Every care organization has at least one device that nobody dares touch. It might be a monitor running an old version of Windows, an imaging workstation tied to a specific driver or a piece of lab equipment whose vendor stopped issuing updates years ago. It works, it is expensive to replace and it is also a security weak point.
When a device cannot be patched, you do not simply accept the risk and move on. You reduce it with compensating controls and make a plan. Here is how.
Medical and clinical systems face particular constraints:
Manufacturers may validate specific configurations, and changes can affect safety or support
Regulatory processes can slow updates
Devices may run for many years, long past the support life of their operating systems
Staff cannot take a device out of service easily
Some devices cannot run security software at all
The result is that devices often remain exposed long after their weaknesses become public.
You cannot manage what you do not see. Build an inventory of clinical and connected devices, including:
Make, model and serial number
Operating system and software version
Network connection type and address
Location and responsible department
Vendor support status
Whether it stores or transmits resident information
Network discovery tools can help find connected devices, but a walk-through with clinical engineering or nursing leaders will catch devices that rarely connect.
Contact the vendor and ask what security updates are available, what the support end date is and what configuration they recommend. Many manufacturers publish security guidance, and some devices can accept updates that your team was not aware of. Document the response. Ask for a Manufacturer Disclosure Statement for Medical Device Security (MDS2), a standard form many vendors provide that describes a device's security features.
The most effective compensating control is network segmentation:
Place devices on a separate network segment from computers used for email and browsing
Allow only the specific connections the device needs, such as to its server or the vendor's service
Block internet access unless it is essential, and then limit it to specific destinations
Prevent devices from talking to one another unless needed
If a device is compromised, segmentation limits how far an attacker can go.
Disable unused services, ports and accounts
Change default passwords, and store the new ones securely
Remove USB access or restrict it to approved media
Lock down remote support: require the vendor to connect through a controlled, logged and time-limited method rather than a permanent connection
Physically secure the device where practical
Devices that cannot defend themselves need others to watch for them. Use network monitoring to detect unusual traffic, such as a pump suddenly communicating with the internet. Alert on attempts to connect from unexpected systems. Keep logs, so you can investigate if something happens.
If the device holds configuration or data, back it up and test restoring it. Know what clinical staff will do if the device goes down, including manual alternatives. Include these devices in your downtime and emergency procedures.
Compensating controls are a bridge, not a destination. Add devices to a replacement schedule based on risk and clinical importance. When buying new equipment, include security in the evaluation: ask about patching policy, support life, encryption, authentication and remote access before purchasing.
HIPAA requires you to assess risks to electronic PHI and manage them to a reasonable and appropriate level. For each unpatchable device, record the risk, the controls you applied and the replacement plan. This gives you a defensible position and a clear view of your remaining exposure.
Clinical and biomedical staff understand the device's role and how it is used. Any change should be coordinated with them. Safety comes first, and no security change should be made without confirming it will not affect patient or resident care.
Inventory completed and kept current
Vendor support and security documentation obtained
Device isolated on its own segment
Internet access blocked or restricted
Default passwords changed
Vendor remote access controlled
Monitoring in place
Downtime procedure written
Replacement planned and budgeted
We help healthcare organizations find connected devices, design network segments for them and set up monitoring. If you are unsure how many such devices you have, a discovery scan and walk-through is a practical starting point.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034