Medical Devices Face Major Hurdles in Post-Quantum Cryptography Transition
A significant portion of medical devices lack the capability to support post-quantum cryptography (PQC), leaving sensitive patient data vulnerable to future quantum-enabled cyberattacks.

A new study by Forescout has revealed substantial challenges for the healthcare sector in its transition to post-quantum cryptography (PQC), a critical defense against future quantum computing threats. The research indicates that a vast majority of Internet of Medical Things (IoMT) devices and medical operational technology (OT) systems are ill-equipped to handle the cryptographic shifts required to protect data from quantum-enabled attacks.
Forescout's analysis, which examined over 2.5 million devices across more than 50 healthcare delivery organizations (HDOs), found that a mere 6% of IoMT devices and 16% of medical OT devices utilize Secure Shell (SSH) implementations capable of supporting PQC. This starkly contrasts with traditional IT devices, where approximately 50% are already capable of PQC implementation, highlighting a significant disparity in security readiness.
Post-quantum cryptography (PQC) refers to new cryptographic algorithms designed to withstand attacks from quantum computers, which are projected to possess the capability to break current encryption standards within the next five years. The healthcare industry, heavily reliant on connected devices for patient care—including infusion pumps, patient monitors, and imaging systems—faces a unique risk due to the long lifecycles and limited upgrade paths of these critical systems.
Daniel dos Santos, VP of Research at Forescout, emphasized the critical nature of this disparity. "Our research shows that the devices least prepared for the transition are often the same devices healthcare organizations depend on most for delivering patient care," he stated. "Visibility into those assets and the data they handle is essential for building a practical migration strategy."
The study also identified over 5500 internet-exposed systems within healthcare environments, many of which contain highly sensitive data such as electronic medical records (EMRs) and picture archiving and communication systems (PACs). Alarmingly, only 31% of these exposed systems support TLS 1.3, the only TLS version currently capable of supporting standardized PQC. This leaves them vulnerable to "harvest now, decrypt later" attacks, where threat actors exfiltrate encrypted data today with the intent of decrypting it once powerful quantum computers become available.
Given that healthcare data, including patient histories, diagnostic images, and prescription records, retains its value and sensitivity for decades, the implications of these "harvest now" attacks are particularly severe. The long-term confidentiality and integrity of patient information are at significant risk if proactive measures are not taken.
To address these vulnerabilities, Forescout urges healthcare organizations to begin preparing for quantum-enabled attacks immediately. Key recommendations include conducting comprehensive inventories and classifications of all connected assets, assessing PQC readiness, and implementing segmentation and isolation for legacy systems that cannot be upgraded. Furthermore, organizations are advised to integrate PQC readiness into their governance and procurement processes, prioritize TLS 1.3 adoption, and actively engage with vendors to understand their PQC migration roadmaps.