Scenario: connecting an MVZ's locations
Scenario: a typical case, worked through the way I would approach it. Not a client project; names and figures are examples.
An MVZ, a German medical care centre, has grown to three locations through acquisitions, and each location brought its own IT. This is how I would bring the three into one secure network, with central services, monitoring for everything and an emergency plan that gets practised.
Starting point
The MVZ has three locations with around forty workstations between them. The practice software runs on a server at the main site, and the other two reach it through a remote support tool. Each location has its own router, its own file share and its own habits. Updates are installed by whoever has time. Each site is connected to the telematics infrastructure, looked after by the TI provider.
What is at stake
Nobody has an overview of which devices exist and how up to date they are. One unpatched PC at one site is a way in for all of them, because the remote support tool already links the sites. If the internet line at the main site fails, the practice software stops for all three locations. And under the revised KBV IT security guideline, an MVZ of this size falls under the more extensive requirements, which are hard to prove without documentation.
Approach
1. Inventory at every site
I record devices, programs, accounts and lines at each location and note who is responsible for what. The result is a list of risks sorted by urgency, and a picture of what should run centrally and what locally.
2. Target network
The sites are linked by a permanent VPN between the routers, so the remote support tool is no longer needed for that. Each location gets separate networks for practice PCs, medical devices, phones and guests. User accounts are managed centrally, so a change in the team is entered once and applies at every site. Each location gets a mobile backup line, which the router switches to by itself.
3. Central services and backups
File storage, user management and backups run centrally. The backup follows the 3-2-1 rule with an immutable off-site copy, as described in the backup scenario. The practice software stays in the vendor's care. I agree with the vendor how the server and the backup work together.
4. Monitoring and updates
All devices report to central monitoring whether they are running, how full their disks are and which updates are missing. Updates are rolled out centrally, first to a small test group and then to everyone. Lines, VPN and backups appear on the same overview.
5. Switching over site by site
The switch happens one site at a time and outside consulting hours, so on any given day two locations carry on untouched.
- PrepareDevices preconfigured, accounts created, the way back planned.
- Smallest siteeveningNew router, new networks, connected to the VPN.
- CheckOne consulting day on the new network, feedback worked in.
- Second siteeveningWith what the first one taught us.
- Main siteweekendLast, because the practice software runs here.
6. Documentation and emergency plan
At the end there is a network plan, a list of all devices and accounts, and an emergency plan for each location. The plan says what the team on site can check themselves and whom to call. Once a year we walk through an outage, for example of the line at the main site.
The result I would aim for
- All three locations work in one network, with the same rules and no remote support tool between the sites.
- If a line fails, the site keeps working over mobile.
- Updates and backups run centrally and can be seen on one overview.
- For the IT security guideline there is documentation that shows where things stand.
What it takes
The MVZ needs one contact person per site and evenings or a weekend when the switch may happen. Decisions are needed on which services run centrally and who handles the day to day afterwards. Costs come from new routers, mobile contracts for the backup lines, possibly a central server, and the time for planning and the switch. We work out the exact scope in the first call.
Related services
Several locations, one IT?
In a free first call we look at how your locations are connected today and what a sensible first step would be.