Healthcare faces a widening gap between its connected medical devices and the encryption standards that will be needed once quantum computers mature. A new Forescout Research — Vedere Labs analysis of more than 2.5 million internet-of-medical-things devices, used across more than 50 healthcare delivery organizations, found most cannot support a move to post-quantum cryptography.
Just 6% of IoMT devices and 16% of operational technology devices use SSH implementations that can handle post-quantum cryptography, according to the October 2026 report. Among IT devices, roughly 50% are ready. The lowest readiness sits in the devices used directly for patient care.
Quantum machines handle certain problems that would take conventional supercomputers millennia in minutes or hours. Google has predicted the current encryption base could fall within five years, perhaps as early as 2029.
The immediate risk is “harvest now, decrypt later.” Encrypted traffic captured today can be stored and cracked once quantum hardware catches up. Healthcare data holds long-term value — unlike account or card numbers that can be reissued — so the exposure window is longer than in other sectors.
Why it matters for healthcare security teams — device procurement is where the fix starts. Security leaders should add post-quantum readiness questions to every medical device purchase and track cryptography support as a lifecycle requirement, not an afterthought.