Skip to content
TrackPodcasts
businessMar 10, 2026

How Healthcare Can Get Started Addressing Post-Quantum Risk

About this episode

Many healthcare sector organizations are delaying to even begin contemplating - let alone strategizing - how to mitigate post-quantum risk - but procrastination is a major mistake, said Ali Youssef, director of emerging tech security, at Henry Ford Health.

Get every episode summarized

Each time Data Breach Today Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

50 searchable segments. Every word is indexed and playable.

How Healthcare Can Get Started Addressing Post-Quantum Risk

Data Breach Today Podcast

0:00
0:00

Full transcript

Data Breach Today PodcastHow Healthcare Can Get Started Addressing Post-Quantum Risk. Machine-transcribed; use the interactive transcript above to jump the player to any line.

I'm Mary Ann Kolbasek-McGee, Executive Editor at Information Security Media Group. I'm here at HIMS 26 today, speaking with Ali Yusef, who is Director of Emerging Technology Security at Henry Ford Health. So Ali, you're going to be here speaking at HIMS about the post-quantum concerns in health care. At this point, do you think health care SISOs, CIOs, and their teams are paying enough attention to quantum risk? Why or why not? And is this something that you think they perceive as being too far in the future still to worry about? Yes, yeah, I mean, my experience with it. So in our case at Henry Ford, we just started the post-quantum cryptography program. And I think one of the things people get confused about is, you know, confusing post-quantum computing with post-quantum cryptography. We're not concerned about, you know, supercomputers being very affordable or quantum computers, you know, being mainstream in the near term.

But from a post-quantum cryptography standpoint, I think this is the right time to start preparing, you know, developing programs that may span several years to actually get our arms around. How we're using cryptography today, especially in a health care setting, a lot of the devices are legacy devices. So understanding in depth, you know, how cryptography is being used and coming up with a plan to be prepared for the future, you know, for when these computers do emerge on a large scale. So with that said, what would you like, what would you like health care SISOs, CIOs, and their teams to know about what quantum could potentially mean operationally to their organizations if they are unprepared in a post-quantum world? Sure, yeah. So I mean, there are some very serious HIPAA ramifications that we need to be aware of, I think, in this space, especially in health care where we have to retain data for long periods of time.

I think it's this notion of capture that data now and decrypted later is very concerning from a HIPAA standpoint. And I think cryptography is really, it's an invisible enemy. We're not aware that we've had an issue until after it happens and some communication breaks down and, you know, there could be patient safety ramifications and those scenarios that I think we need to be aware of. So I think first and foremost, the most important thing to get in front of right away is having an understanding of your inventory when it comes to cryptography. How many devices are legacy? How many can be upgraded? And to start talking with manufacturers to try to understand what are their plans for the future? Are they thinking about this? Are they preparing for it? Because worst case scenario is, you know, we get to 2030 and then we're completely unprepared in having to deal with this monster of an issue. So in my opinion, I mean, there's no harm in beginning to prepare now while we have that runway.

So what types of IT systems, applications and devices in healthcare, you think are most at risk for quantum vulnerable cryptography? And what are the risks? You mentioned, you know, there's so many legacy devices and so on and so forth. What's most vulnerable, you think? So in my space, right, the emerging tech space, I think one device category that comes to mind that's concerning is medical devices. But really, I think more concerning are some of the digital platforms that have APIs into other systems like electronic medical records, pharmacy, things like that that use certificates on the back end. I think there's a risk, if we're unaware of the types of certificates being used in those scenarios, they could break and cause major, have major patient safety ramifications. Because then that is not flowing as quickly as it needs to. And I think those effects can cascade from there. From a device standpoint, specifically, you know, I went into a lot of medical devices that have encryption standards that date back to, I want to say a decade, it's even more than a decade, like 2008, you know, time frame.

So we really need to start understanding what we have in our environment and essentially segmenting it if it needs to be segmented. In some cases, the devices may not be able to make the journey to post quantum, you know, via post quantum cryptography. They may not have the capability to be available. So there may be scenarios where we need to look at updating devices. I think the earlier we can prepare a budget for that sort of thing, the better shape will be in. But hip as the biggest sort of concern from my vantage point, I think just having data out there, you know, where it's just a ticking time bomb and someone is waiting until they have the capability to decrypt it, you know, which can cause massive data reach ramifications that no one really wants. Well, you had mentioned that you have a post quantum program. Can you tell us something about the approach that you're taking to post quantum risk in your organization? Any steps that you're taking that you think would be helpful for other healthcare entities to consider, especially to get started in addressing these risks?

Yeah, I think first and foremost is to focus on the issue and assign at least an individual to start working on this area. And I think as far as the approach, the biggest sort of foundational element that is needed is inventory. You'll run into a lot of health systems that don't even have a PKI strategy today. We're talking about zero trust. We've been talking about zero trust for years. But having your arms around and understanding your digital certificate use is really paramount to that equation. If you ever want to reach, you know, the zero trust, you know, Shangri-La type model, that's a massive requirement. So I think the biggest piece is inventory. So a sea bomb, cryptographic bill of materials. That'll be the first thing I would focus in on followed by understanding, assigning some risk profile to the various uses of digital certificates. And then looking at the lower risk scenarios, how, you know, looking at a migration path from a post-quantum cryptography standpoint.

The other piece is really understanding if you have legacy cryptography in your environment, this is the time to start coming up with plans to decommission these platforms or update them. So I think those are the first steps. And then after that, then we can start focusing on some of the higher risk areas. And if we need to work on some pilots to prove certain concepts. And I think you build on it from there. And this, what I've described is something that will take several years. It's not something that's done, you know, in a year. It may take you a year to just inventory what you have. Do you have a team working with you? So yeah, so I am over emerging technology in post-quantum cryptographies, one of the pillars that we're focused in, we're building out a team. I do have an individual identified now and a sign that's a subject matter expert in this area to drive it. But I think over time we will have to have a team handling it. And finally, in addition to post-quantum issues, what other emerging technologies are you keeping a close eye on right now, or are piloting that you'd like to mention, or, you know, is worth mentioning?

Yeah, so the big one's obviously going to be AI. I think that's just moving at a very fast pace. And we're keeping a very close eye on it. And I think like many other health systems are on the country, we're looking very closely at analytics, automation, and AI, those three areas. And I think AI specifically presents some really interesting security scenarios. So it's been another area that I've been paying a lot of attention to. And AI has really permeated other areas as well, like medical instrumentation. I mean, even if you, if you marry it with post-quantum cryptography or any of these other emerging texts, it just makes them not much more potent from a cyber security risk standpoint. So AI would be the big one, I would say. Can AI, do you think, help at all in terms of health care entities addressing their post-quantum risks and solutions, or not really? Yeah, I think it can definitely help as far as being able to detect how essentially coming up with that C-BOM inventory, I think it can help with automating that process.

So it doesn't have to be a manual effort, because one thing we know for sure, right, we are manual processes are no longer viable in this space. If you look at the latest NIST guidance in this area, and the fact that now digital certificates, it's a 47 day life cycle. So that's taking us from looking at a digital cert and being able to use it for like a year, sometimes longer, down to having to switch eight times a year, essentially, to refresh that certificate. So with the hundreds of thousands of certs out there, automation is becoming much more important. And so I think AI can help from that standpoint. Well, thank you so much, Ali. I've been speaking to Ali Yosef, I'm Mary Ann Kolbysak-McGee of the Information Security Media Group. Thanks for joining us.

More episodes

More from Data Breach Today Podcast

View all episodes →