Why guest Wi-Fi is not the clinical network
Patients should check email. They should not see the DEXIS archive. That is one VLAN sentence.
Journal · Chairside Manners · D·06 | Last reviewed: October 1, 2026 | 3 min read | By CyberDental Group LLC, Hialeah, Florida
Short answer: Guest Wi-Fi must be a separate network from the clinical network, isolated at the firewall so guest devices can reach the internet and nothing else. Without separation, any patient phone or compromised device sits one hop from your imaging and practice-management data. The fix is VLANs, client isolation and distinct SSIDs for staff, clinical devices and guests.
At a glance
| Principle | Guests reach the internet only |
| How | Separate VLANs and SSIDs with firewall rules |
| Also separate | Staff BYOD, IoT devices, TVs, cameras |
| Never | Put clinical devices on the guest network or share one Wi-Fi password |
| Benefit | Limits blast radius of any compromised device |
Why can't patients use the same network as the practice?
Because devices on the same network can talk to each other by default. A patient's phone, a visitor's laptop or a smart TV that has been compromised is then one hop away from the server holding your imaging archive and practice-management database. Segmentation removes that adjacency. The sentence to remember: guests can reach the internet and nothing else.
What does a proper layout look like?
| Network | Who/what uses it | Can reach |
|---|---|---|
| Clinical | Workstations, sensor PCs, server, printers | Internal systems; controlled internet access |
| Staff / business | Front-desk and office computers, staff phones if allowed | Needed internal systems; internet |
| Guest | Patients, visitors | Internet only |
| IoT / media | TVs, cameras, music, thermostats | Internet as needed; no clinical access |
Each is a separate VLAN with its own SSID (for Wi-Fi), and the firewall enforces what can talk to what. See A glossary of the house for VLAN.
What are the key settings?
- Client isolation on the guest network, so guest devices cannot see each other either.
- Firewall rules that block guest and IoT traffic to clinical and staff networks.
- A different password for guest Wi-Fi, changed periodically, or a captive portal.
- Bandwidth limits on guest traffic so a patient streaming video cannot starve imaging.
- Wired where it matters: sensor PCs and servers on cable, not Wi-Fi. See How dental imaging networks actually fail.
What about staff using their own phones?
Bring-your-own-device is a policy question. Staff phones should join the staff or guest network according to policy, not the clinical network. If staff access email or PHI on a personal device, it should be managed and protected with MFA. See Microsoft 365 for dental practices.
What are the common mistakes?
- One Wi-Fi network for everyone, with the password on a sign at the front desk.
- A consumer router plugged into the clinical network "for the waiting room."
- Smart TVs and cameras on the same network as workstations.
- A guest network that is separate in name but not in the firewall rules.
Is this a HIPAA matter?
Yes. Network segmentation is a standard safeguard to limit unauthorized access to ePHI, and the proposed Security Rule update would make it explicit; see NPP 2026 vs the Security Rule NPRM. Even under the current rule, an assessment of risk that ignores an open network is difficult to defend.
Frequently asked questions
Should patients be on the same Wi-Fi as my practice computers?
No. Guest Wi-Fi should be a separate, isolated network that reaches only the internet.
What is a VLAN in a dental office?
A VLAN logically separates a network into segments, such as clinical, staff and guest, so devices on one segment cannot automatically reach devices on another.
Can imaging sensors run over Wi-Fi?
Wired connections are strongly preferred for sensor PCs and servers. Wi-Fi adds variability that causes intermittent imaging failures.
Sources and further reading
- NIST SP 800-66 Rev. 2: Implementing the HIPAA Security Rule
- HHS 405(d): Health Industry Cybersecurity Practices
Related in the Journal
- How dental imaging networks actually fail
- Florida de-novo IT build-out checklist
- NPP 2026 vs the Security Rule NPRM — two different clocks
- A glossary of the house
About CyberDental
CyberDental Group LLC is a dental-exclusive managed IT and cybersecurity provider headquartered in Hialeah, Florida. Founded in 2016 by Mr. Dimitri Lopez, it supports 1,000+ licensed dental practices, has completed 250+ dental office IT build-outs, and operates a dental-only HelpDesk. Plans are priced per location: Remote $350/month, Priority $650/month, Ultimate $1,200/month; Concierge is quoted for multi-location groups and DSOs. CyberDental signs a Business Associate Agreement (BAA) with every practice it serves.
- HelpDesk: (954) 639-7049
- Email: support@cyberdental.co
- Address: 480 W 84th Street, Suite B106, Hialeah, FL 33014
- Website: cyberdentalgroup.com