“Our research shows that the devices least prepared for the transition are often the same devices healthcare organizations depend on most for delivering patient care. Visibility into those assets and the data they handle is essential for building a practical migration strategy.” — Daniel dos Santos, VP of research, Forescout.
Measured readiness: the hard numbers
An investigation by Forescout that analyzed more than 2.5 million devices across over 50 healthcare delivery organizations (HDOs) found stark gaps in post-quantum cryptography (PQC) readiness. Only 6% of Internet of Medical Things (IoMT) devices and 16% of medical operational technology (OT) devices use Secure Shell (SSH) implementations capable of supporting a transition to PQC. By contrast, roughly 50% of traditional IT devices examined can support PQC implementation today.
Internet exposure and the TLS 1.3 shortfall
Forescout identified more than 5,500 internet-exposed systems among the devices studied, including platforms that house sensitive healthcare data such as electronic medical records (EMRs) and picture archiving and communication systems (PACs). Of those exposed systems, just 31% support TLS 1.3 — the only version of TLS the report cites as capable of supporting standardized PQC. That gap creates an acute migration challenge for systems already reachable from the public internet.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadWhy “harvest now, decrypt later” targets healthcare data
The report warns that internet-exposed systems that lack PQC-ready encryption are especially vulnerable to “harvest now, decrypt later” attacks: adversaries can capture encrypted data today and keep it until quantum computers are capable of breaking present-day encryption. Forescout underscores that medical histories, diagnostic images, laboratory results, prescription records and other healthcare data retain their value and sensitivity for decades — a characteristic that makes healthcare uniquely attractive for future decryption efforts.
Devices central to care are the least upgradeable
Forescout emphasizes that many clinical systems implicated in the study — infusion pumps, patient monitors, imaging systems and laboratory equipment — have long lifecycles, limited upgrade paths and slower adoption of modern cryptographic standards. Those same constraints mean the devices healthcare organizations rely on most for direct patient care are often the least prepared to support a PQC transition, a point Daniel dos Santos highlighted in the report.
Forescout’s practical checklist for healthcare teams
- Inventory and classify connected IT, OT, IoT and IoMT assets, including mapping their communications with other assets.
- Assess which assets already support PQC and identify systems that require upgrade, replacement or compensating controls.
- Segment and isolate legacy systems that cannot be upgraded to reduce exposure.
- Incorporate PQC readiness into governance, procurement and risk-management processes, and enforce TLS 1.3 wherever possible.
- Engage vendors to obtain clear PQC roadmaps and migration timelines.
What this means for technologists, procurement leaders, and patients
- Technologists and security teams: Expect to prioritize discovery and segmentation work immediately, since the report indicates many clinical devices cannot be upgraded and are internet-exposed.
- Procurement and vendor managers: The report recommends incorporating PQC readiness into procurement and engaging vendors for migration timelines — a direct signal to require PQC roadmaps in purchasing decisions.
- Patients and clinical staff: The persistence and long-term sensitivity of medical records — singled out by Forescout — mean that protecting stored and transmitted clinical data has implications for patient privacy years into the future.
Forescout’s analysis paints a practical problem rather than a distant hypothetical. With quantum-capable computers predicted in the report to be able to break current encryption within the next five years, the company urges healthcare organizations to act now: inventory assets, enforce TLS 1.3 where possible, segment legacy devices and press vendors for PQC migration plans. Those steps are not theoretical policy prescriptions in the report — they are the immediate actions Forescout identifies as the foundation of any practical migration strategy for medical environments whose devices, in many cases, cannot be upgraded to support PQC.
Read the original Forescout findings: https://www.infosecurity-magazine.com/news/medical-devices-pqc-transition/




