Skip to content

Patient records stay sensitive for a lifetime, on devices that cannot be patched to match.

Encrypt ePHI in motion across bedside devices, imaging and interface engines without touching them, and keep the asset inventory and network map the HIPAA update asks for.

Q-day is uncertain. The requirements for hospital systems are not.

Nobody knows when a cryptographically relevant quantum computer will arrive (Q-day), but your cryptography requirements do not depend on that date. Four reasons to start now:

AI is already finding weaknesses in algorithms

Anthropic’s Claude Mythos preview found serious weaknesses in candidate algorithms without a quantum computer. Cryptography can fail before Q-day arrives.

Adversaries are harvesting encrypted data now

They are collecting patient records which stay sensitive for a lifetime, to decrypt when Q-day arrives: harvest now, decrypt later.

Regulators already require PQC migration

For a hospital that means the safeguards on ePHI wherever it moves that the HIPAA Security Rule requires, the encryption in transit, asset inventory and network map its proposed update makes mandatory, and the cyber-device requirements FDA section 524B places on connected instruments.

Estimates for Q-day keep shrinking

Google has set 2029 as the target for its own migration. If yours is not finished in time, the foundation of EHR, clinical-device and payer connections is at risk.

Google’s 2029 target and resource estimates: QuSecure, April 2026. NIST IR 8547, initial public draft, November 2024. Anthropic, Claude Mythos preview, 2026.

Why use QuProtect?

Cryptography belongs in a layer you control and configure, not in application code.

No rewrite, no rip-and-replace

QuProtect moves critical and legacy systems to PQC in a fraction of the time and cost.

Discovery and remediation in one platform

Many PQC solutions stop at discovery and leave the fix to you.

Built for large, complex organizations with highly sensitive traffic

Developed with the U.S. Army and U.S. Air Force.

Nothing is re-coded

A hospital cannot take clinical systems down to re-code them, so QuProtect does not ask for it.

The next migration is a configuration change

It is made from an Orchestrator you control, not run as another program.

Proven in production

Banco Sabadell validated post-quantum TLS in four months.

Use case in action

Your network, from the cryptography it runs today to the policy change that keeps it current. Move through the five steps, or click a number on the drawing.

  1. Clinical floors

    • Bedside monitors and pumps cannot be upgraded
    • Imaging (CT, MRI) cannot be upgraded
    • Lab analyzers cannot be upgraded
  2. Hospital data centre

    • Interface engine (HL7)
    • EHR
    • PACS
  3. Outside the walls (not yours to change)

    • Payers and clearinghouses
    • Health information exchange
    • Cloud EHR and telehealth

Legacy cryptography, and what Q-day does to it

Monitors, pumps, scanners and analyzers reach the interface engine and PACS on old TLS or none, and the EHR reaches payers, the health information exchange and telehealth on TLS 1.2 with RSA key exchange. Traffic recorded today can be stored until a quantum computer running Shor’s algorithm recovers those keys, and a patient record stays sensitive for a lifetime.

Step 1 of 5

Sensors find the legacy negotiations and rank the violations

Reconnaissance sensors read what is on the device VLANs and the data centre and record the protocols, cipher suites, certificates and keys in use, without touching a device. Each policy violation is ranked by severity: the clinical device hops first, RSA key exchange on the payer and exchange links next.

Step 2 of 5

Encryptors remediate at the network layer

A gateway in front of each device VLAN and sidecars beside the interface engine, the EHR and PACS carry each hop over TLS 1.3 with NIST post-quantum key exchange, X25519MLKEM768. No patch on a pump or a scanner, and no application change.

Step 3 of 5

Data in transit is secured, and the CBOM proves it

ePHI recorded in transit from now on is not readable by a future quantum computer. The CBOM lists each connection’s protocol, algorithm and certificate with no open violations, and doubles as the asset inventory and network map the HIPAA update asks for.

Step 4 of 5

Crypto-agility: the next algorithm is a policy change

When a standard moves, the Orchestrator pushes the new policy to each encryptor and the connections renegotiate, here from ML-KEM-768 to ML-KEM-1024, while care continues. It is a policy push, not a device refresh.

Step 5 of 5

Other use cases

Asset inventory and network map for HIPAA

The CBOM doubles as the technology asset inventory and network map the Security Rule update asks for.

Interface engine, EHR and PACS

Sidecar encryptors carry HL7 and imaging traffic over TLS 1.3 and post-quantum key exchange with no application change.

FDA 524B connected devices

Cyber-device requirements met at the network for instruments on 10 to 20 year lifecycles.

Evidence for the risk analysis

Logged handshakes and rotations with a CBOM carrying owner and criticality.

ePHI in motion on device VLANs

Monitors, pumps and imaging sit behind gateway encryptors, so encryption in transit does not depend on patching the device.

Payer, HIE and telehealth links

Connections leaving the hospital carry post-quantum TLS to its edge, and end to end where the partner negotiates it, so records recorded in transit today are not readable later.

Certificates at 47-day lifetimes

Automated provisioning and rotation across clinical and administrative systems.

Algorithm change by policy

The next standard is a policy push, not a device refresh.

Reference material for this page

See what your network negotiates today