Healthcare
,
Industry Specific
,
Next-Generation Technologies & Secure Development
Security Leaders Say Legacy Devices and Vendor Dependence Are in the Way
Tiffany Wang •
September 4, 2026

Image: Shutterstock/ISMG
It is hard for hospitals to catch up with the transition to quantum-safe encryption when some of their systems are stuck at the turn of the millennium, said security leaders at major hospital networks.
See Also: Reduce Cloud Risk in Healthcare with Security by Default
The challenge stems from healthcare’s complex system of third-party vendors, medical devices in all shapes and technical debt. There are also executives who are skeptical of the need for post-quantum cryptography.
“We’re currently in the exploratory phase,” said New York-Presbyterian Hospital’s Senior Technical Architect Steve Craig at a Wednesday panel discussion at the U.S. government-sponsored 2026 Health Insurance Portability and Accountability Act Security conference.
“We’re discussing what we have. We’re starting to talk to our vendors, starting to ask questions about it, starting to get those into some of our risk reviews. We don’t expect our vendors to be ready, but we do expect our vendors to be aware, and we want to start getting it on their roadmap and know where they’re at,” Craig said.
Nathan Lesser, CISO at Children’s National Hospital, said the pediatrics provider has not reached the inventory phase yet. “I would say we’re behind Steve since they’re doing discovery. We’re talking about starting to do discovery,” Lesser said.
The quantum threat was thrust into center stage by June White House executive orders, which directed federal agencies to migrate most of their systems to quantum-resistant algorithms by 2030. The urgent call came after recent innovations and developments signaled that the much-discussed quantum machines are no longer a far-off prospect (see: Trump Executive Order Accelerates Post-Quantum Security Push).
“If you have a large enough quantum computer – what we today call a cryptographically relevant quantum computer – it would break many of the crypto systems that we rely on to provide protection,” said Dustin Moody, mathematician on the National Institute of Standards and Technology’s cryptography team.
“Specifically, it would break a class of crypto systems called public key cryptography. Now, that’s not all of cryptography, but it plays a crucial role in initial key establishment as well as digital signatures for authentication,” Moody said on the panel.
Larger and longer mathematical keys are not sufficient solutions, Moody said, because they will only buy weeks or months of time before quantum computers become fast enough to break them as well.
With quantum supercomputing capabilities, malicious actors could unlock critical data or manipulate identity verification to access systems. They could also store away encrypted traffic now and wait for the powerful computers to decrypt later.
A call to action from the G7 countries has framed PQC as a “foreseeable evolution of cryptographic best practices,” which Moody said will take organizations at least 20 years (see: G7 Says Migrating to PQC Early Is Cheaper Than Later).
“This migration will take time. It’s going to be costly and it’s going to be painful. And you need to do it before the quantum computer is built,” Moody said.
Healthcare faces an even harder task than other critical sectors like financial services and advanced manufacturing because of its complex vendor relationships and medical internet of things devices, Lesser said.
Hospitals manage some applications and endpoints in-house, while other software and equipment are leased, managed by third parties and connected to external applications. “We find ourselves in a position where even our discovery tools don’t do a good enough job of tracking everything that’s out there,” Lesser said.
“I have teams that are responsible for equipment and they don’t have an idea of what they’re working on, let alone what’s involved in the stuff they’re working on,” Craig said. “So they’re dependent on a vendor who says, ‘How do you spell PQC?'”
Some vendors don’t know what’s coming next because they are still trying to upgrade the deprecated secure sockets layer protocol to the transport layer security encryption, introduced in 1999.
“I’ve seen operating systems on medical devices that when I see them I just have to shake my head. These things should not have been on the network for the last decade or more,” Craig said. “When you run across those, and then you say, ‘So, you’re going to handle PQC very well, won’t you?’ The answer went, ‘Windows 98 doesn’t support PQC. I don’t know why.'”
The cost of modernizing the system is already “prohibitive,” Craig said. Then, the TLS certificate lifespans are being reduced to 47 days by 2029, mandating organizations to renew their certificates almost every month, which takes energy and awareness away from PQC.
“They’re like, as long as we keep updating the certificates every month and a half, we should be fine. No, that’s not even close. Just getting people to pay attention – I feel like the crazy man screaming at the storm,” Craig said.
Lesser said he tried getting executives’ heads around Q-day by comparing it with Y2K, when organizations worldwide had to update computer systems that stored years of data with only two digits and risked misreading 2000 as 1900 come the advent of Jan. 1, 2000. But that story had been a hard sales pitch.
“The response we get is like, ‘Oh yeah, well, but that was a big nothing burger, right?’ That’s a little funny to say for the people in the outside world that largely experienced Y2K as a nothing burger,” Lesser said. “It was a massive buildup to an event that didn’t happen, but only because there was so much work that went into converting all of these systems.”
In resource-constrained situations, organizations can first lean on PQC-secure communications provided by major technology firms such as Cisco, Cloudflare, Google and AWS, said John Dombrowski, senior cybersecurity engineer at Mitre, the nonprofit behind the ATT&CK framework.
Once migration begins, organizations should adopt NIST’s finalized ML-KEM and ML-DSA post-quantum cryptography standards, Moody said. Although the algorithms may not be compatible with small devices that cannot support even classical encryption, that should not delay action.
“There could be new algorithms in the future that have smaller signatures or smaller ciphertext sizes. We don’t want you to wait to migrate because you’re hoping for something like that to come along,” Moody said. “If in the future better ones come along, well, you built in crypto agility, so you’ll be able to switch to those.”