All termsNetwork zones
DMZ
A demilitarized zone — a buffer network between the trusted internal (clinical) network and untrusted external networks, hosting systems that must be reachable from outside.
When to use it
Route traffic through a DMZ whenever data crosses the organization's boundary — external partners, cloud services, or internet-facing endpoints.
In plain terms
It is the building's reception area: outsiders can reach it, but they cannot walk straight into the back offices.
Common gotchas
- Systems in the DMZ should hold no more data than necessary; treat it as semi-trusted.
- Every hop in and out of the DMZ is a firewall rule someone has to own and document.
- A relay or proxy in the DMZ often terminates and re-initiates connections, so it can appear as the source to internal systems.