardware. 

The outcome the team talks about first isn’t the segmentation. It’s the robotic surgical systems that went live on December 29, after roughly two years of being held off the network on security grounds and acquisition onboarding that fell from six to nine months down to weeks. Containment is what made both possible. One health system’s numbers won’t transfer to another. What transfers is the proof that the stall isn’t inevitable. 

Where to start 

Three questions reveal more about a hospital’s containment posture than most audits: 

1. Could your team say, today, which devices are able to reach your most critical clinical systems? 

2. If one device were compromised tonight, what would limit how far it spreads? 

3. If you started tomorrow, who would own policy: the network team, the security team, or both? 

If any of those answers aren’t certain, that’s the place to begin. Start with visibility, then identity, then one contained zone that proves the model. A rip-and-replace program isn’t the prerequisite people assume it is. 

Elisity works with health systems on this problem: identity-based microsegmentation that deploys on existing network infrastructure. To see how hospitals are approaching containment as a patient safety discipline and how St. Luke’s did it, please visit our website.  

Similar Posts

Leave a Reply