Nursing homes: visitors on the portal, staff on EAP-TLS, a personal WiFi key for every device that needs one
Care-planning tablets authenticate with EAP-TLS, telecare and sensors get MAC-bound keys on their own VLAN, agency staff get keys that end with their booking, and families sign in on the portal. One log covers every home in the group.
- ISO 27001 and Cyber Essentials Plus
- 99.9% RADIUS uptime SLA
- 80,000+ venues in 90 countries
- Agency keys end with the booking
Who is on the care homes network
Who and what connects, and where each one lands
Care-planning tablets on EAP-TLS, call points and alert units on MAC-bound keys, and agency keys that end with the booking: no shared passphrase on the wall.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Families and other visitors | Open | Captive portal sign-in, consent recorded | Guest VLAN, client isolation on | Consent recorded at sign-in, and no account to clean up afterwards |
| Care-planning tablets and eMAR devices | Secure | EAP-TLS, certificate from your MDM over SCEP (managed by your MDM) | A clinical-records VLAN, apart from guest and resident traffic | Certificate revoked when the device is wiped or retired |
| Care staff, nurses and managers | Secure | EAP-TLS, certificate from your MDM over SCEP | VLAN by directory group | Account disabled, and RADIUS CoA ends the session |
| Visiting physicians and home health nurses | Secure | Passpoint or OpenRoaming profile | Guest-class VLAN, with no portal on return | Profile installed once, valid at every home that runs it |
| Agency staff | xPSK | Individual key, MAC-bound (time-limited, no MDM) | A staff VLAN and a bandwidth limit per key | Ends when the booking ends |
| Residents' tablets, phones and TVs | xPSK | Individual key, MAC-bound | A resident VLAN or role, client isolation on | Revoked alone when a device is retired |
| Telecare units, call points and sensors | xPSK | Individual key, MAC-bound (bound to the device's MAC) | A care-systems VLAN, unreachable from residents and guests | Revoked alone when a unit is replaced |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Care homes: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Families and one-off visitors: portal, consent, a guest VLAN
The guest lane. Visitors get internet access on a VLAN that never meets a resident's device or a care system.
- Families on the captive portal. Sign-in by SSO, Google, Apple, Facebook or SMS, with consent recorded for GDPR and CCPA. The portal and RADIUS go onto a controller in under 15 minutes.
- Guests apart from residents and care systems. A guest VLAN with client isolation on, so a visitor's laptop sees no tablet, no TV and no telecare unit, and the portal log shows who signed in and when.
Managed care devices and staff: EAP-TLS and directory groups
One WPA-Enterprise SSID. Cloud RADIUS checks the certificate and the directory, and returns the VLAN for the group, so nobody needs the passphrase from the wall.
- EAP-TLS for care-planning tablets and eMAR devices. A certificate from your MDM over SCEP puts each managed device on a clinical-records VLAN apart from guest and resident traffic: Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy. Setup is five to ten minutes, once.
- Directory groups decide the VLAN. Entra ID, Okta or Google Workspace over SAML and SCIM. Nurses, managers and maintenance each land in their own lane, and disabling a leaver once stops them at every home.
- Passpoint for visiting professionals. Install a profile once and rejoin automatically on every visit, at every home that runs it, with OpenRoaming free through the Connect license.
Agency staff, residents' devices and telecare: a key each
Anything that cannot take a certificate gets its own key on one SSID, and a MAC binding stops it becoming the next shared password.
- Agency staff on keys that end with the booking. A time-limited key from the self-service portal or the Purple API, with nothing to install and no MDM enrollment, ending on the day the shift booking does.
- Residents' devices private to them. A key per tablet, phone or TV on a resident VLAN with client isolation on, so one resident's devices are never visible to another's. To the device the key is an ordinary WPA2-Personal passphrase, which means family can help set up a tablet without the home's IT.
- Monitoring and emergency response units. Each unit joins on a MAC-bound key and a care-systems VLAN of its own, apart from resident and guest traffic.
- Door controllers and environmental sensors. A key per device, on a building-systems VLAN a resident's tablet cannot reach.
Lifecycle
Key lifecycle: onboard, place, operate, offboard
The same four moves serve a telecare unit, an agency worker and a care-planning tablet, tied to the records the home already keeps: the shift booking, the device register and the directory.
Issue when the booking or device is created
Key an agency worker when the shift is booked, and a telecare unit when it is commissioned: from the console, in bulk from a list, or through the Purple API. Each key is bound to a MAC or a booking window.
Place on the lane the role needs
RADIUS returns the VLAN, role or group policy, depending on your vendor. Your access points enforce it, and anything that must cross lanes is allowed by policy at your gateway.
Operate from one log
Every accept and reject carries its reason, by member of staff, agency key and device, across every home in the group, streamed to Microsoft Sentinel, Splunk, Elastic or Datadog.
End the booking, not the network
When a booking ends its key stops being accepted and nobody else is disconnected. Disable a leaver and the certificate stops being accepted, with RADIUS CoA ending any live session.
One authentication log
One authentication log across every home
Staff certificates, agency keys, telecare units and visitor sessions land in the same log, so a manager or an inspector's question gets an answer from a query and not from memory.
- Which agency keys are live today, whose booking they belong to and when each ends.
- Which care-planning tablets authenticated with a certificate, and which were rejected and why.
- Which telecare units are on the network at each home, on which VLAN.
- Whether a leaver's or agency worker's session ended when the account or booking did.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
A supplier your IT and compliance leads can check
Purple holds ISO 27001 and Cyber Essentials Plus, and the cloud RADIUS service carries a 99.9% RADIUS uptime SLA in your contract.
- 99.9%
- cloud RADIUS uptime SLA, in your contract
- 80,000+
- venues run on Purple, in 90 countries
- 500M
- logins a year
- 99.999%
- uptime, with a 99.9% cloud RADIUS SLA and multi-region failover
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
What replaces the shared passphrase on the wall?
Three things, by device class. Managed devices authenticate with an EAP-TLS certificate from your MDM, devices that cannot hold one get an individual xPSK key bound to their MAC, and visitors use the captive portal. Nobody holds a passphrase that unlocks everything, so there is nothing to rotate when someone leaves.
How does an agency worker's key end with the booking?
The key is issued with an end date, from the console, in bulk or over the Purple API. When the date passes, cloud RADIUS rejects it, and RADIUS CoA ends a live session on access points that support it. No account is left in your directory and nothing is installed on their phone.
How do telecare units and call points connect?
Like any device with no supplicant: as a WPA2-Personal client on an individual xPSK key, bound to the unit's MAC, with RADIUS returning a care-systems VLAN. Your access points call it iPSK on Cisco, DPSK on Ruckus, PPSK on Extreme or MPSK on HPE Aruba, and Purple runs all of them. Replacing a unit means revoking one key and issuing another.
Do we need new access points in our homes?
No. Purple Access is a cloud overlay on the access points your homes already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Book a demo: we issue and revoke a key on a live network
Bring a care-planning tablet, a telecare unit, an agency worker's phone and a visitor's laptop. We issue each a certificate or key, place it on its VLAN and revoke one live, on the access points your homes already run.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.