Every few weeks, your computers, phones, printers and network equipment ask for updates. Many of those updates fix security flaws, which are holes attackers actively try to use. Patch management is simply the discipline of applying those fixes promptly and safely, across every device and application you rely on.
It sounds routine, but in a care facility it is tricky. Systems run around the clock, staff cannot pause for a restart during med pass, and some equipment is old or tied to vendor-controlled software. Here is how to approach it so security and care both win.
When a software vendor publishes a fix for a flaw, the flaw becomes public knowledge. Attackers study those announcements and build tools to exploit systems that have not yet been updated. CISA maintains a catalog of known exploited vulnerabilities, which reflects flaws that are being used in real attacks. Many ransomware incidents begin with an unpatched system, often one that has been exposed for months.
Most people think of Windows updates, but the list is longer:
Operating systems on workstations, laptops and servers
Web browsers and common applications like PDF readers and office suites
Firewalls, routers, switches and wireless access points
Virtual private network and remote access software
Printers and copiers
Server software and databases
Mobile phones and tablets
Connected medical and building devices, where vendors permit
Network edge devices deserve special attention, since they face the internet directly.
You cannot patch what you do not know about. Maintain a current list of devices and software, including versions and owners. Ask your IT provider for a report that shows which devices are missing updates and which are no longer supported by the manufacturer. Unsupported systems no longer receive security fixes, and they deserve a replacement plan.
Not every patch is equally urgent. A practical approach groups updates this way:
Critical and actively exploited: Apply as quickly as possible, often within days.
High severity: Apply within a few weeks.
Routine: Include in a regular monthly cycle.
Internet-facing systems and those holding resident data come first.
Updates occasionally break things. Protect resident care by testing important patches on a small group of devices before deploying widely. For the EHR and clinical applications, check with the vendor on supported versions and any required compatibility steps. Keep the ability to roll back a bad update.
Patch windows should avoid medication passes, shift changes and peak documentation times. Options include:
Overnight or early-morning maintenance for servers and network gear
Staggered rollouts so not every station restarts at once
Rolling updates for shared workstations during low-traffic periods
Clear notices to staff so a restart is not a surprise
Avoid letting staff postpone restarts forever. A device that has not restarted in weeks often has patches waiting.
Some medical or specialty devices run old software and cannot be updated easily. Compensate with:
Network segmentation to isolate them
Restricting internet and remote access
Vendor discussions about update plans and support life
Replacement planning in your capital budget
Documenting the risk in your HIPAA risk analysis
Patching is only done when it is confirmed. Review reports showing the percentage of devices fully patched, any failures and any exceptions. Track how long critical patches take to deploy. Share a simple summary with leadership monthly or quarterly.
Patching workstations but ignoring firewalls and network equipment
Leaving old devices on the network after they stop receiving updates
Disabling updates to avoid disruption and forgetting to turn them back on
Treating patching as a one-time project rather than an ongoing routine
Not having a named owner responsible for it
The HIPAA Security Rule requires protection against reasonably anticipated threats. Prompt patching is widely regarded as a basic safeguard, and the HHS 405(d) Health Industry Cybersecurity Practices include vulnerability management among core practices.
UnityCare IT manages patching for healthcare clients, including testing, scheduling around resident care and reporting. If you are unsure how current your systems are, we can run an assessment and show you where updates have been missed.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034