Some of the most embarrassing IT outages have a simple cause: something expired. A website suddenly shows a security warning, email stops flowing, a phone system cannot register, or staff cannot reach a clinical application because a certificate ran out overnight. Nothing was hacked and nothing broke, but a date passed and nobody was watching.
Expirations are among the easiest problems to prevent. All it takes is a list, an owner and reminders.
Your domain registration, the right to use a name like yourfacility.org, is leased for a period, often one to ten years. If it lapses, your website and email can stop working, and someone else may register the name. The risk is real, and the consequences, such as lost email and phishing misuse of your brand, can be serious.
Certificates prove that a website or service is genuine and enable encrypted connections. They have limited lifetimes, and the industry has been moving toward shorter ones. When a certificate expires, browsers and applications warn users or refuse to connect.
Certificates are used for public websites, patient or family portals, remote access gateways, email servers, VPNs, wireless authentication and internal applications.
Software subscriptions and support contracts
Security feature licenses on firewalls and other devices
Warranty and maintenance agreements
Cloud service plans
Code-signing certificates and API keys
Password and service account expirations used by applications
Email authentication records and the keys behind them, which may be rotated periodically
The person who bought the item left the organization.
Renewal notices go to a former employee's mailbox or a spam folder.
Auto-renew fails because a payment card expired.
Certificates are installed in several places and one is forgotten.
No one is clearly responsible.
List every domain and certificate your organization depends on. Include:
The name or purpose
Where it is registered or issued
The expiration date
Where it is installed or used
Who is the owner, and who is the backup
How it is renewed, and whether renewal is automatic
The account and payment method tied to it
Check your domain registrar account, ask IT staff and vendors, and scan your known websites and services for certificate dates. Some tools can examine your public hostnames and report expiration, which also helps you find forgotten ones.
Register domains in the organization's name, not an employee's or a web developer's.
Use a role-based email address, such as a shared IT mailbox, for renewal notices, so messages survive staff changes.
Keep two administrators on registrar and certificate accounts.
Use a company payment method, and track its expiration date as well.
Enable registrar locks and multi-factor authentication to prevent unauthorized transfers.
Turn on auto-renewal for domains, and confirm that the payment method is valid.
Use certificate issuance and renewal automation if your systems support it. Automated renewal substantially reduces the chance of human error.
For certificates that cannot be automated, schedule specific renewal tasks.
Automation is not a substitute for monitoring, since renewals can still fail. Verify that new certificates are actually in place after a renewal.
Create calendar reminders at 90, 60, 30 and 7 days before each date.
Use a monitoring tool to alert when a public certificate is within a set number of days of expiring.
Review the list in a short monthly or quarterly meeting.
Escalate to a named manager if a renewal has not happened by a set date, such as 14 days before expiration.
Write a short procedure for each important certificate, since renewal often requires generating a request, installing the new file and restarting a service. Test it in a quiet period. Document who does what, so that renewal does not depend on one person's memory.
If something does expire, treat it as a lesson. Restore service, then identify why alerts failed, update the inventory and add monitoring.
Care organizations depend on connected systems, including pharmacy, labs, electronic records, family portals and remote access. An expired certificate can interrupt several of these at once, and downtime in a care setting affects residents and staff directly.
UnityCare IT tracks domains, certificates and renewal dates as part of managed IT service so that the calendar, not an outage, drives renewals. If you do not have a list today, even a simple spreadsheet is a strong first step.
An outsourced IT department with proactive maintenance and one number to call.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172