Cybersecurity: 24/7/365

The ultrasound cart in room three runs Windows 7. It works. The images are clear, the techs know the interface, and the vendor quoted $40,000 to replace a machine that does its job perfectly well. So it stays.
That machine has not received a security patch since January 2020. Every vulnerability found in it since then is public, unfixed, and permanent. It sits on the same network as your electronic health record.
This is the most common serious security gap in small practices, and it is almost never a decision anyone made on purpose. It accumulates.
An operating system reaches end of life when the vendor stops shipping security updates for it. The software keeps running. Nothing breaks on the EOL date. That is exactly what makes it dangerous — there is no visible failure to prompt action.
The lifecycle has three stages worth knowing. During mainstream support you get features and fixes. During extended support you get security patches only. After end of life you get nothing, and any newly discovered flaw stays open forever.
End-of-life software is not limited to Microsoft Windows. It covers the operating system on your server, the firmware on a router that stopped getting updates in 2019, the database engine under an old practice management system, and the embedded OS inside medical devices. Legacy software of any kind stops receiving bug fixes and security fixes on the same schedule.
The risk is not that an unsupported system is mysteriously weaker. It is that the list of known vulnerabilities only grows, and nobody will ever fix them.
When a flaw is found in a supported operating system, the vendor ships security patches and defenders install them. When a flaw is found in an EOL operating system, the details still get published — but there is no patch. Attackers get the map; you get nothing. Automated scanning tools check for exactly these known vulnerabilities because an outdated system is the cheapest way into a network.
Vendor support is the whole difference. Supported products get security fixes for newly found security vulnerabilities; unsupported software gets a public advisory and nothing else. Every month that outdated software stays in service, the gap between what attackers know and what you can fix gets wider.
Medical environments make this worse than average. Roughly 1 in 5 connected medical devices runs an end-of-life operating system, and those devices frequently cannot be patched at all because the manufacturer validated the software as a unit. The exploit path is not theoretical: an unsupported imaging workstation is a foothold, and from there the attacker moves laterally toward records.
Ransomware crews specifically hunt for EOL systems, and healthcare organizations carry more of them than most industries. If you want the full picture of how that plays out in a practice, our guide on protecting patient data from ransomware walks through the attack chain.
The Health Insurance Portability and Accountability Act does not name Windows versions. It does not have to.
The Security Rule requires you to protect against reasonably anticipated threats and to run a risk analysis covering all systems that touch electronic protected health information. An unsupported operating system with public, unpatchable flaws is a reasonably anticipated threat by any reading. Continuing to use it, with no documented compensating controls, is very hard to defend.
This becomes concrete after a breach. Investigators reconstruct how the attacker got in. If the answer is an EOL system you knew about, the compliance issues stack on top of the incident itself, and HIPAA penalties run from $145 to $2.19 million per violation depending on culpability. A fine assessed for willful neglect is a different category from one assessed for an honest gap — and "we knew and budgeted around it" reads as the former.
The cost math is not close. The average healthcare data breach reaches $7.42 million according to IBM's 2025 Cost of a Data Breach Report, and healthcare has been the most expensive industry for 14 consecutive years. Even a contained incident stops the schedule, and healthcare downtime runs about $7,900 per hour. A $40,000 ultrasound replacement stops looking expensive.
Patient trust is the part that does not appear on any invoice. A practice that has to send breach letters explaining that the entry point was a decade-old machine spends years rebuilding something it did not have to lose.
If your practice takes card payments, the Payment Card Industry Data Security Standard applies to you as well, and it is far more direct than HIPAA. PCI DSS requires that system components be supported by the vendor and receive security updates. Running an unsupported operating system in the cardholder environment is a plain failure against those security standards, not a matter of interpretation.
Cyber insurers have caught up too. Applications increasingly ask whether you run end-of-life software, and answering carelessly can put a claim at risk later. Our cyber insurance buyer's guide covers how those questions are used.
Most practices underestimate their exposure because nobody has counted. Build the inventory before you build the plan.
For each item, record the OS version, the vendor's published end-of-life date, and whether it touches PHI. That table is the whole assessment. It also belongs in your HIPAA risk assessment, where an auditor will expect to see it.
You have four options, in order of preference.
Migrate. Move to a supported operating system. For ordinary workstations this is the right answer almost every time, and modern hardware is cheap next to the alternative.
Replace. Where the device and its software are one unit, replacement is the only real fix. Budget it across fiscal years rather than pretending the problem will wait — our guidance on what a practice should spend on IT covers how to size that line item.
Buy extended support. Some vendors sell paid security updates past the normal end date. This is a bridge, not a fix, and the price usually climbs each year on purpose.
Isolate. When a device genuinely cannot be replaced this year, segment it. Put the EOL system on its own network segment with no internet access, allow only the specific connections it needs, and enforce that at the firewall. This is a compensating control, and you must write down why it was necessary and what you did. It reduces risk; it does not eliminate it.
Do this as documented risk acceptance, with a named owner and a date the exception expires. An undocumented exception is indistinguishable from neglect after the fact.
Segmentation is worth doing properly. The same approach protects imaging and lab equipment generally, which we cover in securing connected medical devices.
Practices that fix this once usually find themselves in the same position four years later. The fix is treating lifecycle as a standing process, not a project.
Record the end-of-life date at purchase, not when it arrives. Every device gets a retirement year the day it enters the building. Review the list annually, and put the next two years of replacements into the budget so the money exists when the date comes.
Watch for compatibility issues as the excuse that keeps EOL systems alive. "Our practice management software only runs on that version" is a real constraint, and it is also a reason to ask your software vendors for their roadmap in writing. A vendor who cannot support a current operating system is telling you something about their product.
Bring end users into it as well. Staff are the ones who notice that a machine is slow, unpatched, or running something nobody recognises, and they will only mention it if someone has explained why data security depends on it.
Planning your replacements alongside everything else on the calendar makes them easier to fund. Our technology roadmap for small practices puts hardware refresh in context with the rest of the year.
You cannot budget for what you have not counted. Spend an afternoon walking the practice and listing every device with an operating system, then look up three dates: when support ended, or when it ends.
Most practices find one or two surprises. Finding them now is considerably cheaper than an investigator finding them later.
Ready to take the next step? Explore our healthcare IT services, book a free consultation, or compare our plans.