Design and Implementation of a Zero-Trust Architecture for Securing Cloud-Based Healthcare Systems in the US
Abstract
-The rapid migration of US healthcare systems to cloud infrastructure has substantially expanded the attack surface for cyber threats targeting protected health information (PHI). Traditional perimeter-based security models have proven inadequate against the sophistication of modern ransomware campaigns, insider threats, and supply-chain compromises. This study investigates the design and implementation of a Zero-Trust Architecture (ZTA) tailored for cloud-based healthcare systems in the United States. Drawing on a systematic literature review of 60 peer-reviewed studies, government standards, and validated case analyses published between 2018 and 2025, the research identifies seven primary security themes identity and access management, data encryption and PHI protection, micro-segmentation, regulatory compliance, continuous monitoring, interoperability challenges, and AI-driven threat detection and proposes a five-layer Unified Zero-Trust Healthcare Framework (UZTHF). The framework integrates NIST SP 800-207, HIPAA Security Rule requirements, HITECH obligations, and NIST CSF 2.0 into a coherent, cloud-native implementation roadmap. Case study evidence from Mayo Clinic, Kaiser Permanente, the US Department of Veterans Affairs, Intermountain Healthcare, and Ascension Health demonstrates that ZTA deployments consistently reduce unauthorized access incidents, shorten mean time to detect (MTTD), and improve HIPAA audit outcomes. Findings indicate that while ZTA offers transformative security benefits for healthcare cloud environments, adoption barriers including implementation complexity, workforce skill gaps, legacy EHR integration, and regulatory ambiguity require coordinated policy and industry responses. The UZTHF provides actionable, standardized