Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-08 · updated: 2026-10-08 · tags: [incident, healthcare] · confidence: high · severity: low · affected_sectors: [healthcare] · au_impact: false

Forescout's October 2026 PQC in Healthcare Report, analysing more than 2.5 million IoMT devices across more than 50 healthcare delivery organisations, found only 6% of IoMT and 16% of OT devices run SSH implementations supporting post-quantum cryptography, against roughly 50% of IT devices — and the least-prepared devices are often those used directly for patient care. Of internet-exposed medical information systems (5,500 identified, including EMRs and PACS), just 31% support TLS 1.3, the only TLS version able to carry standardised PQC: 6% of PACS, 33% of EMRs and 13% of laboratory management systems. Forescout warns the healthcare risk is amplified by the long-term sensitivity of health data and the harvest-now-decrypt-later threat, with Google predicting current encryption could be obsolete as early as 2029. Recommended steps: full asset inventory, prioritised upgrades or compensating controls for internet-exposed systems, TLS 1.3 enforcement and segmentation of non-upgradable devices.

Attribute Detail
Sector Healthcare
Date 2026-10-08
Source HIPAA Journal
Reliability Tier 2