up:: For Business Leaders MOC

What if we run a clinic or hospital?

Health systems hold the worst combination of properties in this entire subject: data that stays sensitive for a patient’s whole life, retention obligations that force you to keep it, and equipment that cannot be updated.

Most organizations have one of those problems. You have all three at once, usually on a margin that leaves no room for a program.

The realistic position is that a health system will not solve this the way a bank will. What it can do is know which of its systems carry lifetime-sensitive records, get dated answers from the handful of vendors that matter, and stop buying equipment that makes the problem permanent.

The short version:

  • Clinical facts stay true for a lifetime, which makes health records the longest-lived personal data any organization holds.
  • Retention rules force you to keep them. Federal documentation carries a 6-year floor and state medical-record retention frequently runs longer.
  • Your estate is mostly 5 vendors, which is the good news, since it makes the vendor question tractable.
  • Connected medical devices are the hard part, and for some there is no clean answer.
  • Procurement is your strongest lever, because equipment bought this year sets your exposure for 15.
  • A small practice can do the useful parts in a morning.

Why is health data the worst case?

Because 3 things stack, and few sectors carry all 3.

It never stops being true. A diagnosis from 2026 is still a diagnosis in 2046. A genetic result, a psychiatric history, a fertility record, or an HIV status carries consequence for as long as the patient lives, and in the genetic case for relatives who were never your patients.

You are required to keep it. Federal health-privacy rules require 6 years of compliance documentation, state medical-record retention often runs longer, and pediatric records commonly persist for years past majority. Deletion, the cheapest protection available to most organizations, is largely unavailable to you.

Source: 45 CFR § 164.316(b)(2)(i), govinfo.gov.

It concentrates. A single record links identity, family, finances, employment, and behavior. A breach of it is not one fact about a person, it’s the person.

What in our estate actually matters?

For most providers the answer is a short list, which is genuinely encouraging.

SystemWhy it mattersWho controls the cryptography
Electronic health recordsThe concentration point for everything aboveYour EHR vendor, almost entirely
Imaging and PACSLong-retained, large, frequently on old infrastructureVendor, often on slow release cycles
Lab and diagnostic interfacesContinuous flows of results between organizationsShared between you and the lab
Billing and clearinghousesPersonal and financial data together, moving to third partiesClearinghouse and payer
Patient portals and telehealthWhere patients send you things over the open internetVendor, usually on modern platforms
Connected medical devicesThe category with no clean answerManufacturer, frequently fixed at build
Research data and biobanksGenetic and longitudinal data with no expiry at allMixed, often institutional

Five of those 7 are vendor products. That means the highest-value action available to you is a set of emails rather than an engineering program. See What can I not fix myself.

What about the devices?

This is the part with no satisfying answer, and pretending otherwise would be dishonest.

Connected medical equipment routinely carries cryptography fixed at manufacture, service lives of 10 to 20 years, and safety certification that makes any change a re-certification event. Infusion pumps, imaging systems, monitors, and implanted devices all sit in this category. For implanted devices, updating cryptography can mean a procedure on a patient.

Regulators have moved on device cybersecurity generally, and premarket expectations now address it, which reaches equipment being designed rather than equipment already in your building.

Source: U.S. Food and Drug Administration, “Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions,” fda.gov.

What’s actually available to you:

  1. Ask at purchase, while you still have leverage. Equipment bought this year determines your exposure into the 2040s. The procurement question is the single highest-leverage thing a health system can do here.
  2. Segment what can’t be fixed. A device whose cryptography is frozen is a device whose network exposure should be limited, which is standard practice for other reasons already.
  3. Know which ones they are. An inventory of unfixable equipment is a genuine asset for planning replacement cycles and for answering an auditor.
  4. Leave the systemic part to regulators and manufacturers. A hospital cannot re-engineer an infusion pump, and the honest allocation of that responsibility sits upstream. See Is my pacemaker safe.

What should we actually do?

Six things, ordered by value against effort. None requires a program.

  1. Send the vendor question to your EHR, imaging, billing, and lab partners. Four emails. The template at What if we are a small business works unchanged.
  2. Put a post-quantum requirement into device and system procurement. Free, immediate, and it prevents you from buying a 2045 problem in 2027.
  3. Identify which record categories carry lifetime sensitivity. Genetic, psychiatric, reproductive, infectious disease, and pediatric records sit at the top. This tells you what to protect first.
  4. Review retention against what the rules actually require. Records kept past obligation are exposure you chose. Within the rules there is usually more room than assumed.
  5. Name an owner. One person who can get answers from IT, procurement, and compliance.
  6. Write down where you are. Payers, partners, and research collaborators will start asking, and an honest position beats an improvised one.

Does this differ by size?

Substantially, and small practices have the tractable version.

A practice or small clinic runs on an EHR, a billing service, and a handful of devices. That entire exposure is a vendor list you already have in your billing records, and the useful work is a morning. See What if we are a small business.

A hospital or health system has the full estate problem: decades of accumulated systems, acquisitions, thousands of connected devices, and research infrastructure. The work looks like any large organization’s, with the device population as the distinguishing difficulty. See Where do we actually start.

What do we tell patients who ask?

Honestly, and with the reassurance that’s actually true.

The accurate answer for most providers is that the data is encrypted today, the encryption in use is scheduled for replacement industry-wide, you have asked your vendors for their timelines, and the records that stay sensitive longest are the priority. That’s a better answer than most organizations in any sector can give.

What to avoid is claiming a program you don’t have. Patients rarely ask, and regulators and payers ask in writing.

Questions people ask

Does HIPAA require us to do anything about this? No rule names post-quantum cryptography. The security rule requires reasonable and appropriate safeguards, which is a general standard interpreted against what was publicly known at the time, and the replacement standards have been public since August 2024.

Are we a target? Attribution for any specific dataset is unprovable. What’s documented is that health data is among the most valuable categories in every breach market that exists, and it has the longest useful life of anything you hold.

Our EHR vendor says they’re compliant. Ask which algorithms and which product version, and whether it’s enabled or merely supported. Shipping support and having it turned on are different states.

What about our research data? Genetic and longitudinal research data has no expiry at all and frequently outlives the study, the funding, and sometimes the institution. It belongs at the top of your priority list.

Can we just encrypt everything more? Adding layers of the same kind of encryption doesn’t address this. The exposure is in how keys are agreed rather than how records are scrambled. See What is technically happening to our systems.

We have no IT staff. Then the vendor emails and the procurement question are your whole program, and they’re genuinely most of the available value.

Where to go next

Go deeper into the technical detail

The technical version, covering implantables and hospital equipment with decade-plus service lives, is PQC in Medical Devices.

These open the Post-Quantum Field Guide, a separate site written for security professionals.


Last verified 2026-07-31 · Maintained by Addie LaMarr, LaMarr Labs.