As reported by Dark Reading, a study of 2.5 million devices across 50 healthcare organizations reveals the sector is dangerously unprepared for the post-quantum cryptography (PQC) era. While the headline frames this as a quantum readiness problem, Shield53's analysis suggests it is more accurately a legacy cryptography management crisis that quantum computing will eventually make catastrophic — but that is already creating exposure today.
Why This Matters Now, Not Later
The healthcare sector's quantum readiness gap is frequently dismissed as a future problem. It is not. The threat model has two components, and one is already active:
- "Harvest Now, Decrypt Later" (HNDL): Adversaries are actively exfiltrating encrypted healthcare data — electronic health records (EHR), genomic data, imaging archives — with the expectation that quantum capabilities will eventually unlock it. Given the longitudinal sensitivity of medical data (a person's DNA or health history does not expire), this is a uniquely severe risk for healthcare.
- Operational Technology (OT) Lifecycles: Medical IoT devices, infusion pumps, and imaging systems often have 10-15 year deployment lifecycles. Firmware-level cryptographic primitives embedded in these devices cannot be patched via software updates. Devices shipping today with classical cryptography will still be in production when quantum threats materialize.
The healthcare sector is not merely behind on a migration timeline. It is accumulating cryptographic debt on devices that cannot easily be upgraded, while adversaries are already stockpiling the encrypted output.
Who Is Most at Risk
Large hospital systems and integrated delivery networks with sprawling, heterogeneous device fleets are the most exposed. However, the risk is compounded for organizations that have not yet completed basic cryptographic asset inventories. You cannot migrate what you have not cataloged.
The Real Challenge: Cryptographic Discovery
The study's device count — 2.5 million across 50 organizations — underscores the scale problem. Most healthcare CISOs cannot answer a fundamental question: Where is cryptography used across our environment, and what algorithms are in use? Without a cryptographic bill of materials (CBOM), PQC migration is theoretical.
Shield53 Recommendations
Immediate Actions (0-6 Months)
Strategic Actions (6-24 Months)
- Adopt a Crypto-Agile Architecture: Ensure systems can swap cryptographic primitives without requiring code rewrites. This is the single most important architectural shift for long-term resilience.
- Pilot NIST PQC Standards: Begin pilots with ML-KEM (formerly Kyber) for key establishment and ML-DSA (formerly Dilithium) for signatures in non-production environments.
- Integrate PQC into Risk Frameworks: Update vendor risk assessments and third-party risk management policies to require PQC readiness timelines.
The healthcare sector's quantum readiness is not a waiting game. The data being collected today is the target of tomorrow's decryption capabilities. The time to inventory, prioritize, and architect for agility is now.