ZERO TRUST IN HEALTHCARE ENVIRONMENTS: RECONCILING THE PRINCIPLE OF LEAST PRIVILEGE WITH AVAILABILITY REQUIREMENTS IN LIFE-SUPPORT SYSTEMS

Autores

  • Tadeu Marcos Borges Paes Autor
  • Francisco Nicolás Isnardi Begot Autor
  • Carlos Kiyoshi Yanaguibashi Menezes Autor
  • Eudes Danilo da Silva Mendonça Autor
  • Vinicius Campos de Meneses Autor

DOI:

https://doi.org/10.56238/IIMultiCientifica-012

Palavras-chave:

Zero Trust Architecture, Least Privilege, Healthcare Cybersecurity, Context-Aware Access Control, Life-Support Systems, Hospital Network Security

Resumo

This paper examines the challenges of implementing the Zero Trust Architecture (ZTA) in healthcare environments, with a particular focus on reconciling the Least Privilege principle with the stringent availability requirements of life-critical systems. While Zero Trust promotes strict access control and continuous verification, healthcare infrastructures must ensure uninterrupted operation of medical devices and clinical workflows, where delays or access restrictions may directly impact patient safety. This work provides a systematic analysis of the inherent trade-offs between security and availability in hospital networks, especially in the context of legacy systems, heterogeneous medical devices, and real-time clinical decision-making. We review existing approaches to access control, including role-based and attribute-based models, and evaluate their limitations when applied to dynamic and high-stakes medical environments. Furthermore, we propose a context-aware access control framework that dynamically adjusts privilege levels based on operational conditions, such as emergency scenarios, user roles, and device criticality. The proposed model aims to preserve the core principles of ZTA while ensuring that essential medical services remain continuously available. Finally, we discuss implementation challenges, potential risks, and future research directions toward resilient and secure healthcare infrastructures.

Downloads

Publicado

2026-04-19

Como Citar

Paes, T. M. B. ., Begot, F. N. I. ., Menezes, C. K. Y. ., Mendonça, E. D. da S. ., & de Meneses, V. C. . (2026). ZERO TRUST IN HEALTHCARE ENVIRONMENTS: RECONCILING THE PRINCIPLE OF LEAST PRIVILEGE WITH AVAILABILITY REQUIREMENTS IN LIFE-SUPPORT SYSTEMS. Anais Eventos. https://doi.org/10.56238/IIMultiCientifica-012