Healthcare
What Actually Keeps Healthcare Technology Running
Thursday, September 10, 2026
2 min read

In early 2024, a cyberattack on Change Healthcare took down claims processing for an estimated 70% of providers and payers across the United States. Pharmacies couldn't verify insurance. Hospitals couldn't submit claims. The disruption rippled through the industry for months. The attack itself was the headline, but the underlying story was less dramatic and more familiar: a legacy infrastructure vulnerability that had existed long before anyone exploited it.
That's usually how it goes. The systems that fail publicly and catastrophically almost never fail because of some novel, unforeseeable threat. They fail because ordinary maintenance, patching, monitoring, access review, capacity planning, got deferred long enough that a gap turned into a door.
The number nobody puts in a proposal
There's a metric in software operations called change failure rate: the percentage of deployments or updates that end up causing an outage or requiring a rollback. Industry benchmarks put legacy systems at around a 46% change failure rate, compared to roughly 15% for actively maintained, cloud-native platforms. That gap isn't about the age of the code so much as what's been done with it since it shipped. A ten-year-old system that's been patched, monitored, and re-architected as needs changed can be safer to update than a two-year-old system nobody has touched since launch.
None of that shows up in a sales conversation. Vendors pitch roadmaps, integrations, and features. They don't lead with their patch cadence, their incident response times, or how they handle a dependency that's reached end of life. That's not dishonesty so much as incentive: nobody buys a maintenance schedule. But it's exactly the work that determines whether the system anyone bought is still trustworthy in year five.
The regulatory floor is about to catch up
For years, this has mostly been an operational risk that stayed invisible unless something broke. That's changing. HHS has proposed the first significant update to the HIPAA Security Rule in years, with final rules expected in 2026. The proposed changes include mandatory multi-factor authentication for administrative access, mandatory encryption, network segmentation requirements, and 72-hour restoration timelines for critical systems after an incident. The Healthcare Cybersecurity Act of 2025 is moving through Congress alongside it, with provisions for sector-specific risk management and resource allocation for high-risk facilities.
Read together, these signal something specific: maintenance discipline is moving from an internal best practice to something regulators will expect organizations to demonstrate, not just claim. A health system won't be able to answer "how do you handle this" with a shrug much longer.
What this actually looks like day to day
The unglamorous version of good maintenance isn't exciting to describe. It's patching on a schedule instead of when something breaks. It's monitoring that flags a problem before a user does. It's treating a vendor's end-of-life notice on a dependency as a project, not a footnote. It's testing a rollback before a deployment needs one, not during the outage.
None of that is a feature. It's closer to an operating habit, one that either exists as a structural part of how a platform is run, or gets rebuilt from scratch every time something forces the issue. The systems that hold up over years, across changes in leadership, changes in regulation, and changes in the threat landscape, are the ones where this work was never optional in the first place.
A pitch deck can promise a roadmap. It can't promise a decade of Tuesdays where nothing broke because someone did the unremarkable work of keeping it that way.
Sources: Oxmaint — The Hidden Risk in Healthcare: Legacy Infrastructure, Cybersecurity, and Maintenance Gaps · Oxmaint — Healthcare Cybersecurity and Infrastructure Risk · Next Olive — 2026 Legacy System Maintenance Cost: Trends & Budget Guide