Unpatched software is one of the most common ways attackers get in. When a vendor announces a security flaw, criminals often begin trying to exploit it within days or even hours. At the same time, anyone who has worked a care floor knows why IT teams hesitate: a workstation that restarts in the middle of charting, or an update that breaks a printer driver, creates real problems for staff and residents.
The solution is not to avoid patching. It is to patch deliberately, with planning that respects clinical workflow.
CISA maintains a catalog of known exploited vulnerabilities and encourages organizations to prioritize fixing those first. The pattern is consistent: flaws in operating systems, web browsers, VPN appliances, firewalls and common business software get actively exploited after disclosure. A facility that applies updates months late spends much of the year exposed to problems that already have fixes.
You cannot update what you do not know about. Keep an inventory that includes:
Workstations, laptops and tablets
Servers and virtual machines
Firewalls, switches, wireless access points and VPN devices
Printers and multifunction devices
Medical and building devices, which often require vendor involvement
Third-party applications such as PDF readers, browsers and remote tools
Cloud services are typically patched by the provider, but you remain responsible for settings, accounts and any software you install yourself.
Not every update has the same urgency.
Emergency: actively exploited flaws, especially in internet-facing systems such as firewalls and VPNs. Aim to patch within days, sometimes sooner.
High: critical vulnerabilities in operating systems and common software. Patch within a couple of weeks.
Routine: other updates in a regular monthly cycle.
Your own targets should match your risk tolerance and resources. Whatever you choose, write it down and follow it.
Pick times with the least clinical impact and agree on them with nursing leadership.
Workstations: schedule installs outside peak charting times, and set active hours so restarts do not occur mid-shift. Shared nurse station computers might be updated during the quietest overnight hours, with a staggered approach so not all machines are down at once.
Servers and network equipment: use planned windows, often late night or early weekend, with notice to affected departments.
Medical devices: coordinate with clinical engineering and vendors. Never update a clinical device without checking manufacturer guidance.
Stagger rollouts so there is always a working workstation on each unit.
Even well-made updates occasionally cause trouble. A simple testing approach:
Choose a small pilot group of representative devices, such as one workstation from each major department.
Apply updates and watch for a few days.
Verify key functions: EMR login, printing, scanning, eFax, barcode scanners and other peripherals.
Roll out to the rest in stages.
For critical servers, snapshots or backups before updating make rollback possible.
Most resentment about updates comes from surprise. Send brief notices to affected staff:
What will be updated and when
How long it might take
What staff should do beforehand, such as saving work
Who to call if something does not work afterward
A short message at the start of a shift, delivered through a huddle or posted at the station, can prevent a flood of calls.
Some software and devices no longer receive security updates. Options include replacing them, isolating them on a segmented network, restricting what they can reach, and monitoring them closely. Document the exception and the compensating controls. Note that support for Windows 10 is scheduled to end in October 2025, so start planning for workstations that cannot upgrade.
If your EMR or another application depends on a specific version of software, talk to the vendor about their compatibility and patching timeline. Ask for guidance in writing.
Kiosks, nurse station computers and servers may run for months without restarting, which delays updates that need a reboot. Schedule restarts deliberately.
Track results. Reports from your management tools should show which devices are fully patched, which failed, and which are offline. Follow up on stragglers every month, since laptops that spend time off the network are often the most out of date.
Week 1: review new updates and priorities
Week 2: pilot on test devices
Week 3: deploy in stages during agreed windows
Week 4: verify, chase exceptions, and report to leadership
UnityCare IT manages patching for healthcare clients with schedules built around clinical workflows and reporting that shows what is current. If updates in your facility are ad hoc or avoided, we can help you build a rhythm that works.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034