A recent investigation by Forescout has revealed a critical vulnerability in the healthcare sector’s ability to transition to post-quantum cryptography (PQC). The study analyzed over 2.5 million devices across more than 50 healthcare delivery organizations and found that only 6% of Internet of Medical Things (IoMT) devices and 16% of medical operational technology (OT) devices are equipped to support PQC. This stands in stark contrast to the 50% of traditional IT devices that are ready for such a transition.

PQC involves new cryptographic algorithms crafted to defend against future threats posed by quantum computers, which are anticipated to be capable of breaking current encryption methods within the next five years. The report, released on October 6, underscores the heavy reliance of healthcare environments on IoMT, OT, and IoT devices. These systems, which include essential tools like infusion pumps and patient monitors, are integral to patient care but often lag in adopting updated cryptographic standards due to long lifecycles and limited upgrade options.

Forescout's VP of research, Daniel dos Santos, emphasized the importance of visibility into these assets to formulate a viable migration strategy. The investigation also uncovered over 5500 internet-exposed systems containing sensitive healthcare data, such as electronic medical records and diagnostic images. Among these, a mere 31% support TLS 1.3, the only version capable of standardized PQC support. This deficiency leaves these systems vulnerable to 'harvest now, decrypt later' attacks, where encrypted data is stolen now with the intent of decryption once quantum computing advances.

The persistence of healthcare data value over decades amplifies the risk. Forescout strongly advises healthcare organizations to begin preparations for quantum-enabled threats to safeguard sensitive patient information.