Medical Devices That Cannot Be Patched: Compensating Controls

Every care organization has at least one device that nobody dares touch. It might be a monitor running an old version of Windows, an imaging workstation tied to a specific driver or a piece of lab equipment whose vendor stopped issuing updates years ago. It works, it is expensive to replace and it is also a security weak point.

When a device cannot be patched, you do not simply accept the risk and move on. You reduce it with compensating controls and make a plan. Here is how.

Why these devices are different

Medical and clinical systems face particular constraints:

Manufacturers may validate specific configurations, and changes can affect safety or support

Regulatory processes can slow updates

Devices may run for many years, long past the support life of their operating systems

Staff cannot take a device out of service easily

Some devices cannot run security software at all

The result is that devices often remain exposed long after their weaknesses become public.

Step 1: Find them

You cannot manage what you do not see. Build an inventory of clinical and connected devices, including:

Make, model and serial number

Operating system and software version

Network connection type and address

Location and responsible department

Vendor support status

Whether it stores or transmits resident information

Network discovery tools can help find connected devices, but a walk-through with clinical engineering or nursing leaders will catch devices that rarely connect.

Step 2: Ask the manufacturer

Contact the vendor and ask what security updates are available, what the support end date is and what configuration they recommend. Many manufacturers publish security guidance, and some devices can accept updates that your team was not aware of. Document the response. Ask for a Manufacturer Disclosure Statement for Medical Device Security (MDS2), a standard form many vendors provide that describes a device's security features.

Step 3: Isolate

The most effective compensating control is network segmentation:

Place devices on a separate network segment from computers used for email and browsing

Allow only the specific connections the device needs, such as to its server or the vendor's service

Block internet access unless it is essential, and then limit it to specific destinations

Prevent devices from talking to one another unless needed

If a device is compromised, segmentation limits how far an attacker can go.

Step 4: Reduce exposure

Disable unused services, ports and accounts

Change default passwords, and store the new ones securely

Remove USB access or restrict it to approved media

Lock down remote support: require the vendor to connect through a controlled, logged and time-limited method rather than a permanent connection

Physically secure the device where practical

Step 5: Monitor

Devices that cannot defend themselves need others to watch for them. Use network monitoring to detect unusual traffic, such as a pump suddenly communicating with the internet. Alert on attempts to connect from unexpected systems. Keep logs, so you can investigate if something happens.

Step 6: Back up and plan for failure

If the device holds configuration or data, back it up and test restoring it. Know what clinical staff will do if the device goes down, including manual alternatives. Include these devices in your downtime and emergency procedures.

Step 7: Plan replacement

Compensating controls are a bridge, not a destination. Add devices to a replacement schedule based on risk and clinical importance. When buying new equipment, include security in the evaluation: ask about patching policy, support life, encryption, authentication and remote access before purchasing.

Document in your risk analysis

HIPAA requires you to assess risks to electronic PHI and manage them to a reasonable and appropriate level. For each unpatchable device, record the risk, the controls you applied and the replacement plan. This gives you a defensible position and a clear view of your remaining exposure.

Involve clinical leaders

Clinical and biomedical staff understand the device's role and how it is used. Any change should be coordinated with them. Safety comes first, and no security change should be made without confirming it will not affect patient or resident care.

Quick checklist

Inventory completed and kept current

Vendor support and security documentation obtained

Device isolated on its own segment

Internet access blocked or restricted

Default passwords changed

Vendor remote access controlled

Monitoring in place

Downtime procedure written

Replacement planned and budgeted

How UnityCare IT can help

We help healthcare organizations find connected devices, design network segments for them and set up monitoring. If you are unsure how many such devices you have, a discovery scan and walk-through is a practical starting point.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034