Back to Blog
Risk Management
10 min read

Vulnerability Management for Healthcare: From Scanner Dump to Fixed

Forty thousand findings and nothing fixed is the normal failure mode. Prioritising with EPSS and CISA KEV instead of CVSS alone, patch windows that respect clinical uptime, and SLAs that hold up in an audit.

GuardsArm Team

Security Experts

September 24, 2026

Vulnerability management for healthcare

Most vulnerability management programmes fail in the same way: the scanner works perfectly, produces forty thousand findings, and nothing gets fixed. The problem was never detection. It is that severity alone gives you no way to choose, and a list you cannot action is indistinguishable from no list at all.

~4%
Share of published CVEs ever observed being exploited in the wild
Cyentia / FIRST EPSS research
Thousands
New CVEs published monthly — triage by CVSS alone cannot keep pace
NVD
24/7/365
Clinical uptime requirement that makes healthcare patch windows genuinely scarce

Severity is not priority

CVSS measures how bad a vulnerability would be if exploited. It says nothing about whether anyone is exploiting it, or whether the affected asset matters to you. Sorting by CVSS puts a theoretical 9.8 on an isolated test server above a 7.5 being actively used against hospitals this week.

Three inputs together give you something actionable:

InputQuestion it answersSource
CVSSHow bad if exploited?NVD
EPSSHow likely is exploitation in the next 30 days?FIRST
KEVIs it already being exploited?CISA Known Exploited Vulnerabilities
Asset contextDoes this system matter, and is it reachable?Your CMDB

The rule that cuts the list down: anything on the CISA KEV catalogue that exists in your estate is an emergency regardless of its CVSS score. Everything else is scheduled work.

Turning a scanner dump into a work queueTurning a scanner dump into a work queueAll open findings40000Illustrative funnel: exposure, exploitation likelihood and asset criticality reduce a forty-thousand-finding backlog to a few dozen items that matter this week.Raw scanner outputInternet-reachable4200Illustrative funnel: exposure, exploitation likelihood and asset criticality reduce a forty-thousand-finding backlog to a few dozen items that matter this week.Filter by exposureHigh EPSS or on KEV380Illustrative funnel: exposure, exploitation likelihood and asset criticality reduce a forty-thousand-finding backlog to a few dozen items that matter this week.Filter by real-world exploitationOn a critical clinical asset46Illustrative funnel: exposure, exploitation likelihood and asset criticality reduce a forty-thousand-finding backlog to a few dozen items that matter this week.Filter by business impact
Illustrative proportions. The shape is what matters — three filters, two orders of magnitude.

The healthcare-specific constraints

You cannot reboot the ward. Patch windows compete with clinical operations. This means a rolling schedule negotiated with clinical leadership, not a monthly maintenance night borrowed from a corporate playbook.

Clinical applications are vendor-certified. Patching the operating system under Epic or a PACS may void support until the vendor certifies the patch. You wait, and you compensate.

Medical devices are their own category. They belong in the programme for visibility but on an entirely different remediation track — see IoMT security. Never run an active scan against a clinical device VLAN without written agreement.

Legacy is permanent. Some systems will never be patched, because the manufacturer is gone or recertification is impossible. These need documented compensating controls and a replacement date, not an annual re-scan that rediscovers the same finding.


Remediation SLAs that hold up

Publish them, agree them with clinical and application owners, and measure against them. Unagreed SLAs are aspirations.

CategoryTargetNotes
On CISA KEV, internet-facing48 hoursEmergency change process
On CISA KEV, internal7 days
Critical, internet-facing7 days
Critical, internal30 days
High60 days
Medium90 days or next release
Vendor-blockedCompensating control in 14 daysFormal risk acceptance, named clinical owner, review date
Measure the right number
Total open findings only ever goes up and tells you nothing. Track SLA compliance by category, mean time to remediate for KEV items, and count of overdue criticals. Those three move when the programme works.

The lifecycle

Vulnerability management lifecycleAsset discovery feeds assessment, findings are prioritised by exploitation likelihood and asset context, remediated or compensated, then verified.Discoverassets firstAssessscan + intelPrioritiseEPSS, KEV, contextRemediatepatch or compensateVerifyconfirm, do not assume
Verification is the step most often skipped — a closed ticket is not evidence.

Discovery comes first and is the usual weak point. You cannot assess what you do not know you own. Reconcile the CMDB against network discovery, cloud provider inventories and the biomedical asset register — then keep reconciling, because the gap reopens continuously.

Verification is not optional. "Patch deployed" is a deployment-tool status. Re-scan to confirm the finding is gone. A meaningful share of "remediated" findings persist because the patch failed, the service was not restarted, or the change was rolled back.


Where this meets HIPAA

The Security Rule requires a risk analysis and risk management process. A vulnerability management programme is the operational evidence that you do this continuously rather than annually. What an assessor looks for is not a clean scan — nobody has one — but a defensible process: findings are identified, prioritised on stated criteria, remediated to published timelines, and accepted risks are documented with an owner and a review date.

An unpatched critical with a signed, reviewed risk acceptance and a compensating control is a defensible position. The same vulnerability with no record is the one that becomes an enforcement finding.

GuardsArm builds risk-based vulnerability management programmes for healthcare, including safe discovery on clinical networks and SLAs that clinical operations will actually agree to. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.