Skip to Content
AIMdefense | Next Generation Firewall
  • 0
  • 0
    • Home
    • Features
    • NGFW Package
    • Deployment
    • Docs & Downloads
    • About AIMdefense
    • Solutions
    • Success Stories
    • Contact
  • Follow us
  • English (UK) Deutsch Türkçe
AIMdefense | Next Generation Firewall
  • 0
  • 0
    • Home
    • Features
    • NGFW Package
    • Deployment
    • Docs & Downloads
    • About AIMdefense
    • Solutions
    • Success Stories
    • Contact
  • Follow us
  • English (UK) Deutsch Türkçe

A practice network the practice can run on its own

How a medical practice segments its network behind an AIMdefense firewall and moves its connections to the Association of Statutory Health Insurance Physicians (KV) and to billing service providers onto clearly defined paths.

The practice

An independent medical practice with nine treatment rooms. Each room is equipped with one workstation. Reception has two further PCs and three printers. The practice management software runs on a dedicated server located on the practice premises.

There is no in-house IT department. The systems are looked after by a relative of the practice owners who brings IT experience from his professional career. Responsibility for the operation of the practice lies with the owner.

The starting position

Until now, the only device between the practice network and the internet was a router. There was no firewall, and there was no separation between the server, the treatment room workstations, reception and the printers. All devices were connected to a single flat network.

At the same time, the practice maintains external connections: to the KV and to billing service providers for private billing. This means that regular data paths lead into the practice network, and at the end of that network sits a server holding patient data. Without a firewall, there was no point at which these paths could be filtered, restricted or logged.

The trigger

The initiative came from the relative who supports the practice. He made it clear to the practice management what unauthorised external access to patient data would mean for a practice, in professional terms, in legal terms and for the relationship of trust with patients. In his view, a router alone was not a sufficient boundary.

"I carry the responsibility and I had it implemented. All I really want is to keep operations secure. It is unimaginable how much know-how is demanded of a small practice. A simpler solution and simpler support would be desirable."

— Owner of the practice

This statement describes the situation of many independent medical practices. Responsibility for protecting patient data lies with the practice management, while the technical knowledge required to do so is rarely available in-house.

The solution

The practice uses AIMdefense as its central firewall and has built its entire infrastructure behind it. The network is now divided into clearly separated zones:

  • the server running the practice management software as a specially protected zone
  • the nine treatment room workstations
  • reception
  • the printers in a segment of their own

Rules between these zones permit only the communication that is actually required. The connections to the KV and to the billing service providers now run over defined and documented paths instead of an open network. Filtering and logging take place at the firewall. Configuration states are backed up and can be restored.

The system is operated through an interface that the relative supporting the practice learned to use without additional training. It is supplied Assembled in Germany.

Implementation

Setup and switchover were completed within a single day. The switchover itself took place at a weekend while the practice was closed and took around three hours. Consultation hours were not affected at any point, and no alternative appointments were required for patients.

The result

The practice runs its network on its own. The server holding patient data is no longer in the same network as the printers and the workstations. An incident on an end device remains confined to its segment. The external data paths are named, governed and traceable instead of running implicitly through a router.

For the practice management, this means above all that the protection of patient data no longer depends on knowledge and trust that have grown over time. It now rests on a documented structure that can be reviewed and restored.

"One less thing to worry about."

— Owner of the practice

Key facts

SectorOutpatient care, single practice
AIM productsAIMdefense
ArchitectureSegmented practice network behind a central firewall
Previous systemRouter without a firewall
Environment1 server, 11 workstations, 3 printers
External connectionsAssociation of Statutory Health Insurance Physicians (KV), billing service providers
SupportSelf-managed by the practice
Project duration1 day
Downtimearound 3 hours, at a weekend while the practice was closed

More about AIMdefense

For the functions behind segmentation, rule sets and logging, please see the Features page.

Request a demoBecome a partner
AIMdefense

Next generation firewall, software-first.

Secure 2 Fiber GmbH · Am Brambusch 24 · 44536 Lünen

+49 231 999 85 400 · info@secure2fiber.com

AIM family

AIM
AIMdefense
AIMSTRONG
AIMcompute
AIMroute
AIMnetworks
AIMsoc (coming soon)
AIMdesk

Legal

Imprint
Privacy
Terms
Company website
Become a partner

© Secure 2 Fiber GmbH · The AIM, AIMSTRONG and AIMdefense marks are subject to the trademark rights of Secure 2 Fiber GmbH.

Copyright © Secure 2 Fiber GmbH

We use cookies to provide you a better user experience on this website. Cookie Policy

Only essentials I agree