The Patching Gap: Closing the Window Between Fix and Install

Software vendors regularly release updates to fix security flaws. Attackers study those fixes and write tools to exploit organizations that have not yet installed them. The gap between a patch being released and your installing it is a window of opportunity for criminals, and it is one of the most common ways intruders get in.

Healthcare organizations have a good reason to be cautious about patching: a bad update during a medication pass can cause real problems. The answer is not to avoid patching but to manage it carefully. Here is how.

What needs patching

Patching is not only about Windows. A complete list includes:

Operating systems on workstations, laptops and servers

Applications such as browsers, PDF readers and Office

Network equipment: firewalls, switches, wireless access points and routers

Server software and databases

Virtualization and backup software

Printers and copiers, which are often forgotten

Medical and IoT devices, subject to manufacturer guidance

Mobile devices and tablets

Know what you have

Patching starts with an inventory. A device that is not on your list will not be patched. Maintain a list of devices, operating systems and key software, with an owner for each, and keep it current as equipment changes.

Set priorities by risk

Not every patch is equally urgent. Consider:

Severity: updates that fix flaws already being used by attackers should move to the front. CISA maintains a Known Exploited Vulnerabilities catalog that is a useful reference.

Exposure: systems facing the internet, such as firewalls and VPNs, are the highest priority.

Importance: systems holding resident data or supporting critical care need careful, but not neglected, attention.

A common practice is to patch critical issues within days and routine ones within a few weeks, with documented exceptions for systems that need vendor testing.

Build a schedule that respects care

Define maintenance windows

Agree with nursing leadership on times when reboots and updates are acceptable, such as overnight on a specific day. Communicate them in advance so staff are not surprised. For systems that must be available around the clock, plan clustered updates with redundancy so one can be updated while another continues to serve.

Test before broad deployment

Apply updates first to a small pilot group, including a representative nurse station and a medication cart, and watch for problems before releasing to everyone. Check that your EHR and key applications work after each major update. Ask software vendors for compatibility notes on significant changes.

Stage the rollout

Update in waves, not all at once. If an update causes trouble, only a few users are affected, and you can pause the rest.

Keep a rollback plan

Back up systems and configurations before changes. Know how to uninstall an update or restore a prior state, and who has the authority to decide.

Automate where you can

Manual patching depends on memory, and memory fails during busy weeks. Use management tools to deploy updates, report on status and flag machines that have not checked in for a long time. Automation should still follow the schedule and testing rules above.

Handling devices that cannot be patched

Some medical devices, building systems or legacy applications cannot be updated, or only by the manufacturer. For these:

Ask the vendor about security updates and a support timeline

Place the device on an isolated network segment

Restrict its internet access and the systems that can reach it

Monitor it for unusual activity

Document the risk and your compensating controls in your risk analysis

Plan for replacement as part of budgeting

Verify and report

Do not assume an update worked. Check that patches installed successfully and that no machines are left behind. Produce a monthly report showing the percentage of devices current, outstanding exceptions and the oldest missing updates. Review it with leadership. This also gives you evidence for insurers and for HIPAA risk management.

Common mistakes

Patching only the operating system and skipping applications and network devices

Letting machines stay offline or off for weeks so they miss updates

Disabling updates entirely because of one bad experience

Applying updates without testing on key clinical software

Leaving firewall and VPN firmware unpatched, even though these face the internet

Having no record of what was updated and when

Communicate with staff

Tell people what is happening and why. A short note such as "Computers will restart between 2 and 4 a.m. on Tuesday; please save your work and leave devices powered on" avoids lost documentation and frustrated calls.

How UnityCare IT helps

We manage patching for healthcare clients on schedules agreed with their clinical teams, including testing, reporting and exception handling for legacy devices. If you are not sure how current your systems are, we can run a quick assessment and show you what is outstanding.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: 2524 N Broadway Ste 554 PMB 947974, Edmond, Oklahoma 73034