
Another proposed change to the HIPAA Security Rule involves network segmentation. While the term may sound technical, the concept is fairly straightforward.
What is Network Segmentation?
It is a security control that divides your network into separate areas. The goal is to limit how far an unauthorized user can go if they gain access to your organization’s systems. If someone gets through one door, you do not want them to suddenly have keys to every room in the building. If an attacker compromises one computer, account, or system, network segmentation can help prevent them from automatically reaching other systems that contain sensitive information, including electronic protected health information (ePHI).
Where Do You Start?
Before you can segment your network, you first need to understand where your PHI lives.
- Is ePHI stored on your servers?
- Is ePHI being sent or stored in email?
- Is ePHI contained within your EMR or EHR? Do you have any legacy systems?
- Is there any medical equipment that contain hard drives with ePHI?
- Are employees storing PHI on workstations, laptops, smartphones, or shared drives?
- Are there other applications or cloud systems that contain PHI?
Once you understand where PHI is located, your IT team or managed service provider (MSP) can determine how those systems should be separated from other parts of your network.
Why Does This Matter?
Strong cybersecurity includes limiting the damage when something does happen. Without segmentation, an attacker who gains access to one part of your environment may be able to move through the network and access additional systems. With segmentation, you can create barriers that make that movement more difficult. An unauthorized user gaining access to one system should not automatically mean they have access to everything. Start by identifying where your PHI lives, then work with your IT provider to determine whether appropriate barriers exist between critical systems and the rest of your network.

Leave a Reply