Case study / Healthcare
A large academic health system reduced lateral movement risk across ~50,000 switchports
Gruve helped extend fabric-based micro-segmentation to clinical, IoT and legacy devices that cannot reliably run endpoint agents.
~50,000
Switchports operating under fabric-based segmentation policy across clinics, hospitals and the cancer center
30+
IP devices at each patient bed brought under policy, including imaging, IV pumps and bedside monitors
The Challenge
The devices that matter most are the ones you can least touch
At a large academic health system, security risk is clinical risk. CT scanners, X-ray machines, IV pumps, bedside monitors, building management systems and standard IT workloads share the same broad operating environment. If malware can move laterally from one device to another, the risk can affect care delivery, not just IT operations.
The constraint was the device mix. Healthcare environments include legacy, clinical and IoT devices that cannot be treated like standard laptops or servers. Some devices do not support security agents. Some still run older operating systems. Cameras, displays and other IoT devices cannot take endpoint agents either. The health system needed segmentation that worked even when the endpoint itself could not be changed.
Healthcare has a lot of legacy devices which don’t even support any security agents to be installed on them. Some of them even run Windows 95. The only option you’re left with is putting agents on them to segment them, but that becomes a very, very expensive solution. Plus, you can’t even deploy agents on IoT devices. That’s where a fabric-based solution comes into the picture. Every device gets segmented the moment the packet from the device hits the fabric.
Director, Network and Data Center Services
a large academic health system
Why Gruve
Start with the outcome, not the product.
Gruve kept the program focused on the outcome and the operating model. The work started with the patient-safety risk of lateral movement, then moved to device visibility, then to policy design based on how the real estate communicates.
The value proposition was practical coverage: bring clinical, IoT, building-management and legacy devices under segmentation policy without requiring agents on devices that could not support them. Classifying devices at this scale is the hard part, and the director recommends working with a services partner that has already done this in healthcare environments and is validated by top vendors.
The approach
Proven at one clinic before it governed a hospital
Step 1
Outcome and visibility
Define the goal, then build a complete picture of the connected estate.
Step 2
Device profiling and policy design
Build profiles around how devices actually communicate, then design policy against those profiles.
Step 3
Monitor mode and smaller-site validation
Run policy in monitor mode, validate at a smaller site, and involve biomedical and building-management stakeholders early.
Step 4
Staged rollout to full scale
Expand from simpler environments to larger hospital settings and the cancer center, using weekend change windows and post-change validation.
The outcomes
Fabric enforcement for the devices endpoint tools cannot reach
Risk reduced
What changed: Close to 50,000 switchports under fabric-based segmentation policy
Why it mattered: Reduced unnecessary east-west paths across clinics, hospitals and the cancer center
Estate covered
What changed: Clinical, IoT, building-management and standard IT devices brought into the segmentation model
Why it mattered: The case includes devices that cannot reliably run endpoint agents
Operational control
What changed: Policy based on device identity and communication needs, not only IP and VLAN structure
Why it mattered: Device moves and network changes become easier to manage safely
Cost per outcome
What changed: Fabric-based segmentation avoids relying only on per-endpoint agents
Why it mattered: The director describes agent-based segmentation as very expensive and incomplete for healthcare IoT and legacy devices
The path not taken
Two realistic options, both with a ceiling
The first path was to keep extending VLANs, ACLs and firewall-centric segmentation. That approach can help, but it becomes hard to maintain when policy is tied to IP addressing, subnet design and constant device movement.
The second path was to rely on endpoint agents. That breaks down in healthcare because many clinical, legacy and IoT devices cannot run agents at all, and the economics become difficult at scale.
What would have happened
The highest-risk devices would still be the hardest to protect
Without fabric-based segmentation, the health system would have had to choose between a hard-to-maintain network segmentation model and an endpoint-agent model that many healthcare devices could not support. The practical risk is unnecessary east-west movement across systems that support care delivery.
What's next
The sequence travels. The scale does not have to
The lesson is the sequence: start with visibility, understand the device estate, build and test profiles, run policy in monitor mode, validate at a smaller site, then expand. A smaller hospital does not need the health system’s scale to apply the same operating model.
Related Service
