Implementing Zero Trust Security in Microservice Architecture of Electronic Health Record

Mary Jane C. Samonte, Jon Eril R. Aparize, Joyous M. Geronimo, Crispin C. Oriño · 2024

The security and privacy of Electronic Health Records (EHR) are critical in the healthcare sector, where breaches can have severe consequences. Traditional security models, relying on perimeter-based defenses, have proven insufficient in the face of sophisticated threats. This paper proposes the integration of Zero Trust Security (ZTS) into the microservice architecture of EHR systems to address these evolving challenges. By leveraging the “never trust, always verify” principle, ZTS strengthens security through continuous authentication, least-privilege access, and micro-segmentation. The microservices architecture further enhances scalability and flexibility in handling sensitive healthcare data. This paper identifies key vulnerabilities in current EHR systems, outlines research gaps, and proposes a comprehensive ZTS-based solution tailored to mitigate insider threats, unauthorized access, and data breaches. The findings demonstrate how ZTS can bolster the resilience and regulatory compliance of EHR systems, providing a robust framework for safeguarding patient confidentiality and trust in healthcare.

Read the paper · More papers on PaperTik