Patching and Updates: Why “Remind Me Later” Is a Risk Decision
Attackers read the same patch announcements your vendors publish. Every unpatched computer in your clinic is a known target — here is how it happens and what “managed” really means.

Why “remind me later” is a risk decision
Every “remind me later” click on a security update is a decision — it just does not feel like one. Software vendors release patches because they found holes, and the day a patch is published, attackers know about the hole too. From that day on, every unpatched computer is a known target.
This is not theoretical. The ransomware that recently hit a Coastal Bend dental practice — like most ransomware hitting small businesses — did not use some genius zero-day exploit. It used known vulnerabilities in systems that had not been updated. The patch existed. It just was not installed.
How unpatched systems actually get hit
The sequence is almost always the same:
- A vulnerability is published along with the patch that fixes it. Security researchers, vendors, and attackers all read the same announcements.
- Attackers scan the internet for systems still showing the vulnerable version. This is automated — nobody is targeting your clinic specifically. You get found because you are visible.
- The exploit runs itself. No phishing email needed, no one clicking anything. The vulnerable system gets compromised sitting quietly on your network.
- From one machine to the network. Once inside, ransomware spreads to every reachable system — the EHR server, the file shares, the backups if they are connected.
The window between patch release and mass exploitation keeps shrinking. “We update when we get around to it” is a strategy from a slower era.
Small clinics sometimes assume attackers only target large hospitals. The scanning that finds vulnerable systems is automated and indiscriminate — it does not know or care that you have fourteen employees. Smaller targets are attractive precisely because they are less likely to have monitoring that notices the intrusion. Obscurity is not a control.
What “managed” patching actually means
There is a difference between updates happening and updates being managed. Managed means:
Every device is inventoried. You cannot patch what you do not know exists — including that old PC in the back room still running an ancient operating system.
Patches deploy automatically on a schedule, not when someone remembers. Workstations overnight, servers in a maintenance window.
Someone verifies it worked. A report shows which machines patched and which failed — because patches do fail, and a failed patch nobody notices is the same as no patch.
Third-party software is included. Windows updates alone are not enough. Browsers, PDF readers, the EHR client, remote-access tools — attackers love the applications everyone forgets.
The patching conversation to have with your EHR vendor
Your workstations are only half the picture — the EHR itself, and the server or cloud behind it, need patching too, and that is the vendor’s job. Ask them directly: what is your patch cadence, do you test updates before deploying to our clinic, and will we be notified of maintenance windows in advance? If your EHR runs on a server in your back room, clarify who patches the operating system underneath it — many clinics discover this gap only after an incident, when the vendor points at the clinic and the clinic points at the vendor. Get the answer in writing and file it with your risk assessment. “Somebody handles it” is how unpatched servers are born.
For cloud-based EHRs, ask how quickly critical security patches reach your clinic and whether you have any say over timing — then confirm your own devices are current, because a patched cloud behind an unpatched browser is still exposed.
What to do Monday morning
Ask your IT provider — or check yourself — two questions: when did each computer in the clinic last install updates, and is there a machine nobody is sure about? The answers tell you whether patching is managed or wishful. Anything past 30 days overdue goes to the top of the fix list.
Do not forget the devices nobody thinks about: the networked printer, the firewall on the wall, the old tablet used for intake forms. If it has an IP address, it needs updates — or a documented reason it cannot be updated and compensating controls around it.
Document the patch status of every device in one place — a simple spreadsheet beats a memory. Review it monthly, and treat any device more than 30 days behind as an open risk, not a background task.
Not sure where your practice stands?
Our free network assessment reviews your computers, backups, and security — and gives you a plain-English read on what's solid and what isn't. No scare tactics.
Call (361) 704-1373 or request yours online.
Request your assessment →Not ready to book? Start with the checklist.
Our 10-Point Small Business IT Security Checklist walks you through the ten things that matter most — in plain English, no jargon. Work through it at your own pace. No sales call, no pitch — just the checklist.
Frequently asked questions
Will updates break our EHR or other software?
Occasionally, which is why managed patching tests critical updates and schedules them outside patient hours. The far larger risk is running unpatched — an update glitch is an inconvenience, ransomware is a catastrophe.
How quickly should patches be installed?
Critical security patches: within days, not weeks. Routine updates: on a regular monthly schedule at minimum. The gap between a patch release and active exploitation keeps getting shorter.
Does automatic updating count as managed patching?
Only partly. Automatic updates help, but managed means someone verifies every device actually patched, handles the failures, covers third-party applications, and keeps the stragglers — like that back-room PC — in the program.
What about our medical devices and scanners?
Devices like imaging equipment often run embedded systems you cannot patch yourself. Inventory them, ask the vendor about their update process, and isolate them on their own network segment so a compromised workstation cannot reach them.
We are a Mac / cloud-based clinic. Do we still need to worry?
Yes, less about operating-system patches and more about browsers, applications, and the cloud services themselves. And phishing plus stolen passwords — patched or not — remain the top entry point, which is why MFA matters alongside patching.