Patient records stay sensitive for a lifetime, on devices that cannot be patched to match.
Encrypt ePHI in motion across bedside devices, imaging and interface engines without touching them, and keep the asset inventory and network map the HIPAA update asks for.
Q-day is uncertain. The requirements for hospital systems are not.
Nobody knows when a cryptographically relevant quantum computer will arrive (Q-day), but your cryptography requirements do not depend on that date. Four reasons to start now:
AI is already finding weaknesses in algorithms
Anthropic’s Claude Mythos preview found serious weaknesses in candidate algorithms without a quantum computer. Cryptography can fail before Q-day arrives.
Adversaries are harvesting encrypted data now
They are collecting patient records which stay sensitive for a lifetime, to decrypt when Q-day arrives: harvest now, decrypt later.
Regulators already require PQC migration
For a hospital that means the safeguards on ePHI wherever it moves that the HIPAA Security Rule requires, the encryption in transit, asset inventory and network map its proposed update makes mandatory, and the cyber-device requirements FDA section 524B places on connected instruments.
Estimates for Q-day keep shrinking
Google has set 2029 as the target for its own migration. If yours is not finished in time, the foundation of EHR, clinical-device and payer connections is at risk.
Google’s 2029 target and resource estimates: QuSecure, April 2026. NIST IR 8547, initial public draft, November 2024. Anthropic, Claude Mythos preview, 2026.
Why use QuProtect?
Cryptography belongs in a layer you control and configure, not in application code.
No rewrite, no rip-and-replace
QuProtect moves critical and legacy systems to PQC in a fraction of the time and cost.
Discovery and remediation in one platform
Many PQC solutions stop at discovery and leave the fix to you.
Built for large, complex organizations with highly sensitive traffic
Developed with the U.S. Army and U.S. Air Force.
Nothing is re-coded
A hospital cannot take clinical systems down to re-code them, so QuProtect does not ask for it.
The next migration is a configuration change
It is made from an Orchestrator you control, not run as another program.
Proven in production
Banco Sabadell validated post-quantum TLS in four months.
Use case in action
Your network, from the cryptography it runs today to the policy change that keeps it current. Move through the five steps, or click a number on the drawing.
-
Clinical floors
- Bedside monitors and pumps cannot be upgraded
- Imaging (CT, MRI) cannot be upgraded
- Lab analyzers cannot be upgraded
-
Hospital data centre
- Interface engine (HL7)
- EHR
- PACS
-
Outside the walls (not yours to change)
- Payers and clearinghouses
- Health information exchange
- Cloud EHR and telehealth
Legacy cryptography, and what Q-day does to it
Monitors, pumps, scanners and analyzers reach the interface engine and PACS on old TLS or none, and the EHR reaches payers, the health information exchange and telehealth on TLS 1.2 with RSA key exchange. Traffic recorded today can be stored until a quantum computer running Shor’s algorithm recovers those keys, and a patient record stays sensitive for a lifetime.
Sensors find the legacy negotiations and rank the violations
Reconnaissance sensors read what is on the device VLANs and the data centre and record the protocols, cipher suites, certificates and keys in use, without touching a device. Each policy violation is ranked by severity: the clinical device hops first, RSA key exchange on the payer and exchange links next.
Encryptors remediate at the network layer
A gateway in front of each device VLAN and sidecars beside the interface engine, the EHR and PACS carry each hop over TLS 1.3 with NIST post-quantum key exchange, X25519MLKEM768. No patch on a pump or a scanner, and no application change.
Data in transit is secured, and the CBOM proves it
ePHI recorded in transit from now on is not readable by a future quantum computer. The CBOM lists each connection’s protocol, algorithm and certificate with no open violations, and doubles as the asset inventory and network map the HIPAA update asks for.
Crypto-agility: the next algorithm is a policy change
When a standard moves, the Orchestrator pushes the new policy to each encryptor and the connections renegotiate, here from ML-KEM-768 to ML-KEM-1024, while care continues. It is a policy push, not a device refresh.
Other use cases
Asset inventory and network map for HIPAA
The CBOM doubles as the technology asset inventory and network map the Security Rule update asks for.
Interface engine, EHR and PACS
Sidecar encryptors carry HL7 and imaging traffic over TLS 1.3 and post-quantum key exchange with no application change.
FDA 524B connected devices
Cyber-device requirements met at the network for instruments on 10 to 20 year lifecycles.
Evidence for the risk analysis
Logged handshakes and rotations with a CBOM carrying owner and criticality.
ePHI in motion on device VLANs
Monitors, pumps and imaging sit behind gateway encryptors, so encryption in transit does not depend on patching the device.
Payer, HIE and telehealth links
Connections leaving the hospital carry post-quantum TLS to its edge, and end to end where the partner negotiates it, so records recorded in transit today are not readable later.
Certificates at 47-day lifetimes
Automated provisioning and rotation across clinical and administrative systems.
Algorithm change by policy
The next standard is a policy push, not a device refresh.