Unpatched software is one of the most common ways attackers get into networks. Vendors release fixes for known flaws, and criminals scan for systems that have not applied them. Yet in a care facility, "just update everything tonight" is not simple. Computers run around the clock, clinical software can be sensitive to changes, and a surprise restart at 6:45 a.m. can delay medication administration.
Good patch management balances security and availability. This guide explains how to do both.
Many people think only of Windows computers. A complete list includes:
Operating systems on workstations, laptops and servers
Applications such as browsers, PDF readers and office software
Firewalls, switches, routers and wireless access points
Printers, scanners and copiers
Servers and virtualization platforms
Phone systems and building controllers
Medical and clinical devices, in coordination with manufacturers
Network devices and printers are frequently forgotten, and attackers know it.
You cannot patch what you have not listed. Keep a simple inventory with device name, location, operating system, owner and criticality. Many managed IT providers collect this automatically with management software. Spot-check it against reality by walking the building once a year.
Not all patches are equally urgent.
Critical and actively exploited. Apply within days. CISA maintains a catalog of known exploited vulnerabilities that is a helpful reference for priorities.
High severity on internet-facing systems. Firewalls, remote access and email servers deserve fast attention.
Routine updates. Apply on a regular monthly schedule.
Low severity. Bundle into regular cycles.
Set targets in writing, such as emergency fixes within a few days and routine updates within a few weeks. Then measure against them.
Work with your director of nursing to find quiet periods. Many facilities find that mid-afternoon between shifts or very late at night works better than early morning. Consider these tips:
Avoid med passes, shift change, meal service and the hours around admissions.
Stagger workstation updates by unit so that not every station is down at once.
Keep at least one working computer per unit during any update.
Announce maintenance windows in advance, and post them in the staff huddle.
Let staff postpone a restart briefly, but set a deadline so updates cannot be delayed forever.
Clinical software and updates sometimes clash. Use a small test group first.
Apply updates to a few non-critical machines, ideally in the business office or IT.
Run through key tasks, such as opening the EHR, printing and scanning.
Wait a day or two and watch for problems.
Roll out to the rest in stages.
For servers and clinical applications, check with the software vendor about supported updates before applying, and take a backup or snapshot first.
Installing is not the same as succeeding. Check reports to confirm which systems actually applied the patch, and follow up on those that did not. Common causes are devices that were off, lacked disk space or need a restart. Keep a record of exceptions with the reason and a plan to resolve them.
Some systems run old software that the manufacturer no longer updates, or that must stay as validated. Do not ignore them. Instead:
Place them on an isolated network segment
Block internet access unless truly required
Limit who can connect to them
Monitor them closely
Plan replacement as part of your budget
Occasionally a serious flaw is announced that attackers are exploiting immediately. Decide ahead of time who authorizes an out-of-cycle patch and how staff will be notified. Clinical leadership should know that a short disruption may be necessary and why.
Which systems are covered by patching, and which are not?
What percentage of devices are fully patched right now?
How quickly do you apply critical updates?
Do you test updates before deploying them?
How do you handle devices that are offline for long periods?
The HIPAA Security Rule requires covered entities to protect against reasonably anticipated threats, and keeping software updated is a widely recognized part of doing that. The HHS 405(d) Health Industry Cybersecurity Practices also include vulnerability management among core practices. Your patching records show you take that seriously.
UnityCare IT manages patching for healthcare organizations with schedules built around clinical routines, plus reporting that shows what was updated and what was not. If your update process is currently "whenever the computer asks," we can help you do better.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172