

Forescout research covering more than 2.5 million devices finds that healthcare IoT and operational technology are significantly less prepared for post-quantum cryptography than conventional IT systems, creating a difficult migration challenge for long-lived medical infrastructure.
For hospitals, preparing for quantum-era cybersecurity is not simply a matter of replacing one encryption algorithm with another. Healthcare networks combine conventional IT systems with infusion pumps, patient monitors, imaging equipment, laboratory systems and other connected devices that can remain operational for many years. Many of those assets were never designed for rapid cryptographic upgrades.
That hardware reality is emerging as a significant obstacle to post-quantum cryptography (PQC) migration. New research from Forescout Research – Vedere Labs found that only 6% of Internet of Medical Things (IoMT) devices using SSH rely on implementations capable of supporting PQC. The figure rises to 16% for operational technology devices, compared with 50% across traditional IT systems.
The findings are based on analysis of more than 2.5 million devices across over 50 healthcare delivery organizations.
A device lifecycle problem, not just an encryption problem
The readiness gap between medical devices and conventional IT is particularly important because the two categories follow very different replacement cycles. Servers and enterprise software can often be upgraded or migrated comparatively quickly. Specialized medical equipment may have longer operational lifetimes, more restricted upgrade paths and clinical dependencies that make replacement considerably more complicated.
In healthcare, some of the systems least ready for new cryptographic standards are also embedded directly into patient-care workflows. The challenge therefore extends beyond security teams to medical-device manufacturers, hospital engineering departments, procurement teams and the broader IoMT supply chain.
The report also identified more than 5,500 internet-exposed healthcare systems, including electronic medical record and picture archiving and communication systems. Among exposed systems examined by Forescout, only 31% supported TLS 1.3, which the company identifies as the TLS version capable of supporting standardized post-quantum cryptography.
Forescout ranks electronic medical records, medical imaging, laboratory results, medication and prescription information, and financial or payment data among the healthcare data categories currently carrying the greatest risk based on exposure, network presence and sensitivity.
Why healthcare faces a particularly long migration
The immediate threat is not that quantum computers are already breaking hospital encryption. Cryptographically relevant quantum computers capable of doing so are not currently available. However, as explored in our analysis of quantum computing and its implications for IoT security, the evolution of quantum technologies raises important questions about the long-term protection of connected systems. One concern is the so-called “harvest now, decrypt later” model, in which attackers collect encrypted information today in anticipation of being able to decrypt it in the future.
This matters in healthcare because medical information can remain sensitive for decades. Unlike a compromised password or payment credential, a patient’s medical history, diagnostic image or laboratory record cannot simply be replaced after disclosure.
For connected healthcare architectures, that changes the migration calculation. Organizations need to identify not only which devices use vulnerable cryptography, but also where sensitive information is generated, transported and stored across IT, IoT, OT and IoMT systems. This reinforces the wider security and data-governance challenges surrounding connected healthcare IoT environments.
Legacy IoMT will require compensating controls
A practical implication of the research is that some medical devices may never receive native PQC support. Devices constrained by hardware, firmware, vendor support or certification requirements could remain in service while the surrounding infrastructure moves to newer cryptographic standards.
That makes network architecture part of the PQC transition. Forescout recommends asset inventory and classification, prioritization of internet-facing systems and external connections, deployment of TLS 1.3 where possible, and identification of systems that will require upgrades, replacement or compensating controls. Legacy systems that cannot be modernized may need stronger segmentation, restricted access and enhanced monitoring.
For IoT and medical-device manufacturers, the findings also underline the growing importance of crypto-agility: products designed for long operational lifetimes increasingly need a way to change cryptographic mechanisms without replacing the underlying device. For healthcare providers, PQC readiness is therefore likely to become as much a procurement and lifecycle-management consideration as a cybersecurity project.
The broader lesson extends beyond healthcare. Long-lived connected assets are one of the hardest parts of any large-scale cryptographic transition. Hospitals simply expose that problem particularly clearly: their networks combine sensitive data, heterogeneous connected equipment and devices that cannot necessarily move at the speed of enterprise IT.
The post Post-Quantum Security Gap Leaves Healthcare IoT Devices Behind appeared first on IoT Business News.
