Long-term care / healthcare
Secure networking and Microsoft 365 with strict data protection for a care home
- Client
- Chronus Equity sp. z o.o.
- Location
- Zebrzydowice, Silesia, Poland
Client and context
Chronus Equity sp. z o.o. operates Cudowny Poranek — a private, round-the-clock residential care home in Zebrzydowice, Silesia. The facility combines residential care with a therapeutic programme: rehabilitation, occupational therapy and salt-cave halotherapy.
A care facility places demands on IT infrastructure that a typical office never sees: resident records contain special-category data under GDPR, staff work in shifts on shared devices, and residents, families and visitors move through the building — each group needing a different level of network access.
The challenge
Before the project the facility ran a single flat network with no traffic separation — administration computers, staff devices, CCTV and guest WiFi shared one address space. Resident records and correspondence flowed through scattered mailboxes with no central access policies.
The goal was an environment where residents' medical and care data is accessible only to authorised staff, from managed devices and predictable locations — without slowing down the daily work of the care team.
Networking: Ubiquiti UniFi with full VLAN segmentation
We designed and built the LAN and WiFi network from the ground up on the Ubiquiti UniFi stack — from the gateway and switches to access points covering the building and grounds.
Traffic was split into isolated VLAN segments: administration and records, care staff, CCTV, technical devices, and a guest network for residents and visitors. Firewall rules between segments restrict communication to the necessary minimum, and the guest network is fully isolated from facility resources.
The staff network uses WPA2-Enterprise authentication tied to employee identity — leaving the team means losing network access automatically, with no shared passwords to rotate.
Microsoft 365 with strict Conditional Access
Email and collaboration moved to Microsoft 365 with Exchange Online. Team identity is managed centrally in Entra ID, and access to facility data is governed by Conditional Access policies tailored to working with resident records.
Access to resources containing care documentation requires multi-factor authentication and a compliant, Intune-managed device. Privileged accounts carry additional restrictions, and sign-ins from unusual locations are blocked.
Facility devices — duty-room computers and administration workstations — are managed by Intune with enforced disk encryption, compliance policies and remote wipe.
DLP: protecting resident data
Data about care-home residents is special-category data — a leak carries consequences far beyond those of a typical business. We deployed Microsoft Purview DLP policies that recognise personal and medical data in messages and documents.
Attempts to send documentation outside the organisation, or share it with unauthorised recipients, are blocked or require an explicit, justified override — and every such event lands in the audit log. The policies work in the background without changing the team's daily habits.
Results
- Full traffic separation: records, staff, CCTV and guests in isolated VLAN segments
- Resident documentation accessible only from managed devices, after MFA
- DLP policies protecting special-category data in line with GDPR
- WiFi covering the building and grounds with a secure guest network
- Central identity and device management — staff onboarding and offboarding in minutes
Technology stack
Running a medical or care facility? Let's talk about the security of your data.
Book a consultation