Breaking
SecurityDeveloping Story

Medical Devices Lag on Quantum-Safe Crypto

Forescout found only 6% of IoMT and 16% of medical OT devices run SSH that can move to post-quantum cryptography.

··1 day ago·4 min read
Princess Margaret Cancer Centre, Toronto, Ontario
Photo by Ken Lund on Unsplash

Hospitals run on machines that were never built to be upgraded. An investigation by Forescout has found that most medical devices cannot make the move to post-quantum cryptography, leaving sensitive healthcare data exposed to attacks that quantum computers are expected to enable in the years ahead.

The findings, published on October 6, point to a gap that spans the devices clinicians rely on every day — infusion pumps, patient monitors, imaging systems, and laboratory equipment among them.

A 6% Ceiling for IoMT

Forescout analyzed more than 2.5 million devices across more than 50 healthcare delivery organizations. Just 6% of Internet of Medical Things (IoMT) devices and 16% of medical operational technology (OT) devices use Secure Shell implementations capable of supporting a transition to post-quantum cryptography, the company reported.

That compares with 50% of traditional IT devices that can support a PQC implementation — a gap the report treats as a structural problem rather than an oversight.

Post-quantum cryptography refers to new algorithms designed to protect data from attacks launched by quantum computers, which are predicted to be capable of breaking existing encryption methods within the next five years.

Why Healthcare Is Stuck

The report highlighted that healthcare environments are highly dependent on IoMT, OT and IoT devices, many of them directly involved in patient care. Those same devices often have long lifecycles, limited upgrade paths and slower adoption of modern cryptographic standards.

The result is a population of machines that may still be in service when the cryptography protecting their data stops being trustworthy.

A Warning From Forescout

Daniel dos Santos, VP of research at Forescout, tied the readiness gap directly to the clinical role these devices play.

“Our research shows that the devices least prepared for the transition are often the same devices healthcare organizations depend on most for delivering patient care. Visibility into those assets and the data they handle is essential for building a practical migration strategy.”

— Daniel dos Santos, VP of research at Forescout

Exposed Systems Hold Patient Records

Across the devices analyzed, the researchers identified more than 5500 internet-exposed systems. Those included platforms containing sensitive healthcare data, such as electronic medical records and picture archiving and communication systems.

Of these exposed systems, just 31% support TLS 1.3, the only TLS version capable of supporting standardized PQC.

Forescout warned that these systems are particularly vulnerable to harvest now, decrypt later attacks, in which threat actors steal encrypted data today with the intent of decrypting it in the future when quantum computers become powerful enough. The report noted that medical histories, diagnostic images, laboratory results and prescription records retain their value and sensitivity for decades, unlike other types of information.

The Inventory Problem

Forescout urged healthcare organizations to begin preparing for quantum-enabled attacks now. Its recommendations start with knowing what is actually connected.

  • Inventory and classify all connected IT, OT, IoT and IoMT assets, including their communication with other assets
  • Assess which assets support PQC today and identify systems that require upgrades, replacement or compensating controls
  • Segment and isolate legacy systems that cannot be upgraded
  • Incorporate PQC readiness into governance, procurement and risk management processes, including enforcing TLS 1.3 wherever possible
  • Engage vendors to understand their PQC roadmaps and migration timelines

The list reflects a practical sequencing problem: an organization cannot plan a migration for devices it has not accounted for, and it cannot count on vendors to move faster than its own procurement cycles.

The Numbers That Define the Gap

  • 2.5 million devices analyzed across more than 50 healthcare delivery organizations
  • 6% of IoMT devices use SSH implementations capable of supporting a PQC transition
  • 16% of medical OT devices meet the same bar
  • 50% of traditional IT devices can support PQC implementation
  • 5500+ internet-exposed systems identified
  • 31% of exposed systems support TLS 1.3

A Timeline Measured in Years

The report's framing rests on a forecast rather than a current capability: quantum computers are predicted to be capable of breaking existing encryption methods in the next five years. That prediction is what turns encrypted data sitting in a medical records system today into a future liability.

It is also what makes the device-level numbers matter. A device that cannot support PQC does not become safe simply because the threat is not yet realized. It becomes a candidate for compensating controls, segmentation, or replacement.

Where the Pressure Lands

For healthcare organizations, the report's findings suggest that the quantum transition is arriving on a schedule that overlaps with the working life of equipment already installed in clinical settings. The devices least likely to support PQC are the ones most tightly bound to patient care, and the data they process is the kind that stays sensitive for decades.

That combination could mean that a migration strategy built only around traditional IT systems leaves a substantial share of the environment untouched. Whether hospitals can close that gap depends on choices they make now — what they inventory, what they ask vendors, and what they are willing to segment or retire before the cryptography underneath it becomes obsolete.

#post-quantum cryptography#healthcare security#iomt#forescout#harvest now decrypt later

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories