Only 6% of Internet of Medical Things (IoMT) devices and 16% of OT devices use SSH implementations capable of supporting PQC – far below the 50% observed across traditional IT devices.
Forescout Technologies, a cybersecurity company focused on asset intelligence, exposure management and network security, has announced new research from Forescout Research – Vedere Labs examining the challenges healthcare organisations face in preparing for the transition to post-quantum cryptography (PQC).
The report, Post-Quantum Cryptography (PQC) in Healthcare: From Data Risk to Migration Readiness, analyses more than 2.5 million devices across more than 50 healthcare delivery organisations (HDOs) and identifies significant readiness gaps that could leave sensitive healthcare data vulnerable to future quantum-enabled attacks.
Post-quantum cryptography (PQC) refers to a new generation of cryptographic algorithms designed to protect data against attacks from future quantum computers. New research finds IoMT and OT devices in healthcare organisations lag significantly behind traditional IT systems, putting patient data at risk.
Key findings
- Only 6% of IoMT devices and 16% of OT devices currently use SSH implementations that support PQC, compared to 50% of IT devices.
- More than 5,500 Internet-exposed healthcare systems were identified, including electronic medical records (EMRs) and picture archiving and communication systems (PACS) platforms containing sensitive healthcare data.
- Across exposed healthcare systems, only 31% support TLS 1.3, the only TLS version capable of supporting standardised PQC.
- Based on network presence, exposure and the sensitivity of the data involved, the five healthcare data types currently most at risk are EMRs, medical imaging, laboratory results, medication and prescription data and financial/payment information.
“Healthcare organisations face a unique challenge when preparing for the quantum computing era,” said Daniel Trivellato, VP of OT, Healthcare and Cyber Risk Solutions at Forescout. “Unlike many other types of data, patient information retains its value and sensitivity for decades, making it particularly vulnerable to harvest-now, decrypt-later attacks. In these attacks, adversaries collect encrypted data today with the intent of decrypting it once sufficiently powerful quantum computers are available. Medical histories, diagnostic images, laboratory results, prescription records and other healthcare data cannot simply be reset or replaced if exposed. Organisations need to understand where this data resides, how it moves across their environments and which systems will be most difficult to transition to PQC standards.”
Specialised devices create a quantum migration challenge
The report found that healthcare environments remain highly dependent on specialised operational technology (OT), Internet of Medical Things (IoMT) and IoT devices that often have long lifecycles, limited upgrade paths and slower adoption of modern cryptographic standards. Many of these systems are directly involved in patient care, including infusion pumps, patient monitors, imaging systems and laboratory equipment.
Quantum computers able to break current cryptography are not yet available, but they are rapidly approaching and healthcare organisations are seeing increased pressure from governments, standards bodies and regulators to begin migration planning now. The problem is that many devices do not yet have quantum-safe alternatives and others are often costly or difficult to replace. This makes compensating controls, such as network segmentation, access restrictions and enhanced monitoring, a critical part of PQC migration planning.
“PQC migration is not simply an encryption upgrade project,” said Daniel dos Santos, VP of Research at Forescout. “Healthcare providers need to understand which assets store, process and transport their most sensitive data, which systems can realistically be upgraded and where compensating controls will be required. Our research shows that the devices least prepared for the transition are often the same devices healthcare organisations depend on most for delivering patient care. Visibility into those assets and the data they handle is essential for building a practical migration strategy.”
Recommendations for healthcare organisations
To prepare for the transition to PQC, Forescout recommends that healthcare organisations:
- Inventory and classify all connected IT, OT, IoT and IoMT assets, including their communication with other assets.
- Prioritise Internet-facing systems, partner connections, patient portals and external APIs.
- Enforce TLS 1.3 wherever possible.
- Assess which assets support PQC today and identify systems that require upgrades, replacement or compensating controls.
- Incorporate PQC readiness into governance, procurement and risk management processes.
- Segment and isolate legacy systems that cannot be upgraded.
- Engage vendors to understand their PQC roadmaps and migration timelines.
The Vedere Labs research findings reinforce the need for healthcare organisations to begin preparing now for a transition that will likely take years to complete. As quantum computing capabilities continue to advance, organisations that understand their assets, prioritise their most sensitive data and develop phased migration plans will be better positioned to protect patient information and maintain regulatory compliance.


