Case Study · St. Luke’s Health
Fully segmented in 46 days across 15 hospitals & 85,000 devices with
zero new hardware
St. Luke’s spent years unable to safely segment its network without disrupting patient care. With Elisity, they achieved full Zero Trust segmentation across all 15 hospitals and 85,000 devices in just 46 days with no downtime, a level of speed and protection modern healthcare requires. Watch how they did it in the full 2 minute case study below.
Average Time to Exploit Is Shrinking Dramatically
2022
3
0 1 2 3
0
0 1 2 3 4 5 6 7 8 9 0
Now
01
01
Attackers can weaponize a vulnerability in about a day. As time to exploit shrinks, healthcare systems still take weeks to patch.
AI has compressed the average time to exploit vulnerabilities from 30 days to less than one day. Meanwhile, the median patch cycle remains nearly 70 days. As regulators move to require network segmentation under the HIPAA Security Rule, St. Luke’s implemented segmentation in just 46 days.
Healthcare’s exposure gap is real.
St. Luke’s lived it firsthand.
For years, St. Luke’s couldn’t safely segment its network, and every failed attempt meant saying no to clinical teams. The cost of getting it wrong wasn’t a security incident, it was a compromise to patient safety. Meanwhile HIPAA pressure kept building, and the business kept waiting on technology the IT and security teams couldn’t safely turn on.
Spanning 15 hospitals, 350 physician practices, 1,800 vendors, and roughly 75 square miles, St. Luke’s had outgrown legacy segmentation. Every segmented device required an IP change, static clinical equipment demanded vendor coordination, and manual VLAN administration could not keep up.
The Results
15 hospitals
Secured
85,000
Devices protected
350+
Physician practices
2 weeks
Ahead of schedule
23,000+
Users protected
$0
No new hardware
Identity-based microsegmentation, not VLANs, firewalls, or NAC. The approach that finally worked where the team couldn’t patch or re-IP thousands of clinical devices.
Ransomware blast radius dropped from organization-wide to a single device
Deployed on existing infrastructure. No agents installed, no new hardware purchased.
Security team approved previously blocked robotic surgical systems allowing providers 3,000 miles away to join live procedures.
“Within 46 days, we went from no microsegmentation to having all of our microsegmentation completed.”
Dan Dopsovic
Network Architect, St. Luke’s University Health Network
“I spent the last 5 years trying to architect how to microsegment my environment. [With Elisity] It only took me two months.”
David Finkelstein
CISO, St. Luke’s University Health Network
Zero Trust Posture: Self-Assessment
How Exposed Is Your Network?
Measure your Zero Trust Maturity across Access Control, Transmission Security, and Network Segmentation, in just 30 seconds.
Your responses are scored against the CISA Zero Trust Maturity Model and mapped to the corresponding HIPAA Security Rule safeguards, using the same approach that supported St. Luke’s 46-day deployment.
- 30 seconds, 3 questions, no email required to see your score
- Scored on the CISA Zero Trust Maturity Model
- Mapped to the HIPAA Security Rule safeguards – including the new segmentation control in the proposed 2026 update
Zero Trust Posture
Self-assessment
out of 100
Zero Trust Maturity Score
Unknown
Answer 3 questions to estimate your score across Elisity's three scoring factors.
Score Factors
Access Control
§ 164.312(a)
AC
Are access policies enforced at the network layer, not just the application?
Transmission Security
§ 164.312(e)
TS
Is ePHI encrypted in transit and isolated inside your network?
Network Segmentation
New Requirement)
NS
Are ePHI systems separated from general network traffic?
Your answers place each area on the four maturity stages of the CISA Zero Trust Maturity Model — Traditional, Initial, Advanced, Optimal. The three areas assessed map to technical safeguards in the HIPAA Security Rule: Access Control (§ 164.312(a)), Transmission Security (§ 164.312(e)), and the network segmentation control in the proposed 2025 update. The CISA model provides the maturity scale; the HIPAA safeguards provide the regulatory mapping. Each area is weighted equally.
1How do you control access to systems that handle patient data (ePHI)?
2How is ePHI protected in transit across your internal network?
3What best describes your current network segmentation approach?
out of 100
Access Control
§ 164.312(a)
AC
Transmission Security
§ 164.312(e)
TS
Network Segmentation
New Requirement
NS
Biggest Gap
This self-assessment provides an educational estimate based on your responses. It is not a compliance audit, legal advice, or a determination of HIPAA compliance. The 2025 HIPAA Security Rule update is a proposed rule and is not yet final. Consult your compliance and legal teams for a formal assessment.
Get a personalized analysis of your Zero Trust Maturity score
Analyze your score and dig deeper into the gap analysis, HIPAA Security Rule mapping, and gain a remediation roadmap, based on your answers.
Understand the Proposed 2025 HIPAA Security Rule Update and What It Means for You.
For the first time in two decades, HHS is proposing a major update to the HIPAA Security Rule. Explore the proposed rule, understand the new network segmentation requirement it introduces, and see what it could mean for your organization.
Powered by Claude. Answers may be inaccurate. Chats are stored and may be reviewed to improve the assistant. Please don’t share confidential information.
Healthcare Microsegmentation
FAQs
Common questions from healthcare security teams evaluating
microsegmentation. Answers reflect the approach St. Luke’s
and other hospital systems take with Elisity.
In phases, on the network you already have, with no agents and no new hardware. Classify each device by identity, simulate policy against live traffic to confirm nothing breaks, then enforce. St. Luke's did 15 hospitals and 85,000 devices in 46 days, without disrupting care.
Elisity secures them without touching the device: no agent, no patching, no IP changes. It classifies each device by identity and enforces least privilege policy on your existing infrastructure, so it can only reach what it needs. If one is ever compromised, the policy contains it. St. Luke's cut ransomware blast radius to a few devices.
On a flat network, one compromised device can reach almost everything, so ransomware spreads sideways across the hospital. Microsegmentation confines each device to only the connections it needs, so an infection has nowhere to go. At St. Luke's, that took ransomware blast radius from "could take down the organization" to a few devices.
No. Elisity runs on your existing infrastructure with no agents and no IP changes, so there is nothing to install on clinical devices and no maintenance window to schedule. Every policy is simulated against live traffic before it is enforced, so nothing goes live until you have confirmed it won't interrupt care. St. Luke's segmented 15 hospitals and 85,000 devices without disrupting patient care.
Both frameworks focus on controlling access to ePHI and limiting how far a threat can spread. Identity-based microsegmentation enforces least privilege so only authorized systems can reach ePHI, which maps to the HIPAA access control and transmission security safeguards (45 CFR 164.312) and to network segmentation, a HICP recommended practice and the new control in the proposed 2025 HIPAA Security Rule update. It won't make you compliant on its own, but it is a concrete step toward both.
Faster than most teams expect, because it runs on infrastructure you already own with no agents and no new hardware. St. Luke's deployed across 15 hospitals and 85,000 devices in 46 days, two weeks ahead of schedule, after a decade of failed attempts with traditional approaches.
Schedule a Demo. See how fast Elisity can Segment Your Network.
Fill out the form and our team will follow up within 1 business day. Don’t let threats take you by surprise. Reclaim control of your network’s security posture with Elisity. Unlock enhanced threat detection and policy management capabilities to achieve cybersecurity objectives confidently.
See complete visibility across every IT, IoT, OT and IoMT device on your network, discovered and classified within hours of deployment
Walk through building identity-based microsegmentation policies in simulation mode before a single rule is enforced in your environment
Discover how your team can go from planning to active policy enforcement in days, using your existing network infrastructure
2000 +
Avg Policies Enforced
10000 +
Avg Devices Protected
2
Avg Days to Deploy
