Quantum readiness lags in medical devices, Forescout finds

Quantum readiness lags in medical devices, Forescout finds

The connected equipment hospitals depend on most is also the least ready for the move to quantum-resistant encryption, according to a new Forescout report titled Post-Quantum Cryptography (PQC) in Healthcare: From Data Risk to Migration Readiness.

The researchers looked at more than 2.5 million devices on more than 50 networks belonging to healthcare delivery organizations (HDOs), the hospitals, clinics and other providers that treat patients. They also tracked attack claims against healthcare providers worldwide between January and August 2026. That count included 461 public ransomware claims and 300 claims by hacktivists.

According to Forescout, attackers are using IT, IoMT (Internet of Medical Things), OT and IoT devices in these environments to deploy ransomware, extort payments and sell stolen patient data.

Why patient data is a long-term target

The report focuses on harvest-now, decrypt-later attacks. In this scenario, an adversary steals encrypted data today and stores it until quantum computers are strong enough to break the encryption.

Healthcare data suits this approach well. Daniel Trivellato, VP of OT, Healthcare, and Cyber Risk Solutions at Forescout, pointed out that patient information "retains its value and sensitivity for decades." Medical histories, diagnostic images, lab results and prescription records can't be reset like a password once they leak.

"Organizations need to understand where this data resides, how it moves across their environments, and which systems will be most difficult to transition to PQC standards," Trivellato said.

Medical devices trail IT systems

The gap shows up clearly in SSH, the protocol used for secure remote management of equipment. Only 6% of connected medical devices and 16% of OT devices ran SSH software capable of supporting PQC. For IT devices, the figure was 50%. Similar support has started to arrive in mainstream tools, as seen when OpenSSH added post-quantum signatures in its latest release.

Forescout notes that these numbers only show the software can support quantum-resistant protection. They don't confirm that the protection is actually switched on.

Part of the problem is how long hospital equipment stays in use. Infusion pumps, ventilators, patient monitors and building controls can run for years. Changing their cryptography may require a vendor update, recertification or new hardware, and each of these can slow down migration.

Forescout recommends that migration plans establish which systems can be upgraded and when vendors will offer support. Devices that can't be updated may have to be isolated or replaced, in a way that does not disrupt patient care.

"Our research shows that the devices least prepared for the transition are often the same devices healthcare organizations depend on most for delivering patient care," said Daniel dos Santos, VP of Research at Forescout.

Exposed systems and weak protocol support

The report also advises security teams to map where patient data is created, stored and sent, including through servers, routers and remote access gateways. Records and diagnostic images may need protection for decades. Appointment schedules and live monitor readings carry their own privacy, accuracy and availability requirements.

Links between devices can widen exposure. A CT scanner, for example, sends images to a picture archiving and communication system (PACS), which may be reachable over the internet.

Researchers counted more than 5,500 medical information systems exposed online. Electronic medical record platforms made up 46% of them and PACS made up 40%. Laboratory management and medication dispensing systems also appeared in the results.

On average, only 31% of the exposed systems supported TLS 1.3, the protocol version that provides a foundation for standardized PQC in network connections. Again, support alone does not mean quantum-resistant protection is in use.

Our Take

The findings suggest that healthcare's quantum problem is mostly an asset management problem. Hospitals can't migrate what they can't see, and many of their most critical devices depend on vendor timelines they don't control. This matches what we have seen in other sectors, where legacy equipment still blocks OT visibility.

The thousands of exposed EMR and PACS systems are a present-day risk as well as a future one. Data stolen from them today could stay sensitive long after a breach.

It is worth watching whether device makers commit to clear PQC roadmaps. Policy is another factor, with a healthcare cybersecurity bill moving through Congress that could put more pressure on the sector.