Segmenting medical devices without breaking clinical workflow
Unpatched medical devices on a flat clinical network are a well-known risk with a poorly-known fix. The constraint is not technical.
Dr. Amara Osei
Principal Security Architect
The devices are not going to be patched
A significant proportion of connected medical equipment runs operating systems that stopped receiving security updates years ago, and cannot be updated without invalidating regulatory certification. This is not negligence; it is how medical device approval works.
Any security model that depends on patching these devices is therefore not a model. The realistic goal is containment: assume the device is compromisable and design so that compromise does not propagate.
Discovery before design, always
The first obstacle is that nobody has an accurate inventory. Biomedical engineering holds one list, IT holds another, and neither includes the infusion pump that estates installed in 2019.
Passive network discovery over a full clinical cycle — including weekends and night shifts — reliably finds devices that appear on no register. Four weeks of passive observation before any design work is the highest-value phase of the project.
- Passive discovery over a minimum four-week clinical cycle
- Reconciliation against biomedical, IT and estates registers
- Traffic profiling per device class before writing a single rule
Segment by clinical function, not by device type
The instinctive design segments by device category — all infusion pumps here, all imaging there. In practice this cuts across clinical workflows and generates rule exceptions until the segmentation is meaningless.
Segmenting by clinical function instead, so that a care pathway's devices and the systems they talk to sit in the same zone, produces far fewer cross-zone flows and a rule base a human can still read in two years.
Fail open, and say so
In a hospital, a security control that blocks clinical traffic during an incident is itself a clinical incident. Segmentation must be designed to fail open, with monitoring and alerting rather than automated blocking on the clinical path.
This is an uncomfortable conversation with a security team used to automated containment, and it needs to happen at design stage with clinical leadership present rather than being discovered at 3am.
Tagged
- Healthcare
- Network security
- Segmentation