Most successful cyberattacks do not rely on brilliant new tricks. They use known weaknesses in software for which a fix has already been released. Patching, the routine installation of those fixes, is therefore one of the highest-value security habits. It is also one many care facilities avoid, because updates can interrupt work, reboot computers during a shift or occasionally break an application.
The answer is not to skip updates. It is to build a predictable routine that staff trust.
When a software vendor discloses a vulnerability, attackers study it quickly. Systems that remain unpatched become easy targets. CISA maintains a catalog of known exploited vulnerabilities that organizations are urged to fix promptly, and cyber insurers often ask how quickly you apply critical updates. The HIPAA Security Rule expects protection against malicious software and a program to identify and address vulnerabilities as part of risk management.
Patching extends beyond Windows.
Operating systems on workstations, laptops and servers
Web browsers and plug-ins
Office suites, PDF readers and other common applications
Clinical and business software, in coordination with vendors
Network devices such as firewalls, switches and wireless access points
Printers, scanners and other connected devices
Mobile devices and tablets
Virtualization platforms and backup systems
Build an inventory so you know what exists. Unknown equipment is never patched.
Microsoft publishes security updates on the second Tuesday of each month, which many organizations use as an anchor. A simple cycle might look like this.
Identify the new updates and rate them by severity and exposure
Check vendor notices for compatibility concerns, especially for the EMR and any software that connects to it
Confirm that backups are current
Apply updates to a small pilot group, such as IT-managed machines and one or two friendly departments
Watch for problems with printing, login, medication cart software and other critical workflows
Record any issues and workarounds
Deploy to remaining systems in waves, starting with lower-risk areas
Schedule installs and reboots outside peak times, such as the early morning or between shifts
Notify staff in advance about restart windows
Check reports for devices that failed to update or have not checked in
Follow up on stragglers, including laptops that rarely connect
Summarize results for leadership, including any outstanding exceptions
Some vulnerabilities are being actively exploited, and waiting until next month is too long. Define an emergency path that allows critical updates to be tested quickly and deployed within days. Many organizations set target timeframes, such as a few days for critical, shorter for those under active attack, and a few weeks for routine updates. Pick targets you can actually meet and document them.
Some equipment runs outdated software that vendors no longer support or will not allow you to update. Do not ignore these systems. Reduce the risk by:
Isolating them on a separate network segment
Restricting which systems can connect to them
Blocking internet access unless required
Increasing monitoring
Setting a replacement date in your budget
Unsupported operating systems are a major insurance and compliance concern, so a replacement plan matters.
The biggest source of pushback is disruption.
Use maintenance windows that avoid medication passes and shift changes
Allow limited deferrals so a nurse can postpone a restart for a few hours, but not indefinitely
Explain why updates matter in short, plain terms
Make sure shared workstations can restart automatically overnight
Communicate when something has been fixed in response to a complaint
Manual patching does not scale. Use management tools that deploy updates, report on status and flag devices that fall behind. Review the data regularly. A dashboard that shows the percentage of machines current is useful, but pay more attention to the oldest unpatched system, because that is where an attacker will look.
Write a short patch management policy that covers scope, timelines, testing, exceptions and responsibility. Keep records of what was deployed and when. This supports your HIPAA documentation and gives you answers at insurance renewal.
UnityCare IT manages patching for healthcare organizations, including testing, scheduling around clinical workflows and monthly reporting. If updates in your facility happen only when someone remembers, we can help you establish a routine that works.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034