Indy,
Thanks for the post and links.
So from what I am reading, even if the router is patched with the WPA2 KRACK update, if other devices connected via WPA2 remain corrected to the network and are unpatched, then the network is not secure. Is that correct?
From an attack surface perspective, securing the access point is the key.
If you have devices that aren't patched, then they are a risk in attaching to compromised networks, and then exposing banking credentials, patient data, etc.
Longer term, Docs need to implement VPNs to secure their network usage. Especially when traveling.