Home / Current Issue / Paper 1709404
Zero Trust Architecture for Healthcare: Reinventing Cybersecurity in the Age of AI and IoT-Driven Patient Data
Subject area: Science,Engineering and Technology · Area of research: Cybersecurity
Abstract
The exponential digitalization of the healthcare industry has ushered in an era of establishing electronic health records (EHRs), health and medical wearables, and cloud-connected diagnostic systems as bases for clinical operations. While this transformation has impacted the healthcare infrastructure, it has also exposed it to increasingly complex and persistent cyber threats, including ransomware, phishing campaigns, insider breaches, and unauthorized access to sensitive patient data. Traditional perimeter-based cybersecurity models once thought to be sufficient, have proven insufficient in protecting against sophisticated attackers who exploit internal vulnerabilities and employ lateral movement techniques. The evolution of these risks gave rise to the emergence of ZTA (Zero Trust Architecture), which represents a paradigm shift in the mind of "never trust, always verify." This paper focuses on the implementation of ZTA in healthcare systems, highlighting its collaboration with AI for real-time threat detection and with IoMT for secure device access and telemetry. We propose an integrated ZTA approach explicitly tailored to healthcare environments, drawing heavily on state-of-the-art AI-enabled anomaly detection, federated learning, and micro-segmentation. The effectiveness of this framework in breach detection, access policy enforcement, and system resilience was assessed through case-based analysis and simulated threat modeling. Results demonstrate that AI-enabled ZTA approaches significantly decrease false positives, increase the accuracy of detection, and reduce the lateral propagation of threats in sophisticated healthcare environments. Aspects posing practical challenges for deployment, such as interoperability, HIPAA and GDPR compliance, and resource constraints on legacy medical devices, are given further attention. Hence, offering the position of studying ZTA supported by intelligent automation is not merely a technical enhancement but rather an evolution that must be embraced to protect the digital health ecosystem from increased cyber threats. Along the same lines, future work will involve exploring blockchain integration, enhancing edge AI paradigms, and setting up dynamic trust scoring for contextual access control.
Keywords
Zero Trust Architecture, Healthcare Cybersecurity, AI in Healthcare, Internet of Medical Things (IoMT), Electronic Health Records (EHR), Anomaly Detection, Access Control, Federated Learning, Medical Device Security, HIPAA Compliance, Threat Detection, Microsegmentation, Identity and Access Management (IAM), Cyber Threat Intelligence, Data Privacy
References
[1] Al-Hammuri, K., Gebali, F., & Kanan, A. (2023, November 28). ZTCloudGuard: Zero trust context-aware access management framework to avoid misuse cases in the era of generative AI and cloud-based health information ecosystem [Preprint]. arXiv. https://arxiv.org/abs/2312.02993
[2] Ameer, T., et al. (2022). Zero trust vs. VPN: Cost-efficiency analysis. Cybersecurity Journal, 2022(6), 76–89.
[3] Bertino, E. (2021). Zero trust architecture: Does it help? IEEE Security & Privacy, 19(2), 95–96. https://doi.org/10.1109/MSEC.2021.3050518
[4] Buck, J., et al. (2021). Multivocal literature review on zero-trust security implementation. Computers & Security, 141, 103827. https://doi.org/10.1016/j.cose.2024.103827
[5] Campbell, B. (2020). Trust points as vulnerabilities. Cybersecurity Journal, 2020(1), 20–32.
[6] Cloud Security Alliance. (2023). Medical devices in Zero Trust Architecture. https://cloudsecurityalliance.org
[7] CISA. (2022). Zero Trust Maturity Model. Cybersecurity and Infrastructure Security Agency. https://www.cisa.gov/resources-tools/resources/zero-trust-maturity-model
[8] ElSayed, Z., Elsayed, N., & Bay, S. (2024, January 14). A novel zero-trust machine learning green architecture for healthcare IoT cybersecurity: Review, analysis, and implementation [Preprint]. arXiv. https://arxiv.org/abs/2401.07368
[9] Edo, O. C., Ang, D., Billakota, P., & Ho, J. C. (2023). A zero-trust architecture for health information systems. Health and Technology, 14(2), 189–199. https://doi.org/10.1007/s12553-023-00809-4
[10] Fang, X., et al. (2022). Continuous verification in zero trust. Cybersecurity Journal, 2(3), 133–150.
[11] Fernandez, E. B., & Brazhuk, A. (2024). A critical analysis of zero trust architecture (ZTA). Computer Standards & Interfaces, 89, 103832. https://doi.org/10.1016/j.csi.2024.103832
[12] Ghubaish, A., Salman, T., Zolanvari, M., Unal, D., Al-Ali, A., & Jain, R. (2023). Recent advances in the Internet of Medical Things (IoMT) systems security [Preprint]. arXiv. https://arxiv.org/abs/2302.04439
[13] He, Y., Huang, D., Chen, L., Ni, Y., & Ma, X. (2022). A survey on zero-trust architecture: Challenges and future trends. Wireless Communications and Mobile Computing, 2022, Article 6476274. https://doi.org/10.1155/2022/6476274
[14] Horowitz, B. T. (2023, February 20). Zero trust in healthcare: Securing critical applications. HealthTech Magazine. https://www.healthtechmagazine.net/article/2023/02/zero-trust-healthcare-perfcon
[15] Jia, Y., McDermid, J., Lawton, T., & Habli, I. (2021). The role of explainability in assuring safety of machine learning in healthcare. arXiv. https://arxiv.org/abs/2109.00520
[16] Jericho Forum. (2003). De-perimeterization vision statement. Jericho Forum. https://open-group.org/jericho
[17] Khattak, A., et al. (2019). IoT perception layer threat analysis. Cybersecurity Journal, 2019(5), 328–345.
[18] Katsis, C., & Bertino, E. (2024, November 22). ZT-SDN: An ML-powered Zero-Trust architecture for software-defined networks [Preprint]. arXiv. https://arxiv.org/abs/2411.15020
[19] Liu, C., Tan, R., Wu, Y., Feng, Y., Jin, Z., Zhang, F., & Liu, Y. (2024). Dissecting zero trust: Research landscape and its implementation in IoT. Cybersecurity, 7, Article 20. https://doi.org/10.1186/s42400-024-00212-0
[20] Marsh, S. P. (1994). Trust in computer security (Master's thesis). University of Stirling.
[21] Mohseni Ejiyeh, A. (2023). Real-time lightweight cloud-based access control for wearable IoT devices: A zero-trust protocol. In Workshop on Security and Privacy of Sensing Systems, Istanbul.
[22] NIST. (2020). Zero Trust Architecture (SP 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207
[23] Omâr, M., et al. (2020). Access privileges in zero trust. Cybersecurity Journal, 2020(4), 145–158.
[24] Phiayura, P., & Teerakanok, S. (2023). A comprehensive framework for migrating to zero-trust architecture. IEEE Access, 11, 19487–19511. https://doi.org/10.1109/ACCESS.2023.3245678
[25] Republic of Korea Ministry of Science & ICT. (2023). Zero Trust Guidelines 1.0. https://www.msit.go.kr
[26] Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero Trust Architecture (NIST SP 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207
[27] Sanakal, A. P. (2025). AI-enhanced actual costing in ERP: A path toward real-time cost transparency. International Journal of Accounting and Information Systems, 28(1), 45–62. https://doi.org/10.1016/j.accinf.2025.100531
[28] Sasada, T., Taenaka, Y., Kadobayashi, Y., & Fall, D. (2024). Web-biometrics for user authenticity verification in zero-trust access control. IEEE Access, 12, 129611–129622.
[29] Sengupta, B., & Anantharaman, L. (2021). Distrust: Distributed and low-latency access validation in zero-trust architecture. Journal of Information Security Applications, 63, 103023. https://doi.org/10.1016/j.jisa.2021.103023
[30] Shakya, S., Abbas, R., & Maric, S. (2025, February 5). A novel zero-touch, zero-trust, AI/ML enablement framework for IoT network security [Preprint]. arXiv. https://arxiv.org/abs/2502.03614
[31] Stafford, V. A. (2020). Zero Trust Architecture. NIST Special Publication 800-207. https://doi.org/10.6028/NIST.SP.800-207
[32] Syed, N. F., Shah, S. W., Shaghaghi, A., Anwar, A., Baig, Z., & Doss, R. (2022). Zero trust architecture (ZTA): A comprehensive survey. IEEE Access, 10, 57143–57179. https://doi.org/10.1109/ACCESS.2022.3174679
[33] Teerakanok, S., Uehara, T., & Inomata, A. (2021). Migrating to zero-trust architecture: Reviews and challenges. Security and Communication Networks, 2021, Article 9947347. https://doi.org/10.1155/2021/9947347
[34] Waheed, N., Rehman, A. U., Nehra, A., et al. (2023). FedBlockHealth: Federated learning & blockchain in IoT-enabled healthcare [Preprint]. arXiv. https://arxiv.org/abs/2305.02987
[35] Wu, L. (2022). IoHT and Zero Trust at perception layer. Cybersecurity Journal, 2022(3), 210–225.
[36] Yan, X., & Wang, Y. (2020). Comprehensive survey of Zero Trust. IEEE Transactions on Trustworthy Computing, 17(1), 88–110.
[37] Zhao, Y., et al. (2020). Device information in ZTA verification. Cybersecurity Journal, 1(2), 77–95.
[38] Zakhmi, K., Ushmani, A., Mohanty, M. R., et al. (2025). Evolving ZTA for AI-driven cyber threats in healthcare. Cureus, 17(6), e15532.
[39] Adahman, Z., Malik, A. W., & Anwar, Z. (2022). Analysis of Zero Trust architecture & cost effectiveness. Computers & Security, 112, 102534. https://doi.org/10.1016/j.cose.2021.102534
[40] Corpuz, E. G. (2023). Enhancing cybersecurity in the Philippines healthcare sector through Zero Trust. ACM Southeast Asia Workshop on Cybersecurity. https://doi.org/10.1145/3698062.3698090
How to cite this paper
@article{1709404,
author = {Ahmad Ikram},
title = {Zero Trust Architecture for Healthcare: Reinventing Cybersecurity in the Age of AI and IoT-Driven Patient Data},
journal = {Iconic Research And Engineering Journals},
year = {2025},
volume = {8},
number = {12},
pages = {1523-1534},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1709404.pdf},
abstract = {The exponential digitalization of the healthcare industry has ushered in an era of establishing electronic health records (EHRs), health and medical wearables, and cloud-connected diagnostic systems as bases for clinical operations. While this transformation has impacted the healthcare infrastructure, it has also exposed it to increasingly complex and persistent cyber threats, including ransomware, phishing campaigns, insider breaches, and unauthorized access to sensitive patient data. Traditional perimeter-based cybersecurity models once thought to be sufficient, have proven insufficient in protecting against sophisticated attackers who exploit internal vulnerabilities and employ lateral movement techniques. The evolution of these risks gave rise to the emergence of ZTA (Zero Trust Architecture), which represents a paradigm shift in the mind of "never trust, always verify." This paper focuses on the implementation of ZTA in healthcare systems, highlighting its collaboration with AI for real-time threat detection and with IoMT for secure device access and telemetry.
We propose an integrated ZTA approach explicitly tailored to healthcare environments, drawing heavily on state-of-the-art AI-enabled anomaly detection, federated learning, and micro-segmentation. The effectiveness of this framework in breach detection, access policy enforcement, and system resilience was assessed through case-based analysis and simulated threat modeling. Results demonstrate that AI-enabled ZTA approaches significantly decrease false positives, increase the accuracy of detection, and reduce the lateral propagation of threats in sophisticated healthcare environments. Aspects posing practical challenges for deployment, such as interoperability, HIPAA and GDPR compliance, and resource constraints on legacy medical devices, are given further attention.
Hence, offering the position of studying ZTA supported by intelligent automation is not merely a technical enhancement but rather an evolution that must be embraced to protect the digital health ecosystem from increased cyber threats. Along the same lines, future work will involve exploring blockchain integration, enhancing edge AI paradigms, and setting up dynamic trust scoring for contextual access control.},
keywords = {Zero Trust Architecture, Healthcare Cybersecurity, AI in Healthcare, Internet of Medical Things (IoMT), Electronic Health Records (EHR), Anomaly Detection, Access Control, Federated Learning, Medical Device Security, HIPAA Compliance, Threat Detection, Microsegmentation, Identity and Access Management (IAM), Cyber Threat Intelligence, Data Privacy},
month = {June},
}