Critical Healthcare Systems Aren’t Quantum-Ready

Critical Healthcare Systems Remain Vulnerable to Quantum-Ready Attacks

A recent study has revealed that the healthcare sector is woefully unprepared for the advent of post-quantum cryptography (PQC), leaving sensitive patient data potentially exposed to “harvest now, decrypt later” attacks. Researchers from Forescout Technologies analyzed over 2.5 million devices across more than 50 healthcare delivery organizations and found significant gaps in readiness for PQC.

The analysis revealed that only half of IT devices surveyed were running SSH implementations capable of supporting PQC, while operational technology (OT) and Internet of Medical Things (IoMT) devices fared even worse. A mere 16% of OT devices and just 6% of IoMT devices supported PQC-ready protocols. These devices include patient monitors, insulin pumps, defibrillators, ventilators, laboratory equipment, and imaging devices that handle or transmit sensitive patient information.

The numbers are particularly concerning given the fact that over 5,500 healthcare systems containing electronic medical records and medical imaging data were reachable from the public Internet. Alarmingly, just 31% of these systems used TLS 1.3, a foundational technology for deploying standardized PQC. This lack of support leaves much of the exposed healthcare infrastructure without adequate protection against potential quantum attacks.

The stakes are high because sensitive patient data can remain valuable and confidential for decades. Threat actors who steal encrypted health data today could potentially decrypt and exploit it years later, once sufficiently powerful quantum computers become available. Healthcare is already one of the most targeted sectors, with ransomware attacks on the rise. The potential for “harvest now, decrypt later” attacks is therefore not just theoretical.

“The main takeaway is that healthcare organizations should start preparing now, before large-scale quantum attacks become practical,” warns Daniel Trivellato, Forescout’s vice president of OT, healthcare, and cyber-risk solutions. He emphasizes the need for a coordinated effort across infrastructure teams, clinical engineering, biomedical engineering, enterprise architecture, application owners, procurement, compliance, and medical device vendors.

One significant challenge to PQC-readiness is that many medical devices are difficult to upgrade due to their specialized nature and long lifespans. Devices such as imaging systems and patient-care equipment often run on older operating systems or embedded components, requiring vendor involvement, regulatory review, or even replacement of the equipment. “Many of these specialized devices are among the most difficult assets to upgrade and are often critical to patient care,” Trivellato notes.

To mitigate this risk, healthcare organizations must be prepared for significant investments in modernization, validation, recertification, and lifecycle replacement planning. In fact, simply updating software may not be enough – it may require years of coordinated effort across stakeholders.

In conclusion, the study’s findings serve as a stark reminder that improving internal IT readiness alone does not guarantee PQC-readiness. Healthcare organizations must take proactive steps to prepare for the post-quantum cryptography era, starting with a comprehensive risk assessment and implementation plan. This requires a concerted effort from healthcare providers, device manufacturers, regulators, and service providers to close the gap between current vulnerabilities and PQC-readiness.


Source: Dark Reading — 2026-10-06