Healthcare: patients on the portal, clinicians on EAP-TLS, a personal WiFi key per medical device
Infusion pumps and telemetry that cannot do 802.1X get MAC-bound keys on a locked-down VLAN. Clinicians authenticate with EAP-TLS or directory groups, staff phones join without MDM enrollment, and patients and visitors stay apart from each other and from clinical systems.
- £12k a year saved at St George's
- ISO 27001 and Cyber Essentials Plus
- 99.9% RADIUS uptime SLA
- No MDM for staff phones
Who is on the hospitals and healthcare network
Who and what connects, and where each one lands
Infusion pumps and telemetry that cannot hold a certificate get a MAC-bound key on a locked-down VLAN.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Staff on their own phones | Open | Purple app onboarding, certificate installed, no MDM | Onboarding lane, then the group VLAN | Ends with the directory account |
| Patients | Open | Captive portal sign-in, consent recorded | Patient VLAN, client isolation on, apart from clinical systems | Consent recorded at sign-in, and no account to clean up afterwards |
| Visitors | Open | Captive portal sign-in, consent recorded | Guest VLAN, client isolation on, apart from patients | Consent recorded at sign-in |
| Clinicians and admin staff on managed devices | Secure | EAP-TLS, certificate from your MDM over SCEP (workstations, laptops, handhelds) | Clinical and administrative VLANs by directory group | Account disabled, and RADIUS CoA ends the session |
| Locums and visiting consultants | Secure | Passpoint or OpenRoaming profile | Guest-class VLAN, with no portal on return | Profile installed once, valid at every site that runs it |
| Infusion pumps, telemetry and monitoring devices | xPSK | Individual key, MAC-bound (bound to the device's MAC) | A locked-down biomedical VLAN per device class | Revoked alone when a device is replaced or retired |
| Contractors and equipment engineers | xPSK | Individual key, MAC-bound (time-limited, no MDM) | A VLAN and a bandwidth limit per key | Ends on its end date |
| Staff accommodation residents | xPSK | Individual key, MAC-bound (a key per device) | A resident VLAN or role per household, client isolation on | Keys end at move-out |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Hospitals and healthcare: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Patients, visitors and staff phones: portal and onboarding lane
The guest lane and the BYOD onboarding lane. Patients and visitors reach the internet and nothing else, and staff personal phones get a certificate without being enrolled in device management.
- Patients and visitors apart from each other and from clinical systems. Two VLANs on the captive portal, client isolation on, with consent recorded for GDPR and CCPA. One patient's device cannot see another's, and neither can see a clinical system.
- Staff on their own devices without MDM enrollment. Sign in once in the Purple app and a WiFi pass installs, on Windows, macOS, Linux, iOS and Android. The directory group decides the VLAN, and the account ending ends the pass.
- Sign-in methods per site. SSO, Google, Apple, Facebook or SMS, chosen per site, and under 15 minutes to add the splash URL and RADIUS to a controller.
Clinical and administrative staff: EAP-TLS and directory groups
One WPA-Enterprise SSID. Cloud RADIUS checks the certificate and the directory group and returns the VLAN, so a ward clerk and a consultant land in different lanes on the same access points.
- EAP-TLS for managed devices. Workstations, laptops and handhelds get a certificate from your MDM over SCEP: Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy. Setup is five to ten minutes, once, for the whole organization.
- Directory groups decide the VLAN. Entra ID, Okta or Google Workspace over SAML and SCIM. Disable a leaver once and every site stops authenticating them, with RADIUS CoA ending the live session.
- Passpoint for locums and visiting consultants. Install a profile once and rejoin automatically at every site that runs it, with OpenRoaming free through the Connect license.
Medical devices, contractors and accommodation: a key each
Devices with no 802.1X supplicant, no certificate store or no screen get an individual key on one SSID. MAC binding keeps a key a key and not a second shared password.
- Infusion pumps and telemetry on locked-down VLANs. A MAC-bound key per device and a VLAN per device class, so the pump is reachable by what monitors it and by nothing else. Replacing a pump revokes one key.
- Contractors and engineers with nothing to install. A time-limited key from the self-service portal or the Purple API, ending on the day the job does.
- Staff accommodation run like an apartment block. A key per resident device, a VLAN or role per household and keys that end at move-out, on the same access points and the same platform as the ward.
- Patient tablets for family calls. Hospital-owned tablets on keys of their own. St George's Healthcare NHS Trust saves £12k a year on patient iPads for family calls.
Lifecycle
Key lifecycle: commission, place, operate, decommission
The same four moves serve a telemetry monitor, an engineer's laptop and a clinician, tied to the systems the trust or group already runs: the asset register, the directory and the contractor booking.
Issue at commissioning
Key a device when biomedical engineering commissions it, in bulk from the asset register export or through the Purple API. Each key is bound to the device's MAC address.
Place on a VLAN by device class
RADIUS returns the VLAN, role or group policy, depending on your vendor. Your access points and gateway enforce it, and the route from a pump to its monitoring server is a rule on your gateway.
Operate from one log
Every accept and reject carries its reason, by clinician, contractor and device, across every site, streamed to Microsoft Sentinel, Splunk, Elastic or Datadog.
End one key, or one leaver
Retire a pump and you revoke its key alone. Disable a leaver and the certificate stops being accepted, with RADIUS CoA ending the live session.
One authentication log
One authentication log across every site
Clinician certificates, device keys, contractor keys and patient sessions land in one log, so which device is on which VLAN, and why, is a query and not a survey.
- Which medical devices are on the network at each site, on which VLAN and with which key.
- Which unknown devices tried a clinical VLAN and were rejected.
- Which contractor keys are live today and when each ends.
- Which staff authenticated by certificate, and which were rejected and why.
- Whether a leaver's session ended when their account was disabled.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
In the NHS and in estates like yours
St George's Healthcare NHS Trust saves £12k a year on patient iPads for family calls. Purple holds ISO 27001 and Cyber Essentials Plus.
- £12k
- a year saved on patient iPads for family calls, St George's Healthcare NHS Trust
- 99.9%
- cloud RADIUS uptime SLA, in your contract
- 80,000+
- venues run on Purple, in 90 countries
- 500M
- logins a year
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
How does an infusion pump with no certificate store get on the network?
To the pump, its xPSK key is an ordinary WPA2-Personal passphrase, so there is no supplicant and no portal. The per-device key lives on the access point side, bound to the pump's MAC, and RADIUS returns the biomedical VLAN. Where the pump itself speaks 802.1X, use EAP-TLS and keep the key for everything else.
Is this the iPSK our wireless vendor already offers?
It is the same mechanism under the vendor's own name: iPSK on Cisco, DPSK on Ruckus, PPSK on Extreme and Ubiquiti UniFi, MPSK on HPE Aruba and Juniper Mist. Purple Access runs the key lifecycle for all of them from one platform, so a mixed estate does not need a different process per site.
How are patients kept apart from each other and from clinical systems?
Patients and visitors use the captive portal and land on their own VLANs with client isolation on. RADIUS returns the VLAN, and your access points and gateway enforce it. Nothing on the guest side has a route to a clinical VLAN unless your gateway policy allows it.
Can staff accommodation run on the same platform as the wards?
Yes. Treat each apartment or room as a household: a key per device, a VLAN or role per household, and keys that end at move-out. It runs on the same access points, with its own log lane and no route to clinical VLANs.
Do we need new access points?
No. Purple Access is a cloud overlay on the access points your sites already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Book a demo: we issue and revoke a key on a live network
Bring one ward's worth of devices: an infusion pump, a telemetry hub, a clinician's laptop and a contractor's. We issue each a key or a certificate, place it on its VLAN and revoke one live, on the access points you already run.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.