This does not surprise my one bit. I know about 99% of the medic equipment control by a PC backend is running =< Win 2K or some other old OS and if the owns even thing of install a patch/update onto the box they void all warranty and maintenance contracts on what could be a +2Mil $ bit of kit.
Also I've seen a hell of a lot of "update" to system where they just update the front-end system to a better GUI but the real work/data is stored and done on the old outdated, unpatched system {AS/400, Novell, NT4, etc}



