Implementing Zero-Trust Architecture and Advanced Encryption Techniques in Healthcare Data Systems: A Simulation-based Evaluation of an Adaptive, AI-Driven Security Framework

Chinyere Nelson Amaeze *

Department of Information Technology, American National University, United States.

Ezekiel Dauda Gambo

Department of Haematology and Blood Transfusion Science, Igbinedion University Okada, Okada, Edo State, Nigeria.

*Author to whom correspondence should be addressed.


Abstract

Background: Healthcare data systems in the United States face a threat environment in which conventional perimeter-based security architectures are increasingly mismatched to cloud-connected, vendor-dependent, and Internet of Medical Things (IoMT)-enabled clinical infrastructure. Zero-trust architecture (ZTA) and advanced encryption techniques are widely recommended as remedies, yet empirical, quantitative evidence directly comparing zero-trust and perimeter-based postures, and benchmarking the specific cryptographic primitives proposed for healthcare deployment, remains limited.

Objective: This study designs, implements, and empirically evaluates a four-layer Zero-Trust Encrypted Healthcare Data Architecture (ZTE-HDA) that integrates an artificial intelligence/machine learning (AI/ML)-driven continuous verification engine, governed, micro-segmented access control, and a layered encryption scheme combining symmetric, asymmetric, and homomorphic primitives.

Methods: A synthetic dataset of 60,000 access events (3.33% labelled malicious across five attack archetypes: credential theft, insider snooping, ransomware staging, lateral movement, and subtle impossible-travel) was generated to train and evaluate four candidate continuous-verification models (logistic regression, random forest, gradient boosting, and a multilayer perceptron). A benchmark suite measured the performance of AES-256-GCM, ChaCha20-Poly1305, RSA-2048/4096, elliptic-curve Diffie-Hellman (ECDH P-256), a hybrid ECDH+AES-256-GCM scheme, and Paillier homomorphic encryption across payload sizes representative of healthcare data artefacts. A 10,000-trial Monte Carlo simulation modelled lateral breach propagation across a 20-segment healthcare data network under perimeter-based versus zero-trust, continuously verified, micro-segmented conditions. No real patient data, live hospital network, or production healthcare information system was used at any stage; all experiments were conducted entirely on synthetic, computer-generated data.

Results: The gradient boosting and multilayer perceptron models achieved the strongest overall discrimination (area under the receiver operating characteristic curve [AUC] of 0.989 and 0.990, respectively; F1-scores of 0.915 and 0.926), with recall (detection rate) of 88.5% to 94.7% across all four models and a mean per-event inference latency below 3.1 milliseconds for three of the four models, supporting real-time policy decisions. AES-256-GCM substantially outperformed ChaCha20-Poly1305 on this hardware, reaching throughput of approximately 8.0 gigabytes per second for 512 kilobyte payloads, consistent with AES-NI hardware acceleration. Paillier homomorphic addition of 25 encrypted laboratory values was verified to be exact (decrypted sum equal to the plaintext sum to six decimal places) but carried substantial per-value overhead (approximately 104 milliseconds to encrypt a single value). The Monte Carlo simulation showed that the zero-trust, continuously verified architecture reduced the mean breach blast radius from 8.75 to 1.12 of 20 simulated data segments (an 87.2% reduction) and eliminated simulated full-network compromise entirely (13.2% of perimeter-model trials versus 0% of zero-trust-model trials).

Conclusion: An AI/ML-driven continuous verification engine combined with layered, workload-appropriate encryption and micro-segmentation produces large, quantifiable reductions in simulated breach impact relative to a perimeter-based baseline, while remaining within latency and computational budgets that are suggestive of, though not yet confirmed to be, compatibility with real-time clinical operation; this remains to be validated on live clinical systems. The findings, while derived from a simulation rather than a live clinical deployment, offer a preliminary, reproducible quantitative reference point, rather than a confirmed operational benchmark, for healthcare organisations and policymakers evaluating zero-trust and advanced-encryption investment under the evolving United States regulatory landscape.

Keywords: Zero-trust architecture, healthcare data security, continuous verification, machine learning, advanced encryption, micro-segmentation, electronic health records, Internet of Medical Things, homomorphic encryption, breach-propagation simulation


How to Cite

Amaeze, Chinyere Nelson, and Ezekiel Dauda Gambo. 2026. “Implementing Zero-Trust Architecture and Advanced Encryption Techniques in Healthcare Data Systems: A Simulation-Based Evaluation of an Adaptive, AI-Driven Security Framework”. Advances in Research 27 (4):457-72. https://doi.org/10.9734/air/2026/v27i41685.

Downloads

Download data is not yet available.