Every facility has a few of them: the desktop in the supply room that has run the same way for years, the workstation that only runs one old application, the laptop that nobody remembers buying. Out-of-date software is one of the most reliable ways for attackers to get in, because known weaknesses are widely documented and often exploited automatically. Patching and endpoint protection are not glamorous, but they close a large share of the doors that matter.
You cannot protect what you do not know you have. Build a list that includes:
Computers, laptops and tablets, with the operating system and version
Servers and virtual machines
Network equipment such as firewalls, switches and wireless access points
Printers and copiers, which often have storage and network access
Specialty devices tied to clinical or building systems
For each item, note the location, owner, purpose and whether it handles PHI. Tools managed by your IT provider can build and update this automatically, but a first pass by walking the building is worthwhile.
When a vendor ends support for an operating system or application, security fixes stop. Running unsupported software on a network that handles PHI is a serious risk that should appear in your HIPAA risk analysis. Windows 10, for instance, is scheduled to reach end of support in October 2025, so if you have computers that cannot upgrade to Windows 11, now is the time to plan replacements.
For each unsupported item, choose one of these paths:
Upgrade or replace it
Retire it if it is no longer needed
If it must remain, isolate it on a restricted network segment with limited connections, and document the exception and the plan to remove it
A predictable schedule works better than ad hoc updates.
Test group first: Apply updates to a small set of non-critical machines, then roll out to everyone
Regular windows: Choose off-peak times, such as overnight, and avoid shift changes and medication passes
Urgent patches: When a serious, actively exploited flaw is announced, shorten the timeline. CISA maintains a catalog of known exploited vulnerabilities that is a useful reference.
Reboots: Updates often need a restart. Make sure shared stations restart on schedule rather than staying on for weeks.
Third-party software: Browsers, PDF readers, Java and remote access tools need updates too, not just the operating system
Firmware: Firewalls, switches and printers need attention as well
Coordinate with your EHR vendor before changing operating systems or browsers on clinical workstations, since compatibility can matter.
Traditional antivirus relied on matching known malicious files. Modern endpoint detection and response tools also watch behavior, such as a program suddenly encrypting many files, and can isolate a computer from the network automatically.
When comparing options, ask:
Does it detect and contain ransomware-like behavior?
Can it be managed centrally and report to someone who will respond?
Who monitors the alerts, and how quickly? A tool with no one watching it offers limited protection.
Does it work on your older computers without slowing them down?
Does it integrate with your clinical applications without breaking them?
Turn on full-disk encryption for laptops and any portable device
Remove local administrator rights from everyday user accounts
Enable automatic screen lock
Restrict removable drives where feasible
Block software installs from unknown sources
Keep backups tested and separate from the network
Run a monthly report showing which devices missed updates, have disabled protection or have not checked in. Follow up on exceptions. A laptop that has been in a drawer for three months will be far behind when it is plugged back in.
Older computers are a cost in time and risk. Plan a rolling replacement cycle, replacing a portion every year instead of everything at once. Document the cost of failures and support time to help justify the budget. Consider that a single ransomware recovery typically costs far more than a modest refresh program.
If you do not currently have a complete device list and patch report, start there. UnityCare IT provides device inventory, patch management and managed endpoint protection for healthcare and senior-living organizations, and can identify which of your systems are approaching end of support.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034