Skip to main content
Skip to content
Home/Knowledge Center/Post-Quantum Cryptography for Healthcare
Industry8 min read

Post-Quantum Cryptography for Healthcare

Patient health records have multi-decade lifetimes and face immediate HNDL risk. Healthcare organizations must migrate to post-quantum cryptography before their long-lived PHI is compromised by future quantum decryption.

Healthcare HNDL Exposure

Healthcare organizations are among the most exposed to harvest-now-decrypt-later risk because of the extraordinary longevity of health data. A patient's electronic health record may be created at birth and retained through their lifetime and beyond. Medical history, diagnoses, genetic data, mental health records, and treatment information are among the most sensitive categories of personal data.

An adversary collecting encrypted health records today bets that the data will still be valuable when quantum decryption becomes possible. For health data with a fifty-year confidentiality requirement, that bet has a very long payoff window. Healthcare organizations must treat HNDL as an immediate threat to their archival data, not a future concern.

Long-Lived Health Data

Electronic health records (EHR) are the primary concern. EHRs contain decades of patient history, including diagnoses, medications, lab results, imaging, and clinical notes. These records are retained for the patient's lifetime and often beyond. Systems that transmit or store EHRs using quantum-vulnerable encryption are exposing this data to HNDL collection today.

Genetic and genomic data represents an even higher-value target. Genomic sequences reveal information not just about the individual patient but about their biological relatives, and the sensitivity of this information is permanent. Organizations handling genomic data should treat their cryptographic posture with particular urgency.

Insurance and billing records, while less sensitive than clinical records, are retained for years under regulatory requirements. HIPAA mandates record retention of at least six years, and some state laws require longer retention. Systems protecting this data should also be included in the migration inventory.

Medical Device Challenges

Medical devices present some of the most difficult post-quantum migration challenges. Implanted devices, diagnostic equipment, and patient monitoring systems often have long operational lifetimes and limited or no capacity for over-the-air cryptographic updates. A device deployed today may still be in service a decade from now.

Device manufacturers must begin incorporating post-quantum algorithms into new products now. Organizations procuring new devices should require post-quantum readiness as part of their procurement criteria. For devices already in service, organizations must assess whether firmware updates are feasible and coordinate with manufacturers.

FDA guidance on cybersecurity for medical devices increasingly addresses cryptographic requirements. The 2023 FDA Cybersecurity Guidance for Medical Devices emphasizes the importance of updatable software and cryptographic agility. Organizations should review device inventories against this guidance.

Regulatory Context

HIPAA's Security Rule requires covered entities and business associates to implement appropriate technical safeguards to protect electronic protected health information (ePHI). While HIPAA does not yet specifically mandate post-quantum cryptography, the Security Rule's requirements for encryption and access controls extend to the choice of cryptographic algorithms.

Healthcare organizations operating systems that include government healthcare programs should also monitor federal agency guidance from HHS and CISA. CISA has published healthcare-specific post-quantum cybersecurity guidance and should be treated as an authoritative source for healthcare sector requirements.

Health information exchanges and regional health information organizations create ecosystem dependencies. Migrating one organization's systems while its HIE counterparts remain on classical cryptography limits the protection available for data in transit across the exchange.

Implementation Approach

The migration starting point for healthcare is a cryptographic inventory focused on systems protecting ePHI with long retention periods. EHR systems, imaging archives, genomic data repositories, and health information exchange connections are all high-priority inventory targets.

Hybrid TLS for all connections carrying ePHI provides immediate HNDL protection for new data in transit. Certificate migration for systems authenticating healthcare entities follows. Medical device procurement criteria should be updated immediately to require post-quantum algorithm support in new purchases.

Business associate agreements and contracts with health technology vendors should be reviewed to ensure they address cryptographic security obligations, including the expectation of post-quantum readiness as standards are finalized.

References

Apply This to Your Organization

Schedule a Consultation

A post-quantum readiness specialist will walk through how these concepts apply to your specific systems, data, and timeline.