Common signs include broad east-west reachability, dependence on undocumented vendor connections, long delays to onboard acquired sites, and a security team that can only block rather than safely approve change. If a compromised endpoint can still talk widely across the estate, the network is not segmented enough for modern clinical risk.
What “Too Flat” Looks Like in a Hospital Network
A hospital network is still too flat when segmentation exists on paper but not in practice. The warning signs are operational, not theoretical: systems can reach too much, change moves too slowly, and exceptions become the normal path. In healthcare, that usually means clinical uptime and device compatibility have been allowed to outrank boundary control.
Broad east-west reachability is the clearest indicator because compromise no longer stays local. If one endpoint, imaging workstation, or vendor foothold can traverse widely across the estate, then segmentation is not enforcing meaningful trust boundaries between wards, platforms, and third-party access paths.
Another sign is that onboarding a new site, acquired clinic, or specialist service depends on long exception chains and manual firewall workarounds. That usually means the network model is compensating for poor zone design rather than supporting repeatable expansion. A segmented environment should make growth safer, not force every integration through a bespoke carve-out.
Operational Friction That Reveals Weak Segmentation
flat network often expose themselves through the way changes are approved. If the security team can only block requests, but cannot safely approve defined patterns of change, the environment lacks a mature trust model. Good segmentation should let teams predefine which flows are allowed, under what conditions, and with what monitoring, rather than treating every new requirement as an emergency exception.
Undocumented vendor connections are another common warning sign. When remote support paths, medical device telemetry, or outsourced maintenance tunnels are invisible to the network team, segmentation is being undermined by shadow connectivity. The problem is not only lack of documentation, it is that unknown paths cannot be risk-ranked, constrained, or revoked quickly when needed.
Watch for environments where uptime arguments routinely defeat boundary design. In hospitals, clinical availability matters, but “we cannot segment because patient care depends on connectivity” is often a sign that architecture and operations were never aligned. Mature segmentation accounts for clinical workflow, device constraints, and failover, rather than leaving the estate broadly open as the easiest way to keep it running.
How to Judge Whether the Estate Is Segmented Enough
The practical test is whether a compromise has a bounded blast radius. If a workstation, server, or contractor connection is compromised, the attacker should not be able to move laterally into unrelated clinical systems, identity services, or management planes without additional controls. The more widely one foothold can talk, the flatter the network still is.
Another test is whether policy can be expressed in zones, not one-off exceptions. If the answer to every request is a bespoke rule that a few people understand, the network has not become more secure, it has become harder to govern. Segmentation is working when access patterns are predictable, reviewable, and tied to business function rather than historical convenience.
Hospitals can also use the speed of safe change as a signal. If a newly acquired site takes months to integrate because segmentation is an afterthought, the environment is not resilient. The goal is to make separation routine enough that business expansion, incident response, and clinical engineering can all happen without flattening the network.
Risk and Threat Considerations
Flat hospital networks increase the impact of a single compromised endpoint, vendor account, or exposed service because attackers can pivot laterally toward high-value clinical, administrative, or operational systems. They also make it harder to contain third-party access and harder to prove that critical zones are actually isolated.
Failure mechanism: Excessive east-west reachability, undocumented vendor paths, and exception-driven firewalling let an initial foothold traverse the estate with minimal resistance, so containment depends on hope rather than enforced segmentation.
Impact: A local compromise can become a network-wide incident, increasing ransomware spread, clinical disruption, and recovery scope while also delaying safe remediation during an active event.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, NIST CSF 2.0, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-4 — Information Flow Enforcement | Directly addresses restricting east-west traffic between hospital zones. |
| AC-6 — Least Privilege | Supports limiting vendor and internal access to only required systems and paths. | |
| CM-2 — Baseline Configuration | Relevant because segmentation depends on governed, repeatable network configurations. | |
| Recommendation — Define and enforce approved inter-zone flows so compromise cannot spread freely. Reduce each network path and administrative route to the minimum needed for the task. Maintain approved segmentation baselines and review deviations as controlled exceptions. | ||
| NIST CSF 2.0 | PR.AA-05 — Identity Management, Authentication, and Access Control | Applies where network access paths depend on controlling who or what may connect. |
| PR.PS-01 — Configuration Management | Relevant to controlled network zoning, firewall policy, and safe change handling. | |
| Recommendation — Tie access paths to authenticated, authorised entities and review them regularly. Manage network segmentation rules as controlled configurations with approval and traceability. | ||
| NIST Zero Trust (SP 800-207) | Zero Trust Architecture | The question is fundamentally about reducing implicit trust and lateral reach. |
| Recommendation — Design access around explicit trust decisions and continuous verification rather than broad reachability. | ||
| CIS Controls v8 | CIS-12 — Network Infrastructure Management | Directly supports segmenting network infrastructure and controlling internal traffic paths. |
| CIS-3 — Data Protection | Relevant because flatter networks expand the blast radius to sensitive clinical and operational data. | |
| CIS-4 — Secure Configuration of Enterprise Assets and Software | Applies where flatness results from weak baseline hardening and uncontrolled exceptions. | |
| Recommendation — Inventory and segment network infrastructure so internal traffic is tightly governed. Restrict pathways to sensitive systems so a foothold cannot reach broad data stores. Harden network devices and endpoint configurations to support enforced segmentation. | ||
| ISO/IEC 27001:2022 | A.8.20 — Network security | Directly covers protection of network services, traffic, and segmentation boundaries. |
| Recommendation — Implement and review network security measures that separate critical hospital zones. | ||
Practitioner Guidance
What to verify: Confirm whether each major clinical, administrative, and third-party zone has a documented allowed-flow model, not just a block list. If you cannot show which systems should talk to which, by design, the network is still too flat.
Decision rule: If a connection is justified only by legacy convenience or a vendor’s preferred support method, treat it as a segmentation gap until it is constrained, monitored, or replaced. If the connection is essential for patient care, redesign the path rather than leaving the whole zone open.
What good looks like: Acquired sites, medical devices, and remote support channels should be able to come online through predefined patterns with limited blast radius. A mature estate allows change without forcing broad trust.
Practitioner takeaway: In hospitals, “too flat” usually means the network still optimises for connectivity first and containment second. If you cannot isolate a compromised endpoint without breaking the entire operation, the architecture is still carrying unacceptable clinical and security risk.
Related resources from NHI Mgmt Group
- Why do phishing attacks still succeed even when people know the warning signs?
- What are the signs that NTLM is still too deeply embedded in a Windows environment?
- What are the signs that remote access controls are too dependent on the network perimeter?
- What are the signs that mobile privacy controls are still too coarse-grained for real user consent?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org