Patch Management in 24/7 Care Environments: A Risk-Based Model
There is no maintenance window in a hospital. Rolling schedules negotiated with clinical leadership, vendor certification delays, and what to do about systems that will never be patched.
GuardsArm Team
Security Experts
Corporate patch management assumes a maintenance window. Hospitals do not have one. The emergency department does not close, inpatients do not go home at midnight, and imaging runs through the weekend. Patching therefore competes directly with clinical operations, and the team that treats it as a purely technical scheduling problem loses that argument every time.
Rolling windows, negotiated by service
Rather than one hospital-wide maintenance night, agree a rolling schedule per clinical service with that service's leadership. Each has a genuine quiet period, and they differ:
| Service | Typically quietest | Constraint |
|---|---|---|
| Elective theatres | Overnight, weekends | Emergency list can activate |
| Outpatient clinics | Evenings, weekends | Largely predictable |
| Imaging | Overnight, excluding trauma | Emergency scanning always possible |
| Laboratory | Brief windows only | Runs continuously |
| Emergency department | Never | Requires redundancy rather than a window |
| Wards | Never | Requires redundancy rather than a window |
For the last two, the answer is not a window. It is redundancy — clustering, failover, rolling node updates — so that patching one node does not take the service down. That is an infrastructure investment, and framing it as the alternative to an impossible maintenance window is how it gets funded.
Prioritise by exploitation, not severity
Severity alone produces a list nobody can act on. The filters that matter are covered in vulnerability management; the short version:
- On CISA KEV and reachable — emergency, regardless of CVSS
- Internet-facing — next
- High EPSS — likely to be exploited soon
- Everything else — scheduled work
Applying that filter to a hospital estate typically turns tens of thousands of findings into a few dozen that need action this month, which is a queue clinical leadership can actually be asked to accommodate.
Vendor certification, handled rather than resented
Clinical application vendors must validate patches before supporting them. That delay is genuine, and it is also frequently used as an indefinite excuse.
Systems that will never be patched
Every hospital has them: the analyser running an operating system that went end of support years ago, the imaging workstation whose vendor no longer exists. Pretending these will be patched wastes the effort that should go into containing them.
Treat each explicitly:
- Documented risk acceptance with a named clinical owner, not just IT
- Compensating controls — isolated VLAN, allow-listed flows, no internet egress, enhanced monitoring. See legacy Windows endpoints
- A replacement date in the capital plan, because this is a budget problem dressed as a security one
- Annual review, so it does not become permanent by default
Measure what clinical leadership recognises
- Time to patch KEV items — the number that matters most
- Percentage of scheduled windows used — unused windows mean the process is stalling
- Patches deferred for vendor certification, with age
- Unplanned downtime caused by patching, which should be near zero and is what buys you the next window
- Never-patchable count, trending down as replacements land
That fourth measure is the one that builds trust. A patching programme that has never caused an outage gets its windows approved; one that has caused two gets argued with for years.
GuardsArm builds risk-based patch programmes for clinical environments, including the negotiation with service leadership. Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


