Industries · Healthcare and life sciences

Healthcare cybersecurity: two problems, one agent

A clinical group carries two very different risks at once. Ransomware that stops care this afternoon, and patient records that have to stay private for decades. QNova Client answers both from the same signed agent on the same device, and QS-WAN keeps the record of who can reach what.

The person who usually reads this page
01
Runs IT for several sites
02
Was named responsible for security
03
Has nobody dedicated to it

The blocker is rarely budget. It is not knowing what counts as enough.

The constraint

One threat is measured in hours, the other in decades

Healthcare gets asked to hold two timescales in one head. Ransomware is an operational event: appointments cancelled, records unavailable, staff working on paper, and a decision to make while the phones ring. Confidentiality is the opposite. A patient record is sensitive for the rest of that person’s life, and the copy someone captures today can be opened later.

That second half is why encryption choices matter here more than in most sectors. Traffic captured now can be stored and decrypted when the tools improve, which makes an ordinary tunnel a long term liability rather than a solved problem.

Meanwhile the people who have to act are rarely a security team. In smaller clinical groups it is the person who already runs the network, the printers and the practice software, told in a letter that they are now responsible for security as well.

Two problems, two timescales, and usually one person holding both.
What makes healthcare different
01

Care cannot wait for a change window

Clinical systems run through the night and through the weekend. Anything that needs a device restarted, or a system taken out of service, has to fit around patients rather than the other way around.

02

The network is full of guests

Imaging vendors, practice software suppliers, laboratories and locum staff all need access to something, often urgently, often from a device you have never seen.

03

The obligation arrived by law

NIS2 brings many health providers into scope across the European Union, and in Portugal the Decreto-Lei n.o 125/2025 made somebody personally responsible by name. The work starts before the expertise does.

How QuantumNova covers both

One signed agent on the device, one console behind it

QNova Client is one signed agent that replaces a VPN, endpoint protection, remote support, a password manager and encrypted file transfer. QS-WAN is the console that decides who reaches what. In a clinical group that lands as three things.

01

Contain first, ask afterwards

On Windows the client runs eleven detection engines, and the principle is to suspend the process tree on the thread that caught it, before anyone sees a card. A file system filter stops untrusted processes writing into document folders, which is the shape most ransomware takes on a reception desk.

02

Confidentiality with a long horizon

Everything between a device, a gateway and the control plane is post-quantum by default, aligned with FIPS 203, FIPS 204 and CNSA 2.0, and hybrid by design. The cryptographic inventory is documented by subsystem, which is the artefact a regulator tends to ask for first.

03

Suppliers reach one segment, not the network

An imaging vendor gets a device certificate for one gateway and a path to one segment, drawn as an edge in the Network Map that you can switch off. A locum leaves and the certificate is revoked from the console.

Underneath, the same everywhere

Company policy that holds

The signed company policy keeps protection on: what the organisation turned on, the user cannot quietly turn off, which matters on a shared workstation at a reception desk.

Runs where you decide

License QS-WAN onto your own infrastructure, take a gateway we ship configured, or let us host it. A clinical group that keeps its records on site can keep the console there too.

When the questionnaire arrives

The evidence is produced while you work, not the week before

Insurers, hospital groups and regulators ask the same handful of questions. These are the answers the platform already holds, so the week before an audit goes on reading rather than collecting.

Q1

Which devices are protected, and are they current?

Each device, its posture and its protection state, with the detection history kept and paginated rather than summarised into a number.

Q2

Who can reach the clinical systems?

User profiles, their devices, one certificate per gateway membership, and the permitted paths drawn as edges you can switch off.

Q3

How are the records protected in transit?

Post-quantum key establishment by default, hybrid by design, with the cryptographic inventory documented by subsystem.

Q4

Can you show it rather than say it?

Assessments return pass, fail, partially satisfied or not tested, next to a risk score built from 19 indicators. More on being ready for the audit.

What a green tick means. A green confirmation means the change was recorded. A device or gateway that was offline applies it on reconnect, so a laptop in a doctor’s bag is only current once it comes back.

Where it stops

What this is not, said plainly

Healthcare buyers get promised a great deal. It is worth being exact about what this does not cover, before rather than after.

It is not a managed service

QuantumNova is a product. Nobody here watches your network, and no analyst of ours reads your alerts. The platform produces the score and the evidence; your people, or your provider, act on them.

It does not touch clinical records

This protects the devices and the paths between them. The record system, its access rules and its clinical audit trail stay with the software you already run.

It does not certify you

The platform helps you answer NIS2 and similar questions with evidence. Whether that evidence is enough is decided by an auditor, not by a console.

Coverage differs by platform

Windows is the complete implementation. Linux is a genuine port with gaps we declare, and macOS and iOS are planned, so a clinic on mixed devices should plan by column, not by tick.

Start with the thing that would hurt on Monday

If ransomware on a reception desk is the fear, start there. If it is the supplier with a standing connection, start there instead. A demonstration is free, and it is a conversation, not a pitch.

NEWSLETTER

Get weekly tips, product news and early access, straight to your inbox.

Scroll to Top