Critical Healthcare Systems Remain Vulnerable to Quantum-Ready Attacks
Healthcare organizations are failing to prepare for the dawn of the post-quantum cryptography era, leaving millions of sensitive patient records and medical imaging data potentially vulnerable to devastating attacks. A recent study by Forescout Technologies analyzed 2.5 million devices across over 50 healthcare delivery organizations and uncovered a staggering lack of readiness for post-quantum cryptography (PQC). The findings are a wake-up call for the industry, which has already been a prime target for cyber threats.
The study’s results are alarming: only half of IT devices surveyed were running SSH implementations capable of supporting PQC, while operational technology (OT) and Internet of Medical Things (IoMT) devices lagged far behind. These devices include patient monitors, insulin pumps, defibrillators, ventilators, laboratory equipment, and imaging machines – all critical to patient care and handling highly sensitive data. In fact, over 5,500 healthcare systems containing electronic medical records and medical imaging data were reachable from the public Internet, with a mere 31% using TLS 1.3, the foundation for deploying standardized post-quantum cryptography.
The consequences of not adapting to PQC are severe: threat actors who steal encrypted health data today could potentially decrypt it years later, when sufficiently powerful quantum computers become available. Healthcare is already one of the most targeted sectors, with ransomware attacks a constant threat. The potential for “harvest now, decrypt later” attacks – where attackers steal sensitive data now and exploit it later – is all too real.
The study’s lead researcher warns that healthcare organizations must start preparing immediately: “The main takeaway is that healthcare organizations should start preparing now, before large-scale quantum attacks become practical.” To achieve this, CISOs and other security decision makers must lead the effort, but they must also ensure that getting PQC-ready is not just a security initiative. It will require coordination among multiple stakeholders, including infrastructure teams, clinical engineering, biomedical engineering, enterprise architecture, application owners, procurement, compliance, and medical device vendors.
One significant challenge facing healthcare organizations is the difficulty of upgrading legacy medical gear. Many devices are specialized systems with long lifespans and tightly controlled software environments, making upgrades complex and costly. In some cases, even replacement of equipment may be necessary. Organizations must prepare for significant investments in modernization, validation, recertification, and lifecycle replacement planning.
The fact that 50% of IT systems surveyed were PQC-ready yet only 31% of Internet-exposed healthcare systems supported TLS 1.3 highlights the need for a comprehensive approach to PQC readiness. Improving internal IT readiness alone is not enough; organizations must also address the security of their external-facing systems.
To mitigate these risks, healthcare organizations should take immediate action: start by identifying and prioritizing devices that require upgrade or replacement, engage with device manufacturers and regulatory bodies to ensure compliance, and invest in modernization efforts. By doing so, they can protect sensitive patient data and prevent devastating attacks from exploiting vulnerabilities years down the line.
Source: Dark Reading — 2026-10-06