Research
Forescout finds healthcare systems underprepared for quantum threats
Only 31% of more than 5,500 internet-facing healthcare systems analyzed support an encryption protocol capable of supporting post-quantum cryptography.
Forescout research suggests healthcare organizations are behind in preparing for quantum-computing threats. Researchers analyzed more than 2.5 million devices across more than 50 healthcare organizations and found connected medical devices, including infusion pumps and patient monitors, were less prepared for post-quantum cryptography than traditional IT systems. IT accounts for 66% of connected devices in a given healthcare environment, the report said. Of more than 5,500 internet-facing healthcare systems analyzed, only 31% support an encryption protocol capable of supporting post-quantum cryptography.
Forescout described a concern called “harvest now, decrypt later,” in which attackers collect encrypted healthcare data now and store it in case future quantum computers can decrypt it. The National Institute of Standards and Technology released its first set of post-quantum cryptography standards in 2024. Forescout vice president Daniel Trivellato said it remains an open question whether healthcare will face specific regulatory requirements or whether the standards will be incorporated into existing cybersecurity obligations.


