Part of Architecture pattern for connected medical devices - Pathology Pillar
Sample network segmentation pattern
Sample VLAN configuration for Pathology Pillar
Below is a recommended virtual local area network (VLAN) configuration for you to adopt when segmenting pathology devices on your clinical network:
Order and request VLAN- This VLAN will host all applications and system components used to facilitate the request and ordering of pathology tests for patients and the distribution of test results.
Patient administration services (PAS) VLAN – The VLAN will host PAS systems or equivalent.
Hospital information system (HIS) VLAN – This VLAN could host the HIS and/or PAS as determined by your trust's subject matter expert.
Laboratory information management system (LIMS) VLAN – This VLAN is a logical grouping of LIMS components (application, middleware, server) connected to your clinical network.
Integration VLAN - This VLAN will be dedicated to hosting your the integration engine components.
Point of care testing 1 (POCT1) VLAN – This VLAN will be dedicated to all POCT devices that connect to your organisation’s clinical network to communicate sensitive patient information acquired via testing using POC devices.
POCT2 VLAN - Another VLAN comprising additional POCT devices to ensure continuity of service in the event of a negative cyber event.
Analyser1 VLAN – This VLAN will host only pathology analysers connected to your clinical network (for example, in a laboratory or secondary care location).
Analyser2 VLAN – Another VLAN comprising additional pathology analyser devices to ensure continuity of service in the event of a negative cyber event.
The above are recommendations and are by no means an exhaustive list. You can configure VLANs based on your understanding of the network.
Sample VLAN configuration for pathology modalities using port assignment
Below is an example of VLAN configuration of pathology diagnostic connected medical devices on a clinical network for a medium to large sized health and care organisation.
VLAN name | VLAN number | VLAN subnet assignment | Switch assignment | Switch port/number |
---|---|---|---|---|
Order - request | 10 | 172.16.2.0/28 |
Switch 4 |
Fa0/19 |
PAS | 20 | 172.16.3.0/28 |
Switch 3 |
Fa0/13 |
HIS-EPR | 30 | 172.16.4.0/28 | Switch 2 | Fa0/8 |
LIMS | 40 | 172.16.5.0/28 |
Switch 2 Switch 1 |
Fa0/3 Fa0/9 |
Integration | 50 | 172.16.7.0/28 | Switch 4 | Fa0/18 |
POCT1 | 60 | 172.16.8.0/28 |
Switch 3 Switch 4 |
Fa0/12 Fa0/19 |
POCT2 | 70 | 172.16.9.0/28 |
Switch 1 Switch 2 |
Fa0/2 Fa0/7 |
Analyser1 | 80 | 172.16.10.0/28 |
Switch 4 Switch 3 |
Fa0/16 Fa0/11 |
Analyser2 | 90 | 172.16.11.0/28 |
Switch 1 Switch 3 |
Fa0/1 Fa0/16 |
Table 6: Sample VLAN configuration for pathology connected medical devices.
Last edited: 6 November 2023 11:43 am