Back to Blog
Risk Management
8 min read

Patch Management in 24/7 Care Environments: A Risk-Based Model

There is no maintenance window in a hospital. Rolling schedules negotiated with clinical leadership, vendor certification delays, and what to do about systems that will never be patched.

GuardsArm Team

Security Experts

December 8, 2025

Patch management in clinical environments

Corporate patch management assumes a maintenance window. Hospitals do not have one. The emergency department does not close, inpatients do not go home at midnight, and imaging runs through the weekend. Patching therefore competes directly with clinical operations, and the team that treats it as a purely technical scheduling problem loses that argument every time.

No window
Clinical services run continuously; there is no universal quiet period
Vendor gated
Patching under a clinical application may void support until certified
Never-patchable
Some systems will not be patched again, and need a different treatment

Rolling windows, negotiated by service

Rather than one hospital-wide maintenance night, agree a rolling schedule per clinical service with that service's leadership. Each has a genuine quiet period, and they differ:

ServiceTypically quietestConstraint
Elective theatresOvernight, weekendsEmergency list can activate
Outpatient clinicsEvenings, weekendsLargely predictable
ImagingOvernight, excluding traumaEmergency scanning always possible
LaboratoryBrief windows onlyRuns continuously
Emergency departmentNeverRequires redundancy rather than a window
WardsNeverRequires redundancy rather than a window

For the last two, the answer is not a window. It is redundancy — clustering, failover, rolling node updates — so that patching one node does not take the service down. That is an infrastructure investment, and framing it as the alternative to an impossible maintenance window is how it gets funded.


Prioritise by exploitation, not severity

Severity alone produces a list nobody can act on. The filters that matter are covered in vulnerability management; the short version:

  • On CISA KEV and reachable — emergency, regardless of CVSS
  • Internet-facing — next
  • High EPSS — likely to be exploited soon
  • Everything else — scheduled work

Applying that filter to a hospital estate typically turns tens of thousands of findings into a few dozen that need action this month, which is a queue clinical leadership can actually be asked to accommodate.


Vendor certification, handled rather than resented

Clinical application vendors must validate patches before supporting them. That delay is genuine, and it is also frequently used as an indefinite excuse.

Handling a vendor-gated patchHandling a vendor-gated patch1Track the advisoryOn releaseKnow which of your systems are affected before the vendor contacts you.2Ask for a dateWithin daysA specific certification date, not "under review". Record the answer.3Compensate meanwhileImmediatelyTighter segmentation, protocol filtering, increased monitoring. Document as risk treatment.4Escalate contractuallyIf it slipsCertification timeliness belongs in the contract and in renewal discussions.
The compensating control is what you actually rely on during the gap, so it needs to be real.
Put certification timelines in the contract
Most healthcare software contracts say nothing about how quickly the vendor will certify a security patch. Adding a commitment at renewal costs nothing and converts an open-ended wait into an obligation.

Systems that will never be patched

Every hospital has them: the analyser running an operating system that went end of support years ago, the imaging workstation whose vendor no longer exists. Pretending these will be patched wastes the effort that should go into containing them.

Treat each explicitly:

  • Documented risk acceptance with a named clinical owner, not just IT
  • Compensating controls — isolated VLAN, allow-listed flows, no internet egress, enhanced monitoring. See legacy Windows endpoints
  • A replacement date in the capital plan, because this is a budget problem dressed as a security one
  • Annual review, so it does not become permanent by default

Measure what clinical leadership recognises

  • Time to patch KEV items — the number that matters most
  • Percentage of scheduled windows used — unused windows mean the process is stalling
  • Patches deferred for vendor certification, with age
  • Unplanned downtime caused by patching, which should be near zero and is what buys you the next window
  • Never-patchable count, trending down as replacements land

That fourth measure is the one that builds trust. A patching programme that has never caused an outage gets its windows approved; one that has caused two gets argued with for years.

GuardsArm builds risk-based patch programmes for clinical environments, including the negotiation with service leadership. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.