Walk through almost any nursing home, clinic or assisted living community and you will find a mix of equipment: a few new laptops, some desktops that are five or six years old, and at least one machine nobody wants to touch because a specialized program only runs on it. Budgets for IT are limited, and replacing everything at once is rarely realistic. Still, those aging computers are where many attacks land.
This post covers how to protect older endpoints, how to prioritize replacement and what to do with systems that cannot be retired right away.
End of support. When a vendor stops issuing security updates for an operating system, newly discovered flaws stay open forever. Windows 10, for instance, is scheduled to reach end of support in October 2025, which makes planning relevant now.
Hardware limits. Older machines may not support modern security features such as secure boot, TPM-based encryption or current endpoint security software.
Performance. Slow computers encourage staff to work around controls, such as disabling antivirus or leaving screens unlocked.
Unpatched software. Browsers, PDF readers and other applications are often neglected on machines that nobody owns.
You cannot protect what you cannot see. Build an inventory that lists:
Device name, location and assigned user or unit
Operating system and version
Age, warranty status and hardware specifications
Whether it handles protected health information
Whether it has encryption and endpoint protection installed
The applications that depend on it
Remote management tools can gather most of this automatically. This inventory also supports your HIPAA risk analysis and device and media controls.
A simple three-bucket approach works well:
Bucket A, replace soon: Devices on unsupported operating systems, or too old to run current security tools, that connect to resident data or the internet
Bucket B, protect and plan: Supported but aging devices that still receive updates, scheduled into a multi-year refresh cycle
Bucket C, isolate: Systems that cannot be updated because of a dependency, such as software tied to a specific device or an old operating system
For machines remaining in service, apply layers.
Install modern endpoint detection and response software that monitors behavior, and keep it centrally managed
Enable full-disk encryption wherever hardware supports it
Remove local administrator rights from everyday users
Patch the operating system and every application on a defined schedule
Disable unneeded services, USB storage and legacy protocols
Use application allow-listing on fixed-purpose machines
Keep tested backups of data and configurations
When an unsupported system must stay, reduce exposure.
Place it on a separate network segment with a firewall that only allows the traffic it needs
Block direct internet access and email on that machine
Limit who can sign in, and require individual accounts
Monitor it closely for unusual activity
Document the business reason, the compensating controls and a target date for retirement
Documenting accepted risk with an owner and a review date is the kind of evidence that shows a regulator you are managing risk deliberately.
A rolling refresh spreads cost and avoids emergencies. Many organizations aim to replace a portion of devices each year based on age and role, with a typical business laptop life of roughly four to five years. Budget for it in advance, and consider leasing or device-as-a-service arrangements if capital is tight. Prioritize clinical workstations and anything exposed to email and web browsing.
A cheap old computer that crashes during medication administration costs staff time, delays care and increases support tickets. When you weigh replacement costs, include productivity, security risk and the support hours saved.
Which of our devices are on unsupported operating systems today?
Which devices lack encryption or endpoint protection?
Which have special-purpose software that blocks upgrades?
What is our replacement schedule and budget for the next three years?
Where have we accepted risk, and who signed off?
Start with the inventory, then fix the top ten riskiest devices. Progress on the worst cases reduces risk faster than a perfect plan that never launches.
UnityCare IT helps healthcare organizations inventory their devices, deploy managed endpoint protection and build practical refresh budgets. If aging computers are on your mind, we can help you sort out what to protect, isolate or replace.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034