Software updates are boring, which is exactly why they get skipped. Yet known, unpatched vulnerabilities are among the most common ways attackers get into networks. CISA maintains a catalog of known exploited vulnerabilities, and the list is a reminder that attackers rapidly use flaws that vendors have already fixed.
In healthcare, patching has extra friction: clinical systems cannot go down at will, vendors sometimes restrict updates and equipment can be old. Here are seven mistakes we see most often, and how to avoid them.
Operating system updates are only part of the picture. Attackers target:
Web browsers and PDF readers
Firewalls, VPN appliances and routers
Hypervisors and servers
Printers and copiers
Wireless access points
Third-party applications such as remote tools and file transfer software
Internet-facing devices like VPNs and firewalls deserve the fastest attention because attackers scan for them continuously.
You cannot patch what you do not know about. Keep a current list of computers, servers, network equipment and applications, with operating system versions and owners. A simple spreadsheet is better than nothing, though automated discovery is better still.
Not all updates are equal. Prioritize by:
Whether the vulnerability is being exploited in the wild
Whether the affected system is exposed to the internet
How critical the system is to care
The severity rating and your own environment
A tiered approach might apply critical, exploited fixes in days, routine updates monthly and low-risk changes on a quarterly schedule.
Pushing updates to everything immediately can break clinical applications. Waiting indefinitely leaves holes open. A sensible middle route:
Test updates on a small pilot group of non-critical machines
Watch for problems for a short, defined period
Roll out in waves, starting with less critical systems
Keep a rollback plan
EHR vendors, medical device makers and other suppliers may control update schedules. Do not simply accept "we cannot patch it." Ask:
When is the next supported update?
What compensating controls do you recommend?
Can the device be placed in an isolated network segment?
What is the end-of-support date?
If a vendor cannot patch, isolate the system and record the risk.
Once software reaches end of support, security fixes stop. Windows 10, for example, is scheduled to reach end of support on October 14, 2025, so now is a good time to inventory machines and plan replacements or upgrades. Do the same for server operating systems, database software and network equipment.
Patch deployment tools sometimes report success when machines are offline, failed or never checked in. Run regular reports that show which devices are missing updates, and follow up on exceptions. Laptops that rarely connect to the office network are common culprits.
Weekly: review new critical advisories, especially for internet-facing systems
Monthly: deploy routine operating system and application updates
Quarterly: review firmware on network and security devices
Annually: review the lifecycle of all systems and plan replacements
Schedule maintenance windows with clinical leadership so downtime is planned and communicated. Many facilities use overnight windows for servers and staggered times for workstations.
Keep records of what was patched, when and what exceptions exist. This supports the HIPAA risk management requirements and answers questions from auditors and insurers.
Patching fails most often when everyone assumes someone else is handling it. Name one person or team accountable for each category: workstations, servers, network devices and applications. Give them authority to schedule maintenance windows and report exceptions to leadership each month. Clear ownership turns patching from a background worry into a managed, measurable routine.
UnityCare IT provides managed patching and monitoring for healthcare organizations, including coordination with vendors and clinical schedules. If you are unsure how current your systems really are, we can start with an inventory and a simple report.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172