The Bottom Line Up Front
A newly published analysis of 2.5 million devices across 50 healthcare organizations delivers a finding that should concern every CISO, biomedical engineering lead, and compliance officer in the sector: healthcare's cryptographic posture is nowhere near ready for the post-quantum era. The study, reported by Dark Reading, examined device fleets at scale and concluded that the sector has a long road ahead before it can withstand cryptographically relevant quantum computers (CRQCs) — machines capable of breaking the RSA and elliptic-curve cryptography that protect virtually every medical device, EHR integration, VPN tunnel, and TLS session in production today.
There is no CVE here. There is no zero-day, no exploit kit, no ransomware affiliate. That is precisely what makes this dangerous: the threat model is harvest-now, decrypt-later (HNDL) — passive interception of encrypted traffic and stored ciphertext today, with decryption deferred until quantum capability matures. Nation-state collection programs are believed to be stockpiling encrypted health data, research IP, and genomic datasets right now. Every day a hospital transmits PHI over non-quantum-safe channels is a day that data's confidentiality clock starts ticking.
Healthcare is uniquely exposed. Medical devices live 10–15+ years in production, run frozen firmware stacks, are constrained by FDA validation cycles, and frequently cannot be patched without vendor recertification. A cryptographically relevant quantum computer arriving in the early-to-mid 2030s will meet device fleets deployed this year still running TLS 1.2 with RSA key exchange. Defenders cannot patch their way out of this at the last minute. Migration is a multi-year program, and the study's findings suggest most organizations haven't seriously started.
Technical Analysis: Why Healthcare Is Structurally Behind
The Quantum Threat, in Practical Terms
Shor's algorithm, executed on a sufficiently large fault-tolerant quantum computer, breaks the asymmetric primitives that underpin modern secure communications: RSA, ECDH, ECDSA, and DSA. Symmetric cryptography fares better — Grover's algorithm only halves effective key strength, so AES-256 retains ~128-bit post-quantum security — but the key exchange and digital signature layers that establish and authenticate encrypted sessions collapse.
The harvest-now, decrypt-later model means defenders cannot wait for a CRQC to exist before acting. The relevant question is the Mosca inequality: if (data shelf-life + migration time) exceeds time-to-CRQC, you are already late. For healthcare:
- PHI shelf-life is measured in decades. HIPAA requires six-year minimum documentation retention, but clinical value — and regulatory sensitivity — of diagnoses, genetic markers, mental health records, and HIV status persists for a patient's lifetime. Genomic data is effectively permanent: your DNA sequence intercepted in 2026 is still your DNA sequence in 2045.
- Migration time in healthcare is the longest of any sector. Device replacement cycles of a decade or more, FDA premarket constraints on cryptographic changes, and thousands of embedded TLS/IPsec/VPN stacks mean a PQC migration measured in years, not quarters.
What the Study Signals About the Device Fleet
Across the 50 organizations surveyed — spanning 2.5 million devices — the picture is consistent with what those of us who assess hospital environments see every engagement:
- Massive legacy cryptography exposure. Imaging systems (CT, MRI, PACS), infusion pumps, patient monitors, and lab analyzers shipping with embedded TLS stacks built on RSA-2048 key exchange and, in many cases, TLS 1.0/1.1 that can't even support modern classical crypto, let alone PQC.
- Long-lived, unpatchable-by-design assets. A significant share of connected medical devices cannot accept firmware updates without vendor-issued, FDA-consistent patches. Cryptographic agility — the ability to swap algorithms — simply doesn't exist in these firmware builds.
- No cryptographic inventory. Most organizations cannot answer the most basic PQC question: which systems use which algorithms, key sizes, and protocols, and where does our long-lived data flow? Without a cryptographic bill of materials (CBOM), migration planning is guesswork.
- Flat trust architectures. Legacy devices that cannot be upgraded must be compensated for architecturally — segmentation, gateway-based crypto translation, strict egress controls — yet many clinical networks remain under-segmented because segmentation projects collide with clinical uptime requirements.
Exploitation Status
There is no confirmed in-the-wild quantum exploitation — no CRQC exists today capable of breaking RSA-2048, and this is not a CISA KEV-style emergency. The operative risk is theoretical-but-actively-prepared: intelligence community and industry assessments have long warned that adversaries are collecting encrypted traffic and data stores now for later decryption. For long-shelf-life data classes like PHI and genomic data, the HNDL window is already open. Treat this as a strategic exposure, not an incident — but one with a hard, externally-set deadline.
Executive Takeaways
Because this story concerns sector-wide cryptographic posture rather than a specific exploit, the defensive value here is programmatic. These are the actions we are advising our healthcare clients to take now:
-
Build a cryptographic inventory and CBOM before anything else. You cannot migrate what you haven't mapped. Inventory every instance of RSA/ECC across TLS endpoints, VPN concentrators, code-signing, device certificates, database TDE, and medical device firmware. NIST's National Cybersecurity Center of Excellence (NCCoE) Migration to Post-Quantum Cryptography project and CISA's PQC Initiative both publish discovery guidance. Automated discovery tooling (TLS scanners, CBOM generators such as those aligned to the CycloneDX standard) should feed your asset management platform — this inventory also pays off immediately for certificate lifecycle and TLS deprecation work.
-
Apply the Mosca math to your data classes. Rank data by confidentiality shelf-life. Genomic data, behavioral health records, research IP, and identity documents that must remain confidential for 20+ years are HNDL-exposed today if they traverse non-quantum-safe channels. These flows get migration priority; short-lived session data can wait for normal refresh cycles. This triage turns an overwhelming program into a sequenced roadmap.
-
Force PQC roadmaps into vendor contracts now. Medical device procurement cycles are the leverage point. Every RFP and renewal should require: disclosure of cryptographic primitives in use, a committed PQC migration timeline aligned to NIST standards, crypto-agility in new firmware, and support for hybrid (classical + ML-KEM) key exchange. If a vendor cannot answer, that is procurement risk data. The HTCC and H-ISAC communities are already building shared vendor-questionnaire templates — use them rather than starting from scratch.
-
Adopt hybrid key exchange on internet-facing and inter-site infrastructure first. Major TLS stacks, browsers, and cloud providers already support hybrid X25519+ML-KEM key agreement. Enabling it on patient portals, telehealth platforms, API gateways, and site-to-site VPNs is low-risk, backward-compatible, and immediately closes the HNDL window on those flows — even while endpoints remain classical. This is the highest-value early move for most organizations.
-
Compensate architecturally for devices that will never migrate. Accept reality: a meaningful share of your 2026 fleet will still be running RSA-era cryptography when it is decommissioned. For these devices: strict network segmentation (clinical VLANs with default-deny east-west rules), gateway-based encrypted transport so legacy plaintext/weak-TLS never traverses untrusted segments, medical-device-aware monitoring, and aggressive decommissioning of end-of-support systems. Unmanaged legacy devices are also your classical breach risk — the same segmentation controls serve both threats.
-
Anchor the program to published regulatory timelines. Migration is no longer optional guidance. OMB M-23-02 already requires federal agencies to inventory quantum-vulnerable cryptography; CNSA 2.0 sets 2025–2033 transition targets for national security systems; and both U.S. and EU roadmaps point to 2030 for high-risk systems and ~2035 for full deprecation of quantum-vulnerable algorithms. HIPAA's Security Rule is evolving in the same direction. Frame your board-level ask around these dates: a healthcare PQC migration starting in 2026 is on schedule; one starting in 2030 is already late for long-lived data.
Remediation: The Migration Roadmap
There is no patch to apply — remediation here is a sequenced program. The concrete steps we run with clients:
Phase 1 — Discovery (now):
- Stand up cryptographic discovery scanning across production VLANs, including biomedical/clinical engineering networks (coordinate with clinical engineering — active scanning of fragile legacy devices requires care).
- Produce a CBOM per critical system: algorithms, key sizes, protocol versions, certificate chains, and data flows.
- Identify and flag any residual TLS 1.0/1.1, SSL, RC4, 3DES, or export-grade crypto — these are classical-era emergencies that also block PQC readiness.
Phase 2 — Standards alignment:
- Adopt the finalized NIST PQC standards as your target state: FIPS 203 (ML-KEM, key encapsulation), FIPS 204 (ML-DSA, digital signatures), and FIPS 205 (SLH-DSA, stateless hash-based signatures). FIPS 206 (FN-DSA) is forthcoming — track it.
- Require hybrid modes (classical + PQC) during transition rather than PQC-only, maintaining interoperability and hedging against implementation immaturity.
- Reference: NIST PQC standardization, CISA Post-Quantum Cryptography Initiative, OMB M-23-02, and NSA CNSA 2.0.
Phase 3 — Prioritized migration:
- Internet-facing TLS termination, VPN gateways, and inter-site links → hybrid key exchange first.
- Internal PKI, code-signing, and device identity → plan ML-DSA certificate hierarchies; this is a multi-year effort because device trust anchors are baked into firmware.
- Data-at-rest: confirm AES-256 for storage encryption (quantum-resilient); the exposure is key wrapping and transport, which migrate with your asymmetric stack.
- Procurement gate: no new device or platform enters the environment without a PQC roadmap commitment.
Phase 4 — Governance:
- Assign an owner (typically the CISO with biomedical engineering as a named stakeholder), report progress quarterly, and tie milestones to the 2030/2035 external deadlines.
- Fold PQC readiness into your NIST CSF / HIPAA risk assessments so it is tracked as a managed risk, not an aspiration.
The 2.5-million-device dataset is a mirror. The organizations in that study are not outliers — they are the sector. The defenders who treat 2026 as year one of the migration, rather than year zero of the denial, are the ones whose patient data will still be confidential when the quantum era arrives.
Related Resources
Security Arsenal Healthcare Cybersecurity AlertMonitor Platform Book a SOC Assessment healthcare Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.