As NHS leaders focus on the government's three big shifts (hospital to community, treatment to prevention, analogue to digital) a quieter risk is building in the background. Quantum computing promises real advances for patient care, but it also threatens the encryption that currently keeps patient data safe. And this risk applies whether or not your organisation ever touches quantum technology directly.
Bad actors are already harvesting encrypted NHS data today, ready to unlock it the moment quantum computing catches up. The UK government has committed £670 million to quantum computing, accelerating timelines that NHS leaders can no longer treat as a distant problem. This isn't tomorrow's issue. It's today's imperative.
Understanding the quantum threat
Quantum computers use qubits, which can hold multiple states at once, multiplying processing power exponentially compared with classical computers. For most industries that's an exciting prospect. For the NHS, holding decades' worth of sensitive patient data, it's a serious vulnerability.
"Harvest now, decrypt later." Bad actors are collecting encrypted NHS data today with the intention of decrypting it once quantum computing matures. The National Cyber Security Centre has flagged this as a significant risk for any organisation holding high-value data over the long term, and the NHS is a prime target.
Q-Day is coming, but no one knows when. Security experts use the term "Q-Day" to describe the point at which quantum computers can break current encryption standards. Unlike Y2K, there's no fixed date to plan around. By the time Q-Day arrives, any data harvested in the meantime will already be exposed.
Traditional encryption won't hold. Methods that would take classical computers millions of years to crack could be broken by quantum systems in minutes, rendering today's safeguards obsolete almost overnight.
Why this matters to the NHS right now
Several factors make this an urgent, board-level issue rather than a future IT concern:
- Decades of sensitive data. Patient records, genomic data and clinical trial information stay sensitive for years, sometimes decades, making the NHS especially exposed to harvest-now, decrypt-later tactics. Some countries, including Japan, mandate patient data protection for up to 100 years.
- A health service in transition. The shift to a more digital, prevention-focused NHS, as set out in the government's response to Lord Darzi's review, can't afford to overlook data security along the way.
- Legacy infrastructure. Many NHS organisations still rely on a complex web of legacy systems and middleware that may not support quantum-safe encryption.
- Recent incidents prove the risk is real. The 2024 London cyberattacks showed how exposed NHS systems already are, even before quantum capability enters the picture.
- No national quantum strategy yet. There's currently no dedicated NHS quantum strategy, leaving individual trusts to assess and manage this risk largely on their own.
Becoming quantum-ready: where to start
IBM research suggests most organisations need around 12 years to become fully quantum-safe. For the NHS, that means the clock is already running. Five steps forward-thinking leaders are taking:
- Board-level ownership. This is a strategic risk, not just an IT ticket. Boards need to understand the potential impact on patient safety and organisational resilience, and assign clear accountability.
- Data visibility. You can't protect what you can't see. Organisations need full oversight of where sensitive data lives, how it moves and who can access it.
- Crypto-agility. Build the flexibility to adapt encryption approaches as quantum technology evolves, including working with suppliers to secure the wider digital ecosystem.
- Business-critical system assessment. Identify which systems will struggle to support quantum-safe encryption and prioritise them for upgrade or replacement.
- Quantum-safe encryption. Begin adopting post-quantum cryptography standards as they mature, rather than waiting for a forced migration later.
Many of these steps start with the same foundation: knowing where your sensitive data actually sits today. Our guide to data security maturity in healthcare walks through how to build that visibility and turn it into a practical roadmap.
The opportunity side of quantum
It's not all risk. Quantum computing also opens up genuine opportunities for the NHS:
- Better diagnostics. Researchers at the University of Nottingham have developed quantum sensors, worn like a bicycle helmet, that can detect the onset of epilepsy in children, with similar diagnostic applications expected across other conditions.
- Deeper data analytics. Quantum computing could reveal patterns across patient and operational data that classical systems simply can't surface.
- Faster drug discovery. Quantum simulations may dramatically speed up the modelling of chemical reactions, opening new pathways for treatment development.
- Smarter resource allocation. Complex scheduling and capacity problems, the kind that affect patient flow and waiting times, could be solved more efficiently.
The organisations that get ahead of the security risk now will also be the ones best placed to take advantage of these benefits when they arrive.
Act now, or pay for it later
The exact timing of Q-Day is still uncertain, but the cost of waiting isn't: compromised patient data, disrupted services and damaged public trust. NHS organisations that start building quantum-readiness today protect themselves on two fronts at once, reducing the risk of harvested data being exposed later, while positioning themselves to benefit from quantum-driven innovation in care delivery.
The real question for NHS leaders isn't whether quantum will reshape healthcare security. It's whether your organisation will be ready when it does.
Get your roadmap to a quantum-safe NHS
Quantum Ready: Securing Data in the NHS
Our comprehensive whitepaper outlines these critical data security risks and provides NHS leaders with the essential roadmap to develop a proactive, quantum-safe strategy now. Download your copy to protect patient safety, enhance cyber resilience, and ensure your NHS organisation's future in the quantum age.
Download Whitepaper