Forescout's October 2026 PQC in Healthcare Report, analysing more than 2.5 million IoMT devices across more than 50 healthcare delivery organisations, found only 6% of IoMT and 16% of OT devices run SSH implementations supporting post-quantum cryptography, against roughly 50% of IT devices — and the least-prepared devices are often those used directly for patient care. Of internet-exposed medical information systems (5,500 identified, including EMRs and PACS), just 31% support TLS 1.3, the only TLS version able to carry standardised PQC: 6% of PACS, 33% of EMRs and 13% of laboratory management systems. Forescout warns the healthcare risk is amplified by the long-term sensitivity of health data and the harvest-now-decrypt-later threat, with Google predicting current encryption could be obsolete as early as 2029. Recommended steps: full asset inventory, prioritised upgrades or compensating controls for internet-exposed systems, TLS 1.3 enforcement and segmentation of non-upgradable devices.
| Attribute | Detail |
|---|---|
| Sector | Healthcare |
| Date | 2026-10-08 |
| Source | HIPAA Journal |
| Reliability | Tier 2 |