An analysis of medical devices indicates that healthcare organizations face a significant risk of future quantum-enabled attacks, as only a small percentage are capable of supporting a transition to post-quantum cryptography (PQC). The analysis was conducted by cybersecurity firm Forescout on more than 2. 5 million Internet of Medical Things (IoMT) devices used by more than 50 healthcare delivery organizations.
The findings are published in its October 2026 PQC in Healthcare Report . Quantum computers vastly surpass the computational ability of standard computers as they process information using quantum states. They are capable of tackling complex problems that even today’s supercomputers are unable to solve.
A problem tackled by a quantum computer may take minutes or hours compared to millennia by today’s most powerful computers. One such application would be cracking today’s encryption models. Quantum computers are still under development, but Google has predicted that advances currently being made could render current encryption methods obsolete in the next five years, potentially as early as 2029.
While it may appear that there is no immediate risk, encrypted data could potentially be harvested now for decryption later when quantum computing has sufficiently advanced. Forescout warns that the risk is greater in healthcare due to the long-term value of healthcare data, compared to data such as account numbers and payment card information which can be easily changed.
According to the analysis, only 6% of IoMT devices and 16% of operational technology (OT) devices use SSH implementations that support PQC. These devices are relied on by healthcare organizations for a range of functions; however, the lowest percentage of IoMT devices capable of supporting PQC are those used for providing patient care. By comparison, around 50% of IT devices are capable of supporting PQC.
Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form. Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy PQC involves the use of new cryptographic algorithms capable of protecting against attacks from quantum computers; however, healthcare is particularly exposed because many medical devices in use are not capable of supporting PQC, including systems and devices that contain large volumes of highly sensitive healthcare data such as electronic medical records (EMRs), Picture Archiving and Communications Systems (PACS), and devices used for patient care such as patient monitors, imaging systems, infusion pumps, and lab equipment.
These systems and devices tend to have long lifecycles; however, they also have limited paths for upgrading, including upgrades to support new cryptographic standards. Many of these devices and systems are also exposed to the Internet, which makes them vulnerable to attack. The researchers identified 5,500 Internet-exposed systems, including EMRs and PACS.
Overall, out of all exposed medical information systems, only 31% supported TLS 1. 3 – the only TLS version capable of supporting standardized PDC. The analysis found that 6% of PACS supported TLS 1.
3, falling to 33% for EMRs, and 13% for laboratory management systems. The key to protecting data against quantum-enabled attacks is preparation. “PQC migration is not simply an encryption upgrade project,” said Daniel dos Santos, VP of Research at Forescout.
“Healthcare providers need to understand which assets store, process, and transport their most sensitive data, which systems can realistically be upgraded, and where compensating controls will be required. Our research shows that the devices least prepared for the transition are often the same devices healthcare organizations depend on most for delivering patient care.
Visibility into those assets and the data they handle is essential for building a practical migration strategy.” Forescout recommends that healthcare organizations start preparing now by creating a comprehensive and accurate inventory of all systems and devices, including IT, OT, IoT, and IoMT devices, along with data types and connections, prioritizing internet-exposed connections.
All assets should be assessed to determine if they are capable of supporting PQC, and any assets that are not should be prioritized for upgrades or compensating controls, especially Internet-exposed connections such as patient portals, external-facing APIs, VPN gateways, and inter-organization data exchange. TLS 1. 3 should be enforced, where possible.
Any systems that cannot be upgraded should be segmented and isolated, and PDQ readiness should be incorporated into governance, procurement, and risk management processes. ForeScout also recommends ensuring that vendors understand PQC roadmaps if they have not offered alternatives, as well as timelines for migration to PQC. The post Many Medical Devices Incapable of Supporting Transition to Post-Quantum Cryptography appeared first on The HIPAA Journal .
Originally published at hipaajournal.com


