Software updates can feel like an interruption: a laptop restarts during a shift, a program changes its layout or a printer stops working. So updates get postponed. But unpatched software is one of the most common ways attackers get in. Many well-known breaches have exploited vulnerabilities for which a fix was already available.
The answer is not to ignore updates or to install them chaotically. It is to adopt a predictable routine that fits the rhythm of a 24-hour facility.
It is more than Windows. Build a list covering:
Operating systems on computers, servers and laptops
Web browsers and plug-ins
Office applications, PDF readers and other common software
Firewalls, switches, access points and VPN appliances
Printers and scanners
Phone systems
Medical devices and building systems, with vendor guidance
Cloud and hosted applications, which the vendor usually updates
You cannot patch what you have not inventoried, so start there.
A common approach is to align with the vendor release schedule. A sample rhythm:
IT reviews newly released updates, noting any flagged as critical or actively exploited. CISA's Known Exploited Vulnerabilities catalog is a useful public reference for prioritizing.
Apply updates to a small pilot group, such as IT's own computers and one friendly department. Check that the EHR, printers, scanners and key interfaces still work.
Roll out to the remaining computers in waves, scheduled outside peak documentation times. Provide advance notice so staff can save work.
Confirm that updates installed, follow up on failures, and document exceptions.
When a vulnerability is being actively exploited, especially on internet-facing systems such as VPNs and firewalls, do not wait for the monthly cycle. Set an expedited process that targets days, not weeks.
Use maintenance windows during low-activity hours, such as overnight for servers.
For nurse stations and shared workstations, schedule restarts with staff input.
Avoid updating all computers on one hall at once.
Communicate in advance with a short message: what will happen, when and who to call.
Never restart a medication cart computer mid-pass; coordinate with the unit.
Some EHR integrations and older applications can break after updates. Ask your software vendors about compatibility before major operating system upgrades. Keep a rollback plan, such as system restore points or backups.
Some equipment runs older operating systems or lacks vendor updates. Do not ignore it. Options include:
Isolating the device on its own network segment
Restricting internet access and unnecessary connections
Asking the manufacturer about upgrade paths or support options
Documenting the risk and a replacement plan in your risk analysis
When a vendor stops releasing security fixes, the software becomes a growing liability. Track end-of-support dates and budget for replacement before they pass.
Ask for a simple monthly report:
Percent of computers fully patched
Machines more than 30 days behind
Servers and network devices with pending updates
Exceptions and reasons
Review it with leadership and set a goal, such as no critical patches older than a defined number of days.
Laptops that never connect to the network. Use cloud-managed patching or require periodic check-ins.
Staff who postpone restarts for weeks. Set deadlines after which restarts are enforced, with warnings.
Lack of ownership. Assign a named person or provider.
No inventory. Start with a basic list and refine it.
UnityCare IT manages patching for healthcare clients with scheduled maintenance windows, testing and monthly reporting. If you are unsure how current your systems are, we can run an assessment and show you what is out of date.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172