
Company: Norsk Helsenett SF
Headquarters: Trondheim, Norway
Industry: Healthcare IT
Challenges:
- Complex configuration, operation, and maintenance of FortiClient VPN and Always On VPN (Microsoft RRAS).
- Limited cross-platform client support.
- Growing list of known vulnerabilities in IPsec and SSL VPN implementations, with large codebases expanding the attack surface.
- No flexible way to rapidly provision secure access, whether for third parties or in crisis scenarios.
- Poor alignment with modern authentication through Identity Providers (IdPs).
Key Results:
- Smaller attack surface, with WireGuard's minimal codebase and no services exposed directly to the internet.
- Identity-based access control with IdP integration and policy-based segmentation.
- Lower operational complexity and a more stable, performant connection experience for users.
- Rapid, secure provisioning for external partners and emergency scenarios.
Technologies Used: WireGuard, IdP integration, Windows, macOS, Linux, and mobile clients
About Norsk Helsenett
Norsk Helsenett SF is the national service provider for e-health in Norway. A state enterprise under the Ministry of Health and Care Services, it is responsible for the secure infrastructure that connects the country's health and care services, and for operating national e-health solutions on the ministry's behalf.
That mandate gives Norsk Helsenett a key role in Norway's healthcare digitalization efforts, where secure and efficient electronic interaction across the health and care services is not a convenience but a requirement.
The Challenge: Legacy VPNs in a Zero-Tolerance Environment
Few organizations face stricter connectivity requirements than a national e-health provider. Norsk Helsenett protects sensitive healthcare data and critical infrastructure, which means minimizing exposure to the public internet, encrypting all communication between stakeholders, and maintaining strong authentication and traceability. On top of that, the organization must provide secure access to external actors such as suppliers, developers, and partners, and remain available and robust even in crisis situations.
The existing VPN stack was not built for this. Norsk Helsenett relied on FortiClient VPN and Always On VPN (Microsoft RRAS), and both presented persistent problems. Cross-platform support was limited, and configuration, operation, and maintenance were complex and time-consuming.
Security was a concern of its own. Traditional VPN technologies, particularly SSL VPN, carry large and complex codebases with a broad surface to defend, and the number of known vulnerabilities in both IPsec and SSL VPN implementations keeps growing.
Finally, the legacy solutions lacked flexibility where Norsk Helsenett needed it most: rapid provisioning for third parties and crisis scenarios, and integration with modern authentication through Identity Providers.
The Solution: WireGuard-Based Connectivity, Delivered Through NetBird
Norsk Helsenett chose NetBird, built on the WireGuard protocol. WireGuard's modern, minimalistic codebase was the deciding factor: far less code means far less to attack, and its open source code provides the transparency needed for security auditing. Strong performance and simple configuration came as part of the package.
NetBird turns that protocol into a manageable platform. Cross-platform clients cover Windows, macOS, Linux, and mobile devices, closing the coverage gaps of the previous stack. Integration with Identity Providers brings authentication in line with the organization's access management strategy, while centralized management and policy-based access control enable identity-based segmentation across the network.
Crucially, services no longer need to be exposed directly to the internet to be reachable: encrypted, peer-to-peer connections replace open endpoints.
The Results: Stronger Security, Simpler Operations
The move to NetBird delivered on the two fronts that mattered most: security and operability.
The attack surface shrank and authentication now runs through modern identity solutions, strengthening access control. Day-to-day management and maintenance are simpler than with the previous VPN solutions, and users experience more stable, performant connections.
The flexibility gains are just as important for Norsk Helsenett's mission. Secure access for external collaborators is now easy to provision, and connectivity can be deployed rapidly in emergencies. Across all platforms, the organization has a more standardized and scalable approach to secure network access.
Conclusion
With NetBird, Norsk Helsenett has modernized network access for one of the most demanding environments imaginable: national healthcare infrastructure. Security is stronger, administration is simpler, and access provisioning is flexible enough to cover everything from daily operations to crisis response.
That foundation positions Norsk Helsenett to meet future requirements in the e-health sector, particularly in enabling collaboration with external stakeholders, while maintaining the level of security that critical infrastructure demands.
