Designing Secure Healthcare Microservices for State and Federal Systems
DOI:
https://doi.org/10.64137/3107-9458/ICACSIS-114Keywords:
Healthcare Microservices, Healthcare Information Systems, Cybersecurity, State and Federal Healthcare Systems, HIPAA Compliance, Zero Trust Architecture, Cloud Security, Healthcare Interoperability, Secure API Gateway, Healthcare Data ProtectionAbstract
The growing digitalization of healthcare has transformed drastically the delivery, management and access to medical services in the state and federal systems. But as governments roll out electronic health records, telemedicine platforms, health information exchanges and data-driven public health programs, there is a rising need for scalable, adaptable and interoperable software structures that can support different healthcare tasks. Usually, traditional monolith systems struggle to keep up with these changing requirements. This leads enterprises to think about microservices architecture, which provides separate deployment of services, greater maintainability and faster innovation. Adopting microservices in government healthcare systems presents unique security challenges due to the sensitive nature of patient data and the tight regulatory requirements under HIPAA and other federal and state compliance rules. Challenges such as unauthorized access, data breaches, unsecure service communication, identity management and scattered attack surfaces require sophisticated security measures adapted to healthcare ecosystems. This paper presents a secure microservices platform for state and federal infrastructures in healthcare. The framework includes security-by-design concepts, zero-trust architecture, strong authentication and authorization, encrypted communication between services, constant monitoring, and governance focused on compliance. The proposed architecture is projected to enhance system resilience, in addition to offering interoperability, scalability and operational efficiency of distributed healthcare services. Existing healthcare security challenges are discussed extensively and the design shows how existing security standards may be efficiently integrated into microservice environments to secure patient data and provide reliable healthcare delivery. The results underscore the need for combining architecture flexibility with proactive safeguards against new cyber risks in government healthcare infrastructures. The study proposes a pragmatic and versatile security model to support policymakers, healthcare administrators and system architects to design secure, compliant and future-proof healthcare platforms that might facilitate the ongoing digital transformation efforts at both state and federal levels.
References
[1] Adepu, Ganesh. "Zero-Trust Digital Government Platforms: Secure Identity, API Governance, and Cloud-Native Service Architecture."
[2] Krämer, Michel, Sven Frese, and Arjan Kuijper. "Implementing secure applications in smart city clouds using microservices." Future International Journal of Engineering & Extended Technologies Research (IJEETR) 3.3 (2021): 3089-3093.
[3] Generation Computer Systems 99 (2019): 308-320.
[4] Berardi, Davide, et al. "Microservice security: a systematic literature review." PeerJ Computer Science 8 (2022): e779.
[5] Chatterjee, Ayan, et al. "Sftsdh: Applying spring security framework with TSD-based oauth2 to protect microservice architecture apis." Ieee Access 10 (2022): 41914-41934.
[6] Chandramouli, Ramaswamy. "Microservices-based application systems." NIST Special Publication 800.204 (2019): 800-204.
[7] Preuveneers, Davy, and Wouter Joosen. "Access control with delegated authorization policy evaluation for data-driven microservice workflows." Future Internet 9.4 (2017): 58.
[8] Alshudukhi, Khulud Salem, et al. "An interoperable blockchain security frameworks based on microservices and smart contract in IoT environment." Electronics 12.3 (2023): 776.
[9] Mateus-Coelho, Nuno, Manuela Cruz-Cunha, and Luis Gonzaga Ferreira. "Security in microservices architectures." Procedia Computer Science 181 (2021): 1225-1236.
[10] Al-Doghman, Firas, et al. "AI-enabled secure microservices in edge computing: Opportunities and challenges." IEEE Transactions on Services Computing 16.2 (2022): 1485-1504.
[11] Zaki, John, et al. "Introducing cloud-assisted micro-service-based software development framework for healthcare systems." IEEE Access 10 (2022): 33332-33348.
[12] Odofin, Oyejide Timothy, et al. "Improving healthcare data intelligence through custom NLP pipelines and fast API micro services." J Front Multidiscip Res 4.1 (2023): 390-7.
[13] Moustafa, Nour, Kim-Kwang Raymond Choo, and Adnan M. Abu-Mahfouz. "Guest editorial: AI-enabled threat intelligence and hunting microservices for distributed industrial IoT system." IEEE Transactions on Industrial Informatics 18.3 (2021): 1892-1895.
[14] Calderón-Gómez, Huriviades, et al. "Telemonitoring system for infectious disease prediction in elderly people based on a novel microservice architecture." IEEE access 8 (2020): 118340-118354.
[15] Karvannan, Rajesh. "Real‑Time Prescription Management System Intake & Billing System." International Journal of Humanities and Information Technology 5.02 (2023): 34-43.
[16] Fritzsch, Jonas, et al. "Adopting microservices and DevOps in the cyber‐physical systems domain: A rapid review and case study." Software: Practice and Experience 53.3 (2023): 790-810.


