The Machine You Cannot Replace: What Segmentation Buys and What It Does Not

There is a C-arm in a Santa Clarita orthopedic practice running a version of Windows that stopped receiving security updates years ago. The practice cannot patch it. They cannot swap the computer inside it either, because to the manufacturer it is not a computer, it is part of a regulated medical device, and touching it voids support on equipment that cost more than a car. The imaging is excellent. It will still be excellent in 2036.

That machine is not a mistake somebody made. It is the normal condition of a regulated practice, and the useful question is not how to get rid of it. The useful question is what you put around it, what that actually buys, and what it does not buy. Most of the advice available on this subject answers a different question, because the person giving it would rather sell you a replacement.

Overview

The industry default is replace it, and for a great many things that answer is correct and cheap. Windows 10 stopped receiving security updates on 14 October 2025. For a front desk workstation running a browser and a scheduling client, the arithmetic on replacing it is not close, and anybody telling you otherwise is doing you a disservice.


The trouble is that replace it is a single answer given to a category that is not uniform. At least 3 different objects hide inside the phrase legacy system, and they have 3 different correct answers.


The first is the machine that could be replaced and simply has not been. Nothing prevents it. It is money, scheduling, and the fact that it still turns on. This is an ordinary budget conversation and it is the only one of the 3 that a purchase order actually solves.


The second is the machine that could be replaced, but not by you alone. The practice management server the software vendor has not yet certified on a current operating system. The lab interface that breaks if anything underneath it moves. In an accounting firm it is the tax package pinned to a specific operating system version that the publisher will not support anywhere else until a release that lands after filing season. You are not the constraint here. The vendor is, and their timeline is not yours, which is the same dependency our piece on third party vendor risk traces through the rest of the building.


The third is the machine that cannot be replaced at any price, because the computer is the equipment. The imaging modality, the C-arm console, the analyzer. There is no version of this where you buy a new PC and move on. It is close to universal in a medical or dental practice and it is the category the rest of this piece is really about.


Only the first is a budget problem. The second and third are architecture problems, and architecture is what segmentation is. Our earlier piece on technology debt made the case that aging systems accumulate real cost, and that case stands. This is the other half of it: what to do about the portion of that debt you are never going to be allowed to pay off.

The Challenge

The Windows 10 arithmetic is public, and it doubles every year. Microsoft sells Extended Security Updates for a maximum of 3 years past the October 2025 cutoff, and publishes the per device price: 61 dollars for the first year, 122 for the second, 244 for the third. It is sold by the whole year with no partial periods, the device has to be on version 22H2 to be eligible, and the cost is cumulative, so enrolling in the second year means paying for the first one retroactively as well. Year One coverage started in November 2025, which puts the second year this fall.


Run that against your own workstation count rather than taking anyone's word for it. A practice with 20 machines that skipped Year One and enrolls now pays 183 dollars per device, or 3,660 dollars, to buy a year of security patches for computers it is going to replace anyway. That is not a scare figure. It is Microsoft's published price list multiplied by a number you already know.


There is a free version, and it is almost certainly not available to you. This is where the subject gets genuinely misreported. Microsoft does run a free Extended Security Updates route, and it is real: sync your PC settings, or spend 1,000 Microsoft Rewards points, or pay 30 dollars once, and you are covered until 12 October 2027. That program explicitly excludes devices joined to an Active Directory domain or to Microsoft Entra, and devices enrolled in mobile device management. Which is to say it excludes, by definition, every workstation in a properly managed practice.


So when somebody tells you Microsoft extended free support into 2027, they are describing a home computer. There is also an uncomfortable version of the same fact worth sitting with: if one of your practice workstations does qualify for the consumer route, that is not a saving. It means the machine is not domain joined and not under management, which is a considerably larger finding than the licence it just saved you.


The server clock is closer than the workstation clock. Windows Server 2016 reaches its extended end date on 13 January 2027, which is about 5 months out. A small practice usually runs 1 or 2 servers, and the server is usually the thing holding the practice management database, which is the thing the software vendor certifies. So this decision frequently is not the practice's to make alone, and finding that out in December is worse than finding it out now.


The device you cannot touch is a different problem entirely. Vendor locked clinical hardware comes with support terms that commonly prohibit third party agents and third party software outright. You are not being obstructed by an unhelpful vendor; you are being told the conditions under which a regulated device stays supported. The FDA divides that responsibility plainly: manufacturers are responsible for remaining vigilant about risks in their devices, and health care organizations should evaluate their network security and protect their own systems.


Read as an operating instruction rather than as policy language, that is the whole legacy device problem in 2 sentences. The manufacturer will not let you change the device. The network around the device is yours. Everything useful you can do sits in the second sentence.


Knowing which devices fall in that category, and what specifically happens when one is touched, is not something a general IT background supplies. It comes from 5 years of X-ray, fluoroscopy and C-arm engineering work, and it is a list you learn by being in the room when someone breaks something, not by reading about it.

Why It Matters

5 reasons this is worth an afternoon:

Segmentation is a compensating control, not an absolution. This is the sentence the rest of the piece hangs on, so it goes here rather than in a footnote at the bottom. Putting a legacy device on its own segment buys it a supported life. It does not make the device safe. It is still unpatched and still exploitable by anything that reaches it; what changes is the size of the set that can reach it and the size of the set it can reach. A provider who tells you segmentation solves the problem is making the same category of error as the one who tells you to replace everything, pointed the other way, and both errors end up on an invoice. Containment is one layer of a defense that has several, and it is the layer that buys time rather than the one that removes risk.


The unsupported system is a question on a form you already signed. Cyber insurance applications ask about end of life operating systems and unsupported software by name. That question is not paperwork. It is a representation on the document a carrier reads again at claim time, and answering it from an incomplete inventory is how a practice discovers the difference between a denial and a rescission, which our piece on the cyber insurance application works through in detail.


The proposed Security Rule update names this directly. HHS proposes to require network segmentation, to require a technology asset inventory and a network map showing how electronic protected health information moves through the practice, revised at least once every 12 months, and to remove the distinction between required and addressable so that implementation specifications become required with limited exceptions. It is a proposal and it has not been finalized, and our earlier piece on that rule covers why the published dates around it have been unreliable. The point is not a deadline. The point is that what is being proposed is what you would build anyway.


You cannot segment what you have not inventoried. Practices routinely discover during this exercise that no complete list of connected devices exists, which is the same conclusion our piece on connected devices in the building reached from the other direction. The configuration work is the easy part. Walking the building, counting the things nobody counted, and asking what each one actually needs to reach is the work, and it is the part that produces the document a regulator asks for later.


Sometimes the honest answer is not to spend the money. Worth stating plainly because it is the recommendation an upsell structurally cannot make. A machine doing 1 job, on a segment that reaches nothing else, running software that has not needed a new feature since 2015, is not automatically a problem waiting for a purchase order. It is a risk to be contained, documented and reviewed. A provider who cannot tell you which of your old systems are genuinely fine is not being careful. They are being uninformative, and the invoice usually reflects it.

What Organizations Should Watch For

  • A flat network. One network where the front desk, the imaging modality, the guest wifi, the smart thermostat and the server can all see each other. This is still the most common arrangement in a small practice, and it is the condition that makes every other item on this list worse.
  • It cannot be updated, with no follow up question. There are 3 very different situations behind that sentence: the vendor will not support an update, the device physically cannot take one, and nobody has asked in 3 years. Only the third is free to fix, and it is more common than the other 2 combined.
  • A legacy system with general internet access nobody has justified. Ask what it genuinely needs to reach. The answer is usually 1 server and a printer, occasionally 1 vendor address, and almost never the open internet.
  • Standing remote access left on for a vendor. The imaging company's support tunnel, the practice management vendor's remote session tool, installed once for a go live and never reviewed since. It is a door into the segment you built the segment to protect.
  • Segmentation that exists on a diagram. A separate VLAN with no rules governing what crosses between it and everything else is a label, not a boundary. Ask to see the rules, not the drawing.
  • Shared local credentials on the old box. Legacy systems tend to run a local account the whole office knows, because that is what the workflow needed in 2014, and modern controls frequently cannot be layered on top of it. Our piece on why multi factor is not enough on its own covers the shape of that gap.
  • The unsupported system nobody wrote down. If it is not on the inventory it is not in the risk analysis, and an undocumented unsupported device is reliably the first thing an investigator finds and the last thing the practice expected them to ask about.

Recommended Actions

  • Get a written list of every system running unsupported software, sorted into the 3 categories above. Could be replaced, could be replaced but not independently, cannot be replaced at all. The sort is the valuable part, because it tells you which items are budget decisions and which are architecture decisions, and those get handled by different people on different timelines.
  • Ask each vendor in writing what their software is certified to run on, and when the next certification lands. For the middle category this is the entire constraint, it is knowable today, and it is far cheaper to learn in August than in December.
  • Settle the Windows 10 question before Year One coverage ends this fall. The price doubles annually and the back years are payable, so the cost of deciding later is not flat. For most front desk machines the answer will be replacement rather than enrollment, but that should be a calculation rather than a default.
  • For anything that stays, define what it is allowed to reach and enforce it. Not the internet, 1 server. Not the whole network, 1 printer and 1 workstation. Then confirm what can reach it, which is the half people forget.
  • Write the containment down, with a named review date. A legacy device that is inventoried, contained, justified and reviewed is a defensible position you chose. The identical device with no paperwork is a finding. The difference between those 2 outcomes is a document, and it is the cheapest thing on this list.
  • When something genuinely does need replacing, ask for 3 options with the reasoning behind each. The cheap one and what it trades away, the expensive one and what it buys, and the suggested one and why it fits your environment specifically. Then buy it direct at the vendor's price and own it outright. Ours is written into the published agreement rather than promised on a page, and what our own service does and does not include is on the pricing page with the number attached.

The SecureLynx Perspective

Observe:

Our standing rule is that nothing unmanaged runs in a regulated practice. Even a kiosk gets management, segmented or not. There is exactly 1 exception and it is deliberately narrow: clinical hardware that cannot accept the tooling without voiding the manufacturer's warranty or support. Those devices are carried as supported but unmanaged, they appear on the inventory labelled as exactly that, and they are priced out of the per endpoint tooling rather than quietly billed as though they were covered. An exception you can see on a list is a different thing from an exception nobody mentioned, and our approach to managed IT is built around that difference.


Adapt:

The imaging half of this is not knowledge that comes out of a manual. 5 years of X-ray, fluoroscopy and C-arm engineering is where the working list of which modalities can be touched, which cannot, and what breaks when the distinction is missed actually comes from. Where hardware genuinely needs replacing, the recommendation arrives as 3 options with their reasoning, priced from a vendor with no markup motive, because we do not resell hardware at all. That is not a promise made here, it is a clause in the published agreement. The practice buys direct, owns everything, and keeps the warranty in its own name, which also means nothing of ours is ever load bearing in your closet if you decide to leave. The inventory, the containment decisions and their review dates live in the client portal, exportable, with the primary copy yours.


Protect:

Then the honest limits, because this is a subject where they matter more than the capability. Segmentation does not make an unsupported device safe and we will not tell you it does. We are not the device manufacturer and cannot certify any modality for anything. A contained legacy system is a documented risk you have chosen on purpose and agreed to look at again on a date, which is a real and defensible position rather than a solved problem, and describing it as solved would be the first dishonest thing in the file. What we will do is tell you which of your old systems are genuinely fine and need nothing. That is the recommendation that costs us a sale, and it is the reason to believe the ones that do not. Point every question on this page at us first, and read the agreements before you ever call.

Common questions

Our imaging vendor says we cannot put any security software on the machine. Is that true, or are they protecting themselves?

Usually both, and it matters less than you would think which one it is. Manufacturer support terms commonly prohibit third party agents on regulated devices, and installing one can void support on equipment that costs more than a car. What matters is that this does not leave you without options. The FDA divides the responsibility plainly: the manufacturer is responsible for identifying risks in the device, and the health care organization is responsible for evaluating its own network security. Read as an operating instruction, that means the device is theirs and the network around it is yours. So the move is not to argue about the agent. It is to put the device on a segment that reaches only what it needs, write down why, and review it on a schedule. Ask the vendor one written question while you are there: what is this certified to run on, and when does the next certification land.

Windows 10 stopped getting updates last October and we are still on it. How much trouble are we in, and did Microsoft not extend it for free?

Two different programs get conflated here constantly. Microsoft does offer free Extended Security Updates to consumers, through syncing PC settings, running until October 2027. That program explicitly excludes devices joined to an Active Directory domain or Microsoft Entra, and devices enrolled in mobile device management, which describes every properly managed practice workstation. The commercial program is a separate, paid, per device track: 61 dollars for the first year, 122 for the second, 244 for the third, and enrolling late means paying for the earlier years as well. As for trouble, an unsupported operating system holding protected information is a finding in your risk analysis and a question on your cyber insurance application, in both cases whether or not anything has gone wrong yet.

Is segmentation something our IT person can just set up, or is it a project?

It depends almost entirely on the inventory rather than on the configuration. Building a segment and writing rules for it is ordinary work that a competent person does in an afternoon. Knowing what belongs on it, what each of those systems genuinely needs to reach, and which of them the vendor will still support afterward is the part that takes time, and it is where most practices discover their device list is incomplete. So treat the inventory as the project and the segmentation as the last step. That is also the order the proposed Security Rule update puts them in, which is a reasonable hint that it is the right one.