Skip to Main Content Subscribe

ASPR Signals New Quantum Guidance Amid Health Cyber Threats

Share

The health agency is the latest to provide guidance on post-quantum cryptography amid a government-wide focus to get ahead of quantum threats.

3m read
Written by:
HHS ASPR Senior Cybersecurity Advisor Bob Bastani (center) discusses why healthcare organizations need to think about PQC migration at GovCIO Media & Research's Health IT Summit in Bethesda, Maryland on Sept. 2, 2026.
HHS ASPR Senior Cybersecurity Advisor Bob Bastani (center) discusses why healthcare organizations need to think about PQC migration at GovCIO Media & Research's Health IT Summit in Bethesda, Maryland on Sept. 2, 2026. Photo Credit: Invision Events

The Administration for Strategic Preparedness and Response (ASPR) is preparing to release post-quantum cryptography (PQC) migration guidance to help hospitals and public health organizations prepare for emerging cyber threats.

“We’re working very closely with our private sector partners, and we’re about to release guidance documents in terms of how to prepare and mitigate quantum-related threats,” said ASPR Senior Cybersecurity Advisor for Critical Infrastructure Bob Bastani at GovCIO Media & Research’s Health IT Summit.

ASPR, a division of the Department of Health and Human Services, updated its Risk Identification and Site Criticality (RISC) tool earlier this year to include a cybersecurity assessment. The updated toolkit, known as RISC 2.0, includes resources to help health systems and public health partners better assess their cybersecurity posture amid growing ransomware threats.

Bastani said RISC 2.0 does not currently include PQC guidance, but cybersecurity leaders can use best practices such as inventorying data and systems to better prepare their organizations for a future PQC migration.

CDW Healthcare Industry Strategist Nelson Carreira echoed the need for organizations to begin or advance their PQC migration strategies. Carreira said threat actors are already collecting encrypted data with the intention of decrypting it once quantum computers are capable of breaking current encryption methods, a tactic known as “harvest now, decrypt later.”

“PQC migration is something you should start today, because it’s going to be a massive threat,” said Carreira. “The sooner you can get started, the better. NIST has the algorithms posted, so leverage your partners to help you migrate because it is a huge endeavor.”

The Value of Communication, Transparency

As cybersecurity shifts from being solely the responsibility of IT departments to a shared responsibility among clinicians, healthcare providers and technology teams, communication and transparency are essential to ensuring critical applications remain online during an emergency.

Carreira said technology and clinical teams need to communicate more closely to understand the tiering of critical applications and how those applications align with business impact analyses. Without input from a range of stakeholders, organizations risk treating too many applications as Tier One priorities.

“Out of 100 applications, you’d have 25 to 30 in your tier one and even above that is tier zero,” said Carreira. “Tier zero — that’s all the ‘connective tissue’ that needs to be running before your tier one applications should even come back.”

Communication between public and private healthcare partners is critical to helping organizations prevent the spread of ransomware and other cyberattacks. Since 2021, Medusa ransomware attacks have impacted more than 500 victims across critical infrastructure sectors, including the healthcare and public health sector, according to an August release from the Cybersecurity and Infrastructure Security Agency (CISA).

HHS and CISA together released a toolkit for healthcare and public health organizations that provides a centralized location to learn more about cyber training exercises, resources for incident reporting and voluntary cybersecurity goals specific to the sector.

“It has things like CISA’s vulnerability scanning, and it has access to those [cybersecurity] exercises,” said Charles Sweat, healthcare and public health liaison at CISA. “We can come out to the organization and set up custom exercises. It also has contact information for CISA’s field personnel, PSAs and links to other resources within HHS, like the RISC 2.0.”

Bastani encouraged organizations to use available tools and report cyber incidents as quickly as possible so CISA, ASPR and other officials can help mitigate related threats. He added that healthcare systems are interconnected, meaning an incident affecting one organization could potentially spread laterally to another organization’s systems.

“There is a tendency when incidents happen, to keep the information doors ‘closed.’ That’s really not a good thing in terms of how we deal with these threats,” said Bastani. “So share the information, reach out to us. We have a system to take that information, condense it, summarize it, get the useful part of it and share it across the sectors with others.”

Related Content