If the software for the medical equipment is not changed why should the hardware need upgrading?
It is only when you use newer packages with higher hardware demands that the PC needs to be changed.
If the equipment is not networked and does not have disks inserted in to it how will it get a virus?
But if the above is not true there is a problem. If you add or update virus protection software you are modifying the equipment, are you going to get all the software revalidated and get it CE marked in its new state? Even if CE marking does not apply to you, you need to know the additional software will not affect the correct operation of the medical part of the software.
But try telling your ICT department this.
Robert