Patching Myths vs. Reality in Healthcare Environments

Ask a clinical administrator why a computer has not been updated in months and you will often hear the same answers. We cannot reboot during shifts. The vendor says do not touch it. Last time we updated, something broke. These concerns are real, but they have hardened into myths that leave facilities exposed to well-known attacks.

Here are the most common patching myths and what is actually true.

Myth 1: Our systems are too small to be a target

Reality: attackers rarely choose targets one at a time. Automated tools scan the internet for known weaknesses and exploit whatever they find. A 60-bed facility with an unpatched remote access gateway is as visible to those tools as a large hospital. Size does not protect you; known unpatched flaws do.

Myth 2: Updates cause more problems than they solve

Reality: an update can occasionally cause trouble, which is why you test and stage them. But the risk of a flawed update is typically smaller and more manageable than the risk of leaving a published vulnerability open, particularly one that attackers are actively using. CISA maintains a Known Exploited Vulnerabilities catalog precisely because some flaws are being used in real attacks and deserve priority.

Myth 3: We cannot patch medical devices

Reality: some devices truly cannot be updated without the manufacturer, and some have FDA-regulated software. But this does not mean doing nothing. You can:

Ask the manufacturer for current patch status and support timelines.

Place unpatchable devices on a segmented network with tight firewall rules.

Disable unneeded services and internet access.

Include them in your inventory and risk analysis.

Plan replacement of devices that are no longer supported.

Myth 4: Automatic updates are reckless in healthcare

Reality: automatic updates for ordinary office workstations, browsers and many applications are usually safer than manual processes that get postponed forever. The better question is which systems can update automatically and which need scheduling. Clinical servers and the EHR typically need coordination with the vendor. Staff computers typically do not.

Myth 5: Antivirus protects us even if we do not patch

Reality: security software helps, but it is a second layer, not a substitute. Many attacks use legitimate software features or newly discovered flaws that antivirus does not recognize yet.

Myth 6: Patching means only Windows

Reality: the list is longer. Include:

Firewalls, routers, switches and Wi-Fi controllers.

VPN and remote access appliances, which are frequent targets.

Hypervisors and server firmware.

Browsers, PDF readers, Java and other third-party applications.

Printers, scanners and phone systems.

Mobile devices and tablets.

Network edge devices deserve special attention because they face the internet directly.

A realistic patching approach

Know what you have

Patching starts with an inventory. You cannot update what you do not know exists.

Sort by risk

Prioritize internet-facing systems, devices with known exploited vulnerabilities and systems holding sensitive data. Then work down.

Set a schedule

A monthly cycle for routine updates and a faster track for critical ones is common. Define target timeframes, such as critical updates within days and routine updates within a few weeks, and write them into policy.

Test before broad rollout

Use a small test group, such as IT workstations and one or two clinical ones, before deploying widely. Verify the EHR and key applications still work.

Schedule around care

Choose maintenance windows such as overnight or between shifts, and communicate them. Make sure clinical staff know whom to call if something misbehaves afterward.

Have a rollback plan

Keep backups and know how to uninstall an update. This takes the fear out of the process.

Verify and report

Check that updates actually installed. A tool that reports compliance by device is far more reliable than assuming.

Retire what cannot be fixed

Software and hardware that no longer receives security updates are a standing risk. Put them on a replacement plan with dates.

Tie it to HIPAA

The Security Rule requires protection from malicious software and a risk-based approach to vulnerabilities. Documented patching practices, with exceptions and compensating controls, show you took reasonable steps.

Support when you need it

UnityCare IT manages patching for healthcare facilities, including testing, off-hours scheduling and coordination with EHR vendors. If you are unsure which of your systems are out of date, an inventory is a good first step and we can help you build one.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172