Skip to content
Open access

Implementing Zero-Trust Architecture and Advanced Encryption Techniques in Healthcare Data Systems: A Simulation-based Evaluation of an Adaptive, AI-Driven Security Framework

Jul 2026 · Advances in Research · 0 citations

Abstract

Background: Healthcare data systems in the United States face a threat environment in which conventional perimeter-based security architectures are increasingly mismatched to cloud-connected, vendor-dependent, and Internet of Medical Things (IoMT)-enabled clinical infrastructure. Zero-trust architecture (ZTA) and advanced encryption techniques are widely recommended as remedies, yet empirical, quantitative evidence directly comparing zero-trust and perimeter-based postures, and benchmarking the specific cryptographic primitives proposed for healthcare deployment, remains limited. Objective: This study designs, implements, and empirically evaluates a four-layer Zero-Trust Encrypted Healthcare Data Architecture (ZTE-HDA) that integrates an artificial intelligence/machine learning (AI/ML)-driven continuous verification engine, governed, micro-segmented access control, and a layered encryption scheme combining symmetric, asymmetric, and homomorphic primitives. Methods: A synthetic dataset of 60,000 access events (3.33% labelled malicious across five attack archetypes: credential theft, insider snooping, ransomware staging, lateral movement, and subtle impossible-travel) was generated to train and evaluate four candidate continuous-verification models (logistic regression, random forest, gradient boosting, and a multilayer perceptron). A benchmark suite measured the performance of AES-256-GCM, ChaCha20-Poly1305, RSA-2048/4096, elliptic-curve Diffie-Hellman (ECDH P-256), a hybrid ECDH+AES-256-GCM scheme, and Paillier homomorphic encryption across payload sizes representative of healthcare data artefacts. A 10,000-trial Monte Carlo simulation modelled lateral breach propagation across a 20-segment healthcare data network under perimeter-based versus zero-trust, continuously verified, micro-segmented conditions. No real patient data, live hospital network, or production healthcare information system was used at any stage; all experiments were conducted entirely on synthetic, computer-generated data. Results: The gradient boosting and multilayer perceptron models achieved the strongest overall discrimination (area under the receiver operating characteristic curve [AUC] of 0.989 and 0.990, respectively; F1-scores of 0.915 and 0.926), with recall (detection rate) of 88.5% to 94.7% across all four models and a mean per-event inference latency below 3.1 milliseconds for three of the four models, supporting real-time policy decisions. AES-256-GCM substantially outperformed ChaCha20-Poly1305 on this hardware, reaching throughput of approximately 8.0 gigabytes per second for 512 kilobyte payloads, consistent with AES-NI hardware acceleration. Paillier homomorphic addition of 25 encrypted laboratory values was verified to be exact (decrypted sum equal to the plaintext sum to six decimal places) but carried substantial per-value overhead (approximately 104 milliseconds to encrypt a single value). The Monte Carlo simulation showed that the zero-trust, continuously verified architecture reduced the mean breach blast radius from 8.75 to 1.12 of 20 simulated data segments (an 87.2% reduction) and eliminated simulated full-network compromise entirely (13.2% of perimeter-model trials versus 0% of zero-trust-model trials). Conclusion: An AI/ML-driven continuous verification engine combined with layered, workload-appropriate encryption and micro-segmentation produces large, quantifiable reductions in simulated breach impact relative to a perimeter-based baseline, while remaining within latency and computational budgets that are suggestive of, though not yet confirmed to be, compatibility with real-time clinical operation; this remains to be validated on live clinical systems. The findings, while derived from a simulation rather than a live clinical deployment, offer a preliminary, reproducible quantitative reference point, rather than a confirmed operational benchmark, for healthcare organisations and policymakers evaluating zero-trust and advanced-encryption investment under the evolving United States regulatory landscape.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.