Medical Devices Lag on Quantum-Safe Crypto
Forescout found only 6% of IoMT and 16% of medical OT devices run SSH that can move to post-quantum cryptography.

Hospitals run on machines that were never built to be upgraded. An investigation by Forescout has found that most medical devices cannot make the move to post-quantum cryptography, leaving sensitive healthcare data exposed to attacks that quantum computers are expected to enable in the years ahead.
The findings, published on October 6, point to a gap that spans the devices clinicians rely on every day — infusion pumps, patient monitors, imaging systems, and laboratory equipment among them.
A 6% Ceiling for IoMT
Forescout analyzed more than 2.5 million devices across more than 50 healthcare delivery organizations. Just 6% of Internet of Medical Things (IoMT) devices and 16% of medical operational technology (OT) devices use Secure Shell implementations capable of supporting a transition to post-quantum cryptography, the company reported.
That compares with 50% of traditional IT devices that can support a PQC implementation — a gap the report treats as a structural problem rather than an oversight.
Post-quantum cryptography refers to new algorithms designed to protect data from attacks launched by quantum computers, which are predicted to be capable of breaking existing encryption methods within the next five years.
Why Healthcare Is Stuck
The report highlighted that healthcare environments are highly dependent on IoMT, OT and IoT devices, many of them directly involved in patient care. Those same devices often have long lifecycles, limited upgrade paths and slower adoption of modern cryptographic standards.
The result is a population of machines that may still be in service when the cryptography protecting their data stops being trustworthy.
A Warning From Forescout
Daniel dos Santos, VP of research at Forescout, tied the readiness gap directly to the clinical role these devices play.
“Our research shows that the devices least prepared for the transition are often the same devices healthcare organizations depend on most for delivering patient care. Visibility into those assets and the data they handle is essential for building a practical migration strategy.”
— Daniel dos Santos, VP of research at Forescout
Exposed Systems Hold Patient Records
Across the devices analyzed, the researchers identified more than 5500 internet-exposed systems. Those included platforms containing sensitive healthcare data, such as electronic medical records and picture archiving and communication systems.
Of these exposed systems, just 31% support TLS 1.3, the only TLS version capable of supporting standardized PQC.
Forescout warned that these systems are particularly vulnerable to harvest now, decrypt later attacks, in which threat actors steal encrypted data today with the intent of decrypting it in the future when quantum computers become powerful enough. The report noted that medical histories, diagnostic images, laboratory results and prescription records retain their value and sensitivity for decades, unlike other types of information.
The Inventory Problem
Forescout urged healthcare organizations to begin preparing for quantum-enabled attacks now. Its recommendations start with knowing what is actually connected.
- Inventory and classify all connected IT, OT, IoT and IoMT assets, including their communication with other assets
- Assess which assets support PQC today and identify systems that require upgrades, replacement or compensating controls
- Segment and isolate legacy systems that cannot be upgraded
- Incorporate PQC readiness into governance, procurement and risk management processes, including enforcing TLS 1.3 wherever possible
- Engage vendors to understand their PQC roadmaps and migration timelines
The list reflects a practical sequencing problem: an organization cannot plan a migration for devices it has not accounted for, and it cannot count on vendors to move faster than its own procurement cycles.
The Numbers That Define the Gap
- 2.5 million devices analyzed across more than 50 healthcare delivery organizations
- 6% of IoMT devices use SSH implementations capable of supporting a PQC transition
- 16% of medical OT devices meet the same bar
- 50% of traditional IT devices can support PQC implementation
- 5500+ internet-exposed systems identified
- 31% of exposed systems support TLS 1.3
A Timeline Measured in Years
The report's framing rests on a forecast rather than a current capability: quantum computers are predicted to be capable of breaking existing encryption methods in the next five years. That prediction is what turns encrypted data sitting in a medical records system today into a future liability.
It is also what makes the device-level numbers matter. A device that cannot support PQC does not become safe simply because the threat is not yet realized. It becomes a candidate for compensating controls, segmentation, or replacement.
Where the Pressure Lands
For healthcare organizations, the report's findings suggest that the quantum transition is arriving on a schedule that overlaps with the working life of equipment already installed in clinical settings. The devices least likely to support PQC are the ones most tightly bound to patient care, and the data they process is the kind that stays sensitive for decades.
That combination could mean that a migration strategy built only around traditional IT systems leaves a substantial share of the environment untouched. Whether hospitals can close that gap depends on choices they make now — what they inventory, what they ask vendors, and what they are willing to segment or retire before the cryptography underneath it becomes obsolete.
Sources
- Infosecurity Magazine Original source
Continue Reading
CISO Data: Cyber Risk Moves Into Workflow
Five years of Voice of the CISO research show risk shifting from the perimeter to the flow of daily work, with AI governance and human risk at the center.
New SonicWall Flaw Hits VPN Gateways
SonicWall issued hotfixes for a maximum-severity SSRF bug in SMA1000 appliances, urging customers to upgrade before attackers take note.
Hadrian's Series B Fuels AI Pentesting Push
Hadrian raises $40 million to expand its AI offensive security platform and challenge the slow pace of manual pentesting.