FC Health Index1,428.60+0.42%Novo NordiskDKK 812.4+1.10%Intuitive SurgicalUSD 546.9−0.30%EU AI Act — Art. 6in forceM+7FDA 510(k) AI clearances (YTD)312+18 w/wNHS AI Diagnostic Fund£123mcommittedKarolinska trials open48+2Reimbursement CPT codes (AI)17+1 QFC Health Index1,428.60+0.42%Novo NordiskDKK 812.4+1.10%Intuitive SurgicalUSD 546.9−0.30%EU AI Act — Art. 6in forceM+7FDA 510(k) AI clearances (YTD)312+18 w/wNHS AI Diagnostic Fund£123mcommittedKarolinska trials open48+2Reimbursement CPT codes (AI)17+1 Q
Thursday, 17 September 2026 · Oslo · London · New York

Cybersecurity · healthcare cybersecurity · Analysis

The Slow Crisis of Hospital Hardware That Nobody Can Patch

Thousands of clinical machines run obsolete software on modern hospital networks. Regulatory hurdles and operational risks ensure most will never receive an update.

A black and white photograph of an empty hospital corridor with an infusion pump stand stationed beside a closed door.
A black and white photograph of an empty hospital corridor with an infusion pump stand stationed beside a closed door.

Independent coverage

A

By AJ Dellinger

Contributing Writer — Cybersecurity / Tech Policy · Freelance

Edited by Dr. Elin Lindqvist, MD

Published 9 September 2026

7 min read

Evidence: Reporting

Modern wards are filled with networked equipment. Infusion pumps, patient monitors, and imaging carts transmit telemetry across hospital networks every minute. Most of these devices run commercial operating systems that reached end-of-life years ago.

Healthcare hardware has a long operational lifespan. A hospital might expect an MRI scanner or an anaesthesia station to serve for fifteen years. Consumer tech vendors abandon software platforms within five years, leaving a ten-year deficit where no patches exist.

The Regulatory Deadlock

The primary obstacle to maintenance is regulatory validation. When a manufacturer certifies a medical device with health authorities, the operating system and installed libraries form part of that approved state. Modifying the software can invalidate the certification, requiring costly retesting.

Equipment manufacturers therefore treat software updates as commercial risks rather than basic hygiene. Pushing an operating system patch across thousands of deployed field units can trigger fresh regulatory scrutiny. It is cheaper and legally safer for the vendor to leave the vulnerability in place.

The Limits of Network Isolation

Security teams inside hospitals understand the danger. Because they cannot alter the firmware directly, they isolate the hardware using virtual local area networks and strict firewall rules. A segmented device remains an insecure device with a digital moat around it.

This defensive posture frequently collapses in clinical practice. Biomedical technicians often connect unmanaged laptops directly to maintenance ports to calibrate hardware. Clinical staff occasionally bridge separate networks to transfer urgent scans, opening temporary paths that bypass perimeter controls.

Procurement Without Leverage

Hospital procurement departments now request software bills of materials before signing contracts. Knowing that an infusion pump relies on an outdated networking stack offers useful inventory data, but it does not generate a fix. Hospitals rarely possess the commercial leverage to force global medical device manufacturers into rewriting legacy code.

The result is a growing fleet of permanent technical debt inside critical infrastructure. Healthcare institutions cannot replace billions of euros in functioning medical hardware simply because the underlying kernel is vulnerable. Clinical operations will depend on inherently fragile machines for decades to come.

"A segmented device remains an insecure device with a digital moat around it."

Published 9 September 2026