Skip to content
Care and health: Hospitals and healthcare

Healthcare: patients on the portal, clinicians on EAP-TLS, a personal WiFi key per medical device

Infusion pumps and telemetry that cannot do 802.1X get MAC-bound keys on a locked-down VLAN. Clinicians authenticate with EAP-TLS or directory groups, staff phones join without MDM enrollment, and patients and visitors stay apart from each other and from clinical systems.

  • £12k a year saved at St George's
  • ISO 27001 and Cyber Essentials Plus
  • 99.9% RADIUS uptime SLA
  • No MDM for staff phones
Illustration
Illustration: one xPSK SSID with a unique key per device, resident, tenant and contractor, each on its own VLAN and bandwidth limit, revocable on its own.
Book my design session

Who is on the hospitals and healthcare network

Who and what connects, and where each one lands

Infusion pumps and telemetry that cannot hold a certificate get a MAC-bound key on a locked-down VLAN.

Who and what connects, and where each one lands
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
Staff on their own phonesOpenPurple app onboarding, certificate installed, no MDMOnboarding lane, then the group VLANEnds with the directory account
PatientsOpenCaptive portal sign-in, consent recordedPatient VLAN, client isolation on, apart from clinical systemsConsent recorded at sign-in, and no account to clean up afterwards
VisitorsOpenCaptive portal sign-in, consent recordedGuest VLAN, client isolation on, apart from patientsConsent recorded at sign-in
Clinicians and admin staff on managed devicesSecureEAP-TLS, certificate from your MDM over SCEP (workstations, laptops, handhelds)Clinical and administrative VLANs by directory groupAccount disabled, and RADIUS CoA ends the session
Locums and visiting consultantsSecurePasspoint or OpenRoaming profileGuest-class VLAN, with no portal on returnProfile installed once, valid at every site that runs it
Infusion pumps, telemetry and monitoring devicesxPSKIndividual key, MAC-bound (bound to the device's MAC)A locked-down biomedical VLAN per device classRevoked alone when a device is replaced or retired
Contractors and equipment engineersxPSKIndividual key, MAC-bound (time-limited, no MDM)A VLAN and a bandwidth limit per keyEnds on its end date
Staff accommodation residentsxPSKIndividual key, MAC-bound (a key per device)A resident VLAN or role per household, client isolation onKeys end at move-out

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

Hospitals and healthcare: open, secure and xPSK

Three networks, each doing its own job

Identity decides the VLAN inside each network, so one SSID carries many groups.

Patients, visitors and staff phones: portal and onboarding lane

The guest lane and the BYOD onboarding lane. Patients and visitors reach the internet and nothing else, and staff personal phones get a certificate without being enrolled in device management.

  • Patients and visitors apart from each other and from clinical systems. Two VLANs on the captive portal, client isolation on, with consent recorded for GDPR and CCPA. One patient's device cannot see another's, and neither can see a clinical system.
  • Staff on their own devices without MDM enrollment. Sign in once in the Purple app and a WiFi pass installs, on Windows, macOS, Linux, iOS and Android. The directory group decides the VLAN, and the account ending ends the pass.
  • Sign-in methods per site. SSO, Google, Apple, Facebook or SMS, chosen per site, and under 15 minutes to add the splash URL and RADIUS to a controller.
Illustration

Lifecycle

Key lifecycle: commission, place, operate, decommission

The same four moves serve a telemetry monitor, an engineer's laptop and a clinician, tied to the systems the trust or group already runs: the asset register, the directory and the contractor booking.

Issue at commissioning

Key a device when biomedical engineering commissions it, in bulk from the asset register export or through the Purple API. Each key is bound to the device's MAC address.

Illustration

Place on a VLAN by device class

RADIUS returns the VLAN, role or group policy, depending on your vendor. Your access points and gateway enforce it, and the route from a pump to its monitoring server is a rule on your gateway.

Illustration

Operate from one log

Every accept and reject carries its reason, by clinician, contractor and device, across every site, streamed to Microsoft Sentinel, Splunk, Elastic or Datadog.

Illustration

End one key, or one leaver

Retire a pump and you revoke its key alone. Disable a leaver and the certificate stops being accepted, with RADIUS CoA ending the live session.

Illustration

One authentication log

One authentication log across every site

Clinician certificates, device keys, contractor keys and patient sessions land in one log, so which device is on which VLAN, and why, is a query and not a survey.

  • Which medical devices are on the network at each site, on which VLAN and with which key.
  • Which unknown devices tried a clinical VLAN and were rejected.
  • Which contractor keys are live today and when each ends.
  • Which staff authenticated by certificate, and which were rejected and why.
  • Whether a leaver's session ended when their account was disabled.
Illustration

Works with

Your directory, your MDM, your SIEM, your access points

Nothing is replaced. Purple Access sits on the systems your team already runs.

  • Identity providers

    Over SAML and SCIM. Group membership decides the VLAN.
    • Microsoft Entra ID
    • Okta
    • Google Workspace
  • Device management

    EAP-TLS certificates delivered over SCEP, with a compliance-gated join.
    • Microsoft Intune
    • Jamf Pro
    • JumpCloud
    • Kandji
    • Hexnode
    • Iru
    • Addigy
  • SIEM

    The authentication log, over webhook or syslog.
    • Microsoft Sentinel
    • Splunk
    • Elastic
    • Datadog
  • Access points

    Mixed estates are supported.
    • Cisco Meraki
    • HPE Aruba
    • Ruckus
    • Juniper Mist
    • Ubiquiti UniFi
    • Cambium
    • Extreme
    • Fortinet

Proof

In the NHS and in estates like yours

St George's Healthcare NHS Trust saves £12k a year on patient iPads for family calls. Purple holds ISO 27001 and Cyber Essentials Plus.

£12k
a year saved on patient iPads for family calls, St George's Healthcare NHS Trust
99.9%
cloud RADIUS uptime SLA, in your contract
80,000+
venues run on Purple, in 90 countries
500M
logins a year

Add-on: Purple Shield

Add protective DNS with Purple Shield

Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Questions IT leads ask

How does an infusion pump with no certificate store get on the network?

To the pump, its xPSK key is an ordinary WPA2-Personal passphrase, so there is no supplicant and no portal. The per-device key lives on the access point side, bound to the pump's MAC, and RADIUS returns the biomedical VLAN. Where the pump itself speaks 802.1X, use EAP-TLS and keep the key for everything else.

Is this the iPSK our wireless vendor already offers?

It is the same mechanism under the vendor's own name: iPSK on Cisco, DPSK on Ruckus, PPSK on Extreme and Ubiquiti UniFi, MPSK on HPE Aruba and Juniper Mist. Purple Access runs the key lifecycle for all of them from one platform, so a mixed estate does not need a different process per site.

How are patients kept apart from each other and from clinical systems?

Patients and visitors use the captive portal and land on their own VLANs with client isolation on. RADIUS returns the VLAN, and your access points and gateway enforce it. Nothing on the guest side has a route to a clinical VLAN unless your gateway policy allows it.

Can staff accommodation run on the same platform as the wards?

Yes. Treat each apartment or room as a household: a key per device, a VLAN or role per household, and keys that end at move-out. It runs on the same access points, with its own log lane and no route to clinical VLANs.

Do we need new access points?

No. Purple Access is a cloud overlay on the access points your sites already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

Book a demo: we issue and revoke a key on a live network

Bring one ward's worth of devices: an infusion pump, a telemetry hub, a clinician's laptop and a contractor's. We issue each a key or a certificate, place it on its VLAN and revoke one live, on the access points you already run.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.