Critical Healthcare Systems Aren’t Quantum-Ready
A study of 2.5 million devices across 50 healthcare organization suggests the sector has a long way to go in getting ready for the post-quantum cryptography era.
A study of 2.5 million devices across 50 healthcare organization suggests the sector has a long way to go in getting ready for the post-quantum cryptography era.
IT and Internet of Things (IoT) systems across the healthcare sector appear largely unprepared for the post-quantum cryptography (PQC) era, leaving sensitive data potentially vulnerable to “harvest now, decrypt later” attacks.
The situation is particularly acute for Internet-exposed healthcare systems, many of which lack support for TLS 1.3, the foundation for deploying standardized post-quantum cryptography.
Researchers from Forescout Technologies recently analyzed some 2.5 million devices deployed across more than 50 healthcare delivery organizations and uncovered significant gaps in readiness for PQC.
Healthcare: A State of General Quantum Unpreparedness
Only half of the IT devices surveyed, for instance, were running SSH implementations capable of supporting PQC. The numbers were significantly lower for operational technology (OT), at 16%, and Internet of Medical Things (IoMT) devices, at just 6%.
Examples of OT/IoT assets in healthcare delivery organizations include VoIP phones, printers, point-of-sale systems, kiosks and physical-security equipment. IoMT devices include patient monitors, insulin pumps, defibrillators, ventilators, and laboratory and imaging equipment many of which handle or transmit highly sensitive patient and clinical information, including medical readings, diagnostic data and treatment-related information.
Forescout also identified more than 5,500 healthcare systems containing electronic medical records and medical imaging data that were reachable from the public Internet. Just 31% of those systems were using TLS 1.3, leaving much of the exposed healthcare infrastructure without support for current PQC standards.
PQC readiness is particularly important in healthcare because medical records, diagnostic images and other sensitive patient data can remain valuable and confidential for decades. Threat actors who steal encrypted health data today could potentially decrypt and exploit it years later, once sufficiently powerful quantum computers become available. Healthcare is already one of the most targeted sectors especially for ransomware actors so the potential for such harvest now decrypt later attacks is not just theoretical.
“The main takeaway is that healthcare organizations should start preparing now, before large-scale quantum attacks become practical,” warns Daniel Trivellato, Forescout’s vice president of OT, healthcare, and cyber-risk solutions. CISOs and other security decision makers should lead the effort, but they should ensure that getting PQC-ready is not just a security initiative. “Successful migration will require coordination among infrastructure teams, clinical engineering, biomedical engineering, enterprise architecture, application owners, procurement, compliance, and medical device vendors,” he says.
Key Challenge: Difficult-to-Upgrade Legacy Medical Gear
One key challenge, according to Forescout, is that many medical devices are more difficult to upgrade than conventional IT systems because they are specialized systems with long lifespans and tightly controlled software environments. Devices such as imaging systems and patient-care equipment also often run on older operating systems or embedded components and upgrades can require vendor involvement, regulatory review or even replacement of the equipment.
“Many of these specialized devices are among the most difficult assets to upgrade and are often critical to patient care,” Trivellato says. “That means closing the gap will require far more than software updates. It will demand years of coordinated effort across healthcare providers, device manufacturers, regulators, and service providers.” Organizations must be prepared for significant investments in modernization, validation, recertification, and lifecycle replacement planning, he notes.
The fact that 50% IT systems in Forescout’s survey were PQC-ready yet only 31% of Internet-exposed healthcare systems supported TLS 1.3 is also noteworthy. The gap highlights why improving internal IT readiness alone does not always automatically translate into organizational readiness.
“Many healthcare organizations have invested in modernizing portions of their core IT infrastructure, which helps explain the higher PQC readiness of traditional IT assets,” Trivellato says. However, many of the systems exposed to the Internet are not traditional IT but rather clinical software, healthcare information platforms, third-party managed services, and other purpose-built technologies that tend to remain in service longer. These platforms are particularly important from a PQC perspective because organizations using them to exchange data across organizational boundaries, patient portals, cloud environments, teleradiology providers, and external partners.
“These are precisely the environments where we continue to see lower levels of TLS 1.3 adoption and where migration is likely to be most challenging,” Trivellato notes. “The result is that while healthcare has made meaningful investments in modernizing some parts of its environment, securing the pathways through which sensitive data is exchanged remains a significant challenge.”
A good place to start, for healthcare delivery organizations with limited resources, is to prioritize PQC migration based on risk rather than simply by device type. Organizations should first protect sensitive, long-lived data such as EHRs, medical images, lab and prescription records. Also important are Internet-facing systems such as patient portals, APIs and VPN gateways that can be upgraded relatively quickly, Trivellato says. The next step is understanding where that data resides, where it travels, and which systems expose it to external networks. “The key,” Trivellato says, “is to start with visibility, prioritize high-value data and internet-exposed connections, and focus early efforts on the systems that can realistically be upgraded while building a road map for the assets that cannot.”