Cybersecurity · healthcare cybersecurity · Analysis
The Slow Crisis of Hospital Hardware That Nobody Can Patch
Thousands of clinical machines run obsolete software on modern hospital networks. Regulatory hurdles and operational risks ensure most will never receive an update.

Independent coverage
By AJ Dellinger
Contributing Writer — Cybersecurity / Tech Policy · Freelance
Edited by Dr. Elin Lindqvist, MD
Published 9 September 2026
7 min read
Evidence: Reporting
Modern wards are filled with networked equipment. Infusion pumps, patient monitors, and imaging carts transmit telemetry across hospital networks every minute. Most of these devices run commercial operating systems that reached end-of-life years ago.
Healthcare hardware has a long operational lifespan. A hospital might expect an MRI scanner or an anaesthesia station to serve for fifteen years. Consumer tech vendors abandon software platforms within five years, leaving a ten-year deficit where no patches exist.
The Regulatory Deadlock
The primary obstacle to maintenance is regulatory validation. When a manufacturer certifies a medical device with health authorities, the operating system and installed libraries form part of that approved state. Modifying the software can invalidate the certification, requiring costly retesting.
Equipment manufacturers therefore treat software updates as commercial risks rather than basic hygiene. Pushing an operating system patch across thousands of deployed field units can trigger fresh regulatory scrutiny. It is cheaper and legally safer for the vendor to leave the vulnerability in place.
The Limits of Network Isolation
Security teams inside hospitals understand the danger. Because they cannot alter the firmware directly, they isolate the hardware using virtual local area networks and strict firewall rules. A segmented device remains an insecure device with a digital moat around it.
This defensive posture frequently collapses in clinical practice. Biomedical technicians often connect unmanaged laptops directly to maintenance ports to calibrate hardware. Clinical staff occasionally bridge separate networks to transfer urgent scans, opening temporary paths that bypass perimeter controls.
Procurement Without Leverage
Hospital procurement departments now request software bills of materials before signing contracts. Knowing that an infusion pump relies on an outdated networking stack offers useful inventory data, but it does not generate a fix. Hospitals rarely possess the commercial leverage to force global medical device manufacturers into rewriting legacy code.
The result is a growing fleet of permanent technical debt inside critical infrastructure. Healthcare institutions cannot replace billions of euros in functioning medical hardware simply because the underlying kernel is vulnerable. Clinical operations will depend on inherently fragile machines for decades to come.
"A segmented device remains an insecure device with a digital moat around it."