Your practice’s IT security probably focuses on computers: the front desk PC, the laptops, maybe a server. But the digital X-ray sensor, the imaging workstation, the patient monitor, and the smart scale in the exam room are all computers too, and most of them are quietly running whatever operating system the manufacturer shipped years ago and never updated since.
These are called IoMT devices, connected medical things, and they’re usually the least protected computer in the building.
What’s actually happening in 2026
Smart hospitals and practices are expected to have more than 7 million connected medical devices in use by 2026, more than double the number from just a few years ago. 73% of healthcare organizations still operate legacy devices running outdated operating systems that lack modern security protections, and 53% of networked medical devices have at least one known critical vulnerability. Early in 2026, 22% of healthcare organizations had already experienced a cyberattack that targeted a medical device directly.
The reason is structural, not accidental. A manufacturer builds a device, gets it cleared with a specific operating system version, and rarely wants to spend the money to re-certify it every time a security patch comes out. So the imaging workstation or digital sensor ships once, runs the same embedded Windows or proprietary firmware for a decade, and the practice using it has no real way to patch it without risking the vendor’s support agreement or breaking the device’s certified function.
Why this is a HIPAA problem, not just a device problem
Any device sitting on the same network as your EHR and staff workstations is a potential path to PHI, whether or not it was ever meant to be a security concern. An unsupported operating system with a known vulnerability gives an attacker a way onto the network without ever touching a traditional computer or tricking an employee. HIPAA’s Security Rule doesn’t stop at the EHR; it covers every system that could expose patient data, and a flat network where the imaging workstation talks to the same switch as the billing computer makes that scope a lot bigger than most practices realize.
What to actually do about it
You can’t always patch these devices, but you can control what they’re allowed to reach.
- Inventory every network-connected device, not just computers: imaging systems, digital sensors, patient monitors, smart scales, anything with an ethernet port or Wi-Fi radio.
- Put clinical devices on their own isolated network segment: a compromised sensor or workstation shouldn’t be able to reach the EHR or staff computers directly.
- Ask every vendor in writing what operating system a device runs and whether it’s still supported: use the answer to plan realistic replacement timelines instead of finding out during an incident.
- Restrict what these devices can talk to: most only need to reach one or two specific servers, not the general internet or the rest of your network.
- Document unsupported devices as a known risk in your HIPAA risk analysis: if a device can’t be patched, the network controls around it become the compensating safeguard, and auditors want to see that decision made on purpose.
Where ACS fits in
Most practices have never mapped every connected device on their network, let alone segmented them from patient data. ACS’s free 30-minute IT & HIPAA assessment looks at what’s actually talking to your network, where an unsupported device could become an entry point, and what a realistic segmentation plan looks like for your practice.


