Back to Guardra
Hospital security workspace
Understand your clinical network.
Connect your assets, access requirements and firewall rules. See where configured access differs from hospital intent, then assign the review and next steps.
Local assessment · No network probes · No automatic firewall changes
Work stays in this tab. Download an assessment file to save assets, rules and review actions; reload it to continue later. There is no automatic storage or team synchronization. Use infrastructure metadata only; patient records are not needed.
Sign in to a persistent team workspaceAssessment scope and limitations
- Configuration checks only. No packets are sent and connectivity is not verified. A matching rule is not proof that a path is reachable.
- Each requirement checks all inventoried source/destination asset pairs in the named zones for one TCP/UDP destination port. Other addresses, ports, protocols and paths without requirements are not assessed.
- Hospital zones group assets for requirements; they are not firewall interface or vendor security zones. All input rules must already share a single enforcement context.
- No matching explicit rule is unknown; the tool does not assume an implicit deny. Empty zones and missing inputs are coverage gaps.
- Requirements and approvals are entered by the user, not authenticated sign-offs. Review statuses record decisions; they do not change findings or verify remediation.
- Confirm clinical dependencies and obtain clinical/network approval before implementing changes. This tool never changes a firewall.
- Only the supplied ordered rules are reviewed, using first-match semantics within one shared enforcement context. Disabled rules are ignored.
- IPv4 addresses/CIDRs, TCP/UDP destination ports and an any-protocol wildcard are supported. No vendor configuration, IPv6, NAT, zones, objects, schedules, source ports or application identity is modelled.
- Shadowing is reported only when one earlier rule fully covers a later rule. Combined coverage and partial overlap are not detected.
- Broad-access findings describe configured scope; they do not prove exposure or a policy violation. No traffic, reachability, device vulnerability or compliance is tested. Zero findings does not mean secure.
- Priorities are review cues, not vulnerability scores. Validate changes against the original configuration, intended access and operational requirements.