NEWS

Critical Healthcare Systems Aren't Quantum-Ready

A Forescout Vedere Labs study of 2.5 million healthcare devices found just 6% of IoMT and 16% of OT devices are ready for post-quantum cryptography.

Dylan H.

News Desk

October 6, 2026
8 min read
Critical Healthcare Systems Aren't Quantum-Ready

Forescout Study Finds Healthcare's Networked Devices Unprepared for the Post-Quantum Era

A new study from Forescout Technologies' threat-intelligence division, Vedere Labs, reported by DarkReading on October 6, 2026, found that healthcare's networked IT, operational technology (OT), and medical-device infrastructure is dangerously unprepared for the shift to post-quantum cryptography (PQC). Researchers analyzed more than 2.5 million devices across more than 50 healthcare delivery organizations (HDOs) — averaging roughly 50,000 devices per provider — and found that only 6% of Internet of Medical Things (IoMT) devices and 16% of OT devices run SSH implementations capable of supporting PQC, compared with 50% of traditional IT devices.

The gap leaves vast troves of patient data exposed to "harvest now, decrypt later" (HNDL) attacks, in which adversaries capture encrypted traffic today with the intent to decrypt it once quantum computers mature enough to break current public-key cryptography. Compounding the risk, the researchers also identified more than 5,500 Internet-exposed healthcare systems — including electronic medical record (EMR) and medical-imaging platforms — of which only 31% support TLS 1.3, the protocol version required to deploy standardized PQC key exchange.


Study Details

AttributeValue
ResearchersForescout Technologies — Vedere Labs (threat-intelligence division)
ReportedOctober 6, 2026 (DarkReading)
Devices analyzed2.5+ million, across 50+ healthcare delivery organizations (avg. ~50,000 devices/provider)
IT devices with PQC-capable SSH50%
OT devices with PQC-capable SSH16%
IoMT devices with PQC-capable SSH6%
Internet-exposed healthcare systems found5,500+ instances, spanning roughly 50 distinct system types
Exposed systems supporting TLS 1.331% (prerequisite for standardized PQC key exchange)
Exposed systems still on TLS 1.0/1.115%
Most-exposed system typesEMR systems (46% of exposed systems), PACS/imaging (40% of exposed systems)
Researcher quotedDaniel dos Santos, VP of Security Research, Vedere Labs
Core threat model"Harvest now, decrypt later" (HNDL) attacks against long-lived patient data

What the Research Found

A widening readiness gap between IT, OT, and IoMT

The study's central finding is a steep drop-off in quantum readiness the further a device sits from a traditional IT environment. Half of conventional IT assets already run SSH implementations capable of supporting PQC. That figure falls to 16% for OT assets — things like VoIP phones, printers, point-of-sale systems, kiosks, and physical-security equipment found throughout hospital networks — and collapses to just 6% for IoMT devices: patient monitors, insulin pumps, defibrillators, ventilators, infusion pumps, and laboratory and imaging equipment. These are precisely the devices healthcare organizations are least able to patch or replace quickly, given long device lifecycles, limited firmware-upgrade paths, and strict clinical-validation requirements before any software change can ship.

Internet-exposed systems compound the risk

Beyond device-level cryptographic agility, Forescout mapped healthcare systems directly reachable from the public Internet and found more than 5,500 exposed instances across roughly 50 different system types — most concentrated in EMR platforms (46% of exposed systems) and picture archiving and communication systems, or PACS (40% of exposed systems). TLS 1.3 adoption among those exposed systems was uneven and generally low: around 33% for EMR systems, 36% for PACS, and as low as 13% for laboratory-management systems, with roughly 15% of all exposed systems still running the outdated TLS 1.0 or TLS 1.1 protocols. Because standardized PQC key exchange depends on TLS 1.3, any system stuck on an older protocol version has no near-term path to quantum-resistant encryption at all, regardless of what cipher suites it otherwise supports.

Why "harvest now, decrypt later" matters for patient data

The urgency behind these numbers isn't a near-term quantum computer capable of breaking RSA or elliptic-curve cryptography today — none exists yet. It's the HNDL threat model: an adversary with network access or an interception point can record encrypted traffic now and simply wait, decrypting it retroactively once sufficiently powerful quantum hardware arrives. Healthcare data is an especially attractive target for this strategy because, unlike a credit card number that can be canceled, electronic health records, medical imaging, laboratory results, medication and prescription histories, and financial/payment data retain their sensitivity and value for decades. A diagnosis, a genetic test result, or a psychiatric treatment record captured in transit today is just as damaging if decrypted ten or fifteen years from now.

Legacy devices, limited options

Dos Santos's team framed the core operational dilemma bluntly: the devices least prepared for the PQC transition are often the same devices healthcare organizations depend on most for delivering patient care. Ripping out and replacing a hospital's fleet of infusion pumps or imaging systems to get PQC-capable firmware is not realistic on any short timeline, which is why the researchers' guidance leans heavily on compensating controls — asset visibility, exposure reduction, and segmentation — rather than wholesale hardware replacement.


Impact Assessment

Impact AreaDescription
Patient data confidentialityEHRs, imaging, lab results, prescriptions, and payment data captured today could be decrypted retroactively once quantum computing matures; healthcare records keep their sensitivity for decades
Clinical operationsThe least-prepared devices — infusion pumps, ventilators, defibrillators, patient monitors, lab/imaging gear — are also the devices most directly tied to active patient care, raising the stakes of any mitigation that touches them
Legacy device lifecycleIoMT and OT devices often remain in service 10-15+ years with limited firmware-upgrade paths, meaning many scanned devices will still be operating well past NIST's 2030/2035 transition milestones
Regulatory exposureHIPAA-covered entities face compounding liability if long-lived, inadequately encrypted patient data is harvested now and exposed later, even absent any detectable breach today
Internet attack surface5,500+ exposed EMR, PACS, and lab-management systems — many without TLS 1.3 — are reachable today by any attacker positioning for future decryption, not just present-day interception

Recommendations

For healthcare security and IT teams

  • Build a complete asset inventory across IT, OT, and IoMT before attempting any PQC migration planning — you cannot assess readiness for devices you don't know exist on the network. Vedere Labs' VP of Security Research, Daniel dos Santos, named this as the essential first step.
  • Assess data sensitivity and retention requirements per system, prioritizing systems that handle EHRs, imaging, lab results, prescriptions, and payment data for HNDL risk scoring.
  • Evaluate Internet exposure first — enforce TLS 1.3 on any public-facing EMR, PACS, or laboratory-management system as the baseline prerequisite for standardized PQC, and eliminate TLS 1.0/1.1 wherever it still appears.
  • Identify upgrade pathways device by device, flagging any asset whose vendor has no published PQC or crypto-agility roadmap.

For OT and biomedical engineering teams

  • Segment legacy IoMT and OT devices that cannot support PQC behind secure remote-access gateways and zero-trust network boundaries — dos Santos specifically recommended segmentation as the practical containment strategy for devices that can't be upgraded on any realistic timeline.
  • Engage device manufacturers directly on PQC and firmware roadmaps, and track vendor end-of-support dates against NIST's 2030/2035 deprecation milestones rather than assuming current support will extend indefinitely.
  • Treat any device still negotiating SSH without PQC-capable ciphers, or TLS below 1.3, as a priority candidate for compensating controls until a native upgrade path exists.

For compliance and executive leadership

  • Align crypto-migration planning with NIST's phased PQC transition. NIST finalized its first three post-quantum standards — FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) — in August 2024. Draft follow-on guidance, NIST IR 8547, calls for deprecating 112-bit-equivalent algorithms such as RSA-2048 and ECC P-256 after 2030, with full disallowance by 2035.
  • Budget for a multi-year migration, not a single project. Hybrid deployments pairing a classical algorithm with a post-quantum one are the recommended interim approach while legacy systems are phased out.
  • Build PQC readiness and crypto-agility into vendor risk assessments and procurement requirements for any new medical device, imaging system, or OT asset purchased from this point forward.

Key Takeaways

  1. Forescout's Vedere Labs analyzed 2.5+ million devices across 50+ healthcare organizations and found just 6% of IoMT and 16% of OT devices support PQC-capable SSH, versus 50% of traditional IT devices.
  2. Researchers identified 5,500+ Internet-exposed healthcare systems (EMR, PACS, lab platforms), of which only 31% support TLS 1.3 — the protocol baseline required for standardized post-quantum key exchange.
  3. The core risk is "harvest now, decrypt later": attackers can capture encrypted patient data today and decrypt it once quantum computing matures, and healthcare data retains sensitivity and value for decades.
  4. The devices least prepared for the transition — infusion pumps, ventilators, defibrillators, patient monitors, and imaging/lab equipment — are also the devices most critical to direct patient care, limiting how quickly they can be upgraded or replaced.
  5. NIST finalized its first PQC standards (FIPS 203/204/205) in August 2024, and draft guidance (NIST IR 8547) sets 2030 for deprecating 112-bit RSA/ECC and 2035 for full disallowance.
  6. Recommended near-term mitigations center on complete asset inventory, Internet-exposure reduction, TLS 1.3 enforcement, and network segmentation or secure remote-access gateways for legacy devices that cannot be upgraded.

Sources