Most Medical Devices Cannot Support Quantum-Safe Encryption, Forescout Finds
Most medical devices cannot be upgraded to post-quantum cryptography (PQC), according to an investigation by Forescout. PQC refers to new encryption methods designed to resist attacks from quantum computers, which are predicted to be able to break current encryption within the next five years. The researchers analysed more than 2.5 million devices across more than 50 healthcare delivery organisations. They found that only 6% of Internet of Medical Things (IoMT) devices and 16% of medical operational technology (OT) devices use Secure Shell (SSH) implementations capable of supporting a move to PQC. By comparison, 50% of traditional IT devices can support it.
The concern is greatest for devices central to patient care, such as infusion pumps, patient monitors, imaging systems and laboratory equipment. These often have long lifecycles, limited upgrade paths and slower adoption of modern cryptographic standards. The researchers also identified more than 5500 internet-exposed systems, including platforms holding electronic medical records and picture archiving and communication systems. Only 31% of these support TLS 1.3, the only TLS version able to support standardised PQC.
The report warns of "harvest now, decrypt later" attacks, where criminals steal encrypted data today and decrypt it once quantum computers are powerful enough. Healthcare data is especially exposed because medical histories, diagnostic images, lab results and prescriptions stay sensitive for decades. Forescout's Daniel dos Santos said visibility into these assets and the data they handle is essential for building a practical migration strategy.