Patching Without Disruption: A Schedule for 24/7 Care

Software updates are among the least glamorous and most important parts of cybersecurity. Many successful attacks exploit known vulnerabilities for which a fix was already available. CISA maintains a catalog of vulnerabilities known to be actively exploited, and many of them hit common products such as operating systems, VPN appliances and firewalls.

In a facility that never closes, patching raises a real concern. Nobody wants a computer restarting in the middle of a medication pass or a server rebooting while the night nurse is charting. The answer is not to avoid updates. It is to plan them.

What Needs Patching

Many organizations think of Windows updates and stop there. A complete list includes:

Operating systems on servers, desktops and laptops

Web browsers and plug-ins

Office suites, PDF readers and other common applications

EHR client software and supporting components

Firewalls, VPN devices, switches, access points and routers

Server firmware and hypervisors

Printers and copiers

Phone system software

Security cameras and recorders

Mobile devices and tablets

Medical devices, with manufacturer guidance

If you do not have a current inventory, start there. You cannot patch what you do not know exists.

Prioritize by Risk

Not every patch carries the same urgency. Consider:

Severity: vendors and the common vulnerability scoring system rate how serious a flaw is.

Exposure: systems reachable from the internet, such as firewalls and VPNs, deserve the fastest attention.

Active exploitation: if attackers are using a flaw in the wild, treat it as urgent.

Criticality: systems essential to care need careful testing, but should not be neglected.

A sensible policy might call for urgent fixes on internet-facing devices within days, high-severity fixes within a couple of weeks and routine updates on a monthly cycle. Set targets that match your capacity and document them.

Build a Predictable Schedule

Predictability reduces surprises. Many facilities adopt a pattern such as:

Test group first. Apply updates to a few IT-managed machines and a pilot group, watch for problems for a few days, then deploy more widely.

Workstations: update during lower-activity windows, such as mid-morning or early afternoon, or overnight with automatic restart controls. Avoid shift changes and medication passes.

Servers: use a monthly maintenance window, often late at night or on a weekend, announced in advance.

Network devices: patch in off-peak windows with a rollback plan and a second person on call.

Emergency patches: have a process for out-of-band updates when a serious exploited flaw appears.

Publish the schedule to department heads so they know when brief interruptions may happen.

Protect Clinical Workflow

Configure active hours and restart restrictions, so computers do not reboot during peak use

Notify staff before maintenance, with clear start and end times

Make sure downtime procedures are ready for the EHR

Avoid patching all devices on a unit at once, so some remain available

Verify critical functions, such as printing to the medication room, after updates

Test and Verify

Before deployment, confirm compatibility with your EHR and key applications, especially after major operating system or browser changes. Afterward, verify that updates actually installed. Reports from your management tools should show which devices are current and which are behind. Investigate devices that repeatedly fail.

Handle Systems That Cannot Be Patched

Some devices run unsupported software or depend on a vendor to approve changes. For these:

Ask the vendor for their patching policy in writing

Isolate the device on a restricted network segment

Limit who and what can connect to it

Monitor it closely

Plan replacement, and include it in budgeting

Systems that have reached end of support, such as old Windows versions, no longer receive security fixes and carry growing risk.

Document the Process

Keep records of patching policy, schedules, exceptions and compliance reports. The HIPAA Security Rule expects you to protect against reasonably anticipated threats, and a consistent patching process is evidence that you are doing so.

Common Mistakes

Postponing updates indefinitely because of an old complaint

Forgetting network equipment and firmware

Having no way to confirm updates were applied

Applying updates to every machine at once without testing

Ignoring devices that sit in closets and rarely get attention

Letting Someone Else Carry the Load

Managed patching takes time and discipline. UnityCare IT can inventory your systems, build a patching schedule that respects your clinical workflow and report on compliance so nothing falls through the cracks.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034