Healthcare cybersecurity: two problems, one agent
A clinical group carries two very different risks at once. Ransomware that stops care this afternoon, and patient records that have to stay private for decades. QNova Client answers both from the same signed agent on the same device, and QS-WAN keeps the record of who can reach what.
The blocker is rarely budget. It is not knowing what counts as enough.
One threat is measured in hours, the other in decades
Healthcare gets asked to hold two timescales in one head. Ransomware is an operational event: appointments cancelled, records unavailable, staff working on paper, and a decision to make while the phones ring. Confidentiality is the opposite. A patient record is sensitive for the rest of that person’s life, and the copy someone captures today can be opened later.
That second half is why encryption choices matter here more than in most sectors. Traffic captured now can be stored and decrypted when the tools improve, which makes an ordinary tunnel a long term liability rather than a solved problem.
Meanwhile the people who have to act are rarely a security team. In smaller clinical groups it is the person who already runs the network, the printers and the practice software, told in a letter that they are now responsible for security as well.
Care cannot wait for a change window
Clinical systems run through the night and through the weekend. Anything that needs a device restarted, or a system taken out of service, has to fit around patients rather than the other way around.
The network is full of guests
Imaging vendors, practice software suppliers, laboratories and locum staff all need access to something, often urgently, often from a device you have never seen.
The obligation arrived by law
NIS2 brings many health providers into scope across the European Union, and in Portugal the Decreto-Lei n.o 125/2025 made somebody personally responsible by name. The work starts before the expertise does.
One signed agent on the device, one console behind it
QNova Client is one signed agent that replaces a VPN, endpoint protection, remote support, a password manager and encrypted file transfer. QS-WAN is the console that decides who reaches what. In a clinical group that lands as three things.
Contain first, ask afterwards
On Windows the client runs eleven detection engines, and the principle is to suspend the process tree on the thread that caught it, before anyone sees a card. A file system filter stops untrusted processes writing into document folders, which is the shape most ransomware takes on a reception desk.
Confidentiality with a long horizon
Everything between a device, a gateway and the control plane is post-quantum by default, aligned with FIPS 203, FIPS 204 and CNSA 2.0, and hybrid by design. The cryptographic inventory is documented by subsystem, which is the artefact a regulator tends to ask for first.
Suppliers reach one segment, not the network
An imaging vendor gets a device certificate for one gateway and a path to one segment, drawn as an edge in the Network Map that you can switch off. A locum leaves and the certificate is revoked from the console.
Company policy that holds
The signed company policy keeps protection on: what the organisation turned on, the user cannot quietly turn off, which matters on a shared workstation at a reception desk.
Runs where you decide
License QS-WAN onto your own infrastructure, take a gateway we ship configured, or let us host it. A clinical group that keeps its records on site can keep the console there too.
The evidence is produced while you work, not the week before
Insurers, hospital groups and regulators ask the same handful of questions. These are the answers the platform already holds, so the week before an audit goes on reading rather than collecting.
Which devices are protected, and are they current?
Each device, its posture and its protection state, with the detection history kept and paginated rather than summarised into a number.
Who can reach the clinical systems?
User profiles, their devices, one certificate per gateway membership, and the permitted paths drawn as edges you can switch off.
How are the records protected in transit?
Post-quantum key establishment by default, hybrid by design, with the cryptographic inventory documented by subsystem.
Can you show it rather than say it?
Assessments return pass, fail, partially satisfied or not tested, next to a risk score built from 19 indicators. More on being ready for the audit.
What a green tick means. A green confirmation means the change was recorded. A device or gateway that was offline applies it on reconnect, so a laptop in a doctor’s bag is only current once it comes back.
What this is not, said plainly
Healthcare buyers get promised a great deal. It is worth being exact about what this does not cover, before rather than after.
It is not a managed service
QuantumNova is a product. Nobody here watches your network, and no analyst of ours reads your alerts. The platform produces the score and the evidence; your people, or your provider, act on them.
It does not touch clinical records
This protects the devices and the paths between them. The record system, its access rules and its clinical audit trail stay with the software you already run.
It does not certify you
The platform helps you answer NIS2 and similar questions with evidence. Whether that evidence is enough is decided by an auditor, not by a console.
Coverage differs by platform
Windows is the complete implementation. Linux is a genuine port with gaps we declare, and macOS and iOS are planned, so a clinic on mixed devices should plan by column, not by tick.
Start with the thing that would hurt on Monday
If ransomware on a reception desk is the fear, start there. If it is the supplier with a standing connection, start there instead. A demonstration is free, and it is a conversation, not a pitch.
NEWSLETTER
Get weekly tips, product news and early access, straight to your inbox.