Forescout Finds PQC Bottleneck in Medical Hardware
Forescout analyzed more than 2.5 million devices across 50-plus healthcare delivery organizations and found that only 6% of IoMT devices and 16% of medical OT devices can support a post-quantum cryptography transition over SSH. That gap matters because these are often the devices most directly tied to patient care.
The limitation is practical, not theoretical: many medical devices run older SSH and TLS stacks that cannot simply be switched to post-quantum protocols, while internet-exposed EMR and PACS systems still hold data worth stealing now and decrypting later. In Forescout’s sample, more than 5,500 exposed systems were found, and only 31% supported TLS 1.3, the version that can carry standardized PQC.
The result is a hardware-lifecycle problem for healthcare, not a clean software rollout. If a device cannot be upgraded in place, the exposure window lasts until it is replaced or placed behind compensating controls, and that leaves a long tail of patient-care systems outside the normal cryptography migration path.
A study of millions of devices across 50 healthcare orgs suggests the sector has a long way to go in getting ready for the post-quantum cryptography era.