Report: 83% of internet-connected medical imaging devices run on outdated operating systems, up 56% since 2018 due to the end of Windows 7 support in Jan.
Palo Alto Networks' Unit 42 security division said medical equipment is outdated and vulnerable to hacker attacks and health care organizations … Source: Unit42 .
Context & Ripple Effects
The Windows 7 end-of-support deadline in January landed on a device class that had already shown it cannot keep pace with vendor patch cycles: back in 2017, Siemens had to scramble to patch Windows 7-based PET scanners after DHS flagged available exploits, and CareFusion's automated supply system was left with over a thousand remotely exploitable flaws and no fix at all because it ran on end-of-life software. Unit 42's new numbers show the problem compounding rather than resolving — the share of imaging devices on outdated operating systems has grown 56% since 2018.
The timing matters because health care cyber risk has since moved from data loss to patient harm: a later report found 22% of providers saw increased patient mortality after a cyberattack, which reframes an aging-OS statistic as a clinical safety issue, not just an IT hygiene one.
First-order effects
- Hospitals running internet-connected imaging equipment on Windows 7 now face a widening exploit window with no vendor OS patches, forcing security teams to compensate with network segmentation and monitoring around devices they cannot update themselves.
- Device makers like Siemens inherit renewed pressure to certify and ship firmware-level updates for installed fleets, repeating the scanner-patching exercise of 2017 across a larger base.
Second-order effects
- The pattern echoes what happened when breach fears drove enterprises to refresh desktops — analysts tied a 45% rise in US breaches in 2017 to an 11% bump in Windows 10 sales — so health systems may accelerate capital spending on newer imaging hardware or OS-migration contracts, shifting procurement budgets toward vendors who can guarantee longer support lifecycles.
- Cyber insurers and regulators gain a concrete metric for underwriting and auditing hospitals, pushing third-party vendor security gaps — already linked to worse patient outcomes — into contractual requirements.
Third-order effects
- If end-of-support cycles keep outpacing medical device refresh rates, the industry structurally splits into two tiers: hospitals able to buy modern fleets and those running permanently unpatchable equipment, deepening the safety gap documented in post-attack mortality findings.
- Regulators are likely to move from advisories toward enforceable lifecycle requirements for connected medical devices, making OS support duration a design and certification criterion rather than a customer afterthought.
The trend: End-of-support deadlines for consumer operating systems are becoming de facto security cliffs for embedded medical fleets, turning device lifecycle management into a patient-safety and regulatory issue.