Patching and Endpoint Protection for Aging Facility PCs

Every facility has a few of them: the desktop in the supply room that has run the same way for years, the workstation that only runs one old application, the laptop that nobody remembers buying. Out-of-date software is one of the most reliable ways for attackers to get in, because known weaknesses are widely documented and often exploited automatically. Patching and endpoint protection are not glamorous, but they close a large share of the doors that matter.

Start with an inventory

You cannot protect what you do not know you have. Build a list that includes:

Computers, laptops and tablets, with the operating system and version

Servers and virtual machines

Network equipment such as firewalls, switches and wireless access points

Printers and copiers, which often have storage and network access

Specialty devices tied to clinical or building systems

For each item, note the location, owner, purpose and whether it handles PHI. Tools managed by your IT provider can build and update this automatically, but a first pass by walking the building is worthwhile.

Know what is no longer supported

When a vendor ends support for an operating system or application, security fixes stop. Running unsupported software on a network that handles PHI is a serious risk that should appear in your HIPAA risk analysis. Windows 10, for instance, is scheduled to reach end of support in October 2025, so if you have computers that cannot upgrade to Windows 11, now is the time to plan replacements.

For each unsupported item, choose one of these paths:

Upgrade or replace it

Retire it if it is no longer needed

If it must remain, isolate it on a restricted network segment with limited connections, and document the exception and the plan to remove it

Build a patch routine

A predictable schedule works better than ad hoc updates.

Test group first: Apply updates to a small set of non-critical machines, then roll out to everyone

Regular windows: Choose off-peak times, such as overnight, and avoid shift changes and medication passes

Urgent patches: When a serious, actively exploited flaw is announced, shorten the timeline. CISA maintains a catalog of known exploited vulnerabilities that is a useful reference.

Reboots: Updates often need a restart. Make sure shared stations restart on schedule rather than staying on for weeks.

Third-party software: Browsers, PDF readers, Java and remote access tools need updates too, not just the operating system

Firmware: Firewalls, switches and printers need attention as well

Coordinate with your EHR vendor before changing operating systems or browsers on clinical workstations, since compatibility can matter.

Choose endpoint protection that fits

Traditional antivirus relied on matching known malicious files. Modern endpoint detection and response tools also watch behavior, such as a program suddenly encrypting many files, and can isolate a computer from the network automatically.

When comparing options, ask:

Does it detect and contain ransomware-like behavior?

Can it be managed centrally and report to someone who will respond?

Who monitors the alerts, and how quickly? A tool with no one watching it offers limited protection.

Does it work on your older computers without slowing them down?

Does it integrate with your clinical applications without breaking them?

Add the basics around it

Turn on full-disk encryption for laptops and any portable device

Remove local administrator rights from everyday user accounts

Enable automatic screen lock

Restrict removable drives where feasible

Block software installs from unknown sources

Keep backups tested and separate from the network

Verify, do not assume

Run a monthly report showing which devices missed updates, have disabled protection or have not checked in. Follow up on exceptions. A laptop that has been in a drawer for three months will be far behind when it is plugged back in.

Budget for replacement

Older computers are a cost in time and risk. Plan a rolling replacement cycle, replacing a portion every year instead of everything at once. Document the cost of failures and support time to help justify the budget. Consider that a single ransomware recovery typically costs far more than a modest refresh program.

Next steps

If you do not currently have a complete device list and patch report, start there. UnityCare IT provides device inventory, patch management and managed endpoint protection for healthcare and senior-living organizations, and can identify which of your systems are approaching end of support.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034