AN investigation by Forescout has found that the majority of critical medical devices cannot be upgraded to post-quantum cryptography (PQC), leaving patient data potentially vulnerable to future quantum-enabled attacks.
The analysis covered more than 2.5 million devices across more than 50 healthcare delivery organisations and found that only 6% of Internet of Medical Things (IoMT) devices and 16% of medical operational technology (OT) devices currently use SSH implementations capable of supporting a PQC transition. By comparison, roughly half of traditional IT devices can support PQC.
PQC comprises cryptographic algorithms designed to resist quantum computer threats, which researchers warn could break existing encryption within the next five years. The report highlights that many healthcare systems rely on IoMT, OT and IoT devices—such as infusion pumps, patient monitors, imaging systems and laboratory equipment—that often have long lifecycles, limited upgrade paths and slower uptake of modern cryptographic standards.
Across the examined devices, researchers identified more than 5,500 internet-facing systems containing sensitive data such as electronic medical records (EMRs) and PACS. Of these exposed systems, only 31% support TLS 1.3, the TLS version compatible with standard PQC. The findings warn of “harvest now” risks, where threat actors copy encrypted data today with the intention of decrypting it later when quantum capability improves.
To mitigate this, Forescout recommends healthcare organisations inventory and classify connected assets, assess PQC readiness, segment legacy systems, embed PQC considerations into governance and procurement, enforce TLS 1.3 where possible, and engage vendors on PQC roadmaps. The language and recommendations emphasise practical migration planning rather than immediate full deployment.