Skip to main content

Part of Architecture pattern for connected medical devices - Pathology Pillar

Sample network segmentation pattern

Sample VLAN configuration for Pathology Pillar

Below is a recommended virtual local area network (VLAN) configuration for you to adopt when segmenting pathology devices on your clinical network:

Order and request VLAN- This VLAN will host all applications and system components used to facilitate the request and ordering of pathology tests for patients and the distribution of test results.

Patient administration services (PAS) VLAN – The VLAN will host PAS systems or equivalent.

Hospital information system (HIS) VLAN – This VLAN could host the HIS and/or PAS as determined by your trust's subject matter expert.

Laboratory information management system (LIMS) VLAN – This VLAN is a logical grouping of LIMS components (application, middleware, server) connected to your clinical network.

Integration VLAN - This VLAN will be dedicated to hosting your the integration engine components.

Point of care testing 1 (POCT1) VLAN – This VLAN will be dedicated to all POCT devices that connect to your organisation’s clinical network to communicate sensitive patient information acquired via testing using POC devices.

POCT2 VLAN - Another VLAN comprising additional POCT devices to ensure continuity of service in the event of a negative cyber event.

Analyser1 VLAN – This VLAN will host only pathology analysers connected to your clinical network (for example, in a laboratory or secondary care location).

Analyser2 VLAN – Another VLAN comprising additional pathology analyser devices to ensure continuity of service in the event of a negative cyber event. 

The above are recommendations and are by no means an exhaustive list. You can configure VLANs based on your understanding of the network.


Sample VLAN configuration for pathology modalities using port assignment

Below is an example of VLAN configuration of pathology diagnostic connected medical devices on a clinical network for a medium to large sized health and care organisation.

VLAN name VLAN number VLAN subnet assignment Switch assignment Switch port/number
Order - request 10 172.16.2.0/28

Switch 4

Fa0/19

PAS 20 172.16.3.0/28

Switch 3

Fa0/13

HIS-EPR 30 172.16.4.0/28 Switch 2 Fa0/8
LIMS 40 172.16.5.0/28

Switch 2

Switch 1

Fa0/3

Fa0/9

Integration 50 172.16.7.0/28 Switch 4 Fa0/18
POCT1 60 172.16.8.0/28

Switch 3

Switch 4

Fa0/12

Fa0/19

POCT2 70 172.16.9.0/28

Switch 1

Switch 2

Fa0/2

Fa0/7

Analyser1 80 172.16.10.0/28

Switch 4

Switch 3

Fa0/16

Fa0/11

Analyser2 90 172.16.11.0/28

Switch 1

Switch 3

Fa0/1

Fa0/16

Table 6: Sample VLAN configuration for pathology connected medical devices.


Last edited: 6 November 2023 11:43 am