Healthcare sector lags in quantum security

Healthcare entities lack readiness to counter cybersecurity risks emanating from quantum computing, as highlighted in a recent study. This cutting-edge technology has the potential to compromise encryption mechanisms safeguarding patient information.
Medical equipment trails standard IT systems in security preparedness. Merely 6% of medical devices possess protection against future quantum computer assaults, in contrast to 50% of conventional IT infrastructure.
Data categories including electronic health records, diagnostic imaging, and laboratory findings face the highest exposure. Industry specialists recommend healthcare administrators prioritize addressing these vulnerabilities promptly.
Researchers project that functional quantum computers will soon demonstrate superior and expedited processing capabilities for detailed computations compared to classical machines. These advancements, once theoretical, are edging closer to practical implementation.
Global governments and institutions across all industries express concern over quantum computers’ ability to easily compromise encryption methods that secure digital systems today, from financial transactions to hospital networks.
The competition is underway to deploy post-quantum cryptography, innovative encryption protocols engineered to resist both classical and quantum computer attacks, prior to malicious actors exploiting vulnerable systems.
Researchers examined over 2.5 million devices across more than 50 healthcare institutions and discovered that interconnected medical tools such as infusion pumps and patient monitors are less equipped for post-quantum cryptographic transitions than traditional IT systems like workstations and servers.
Medical equipment is notoriously challenging to update yet remains critical for patient care. While IT constitutes 66% of connected devices in a healthcare setting, insecure medical devices could present a security risk if they fail to transition to post-quantum cryptography.
The team also scrutinized over 5,500 internet-accessible healthcare systems, including patient portals and specific application programming interfaces. Only 31% of these systems support an encryption protocol compatible with post-quantum cryptography.
“The primary threat is not that hackers will suddenly use quantum computers to attack hospitals tomorrow,” said Daniel Trivellato, vice president of operational technology, healthcare and cyber risk solutions at Forescout.
Daniel Trivellato said, “Healthcare is particularly exposed because medical records, diagnostic images, laboratory results, and prescription histories can remain sensitive and valuable for decades.”
Ransomware incidents are already widespread in the healthcare sector, even without considering quantum threats. Between January and August this year, Forescout documented 461 public ransomware incidents targeting healthcare providers globally, marking a 47% rise from the same timeframe last year.
Healthcare data breaches incur an average cost of approximately $6.64 million per incident, based on data from IBM. Organizations aiming to enhance security before quantum computing emerges can adopt established frameworks, such as those developed by the National Institute of Standards and Technology.
The National Institute of Standards and Technology offers guidelines and tools to strengthen cybersecurity resilience. Healthcare organizations can leverage these materials to prepare for potential quantum computing risks.
