42 CFR Part 2
Substance-use-disorder record protectionsFederal rules imposing consent requirements stricter than HIPAA on substance-use-disorder treatment records. It regulates records and disclosures, not network boundaries — a segment boundary is not a Part 2 control, and this page previously implied otherwise.
Asset inventory & network map
Proposed HIPAA requirementThe NPRM would require covered entities to maintain a written inventory of technology assets and a map of ePHI movement through the environment. Segmentation cannot be defended in an audit without one, because you cannot evidence isolation of assets you have not enumerated.
Asymmetric routing
Traffic taking different paths each wayWhy observing no traffic never proves a path is closed. If your capture point sits on only one leg of an asymmetric path, or misses a trunk entirely, absence of evidence is not evidence of absence. Any honest assessment reports what it could not see.
DIMSE
DICOM Message Service ElementThe classic DICOM service layer — C-STORE to send an image, C-FIND to query, C-MOVE to retrieve, C-ECHO to test connectivity. Specified with the same trusted-network assumptions as MLLP. DICOM over TLS exists but is unevenly deployed.
ePHI
Electronic protected health informationIndividually identifiable health information held or transmitted electronically. The thing the Security Rule exists to protect, and the reason segment boundaries in a clinical estate carry regulatory weight rather than merely operational weight.
FDA §524B
Cyber device requirementsRequires manufacturers of cyber devices to provide a security plan, an SBOM, and postmarket vulnerability handling. It binds the manufacturer — the hospital still owns the network the device sits on, which is where isolation findings land.
HL7 v2
The messaging standard carrying most clinical trafficPipe-delimited messages — ADT for admissions and transfers, ORM for orders, ORU for results, SIU for scheduling, MDM for documents. Published in the 2000s and still carrying the majority of production interface volume. Its readability is what makes traffic analysis useful in healthcare specifically.
HPH CPGs
HHS Cybersecurity Performance GoalsVoluntary goals for the healthcare and public health sector, split into essential and enhanced tiers. Network segmentation and asset inventory both sit in the enhanced tier. HHS has stated an intention to inform future enforceable standards with them, and the goal names are worth reading directly rather than paraphrased — several circulating summaries, including an earlier version of this page, get the tiers wrong.
IoMT
Internet of Medical ThingsConnected clinical devices — infusion pumps, monitors, ventilators, imaging modalities, lab analysers. Long service lives, vendor-controlled software, and maintenance windows scheduled around clinical availability. Patching is not unavailable — the FDA requires manufacturers of applicable cyber devices to support it — but it moves on the vendor's schedule rather than yours, which is why network position ends up carrying load.
MLLP
Minimal Lower Layer ProtocolThe TCP framing wrapper that carries HL7 v2 messages. It is delimiter-framed — a start byte, the message, an end byte, a carriage return — and has no native TLS, having been specified when the network was assumed trusted. This is why hospitals put stunnel or mutual TLS in front of MLLP ports. How much HL7 runs unencrypted in any given estate is a question for that estate, not something to assert generally.
Network segmentation
Dividing a network to limit lateral movementAn enhanced goal in the voluntary HPH Cybersecurity Performance Goals. The January 2025 HIPAA Security Rule NPRM proposes an explicit network segmentation specification. A proposed requirement should not be presented as an existing obligation.
HHS proposed ruleSegmentation matrix
The written statement of which segments may talkThe artefact an assessment compares traffic against. Where it does not exist in written form, there is nothing to check evidence against — which is itself the most useful finding an organisation can receive.
Shadowed rule
A firewall rule that can never matchA rule positioned after a broader rule that already catches its traffic. Harmless in itself, but it inflates policy size, slows review, and hides intent — nobody can tell whether it was meant to do something.
SPAN / TAP
Ways to copy traffic for analysisA SPAN (mirror) port is a switch feature that copies traffic to a monitoring port — cheap, but prone to blind spots under load. A TAP is purpose-built hardware with higher fidelity. Neither is required for a file-based assessment, which works from logs the organisation already keeps.