Software has flaws. When researchers or attackers discover one, the vendor releases an update, called a patch, to fix it. Once a patch is public, the details of the flaw often become known too, and attackers race to use it against anyone who has not updated. This is why unpatched systems are consistently among the most common ways criminals get into networks.
For healthcare, patching is harder than it sounds. Computers cannot simply be restarted in the middle of a medication pass, and some medical systems cannot be updated without the vendor's approval. A good patching program recognizes those realities and works around them.
It is not only Windows. Make a list of everything that runs software:
Operating systems on servers, desktops and laptops.
Applications such as browsers, PDF readers, office software and remote access tools.
Firewalls, routers, switches and Wi-Fi access points. These devices run firmware that needs updates too.
Printers and copiers.
Medical and building devices.
Phones and tablets.
Cloud systems, where the vendor usually does the patching, but you may need to update settings or plugins.
An up-to-date inventory is the foundation. You cannot patch what you do not know exists.
Fear that an update will break a critical application.
Lack of a maintenance window in a facility that operates around the clock.
Devices that are rarely restarted or are turned off when updates arrive.
Unsupported software that no longer receives updates at all.
Vendor restrictions on medical equipment.
No one clearly responsible for the task.
Someone, whether internal or at your IT provider, must be accountable for patching and for reporting its status to leadership.
Not every patch is urgent. Rank them by:
How serious the flaw is and whether it is being actively exploited. CISA maintains a Known Exploited Vulnerabilities catalog that helps identify issues that should be fixed first.
How exposed the system is. Internet-facing systems such as firewalls and remote access tools deserve the fastest attention.
How important the system is to care.
Apply updates to a small group of machines before wider rollout, particularly where clinical software is involved. Confirm that the EMR, medication carts and printers work afterward.
Choose consistent maintenance windows that avoid medication passes and shift changes. Many organizations pick overnight hours or a low-traffic day. Communicate the schedule so staff know what to expect, and ask them to restart devices when requested.
After patching, confirm that updates installed. Reports often show machines that failed or were missed. Follow up on those instead of assuming success.
Know how to uninstall an update or restore from backup if something goes wrong.
Many organizations set targets such as applying critical security updates within days and routine updates within a few weeks. Choose targets you can meet, document them in policy and track performance. Exceptions should be recorded with a reason and a plan to reduce the risk, such as isolating the device on a restricted network.
When a system can no longer be patched, such as an old operating system running a specialized device, the risk remains. Options include:
Replacing or upgrading, which is the best answer.
Isolating it on a separate network segment with tight rules.
Disabling unneeded services and internet access.
Increasing monitoring.
Document the decision in your HIPAA risk analysis.
A simple monthly report might show the percentage of devices fully patched, the number of overdue critical updates and the list of exceptions. This keeps patching visible and supports conversations about budget.
UnityCare IT manages patching for healthcare and senior living organizations, with schedules built around clinical operations and reporting that administrators can read. If you are unsure how current your systems are, we can run an assessment.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172