Dive Brief:
- Healthcare organizations aren’t prepared for cybersecurity threats from quantum computing — an emerging technology that could break the encryption protecting patient data — according to a new report.
- Medical devices lag behind traditional information technology systems in preparedness. Just 6% of medical devices have security that can withstand future quantum computer attacks, compared with 50% of IT systems, according to the report by cybersecurity company Forescout’s threat intelligence and research arm.
- Electronic medical records, medical imaging and lab results are the data types most at risk. Experts say healthcare leaders should address these risks sooner rather than later.
Dive Insight:
If and when scientists are able to develop practical quantum computers, advanced computers that use quantum mechanics to process data, they predict the technology will be able to accomplish complex computing tasks exponentially better and faster than classical computers. These developments, once strictly theoretical, are potentially only a few years away from reality, and could set the stage for a new frontier of both innovation and security challenges.
Governments and organizations across all sectors are worried that a quantum computer could easily break traditional modes of encryption — the process of protecting data by scrambling it into random numbers — that underpin virtually all digital security today, from online banking to hospital networks.
As such, the race is on to implement what’s known as post-quantum cryptography, a new generation of encryption algorithms designed to withstand attacks from both classical and quantum computers, before cybercriminals can exploit vulnerable systems.
However, Forescout's research suggests that healthcare is running behind in preparing for this critical transition.
Researchers analyzed more than 2.5 million devices across more than 50 healthcare organizations and found that connected medical devices like infusion pumps and patient monitors are less prepared for post-quantum cryptography than traditional IT systems, such as computer workstations and servers.
Medical devices are notoriously difficult to update but are relied upon heavily for patient care. Although IT still accounts for 66% of connected devices in a given healthcare environment, vulnerable medical devices could pose a security threat if they remain unprepared for post-quantum cryptography migration, the report stated.
The researchers also analyzed more than 5,500 internet-facing healthcare systems like patient portals and certain application programming interfaces. Only 31% of those systems support an encryption protocol capable of supporting post-quantum cryptography.
“The primary threat is not that hackers will suddenly use quantum computers to attack hospitals tomorrow,” said Daniel Trivellato, vice president of operational technology, healthcare and cyber risk solutions at Forescout.
The more pressing concern is “harvest now, decrypt later,” a strategy where attackers collect encrypted healthcare data today and store it in hopes that quantum computers will be able to decrypt it in the future.
“Healthcare is particularly exposed because medical records, diagnostic images, laboratory results, and prescription histories can remain sensitive and valuable for decades,” Trivellato said.
Cyberattacks are already rampant across the healthcare sector, even without quantum threats. From January through August of this year, Forescout tracked 461 public ransomware claims against healthcare providers globally, up 47% from the same period last year. More than 60% of those claims targeted U.S. organizations.
Plus, cyberattacks and data breaches are expensive to contain and recover from. Healthcare data breaches cost organizations about $6.64 million on average, according to IBM.
“For a CEO or CFO, the choice is not between spending money now or spending nothing until quantum computers arrive,” Trivellato said. “The choice is between incorporating quantum readiness into existing modernization, procurement, and technology refresh cycles over multiple years, or facing a far larger and more disruptive catch-up effort later.”
He recommended that healthcare leaders focus on taking stock of assets and high-risk systems to prepare.
Organizations looking to bolster security ahead of quantum computing can use established standards to do so, like those from the National Institute of Standards and Technology, a government agency that develops technical standards. The agency released its first set of post-quantum cryptography standards in 2024.
On the regulatory front, Trivellato said it remains an open question whether healthcare will eventually see specific post-quantum cryptography regulatory requirements or whether those standards will be baked into existing cybersecurity obligations.