Applying software updates is one of the least glamorous security tasks and one of the most important. Many successful attacks use vulnerabilities for which a fix was already available. In a long-term care facility, though, there is no quiet overnight window when nobody is using a computer. Medication passes, charting and shift changes happen around the clock, so patching can feel risky. The answer is not to avoid patches. It is to manage them with a plan.
Patch management covers more than Windows updates. A complete inventory includes:
Operating systems on servers, desktops, laptops and tablets.
Applications such as web browsers, PDF readers, Microsoft Office and clinical software.
Network equipment, including firewalls, switches, wireless access points and routers.
Remote access tools and VPN appliances, which attackers actively target.
Printers, scanners and other connected devices.
Phones, mobile devices and their management platforms.
Medical and building devices, where the manufacturer controls updates.
The devices most exposed to the internet, such as firewalls and VPN gateways, should be prioritized because attackers scan for them continuously.
Patching starts with an accurate asset inventory: what each device is, where it is, who uses it, and what software and version it runs. Without it, devices quietly fall out of the update cycle. Your IT provider should be able to produce this from a management tool, and you should review it a few times a year.
Not every update has equal urgency. A reasonable approach is:
Critical or actively exploited vulnerabilities, especially on internet-facing systems: patch as quickly as testing allows, often within days. CISA maintains a catalog of known exploited vulnerabilities that is a useful reference.
High-severity updates on servers and workstations: patch within a short, defined window.
Routine updates: apply on a regular monthly cycle.
Feature updates and low-risk changes: schedule when convenient.
Write these targets into a patch policy so everyone, including leadership and your insurer, knows what to expect.
A bad update can break a clinical application. Reduce that risk with a staged approach:
Test group: a small set of representative machines, including one that runs the EMR workflow, receives updates first.
Pilot group: a slightly larger group, such as the business office, gets them next.
Production rollout: the remaining devices are updated in waves, not all at once, so you never lose every nurse station together.
Ask your clinical software vendors which updates they have certified. Some require delaying certain browser or operating system versions until they confirm compatibility.
Work with nursing leadership to find the least disruptive windows. Practical ideas:
Stagger updates by unit and by hour, so some computers are always available.
Keep spare workstations or carts ready so a device can be swapped if an update goes wrong.
Avoid updates during medication passes, shift change and admissions.
Configure active hours so computers do not restart unexpectedly in the middle of charting.
Communicate in advance with a short notice in huddles and on the unit board.
For servers and network equipment, plan maintenance windows with advance notice, a rollback plan and someone on call.
Patch tools sometimes report success when an update failed or a device was offline. Build verification into the process:
Run reports showing devices missing critical updates.
Follow up on machines that have not checked in for weeks, as these are often laptops, carts or devices that are rarely powered on.
Rescan after major updates, and check that clinical applications still function.
Keep records. They show regulators and insurers that you maintain your systems and are useful when something goes wrong.
Some older devices and applications cannot be updated, or the vendor no longer supports them. Options include isolating them on a separate network segment, limiting who can access them, turning off unneeded services, and planning replacement. Document the risk and the compensating controls. Windows 10 reaches end of support on October 14, 2025, so now is the time to identify computers that cannot upgrade and budget for replacements.
The best patch program is boring: the same schedule every month, a short report to leadership, and few surprises. UnityCare IT manages patching for healthcare and senior-living organizations, coordinating with clinical vendors and nursing leadership. If you are not sure how current your systems are, we can run a report and show you where the gaps are.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172