Jul 2026· 2026 International Conference on Emerging Trends in Information, Communication & Systems (ICETICS)· pp. 1-6· 0 citations· 22 references
Abstract
The growing use of interconnected and digital systems in clinical settings has increased the necessity of smart and robust protection systems that can assume extremely rigid privacy and reliability requirements. This paper presents the GuardianMesh: Anomaly-Resilient Federated Orchestration (GM-ARFO) a new AI-based threat prevention model that can be used to provide security to the world of distributed healthcare information ecosystems. The method proposed will allows collaborative intelligence between heterogeneous medical nodes and does not present sensitive patient information or centralised control. GuardianMesh (GM) works by using local clinical and system cues to create compact privacy preserving representations in the edge and then a detection of anomalous behaviors is possible early on. These depictions are jointly trained in an effective federated orchestration system that is resilient to adversarial manipulation and communication inefficiently. A dec-layer adjudication layer is what is used to package distributed evidence of anomalies to facilitate swift and automatic response procedures with have minimum impact to clinical processes. Moreover, adaptive monitoring adapts to behavior drift and the changing attack plans all the time, ensuring the reliability of detection over a long period. Thorough tests in various conditions of operation and adversary show that GM-ARFO has a high level of detection, low false alarms, lower response time in addition to maintaining data confidentiality. The findings support the fact that the suggested GuardianMesh framework offers a scalable, future-restaurant, and privacy-aware platform of ensuring the safety of next-generation healthcare information infrastructures. The suggested method attains an overall detection accuracy of 96.8%, indicating a highly dependable identification of anomalous behaviours in remote healthcare systems.
Results indicate that a federated TinyML architecture with lightweight patient-state tracking, validation-based ensemble filtering, differential privacy, and post-quantum-secure communication can support privacy-aware and attack-resilient ICU monitoring experiments in resource-constrained IoMT settings.
Umar Hayat Khan, Rahim Khan, Tahani Alsaedi et al.· Scientific Reports· 0 citations
Hospitals are increasingly under pressure because of the growing volume of imaging tests carried out, but also because of the sophistication of the attacks by the cybercriminal. Conventional security systems are unable to meet today's challenges to patient records and radiological data. In this research, these challenges are addressed directly by designing an advanced defence system that is specifically designed for medical imaging archiving and communication systems in radiology departments. Architected an extensive protective architecture with seven layers that are interconnected. It's a combination of cutting-edge encryption techniques capable of resisting the powerful future quantum computer, authentication processes that validate every access attempt on the fly, data patterns that are learned, suspicious activity recognized, blockchain technology that makes data impossible to tamper with, and predictive algorithms that foresee threats before they happen. Our system is proactive, identifying and neutralising threats at an early stage, instead of reacting to attacks as they happen. Real-world validation took place within five different hospital networks, covering two years, and thus subjected the framework to the real conditions of operation and to real cyber threats. The results of the system's performance were outstanding – the system had a rate of 99.9% accuracy in detecting malicious activities and a rate of 0.15% False Alarms. The overhead for security operations was just 23 milliseconds, not affecting clinical workflow. Most impressively, there was a 67% reduction in the number of attempts to break in onto the network unauthorisedly, due to the formidable defence measures that they faced.Our framework thwarted 847 real tests against it, ranging from sophisticated persistent intrusions and previously unknown software vulnerabilities to attempts by ransomware to encrypt patient information – all during testing. The system ensured complete compliance with healthcare privacy laws from various jurisdictions, aligning with the American HIPAA regulations, the European GDPR and the new quantum-security protocols. In essence, this is a paradigm shift in medical imaging security, offering healthcare institutions proactive and intelligent protection that safeguards patient privacy and institutional integrity in the face of future threats.
Srinidhi G. A. Saranya D· Journal of Intelligent Decis...· 0 citations
Healthcare cybersecurity in the United States has historically operated on a reactive model, addressing breaches and ransomware incidents only after clinical damage has occurred. This paper argues that the proliferation of Internet of Medical Things (IoMT) devices, combined with escalating ransomware activity now causally linked to increased in-hospital mortality, makes this reactive posture untenable. Drawing on the peer-reviewed literature, we propose a three-layer conceptual security architecture consisting of passive telemetry collection, unsupervised machine learning anomaly detection (deep autoencoders for network-flow analysis and Isolation Forest models for behavioral and access-log analysis), and an AI-augmented Security Orchestration, Automation, and Response (SOAR) layer enforcing graduated, reversible containment through a software-defined networking control plane. We map this architecture against the NIST Cybersecurity Framework 2.0, the CISA Cross-Sector Cybersecurity Performance Goals, and the HIPAA Security Rule's technical safeguards. Distinct from prior conceptual work in this space, this paper does not stop at naming the failure modes of AI-driven security; it specifies four concrete governance protocols designed to close them: a staged, statistically bounded retraining protocol to resist data poisoning; an ensemble-diversity and protocol-aware evasion defense; a time-bound Clinical Override Protocol that resolves the false-positive-versus-patient-safety tension left unresolved in prior proposals; and a stratified differential-impact auditing requirement to detect performance disparities across device classes and facility resource levels before they cause harm. We also specify a concrete, reproducible validation pathway using public IoT/IoMT intrusion benchmark datasets as the necessary next step toward empirical certification of this architecture. We conclude that artificial intelligence can materially strengthen healthcare's Detect and Respond capabilities, but only within a governance structure that operationalizes, rather than merely acknowledges, these failure modes as first-order design constraints.
Mantaka Rowshon, Sharmin Sultana, Akib Rahman· International Journal of Mul...· 0 citations
The rapid adoption of wearable healthcare technologies has transformed healthcare delivery by enabling continuous patient monitoring, remote diagnostics, and real-time clinical decision-making. Despite these benefits, wearable healthcare systems expose sensitive patient information to numerous cybersecurity threats, including unauthorised access, data tampering, ransomware attacks, denial-of-service attacks, and privacy breaches. Elderly patients are particularly vulnerable because wearable devices continuously collect physiological and behavioural information that must be securely transmitted, stored, and processed. Existing cybersecurity mechanisms often operate independently and fail to provide comprehensive protection across the entire Internet of Medical Things (IoMT) ecosystem. This study presents an adaptive cybersecurity model designed to protect elderly patient data within wearable healthcare systems. The model integrates Multi-Factor Authentication (MFA), Role-Based Access Control (RBAC), AES-256 encryption, blockchain technology, and Multi-Layer Neural Network (MLNN)-based anomaly detection within a unified security architecture. The model adopts a five-layer design consisting of the Data Acquisition Layer, Communication Layer, Intelligent Security Layer, Blockchain Security Layer, and Application and Access Layer to secure data throughout acquisition, transmission, processing, storage, and access stages. A Design Science Research (DSR) methodology was employed to identify cybersecurity challenges, gather stakeholder requirements, design the security architecture, develop a prototype, and evaluate its effectiveness. Stakeholder feedback was collected from 238 respondents, including healthcare professionals, IT personnel, cybersecurity experts, and wearable healthcare users, and informed the development and refinement of the model. The model addresses key limitations of existing security approaches by combining proactive threat detection, decentralised data integrity management, secure access control, and continuous monitoring capabilities. The resulting model enhances confidentiality, integrity, availability, accountability, and adaptability within wearable healthcare environments. The study contributes a comprehensive and scalable cybersecurity model capable of mitigating evolving cyber threats while supporting secure remote patient monitoring, regulatory compliance, and trustworthy healthcare service delivery for elderly patients. Among 156 technical stakeholders, 87.8% rated the model as Effective, Very Effective, or Moderately Effective, indicating strong acceptance for securing elderly patient data. These findings indicate that the model supports secure remote healthcare delivery and regulatory compliance.
George N. Wainaina, N. Masese, Ruth Oginga· East African Journal of Info...· 0 citations
The United States healthcare sector grapples with rising cybersecurity threats. Ransomware and data breaches expose millions of protected health information (PHI) records each year, while artificial intelligence (AI) has advanced analytics and supported clinical decisions and tools. AI amplifies both vulnerabilities and protections, but traditional safeguards often struggle or fail to support collaborative model development with stringent HIPAA and HITECH rules. Privacy-preserving machine learning (PPML) techniques offer potential solutions to this tension.
This narrative review draws together peer-reviewed literature from 2020 to 2026 on AI-driven privacy-preserving techniques like federated learning, differential privacy, homomorphic encryption, secure multi-party computation, and blockchain-AI hybrids applied to US healthcare cybersecurity. These tools allow decentralized training, encrypted operations, and auditable partnerships that curb re-identification, inference attacks, and centralized data risks.
Key findings highlight federated learning’s maturity in multi-institutional applications, differential privacy’s solid defenses for group-level analysis, and the promise of hybrids to overcome individual limitations such as computational overhead and expansion barriers. However, persistent challenges include resource demands, potential bias amplification, adversarial vulnerabilities, and limited real-world longitudinal evidence.
The review calls for uniform testing standards, quantum-proof designs, and policy boots to speed uptake. Such methods strengthen privacy alongside function, paving the way for reliable AI use that protects patients, cuts breach damage, and promotes digital health innovation in an increasingly threatened ecosystem.
Isaiah Thompson Ocansey, Mary Magdalene Linda Yeboah· Magna Scientia Advanced Rese...· 0 citations
Emergency access to Electronic Health Record (EHR) systems presents a difficult balance between protecting sensitive patient information and ensuring that clinicians can obtain critical information without delay. Existing security approaches, including Zero-Trust Architecture (ZTA), multi-factor authentication (MFA), and conventional break-glass mechanisms, primarily rely on user identity, device, or network context and do not consider the patient's current clinical condition. No existing approach uses the patient's real-time clinical deterioration as the signal that drives the access decision, which is the specific gap this study addresses. The novelty of the proposed framework lies in coupling clinical-deterioration prediction directly to Zero-Trust policy enforcement, together with automatic privilege revocation once the patient stabilises, rather than in any single component. This study proposes an AI-driven risk-adaptive Zero-Trust framework that incorporates real-time patient deterioration into access control decisions. An LSTM model analyses five vital signs and classifies patient status as STABLE, WARNING, or CRITICAL. The predicted clinical risk is combined with role-specific emergency authority to calculate a composite risk score that determines one of four access levels: Direct Access, MFA Required, Restricted Access, or Denied. The framework was evaluated using the MIMIC-III Clinical Database Demo, comprising 98 patients and 5,992 NEWS2-labelled time-series sequences, together with 6,000 simulated access requests across six clinical specialities. The proposed model achieved an overall accuracy of 82.20%, a CRITICAL-class recall of 88.00%, and an AUC of 0.9752. The access-control engine produced an average decision latency of 0.265 ms while maintaining complete audit logging and 99.3% least-privilege compliance. These findings suggest that integrating clinical deterioration predictions into Zero-Trust access control can improve emergency responsiveness while preserving security and accountability. Although the framework was evaluated in a simulated environment, the results demonstrate its potential for future deployment and validation in real clinical settings.
Arthur Nashon Malingo, Christian Budoya, G. Tesha· East African Journal of Info...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.