Will you sign a BAA?
Yes, where our operations or support give us access to systems holding PHI. Design-only engagements normally do not require one; we tell you which applies at scoping.
Hospital systems, clinics and health-tech run on networks where a flat VLAN is a HIPAA finding. We design segmented campus and datacenter fabrics, medical-device isolation, firewall policy you can audit, and the documentation your compliance officer and your EHR vendor both ask for.
Yes, where our operations or support give us access to systems holding PHI. Design-only engagements normally do not require one; we tell you which applies at scoping.
Dedicated segments with NAC profiling (Mist Access Assurance, ISE or ClearPass), firewall policy allowing only the flows the device manufacturer documents, and logging of everything else. Devices are grouped by function, not by location.
Yes. Epic, Cerner/Oracle Health and Meditech each publish network requirements; we design to them and produce the evidence their technical review asks for.
Segmentation diagrams, firewall policy exports mapped to the HIPAA Security Rule, change records with twin-validation results, and access logs — all generated from the repository, not reconstructed after the fact.
| HIPAA Security Rule | Technical safeguards mapped to segmentation, access control, audit logging and transmission security; evidence produced from the design repository. |
|---|---|
| HITRUST CSF | Network controls aligned to HITRUST domains for organisations pursuing certification. |
| FDA / medical-device guidance | Device isolation and monitoring consistent with manufacturer MDS2 statements. |
| NIST CSF 2.0 | Used as the control framework for the assessment and roadmap. |
Segmenting clinical, EHR, medical-device, guest and business traffic; NAC profiling for devices that cannot be patched; the evidence to produce for HIPAA Security Rule reviews.