The Current State of Medical Device Security
Forescout's analysis of over 2.5 million devices across more than 50 healthcare delivery organization (HDO) networks reveals a critical gap in readiness for post-quantum cryptography (PQC). Only 6% of connected medical devices and 16% of operational technology devices use SSH software capable of supporting PQC, compared to 50% of IT devices. Additionally, researchers found over 5,500 medical information systems exposed online, with electronic medical record platforms making up 46% and picture archiving and communication systems (PACS) 40%. Of these systems, only 31% on average supported TLS 1.3, the protocol version foundational for standardized PQC.
Between January and August 2026, there were 461 public ransomware claims and 300 hacktivist attack claims against healthcare providers worldwide, highlighting that these vulnerabilities are actively exploited.
The Timeline of Exposure
This isn't a single incident but an ongoing exposure that began when healthcare organizations deployed cryptographic protection that quantum computers will eventually break. The "harvest-now, decrypt-later" threat model means attackers are already collecting encrypted patient data, planning to decrypt it once quantum computers are powerful enough.
Key timeline markers include:
- Current Operations: HDOs use medical devices that will remain in service for years, protected by cryptography vulnerable to future quantum computers.
- Vendor Release Cycles: Equipment upgrades depend on manufacturers releasing quantum-resistant updates.
- Patient Data Lifespan: Medical data retains its value and sensitivity for decades.
- Quantum Computing Horizon: The exact arrival date of quantum computing is uncertain, but preparation must begin now.
Missing or Failed Controls
Cryptographic Protection Lifecycle Planning: Devices were deployed without considering how long encrypted data needs protection versus the security lifespan of cryptographic algorithms. A CT scanner installed today may still be in use when quantum computers can break its encryption, but the patient data it generates will remain sensitive long after.
Vendor Dependency Management: HDOs lack contractual mechanisms to ensure vendors provide quantum-resistant updates within a defined timeframe. You can't upgrade an infusion pump's cryptography if the manufacturer hasn't released the update.
Network Segmentation and Exposure Reduction: Over 5,500 medical information systems are accessible online, creating a direct path for attackers to harvest encrypted data. Systems containing sensitive patient information should not be internet-accessible without compensating controls.
Asset and Data Flow Visibility: Security teams lack complete inventories showing which systems handle patient data, where that data moves, and what encryption protects it. Without this mapping, you can't prioritize which systems need quantum-resistant upgrades first.
Standards and Requirements
NIST SP 800-53 (SC-12, SC-13, SC-17): Requires managing cryptographic keys, using FIPS-validated cryptography, and maintaining protection commensurate with data sensitivity and longevity. If patient data remains sensitive for decades but cryptography becomes obsolete sooner, the requirement isn't met.
HIPAA Security Rule (§ 164.312(a)(2)(iv), § 164.312(e)(2)(ii)): Requires encryption of Protected Health Information at rest and in transit but doesn't specify algorithms. Implementing encryption without considering quantum threats may comply with the rule but fail to protect data over its actual sensitivity lifespan.
NIST Cybersecurity Framework (CSF) 2.0 (PR.DS-01, PR.DS-02): Calls for data protection consistent with risk strategy and protection of data in transit. Your risk strategy must account for "harvest-now, decrypt-later" attacks if you're responsible for data that will remain sensitive beyond the quantum computing horizon.
ISO/IEC 27001 (A.8.24, A.10.1): Requires cryptographic controls appropriate to information classification and protection against threats to cryptographic keys throughout their lifecycle. Deploying medical devices with cryptography that can't be upgraded before quantum computers arrive violates lifecycle management requirements.
Action Items for Your Team
Build a Cryptographic Asset Inventory: Map every system that stores, processes, or transmits patient data. Document cryptographic protocols and whether hardware and software can support quantum-resistant algorithms. This inventory will reveal which systems can be upgraded through software patches, which require hardware replacement, and which depend on vendor timelines.
Classify Data by Sensitivity Duration: Calculate how long each data category requires protection and compare that duration against quantum computing arrival estimates. Prioritize quantum-resistant upgrades for systems handling data with the longest sensitivity windows.
Negotiate PQC Timelines into Vendor Contracts: Include specific language in procurement contracts requiring vendors to provide quantum-resistant updates by a defined date. For existing equipment, discuss PQC roadmaps with vendors. If a vendor can't commit, plan for replacement or compensating controls.
Eliminate Unnecessary Internet Exposure: Remove systems from public networks if they don't need to be internet-accessible. If remote access is necessary, use a VPN or zero-trust access control with quantum-resistant cryptography.
Identify Non-Upgradeable Systems and Plan Compensating Controls: Isolate systems on network segments with quantum-resistant gateways that re-encrypt data before it leaves the protected zone.
Test Your Migration Assumptions: Deploy TLS 1.3 on a subset of systems and verify functionality. Discover incompatibilities in a controlled test environment, not during an emergency migration.
The quantum threat isn't a distant future concern. It's a current cryptographic debt that grows with every patient record generated using algorithms vulnerable to quantum computers. Your migration timeline is dictated by the sensitivity lifespan of your patient data and the protection duration of your current cryptography.




