A medical record outlives the cryptography protecting it.
A diagnosis recorded today must stay confidential for the patient's lifetime, and in some cases beyond it. The encryption protecting that record in transit and the keys wrapping it at rest rely on asymmetric algorithms with a published deprecation trajectory. Harvest-now-decrypt-later does not need to break anything this year; it needs your network traffic and a decade of patience. For health data, the decade is the problem: no other sector has a wider gap between how long the data must stay private and how long its protection will hold.
The public record is explicit. NIST finalized the replacement algorithms in August 2024 and has published the transition timeline. HIPAA's confidentiality obligations do not expire when an algorithm does. And the FDA now requires premarket cybersecurity documentation for connected devices, including a software bill of materials, which means device cryptography is already a regulatory artifact, not an engineering detail.
The identity problem wears a hospital badge and a device label.
Healthcare runs on signatures that prove who did what: electronic prescriptions for controlled substances, clinician authentication, order signing, audit trails that stand up in court. Forge those and the loss is not privacy, it is the integrity of care records and the attribution behind clinical decisions.
Then there is the device fleet. Infusion pumps, imaging systems, and monitors authenticate to your network with machine credentials and ship with firmware signing keys expected to work for fifteen years in the field. A device certified today on quantum-vulnerable signatures will still be on a med-surg floor when those signatures are deprecated. Device lifetime plus procurement cycle versus migration window: in healthcare, that math fails earlier than anywhere else.
The inventory your scan did not produce.
Scanning tools find algorithms in application code. They do not find the credential population a hospital actually runs on: device certificates, service accounts bridging the EHR to everything else, interface engine credentials, badge and SSO infrastructure, and the signing keys inside biomedical equipment your IT asset system lists as a serial number. QCI-QS1 v2.3 makes machine identities a required inventory field group, with order-of-magnitude estimates accepted, because a defensible estimate beats a precise count of the ten percent anyone has mapped.
Running the same migration twice.
Health systems are mid-flight on identity modernization: badge-tap SSO, passkeys for the workforce, federated patient identity. Every credential those programs issue on quantum-vulnerable algorithms is a credential you will issue again. One shared inventory, one re-issuance plan, one named owner for the seam between the identity program and the PQC migration. The standard requires the coordination; whether the programs merge stays your call.
For community hospitals and regional systems.
You do not need a quantum program this year. You need a named owner, an inventory of the systems that touch PHI and the devices that touch patients, a data-lifetime map that will mostly read "decades," and roadmap requests in the mail to your EHR vendor and your top device manufacturers. That is one quarter of work, the sequence is in the standard, and the standard is free.