Post-Quantum Cryptography in Healthcare: Forescout Research Reveals Critical Readiness Gaps Putting Patient Data at Risk
Only 6% of Internet of Medical Things (IoMT) devices and 16% of OT devices use SSH implementations capable of
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.
![]()
Forescout Technologies, Inc., a cybersecurity company focused on asset intelligence, exposure management, and network security, today announced new research from Forescout Research – Vedere Labs examining the challenges healthcare organizations face in preparing for the transition to post-quantum cryptography (PQC). The report, “Post-Quantum Cryptography (PQC) in Healthcare: From Data Risk to Migration Readiness,” analyzes more than 2.5 million devices across more than 50 healthcare delivery organizations (HDOs) and identifies significant readiness gaps that could leave sensitive healthcare data vulnerable to future quantum-enabled attacks.
Post-quantum cryptography (PQC) refers to a new generation of cryptographic algorithms designed to protect data against attacks from future quantum computers. New research finds IoMT and OT devices in healthcare organizations lag significantly behind traditional IT systems, putting patient data at risk.
Key findings:
- Only 6% of IoMT devices and 16% of OT devices currently use SSH implementations that support PQC, compared to 50% of IT devices.
- More than 5,500 internet-exposed healthcare systems were identified, including electronic medical records (EMRs) and picture archiving and communication systems (PACS) platforms containing sensitive healthcare data.
- Across exposed healthcare systems, only 31% support TLS 1.3, the only TLS version capable of supporting standardized PQC.
- Based on network presence, exposure, and the sensitivity of the data involved, the five healthcare data types currently most at risk are EMRs, medical imaging, laboratory results, medication and prescription data, and financial/payment information.
“Healthcare organizations face a unique challenge when preparing for the quantum computing era,” said Daniel Trivellato, VP of OT, Healthcare, and Cyber Risk Solutions at Forescout. “Unlike many other types of data, patient information retains its value and sensitivity for decades, making it particularly vulnerable to harvest-now, decrypt-later attacks. In these attacks, adversaries collect encrypted data today with the intent of decrypting it once sufficiently powerful quantum computers are available. Medical histories, diagnostic images, laboratory results, prescription records, and other healthcare data cannot simply be reset or replaced if exposed. Organizations need to understand where this data resides, how it moves across their environments, and which systems will be most difficult to transition to PQC standards.”
Specialized Devices Create a Quantum Migration Challenge
The report found that healthcare environments remain highly dependent on specialized operational technology (OT), Internet of Medical Things (IoMT), and IoT devices that often have long lifecycles, limited upgrade paths, and slower adoption of modern cryptographic standards. Many of these systems are directly involved in patient care, including infusion pumps, patient monitors, imaging systems, and laboratory equipment.
Quantum computers able to break current cryptography are not yet available but they are rapidly approaching and healthcare organizations are seeing increased pressure from governments, standards bodies, and regulators to begin migration planning now. The problem is that many devices do not yet have quantum-safe alternatives, and others are often costly or difficult to replace. This makes compensating controls, such as network segmentation, access restrictions, and enhanced monitoring, a critical part of PQC migration planning.
“PQC migration is not simply an encryption upgrade project,” said Daniel dos Santos, VP of Research at Forescout. “Healthcare providers need to understand which assets store, process, and transport their most sensitive data, which systems can realistically be upgraded, and where compensating controls will be required. Our research shows that the devices least prepared for the transition are often the same devices healthcare organizations depend on most for delivering patient care. Visibility into those assets and the data they handle is essential for building a practical migration strategy.”
Recommendations for Healthcare Organizations
To prepare for the transition to PQC, Forescout recommends that healthcare organizations:
- Inventory and classify all connected IT, OT, IoT, and IoMT assets, including their communication with other assets.
- Prioritize internet-facing systems, partner connections, patient portals, and external APIs.
- Enforce TLS 1.3 wherever possible.
- Assess which assets support PQC today and identify systems that require upgrades, replacement, or compensating controls.
- Incorporate PQC readiness into governance, procurement, and risk management processes.
- Segment and isolate legacy systems that cannot be upgraded.
- Engage vendors to understand their PQC roadmaps and migration timelines.
The Vedere Labs research findings reinforce the need for healthcare organizations to begin preparing now for a transition that will likely take years to complete. As quantum computing capabilities continue to advance, organizations that understand their assets, prioritize their most sensitive data, and develop phased migration plans will be better positioned to protect patient information and maintain regulatory compliance.
Read the full report, ‘Post-Quantum Cryptography (PQC) in Healthcare: From Data Risk to Migration Readiness,’ and explore Forescout’s Five Steps to PQC Readiness eBook for guidance on preparing for the transition. Learn how to regain control in the era of Frontier AI in Forescout’s whitepaper on The Control Gap.
Frequently Asked Questions
Q: What is post-quantum cryptography (PQC)?
A: Post-quantum cryptography refers to cryptographic algorithms designed to remain secure against attacks from both classical and quantum computers.
Q: Why is healthcare particularly vulnerable to quantum threats?
A: Healthcare organizations store large volumes of highly sensitive patient information that remains valuable for decades. This makes healthcare data an attractive target for harvest-now, decrypt-later attacks.
Q: What healthcare data is most at risk?
A: According to the report, the five data types currently most at risk are electronic medical records (EMRs), medical imaging, laboratory results, medication and prescription data, and financial/payment information.
Q: Where can I get the full report?
A: The report, “Post-Quantum Cryptography (PQC) in Healthcare: From Data Risk to Migration Readiness,” is available here.
Q: How can Forescout help healthcare organizations prepare for PQC migration?
A: Forescout provides continuous asset inventory and classification across IT, OT, IoT, and IoMT environments, helping healthcare organizations identify which systems handle sensitive data, assess PQC readiness, and prioritize migration and compensating controls through the Forescout Vistaro™ platform.
About Forescout
As AI-driven vulnerability discovery and exploitation accelerate attack velocity to machine speed, Forescout is a foundational cyber defense layer that allows organizations to segment and isolate compromised systems, block lateral movement, and automate response across IT, OT, IoT, and IoMT environments. The Forescout Vistaro™ platform, powered by agentic AI and enhanced with Vedere Labs threat intelligence, delivers a Universal Zero Trust Network Access (UZTNA) architecture that integrates seamlessly with 180+ security and IT products. With Forescout Vistaro, organizations get comprehensive inventory and classification of both managed and unmanaged assets, continuous exposure management, and real-time protection including dynamic network segmentation and automated threat response.
View source version on businesswire.com: https://www.businesswire.com/news/home/20261006904671/en/
Media gallery