Microsoft ended mainstream support for Windows 10 back in October 2025. If your practice skipped the upgrade, you’re not alone — plenty of medical offices are still running it today. But “it still works fine” and “it’s still compliant” are two very different things, and the gap between them gets more expensive every month.
Where things actually stand right now
Windows 10 didn’t disappear overnight. Microsoft’s consumer Extended Security Updates (ESU) program covers eligible devices through October 13, 2026, and commercial customers can buy additional coverage that stretches to October 12, 2027. So machines aren’t breaking — they’re just quietly falling out of the update cycle that used to patch newly discovered vulnerabilities automatically.
That distinction matters more in healthcare than almost anywhere else. The HIPAA Security Rule’s technical safeguards require covered entities to keep systems patched and protected against known vulnerabilities. Every day a Windows 10 workstation touching patient data goes without the updates it used to get, the exposure window gets a little wider — and it’s the kind of gap an auditor or a cyber-insurance carrier will ask about directly.
Why this shows up on every HIPAA risk assessment
A proper HIPAA risk analysis looks at every system that stores, processes, or transmits PHI, and unsupported operating systems are one of the first things it flags. It’s not just theoretical: several cyber-insurance applications now ask directly whether all endpoints are running supported, fully patched operating systems. Answer “no,” and you can end up with a higher premium, added exclusions, or a declined policy at renewal — on top of whatever an actual breach would cost.
That’s why “no Windows 10” made our own quick IT and HIPAA health check. It’s a small checkbox with an outsized effect on your risk profile.
The real cost of “we’ll deal with it later”
The math on delay isn’t in your favor.
- Security exposure compounds: unpatched vulnerabilities don’t stay theoretical — attackers actively scan for known weaknesses in end-of-life systems, and ransomware groups specifically target healthcare because PHI is valuable and downtime is costly.
- ESU isn’t free, and it isn’t forever: Extended Security Updates buy time, not a permanent solution — and the per-device cost adds up fast if it’s covering a fleet you were always going to replace.
- Compliance documentation gets harder to defend: if OCR or an insurer asks how you’re mitigating a known, unpatched vulnerability across your fleet, “we’re aware of it” isn’t a safeguard.
- Clinical workflows are the ones at risk: these are the machines running your EHR, your imaging software, your front-desk systems — exactly the workflows you can least afford to have down or compromised.
What a realistic upgrade path looks like
You don’t have to replace every machine on the same afternoon. A practical migration usually looks like this.
- Inventory first: know exactly which devices are still on Windows 10, what they run, and whether they’re eligible for a Windows 11 upgrade or need replacing outright.
- Prioritize by exposure: machines touching PHI or your EHR move first; back-office and low-risk devices can follow.
- Decide on ESU as a bridge, not a destination: if some devices need more runway, ESU can cover the gap — but pair it with a firm replacement timeline, not an open-ended one.
- Document everything: your risk assessment should show the plan, the timeline, and the interim safeguards in place. That paper trail is exactly what auditors and insurers want to see.
- Fold it into ongoing patch management: this isn’t a one-time fire drill — it’s a reminder to keep OS lifecycle tracking as a standing part of your IT and compliance routine.
Where ACS fits in
This is exactly the kind of gap we look for during a free IT and HIPAA assessment: unsupported systems, missing safeguards, and the documentation trail that ties it all together. We’ll tell you plainly where your practice stands and what it would take to close the gap, no obligation either way.


