Healthcare IT Patch Management Remote Desktop Services Windows Server HIPAA Business Continuity

When a Security Patch Breaks Remote Access, Healthcare Can't Just Wait

September 2026 Windows Server updates are breaking Remote Desktop Services on 2019, 2022, and 2025. Here's how healthcare teams should handle the patch-versus-uptime bind.

centrexIT Team
7 min read

Imagine it’s a Tuesday afternoon in a busy clinic. Your team applied this month’s Windows Server security updates over the weekend, exactly the way you’re supposed to. The servers ran fine for a few hours. Then the first provider tries to reconnect to their remote session between patients, and it hangs. Then another. Within a day, nobody can log in, existing sessions won’t drop, and the only thing that brings the terminal server back is a hard reset. Now do that during clinic hours, with a waiting room full of patients and an EHR your staff reaches through those exact remote sessions.

That’s the bind a lot of Windows administrators found themselves in this month, and healthcare organizations are among the most exposed to it.

What actually happened

According to BleepingComputer, Windows admins are reporting that the September 2026 cumulative updates are causing Remote Desktop Services failures on Windows Server 2019, 2022, and 2025 systems, preventing users from connecting and, in some cases, requiring a hard reset to restore functionality.

The pattern is consistent across reports. BleepingComputer describes servers that work normally for a few hours after the update installs, then start failing. Once a server starts failing, existing Remote Desktop sessions may not disconnect or log off properly, and new connection attempts hang during the connection process before eventually failing. One reader told BleepingComputer that all terminal servers in their environment were failing, with sessions dropping and no new connections possible, and that the only solution was a hard reset, all within a day of installing the update. Another admin reported that Remote Desktop Services worked initially but crashed after the first log out, after which no further users could sign in.

The reports span all three affected releases. BleepingComputer lists the specific updates as KB5122876 on Server 2019, KB5122882 on Server 2022, and KB5122871 on Server 2025. One administrator investigating Server 2022 reported what appeared to be a deadlock between Remote Desktop and the Local Session Manager when users began logging out, though BleepingComputer notes that Microsoft has not confirmed this as the cause. Admins who rolled back the September updates say doing so restores Remote Desktop functionality. Microsoft told BleepingComputer it is aware of the reports, is investigating, and will share guidance as it becomes available.

Here’s the part that makes this hard. Rolling back the update fixes the connection problem, but as BleepingComputer points out, removing the update also removes the security fixes included in this month’s Patch Tuesday release. So the workaround that restores your uptime also reopens the very holes you patched to close.

Why this lands harder in healthcare

For a lot of medical practices and clinics, Remote Desktop Services isn’t a convenience. It’s the front door to the clinical workday. Providers reach the EHR through it. Remote and multi-site staff depend on it. Billing and front-office teams work inside those sessions. When RDS goes down mid-day, it isn’t an IT annoyance, it’s a care-delivery interruption, and a hard reset in the middle of a clinic session means every active user loses their place at once.

That forces a decision no one wants to make on the fly. Leave the September update installed and risk your remote access falling over during patient hours. Or roll it back to keep people working and knowingly strip out this month’s security fixes on a server that touches protected health information. Under HIPAA, running known-vulnerable systems that handle PHI isn’t a comfortable place to sit, and neither is an outage that keeps clinicians from reaching patient records. There’s no clean answer here, only a managed one.

The deeper lesson isn’t about this one patch. It’s that “just apply every update immediately” and “never touch anything that’s working” are both wrong. Patching protects you. Patching blind exposes you. The organizations that handle months like this well are the ones that had a plan before the update landed.

What to do right now

If you run Windows Server 2019, 2022, or 2025 and rely on Remote Desktop Services, here’s a sane way through this week.

First, find out whether the September updates are on your RDS and terminal servers. BleepingComputer identifies them as KB5122876 (Server 2019), KB5122882 (Server 2022), and KB5122871 (Server 2025). Know your exposure before you decide anything.

Second, if your remote sessions are already failing, treat it as a service incident, not a mystery. Rolling back the September update has restored functionality for affected admins per BleepingComputer’s reporting. But rolling back removes this month’s security fixes, so that has to be a deliberate, documented decision with a plan to reapply once Microsoft ships a corrected update, not a set-and-forget.

Third, if you haven’t deployed September yet on production RDS, don’t rush it onto every server at once. Stage it. Test remote logins and, critically, log-outs, because the reported failures show up after users start logging off, not at first connection.

Fourth, watch for Microsoft’s guidance. Microsoft told BleepingComputer it is investigating and will share guidance as it becomes available. A fixed update or a documented mitigation is the outcome you’re waiting for, and that’s what lets you get back to fully patched and fully online at the same time.

And fifth, if you’re making the rollback call under pressure with patients in the building, that’s exactly the moment to have someone whose whole job is weighing patch risk against uptime risk, so a clinical manager isn’t guessing between two bad options alone.

This is the quiet, unglamorous work that keeps a practice running: knowing what’s on your servers, testing before you trust, and having a person to call when a routine update turns into a Tuesday-afternoon outage.

centrexIT has been the IT team Healthcare organizations across the West have trusted since 2002. If a patch decision could take your clinic’s remote access offline, it helps to know where you actually stand before you’re forced to choose. Take the 2-Minute Cybersecurity Assessment: https://centrexit.com/assessment/cybersecurity/

Common Questions

Which Windows Server versions are affected? Per BleepingComputer, the reports cover Windows Server 2019, 2022, and 2025, tied to updates KB5122876, KB5122882, and KB5122871 respectively.

Does rolling back the update fix the problem? BleepingComputer reports that admins who rolled back the September updates restored Remote Desktop functionality. The tradeoff is that removing the update also removes this month’s security fixes, which is why the decision needs to be deliberate and documented.

Has Microsoft confirmed the cause? Not as of BleepingComputer’s reporting. One admin described what looked like a deadlock between Remote Desktop and the Local Session Manager, but BleepingComputer notes Microsoft has not confirmed that as the cause. Microsoft said it is investigating and will share guidance as it becomes available.

When do the failures show up? According to BleepingComputer, servers often work normally for a few hours after installing the update, with failures appearing after users begin logging out, at which point new connections hang and fail.

Sources

Found this helpful? Share it with your network.
Written by
centrexIT Team

The centrexIT team brings decades of combined IT expertise, helping San Diego businesses thrive with secure, reliable technology solutions.

Meet Our Team