Context: Addressing Quantum Computing Concerns
You're in a risk committee meeting when someone mentions "Q-Day", the day quantum computers might break current encryption. Suddenly, you're asked if your encryption strategy needs an overhaul, if medical devices are at risk, and if this should be in your risk register.
These aren't just hypothetical questions. John Frushour, CISO at New York-Presbyterian Hospital, argues that practical readiness is more important than doomsday predictions. He points out that quantum-resistant technologies exist, commercial providers will handle much of the transition, and healthcare organizations can prepare without major disruptions.
Here's what your compliance and security teams need to know now.
Q1: Should Post-Quantum Cryptography Be in Our Risk Register?
Yes, but treat it as a technology transition risk, not an immediate threat.
Your ISO/IEC 27001 risk assessment (Clause 6.1.2) already requires identifying risks related to cryptographic controls. Consider post-quantum readiness as a medium-term technology obsolescence risk, similar to phasing out TLS 1.0 or SHA-1, but with more time to prepare.
Include it in your risk treatment plan with a timeline aligned with NIST's post-quantum cryptography standards. Don't create unnecessary urgency, but don't ignore it either. Auditors will expect you to acknowledge emerging cryptographic risks, especially if you handle protected health information or payment data.
Q2: What Can We Do Now Without Major Infrastructure Changes?
Upgrade cipher suites on systems you control.
If your load balancers, VPN concentrators, or hosted infrastructure support TLS 1.3 with strong cipher suites, enable them. This won't cause issues, TLS 1.3 ensures backward compatibility, and it sets a foundation for future quantum-resistant algorithms.
For SOC 2, this aligns with CC6.7 (transmission encryption) and CC6.1 (logical access controls). You're not implementing post-quantum algorithms yet, but you're showing that your cryptographic posture evolves with current standards. Document the changes and rationale in your control evidence.
For ISO/IEC 27001, this supports Annex A 8.24 (use of cryptography). Your cryptographic policy should reference NIST guidance and outline plans to adopt quantum-resistant algorithms as they become standardized and available.
Q3: Do We Need to Replace Medical Devices with Embedded Encryption?
No, and that's not the right approach.
Medical devices are a supply chain dependency, not an immediate action item for your team. Most healthcare organizations don't control the cryptographic implementations in diagnostic equipment, infusion pumps, or patient monitors. Your device manufacturers do.
What you can do: include post-quantum readiness as a vendor assessment criterion for new procurements. When evaluating suppliers under ISO/IEC 27001 Annex A 5.19 (information security in supplier relationships) or SOC 2 CC9.1 (vendor management), ask if they're tracking NIST post-quantum standards and their timeline for firmware updates.
For existing devices, monitor vendor communications about cryptographic upgrades as you do for security patches. Don't create a separate quantum remediation project, integrate it into your existing technology refresh cycles and vendor risk reviews.
Q4: How Do We Know If Our Infrastructure Is Vulnerable?
Conduct a cryptographic inventory, but keep it focused.
Identify where you're using public-key cryptography: TLS/SSL certificates, VPN tunnels, code signing, API authentication, and database encryption. These systems might be vulnerable to future quantum attacks on RSA, ECDSA, and Diffie-Hellman key exchange.
For ISO/IEC 27001, this inventory supports Annex A 8.1 (user endpoint devices) and A 8.24 (use of cryptography). For SOC 2, it shows due diligence under CC6.6 (logical access controls) and CC7.2 (system monitoring).
Don't try to inventory every encrypted field in every database or every device certificate. Focus on externally-facing systems and high-value data repositories first. If you're protecting cardholder data under PCI DSS or electronic protected health information under HIPAA, prioritize those systems.
Q5: Should We Rely on Vendors or Develop In-House Expertise?
Rely on commercial providers for implementation, but own the strategy.
Most organizations will adopt quantum-resistant cryptography through software updates from cloud providers, SaaS vendors, and infrastructure suppliers. You won't be developing post-quantum algorithms yourself.
What you need in-house: someone who understands your cryptographic dependencies well enough to ask vendors the right questions. When your cloud provider supports NIST-standardized quantum-resistant algorithms, know which workloads should migrate first based on data classification and regulatory requirements.
For SOC 2 and ISO/IEC 27001 audits, your Information Security Management System documentation should reference how you evaluate and adopt cryptographic standards. You don't need a quantum physicist on staff, but you need a defined process for tracking cryptographic obsolescence.
Q6: Is There Any Upside to Quantum Computing for Healthcare Security?
Yes, but it's further out than the threat timeline.
Quantum computing could enable advanced analysis of anonymized healthcare data for research without compromising patient privacy. It might strengthen certain types of encryption and improve computational models for threat detection when combined with AI-driven security tools.
However, don't let potential benefits distract from compliance work. Your risk treatment plan should address quantum threats to current encryption before planning quantum-enhanced security capabilities. ISO/IEC 27001 Clause 6.1.3 requires planning actions to address risks, opportunities come second.
Next Steps
Start with NIST's post-quantum cryptography project, which provides the technical standards your vendors will implement. Review your current cryptographic policy against ISO/IEC 27001 Annex A 8.24 and SOC 2 CC6.7 to ensure you have a framework for adopting new algorithms.
Then, talk to your infrastructure and SaaS providers. Ask when they plan to support NIST-standardized quantum-resistant algorithms and what the migration path looks like. You're not looking for promises, you're establishing whether they're tracking the standards and have a technical roadmap.
Finally, add post-quantum readiness as a standing item in your quarterly risk review. Not because Q-Day is imminent, but because cryptographic transitions take years to execute across complex environments. Organizations that start planning now won't be scrambling when quantum computing becomes commercially viable.



