Software updates are the unglamorous backbone of security. Vendors regularly release patches to fix flaws that attackers actively use, and CISA maintains a catalog of known exploited vulnerabilities precisely because so many breaches begin with a weakness that already had a fix available. Yet in a care facility, updates are often postponed. Nobody wants a computer restarting during a medication pass, or an update that breaks the EHR connection.
The answer is not to skip patching. It is to plan it, so it happens on a predictable schedule with testing and a way back if something goes wrong.
When a vendor publishes a fix, the details of the flaw often become public. Attackers can then build tools to exploit systems that remain unpatched. The longer the gap between a patch release and installation, the larger your exposure. This is why insurers ask about patching timelines, and why HIPAA's risk management expectations point toward addressing known vulnerabilities.
The list is longer than most people think:
Operating systems on workstations and servers
Web browsers and plug-ins
Office and productivity software
PDF readers and other common applications
Firewalls, switches, wireless access points and routers
Phone systems and printers
Medical devices and building systems, subject to manufacturer guidance
Hypervisors, databases and other server software
Network devices are frequently forgotten, yet internet-facing firewalls and remote access gateways are prime targets.
Set timelines based on severity. For example, your policy might say:
Critical or actively exploited vulnerabilities: apply within a few days
High severity: within two weeks
Moderate and lower: within the next monthly cycle
Write the policy in plain language and have leadership approve it. Allow documented exceptions when a vendor warns that an update may break a clinical system, along with other safeguards in the meantime.
IT reviews newly released updates, checks vendor notes and identifies anything that affects clinical software. Back up critical systems before changes.
Apply updates first to a small pilot group, such as IT staff computers and a few office users. Watch for problems with EHR connections, printers and scanning.
Roll out to the remaining workstations in stages, using scheduled windows. Servers are updated in off-hours with a rollback plan.
Confirm that updates installed everywhere. Chase down computers that were off, offline or failed. Report to leadership on coverage.
Nursing floor computers are used around the clock, which makes restarts tricky. Practical approaches include:
Scheduling restarts at known quieter times, such as early morning between shifts
Using maintenance windows by wing, so not all stations restart together
Giving users a short advance notice and a limited number of deferrals, after which the restart is enforced
Keeping at least one workstation per area available during updates
Some equipment cannot be patched on your schedule, because the manufacturer must test and release updates. For these:
Ask the vendor for patch guidance and the end-of-support date.
Isolate the devices on a separate network segment.
Limit their internet access and who can connect to them.
Record the risk and the compensating controls in your risk analysis.
Software that no longer receives updates will become more vulnerable over time. Windows Server 2012 reached end of support in October 2023, and Windows 10 is scheduled to reach end of support in October 2025, so begin planning replacements and budget for them now. Maintain a list of end-of-life dates for operating systems and key applications.
Track a few simple numbers each month: the percentage of devices fully patched, the number of devices more than 30 days behind and how long critical patches took to deploy. A short dashboard makes gaps visible.
Patching only the operating system and ignoring third-party applications
Letting laptops that rarely connect to the office network fall behind
Skipping firmware updates on network equipment
No rollback plan
No one assigned responsibility
Patching works best as a predictable service rather than a scramble. UnityCare IT provides managed patching for healthcare organizations, including testing, scheduling around care activities and monthly reporting. If you are not sure how current your systems are, we can run a quick assessment and show you the gaps.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172