Ask a clinical administrator why a computer has not been updated in months and you will often hear the same answers. We cannot reboot during shifts. The vendor says do not touch it. Last time we updated, something broke. These concerns are real, but they have hardened into myths that leave facilities exposed to well-known attacks.
Here are the most common patching myths and what is actually true.
Reality: attackers rarely choose targets one at a time. Automated tools scan the internet for known weaknesses and exploit whatever they find. A 60-bed facility with an unpatched remote access gateway is as visible to those tools as a large hospital. Size does not protect you; known unpatched flaws do.
Reality: an update can occasionally cause trouble, which is why you test and stage them. But the risk of a flawed update is typically smaller and more manageable than the risk of leaving a published vulnerability open, particularly one that attackers are actively using. CISA maintains a Known Exploited Vulnerabilities catalog precisely because some flaws are being used in real attacks and deserve priority.
Reality: some devices truly cannot be updated without the manufacturer, and some have FDA-regulated software. But this does not mean doing nothing. You can:
Ask the manufacturer for current patch status and support timelines.
Place unpatchable devices on a segmented network with tight firewall rules.
Disable unneeded services and internet access.
Include them in your inventory and risk analysis.
Plan replacement of devices that are no longer supported.
Reality: automatic updates for ordinary office workstations, browsers and many applications are usually safer than manual processes that get postponed forever. The better question is which systems can update automatically and which need scheduling. Clinical servers and the EHR typically need coordination with the vendor. Staff computers typically do not.
Reality: security software helps, but it is a second layer, not a substitute. Many attacks use legitimate software features or newly discovered flaws that antivirus does not recognize yet.
Reality: the list is longer. Include:
Firewalls, routers, switches and Wi-Fi controllers.
VPN and remote access appliances, which are frequent targets.
Hypervisors and server firmware.
Browsers, PDF readers, Java and other third-party applications.
Printers, scanners and phone systems.
Mobile devices and tablets.
Network edge devices deserve special attention because they face the internet directly.
Patching starts with an inventory. You cannot update what you do not know exists.
Prioritize internet-facing systems, devices with known exploited vulnerabilities and systems holding sensitive data. Then work down.
A monthly cycle for routine updates and a faster track for critical ones is common. Define target timeframes, such as critical updates within days and routine updates within a few weeks, and write them into policy.
Use a small test group, such as IT workstations and one or two clinical ones, before deploying widely. Verify the EHR and key applications still work.
Choose maintenance windows such as overnight or between shifts, and communicate them. Make sure clinical staff know whom to call if something misbehaves afterward.
Keep backups and know how to uninstall an update. This takes the fear out of the process.
Check that updates actually installed. A tool that reports compliance by device is far more reliable than assuming.
Software and hardware that no longer receives security updates are a standing risk. Put them on a replacement plan with dates.
The Security Rule requires protection from malicious software and a risk-based approach to vulnerabilities. Documented patching practices, with exceptions and compensating controls, show you took reasonable steps.
UnityCare IT manages patching for healthcare facilities, including testing, off-hours scheduling and coordination with EHR vendors. If you are unsure which of your systems are out of date, an inventory is a good first step and we can help you build one.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172