Improving Security Practices in Health Information Systems with STRIDE Threat Modeling
Md Ismail Hossain, Ragib Hasan · 2023
Health Information Systems (HISs) are critical in modern healthcare by facilitating patient health information storage, management, and exchange. However, the increasing reliance on technology and the rise in cyber threats have heightened the importance of ensuring the security of these systems. In this paper, we present a comprehensive approach to improving security practices in HISs by applying the STRIDE threat modeling framework. The STRIDE framework offers a systematic methodology for identifying and analyzing potential vulnerabilities, covering threats such as Spoofing, Tampering, Repudiation, Information disclosure, Denial of Service, and Elevation of Privilege. By applying the STRIDE approach, healthcare organizations can proactively identify threats, evaluate their potential impact, and implement appropriate security controls to mitigate risks. Our threat model highlights the significance of a robust security posture in safeguarding patient privacy, maintaining data integrity, and ensuring the confidentiality of sensitive health information. Furthermore, it emphasizes the need for ongoing risk assessments, employee training, and adherence to industry best practices to address emerging security challenges effectivelvy.