Seven Patch Management Mistakes Healthcare Teams Make

Software updates are boring, which is exactly why they get skipped. Yet known, unpatched vulnerabilities are among the most common ways attackers get into networks. CISA maintains a catalog of known exploited vulnerabilities, and the list is a reminder that attackers rapidly use flaws that vendors have already fixed.

In healthcare, patching has extra friction: clinical systems cannot go down at will, vendors sometimes restrict updates and equipment can be old. Here are seven mistakes we see most often, and how to avoid them.

1. Patching only Windows

Operating system updates are only part of the picture. Attackers target:

Web browsers and PDF readers

Firewalls, VPN appliances and routers

Hypervisors and servers

Printers and copiers

Wireless access points

Third-party applications such as remote tools and file transfer software

Internet-facing devices like VPNs and firewalls deserve the fastest attention because attackers scan for them continuously.

2. No inventory

You cannot patch what you do not know about. Keep a current list of computers, servers, network equipment and applications, with operating system versions and owners. A simple spreadsheet is better than nothing, though automated discovery is better still.

3. Treating every patch the same

Not all updates are equal. Prioritize by:

Whether the vulnerability is being exploited in the wild

Whether the affected system is exposed to the internet

How critical the system is to care

The severity rating and your own environment

A tiered approach might apply critical, exploited fixes in days, routine updates monthly and low-risk changes on a quarterly schedule.

4. Skipping testing, or testing forever

Pushing updates to everything immediately can break clinical applications. Waiting indefinitely leaves holes open. A sensible middle route:

Test updates on a small pilot group of non-critical machines

Watch for problems for a short, defined period

Roll out in waves, starting with less critical systems

Keep a rollback plan

5. Ignoring vendor-controlled systems

EHR vendors, medical device makers and other suppliers may control update schedules. Do not simply accept "we cannot patch it." Ask:

When is the next supported update?

What compensating controls do you recommend?

Can the device be placed in an isolated network segment?

What is the end-of-support date?

If a vendor cannot patch, isolate the system and record the risk.

6. Running unsupported software

Once software reaches end of support, security fixes stop. Windows 10, for example, is scheduled to reach end of support on October 14, 2025, so now is a good time to inventory machines and plan replacements or upgrades. Do the same for server operating systems, database software and network equipment.

7. Not verifying results

Patch deployment tools sometimes report success when machines are offline, failed or never checked in. Run regular reports that show which devices are missing updates, and follow up on exceptions. Laptops that rarely connect to the office network are common culprits.

Build a maintenance rhythm

Weekly: review new critical advisories, especially for internet-facing systems

Monthly: deploy routine operating system and application updates

Quarterly: review firmware on network and security devices

Annually: review the lifecycle of all systems and plan replacements

Schedule maintenance windows with clinical leadership so downtime is planned and communicated. Many facilities use overnight windows for servers and staggered times for workstations.

Document what you do

Keep records of what was patched, when and what exceptions exist. This supports the HIPAA risk management requirements and answers questions from auditors and insurers.

Assign an owner

Patching fails most often when everyone assumes someone else is handling it. Name one person or team accountable for each category: workstations, servers, network devices and applications. Give them authority to schedule maintenance windows and report exceptions to leadership each month. Clear ownership turns patching from a background worry into a managed, measurable routine.

Use help where it makes sense

UnityCare IT provides managed patching and monitoring for healthcare organizations, including coordination with vendors and clinical schedules. If you are unsure how current your systems really are, we can start with an inventory and a simple report.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172