NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Many Medical Devices Incapable of Supporting Transition to Post-Quantum Cryptography

An analysis of medical devices indicates that healthcare organizations face a significant risk of future quantum-enabled attacks, as only a small percentage are capable of supporting a transition to post-quantum cryptography (PQC). The analysis was conducted by cybersecurity firm Forescout on more than 2.5 million Internet of Medical Things (IoMT) devices used by more than 50 healthcare delivery organizations. The findings are published in its October 2026 PQC in Healthcare Report.

Quantum computers vastly surpass the computational ability of standard computers as they process information using quantum states. They are capable of tackling complex problems that even today’s supercomputers are unable to solve. A problem tackled by a quantum computer may take minutes or hours compared to millennia by today’s most powerful computers. One such application would be cracking today’s encryption models.

Quantum computers are still under development, but Google has predicted that advances currently being made could render current encryption methods obsolete in the next five years, potentially as early as 2029. While it may appear that there is no immediate risk, encrypted data could potentially be harvested now for decryption later when quantum computing has sufficiently advanced. Forescout warns that the risk is greater in healthcare due to the long-term value of healthcare data, compared to data such as account numbers and payment card information which can be easily changed.

According to the analysis, only 6% of IoMT devices and 16% of operational technology (OT) devices use SSH implementations that support PQC. These devices are relied on by healthcare organizations for a range of functions; however, the lowest percentage of IoMT devices capable of supporting PQC are those used for providing patient care. By comparison, around 50% of IT devices are capable of supporting PQC.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

PQC involves the use of new cryptographic algorithms capable of protecting against attacks from quantum computers; however, healthcare is particularly exposed because many medical devices in use are not capable of supporting PQC, including systems and devices that contain large volumes of highly sensitive healthcare data such as electronic medical records (EMRs), Picture Archiving and Communications Systems (PACS), and devices used for patient care such as patient monitors, imaging systems, infusion pumps, and lab equipment.

These systems and devices tend to have long lifecycles; however, they also have limited paths for upgrading, including upgrades to support new cryptographic standards. Many of these devices and systems are also exposed to the Internet, which makes them vulnerable to attack. The researchers identified 5,500 Internet-exposed systems, including EMRs and PACS. Overall, out of all exposed medical information systems, only 31% supported TLS 1.3 – the only TLS version capable of supporting standardized PDC. The analysis found that 6% of PACS supported TLS 1.3, falling to 33% for EMRs, and 13% for laboratory management systems.

The key to protecting data against quantum-enabled attacks is preparation. “PQC migration is not simply an encryption upgrade project,” said Daniel dos Santos, VP of Research at Forescout. “Healthcare providers need to understand which assets store, process, and transport their most sensitive data, which systems can realistically be upgraded, and where compensating controls will be required. Our research shows that the devices least prepared for the transition are often the same devices healthcare organizations depend on most for delivering patient care. Visibility into those assets and the data they handle is essential for building a practical migration strategy.”

Forescout recommends that healthcare organizations start preparing now by creating a comprehensive and accurate inventory of all systems and devices, including IT, OT, IoT, and IoMT devices, along with data types and connections, prioritizing internet-exposed connections. All assets should be assessed to determine if they are capable of supporting PQC, and any assets that are not should be prioritized for upgrades or compensating controls, especially Internet-exposed connections such as patient portals, external-facing APIs, VPN gateways, and inter-organization data exchange. TLS 1.3 should be enforced, where possible. Any systems that cannot be upgraded should be segmented and isolated, and PDQ readiness should be incorporated into governance, procurement, and risk management processes. ForeScout also recommends ensuring that vendors understand PQC roadmaps if they have not offered alternatives, as well as timelines for migration to PQC.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist