It's a common setup in small practices: a single router, one Wi-Fi password, shared by reception PCs, practitioner laptops, and patients waiting for their appointment who ask for the Wi-Fi code. It's convenient, nobody has to remember two passwords, and it usually works fine for years without any visible problem.
It's also one of the more overlooked ways a practice's core systems end up reachable from a device the practice has no control over.
Why sharing a network is a risk
Devices on the same network segment can, in principle, see and in some cases reach each other. A patient's phone with malware they don't know about, a visitor's laptop that hasn't been updated in months, or simply someone with less than good intentions sitting in your waiting room with your Wi-Fi password, all end up on the same logical network as the PC running your practice management system, the shared drive holding patient files, and any networked printer or scanner handling referral letters.
Most of the time, nothing happens. That's exactly why the risk goes unnoticed for years. It only becomes a problem the one time it matters, and by then it's an incident, not a near miss.
What the guidance actually says
The Australian Cyber Security Centre's small business guidance is direct about this: as part of securing your router, businesses should turn on a separate guest Wi-Fi network for customers and visitors, alongside changing default passwords and using strong encryption (cyber.gov.au). This sits within the ACSC's broader network segmentation guidance, which describes dividing a network into separate zones so that if one part is compromised, the breach can't easily spread to the rest (cyber.gov.au). That guidance is written with larger organisations in mind, but the underlying principle scales down to a single-router practice just as well: keep the network patients and visitors use separate from the network your practice actually relies on.
What this looks like for a small practice
You don't need enterprise networking equipment to do this properly. Most business-grade routers and access points, and a good number of consumer ones, support a second network with client isolation, meaning guest devices can reach the internet but can't see or reach each other, or your practice's main network.
A reasonable setup looks like:
- A guest network for patients and visitors, isolated from the rest of the practice, with internet access only
- A separate practice network for reception PCs, practitioner devices, and anything with access to the practice management system or patient files
- Default router credentials changed from whatever the device shipped with
- WPA2 or WPA3 encryption with a genuine passphrase, not something written on a sign taped to the reception desk where every visitor can read it
- A defined, small list of people who know the practice network's actual password, separate from the guest one you're happy to hand out freely
Worth doing before you need it
This isn't a project that takes weeks. For most practices, setting up a properly isolated guest network is a same-day piece of work once the right access point or router is in place, and it removes one of the quieter ways an unrelated device ends up with a path to systems holding patient information. It pairs naturally with the endpoint management and email authentication work covered elsewhere on this site, all part of the same basic idea: know exactly what's connected to your systems, and keep what doesn't need to be there, out.
