Are Medical Devices Ready for the Post-Quantum Threat?

Oct 7, 2026
Interview
Are Medical Devices Ready for the Post-Quantum Threat?

Vernon Yai stands at the critical intersection of patient safety and data integrity, serving as a leading voice in the urgent transition to post-quantum security. As an expert in data governance and risk management, he has spent years advising healthcare delivery organizations on how to shield their most sensitive assets from emerging digital threats. His work focuses on the specialized vulnerabilities of medical technology, where the typical rules of IT security often fail against the rigid lifecycles of clinical hardware. This conversation explores the daunting reality of securing millions of connected medical devices against the looming shadow of quantum-enabled decryption.

Only 6% of IoMT and 16% of medical OT devices currently support the protocols required for post-quantum cryptography transition. Why do these specific systems lag so far behind traditional IT, and what unique hardware limitations prevent them from being easily upgraded?

The disparity is stark when you compare that 6% figure to the 50% readiness we see in traditional IT, and it stems from a fundamental difference in how these machines are built. Unlike a standard laptop that receives monthly OS updates, an infusion pump or a patient monitor is often built on highly specialized, low-power microcontrollers designed for one specific clinical task. These devices frequently lack the processing power and memory overhead required to run the computationally heavy math involved in new post-quantum algorithms. Furthermore, many of these systems have rigid, “closed-box” architectures where the manufacturer never intended for the underlying Secure Shell or encryption implementations to be swapped out by an end-user. We are dealing with medical hardware that was designed for a ten-to-fifteen-year lifecycle, often prioritising physical reliability over the agility needed to adopt modern cryptographic standards.

Internet-exposed systems like EMRs and PACs are frequently identified as lacking TLS 1.3 support, making them prime targets for “harvest now, decrypt later” tactics. How do these attacks specifically jeopardize patient privacy over a decades-long timeline, and what immediate steps can be taken to secure this data?

The “harvest now, decrypt later” strategy is a ticking time bomb for healthcare because, unlike a stolen credit card that can be canceled, a person’s medical history is permanent. When we see that only 31% of the 5,500 internet-exposed systems analyzed support TLS 1.3—the only version capable of supporting standardized PQC—it means the remaining 69% are leaking data that can be warehoused by adversaries today. These attackers are collecting diagnostic images and laboratory results with the intent of breaking the encryption in a few years when quantum computers reach maturity. To fight this, organizations must immediately prioritize the implementation of TLS 1.3 across all outward-facing platforms and consider masking these systems behind more robust security gateways to prevent direct exposure. Every day that sensitive data travels over an outdated protocol is a day we are handing a future key to our most private information to bad actors.

Healthcare environments depend heavily on infusion pumps and imaging systems that often have long lifecycles and slow adoption of modern standards. What are the logistical challenges of segmenting these legacy systems, and how can organizations maintain patient care while isolating vulnerable hardware?

Segmenting a hospital is like trying to change the tires on a car while it’s going sixty miles an hour; you cannot simply shut down the network without risking patient lives. The logistical nightmare lies in the fact that these legacy systems, like massive MRI machines or bedside pumps, must communicate with Electronic Medical Records to function, which creates thousands of necessary “holes” in any firewall. If you isolate a device too aggressively, a physician might not get a critical lab result in time, leading to a breakdown in care. The solution involves micro-segmentation, where we create very tight, monitored “bubbles” around these devices that only allow specific, verified communication patterns. This requires a deep, sensory understanding of the network traffic so that we can block potential threats without ever interrupting the flow of data that a clinician needs at the bedside.

Transitioning to quantum-ready standards requires a complete inventory of all connected assets and their communication patterns. Can you walk us through a step-by-step strategy for auditing these devices and how a hospital should prioritize replacements versus applying compensating controls?

An effective audit begins with total visibility; you cannot protect what you cannot see, so the first step is deploying automated tools to identify all 2.5 million-plus devices that might be lurking across a large healthcare network. Once you have an inventory, you must classify them by clinical criticality and data sensitivity—separating a guest-room television from a life-sustaining ventilator. After classification, we analyze their communication protocols to see which ones are using vulnerable versions of SSH or TLS. For those that can’t be upgraded, we perform a triage: if a device is at the end of its life, we prioritize it for immediate replacement with a PQC-ready model. For those with years of service left, we apply compensating controls, such as placing them behind a dedicated security proxy that can handle the modern encryption the device itself cannot manage.

Since many critical devices are non-upgradeable, how should procurement processes change to ensure new equipment is PQC-compliant? What specific technical requirements or roadmap commitments should healthcare administrators demand from their vendors during the bidding process?

We have to stop buying yesterday’s problems, which means healthcare administrators must become much more aggressive during the bidding phase. Procurement teams should mandate that any new connected device must support TLS 1.3 and have a documented, verifiable path for future cryptographic agility. It is no longer enough for a vendor to promise “security”; we need to see specific roadmap commitments that detail how they will transition to post-quantum algorithms as they become standardized. Administrators should demand “right-to-patch” clauses in contracts that hold vendors accountable for keeping the cryptographic stack current throughout the entire lifespan of the equipment. If a vendor cannot demonstrate how their device will remain secure against quantum threats, they should not be allowed on the hospital floor.

What is your forecast for the security of healthcare data over the next five years as quantum computing capabilities continue to advance?

My forecast is that the next five years will be a period of intense “cryptographic reckoning” where the gap between prepared and unprepared organizations will lead to a massive disparity in patient trust. We are moving toward a reality where quantum computers will be capable of breaking the encryption we currently rely on, making today’s data-gathering efforts by threat actors a significant liability. I expect to see a surge in specialized “security-as-a-service” models designed specifically to wrap legacy medical hardware in protective, quantum-resistant layers. Ultimately, the organizations that will thrive are those that stop viewing cybersecurity as a back-office IT issue and start treating it as a fundamental pillar of patient safety and long-term institutional survival.

Trending

Subscribe to Newsletter

Stay informed about the latest news, developments, and solutions in data security and management.

Invalid Email Address
Invalid Email Address

We'll Be Sending You Our Best Soon

You’re all set to receive our content directly in your inbox.

Something went wrong, please try again later

Subscribe to Newsletter

Stay informed about the latest news, developments, and solutions in data security and management.

Invalid Email Address
Invalid Email Address

We'll Be Sending You Our Best Soon

You’re all set to receive our content directly in your inbox.

Something went wrong, please try again later