Patient records carry confidentiality obligations measured in decades, which puts healthcare squarely in the harvest-now-decrypt-later problem. The harder constraint is the device estate. An infusion pump or an imaging system certified years ago cannot be re-cryptographed on a software release schedule, and the regulatory path to changing it runs through the manufacturer.
This is a working day. You bring your own systems inventory and your own device population, and you leave with a plan that separates what you can migrate from what you can only mitigate.
Who this intensive is for
Healthcare CISOs and security architects, biomedical and clinical engineering leads, EHR and clinical application owners, privacy officers, and the medical device manufacturers who supply them. Health systems get the most from it when clinical engineering attends alongside security, because the device conversation cannot be held without them.
Device manufacturers are welcome and gain a different thing from the day: a clear view of what their customers are about to start asking for.
What you’ll be able to do afterward
- Size harvest-now-decrypt-later exposure across patient records, imaging archives, genomic data, and clinical trial data, each of which has a different confidentiality horizon
- Separate the device population that can be migrated by its manufacturer from the population that can only be isolated, gatewayed, or retired
- Apply HIPAA Security Rule obligations to migration planning without overstating what the rule currently requires
- Read FDA premarket and postmarket cybersecurity guidance for what it means for cryptographic change on a certified device
- Plan EHR and clinical application migration around clinical availability constraints rather than against them
- Set post-quantum requirements for the next device procurement and the next EHR contract renewal
What you leave with
Every participant receives the course handbook, a PDF of the full material with the instructor notes written out, and a PDF copy of Quantum Ready. The day itself produces a patient data confidentiality horizon model, a device population triage covering migrate, mitigate, and retire, a clinical systems migration sequence built around availability windows, and procurement language for device and software contracts. All are editable and yours to keep.
The day
Morning, first block. Data and exposure. Which data holds its value longest, and what that means for the order of work. Sizing exposure across records, imaging, genomics, and trials.
Morning, second block. The device problem. Triaging the device estate. What the manufacturer must do, what you can do at the network edge, and what has to be planned out of service.
Afternoon, first block. Clinical systems. EHR and clinical application migration against availability constraints. Integration engines, interfaces, and the parts of the estate nobody owns.
Afternoon, second block. The plan. Assemble the roadmap and the procurement language. Identify what needs a manufacturer conversation and draft how to open it.
Where this sits in your path
Quantum-Safe Healthcare is the prerequisite in substance rather than in rule. It covers the same ground at overview depth, and participants who arrive having taken it start the day with the vocabulary already shared. Afterward, Cryptographic Discovery, Inventory, and CBOM for discovery teams, and PQC Vendor Governance for the device and supplier conversations this workshop will start.
Why we teach this
The day is built on the Applied Quantum PQC Migration Framework, published openly under Creative Commons at pqcframework.org, applied to this sector by instructors who run migration programs in it. No published sector extension exists for this industry yet. The sector material is the instructors’ own field work.