Vulnerability Management for Healthcare: From Scanner Dump to Fixed
Forty thousand findings and nothing fixed is the normal failure mode. Prioritising with EPSS and CISA KEV instead of CVSS alone, patch windows that respect clinical uptime, and SLAs that hold up in an audit.
GuardsArm Team
Security Experts
Most vulnerability management programmes fail in the same way: the scanner works perfectly, produces forty thousand findings, and nothing gets fixed. The problem was never detection. It is that severity alone gives you no way to choose, and a list you cannot action is indistinguishable from no list at all.
Severity is not priority
CVSS measures how bad a vulnerability would be if exploited. It says nothing about whether anyone is exploiting it, or whether the affected asset matters to you. Sorting by CVSS puts a theoretical 9.8 on an isolated test server above a 7.5 being actively used against hospitals this week.
Three inputs together give you something actionable:
| Input | Question it answers | Source |
|---|---|---|
| CVSS | How bad if exploited? | NVD |
| EPSS | How likely is exploitation in the next 30 days? | FIRST |
| KEV | Is it already being exploited? | CISA Known Exploited Vulnerabilities |
| Asset context | Does this system matter, and is it reachable? | Your CMDB |
The rule that cuts the list down: anything on the CISA KEV catalogue that exists in your estate is an emergency regardless of its CVSS score. Everything else is scheduled work.
The healthcare-specific constraints
You cannot reboot the ward. Patch windows compete with clinical operations. This means a rolling schedule negotiated with clinical leadership, not a monthly maintenance night borrowed from a corporate playbook.
Clinical applications are vendor-certified. Patching the operating system under Epic or a PACS may void support until the vendor certifies the patch. You wait, and you compensate.
Medical devices are their own category. They belong in the programme for visibility but on an entirely different remediation track — see IoMT security. Never run an active scan against a clinical device VLAN without written agreement.
Legacy is permanent. Some systems will never be patched, because the manufacturer is gone or recertification is impossible. These need documented compensating controls and a replacement date, not an annual re-scan that rediscovers the same finding.
Remediation SLAs that hold up
Publish them, agree them with clinical and application owners, and measure against them. Unagreed SLAs are aspirations.
| Category | Target | Notes |
|---|---|---|
| On CISA KEV, internet-facing | 48 hours | Emergency change process |
| On CISA KEV, internal | 7 days | |
| Critical, internet-facing | 7 days | |
| Critical, internal | 30 days | |
| High | 60 days | |
| Medium | 90 days or next release | |
| Vendor-blocked | Compensating control in 14 days | Formal risk acceptance, named clinical owner, review date |
The lifecycle
Discovery comes first and is the usual weak point. You cannot assess what you do not know you own. Reconcile the CMDB against network discovery, cloud provider inventories and the biomedical asset register — then keep reconciling, because the gap reopens continuously.
Verification is not optional. "Patch deployed" is a deployment-tool status. Re-scan to confirm the finding is gone. A meaningful share of "remediated" findings persist because the patch failed, the service was not restarted, or the change was rolled back.
Where this meets HIPAA
The Security Rule requires a risk analysis and risk management process. A vulnerability management programme is the operational evidence that you do this continuously rather than annually. What an assessor looks for is not a clean scan — nobody has one — but a defensible process: findings are identified, prioritised on stated criteria, remediated to published timelines, and accepted risks are documented with an owner and a review date.
An unpatched critical with a signed, reviewed risk acceptance and a compensating control is a defensible position. The same vulnerability with no record is the one that becomes an enforcement finding.
GuardsArm builds risk-based vulnerability management programmes for healthcare, including safe discovery on clinical networks and SLAs that clinical operations will actually agree to. Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


