All terms
Network zones

DMZ

A demilitarized zone — a buffer network between the trusted internal (clinical) network and untrusted external networks, hosting systems that must be reachable from outside.

When to use it

Route traffic through a DMZ whenever data crosses the organization's boundary — external partners, cloud services, or internet-facing endpoints.

In plain terms

It is the building's reception area: outsiders can reach it, but they cannot walk straight into the back offices.

Common gotchas

  • Systems in the DMZ should hold no more data than necessary; treat it as semi-trusted.
  • Every hop in and out of the DMZ is a firewall rule someone has to own and document.
  • A relay or proxy in the DMZ often terminates and re-initiates connections, so it can appear as the source to internal systems.

Related