Healthcare Example: Security Service Edge
The healthcare ecosystem is complex and vast. It is made up of different types of organisations delivering or supporting different services across thousands of sites and an extensive supplier base. These services rely on digital information that crosses physical and organisational boundaries.
At the same time as supporting legacy systems and applications tied to expensive medical equipment, and modern cloud-delivered applications, IT teams must also enable the safe adoption of new technologies and ways of working.
Alongside the changing technology and political landscape, IT teams are acutely aware of the cyber threat that is prominent in healthcare, and the severe impact of data breaches and service outages.
Prisma Access is a cloud-delivered security edge that helps to tackle some of these challenges with common security controls and data protection across a range of access methods.
This post will walk through three simple sections: Connect, Protect, Reveal, demonstrating how the platform provides secure access to clinicians wherever they deliver patient care.
Connect
Prisma Access replaces the traditional method of backhauling all traffic to a physical location (like a data centre firewall). Users and sites connect into Prisma Access where traffic is inspected and controlled according to policy.
In industry language Prisma Access is a Security Service Edge (SSE). It can be combined with native SD-WAN to form a Secure Access Service Edge (SASE).
An SSE or SASE architecture means security enforcement moves closer to the natural traffic path, especially for internet and SaaS applications, improving user experience and reducing reliance on data centres and physical hardware.
There are several ways to connect network traffic into the Prisma Access enforcement fabric depending on the requirements of the organisation and user role.
Managed devices, including shared workstations, can use agent-based connectivity, ensuring corporate users are fully protected from any location. Mobile devices such as kiosk or vehicle-mounted tablets can also use the mobile app.
Prisma Browser supports multiple use cases for both managed and unmanaged devices. Since it doesn't require admin rights to install, or any control over the end device, it is well suited to connecting agency or locum staff, social care workers, and third parties.
Site-based connectivity captures all traffic from fixed sites, including headless devices and public WiFi. Prisma Access supports high-bandwidth interconnects, natively integrating with Internet Service Providers (ISPs) and Consumer Network Service Providers (CNSPs).
Traffic ingresses the platform through any of the examples outlined, is inspected according to policy, and then egresses to its destination. Internet and SaaS traffic exits directly from the enforcement fabric. Private clinical applications hosted in a data centre or cloud environment are reached through either a Service Connection, providing a network-centric path, or a Zero Trust Network Access (ZTNA) Connector, which initiates an outbound, application-centric connection, with no inbound firewall rules required.
Identity underpins every access decision, and is integrated directly into the platform. Directory sync and authentication with the existing Identity Provider (IdP), such as Microsoft Entra ID, facilitates identity-based policies and conditional access.
Security policy can be written for people and roles, scoped to the applications they need to access, rather than IP addresses or segments of the corporate network. Combined with application classification, device posture, and session context, Zero Trust principles can be enforced in practice, and at scale. This is important for remote users, and in environments where staff move between sites, wards, and shared devices throughout a shift.
In all connectivity scenarios, a clinician working from a ward, community clinic, or home is subject to the same policy and inspection, without the organisation maintaining separate controls for each scenario.


Protect
Traffic is inspected using Cloud-Delivered Security Services, providing threat prevention, malware and zero-day prevention, data protection, URL filtering, and DNS security.
Traffic is decrypted once and evaluated against every enabled security control in a single pass. Policy-based decryption improves visibility whilst preserving privacy where categories such as health and personal finance are excluded.
Inspection continues throughout the session rather than stopping at the point of connection. Identity, device posture, and context are evaluated for every application request, and re-evaluated if conditions change mid-session. This addresses a common challenge in healthcare, where legacy VPNs and access to flat networks often mean an identity compromise exposes a larger attack surface than is necessary.
Capabilities delivered by the same platform, with consistent policy and operations, include:
- Secure Web Gateway (SWG): works together with Firewall as a Service (FWaaS) to protect all users and traffic from malicious content, phishing attempts, credential theft, and ransomware delivery
- Zero Trust Network Access (ZTNA): provides secure remote access to the specific resources users or third parties need to support patient care
- Cloud Access Security Broker (CASB): controls how corporate and patient data is accessed or shared across organisational boundaries, with Data Loss Prevention (DLP) applied throughout
- AI Access Security: enables the safe adoption of Generative AI and prevents shadow AI and data leakage in prompts or other AI access patterns
- Secure SD-WAN Branch Transformation: optimises branch security and performance across hospitals and smaller community hubs or vaccination centres
- Secure Enterprise Browser: applies last-mile inspection and data controls within the browser session itself, on both managed and unmanaged devices
Applied to a healthcare estate, this looks like:
- Preventing ransomware reaching a community site or GP clinic that has no local security stack
- Preventing a clinician entering their corporate credentials into a phishing page impersonating a trust login portal
- Blocking Command-and-Control (C2) callbacks from a compromised device before the attack escalates
- Providing medical device vendor support with access to the specific equipment they need to maintain, rather than a route onto the corporate network
- Inspecting traffic from home-working clinicians or overseas radiologists without backhauling it through the hospital data centre
- Preventing patient data being sent to unsanctioned applications and services, such as personal cloud storage, WhatsApp, or ChatGPT


Reveal
Threat information and telemetry from every user, site, and application are normalised into a common data model, providing context-based insights across data that was traditionally siloed with different tools. Data residency and processing occur within a defined geographic region, such as the UK.
Security insights are surfaced continuously and in real time with Strata Cloud Manager (SCM). Threats blocked, policy violations, risky or suspicious user behaviour, and unsanctioned applications are all visible against the identity and device used.
Across a healthcare estate, this supports:
- Easily identifying which users, sites, or devices are generating the most blocked threats, and whether that indicates a compromise or training gap
- Understanding shadow IT and unsanctioned SaaS or AI use across clinical and corporate teams, including the movement of patient data
- Tracking third-party and supplier access against the specific systems they are entitled to reach and data they can view
- Uncovering configuration drift, gaps, and overly permissive policies before they become findings in an audit or an incident
- Evidencing what was accessed, by whom, and when, for clinical safety and information governance obligations
- Applying threat intelligence and context from one organisation across the wider healthcare ecosystem, when using a multi-tenant architecture
With policy, enforcement, and telemetry combined, visibility extends to user experience. Autonomous Digital Experience Management (ADEM) correlates endpoint signals, network metrics, enforcement telemetry, and application performance into a single view, with a health score and suggested root cause. When a clinician reports that connectivity is slow, the answer comes from one place.


In summary, Prisma Access applies consistent security controls and data protection across every access method throughout a distributed estate. The burden on local IT teams is consolidated into a single operating model and platform, and security posture is strengthened, reducing both the likelihood and the blast radius of an incident.
If you want to read more about this topic, and how some of the concepts discussed here work, you can also check out Prisma Access Introduction and Prisma Access Distributed Enforcement Architecture.