Forescout's Vedere Labs unit says the medical devices hospitals depend on most are the ones least ready for post-quantum cryptography. The firm's new report, "PQC in Healthcare: From Data Risk to Migration Readiness," pulled data from more than 2.5 million devices across over 50 healthcare delivery organizations, a sample that works out to roughly 50,000 devices per network. SSH implementations capable of supporting quantum-safe key exchange show up on just 6 percent of connected medical devices, versus 16 percent of OT equipment and 50 percent of ordinary IT systems. Capability is not the same as use. Forescout counted what the software could support, not what administrators had actually turned on.
The exposure picture outside the hospital network is worse. A Shodan sweep in the report found more than 5,500 internet-facing instances of 50 different medical information system types. Electronic medical record platforms accounted for 46 percent of that total, and picture archiving and communication systems, PACS, made up another 40 percent. Average support for TLS 1.3, the only TLS version that carries post-quantum key exchange, sat at 31 percent across those exposed systems. PACS systems did slightly better at 36 percent. Fifteen percent of the exposed systems were still running TLS 1.0 or 1.1, protocols with no path to quantum resistance at all.
Forescout tied the readiness gap to an active threat environment. It tracked 461 public ransomware claims against healthcare providers between January and August 2026, up 47 percent from 313 over the same stretch last year. About 65 percent of those claims targeted organizations in the United States. A separate count of 300 hacktivist claims in the same window broke down as 31 percent aimed at disrupting IoT, OT, or connected medical devices directly, 30 percent distributed denial of service, 27 percent data breaches, and the rest defacement.
The quantum computer capable of breaking today's encryption remains years away by most public estimates. The risk already running is harvest now, decrypt later: an adversary records encrypted traffic today and waits for a machine that can break it later. Forescout's researchers argue that clock runs longer in healthcare than almost anywhere else. Daniel Trivellato, the company's VP for OT, healthcare, and cyber risk, points to data that does not expire: patient records keep their value for decades, long past any near-term quantum timeline. Daniel dos Santos, Forescout's VP of research, puts the operational problem plainly. The devices hardest to upgrade are usually the ones care teams can least afford to take offline.
None of this requires panic buying. It requires a list: which systems store, move, or process sensitive data, and which of those can realistically take a software update, ahead of the point when vendor PQC support actually lands. A ten-year-old infusion pump does not get a cryptography upgrade on a web browser's schedule. Start the inventory, and lock in vendor support timelines while the hardware replacement cycle, not the cryptography, sets the real deadline. The math favors whoever knows their fleet before the vendor does.