Skip to content
Care and health: Care homes

Care homes: visitors on the portal, staff on EAP-TLS, a personal WiFi key for every device that needs one

Care-planning tablets authenticate with EAP-TLS, telecare and sensors get MAC-bound keys on their own VLAN, agency staff get keys that end with their booking, and families sign in on the portal. One log covers every home in the group.

  • ISO 27001 and Cyber Essentials Plus
  • 99.9% RADIUS uptime SLA
  • 80,000+ venues in 90 countries
  • Agency keys end with the booking
Illustration
Illustration: one xPSK SSID with a unique key per device, resident, tenant and contractor, each on its own VLAN and bandwidth limit, revocable on its own.
Book my design session

Who is on the care homes network

Who and what connects, and where each one lands

Care-planning tablets on EAP-TLS, call points and alert units on MAC-bound keys, and agency keys that end with the booking: no shared passphrase on the wall.

Who and what connects, and where each one lands
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
Families and other visitorsOpenCaptive portal sign-in, consent recordedGuest VLAN, client isolation onConsent recorded at sign-in, and no account to clean up afterwards
Care-planning tablets and eMAR devicesSecureEAP-TLS, certificate from your MDM over SCEP (managed by your MDM)A clinical-records VLAN, apart from guest and resident trafficCertificate revoked when the device is wiped or retired
Care staff, nurses and managersSecureEAP-TLS, certificate from your MDM over SCEPVLAN by directory groupAccount disabled, and RADIUS CoA ends the session
GPs and district nurses who visit regularlySecurePasspoint or OpenRoaming profileGuest-class VLAN, with no portal on returnProfile installed once, valid at every home that runs it
Agency staffxPSKIndividual key, MAC-bound (time-limited, no MDM)A staff VLAN and a bandwidth limit per keyEnds when the booking ends
Residents' tablets, phones and TVsxPSKIndividual key, MAC-boundA resident VLAN or role, client isolation onRevoked alone when a device is retired
Telecare units, call points and sensorsxPSKIndividual key, MAC-bound (bound to the device's MAC)A care-systems VLAN, unreachable from residents and guestsRevoked alone when a unit is replaced

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

Care homes: open, secure and xPSK

Three networks, each doing its own job

Identity decides the VLAN inside each network, so one SSID carries many groups.

Families and one-off visitors: portal, consent, a guest VLAN

The guest lane. Visitors get internet access on a VLAN that never meets a resident's device or a care system.

  • Families on the captive portal. Sign-in by SSO, Google, Apple, Facebook or SMS, with consent recorded for GDPR and CCPA. The portal and RADIUS go onto a controller in under 15 minutes.
  • Guests apart from residents and care systems. A guest VLAN with client isolation on, so a visitor's laptop sees no tablet, no TV and no telecare unit, and the portal log shows who signed in and when.
Illustration

Lifecycle

Key lifecycle: onboard, place, operate, offboard

The same four moves serve a telecare unit, an agency worker and a care-planning tablet, tied to the records the home already keeps: the shift booking, the device register and the directory.

Issue when the booking or device is created

Key an agency worker when the shift is booked, and a telecare unit when it is commissioned: from the console, in bulk from a list, or through the Purple API. Each key is bound to a MAC or a booking window.

Illustration

Place on the lane the role needs

RADIUS returns the VLAN, role or group policy, depending on your vendor. Your access points enforce it, and anything that must cross lanes is allowed by policy at your gateway.

Illustration

Operate from one log

Every accept and reject carries its reason, by member of staff, agency key and device, across every home in the group, streamed to Microsoft Sentinel, Splunk, Elastic or Datadog.

Illustration

End the booking, not the network

When a booking ends its key stops being accepted and nobody else is disconnected. Disable a leaver and the certificate stops being accepted, with RADIUS CoA ending any live session.

Illustration

One authentication log

One authentication log across every home

Staff certificates, agency keys, telecare units and visitor sessions land in the same log, so a manager or an inspector's question gets an answer from a query and not from memory.

  • Which agency keys are live today, whose booking they belong to and when each ends.
  • Which care-planning tablets authenticated with a certificate, and which were rejected and why.
  • Which telecare units are on the network at each home, on which VLAN.
  • Whether a leaver's or agency worker's session ended when the account or booking did.
Illustration

Audit

Evidence for inspectors and the toolkit

What the authentication log and the VLAN map show an inspector or a toolkit assessor.

  • NHS DSPT

    Evidence of network separation between care systems, residents and guests, and of who had access and when.

Works with

Your directory, your MDM, your SIEM, your access points

Nothing is replaced. Purple Access sits on the systems your team already runs.

  • Identity providers

    Over SAML and SCIM. Group membership decides the VLAN.
    • Microsoft Entra ID
    • Okta
    • Google Workspace
  • Device management

    EAP-TLS certificates delivered over SCEP, with a compliance-gated join.
    • Microsoft Intune
    • Jamf Pro
    • JumpCloud
    • Kandji
    • Hexnode
    • Iru
    • Addigy
  • SIEM

    The authentication log, over webhook or syslog.
    • Microsoft Sentinel
    • Splunk
    • Elastic
    • Datadog
  • Access points

    Mixed estates are supported.
    • Cisco Meraki
    • HPE Aruba
    • Ruckus
    • Juniper Mist
    • Ubiquiti UniFi
    • Cambium
    • Extreme
    • Fortinet

Proof

A supplier your IT and compliance leads can check

Purple holds ISO 27001 and Cyber Essentials Plus, and the cloud RADIUS service carries a 99.9% RADIUS uptime SLA in your contract.

99.9%
cloud RADIUS uptime SLA, in your contract
80,000+
venues run on Purple, in 90 countries
500M
logins a year
99.999%
uptime, with a 99.9% cloud RADIUS SLA and multi-region failover

Add-on: Purple Shield

Add protective DNS with Purple Shield

Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Questions IT leads ask

What replaces the shared passphrase on the wall?

Three things, by device class. Managed devices authenticate with an EAP-TLS certificate from your MDM, devices that cannot hold one get an individual xPSK key bound to their MAC, and visitors use the captive portal. Nobody holds a passphrase that unlocks everything, so there is nothing to rotate when someone leaves.

How does an agency worker's key end with the booking?

The key is issued with an end date, from the console, in bulk or over the Purple API. When the date passes, cloud RADIUS rejects it, and RADIUS CoA ends a live session on access points that support it. No account is left in your directory and nothing is installed on their phone.

Does a segmented network matter for the DSPT?

The Data Security and Protection Toolkit asks how access to care systems is controlled and who has it. The answers are yours to give, and the network supplies the facts they rest on: care-planning tablets on certificates, telecare on MAC-bound keys on their own VLAN, guests on a separate VLAN, and a log of every authentication with its identity and reason.

How do telecare units and call points connect?

Like any device with no supplicant: as a WPA2-Personal client on an individual xPSK key, bound to the unit's MAC, with RADIUS returning a care-systems VLAN. Your access points call it iPSK on Cisco, DPSK on Ruckus, PPSK on Extreme or MPSK on HPE Aruba, and Purple runs all of them. Replacing a unit means revoking one key and issuing another.

Do we need new access points in our homes?

No. Purple Access is a cloud overlay on the access points your homes already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

Book a demo: we issue and revoke a key on a live network

Bring a care-planning tablet, a telecare unit, an agency worker's phone and a visitor's laptop. We issue each a certificate or key, place it on its VLAN and revoke one live, on the access points your homes already run.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.