Home / Current Issue / Paper 1723253
Design and Implementation of a Zero-Trust Architecture for Securing Cloud-Based Healthcare Systems in the US
Subject area: Science,Engineering and Technology · Area of research: ICT
Abstract
The rapid migration of US healthcare systems to cloud infrastructure has substantially expanded the attack surface for cyber threats targeting protected health information (PHI). Traditional perimeter-based security models have proven inadequate against the sophistication of modern ransomware campaigns, insider threats, and supply-chain compromises. This study investigates the design and implementation of a Zero-Trust Architecture (ZTA) tailored for cloud-based healthcare systems in the United States. Drawing on a systematic literature review of 60 peer-reviewed studies, government standards, and validated case analyses published between 2018 and 2025, the research identifies seven primary security themes identity and access management, data encryption and PHI protection, micro-segmentation, regulatory compliance, continuous monitoring, interoperability challenges, and AI-driven threat detection and proposes a five-layer Unified Zero-Trust Healthcare Framework (UZTHF). The framework integrates NIST SP 800-207, HIPAA Security Rule requirements, HITECH obligations, and NIST CSF 2.0 into a coherent, cloud-native implementation roadmap. Case study evidence from Mayo Clinic, Kaiser Permanente, the US Department of Veterans Affairs, Intermountain Healthcare, and Ascension Health demonstrates that ZTA deployments consistently reduce unauthorized access incidents, shorten mean time to detect (MTTD), and improve HIPAA audit outcomes. Findings indicate that while ZTA offers transformative security benefits for healthcare cloud environments, adoption barriers including implementation complexity, workforce skill gaps, legacy EHR integration, and regulatory ambiguity require coordinated policy and industry responses. The UZTHF provides actionable, standardized guidance for healthcare organizations, cloud service providers, and regulators seeking to operationalize zero-trust principles in clinical settings.
Keywords
zero-trust architecture, cloud security, healthcare cybersecurity, HIPAA compliance, protected health information, identity and access management, micro-segmentation, NIST SP 800-207, ransomware, EHR security
References
[1] Al-Issa, Y., Ottom, M. A., & Tamrawi, A. (2019). eHealth cloud security challenges: A survey. Journal of Healthcare Engineering, 2019, 1–15. Wiley
[2] Argaw, S. T., Troncoso-Pastoriza, J. R., Lacey, D., Florin, M.-V., Calcavecchia, F., Anderson, D., Burleson, W., Vogel, J.-M., O'Leary, C., Eshaya-Chauvin, B., & Flahault, A. (2019). Cybersecurity of hospitals: Discussing the challenges and working towards mitigating the risks. BMC Medical Informatics and Decision Making, 19(1), 146.
[3] Balasubramanian, V., Stranieri, A., & Ramsay, H. (2021). Security vulnerabilities and challenges in cloud-based healthcare: A systematic review. Future Internet, 13(9), 231.
[4] Braun, V., & Clarke, V. (2006). Using thematic analysis in psychology. Qualitative Research in Psychology, 3(2), 77–101. Taylor & Francis
[5] Buczak, A. L., & Guven, E. (2016). A survey of data mining and machine learning methods for cybersecurity intrusion detection. IEEE Communications Surveys & Tutorials, 18(2), 1153–1176. IEEE
[6] Center for Internet Security. (2021). CIS controls version 8. Center for Internet Security
[7] Coventry, L., & Branley-Bell, D. (2018). Cybersecurity in healthcare: A narrative review of trends, threats, and ways forward. Maturitas, 113, 48–52. ScienceDirect
[8] Denyer, D., & Tranfield, D. (2009). Producing a systematic review. In D. A. Buchanan & A. Bryman (Eds.), The SAGE handbook of organizational research methods (pp. 671–689). SAGE.
[9] Executive Order 14028. (2021, May 12). Improving the nation's cybersecurity. Federal Register, 86(93), 26633–26649. Federal Register
[10] Ferrag, M. A., Maglaras, L., Janicke, H., Jiang, J., & Shu, L. (2023). Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study. Journal of Information Security and Applications, 76, 103528.
[11] Fu, K., & Blum, J. (2013). Controlling for cybersecurity risks of medical device software. Communications of the ACM, 56(10), 35–37. ACM
[12] Grispos, G., Glisson, W. B., & Storer, T. (2021). Healthcare cybersecurity incidents and investigation: Exploring nurse practitioner perceptions. In Proceedings of the 54th Hawaii International Conference on System Sciences (HICSS). HICSS
[13] Hassan, W., Holt, T., & Ngo, F. (2023). A survey of zero-trust security practices in US health systems. Journal of Cybersecurity and Privacy, 3(2), 180–201.
[14] Health Information and Management Systems Society. (2023). 2023 HIMSS healthcare cybersecurity survey. HIMSS. HIMSS
[15] Health-ISAC. (2023). Health sector cybersecurity coordination center (HC3) 2023 annual threat report. Health-ISAC / HHS. HHS
[16] HHS Office for Civil Rights. (2023). Cybersecurity guidance: Recognized security practices and the HIPAA security rule. US Department of Health and Human Services. HHS
[17] HHS Office for Civil Rights. (2024). HIPAA breach notification rule: 2023 annual data breach summary. US Department of Health and Human Services. HHS
[18] IBM Security. (2023). Cost of a data breach report 2023. IBM Corporation. IBM
[19] Kindervag, J. (2010). No more chewy centers: Introducing the zero trust model of information security. Forrester Research. Palo Alto Networks
[20] Lame, G. (2019). Systematic literature reviews: An introduction. In Proceedings of the Design Society: International Conference on Engineering Design (ICED), 1(1), 1633–1642. Cambridge
[21] Lizotte, D. J., Simmonds, M., Kanji, S., & Holbrook, A. M. (2020). Convergent integrated synthesis in systematic reviews: A practical guide. Systematic Reviews, 9(1), 256. Springer
[22] Mandel, J. C., Kreda, D. A., Mandl, K. D., Kohane, I. S., & Ramoni, R. B. (2016). SMART on FHIR: A standards-based, interoperable apps platform for electronic health records. Journal of the American Medical Informatics Association, 23(5), 899–908. PubMed
[23] Mehraj, S., & Banday, M. T. (2020). Establishing a zero trust strategy in cloud computing environment. In 2020 International Conference on Computer Communication and Informatics (ICCCI) (pp. 1–6). IEEE. IEEE
[24] National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework 2.0 (NIST CSWP 29). US Department of Commerce. NIST
[25] Oughton, E., Usher, W., Tyler, P., & Hall, J. (2022). Infrastructure as a complex adaptive system. Complexity, 2022, 1–17.
[26] Oyedeji, M. A., & Isaiah, I. A. (2026). Investigating the role of blockchain technology in enhancing supply chain security for US manufacturing industries. International Journal of Modern Science and Research Technology, 4(8), 581–596. Zenodo
[27] Page, M. J., McKenzie, J. E., Bossuyt, P. M., Boutron, I., Hoffmann, T. C., Mulrow, C. D., Shamseer, L., Tetzlaff, J. M., Akl, E. A., Brennan, S. E., Chou, R., Glanville, J., Grimshaw, J. M., Hróbjartsson, A., Lalu, M. M., Li, T., Loder, E. W., Mayo-Wilson, E., McDonald, S., & Moher, D. (2021). The PRISMA 2020 statement: An updated guideline for reporting systematic reviews. BMJ, 372, n71. BMJ
[28] Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture (NIST SP 800-207). National Institute of Standards and Technology. NIST
[29] Rushanan, M., Rubin, A. D., Kune, D. F., & Swanson, C. M. (2014). SoK: Security and privacy in implantable medical devices and body area networks. In 2014 IEEE Symposium on Security and Privacy (SP) (pp. 524–539). IEEE. IEEE
[30] Saracino, A., Sgandurra, D., Dini, G., & Martinelli, F. (2016). Madam: Effective and efficient behavior-based Android malware detection and prevention. IEEE Transactions on Dependable and Secure Computing, 15(1), 83–97. IEEE
[31] Securities and Exchange Commission. (2023). Cybersecurity risk management, strategy, governance, and incident disclosure (Final Rule). 17 CFR Parts 229 and 249. SEC
[32] Sousa, P. R., Resende, J. S., Martins, R., & Antunes, L. (2021). Scalable access control for multi-tenant cloud-native applications. In Proceedings of the 16th International Conference on Availability, Reliability and Security (ARES) (pp. 1–9). ACM.
[33] Stafford, T. F. (2020). Zero trust networks. Communications of the ACM, 63(10), 19–21.
[34] Stanton, B., Greene, K. K., & Theofanos, M. (2022). Healthcare workers and cybersecurity: A survey of authentication practices. Journal of Cybersecurity, 8(1), tyac004.
[35] Syed, N. F., Shah, S. W., Shaghaghi, A., Anwar, A., Baig, Z., & Doss, R. (2022). Zero trust architecture (ZTA): A comprehensive survey. IEEE Access, 10, 57143–57179. IEEE
[36] Thati, V., & Sheltami, T. (2022). An intelligent approach for detecting healthcare cloud security threats using user and entity behavior analytics. Computers & Security, 120, 102807.
[37] Thomason, J. (2022). Digital health and cybersecurity in the age of COVID-19. Frontiers in Digital Health, 4, 874416. Frontiers
[38] Verizon. (2023). 2023 data breach investigations report. Verizon Business. Verizon
[39] Walker-Roberts, S., Hammoudeh, M., & Dehghantanha, A. (2018). A systematic review of the availability and efficacy of countermeasures to internal threats in healthcare critical infrastructure. IEEE Access, 6, 25167–25177. IEEE
[40] Ward, B., & Beyer, B. (2014). BeyondCorp: A new approach to enterprise security. ;login: USENIX Magazine, 39(6), 6–11. USENIX
How to cite this paper
@article{1723253,
author = {Michael Akintomiwa Oyedeji, Tinuade Dawotola, Omobolaji Olakunle Oladapo },
title = {Design and Implementation of a Zero-Trust Architecture for Securing Cloud-Based Healthcare Systems in the US},
journal = {Iconic Research And Engineering Journals},
year = {2026},
volume = {10},
number = {3},
pages = {2122-2142},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1723253.pdf},
abstract = {The rapid migration of US healthcare systems to cloud infrastructure has substantially expanded the attack surface for cyber threats targeting protected health information (PHI). Traditional perimeter-based security models have proven inadequate against the sophistication of modern ransomware campaigns, insider threats, and supply-chain compromises. This study investigates the design and implementation of a Zero-Trust Architecture (ZTA) tailored for cloud-based healthcare systems in the United States. Drawing on a systematic literature review of 60 peer-reviewed studies, government standards, and validated case analyses published between 2018 and 2025, the research identifies seven primary security themes identity and access management, data encryption and PHI protection, micro-segmentation, regulatory compliance, continuous monitoring, interoperability challenges, and AI-driven threat detection and proposes a five-layer Unified Zero-Trust Healthcare Framework (UZTHF). The framework integrates NIST SP 800-207, HIPAA Security Rule requirements, HITECH obligations, and NIST CSF 2.0 into a coherent, cloud-native implementation roadmap. Case study evidence from Mayo Clinic, Kaiser Permanente, the US Department of Veterans Affairs, Intermountain Healthcare, and Ascension Health demonstrates that ZTA deployments consistently reduce unauthorized access incidents, shorten mean time to detect (MTTD), and improve HIPAA audit outcomes. Findings indicate that while ZTA offers transformative security benefits for healthcare cloud environments, adoption barriers including implementation complexity, workforce skill gaps, legacy EHR integration, and regulatory ambiguity require coordinated policy and industry responses. The UZTHF provides actionable, standardized guidance for healthcare organizations, cloud service providers, and regulators seeking to operationalize zero-trust principles in clinical settings.},
keywords = {zero-trust architecture, cloud security, healthcare cybersecurity, HIPAA compliance, protected health information, identity and access management, micro-segmentation, NIST SP 800-207, ransomware, EHR security},
month = {September},
}