Patch Management Without Disrupting Shift Change

Unpatched software is one of the most common ways attackers get into networks. Vendors release fixes for known flaws, and criminals scan for systems that have not applied them. Yet in a care facility, "just update everything tonight" is not simple. Computers run around the clock, clinical software can be sensitive to changes, and a surprise restart at 6:45 a.m. can delay medication administration.

Good patch management balances security and availability. This guide explains how to do both.

What needs patching

Many people think only of Windows computers. A complete list includes:

Operating systems on workstations, laptops and servers

Applications such as browsers, PDF readers and office software

Firewalls, switches, routers and wireless access points

Printers, scanners and copiers

Servers and virtualization platforms

Phone systems and building controllers

Medical and clinical devices, in coordination with manufacturers

Network devices and printers are frequently forgotten, and attackers know it.

Step 1: Build an inventory

You cannot patch what you have not listed. Keep a simple inventory with device name, location, operating system, owner and criticality. Many managed IT providers collect this automatically with management software. Spot-check it against reality by walking the building once a year.

Step 2: Rank by risk

Not all patches are equally urgent.

Critical and actively exploited. Apply within days. CISA maintains a catalog of known exploited vulnerabilities that is a helpful reference for priorities.

High severity on internet-facing systems. Firewalls, remote access and email servers deserve fast attention.

Routine updates. Apply on a regular monthly schedule.

Low severity. Bundle into regular cycles.

Set targets in writing, such as emergency fixes within a few days and routine updates within a few weeks. Then measure against them.

Step 3: Choose maintenance windows that fit care

Work with your director of nursing to find quiet periods. Many facilities find that mid-afternoon between shifts or very late at night works better than early morning. Consider these tips:

Avoid med passes, shift change, meal service and the hours around admissions.

Stagger workstation updates by unit so that not every station is down at once.

Keep at least one working computer per unit during any update.

Announce maintenance windows in advance, and post them in the staff huddle.

Let staff postpone a restart briefly, but set a deadline so updates cannot be delayed forever.

Step 4: Test before broad rollout

Clinical software and updates sometimes clash. Use a small test group first.

Apply updates to a few non-critical machines, ideally in the business office or IT.

Run through key tasks, such as opening the EHR, printing and scanning.

Wait a day or two and watch for problems.

Roll out to the rest in stages.

For servers and clinical applications, check with the software vendor about supported updates before applying, and take a backup or snapshot first.

Step 5: Verify and report

Installing is not the same as succeeding. Check reports to confirm which systems actually applied the patch, and follow up on those that did not. Common causes are devices that were off, lacked disk space or need a restart. Keep a record of exceptions with the reason and a plan to resolve them.

Handling devices that cannot be patched

Some systems run old software that the manufacturer no longer updates, or that must stay as validated. Do not ignore them. Instead:

Place them on an isolated network segment

Block internet access unless truly required

Limit who can connect to them

Monitor them closely

Plan replacement as part of your budget

Emergency patching

Occasionally a serious flaw is announced that attackers are exploiting immediately. Decide ahead of time who authorizes an out-of-cycle patch and how staff will be notified. Clinical leadership should know that a short disruption may be necessary and why.

Questions to ask your IT provider

Which systems are covered by patching, and which are not?

What percentage of devices are fully patched right now?

How quickly do you apply critical updates?

Do you test updates before deploying them?

How do you handle devices that are offline for long periods?

Connecting to compliance

The HIPAA Security Rule requires covered entities to protect against reasonably anticipated threats, and keeping software updated is a widely recognized part of doing that. The HHS 405(d) Health Industry Cybersecurity Practices also include vulnerability management among core practices. Your patching records show you take that seriously.

Getting help

UnityCare IT manages patching for healthcare organizations with schedules built around clinical routines, plus reporting that shows what was updated and what was not. If your update process is currently "whenever the computer asks," we can help you do better.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172