Siemens to patch medical PET scanners running Windows 7 by the end of month, following last week's DHS notice about available exploits
Context & Ripple Effects
Siemens is moving to patch its medical PET scanners that run on Windows 7 after a DHS notice flagged available exploits — a direct consequence of Microsoft ending Windows 7 support in January 2020, which left 83% of internet-connected medical imaging devices on outdated operating systems. The move follows a familiar script: DHS issued a similar alert about six flaws in GE Healthcare devices earlier this year.
The deeper problem is devices stranded on end-of-life software — as with CareFusion's automated supply system, where remotely exploitable flaws drew no patch at all. Siemens patching rather than abandoning the installed base is the more favorable outcome for hospital operators.
First-order effects
- Hospitals running Siemens PET scanners on Windows 7 have until the end of the month to apply fixes covering exploits DHS says are already available.
- Siemens bears the engineering cost of back-porting patches to an unsupported operating system across its scanner fleet.
Second-order effects
- Other medical device makers on legacy Windows builds — GE Healthcare among them, per DHS's own alert — face pressure to match Siemens' patch commitment or explain why they won't.
- Microsoft's paid extended-support option for Windows 7 enterprise customers becomes a likely stopgap for device vendors whose hardware can't yet migrate off the OS.
Third-order effects
- If DHS keeps publishing exploit notices for unsupported-OS medical devices, procurement and regulation will push toward vendors guaranteeing OS lifecycle support for the life of the equipment — and toward retiring fleets like CareFusion's that sit beyond patchability.
- The gap between consumer OS support cycles and decade-long medical device lifespans is becoming a structural liability for imaging vendors, not a one-off maintenance issue.
The trend: Medical imaging is colliding with desktop operating-system support lifecycles, turning vendor patch commitments and DHS advisories into the de facto security regime for hospital equipment.