Study Finds Majority of Healthcare Devices Unprepared for Post-Quantum Security
A new analysis of more than 2.5 million medical devices across fifty health‑care organizations indicates that the sector is far from ready for the transition to post‑quantum cryptography, raising concerns about the long‑term protection of patient data.
The research, commissioned by a cybersecurity firm and reported by Dark Reading, examined the encryption methods embedded in a wide range of equipment—from imaging scanners to bedside monitors. investigators discovered that a large share of the devices still rely on legacy algorithms such as RSA and ECC, which are vulnerable to attacks by sufficiently powerful quantum computers.
Because many of these devices are certified for use over periods of a decade or more, replacing or updating their cryptographic modules is not a simple software patch. The study notes that manufacturers often provide limited firmware support, and older hardware may lack the processing capacity to run the larger key sizes required by quantum‑resistant schemes.
Security experts warn that the lag in adopting post‑quantum safeguards could expose health records to future decryption attempts, especially as nation‑state actors accelerate quantum research. In addition to the privacy implications, regulators such as the U.S. Department of Health and Human Services have begun to issue guidance that could eventually make quantum‑ready encryption a compliance requirement.
Industry response has been mixed. Some vendors are already testing lattice‑based and hash‑based algorithms in laboratory settings, while others argue that the cost and logistical challenges of retrofitting millions of devices are prohibitive. Standards bodies, including the National Institute of Standards and Technology, are expected to publish finalized post‑quantum recommendations later this year, giving organizations a clearer roadmap.
Analysts say the path forward will involve a combination of phased firmware updates, strategic device replacement, and robust inventory management to track cryptographic health. Until then, health‑care providers may need to rely on network‑level defenses and strict access controls to mitigate the risk posed by the looming quantum threat.
Comments (0)
Be the first to comment.
Join the discussion