Executive Summary
A comprehensive study by Forescout Technologies analyzing 2.5 million devices across 50+ healthcare organizations revealed critical gaps in post-quantum cryptography (PQC) readiness throughout the healthcare sector. The research found that only 50% of IT devices support PQC-capable SSH implementations, while operational technology devices lag at 16% and Internet of Medical Things (IoMT) devices at a mere 6%. Most concerning, over 5,500 Internet-exposed healthcare systems containing electronic medical records and imaging data showed only 31% adoption of TLS 1.3, the foundation for standardized post-quantum cryptography. This widespread vulnerability exposes sensitive patient data to 'harvest now, decrypt later' attacks, where encrypted health information stolen today could be decrypted once quantum computers become sufficiently powerful.
This research highlights an urgent emerging threat as quantum computing advances accelerate and nation-state actors increasingly target healthcare infrastructure. With medical records maintaining value for decades and healthcare being the most ransomware-targeted sector, organizations face a narrow window to implement quantum-resistant encryption before cryptographically relevant quantum computers emerge.
Why This Matters Now
Healthcare organizations face an imminent quantum cryptography cliff with most critical systems unprepared for post-quantum encryption standards, leaving decades of sensitive patient data vulnerable to future quantum-powered decryption attacks by nation-state and criminal actors.
Attack Path Analysis
Attackers exploited quantum-vulnerable encryption and unprotected IoT/IoMT devices in healthcare systems to establish persistent access. They escalated privileges through exposed medical systems, moved laterally across unencrypted internal networks, established command channels through unfiltered egress, exfiltrated sensitive medical data via unmonitored channels, and caused operational disruption to critical patient care systems.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Exploitation of Internet-exposed healthcare systems lacking TLS 1.3 support and quantum-vulnerable encryption, targeting the 5,500+ systems with electronic medical records reachable from public Internet
MITRE ATT&CK® Techniques
Network Sniffing
Adversary-in-the-Middle
Exploit Public-Facing Application
Unsecured Credentials: Private Keys
Exploitation of Remote Services
Data Manipulation: Transmitted Data Manipulation
Data from Configuration Repository
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
HIPAA Security Rule – Transmission Security
Control ID: 45 CFR 164.312(e)(1)
PCI DSS 4.0 – Strong Cryptography for Transmission
Control ID: 4.2.1
NYDFS 23 NYCRR 500 – Encryption of Nonpublic Information
Control ID: 500.15
CISA ZTMM 2.0 – Data Categorization and Protection
Control ID: Data Security Pillar
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001:2022 – Policy on the Use of Cryptographic Controls
Control ID: A.10.1.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Health Care / Life Sciences
Healthcare systems face critical quantum cryptography vulnerabilities with only 31% supporting TLS 1.3, exposing patient data to harvest-now-decrypt-later attacks across medical devices.
Medical Equipment
Medical device manufacturers must address post-quantum cryptography gaps affecting IoMT devices, patient monitors, and imaging systems with complex upgrade requirements and regulatory compliance.
Pharmaceuticals
Pharmaceutical organizations risk exposure of sensitive research data and patient information through inadequate quantum-ready encryption on Internet-facing systems and clinical platforms.
Biotechnology/Greentech
Biotech firms face quantum cryptography readiness challenges for protecting valuable research data, clinical trial information, and intellectual property from long-term decryption threats.
Sources
- Critical Healthcare Systems Aren't Quantum-Readyhttps://www.darkreading.com/iot/exposed-healthcare-systems-quantum-readyVerified
- Post-Quantum Cryptography Standardshttps://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standardsVerified
- CISA Post-Quantum Cryptography Initiativehttps://www.cisa.gov/post-quantum-cryptography-initiativeVerified
- Healthcare Cybersecurity Threat Landscapehttps://www.hhs.gov/sites/default/files/health-industry-cybersecurity-practices-managing-threats-and-protecting-patients.pdfVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained this healthcare attack by enforcing workload segmentation and controlling east-west traffic flows. The segmented architecture would likely have reduced attacker lateral movement scope and limited access to sensitive medical systems across the network.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud native security fabric would likely have reduced the attack surface by enforcing secure access patterns and limiting direct Internet exposure of medical record systems through controlled entry points.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely have limited privilege escalation scope by isolating IoMT devices and OT systems into separate network segments with restricted cross-segment access to clinical management systems.
Control: East-West Traffic Security
Mitigation: East-west traffic security would likely have constrained lateral movement by enforcing encrypted communication and access policies between medical devices, workstations, and clinical systems across network segments.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility and control would likely have detected and constrained unauthorized command channels by monitoring traffic patterns and enforcing communication policies across medical device networks and clinical systems.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security and policy enforcement would likely have constrained mass data extraction by monitoring and controlling outbound traffic flows from healthcare systems containing electronic health records and medical imaging data.
While some operational disruption may still occur, the constrained attack scope would likely have limited ransomware deployment to isolated network segments rather than affecting entire healthcare system operations.
Impact at a Glance
Affected Business Functions
- Electronic Health Records (EHR) Systems
- Medical Device Operations
- Patient Portals and Telehealth
- Medical Imaging and Diagnostics
Estimated downtime: N/A
Estimated loss: N/A
Healthcare organizations face long-term cryptographic vulnerability exposure affecting electronic medical records, diagnostic images, patient monitoring data, and clinical information. Over 5,500 Internet-exposed healthcare systems containing medical records and imaging data lack adequate post-quantum cryptography protection, potentially enabling future harvest-now-decrypt-later attacks when quantum computers become viable.
Recommended Actions
Key Takeaways & Next Steps
- • Implement encrypted traffic capabilities with HPE to protect data in transit across all healthcare networks and prevent harvest-now-decrypt-later attacks on quantum-vulnerable communications
- • Deploy zero trust segmentation with microsegmentation policies to isolate IoMT devices, OT systems, and clinical networks from broader infrastructure access
- • Establish multicloud visibility and control systems to monitor anomalous interactions between medical devices and detect suspicious automation across healthcare environments
- • Implement egress security and policy enforcement to prevent unauthorized data exfiltration from EHR systems, medical imaging platforms, and patient data repositories
- • Deploy inline IPS with Suricata signatures to detect and block exploit attempts targeting vulnerable healthcare applications and legacy medical device protocols



