Guest Wi-Fi in a medical office: what HIPAA expects, and how to set it up

A receptionist in scrubs works at the front desk of a medical practice, with the waiting room and a wall-mounted TV behind her

Updated October 8, 2026.

The short answer

Give patients their own guest Wi-Fi, walled off from every computer that touches patient records. HIPAA doesn't name Wi-Fi, but your required risk analysis has to cover it, and HHS guidance for small practices says to keep guest networks apart from practice systems. A proposed HIPAA update would make network segmentation an explicit requirement.

Key takeaways
  • Healthcare sent the FBI more ransomware complaints in 2025 than any other critical sector.
  • HHS guidance for small practices says to separate guest Wi-Fi from practice systems.
  • Required segmentation is still a proposal, with final action targeted for July 2027.
  • A separate network is one piece of HIPAA, not the whole job.

Is it safe to share one Wi-Fi with patients?

Many small practices run one network for everything. The front-desk PC, exam room laptop, waiting room TV, card reader and patients' phones all share it.

If the Wi-Fi password is posted on the wall, anyone in the waiting room is one hop from the computer that opens your charts.

460 ransomware complaints from healthcare to the FBI in 2025, the most of any critical infrastructure sector. FBI Internet Crime Report, 20251

Ransomware rarely starts at the server. It lands on one device, then moves sideways across a flat network until it reaches the files that matter. The FBI's advice in the same report is plain: segment networks to stop ransomware from spreading.1

Does HIPAA require a separate guest network?

Not by name. The current HIPAA Security Rule is technology neutral. It never mentions Wi-Fi, guest networks or routers.

It does require an accurate and thorough risk analysis of the threats to your electronic patient data.2 A guest network that shares space with your EHR workstation is exactly the kind of risk that analysis should catch.

HHS enforces this. In April 2025, a small New York neurology practice agreed to pay $25,000 after ransomware hit files on about 6,800 patients. HHS found it had failed to conduct an accurate and thorough risk analysis.3

HHS's free guidance for small practices, the 405(d) Health Industry Cybersecurity Practices, is more direct.4 It recommends:

  • Guest networks that keep visitors apart from practice data and systems, for example in waiting areas.
  • Guest networks that reach only approved guest services, such as the internet.
  • Restricted network zones for higher-risk gear, like security cameras, badge readers and medical devices.
  • Limits on what devices can reach each other, so an attack can't spread across the network.

What the proposed HIPAA rule says about segmentation

On January 6, 2025, HHS proposed a major update to the HIPAA Security Rule.5 Its reason was rising attacks.

264% rise in ransomware breaches reported to HHS from 2018 to 2023. HHS, proposed HIPAA Security Rule, January 20255

For a small practice, these proposed changes matter most:

  • Network segmentation. Technical controls that divide your systems in a reasonable and appropriate way.
  • An inventory and a network map. A written list of your technology and a map of how patient data moves.
  • Multi-factor login for access to systems with patient data, with limited exceptions.
  • Faster patching. Critical risks fixed within 15 calendar days when a patch exists.
  • Recovery plans. Written steps to restore critical systems and data within 72 hours.

As of October 2026, this is still a proposal. HHS's latest regulatory agenda moved it to long-term actions, with final action targeted for July 2027.6 That date is a target, not a deadline, and the final text could change.

Walling off clinical machines makes sense either way. It's cheap, it's fast, and it limits how far one infected device can reach.

A simple Wi-Fi layout for a small practice

Most small practices need four networks. Here's a starting point.

Network Devices Why
Clinical Front-desk PC, exam room laptops, printer Only devices that touch patient records
Office gadgets Waiting room TV, card reader, door camera Gadgets that rarely get updates stay walled off
Staff Staff phones and tablets Personal devices stay off clinical machines
Patients Patients' and visitors' phones Internet only, nowhere near your records

Keep the networks walled off from each other by default. Open a path only when a device truly needs one, then note that choice in your risk analysis.

Connected medical devices may come with their own network rules. Follow the maker's guidance before you move them.

A 10-step Wi-Fi checklist for small practices

  1. List every device on your network. Your router's device list is a good start. Anything you don't recognize gets investigated.
  2. Sketch a simple network map. Mark which devices touch patient data and where that data goes.
  3. Give clinical machines their own network. Nothing else joins it.4
  4. Put patients on guest Wi-Fi with its own name and password.4
  5. Wall off TVs, cameras and card readers in a network of their own.4
  6. Lock down the router. Change the admin password, and turn off remote management, WPS and UPnP unless you need them.7
  7. Use WPA2 or WPA3 encryption on every network.7
  8. Keep everything updated. Replace a router that no longer gets security fixes. Our guide to checking if your router needs replacing walks through it.
  9. Turn on multi-factor login for email, your EHR and any remote access tools.
  10. Write it down. Record what you did and why in your risk analysis. Review it when you add devices or move offices.

Seeing patients by video from home? The same idea applies there: put your work laptop on its own network, away from family devices. Our home office Wi-Fi guide covers the setup, and our post on separating smart devices explains why gadgets need their own space.

What a router can't do for HIPAA

A separate network is one control among many. HIPAA also covers your risk analysis, policies, staff training, backups, access to the computers themselves and business associate agreements with vendors that handle patient data.

A router also can't stop a phishing email or fix a weak password. Segmentation limits how far an attacker gets once inside. It doesn't keep them out on its own.

Where Rio fits. Rio is a $199.99 Wi-Fi 6 router built for this layout. It gives you up to 16 walled-off SecureRooms across 4 Wi-Fi networks, guest Wi-Fi for patients, and holds every new device until you approve it in the app. It doesn't store patient files, sign BAAs or do your risk analysis. See an example on our page for medical practices.

Your charts shouldn't share Wi-Fi with the waiting room.

Rio locks clinical machines in their own SecureRoom, puts patients on guest Wi-Fi, and holds every new device for your OK.

See a medical practice setup

Frequently asked questions

Is offering patients free Wi-Fi a HIPAA violation?

No. Guest Wi-Fi isn't a violation by itself. The risk comes when patients share a network with computers that hold patient records. HHS guidance for small practices recommends a guest network that keeps visitors apart from practice systems, and your risk analysis should show how you handled it.

Does HIPAA require network segmentation?

Not by name today. In January 2025, HHS proposed making segmentation an explicit Security Rule requirement. As of October 2026 it's still a proposal, with final action targeted for July 2027. The current rule still requires a risk analysis, and a flat shared network is a risk it should address.

Can the front desk and patients use the same router?

Yes, if they're on separate networks that can't reach each other. Many routers offer one guest network. Check that it truly blocks guests from your other devices, and consider separate networks for clinical machines and for gadgets like TVs and card readers.

I see patients by telehealth from home. What should I change?

Give your work laptop its own network, away from the family's consoles, tablets and smart gadgets. Keep it updated, use multi-factor login, and follow your practice's and EHR vendor's rules for remote access. Ask your HIPAA advisor if you're unsure which rules apply to you.

Sources

  1. FBI Internet Crime Complaint Center, 2025 Internet Crime Report. ic3.gov (PDF)
  2. 45 CFR 164.308, Administrative safeguards (risk analysis). ecfr.gov
  3. HHS Office for Civil Rights, settlement with Comprehensive Neurology, PC, April 2025. hhs.gov
  4. HHS 405(d), Technical Volume 1: Cybersecurity Practices for Small Healthcare Organizations, 2023 edition. 405d.hhs.gov (PDF)
  5. HHS, HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (proposed rule), Federal Register, January 6, 2025. federalregister.gov
  6. McDermott, Final action on HIPAA Security Rule modifications now projected for July 2027, July 16, 2026. mcdermottlaw.com
  7. Federal Trade Commission, How To Secure Your Home Wi-Fi Network. ftc.gov
Share: Twitter Facebook LinkedIn Email