5.1 Networks and Communications
Key Takeaways
- LAN is the campus fabric, WAN stitches sites and clouds, and WLAN is designed RF—not a single Wi-Fi that can carry guest and clinical traffic together.
- Clinical, biomedical, voice, guest, and management traffic belong on different VLANs and SSIDs; guest Wi-Fi on a clinical VLAN is a design failure.
- QoS protects voice and nurse-call (latency and jitter) and diagnostic imaging (throughput); campus markings that die at the WAN edge do not protect care.
- Telehealth bandwidth is sized for concurrent real-time rooms and wired fallback for stroke and ICU programs, not average daily users.
- Downtime communications require an out-of-band path, local viewers, and a named comms tree; an untested dual WAN is not redundancy.
5.1 Networks and Communications
Quick Answer: Domain I B.2 treats the network as a clinical safety system. CPHIMS items expect you to separate clinical, biomedical, and guest traffic; reserve bandwidth for imaging and voice with quality of service (QoS); and design downtime communications so care continues when the EHR or WAN is down.
Why networks are a Domain I competency
A CPHIMS professional is not asked to configure a switch port. You are asked to decide whether radiology can share a guest SSID, whether a tele-stroke cart is allowed to compete with staff video, and how the hospital talks when the EHR is dark. Network failures show up as delayed images, dropped nurse-call, silent ADT, and clinicians inventing workarounds. Task B.2 tests whether you can design for safety, segmentation, and continuity, not whether you can recite OSI layers from a vendor slide.
LAN, WAN, and WLAN — use the terms as operators use them
| Network | What it connects | Typical healthcare load | CPHIMS design pressure |
|---|---|---|---|
| LAN | Devices on one campus or building | EHR clients, printers, badge readers, VoIP, nurse call, imaging workstations | Segmentation, QoS, wired reliability for life-safety systems |
| WAN | Sites to data centers, clouds, and other hospitals | EHR replication, HIE, claims, remote imaging, disaster recovery | Latency, encryption, dual paths, downtime playbooks |
| WLAN | Mobile clinicians, carts, visitors, some IoMT | COWs, tablets, infusion pumps, guest phones, telehealth carts | Capacity, roaming, SSID-to-VLAN mapping, RF interference |
A local area network (LAN) is the campus fabric: access switches, distribution, core, and the wired drops that still carry most life-safety and imaging traffic. A wide area network (WAN) is the set of circuits and tunnels that stitch campuses, clinics, the data center, and cloud regions. A wireless LAN (WLAN) is RF access that must be designed, not hoped for: channel plans, controller capacity, and SSID-to-VLAN mapping.
Do not treat “we have Wi-Fi” as a design. A 300-bed hospital can have excellent public wireless and still fail a code cart because the clinical SSID is oversubscribed on the same airtime as visitor streaming. Wired remains the default for PACS diagnostic stations, nurse-call controllers, and many biomedical devices that cannot tolerate RF jitter. Wireless is how mobile clinicians move; it is not a license to put every modality on the same radio as a waiting-room tablet.
Campus versus clinic. A hospital LAN is dense, multi-VLAN, and QoS-heavy. A five-provider clinic may be a single switch stack plus a managed WLAN, but the same rules apply: guest traffic stays off clinical VLANs; EHR and payment terminals do not share an open SSID; the WAN circuit is sized for images and visits, not only email. Rural clinics on a single commodity circuit need an explicit statement of what happens when that circuit dies—because it will.
Segmentation: clinical, biomedical, and guest are not one network
Segmentation is the practice of putting different trust and traffic classes on different VLANs, SSIDs, firewalls, and routing domains so a compromise or a flood in one class cannot starve or observe another.
Minimum healthcare pattern:
- Clinical / EHR VLAN — staff workstations, thin clients, medication cabinets, barcode scanners that talk to the EHR.
- Biomedical / IoMT VLAN — infusion pumps, monitors, imaging modalities, smart beds. These devices are often unpatchable and should not browse the internet.
- Voice / real-time VLAN — VoIP, nurse call, RTLS, some video.
- Guest / BYOD VLAN — visitors, patients, and personal phones. Internet only, no route to EHR, PACS, or biomedical subnets.
- Management / jump VLAN — infrastructure admin, out-of-band, privileged jump hosts.
Exam trap: putting guest Wi-Fi on the clinical VLAN is a design failure. Convenience is not a compensating control. A visitor device that can ARP-spoof, scan, or saturate the same broadcast domain as the EHR is an availability and confidentiality incident waiting for an OCR letter. A captive portal authenticates a human; it does not isolate Layer-2 attacks or guest floods.
Micro-segmentation (host-level policy) is a refinement, not a substitute for these coarse VLANs. CPHIMS stems usually test the coarse failure: guest and clinical mixed, or pumps sitting on the same flat network as laptops that browse the web. Firewalls between these zones default-deny. Clinical systems initiate only the flows they need (EHR to interface engine, PACS to archive, pump gateway to a vendor cloud only if a BAA and risk analysis support it). Guest traffic never originates a session into clinical space.
QoS: imaging and voice lose if everything is “best effort”
Quality of Service (QoS) marks and queues packets so delay-sensitive and clinically time-critical traffic is not crushed by bulk transfers. Healthcare has two classes that fail visibly:
- Voice and nurse-call need low latency and low jitter. Dropped packets become unintelligible speech or a silent code.
- Diagnostic imaging (PACS, ultrasound, CT reconstructions, cine loops) needs throughput and predictability. A radiologist waiting on a 400 MB study is a length-of-stay problem, not an IT inconvenience.
QoS is not “make the EHR faster.” It is protect the classes that break care when the pipe is full. Typical markings: voice in an expedited-forwarding queue, interactive EHR in a low-latency data class, imaging in a dedicated assured-forwarding class, guest and software updates in scavenger or best-effort. WAN circuits need the same markings honored by the carrier or SD-WAN policy; campus QoS that dies at the MPLS edge is theater.
Telehealth bandwidth is a QoS and capacity problem, not a “we bought a video app” problem. A tele-ICU or tele-stroke cart needs reserved uplink, wired fallback, and a tested codec. Shared clinic Wi-Fi that also carries guest streaming will freeze a neurologist’s exam. Size for concurrent video rooms, not average daily users. Store-and-forward dermatology is delay-tolerant; real-time stroke is not. Document the minimum megabits and jitter the clinical program accepted, then monitor them. If the program cannot state a number, the infrastructure team cannot defend a circuit.
Downtime communications are part of the network design
When the EHR, DNS, or WAN fails, the network team’s job is not only restore. Care continues on downtime procedures: paper MAR, downtime EHR viewers, analog or cellular backup for codes, overhead page, and a pre-agreed command channel.
Design elements CPHIMS expects you to name:
- Out-of-band path — cellular, radio, or a separate ISP so the incident channel does not ride the failed WAN.
- Read-only downtime viewers — locally cached ADT, meds, allergies, and recent results that do not depend on the primary data center.
- Role-based comms tree — who pages the house supervisor, who tells the ED to stop electronic triage, who notifies affiliated clinics.
- Reconciliation path after restore — how paper orders re-enter the legal record.
A dual WAN with no tested failover is not redundancy. Quarterly tabletops plus a live fail-over of a clinic or a unit are how you prove availability. Tie this to Chapter 12’s business-continuity design; here the point is that communications architecture is a continuity control.
Scenarios and traps
- Trap: “Wi-Fi is Wi-Fi.” Clinical, biomedical, and guest SSIDs must map to different VLANs and firewall policies.
- Trap: “Guest on clinical VLAN is fine if we use a captive portal.” A portal authenticates humans; it does not isolate Layer-2 attacks or guest floods.
- Trap: “QoS is only for VoIP.” Imaging and real-time telehealth fail without reserved capacity.
- Trap: “The WAN is the vendor’s problem.” You still own latency SLAs, encryption, and the downtime script when the circuit dies.
- Trap: “Telehealth works if the app launches.” Measure concurrent video bandwidth and wired fallback for stroke and ICU programs.
A 12-site ambulatory network that backhauls every image over a single 50 Mbps circuit will look “up” in a dashboard and still cancel afternoon MRI reads. Capacity and class, not just uptime, are the CPHIMS measures.
A community hospital’s facilities team wants one SSID so visitors and nurses can “just connect.” The WLAN controller can apply a captive portal. What is the CPHIMS-aligned design?
Afternoon CT reads stall while guest video and workstation patching fill the WAN. Voice is also clipping. What infrastructure change addresses the clinical failure mode?
The primary MPLS circuit to the data center fails. The EHR is unreachable. Which communications design is part of the network plan, not a later afterthought?