Why regulated industries run the least patched devices
- Last updated 09/17/2026
-
On February 19, 2026, a ransomware attack took the University of Mississippi Medical Center's (UMMC) Epic electronic medical record (EMR) system offline, closing 35 clinics across the state.
Elective procedures, imaging appointments, and some chemotherapy and dialysis sessions were canceled. Emergency departments and inpatient units stayed open, but clinicians reverted to paper documentation, recording vitals and orders by hand the way hospitals did before EMRs existed.
UMMC treats more than 70,000 patients a year and is Mississippi's only academic medical center. It took over a week to bring clinics back online.
The scale of that disruption isn't unusual for healthcare ransomware anymore, and neither is the risk surrounding it. A Halcyon study found that in-hospital mortality rises by roughly a third during a ransomware incident.
Unpatched software in healthcare isn't a compliance abstraction. It's the layer standing between a hospital and its ability to function, sometimes with patients' lives on the line.
The industry with the most to lose runs on the oldest software
Hospitals like UMMC run far more than the servers hosting an EMR. Bedside monitors, medication carts, handheld scanners, and Android tablets clinicians carry room to room are all part of the same connected environment, and most of them get far less security attention than the network itself. The Omnissa State of Digital Workspace 2026 report puts a real number on that gap: healthcare, pharmaceuticals, and retail and wholesale carry the highest share of Android devices running operating systems four to five generations behind what's current. Healthcare alone has the highest share running more than five generations behind, older than any other industry the same report tracked.
That age gap isn't something attackers have missed. The FBI's 2025 IC3 Annual Report ranked healthcare the most targeted sector for cyberattacks that year, with 460 confirmed ransomware attacks and 182 data breaches. What makes those old devices worth targeting isn't just their age, though. It's what's sitting unpatched on them. Separate research from ORDR, a healthcare IoT security firm, found that 60% of medical devices are past end-of-life with no security patches available at all, and that 99% of hospitals are running at least one connected device with a known, exploited vulnerability already sitting on it.
That risk doesn't stay contained to the hospital it starts in. The same research found that hospitals near a facility hit by a cyberattack saw cardiac arrests surge 81%, as overflow patients got redirected into emergency departments already stretched thin.
None of this is happening because healthcare is unaware of the problem. RunSafe Security's 2026 Medical Device Cybersecurity Index found that 28% of healthcare organizations operate devices past their manufacturer's end-of-support date, and 44% openly acknowledge those devices carry known, unpatched vulnerabilities still in active use, concentrated in the exact places where failure does the most damage: emergency departments, ICUs, and operating rooms.
Healthcare handles some of the most sensitive data in the country. Right now, it's also one of the least protected industries running it.
Why the most protected data sits on the oldest devices
None of this is happening because healthcare IT teams don't understand the risk. These industries run mission-critical legacy software, medical charting systems, imaging platforms, and inventory systems where an operating system (OS) update can break the application that clinicians and staff depend on.
Vendors of that specialized software are often slow to certify new operating system builds, leaving IT to choose between an update that might break a charting tool mid-shift or a device that stays vulnerable a little longer. An analysis of 92 million medical device procurement records across 36 countries shows how long that gap actually runs: on average, 3.2 years pass between when a medical device is purchased and when a vulnerability in its components is even disclosed. Patching many of them requires taking the device offline; a cost hospitals have to weigh against continuity of care in real time.
Retail and wholesale businesses experience the same pattern for a related but distinct reason: Most deliberately freeze code changes and non-critical patching for a stretch of November and December when transaction volume peaks, along with attacker interest. The logic holds up in isolation: An update that breaks checkout during Black Friday costs more in the moment than the vulnerability it was meant to close. But the freeze creates a predictable window where patching slows just as attention from attackers rises.
E-skimming is one of the clearest examples. Attackers inject malicious code into a checkout page that quietly steals payment details as customers type them in, and these attacks nearly tripled against retail sites from 2023 to 2024. Confirmed fraud attempts rose 17% on Cyber Monday alone in 2025, according to Accertify's platform data, the same day retailers are least willing to touch their own systems.
This irony is apparent in both industries. Patient records in healthcare and payment cards in retail end up least protected at the exact moments they're most exposed.
Catching the problem before an attacker exploits it
The alternative to hoping legacy software holds and nobody notices an unpatched device isn't enforcing stricter policies. It's the ability to see a problem the moment it appears rather than during the next scheduled audit.
Virtual desktop platforms built for healthcare, including Omnissa Horizon, can continuously monitor the health of every device connecting into the environment. The moment a device falls out of compliance, it's locked out automatically. That's a meaningfully different posture than the update-and-hope cycle most healthcare IT teams are running today, and it doesn't require betting a hospital's uptime on a single software vendor's certification timeline.
Continuous observability means real-time visibility into the encryption status of every device, not a quarterly snapshot. It means tracking exactly how many versions behind each device is on its operating system, instead of finding out during the next scheduled audit. And it means flagging a device the moment it drifts out of compliance, so IT can act before an attacker finds it, not after.
Learn more about how Omnissa delivers the continuous visibility and automated compliance controls needed to protect critical systems in today's most targeted industries in our new infographic.