Windows 10 Support Has Ended. Is Your Bozeman Practice Still Running On It?

Eight months ago, on October 14, 2025, Microsoft stopped supporting Windows 10. No more security patches. No more bug fixes. No more technical support from Microsoft, full stop. For most consumers, that deadline came and went without much notice. For a small medical practice in Bozeman still running clinical workstations, billing computers, or EHR-connected machines on Windows 10, that date marked the start of a clock that has been quietly running ever since, and most practice owners have no clear sense of how exposed they currently are.
This is not a future risk to plan around. It is a present condition. Every day a Windows 10 machine touching patient data stays in operation past that deadline, it runs without the security updates that previously closed newly discovered vulnerabilities. Attackers know this. Security researchers know this. The only people who sometimes do not know this are the practice owners and office managers whose computers still say Windows 10 in the corner of the screen, quietly working the same way they always have.
The reason this matters specifically for healthcare, and specifically right now, is that an unsupported operating system is not just an IT inconvenience. Under the HIPAA Security Rule, it is a documented, identifiable gap in the safeguards a practice is required to maintain around protected health information. A practice that has not addressed this is not technically behind schedule. It is currently, today, operating outside the standard HIPAA expects.
What actually changed on October 14, 2025
It helps to be precise about what end of support means, because the practical experience of using a Windows 10 computer did not change overnight. The machine still turns on. The EHR still opens. Email still sends. Nothing visibly broke, which is exactly why this deadline is so easy for a busy practice to miss entirely.
What did change is invisible but consequential. Microsoft no longer issues security patches for newly discovered vulnerabilities in Windows 10. When a flaw is found in the operating system today, eight months after the cutoff, it will never be fixed on a standard Windows 10 installation. That vulnerability simply remains open, indefinitely, on every unsupported machine still running the OS. Security researchers continue finding these flaws because Windows 10 remains one of the most widely deployed operating systems in the world, which means the population of unpatched, exploitable machines is large, well understood by attackers, and growing more vulnerable every month as new flaws accumulate with no corresponding fix.
Microsoft does offer a limited bridge for organizations not yet ready to migrate: a paid Extended Security Updates program that continues providing critical patches for a defined period. This is a genuine option, but it is explicitly temporary and was designed as a short runway for completing a migration, not a long-term substitute for moving to a supported operating system. A practice that has not even started planning a Windows 11 migration eight months after the original deadline is past the point where ESU functions as breathing room. It is now functioning as a deferred decision with a daily cost attached.
Why healthcare practices are the slowest to move off legacy systems
Healthcare has historically lagged behind almost every other industry in retiring legacy technology, and the reasons are specific to how clinical environments actually work, not a matter of healthcare IT being careless.
Diagnostic and clinical equipment is frequently tied to specific software versions that were validated, sometimes through a regulatory process, against a particular operating system. A digital X-ray system, a lab analyzer interface, or specialized diagnostic software may have been installed and certified to run on Windows 10 specifically, and the vendor may not have released, or may not plan to release, a Windows 11 compatible version on any defined timeline. Upgrading the operating system on that workstation without vendor confirmation risks breaking the connection to equipment the practice depends on every day.
Budget cycles in small practices also do not anticipate forced technology refreshes. A four or five computer practice did not necessarily plan for the capital expense of replacing hardware that otherwise works fine, especially when the visible symptom of the problem, the end of Microsoft support, produces no immediate operational disruption. The cost of inaction is invisible until an incident makes it visible, and by then the conversation is no longer about a planned upgrade. It is about incident response.
And practices that have a single break-fix IT relationship rather than an ongoing managed service often have nobody proactively tracking vendor lifecycle deadlines on their behalf. Nobody was watching the calendar for them, so the deadline passed unnoticed, and continues to pass unnoticed every day the gap remains unaddressed.
8 months
since Microsoft ended Windows 10 support on October 14, 2025
73%
of healthcare organizations still operate legacy devices on outdated operating systems
$9.77M
average cost of a healthcare data breach, the highest of any industry tracked
22%
of all disclosed cyberattacks in 2025 targeted healthcare, up 50% year over year
Sources: Microsoft lifecycle documentation, MDDI Online 2025 healthcare cybersecurity survey, MedicalITG 2026 healthcare ransomware analysis.
Why an unsupported OS is a specific, identifiable HIPAA gap, not a general concern
It is worth being precise about why this particular issue carries more weight under HIPAA than ordinary outdated software, because the distinction matters for how a practice should prioritize it.
The HIPAA Security Rule’s technical safeguards require covered entities to implement measures that protect electronic protected health information from unauthorized access. A formal HIPAA risk analysis, which every covered entity is required to maintain and update, must identify vulnerabilities in the systems that store, process, or transmit PHI. An operating system that no longer receives security patches is not a theoretical vulnerability requiring discovery. It is a documented, dated, and publicly known gap, the exact opposite of difficult to identify, since Microsoft has published the end of support date and OCR investigators are aware of it as a matter of public record.
This creates a specific exposure during any OCR investigation that follows a breach. If forensic review traces an incident back to a vulnerability that was patched on supported operating systems but left open on an unsupported one running past its documented end of life, demonstrating reasonable safeguards becomes very difficult. The practice cannot argue the vulnerability was unknown or unforeseeable. The end of support date was published more than a year in advance and covered extensively across the healthcare IT press throughout 2025.
The comparison below outlines the practical difference this status makes for a clinical workstation.
Workstation on Windows 11, current patches
| Security patches | Applied monthly |
| Known CVEs | Remediated on release |
| HIPAA risk analysis status | Defensible |
| Vendor support | Active |
Workstation on Windows 10, unsupported
| Security patches | None since Oct 2025 |
| Known CVEs | Accumulating, unfixed |
| HIPAA risk analysis status | Documented gap |
| Vendor support | Ended |
This is not a marginal distinction. A risk analysis that has identified an unsupported operating system handling PHI and has not documented a remediation plan or compensating controls is itself a separate compliance gap, independent of whether an actual breach ever occurs. For practices that have not reviewed their HIPAA risk assessment since before October 2025, this status alone is reason enough to schedule one now.
Why “it still works” is the wrong test
The most common reason a practice delays addressing this is the simplest one: the computer still works. The EHR opens. Email sends. Nothing about the daily experience of using the machine signals that anything is wrong, which makes the underlying risk easy to discount.
This is precisely the trap. A system that continues to function normally while running unpatched is not evidence of safety. It is the absence of an event so far, on a machine that is structurally more vulnerable today than it was on October 13, 2025, and will be more vulnerable next month than it is today, because the gap between what attackers know about Windows 10 vulnerabilities and what gets fixed only widens over time.
The right test is not whether the machine works. It is whether the practice can answer three specific questions with confidence: which machines touching PHI are still running Windows 10, what specific clinical or billing function depends on each one, and what the actual barrier to migrating each one is, hardware incompatibility, vendor software certification, or simply the project never being scheduled. Most small practices that have not formally inventoried this cannot answer any of the three questions precisely, which is itself diagnostic. An organization that knows its risk posture can describe it specifically. One that has not looked tends to describe it in general reassurances instead.
1. Inventory every machine touching PHI
Identify the operating system on every workstation, server, and device connected to clinical, billing, or scheduling systems. Most practices discover the number of affected machines is higher than expected once equipment-connected workstations are included.
2. Confirm vendor compatibility for equipment-connected workstations
For machines tied to diagnostic or clinical equipment, contact the equipment vendor directly to confirm whether a Windows 11 compatible version exists and what the certified migration path looks like. This determines which machines can move immediately and which require a vendor-led plan.
3. Apply compensating controls to machines that cannot migrate immediately
For workstations that genuinely cannot move off Windows 10 in the short term, isolate them on a segmented network, restrict their access to only what the equipment requires, and document this as a formal compensating control in the practice’s risk analysis rather than leaving the gap unaddressed and undocumented.
4. Set a funded, dated migration plan for every remaining machine
Every machine without a hard compatibility barrier should have a budgeted, scheduled migration date, not an open-ended intention. Update the practice’s risk analysis to reflect the plan and the timeline so the documentation itself demonstrates active remediation, not unaddressed risk.
What a realistic migration looks like for a small practice
A full technology refresh sounds disruptive, and for a practice with no internal IT department, the instinct is often to delay until the project feels more manageable. In practice, migrating off Windows 10 rarely requires replacing every machine simultaneously or disrupting patient care during the transition.
Many workstations currently running Windows 10 are hardware-capable of running Windows 11 with an in-place upgrade, requiring no new hardware purchase at all. The machines that do need replacement can typically be staged over weeks, prioritizing the workstations with the highest PHI exposure first, such as front desk check-in computers and billing terminals, while equipment-tied machines that require vendor coordination move on their own separate, slower timeline.
This is also an opportunity to address related gaps at the same time rather than treating the migration as an isolated project. A practice migrating workstations is a natural moment to also verify network security configurations, confirm backup systems are properly isolated and tested, and review whether multi-factor authentication is consistently enforced across every system that touches patient data. Bundling these reviews into a single coordinated project, rather than addressing each one reactively as a separate fire drill, is both more efficient and more defensible from a compliance documentation standpoint.
For practices that have not reviewed their broader technology environment recently, the front desk HIPAA risks article and the healthcare vendor access security guide both cover adjacent compliance gaps that frequently surface during the same kind of technology review that a Windows 10 migration prompts.
Complete IT management for a healthcare practice means a partner is already tracking vendor lifecycle deadlines like this one before they become urgent, so the practice never finds itself eight months past an end of support date without a plan in motion.
Get a clear picture first
A five-minute assessment shows exactly where your practice’s current IT and compliance gaps sit, including operating system exposure.
Take the readiness quiz →Talk to a local IT partner
Entre works with Bozeman healthcare practices to inventory affected machines, coordinate vendor compatibility, and build a funded migration plan.
Talk to Entre in Bozeman →The clock did not stop because nobody was watching it
Eight months past a published deadline is not early in this problem. It is well into the period where the gap between what a defensible HIPAA posture looks like and what an unaddressed Windows 10 environment actually represents continues to widen. The practices that close this gap well are not waiting for an incident to force the question. They are treating the inventory, the vendor coordination, and the migration plan as work that needs to happen on a schedule they control, rather than one an attacker or an OCR investigation eventually sets for them.
Entre works with healthcare practices across Bozeman and the surrounding region to manage exactly this kind of technology lifecycle work as an ongoing part of complete IT management, so vendor end of support deadlines get tracked and addressed before they become the kind of gap an OCR investigator finds first. The healthcare services page covers the full scope of what that partnership includes.
If you are not certain how many machines in your practice are still running Windows 10, or what your current HIPAA risk analysis says about that exposure, the IT and cybersecurity readiness quiz is a five-minute starting point. Or reach out to Entre directly to talk through your practice’s specific environment and what a realistic migration timeline looks like from here.


















