Back to Guardra

Hospital network security glossary.

14 terms used in the assessment, from clinical protocols to segmentation evidence and its limits.

42 CFR Part 2

Substance-use-disorder record protections

Federal rules imposing consent requirements stricter than HIPAA on substance-use-disorder treatment records. It regulates records and disclosures, not network boundaries — a segment boundary is not a Part 2 control, and this page previously implied otherwise.

Asset inventory & network map

Proposed HIPAA requirement

The NPRM would require covered entities to maintain a written inventory of technology assets and a map of ePHI movement through the environment. Segmentation cannot be defended in an audit without one, because you cannot evidence isolation of assets you have not enumerated.

Asymmetric routing

Traffic taking different paths each way

Why observing no traffic never proves a path is closed. If your capture point sits on only one leg of an asymmetric path, or misses a trunk entirely, absence of evidence is not evidence of absence. Any honest assessment reports what it could not see.

DIMSE

DICOM Message Service Element

The classic DICOM service layer — C-STORE to send an image, C-FIND to query, C-MOVE to retrieve, C-ECHO to test connectivity. Specified with the same trusted-network assumptions as MLLP. DICOM over TLS exists but is unevenly deployed.

ePHI

Electronic protected health information

Individually identifiable health information held or transmitted electronically. The thing the Security Rule exists to protect, and the reason segment boundaries in a clinical estate carry regulatory weight rather than merely operational weight.

FDA §524B

Cyber device requirements

Requires manufacturers of cyber devices to provide a security plan, an SBOM, and postmarket vulnerability handling. It binds the manufacturer — the hospital still owns the network the device sits on, which is where isolation findings land.

HL7 v2

The messaging standard carrying most clinical traffic

Pipe-delimited messages — ADT for admissions and transfers, ORM for orders, ORU for results, SIU for scheduling, MDM for documents. Published in the 2000s and still carrying the majority of production interface volume. Its readability is what makes traffic analysis useful in healthcare specifically.

HPH CPGs

HHS Cybersecurity Performance Goals

Voluntary goals for the healthcare and public health sector, split into essential and enhanced tiers. Network segmentation and asset inventory both sit in the enhanced tier. HHS has stated an intention to inform future enforceable standards with them, and the goal names are worth reading directly rather than paraphrased — several circulating summaries, including an earlier version of this page, get the tiers wrong.

IoMT

Internet of Medical Things

Connected clinical devices — infusion pumps, monitors, ventilators, imaging modalities, lab analysers. Long service lives, vendor-controlled software, and maintenance windows scheduled around clinical availability. Patching is not unavailable — the FDA requires manufacturers of applicable cyber devices to support it — but it moves on the vendor's schedule rather than yours, which is why network position ends up carrying load.

MLLP

Minimal Lower Layer Protocol

The TCP framing wrapper that carries HL7 v2 messages. It is delimiter-framed — a start byte, the message, an end byte, a carriage return — and has no native TLS, having been specified when the network was assumed trusted. This is why hospitals put stunnel or mutual TLS in front of MLLP ports. How much HL7 runs unencrypted in any given estate is a question for that estate, not something to assert generally.

Network segmentation

Dividing a network to limit lateral movement

An enhanced goal in the voluntary HPH Cybersecurity Performance Goals. The January 2025 HIPAA Security Rule NPRM proposes an explicit network segmentation specification. A proposed requirement should not be presented as an existing obligation.

HHS proposed rule

Segmentation matrix

The written statement of which segments may talk

The artefact an assessment compares traffic against. Where it does not exist in written form, there is nothing to check evidence against — which is itself the most useful finding an organisation can receive.

Shadowed rule

A firewall rule that can never match

A rule positioned after a broader rule that already catches its traffic. Harmless in itself, but it inflates policy size, slows review, and hides intent — nobody can tell whether it was meant to do something.

SPAN / TAP

Ways to copy traffic for analysis

A SPAN (mirror) port is a switch feature that copies traffic to a monitoring port — cheap, but prone to blind spots under load. A TAP is purpose-built hardware with higher fidelity. Neither is required for a file-based assessment, which works from logs the organisation already keeps.