Home / Current Issue / Paper 1720214
Development Of a Cloud Based Security Risk Assessment Framework for IoT-Based Health Care System: A Review
Subject area: Science,Engineering and Technology · Area of research: Cyber Security
DOI: https://doi.org/10.64388/IREV10I1-1720214
Abstract
The use of Internet of Things (IoT) technology in healthcare has changed how medical services are provided. IoT devices like wearable sensors, implantable tools, and smart diagnostic machines allow doctors to watch patients' health as it happens and help make better decisions about their care. These devices help doctors talk to patients from a distance and give them tailored care, which makes healthcare faster and better for patients. Even though there are many advantages, the way IoT devices are connected creates big security problems because the medical data being sent over networks is very sensitive. Healthcare organizations have to deal with two main problems: keeping patient information safe and making sure that healthcare services keep running without any interruptions. The growing number of IoT devices, which have different amounts of computing power and security features, has made traditional security methods not enough anymore. Many devices don't have enough power to use strong encryption or detect threats as they happen, which makes them easier targets for attacks like man-in-the-middle, malware insertion, and unwanted access. Even though more people are aware of these problems, healthcare organizations still have a hard time finding a complete and flexible security risk assessment system that covers both IoT devices and cloud-based systems. Current solutions are usually broken, slow to act, or only cover certain kinds of threats. They don't look at all the weaknesses, dangers, and possible problems in a complete way. The design science approach works well because the research is about making a tool (a security risk assessment framework) to deal with a real-world issue. The method will go through these steps: first, identifying and looking at the security issues in IoT healthcare systems, then figuring out what the security framework needs, next creating a cloud-based system to assess risks, followed by building and putting the framework into use, and finally testing and checking how well the framework works. This way, the framework is made to properly handle the security problems in IoT healthcare settings.
Keywords
Cyber Security Threats, Data Protection, HealthCare System, Internet of Things (IoT) Device and e Security Risk Assessment Framework.
References
[1] Abbass, A., et al. (2018). Intelligent security risk assessment using deep learning algorithms in IoT. Proceedings of the 2018 6th International Conference on Wireless Networks and Mobile Communications (WINCOM).
[2] Akinbi, A., et al. (2025). A systematic security analysis of medical internet of things (MIoT) ecosystems in threat modeling scenarios. Frontiers in the Internet of Things.
[3] Al-Qaseemi, S. A., et al. (2018). Security challenges in IoT-based monitoring systems.
[4] Ali, M. (2020). DTLS and Clasp authentication methods for IoT systems.
[5] Almahdi, M. (2019). Patient data safety and awareness against cyber-attacks in IoT environments.
[6] Alqahtani, H., et al. (2020). Security risk management in cloud-connected IoT healthcare systems.
[7] Alrawashdeh, M., et al. (2023). Access control and communication security in healthcare IoT.
[8] AmandaNCraig. (2015). Active cybersecurity programs and threat intelligence sharing.
[9] Azaliah, et al. (2019). An iterative IoT security risk model for healthcare. Indonesian Journal of Electrical Engineering and Computer Science.
[10] Bariro. (2019/2026). Health Guard: A machine learning framework for detecting malicious activities in smart healthcare systems. IEEE Internet Computing / arXiv preprint.
[11] Bokhari, M. U., et al. (2022). Cloud-based security risk assessment and compliance in healthcare IoT.
[12] Borka. (2022). Changing paradigms in digital technology and cybersecurity.
[13] Buccafurri, A. (2012). DTH-P2P social networks and cryptographic protocols for secure systems.
[14] Choi, J., et al. (2018). Sensor-based attacks and security classification methods in mHealth.
[15] Deepak, S. (2018). The CIA triad of data security.
[16] Draz, U. (2018). Cyber threats and real-time data security in technology.
[17] ElSayed, et al. (2024). Network security monitoring and intrusion prediction in healthcare IoT using a convolutional ML autoencoder model. Proceedings of IEEE SoutheastCon 2024 / arXiv preprint.
[18] Eric, P. (2013). Reactive computer system security and incident response history.
[19] Farooq, M. U., et al. (2018). The VICINITY framework for semantic interoperability, privacy, and security in IoT.
[20] Fortino, G. (2018). CoTAG: Cloud-of-Things virtualization and device reliability grouping.
[21] Grispos, et al. (2024). A digital forensic analysis of an electrocardiogram medical device: A first look.
[22] Hamrioui, S. (2017). Policy management rules for secure cloud servers in continuous patient tracking.
[23] Hathaliya, J. J., & Tanwar, S. (2020). Trust management and secure agent technology in IoT e-health.
[24] Hatzivasilis, G. (2019). Certificate-based DTLS handshake mechanisms for resource-constrained e-health gateways.
[25] Huang, X. (2017). Key agreement and cryptographic setup in wireless sensor networks for IoT.
[26] IBM. (2022). What is cybersecurity? IBM.
[27] Ifigeneia. (2021). ENISA threat landscape report: Top 15 cyber threats.
[28] ISO/IEC. (2020). Information technology — Security techniques — Risk management. ISO/IEC 27005 standard.
[29] Jaidi, et al. (2025). An Internet of Medical Things Cyber Security Assessment Model (IoMT-CySAM). Cureus.
[30] Jalkanen, A. (2019). Human factors and the weakest link concept in information security.
[31] Janine, S. (2018). History of early security problems in multi-user computer systems (1970s–1977).
[32] Jasour, et al. (2022). Dynamic risk evaluation using machine learning techniques. Autonomous Robots.
[33] Jonathan, K. (2020). Fundamentals of digital cryptography and secure computations.
[34] Kevin, M. (2011). Encryption at rest (EAR) strategies for database security.
[35] Kevin, M. (2012). Encryption in transit and end-to-end security protocols.
[36] Khan, et al. (2025). IoT medical device risks: Data security, privacy, confidentiality and compliance with HIPAA and COBIT 2019. South African Journal of Business Management.
[37] Kim, L. (2018). Information system security standards and the CIA triad benchmark.
[38] Laura, P. (2019). Data states: Data at rest, data in transit, and data in use.
[39] Li, X., et al. (2011). HTTP-CoAP security model and payload encryption for two-dimensional IoT structures.
[40] Logambal, R. (2017). Three-level wireless body area networks (WBAN) for real-time healthcare monitoring.
[41] Masood, A., et al. (2018). Integrating wireless body area networks with sensor cloud infrastructures.
[42] Mekky, A., et al. (2023). Vulnerability factors, interoperability issues, and attack propagation in medical IoT devices.
[43] Mohammad. (2023). Cybersecurity approach in Internet of Healthcare Things (IoHTs).
[44] Mohammed, B., et al. (2019). Mobicare: Mobile healthcare tracking and body sensor security.
[45] Mohapatra, S., et al. (2018). Security routing protocols and data fusion in IoT network layers.
[46] Nanayakkara, C., et al. (2019). Three-layered IoT health framework under Contiki real-time operating system.
[47] Obidallah, W. J. (2025). A unified computational model for assessing security risks in internet of transportation things-based healthcare applications. Electronics, 14(24), 4894.
[48] Pooja, R. (2018). Conventional encryption techniques and data protection.
[49] Rahmani, A. M., et al. (2015). Biometric safety measures and vulnerability to Denial of Service in IoT perception layers.
[50] Rashid, M., et al. (2023). Managing active security risks and medical IoT device weaknesses.
[51] Rossouw, V. (2013). Definitions and conceptual frameworks in cybersecurity.
[52] ScienceIJSAR. (2022). Risk assessment frameworks for cloud and IoT integration.
[53] Selvaraj, K. (2019). Secret sharing schemes and privacy preservation in patient data blocks.
[54] Sfar, et al. (2018). A roadmap for security challenges in the Internet of Things.
[55] Shah, S. A., et al. (2019). Data authenticity, accuracy, and privacy in real-time health monitoring and telemedicine.
[56] Sultan, A., et al. (2021). Threat identification and continuous risk evaluation in cloud-based IoT healthcare.
[57] Sun, Y. (2019). Identity linking and group secret management in e-health applications.
[58] Sun, et al. (2024). A survey on security issues in IoT operating systems.
[59] Tewari, A. (2016). Evaluation of lightweight DTLS protocols for low-power IoT hardware platforms.
[60] Waeal. (2025). A unified computational model for assessing security risks in internet of transportation things-based healthcare applications.
[61] Yan, Z., et al. (2014). Reliable data communication and situation-aware trust management in IoT.
[62] Yang, K. (2017). Addressing security vulnerabilities in evolving IoT ecosystems.
[63] Yasin, A., et al. (2018). A three-layer network security analysis and access control in IoT.
[64] Yueyang, Z. (2025). Data flow security architecture from patient sensors to healthcare systems.
[65] Zhang, Y., et al. (2023). Privacy concerns and data transmission security in healthcare Internet of Things.
How to cite this paper
@article{1720214,
author = {Tayapiti Edmond, Sarjiyus Omega, Nathan Nachandiya},
title = {Development Of a Cloud Based Security Risk Assessment Framework for IoT-Based Health Care System: A Review},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {10},
number = {1},
pages = {3971-3988},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1720214.pdf},
abstract = {The use of Internet of Things (IoT) technology in healthcare has changed how medical services are provided. IoT devices like wearable sensors, implantable tools, and smart diagnostic machines allow doctors to watch patients' health as it happens and help make better decisions about their care. These devices help doctors talk to patients from a distance and give them tailored care, which makes healthcare faster and better for patients. Even though there are many advantages, the way IoT devices are connected creates big security problems because the medical data being sent over networks is very sensitive. Healthcare organizations have to deal with two main problems: keeping patient information safe and making sure that healthcare services keep running without any interruptions. The growing number of IoT devices, which have different amounts of computing power and security features, has made traditional security methods not enough anymore. Many devices don't have enough power to use strong encryption or detect threats as they happen, which makes them easier targets for attacks like man-in-the-middle, malware insertion, and unwanted access. Even though more people are aware of these problems, healthcare organizations still have a hard time finding a complete and flexible security risk assessment system that covers both IoT devices and cloud-based systems. Current solutions are usually broken, slow to act, or only cover certain kinds of threats. They don't look at all the weaknesses, dangers, and possible problems in a complete way. The design science approach works well because the research is about making a tool (a security risk assessment framework) to deal with a real-world issue. The method will go through these steps: first, identifying and looking at the security issues in IoT healthcare systems, then figuring out what the security framework needs, next creating a cloud-based system to assess risks, followed by building and putting the framework into use, and finally testing and checking how well the framework works. This way, the framework is made to properly handle the security problems in IoT healthcare settings.},
keywords = {Cyber Security Threats, Data Protection, HealthCare System, Internet of Things (IoT) Device and e Security Risk Assessment Framework.},
month = {July},
doi = {https://doi.org/10.64388/IREV10I1-1720214}
}