Most medical devices cannot be upgraded to post-quantum cryptography (PQC), leaving sensitive healthcare data vulnerable to future quantum-enabled attacks, an investigation by Forescout has found.
An analysis of more than 2.5 million devices across more than 50 healthcare delivery organizations (HDOs) observed that just 6% of Internet of Medical Things (IoMT) devices and 16% of medical operational technology (OT) devices use Secure Shell (SSH) implementations capable of supporting a transition to PQC.
This is significantly below the 50% of traditional IT devices that can support PQC implementation.
PQC refers to new cryptographic algorithms designed to protect data from attacks launched from quantum computers, which are predicted to be capable of breaking existing encryption methods in the next five years.
The Forescout report, published on October 6, highlighted that healthcare environments are highly dependent on IoMT, OT and IoT devices. Many of these systems are directly involved in patient care, such as infusion pumps, patient monitors, imaging systems, and laboratory equipment.
Yet these devices often have long lifecycles, limited upgrade paths and slower adoption of modern cryptographic standards.
Daniel dos Santos, VP of research at Forescout, warned: “Our research shows that the devices least prepared for the transition are often the same devices healthcare organizations depend on most for delivering patient care. Visibility into those assets and the data they handle is essential for building a practical migration strategy.”
Healthcare Data Vulnerable to Harvest Now Attacks
Across the devices analyzed, the researchers identified more than 5500 internet-exposed systems.
These included platforms containing sensitive healthcare data, including electronic medical records (EMRs) and picture archiving and communication systems (PACs).
Of these exposed systems, just 31% support TLS 1.3, the only TLS version capable of supporting standardized PQC.
The researchers warned that these systems are particularly vulnerable to harvest now, decrypt later attacks, in which threat actors steal encrypted data today with the intent of decrypting it in the future when quantum computers become powerful enough.
This is because medical histories, diagnostic images, laboratory results, prescription records and other healthcare data retains its value and sensitivity for decades, unlike other types of information.
How Healthcare Organizations Can Prepare for Quantum Attacks
Forescout urged healthcare organizations to start preparing for quantum-enabled attacks now to ensure sensitive patient data is secure. It recommended a number of actions, including:
- Inventory and classify all connected IT, OT, IoT and IoMT assets, including their communication with other assets
- Assess which assets support PQC today and identify systems that require upgrades, replacement or compensating controls
- Segment and isolate legacy systems that cannot be upgraded
- Incorporate PQC readiness into governance, procurement, and risk management processes, including enforcing TLS 1.3 wherever possible
- Engage vendors to understand their PQC roadmaps and migration timelines
