New data reveals that the healthcare sector remains behind in preparing for the transition to post-quantum encryption, even though practical quantum computers may eventually be able to break the encryption algorithms protecting patient data. The lag is more pronounced among connected medical devices, only 6% of which have suitable protection against future quantum attacks, compared with 50% of information technology systems.
Forescout’s Threat Research Unit analyzed more than 2.5 million devices distributed across more than 50 healthcare organizations. The analysis included devices such as infusion pumps and patient monitors, as well as workstations and servers. Although information technology systems account for 66% of connected devices in healthcare environments, medical devices may represent a significant weakness because they are difficult to update and healthcare depends directly on them.
Long-Lived Data Is an Attractive Target
Medical records, diagnostic images, laboratory results, and prescription histories are among the data types most exposed to risk because they remain sensitive and valuable for long periods. The report also found that only 31% of more than 5,500 healthcare systems exposed to the internet, such as patient portals and some application programming interfaces, support an encryption protocol capable of accommodating post-quantum encryption.
This does not mean that attackers will use quantum computers to attack hospitals tomorrow. However, Daniel Trevillyan, vice president of operational technology and healthcare solutions and cyber risk at Forescout, warned of the “harvest now, decrypt later” strategy, in which stolen encrypted data is stored today in the hope of decrypting it when quantum computing becomes capable of doing so.
What Is Changing in Practice?
Forescout recommends that organizations begin by inventorying high-risk assets and systems, and that they integrate quantum readiness into technology refresh cycles, procurement, and system replacement instead of waiting for practical quantum computers to emerge. The National Institute of Standards and Technology (NIST) provides an existing starting point after publishing the first set of post-quantum encryption standards in 2024.
This step is particularly important in a sector already facing widespread attacks. Forescout recorded 461 public claims of ransomware attacks against healthcare organizations worldwide during the period from January to August of the year referenced, an increase of 47% over the same period of the previous year. More than 60% of the attacks targeted U.S. organizations. According to IBM, the cost of healthcare data breaches averages approximately $6.64 million.
The editorial conclusion here is not that a quantum crisis is imminent, but that the long lifespan of medical data and the difficulty of updating devices make the transition a slow process for which planning cannot be postponed. It also remains unresolved whether regulators will impose specific post-quantum encryption requirements on the healthcare sector or incorporate them into existing cybersecurity obligations.