Healthcare stopped being a building some time ago. Virtual consultations, community teams, hybrid administrative work and diagnostics delivered across sites have all moved clinical and patient data out of managed environments and onto networks nobody has assessed.
The systems are secured. The applications are secured. The connection from a district nurse’s temporary accommodation, or an administrator’s shared home broadband, is not.
That is the uncontrolled network edge, and it is one of the least examined gaps in both NHS and private healthcare security.
Most healthcare organisations encrypt data, secure applications and enforce multi-factor authentication. Very few have any visibility of the local network a user is sitting on.
The situations where that matters are entirely ordinary:
Every one of those involves special category data under UK GDPR, reached across a network with no security assurance behind it at all.
Healthcare remains one of the most targeted sectors, and the economics of attacking the edge have changed.
Exploitation of edge-device and VPN vulnerabilities rose from 3% to 22% of vulnerability-related breaches in a single year, according to the Verizon 2025 Data Breach Investigations Report. Scanning for exposed devices is cheap and automated, and the number of actors capable of running these attacks has grown accordingly.
The NCSC and ENISA have both issued guidance pointing at the same exposure: firmware integrity, secure remote access and the security of edge devices.
Encrypted-connectivity clients, commonly VPNs, are widely deployed in healthcare and they do a necessary job. They protect data in transit.
What they do not do is tell you anything about the network underneath. If the local network is compromised, traffic can be intercepted before the secure session is established, other devices on the same connection can be reached laterally, and DNS can be redirected. The encrypted connection is doing exactly what it was designed to do; it was simply never designed to secure the environment it starts from.
Loxada secures that environment. The two work together, and neither replaces the other.
Loxada replaces the unmanaged router at the point of connection with a Loxada secure router, and routes traffic through Loxada’s secure connectivity layer, an encrypted connection from the device out to the internet.
Each device:
There is no local setup and nothing for staff to manage.
Loxada suits a wide range of healthcare settings:
Remote administrative staff in hybrid patterns.
Community-based care teams and allied health professionals.
Diagnostics and imaging specialists working remotely.
Dental, therapy and mental health practitioners using shared facilities.
Clinical trials and research units operating across multiple locations.
Deployment is fully auditable, with monthly security reports and device-status visibility.
Loxada supports the technical controls expected under the frameworks healthcare organisations work to:
UK GDPR, which requires appropriate technical measures around access to special category data.
NHS Data Security and Protection Toolkit (DSPT), where remote working, device management and firmware currency are recurring areas of scrutiny.
NCSC and ENISA guidance on firmware integrity, secure remote access and edge device security.
Cyber insurance criteria, increasingly focused on how remote and home-based staff connect.
Procurement and assurance frameworks, which ask for documented controls rather than stated intentions.
Loxada supports one layer, the networks outside yoru control that your people connect from. It is a preventive control providing deployment coverage and configuration assurance, not monitoring, detection or containment, and it complements the identity, endpoint and encrypted-connectivity tooling around it.