Software updates are boring until the day an unpatched system is the reason for a breach. Attackers regularly exploit known weaknesses for which fixes were already available. The CISA Known Exploited Vulnerabilities catalog exists precisely because so many attacks use flaws that vendors have already addressed.
In a care facility, patching has a complication that an office does not have: there is no quiet time. Medication carts, nurse stations and the EHR are in use all day and night. The answer is not to skip updates, but to build a routine that is predictable and safe.
You cannot patch what you have not listed. Build and maintain an inventory covering:
Servers and workstations, including operating system versions
Laptops and tablets, including those that leave the building
Network equipment such as firewalls, switches and wireless access points
Printers, copiers and other connected devices
Applications such as browsers, PDF readers and clinical software
Medical and building devices that may run older software
Missing or forgotten devices are usually the ones that end up compromised.
Not every update is equally urgent. Prioritize using three questions.
Firewalls, VPN appliances and remote access tools face the outside world and are heavily targeted. Patch these first and fastest.
Vendor and CISA alerts will say so. Active exploitation moves an update to the front of the line.
A flaw on the server holding resident data matters more than one on a lobby kiosk.
Predictability reduces both risk and surprises. A workable schedule might look like this:
Emergency patches for actively exploited flaws on exposed systems, applied within days and sometimes hours
Monthly cycle for operating systems and common applications, aligned with vendor release schedules
Quarterly review for firmware on network gear and devices that need more careful handling
Tell department heads the schedule in advance so they can plan around restarts.
Rather than updating everything at once, roll patches out in stages.
Test group: a few IT-managed machines and a non-critical workstation
Pilot group: a few friendly users across departments
Broad deployment: the remaining systems, staggered by unit or shift
If a patch breaks something, you will discover it with five machines rather than fifty.
Many updates take effect only after a reboot. Configure active hours so computers do not restart during medication passes or shift changes. Schedule shared nurse station computers to restart at the quietest time you can identify, and keep spare workstations available during updates.
For servers, use maintenance windows announced to leadership. Make sure paper downtime procedures are ready, even for a short outage.
Some clinical devices and older applications cannot be updated, either because the vendor no longer supports them or because updates require recertification. When patching is not possible:
Isolate the device on its own network segment
Restrict what it can talk to using firewall rules
Remove internet access if it does not need it
Ask the vendor for a roadmap or a replacement plan
Record the exception and the compensating controls in your risk analysis
When a vendor stops releasing security updates, the system becomes a permanent weakness. Put end-of-support dates on a calendar and budget for replacement before they arrive.
Patching without verification is wishful thinking. Run reports showing which systems are missing updates, and follow up on those that failed or were offline. Review the numbers monthly with your IT provider, and include summaries in leadership reporting.
Before a major update, confirm you have a current backup and know how to reverse the change. Record problems and share them so the next cycle is smoother.
UnityCare IT manages patching for healthcare organizations with scheduling that respects clinical workflows, and we can start by inventorying your devices and showing where updates have fallen behind.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172