Case study hospital group: Microsegmentation for over 2,000 servers

More than 2,000 servers, terminal server farms and central load balancers, spread across several hospitals: KAEMI introduced Zero Trust microsegmentation at a German hospital group. Section 75c SGB V and the Hospital Future Act set the frame.

Contact our experts

The starting point

For the IT security of German hospitals, Section 75c SGB V is the central law, introduced with the Patient Data Protection Act: since January 2022, licensed hospitals have been required to take appropriate technical and organisational safeguards in line with the state of the art. Added to this is the Hospital Future Act (KHZG), which funds digitalisation and requires part of the money to be earmarked for information security. Out of both came the assignment to systematically close the propagation paths in the network.

The group's environment: more than 2,000 servers across several hospitals, from the hospital information system to billing, terminal server farms for nursing and administration, central load balancers in front. No Kubernetes, but a grown, heterogeneous landscape with medical technology that cannot simply be patched. Nobody had a complete view of the east-west traffic between all of it.

The assignment for KAEMI: establish visibility across the entire group, design a segmentation model for servers, terminal servers and load balancers, and introduce it without interrupting patient care at any point. As usual for references from healthcare, we do not name the customer.

The project at a glance

Industry
Healthcare: hospital group
Location
Germany
Environment
More than 2,000 servers, terminal server farms, central load balancers
Driver
Section 75c SGB V (PDSG), KHZG
Scope
Professional services: analysis & design, rollout, handover to the group's IT

Anonymised at the customer's request.

>2,000Servers in one shared dependency map, from the HIS to the administrative applications
3Worlds in one policy model: servers, terminal servers, load balancers
§75cSGB V: IT security in line with the state of the art, binding for licensed hospitals
24/7Patient care: the rollout was not allowed to interrupt it at any point

The legal frame

What Section 75c SGB V and the KHZG demand of IT security

Law and funding frame prescribe no product. But they formulate requirements to which segmentation can make a substantial contribution, especially in an environment with medical technology and long device lifetimes.

Section 75c SGB V (PDSG)

Since January 2022, licensed hospitals in Germany have been required to take appropriate technical and organisational precautions in line with the state of the art, for the availability, integrity and confidentiality of their systems. The sector-specific security standard (B3S) for medical care serves as the reference and, among other things, provides for separating networks by protection needs.

Hospital Future Act (KHZG)

The KHZG funds the digitalisation of hospitals and ties it to information security: part of the funding is earmarked for IT security, and it is a funding category of its own on top. Anyone digitalising will hardly get around segmentation.

Medical technology and legacy systems

Many systems in a hospital cannot simply be patched: vendor approvals, certifications and long device lifetimes stand in the way. Segmentation acts as a compensating control here; it limits whom a vulnerable system can reach at all.

Availability of care

Attacks on hospitals target availability: encrypted systems mean postponed treatments. Containment is therefore not a compliance exercise but protection of care. An incident in one hospital must not become an incident for the whole group.

The environment

Three worlds, one segmentation model

Each of the three worlds brings its own difficulty. They were answered with one model that speaks the same language everywhere, even where load balancers obscure the view of the real communication relationships.

More than 2,000 servers

From the hospital information system through PACS and lab to the administrative applications, spread across several hospitals. The care-critical applications received ringfencing first, enforced directly at the workload. Even systems in the same network segment now only reach them with an explicit rule.

Terminal servers

Nursing, outpatient units and administration work on shared terminal servers; what makes a connection legitimate there is not the server's address but the role of the session. So user- and group-based rules apply: each session reaches the applications of its role, and a compromised session finds no path onward into the HIS.

Central load balancers

The load balancers bundle the traffic of many applications onto a few virtual addresses. Behind them it blurs who is really talking to whom. The dependency map has to resolve the path from client via virtual address to the real server, rules apply in front of and behind the balancer, and the health checks need their own allowances. Otherwise the first enforced rule set reports the pool as down.

The approach

Four phases to enforced segmentation

In a hospital there is no maintenance window for care. So no rule goes live whose effect was not visible in the simulation first.

  1. Visibility first

    Sensors rolled out across all hospitals of the group, then several weeks of observing real traffic. The map also resolved the paths across the load balancers: which client uses which virtual address, and which real servers answer behind it.

  2. Model and simulation

    A tag model by site, environment, application and role, no IP lists. Ringfencing of the HIS, PACS and the other care-critical applications first, then finer rules. Everything in simulation mode: the platform shows what a rule would block before it does.

  3. Step-by-step enforcement

    Enforcement went live hospital by hospital and application by application, in each case only once the simulation no longer reported legitimate connections. Patient care ran on without interruption: no maintenance windows, no outages.

  4. Handover to the group's IT

    Documentation, runbooks and training to finish: the group's IT took over the lead on the platform with clear processes for new systems, new hospitals and exceptions.

The result

What the group has today

  • A communication map across more than 2,000 servers and all hospitals of the group, maintained continuously.
  • HIS, PACS and the other care-critical applications inside a ringfence, enforced at the workload.
  • Role-based rules on the terminal servers of nursing, outpatient units and administration.
  • The paths across the load balancers are fully represented in the policy model, health checks included.
  • Solid evidence for Section 75c SGB V and B3S-oriented audits: map, policies, change history.
  • An incident in one hospital has far fewer ways to spread to the rest of the group.

Make IT security under Section 75c SGB V concrete

In a joint analysis workshop we make visible where an attacker would spread in your environment, and show what segmentation can contribute to the requirements from Section 75c SGB V and B3S. No obligation, and specific to your hospitals.