Skip to content
Care and health: Senior living

Senior living: families on the portal, staff on EAP-TLS, nurse call on a personal WiFi key per device

Alarm devices get MAC-bound keys on a care-systems VLAN residents never reach. Care staff authenticate with EAP-TLS or directory groups, families sign in on the portal, and one authentication log covers assisted living, independent living and every community you run.

  • 80,000+ venues in 90 countries
  • 99.9% RADIUS uptime SLA
  • ISO 27001 and Cyber Essentials Plus
  • Nurse call on its own VLAN
Illustration
Illustration: one xPSK SSID with a unique key per device, resident, tenant and contractor, each on its own VLAN and bandwidth limit, revocable on its own.
Book my design session

Who is on the senior living network

Who and what connects, and where each one lands

Nurse call and fall detection on a key and VLAN of their own, never mixed with residents' streaming.

Who and what connects, and where each one lands
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
Visiting family and friendsOpenCaptive portal sign-in, consent recordedGuest VLAN, client isolation on, apart from resident and care lanesConsent recorded at sign-in, and no account to clean up afterwards
Agency and bank staff on personal phonesOpenPurple app onboarding, certificate installed, no MDMOnboarding lane, then the group VLANEnds with the directory account
Care staff, managers and maintenanceSecureEAP-TLS, certificate from your MDM over SCEPVLAN by directory groupAccount disabled, and RADIUS CoA ends the session
Visiting clinicians who return every weekSecurePasspoint or OpenRoaming profileGuest-class VLAN, with no portal on returnProfile installed once, valid at every community that runs it
Residents' tablets, TVs and phonesxPSKIndividual key, MAC-bound (one key per device)A resident VLAN or role, client isolation on, a bandwidth limit per keyKey ends when the device is retired or the resident moves out
Nurse call, fall detection and wander alarm devicesxPSKIndividual key, MAC-bound (bound to the device's MAC)A care-systems VLAN per device class, unreachable from residents and guestsRevoked alone when a unit is replaced
Voice assistants in resident roomsxPSKIndividual key, MAC-boundA resident-device VLAN, isolated, on the same SSID as every other keyOne key per assistant, rotated or revoked on its own

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

Senior living: open, secure and xPSK

Three networks, each doing its own job

Identity decides the VLAN inside each network, so one SSID carries many groups.

Families and staff phones: portal and onboarding lane

The guest lane and the BYOD onboarding lane. Visitors never touch a resident's network or an alarm VLAN, and staff personal phones join without enrolling in device management.

  • A guest VLAN apart from care and residents. Visiting family sign in on the captive portal, with consent recorded for GDPR and CCPA and client isolation on, so a visitor's laptop cannot see a resident's tablet.
  • Staff personal phones with no MDM. Sign in once in the Purple app and a WiFi pass installs, on Windows, macOS, Linux, iOS and Android. The directory account decides the VLAN.
Illustration

Lifecycle

Key lifecycle: install, place, operate, retire

The same four moves serve an alarm pull-cord, a resident's tablet and an agency worker, tied to the records you already keep: your device register, your rota and your directory.

Issue at installation or admission

Key an alarm unit when the installer commissions it, and a resident's devices when they move in: from the console, in bulk from your device list, or through the Purple API. Each key is bound to the device's MAC address.

Illustration

Place on the lane the device class needs

RADIUS returns the VLAN, role or group policy, depending on your vendor. Your access points and gateway enforce it, and rules between lanes, such as the alarm gateway reaching its monitoring service, live on your gateway.

Illustration

Operate from one log

Every accept and reject carries its reason, by resident device, member of staff and alarm unit, across every community, streamed to Microsoft Sentinel, Splunk, Elastic or Datadog.

Illustration

End one key, or one leaver

Replace a pull-cord unit and you revoke its key alone. When a resident moves out their keys end and nobody else is disconnected. Disable a leaver and the certificate stops being accepted.

Illustration

One authentication log

One authentication log across every community

Alarm units, residents' devices, staff certificates and visitor sessions land in the same log, so "what is this device, and whose is it" is a query and not a walk round the building.

  • Which alarm devices are on the network at each community, on which VLAN, and when each last authenticated.
  • Which staff accounts authenticated today, by which method, and which were rejected and why.
  • Whether a device on a resident lane is one you issued a key to.
  • Whether a leaver's session ended when the account was disabled.
  • How many visitors used the portal this week, kept apart from care systems.
Illustration

Works with

Your directory, your MDM, your SIEM, your access points

Nothing is replaced. Purple Access sits on the systems your team already runs.

  • Identity providers

    Over SAML and SCIM. Group membership decides the VLAN.
    • Microsoft Entra ID
    • Okta
    • Google Workspace
  • Device management

    EAP-TLS certificates delivered over SCEP, with a compliance-gated join.
    • Microsoft Intune
    • Jamf Pro
    • JumpCloud
    • Kandji
    • Hexnode
    • Iru
    • Addigy
  • SIEM

    The authentication log, over webhook or syslog.
    • Microsoft Sentinel
    • Splunk
    • Elastic
    • Datadog
  • Access points

    Mixed estates are supported.
    • Cisco Meraki
    • HPE Aruba
    • Ruckus
    • Juniper Mist
    • Ubiquiti UniFi
    • Cambium
    • Extreme
    • Fortinet

Proof

Care estates run on the same platform

Purple Access runs on 80,000+ venues in 90 countries, and St George's Healthcare NHS Trust saves £12k a year on patient iPads for family calls.

80,000+
venues run on Purple, in 90 countries
500M
logins a year
99.9%
cloud RADIUS uptime SLA, in your contract
99.999%
uptime, with a 99.9% cloud RADIUS SLA and multi-region failover

Add-on: Purple Shield

Add protective DNS with Purple Shield

Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Questions IT leads ask

Can nurse call and fall detection share access points with residents' tablets?

Yes, and stay apart. Each alarm unit gets a key bound to its MAC and RADIUS returns a care-systems VLAN, while residents' devices sit on keys of their own. Your access points and gateway keep the lanes separate, and the log shows which key each device used.

Do voice assistants in every room mean an SSID per room?

No. A voice assistant has no supplicant and no browser, so it joins on an xPSK key like any other device, on the one SSID. 8 to 10 SSIDs use 15 to 25% of channel airtime, which is why per-room or per-device SSIDs are the wrong design.

Do we need new access points in our communities?

No. Purple Access is a cloud overlay on the access points your communities already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

How are residents kept apart from one another and from care systems?

Client isolation is on by default, and each class of device lands on its own VLAN or role returned by RADIUS. Access points and your gateway enforce it. Anything that must cross lanes, such as an alarm gateway reaching its monitoring service, is allowed by policy at your gateway.

Is xPSK the same as the vendor features we already license?

Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple Access runs them from one platform on a mixed estate.

Book a demo: we issue and revoke a key on a live network

Bring one wing's worth of devices: a nurse call hub, a pull-cord unit, a resident's tablet and an agency phone. We issue each a key or a certificate, place it on its VLAN and revoke one live, on the access points you already run.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.