Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
On October 6, 2026, Forescout Research-Vedere Labs published an analysis of more than 2.5 million devices across over 50 healthcare delivery organizations: only 6% of IoMT (Internet of Medical Things) devices and 16% of medical OT systems have SSH implementations capable of supporting post-quantum cryptography. That figure stands in stark contrast to the 50% of traditional IT devices found ready for the transition. The research documents a structural fracture between IT infrastructure and clinical technologies, with implications that stretch across decades of residual patient data life.
- Only 6% of IoMT devices and 16% of medical OT systems support SSH implementations ready for post-quantum cryptography, versus 50% of traditional IT devices.
- More than 5,500 internet-exposed healthcare systems handle sensitive data, yet only 31% support TLS 1.3, the only protocol capable of hosting standardized PQC algorithms.
- The least prepared devices are the most critical to patient care: infusion pumps, ventilators, PACS systems, and laboratory management platforms.
- Between January and August 2026, Forescout tracked 461 public ransom demands against healthcare operators, confirming active offensive pressure on the sector.
The Cryptographic Divide Between IT and Clinical Technologies
Forescout's research measures a specific technical capability: compatibility with post-quantum algorithms requires TLS 1.3 or OpenSSH 8.0+, with support for primitives such as ML-KEM, standardized by NIST in August 2024. In the sample analyzed, only 31% of internet-exposed healthcare systems support TLS 1.3. The internal distribution is even more skewed: 46% of exposed systems correspond to electronic medical record (EMR) platforms, 40% to PACS for medical image storage.
The divide deepens when examining individual device categories. According to data published by HIPAA Journal, only 6% of PACS, 33% of EMRs, and 13% of laboratory management systems support TLS 1.3. SSH readiness percentages are even lower: data published by Industrial Cyber indicates that at the enterprise level, PQC support on TLS stands at 8% for IT devices, 5.6% for IoT/IoMT, and 0.8% for OT. At the global internet level, only 11.8% of SSH servers are PQC-capable, plummeting to 0.3% for Dropbear implementations, which are widespread in the embedded Linux systems of medical devices.
Why Care Devices Don't Migrate
The low readiness percentage reflects not merely technological backwardness but structural constraints. IoMT and medical OT devices operate on proprietary firmware, embedded Linux systems with legacy TLS stacks, or Dropbear SSH implementations that do not receive cryptographic updates. Replacing or updating these components traverses FDA certification cycles, vendor-controlled releases, and, in many cases, hardware limitations that prevent execution of PQC algorithms.
The lifecycle of medical devices typically spans 10-15 years, while patient data — clinical histories, diagnostic images, prescriptions — retains sensitivity and value for decades. This temporal asymmetry constitutes the core of the "harvest-now, decrypt-later" threat model: adversaries collect encrypted data today, expecting to decrypt it when quantum computers render current algorithms obsolete. As Daniel Trivellato, VP of OT, Healthcare and Cyber Risk Solutions at Forescout, stated: "Unlike many other types of data, patient information retains its value and sensitivity for decades, making it particularly vulnerable to harvest-now, decrypt-later attacks."
"The research demonstrates that the devices least prepared for the transition are often the same ones healthcare organizations depend on most for care delivery. Visibility into these assets and the data they handle is essential to building a practical migration strategy." — Daniel dos Santos, VP of Research, Forescout
The Exposed Attack Surface: 5,500 Systems and Ransomware Pressure
Beyond cryptographic readiness data, Forescout identified more than 5,500 internet-exposed healthcare systems containing sensitive data. The distribution shows a concentration on high-value infrastructure: EMR platforms and PACS together represent 86% of the exposed surface. These are not generic endpoints, but purpose-built technologies often managed by third parties or integrated into specialized cloud services.
The current threat context makes this exposure particularly critical. Between January and August 2026, Forescout tracked 461 public ransomware claims and 300 hacktivist claims against healthcare operators worldwide. According to data published by Industrial Cyber, among the 300 hacktivist claims, 31% involved attempts to control or disrupt IoT/OT/IoMT systems, 30% were DDoS attacks, and 27% were data breaches. The overlap between active offensive pressure and future cryptographic vulnerability creates an extended risk window: data stolen today through exposed systems remains compromised even after potential tactical mitigations.
Why It Matters
The Forescout dossier does not specify whether the PQC readiness percentages (6% IoMT, 16% OT) reflect devices theoretically upgradable via configuration or requiring hardware and firmware interventions. No cost estimates emerge for replacing or recertifying the entire medical device fleet, nor PQC roadmap timelines from major industry vendors. The cited measure does not document whether specific healthcare facilities have begun concrete migrations or remain in the planning phase.
The source does not indicate regulatory requirements or compliance deadlines for the post-quantum transition in healthcare (FDA updates, HIPAA), nor provide reliable temporal projections on the availability of quantum computers capable of breaking current encryption. The industrial cost of a coordinated migration among providers, device manufacturers, regulators, and service providers remains unquantified.
The consolidated fact is instead the economic and operational impossibility of replacing infusion pumps, ventilators, and imaging systems for purely cryptographic reasons. The PQC transition in healthcare does not configure as an extended patch management project, but as a multi-year restructuring requiring coordination among clinical engineering, procurement, compliance, and vendors. As Trivellato stated: "Closing the gap will require far more than software updates. It will demand years of coordinated effort among healthcare providers, device manufacturers, regulators, and service providers."
The Takeaway: Temporal Asymmetry and Distributed Responsibility
The picture emerging from the research inverts the conventional logic of security investment. Healthcare organizations have concentrated resources on IT infrastructure with manageable lifecycles, but the most sensitive data resides in devices those investments do not protect. The "temporal asymmetry" — decades of data sensitivity against decades of device lifecycles — shifts the problem from technology to risk architecture.
Responsibility is not localizable to a single party. Medical device vendors control update channels, regulators define certification requirements, healthcare providers manage operational exposure. The lack of unified visibility into assets, data, and cryptographic capabilities — highlighted by Forescout as a prerequisite for any strategy — indicates the first obstacle to action is not technical but organizational. Until facilities map which device carries which data with which protocols, PQC migration remains a goal without a path.
Sources
- https://www.helpnetsecurity.com/2026/10/08/forescout-healthcare-quantum-readiness-report/
- https://www.darkreading.com/iot/exposed-healthcare-systems-quantum-ready
- https://www.infosecurity-magazine.com/news/medical-devices-pqc-transition/
- https://thehackernews.com/2026/10/atlassian-data-center-flaw-draws.html
- https://www.hipaajournal.com/medical-devices-incapable-transition-post-quantum-cryptography/
- https://industrialcyber.co/reports/forescout-finds-healthcare-lagging-in-post-quantum-cryptography-readiness-as-iomt-and-ot-devices-fall-behind-it/
- https://www.intelligentciso.com/2026/10/07/post-quantum-cryptography-in-healthcare-forescout-research-reveals-critical-readiness-gaps-putting-patient-data-at-risk/
- https://thehackernews.com/
- https://thehackernews.com/p/upcoming-hacker-news-webinars.html
- https://thehackernews.com/search/label/Threat%20Intelligence
- https://thehackernews.com/search/label/Vulnerability
- https://thehackernews.com/search/label/Cyber%20Attack
Information is based on the cited source and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.