A system for securing patient data in IoT-enabled hospitals

A cybersecurity framework combining blockchain, AI, and machine learning addresses IoT vulnerabilities in healthcare by protecting patient data through compartmental epidemi modeling and secure storage, ensuring data integrity and compliance.

DE202025101529U1Active Publication Date: 2025-05-08MISHRA BIMAL KUMAR HAZARIBAG +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE202025101529
Authority / Receiving Office
DE · DE
Patent Type
Utility models
Current Assignee / Owner
Filing Date
2025-03-20
Publication Date
2025-05-08
Estimated Expiration
2035-03-31

AI Technical Summary

Technical Problem

Healthcare organizations face inadequate cyber security measures against advanced threats like ransomware, data theft, and IoT vulnerabilities, which compromise patient data integrity and system availability.

Method used

A security framework integrating blockchain technology, artificial intelligence, and machine learning to create a robust defense mechanism for IoT-capable hospitals, utilizing compartmental epidemi modeling, AI-controlled threat detection, and secure data block storage to protect patient data while ensuring compliance with health regulations.

Benefits of technology

The system provides comprehensive protection against evolving cyber threats, maintains data confidentiality and operational efficiency, and ensures compliance with legal standards by adapting to new attack patterns and continuously monitoring for anomalies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A system for securing patient data in IoT-enabled hospitals, consisting of: a network of IoT-enabled medical devices configured to collect and transmit patient data; a blockchain network in conjunction with the aforementioned medical devices, configured to create an immutable ledger of patient data transactions, implement smart contracts for access control, and maintain a decentralized log of data access attempts; an Artificial Intelligence and Machine Learning (AIML) module configured to: monitor blockchain activity for anomalous patterns, implement intrusion detection using machine learning algorithms, perform predictive analytics for threat detection, and execute natural language processing to identify personal data; a secure data block storage configured for: implementing PII data masking for sensitive patient information, maintaining the masked data utility for authorized users, and storing encrypted patient records; a malware detection module configured to detect unauthorized data manipulation attempts, identify exponential data propagation patterns, monitor system vulnerabilities, and track malware transmission behavior; and a defense framework configured to: implement compartmental epidemic modeling for attack analysis, calculate reproduction numbers for malware propagation, adapt security measures based on threat levels, and maintain version control of security updates.
Need to check novelty before this filing date? Find Prior Art

Description

AREA OF INVENTION

[0001] The present disclosure relates to a security system, in particular a system for securing patient data in IoT-enabled hospitals. In particular, the present invention relates to an epidemic quarantine system in connection with the transmission of ransomware in IoT-enabled hospitals. BACKGROUND OF THE INVENTION

[0002] The healthcare industry faces increasing cybersecurity challenges as it adopts new technologies to improve patient care. Healthcare organizations are particularly attractive targets for cybercriminals due to their extensive databases of sensitive patient data, including personal health information, payment details, and medical records. The critical nature of healthcare services often makes these organizations more vulnerable to ransomware attacks, as they cannot afford prolonged system outages that could jeopardize patient care.

[0003] Traditional cybersecurity measures have proven inadequate against evolving threats such as sophisticated malware, data theft, distributed denial-of-service (DDoS) attacks, and social engineering attempts. The healthcare sector's increasing reliance on Internet of Things (IoT) devices and connected systems has created additional vulnerabilities that cybercriminals are actively exploiting. While current security solutions are helpful, they do not sufficiently address the complex interplay between human factors, technological vulnerabilities, and the critical need for uninterrupted healthcare.

[0004] The present invention addresses these challenges by introducing a novel security framework that combines blockchain technology, artificial intelligence, and mathematical modeling. This integrated approach provides a robust defense mechanism specifically designed for IoT-enabled hospitals. The system utilizes compartmental epidemic modeling to understand and predict ransomware behavior while simultaneously implementing blockchain-based data protection and AI-driven threat detection. This combination ensures both the security of patient data and the continuous availability of critical healthcare systems, while also guaranteeing compliance with healthcare regulations such as the HITECH (Health Information Technology for Electronic and Clinical Health Act).

[0005] The system not only protects against current cyber threats but also adapts to new attack patterns thanks to its machine learning capabilities. By integrating PII data masking, intrusion detection systems, and anomaly detection, the system offers comprehensive protection while ensuring that healthcare providers can efficiently access necessary patient information. This solution represents a significant advancement in healthcare cybersecurity. It addresses the unique challenges of modern healthcare facilities while maintaining a balance between data security and operational efficiency. Summary of the invention

[0006] This disclosure relates to a system for securing patient data in IoT-enabled hospitals. The invention presents a comprehensive cybersecurity system for IoT-enabled hospitals that integrates blockchain technology, artificial intelligence, and machine learning to protect patient data. The system implements a multi-layered defense system with secure data block storage, malware detection, and automated threat response mechanisms. It utilizes advanced PII data masking and compartmental epidemic modeling to prevent unauthorized access while ensuring data use for authorized healthcare providers.

[0007] The disclosure relates to the provision of a system for securing patient data in IoT-enabled hospitals. The system comprises: a network of IoT-enabled medical devices that collect and transmit patient data; a blockchain network associated with the medical devices that creates an immutable ledger of patient data transactions, implements smart contracts for access control, and maintains a decentralized log of data access attempts; and an artificial intelligence and machine learning (AIML) module that enables: monitoring blockchain activity for anomalous patterns, implementing attack detection using machine learning algorithms, performing predictive analytics for threat detection, and executing natural language processing to identify personally identifiable information.a secure data block storage system that enables: implementation of PII data masking for confidential patient information, provision of masked data services to authorized users, and storage of encrypted patient records; a malware detection module that enables: detection of unauthorized data manipulation attempts, identification of exponential data propagation patterns, monitoring of system vulnerabilities, and tracking of malware transmission behavior; and a defense framework configured to implement compartmental epidemic modeling for attack analysis, calculate reproduction numbers for malware propagation, adjust security measures based on threat level, and maintain version control of security updates.

[0008] One objective of this disclosure is to provide a system for securing patient data in IoT-enabled hospitals.

[0009] Another objective of this disclosure is to provide a robust security framework that protects patient data in IoT-enabled hospitals through the integration of blockchain, AI / ML, and mathematical modeling.

[0010] Another objective of this disclosure is the implementation of an adaptive defense system capable of detecting, analyzing, and responding to evolving cyber threats while maintaining continuity of healthcare provision.

[0011] Another objective of this disclosure is to ensure compliance with data protection regulations in the healthcare sector while maintaining the accessibility and usefulness of patient information for authorized healthcare providers.

[0012] To further clarify the advantages and features of the present disclosure, the invention is explained in more detail with reference to specific embodiments illustrated in the accompanying drawings. These drawings merely show typical embodiments of the invention and are therefore not to be regarded as limiting its scope. The invention is described and explained in more detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE FIGURES

[0013] These and other features, aspects, and advantages of the present disclosure will be better understood if the following detailed description is read with reference to the accompanying drawings, in which identical symbols consistently represent identical parts. The following applies: Fig. Figure 1 shows a block diagram of a system for securing patient data in IoT-enabled hospitals according to an embodiment of the present disclosure; Fig. Figure 2 shows a diagram illustrating the implementation of cybersecurity in the healthcare system according to one embodiment of the present disclosure. Fig. Figure 3 shows a block diagram illustrating the flow of malicious information in an IoT-enabled hospital system and a secured data block according to an embodiment of the present disclosure; and Fig. Figure 4 shows a schematic diagram illustrating the transmission flow of cyberattacks in the hospital data set according to one embodiment of the present disclosure.

[0014] Experts will also recognize that the elements in the drawings are presented for the sake of simplicity and are not necessarily to scale. For example, the flowcharts illustrate the process by highlighting the main steps to enhance understanding of the aspects of this disclosure. Furthermore, with regard to the construction of the device, one or more components of the device may be represented in the drawings by conventional symbols. The drawings may show only those specific details relevant to understanding the embodiments of this disclosure, so as not to clutter the drawings with details that are readily apparent to those skilled in the art from the present description. DETAILED DESCRIPTION:

[0015] To facilitate understanding of the inventive principles, reference will now be made to the embodiment illustrated in the drawings, and this will be described in detail. However, this does not limit the scope of the invention. Changes and further modifications to the illustrated system, as well as further applications of the inventive principles, are possible, as would normally occur to a person skilled in the art in this field.

[0016] It is clear to the person skilled in the art that the preceding general description and the following detailed description are exemplary and explanatory of the invention and are not intended to limit it.

[0017] References in this specification to “an aspect”, “another aspect”, or similar phrases mean that a particular feature, structure, or property described in connection with the embodiment is included in at least one embodiment of the present disclosure. Therefore, the phrases “in one embodiment”, “in another embodiment”, and similar phrases in this specification may, but need not, refer to the same embodiment.

[0018] The terms "includes," "comprehensive," or variations thereof cover non-exclusive inclusion. A process or method that includes a list of steps does not only include those steps but may also include further steps not explicitly listed or inherent in the process or method. Likewise, the statement "includes... a" for one or more devices, subsystems, elements, structures, or components does not, without further qualification, exclude the existence of other devices, subsystems, elements, structures, or components, or additional devices, subsystems, elements, structures, or components.

[0019] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as understood by a person skilled in the art in the field of the invention. The systems, methods, and examples provided herein serve only for illustration and are not to be understood as limiting.

[0020] Embodiments of the present disclosure are described in detail below with reference to the accompanying drawings.

[0021] The functional units described in this specification are referred to as devices. A device may be implemented in programmable hardware such as processors, digital signal processors, central processing units, field-programmable gate arrays, programmable array logic systems, programmable logic devices, cloud processing systems, or the like. Devices may also be implemented in software for execution by various processor types. An identified device may contain executable code and consist, for example, of one or more physical or logical blocks of computer instructions, which may be organized, for example, as an object, procedure, function, or other construct.However, the executable file of an identified device does not need to be physically stored in the same location, but can consist of different commands stored in different locations which, logically linked, form the device and fulfill its purpose.

[0022] The executable code of a device or module can consist of one or more instructions and may even be distributed across multiple code segments, different applications, and multiple storage devices. Similarly, operational data within the device can be identified and represented in any form and data structure. This operational data can be captured as a single data record or distributed across various storage devices and may exist, at least partially, as electronic signals within a system or network.

[0023] References in this description to “a selected embodiment”, “an embodiment”, or “an embodiment” mean that a particular feature, structure, or property described in connection with the embodiment is included in at least one embodiment of the disclosed subject matter. Therefore, the expressions “a selected embodiment”, “in an embodiment”, or “in an embodiment” appearing at different points in this description do not necessarily refer to the same embodiment.

[0024] Furthermore, the described features, structures, or properties can be combined in any way in one or more embodiments. The following description contains numerous specific details to enable a comprehensive understanding of the embodiments of the disclosed subject matter. However, those skilled in the art will recognize that the disclosed subject matter can also be implemented without one or more of the specific details or with other methods, components, materials, etc. In other cases, known structures, materials, or processes are not presented or described in detail so as not to obscure aspects of the disclosed subject matter.

[0025] According to the exemplary embodiments, the disclosed computer programs or modules can be executed in a variety of ways, for example, as an application in the memory of a device or as a hosted application on a server, communicating with the device application or browser via various standard protocols such as TCP / IP, HTTP, XML, SOAP, REST, JSON, and other suitable protocols. The disclosed computer programs can be written in exemplary programming languages ​​that are executed from the device's memory or from a hosted server, such as BASIC, COBOL, C, C++, Java, Pascal, or scripting languages ​​such as JavaScript, Python, Ruby, PHP, Perl, or other suitable programming languages.

[0026] Some of the disclosed embodiments involve or otherwise involve data transmission over a network, for example, the transmission of various inputs or files over the network. The network may include, for example, the Internet, wide area networks (WANs), local area networks (LANs), analog or digital wired and wireless telephone networks (e.g., PSTN, Integrated Services Digital Network (ISDN), mobile networks, and Digital Subscriber Line (xDSL)), radio, television, cable, satellite, and / or other transmission or tunneling mechanisms for data transmission. The network may comprise multiple networks or subnetworks, each containing, for example, a wired or wireless data path. The network may include a circuit-switched voice network, a packet-switched data network, or another network for transmitting electronic communications.For example, the network can include networks based on the Internet Protocol (IP) or the Asynchronous Transmission Mode (ATM) and supporting voice communication via VoIP, Voice over ATM, or other comparable protocols. In one implementation, the network includes a cellular network configured for exchanging text or SMS messages.

[0027] Examples of networks include a Personal Area Network (PAN), a Storage Area Network (SAN), a Home Area Network (HAN), a Campus Area Network (CAN), a Local Area Network (LAN), a Wide Area Network (WAN), a Metropolitan Area Network (MAN), a Virtual Private Network (VPN), an Enterprise Private Network (EPN), the Internet, a Global Area Network (GAN), etc.

[0028] Fig. Figure 1 shows a block diagram of a system (100) for securing patient data in IoT-enabled hospitals according to an embodiment of the present disclosure.

[0029] According to Fig. 1 The system (100) comprises: a network of IoT-enabled medical devices (102) configured to collect and transmit patient data; a blockchain network (104) associated with the medical devices (102) configured to create an immutable ledger for patient data transactions, implement smart contracts for access control, and maintain a decentralized log of data access attempts; an artificial intelligence and machine learning (AIML) module (106) configured to monitor blockchain activity for anomalous patterns, implement attack detection using machine learning algorithms, perform predictive analytics for threat detection, and execute natural language processing to identify personal data;a secure data block storage (108) configured to implement PII data masking for sensitive patient data, to provide masked data benefits to authorized users, and to store encrypted patient records; a malware detection module (110) configured to detect unauthorized data manipulation attempts, to identify exponential data propagation patterns, to monitor system vulnerabilities, and to track malware transmission behavior; and a defense framework (112) configured to: implement compartmental epidemic modeling for attack analysis, calculate reproduction numbers for malware propagation, adapt security measures to threat levels, and maintain version control of security updates.

[0030] In one embodiment, the AIML module (106) includes an isolation forest module (106a) configured to: detect anomalies in access patterns, identify suspicious activities, and dynamically adjust data visibility based on user permissions.

[0031] In one embodiment, the defense framework (112) also includes a quarantine module (112a) configured to isolate infected system components, implement asymptotic stability measures, and perform recovery procedures based on reproduction number calculations.

[0032] In one embodiment, the blockchain network (104) also includes a distributed ledger (104a) configured to: maintain transparent audit trails; record all data access attempts; implement consensus mechanisms for data validation; and manage cryptographic keys for authorized access.

[0033] In one embodiment, the secure data block storage (108) is connected to the distributed ledger (104a) and also includes a version control system (108a) configured to: maintain logs of data changes, track the implementation of security updates, and provide rollback capabilities for compromised data.

[0034] In one embodiment, the malware detection module (110) also includes a compartmental analysis system (110a) configured for: classifying threats into manipulation and propagation categories, monitoring infection endemic equilibrium points, and analyzing the local stability of security measures.

[0035] In one embodiment, the system (100) also includes a recovery module (114) configured for: implementing attack detection systems; executing anomaly detection protocols; restoring compromised data from secure backups; and implementing security enhancements after an attack.

[0036] In one embodiment, the defense framework (112) also includes an inoculation module (112b) configured to: implement preventive security measures, update antivirus signatures, provide security patches, and maintain firewall configurations.

[0037] In one embodiment, the AIML module (106) also includes a natural language processing engine (106b) configured to: analyze unstructured medical texts, identify confidential information, apply appropriate masking levels, and maintain data usability for authorized users.

[0038] In one embodiment, the system (100) also includes a monitoring dashboard (118) configured to: display the security status in real time, track reproduction numbers, visualize attack patterns, and generate security audit reports.

[0039] In one embodiment, the blockchain network (104), the AIML module (106), the secure data block storage (108), the malware detection module (110), the defense framework (112), the recovery module (114) and the monitoring dashboard (118) can be implemented in programmable hardware devices such as processors, digital signal processors, central processing units, field-programmable gate arrays, programmable array logic, programmable logic devices, cloud processing systems or the like.

[0040] The present invention relates to a security system for protecting patient data in IoT-enabled hospitals. At the heart of the system is a blockchain network that creates an immutable register of all patient data transactions and implements smart contracts for access control. This blockchain infrastructure is augmented by an artificial intelligence and machine learning (AIML) module that continuously monitors blockchain activity for anomalous patterns and implements sophisticated attack detection using machine learning algorithms. The system's secure data block storage implements the masking of sensitive patient information while maintaining data access for authorized users. A specialized malware detection module monitors the network for unauthorized data manipulation attempts and identifies exponential data propagation patterns.It works in conjunction with a defense framework that implements compartmentalized epidemic models for attack analysis. This framework calculates reproduction numbers for malware propagation and adapts security measures to the threat landscape. It includes a quarantine module for isolating infected system components and implementing asymptotic stabilization measures. The system manages version control of security updates and features a recovery module with attack detection systems and anomaly detection protocols. A natural language processing engine analyzes unstructured medical texts to identify sensitive information and apply appropriate masking levels. The system's monitoring dashboard provides real-time security status updates, tracks reproduction numbers, and visualizes attack patterns for administrative oversight.This comprehensive approach ensures both proactive threat prevention and reactive incident response, while also guaranteeing access to critical health data for authorized personnel.

[0041] The present invention aims to analyze the attack behavior of malware in IoT-enabled hospitals using a compartmental epidemic model and to develop a robust defense concept based on the dynamics of ransomware to mitigate such threats. By deriving the reproduction number and determining its asymptotic stability under various conditions, the invention provides a sound analytical basis for understanding malware propagation. Using extensive numerical simulations, including illustrative examples and time series analyses, the invention investigates the effects of defense strategies under different reproduction number scenarios—both below and above 1.The simulation results demonstrate that the transparency and immutability of blockchain, combined with AI-based security solutions such as anomaly and attack detection, offer excellent protection against data breaches. Furthermore, the present invention provides data masking of personally identifiable information (PII) as an effective data protection measure that preserves the value of the data while simultaneously protecting the confidentiality of patient data. With this holistic security approach, healthcare organizations can not only ensure compliance with legal regulations but also guarantee the highest standard of patient data protection.

[0042] The aim of the present invention is to understand the transmission behavior of ransomware in IoT-enabled hospitals by cybercriminals who breach the defense system and steal patient information, and to develop a defense system to minimize cyberattacks.

[0043] Fig. Figure 2 shows a diagram illustrating the implementation of cybersecurity in the healthcare system according to one embodiment of the present disclosure.

[0044] The present invention utilizes medical blockchain technology to improve the cybersecurity of healthcare systems. This technology can address numerous security and privacy issues faced by healthcare organizations, including data breaches, unauthorized access, and data integrity concerns.

[0045] Blockchain can contribute to improving cybersecurity in healthcare in a variety of ways. Fig. Figure 2 shows the implementation of cybersecurity in healthcare. The approach used is divided into three areas, each utilizing blockchain technology.

[0046] Protecting medical data is essential not only for safeguarding individual privacy but also for complying with strict legal frameworks. A breach of healthcare systems can have serious consequences, including identity theft, financial fraud, and compromised patient well-being. The challenge lies in protecting sensitive medical data while simultaneously granting healthcare professionals and researchers access to critical information when needed. Integrating artificial intelligence (AI), machine learning (ML), and blockchain technology provides a robust architecture that addresses these security concerns and fundamentally transforms patient data protection.

[0047] The integration of AI and ML further enhances blockchain security by continuously analyzing access patterns, detecting anomalies, and dynamically managing data visibility based on predefined user permissions. AI algorithms can identify unauthorized access attempts as anomalies in real time, triggering immediate countermeasures to prevent security breaches. The convergence of AI and ML with blockchain technology strengthens the security of patient data through various advanced mechanisms. AI-driven anomaly detection continuously evaluates blockchain activity for deviations from expected behavior. Unauthorized attempts to access multiple patient records within a short period are immediately reported, enabling rapid intervention.Machine learning-based intrusion detection systems (IDS) enable real-time detection of unauthorized changes to patient data, allowing for immediate countermeasures against potential cyber threats. Predictive analytics uses historical data to forecast emerging security risks, enabling proactive safeguards. Natural language processing (NLP) is employed to analyze unstructured medical texts and identify and classify personally identifiable information (PII) in patient records, thereby improving regulatory compliance and security.

[0048] Personally identifiable information (PII) masking is a significant security enhancement for protecting patient records. It renders sensitive data such as names, addresses, and social security numbers unreadable to unauthorized individuals while simultaneously ensuring the operational integrity of the data. When stored on the blockchain, patient identities are obfuscated, allowing only authorized personnel with the appropriate cryptographic keys to access the necessary information. This guarantees enhanced data protection, data minimization, immutable audit trails, and the preservation of data integrity in healthcare.

[0049] Fig. Figure 3 shows a block diagram illustrating the flow of malicious information in an IoT-enabled hospital system and a secured data block according to an embodiment of the present disclosure.

[0050] The vulnerability of IoT-enabled hospital networks to malicious cyberattacks is a significant problem. The traditional system (S1) consists of an internet-connected network where sensitive medical data, including personal and clinical details, is stored. However, this framework lacks comprehensive security measures and is therefore exposed to sophisticated cyberattacks.

[0051] Fig. Figure 3 illustrates the transmission of malicious information and the implementation of AIML and blockchain technology to secure data blocks in an IoT-enabled hospital environment managing patient records. The proposed system introduces a structured, multi-component framework that defines existing vulnerabilities and incorporates advanced security enhancements to protect sensitive medical data.

[0052] The baseline scenario reflects the current state of many hospital networks, characterized by several distinct areas. Area S1 represents a conventional, internet-connected infrastructure where sensitive patient data, both personal and medical, is stored. However, this system is vulnerable due to its reliance on basic security mechanisms and lacks the necessary robustness to effectively counter cyber threats. The absence of advanced security protocols exposes patient records to potential cyberattacks.

[0053] To enhance security, the S2 compartment was introduced as a reinforced alternative, offering extensive improvements to software and hardware components. This enhanced configuration includes the latest patch updates, an advanced firewall, and a sophisticated antivirus application. Together, these elements form a strengthened layer of defense, significantly increasing the system's resilience against external threats and unauthorized access.

[0054] Despite these security enhancements, the system remains a target for cybercriminals. The I-area represents an external malicious entity attempting to penetrate the secured infrastructure. This intrusion attempt targeting System 2 results in unauthorized access and subsequent compromise of sensitive patient records, thereby endangering confidential data. The attack strategy can be divided into two main threats. Q1-area encompasses data manipulation, where the attacker manipulates critical patient records, thus compromising data integrity and patient safety. Q2-area involves the exponential spread of compromised data, with multiple unauthorized copies being distributed in public domains, significantly increasing the severity of the breach and undermining patient confidentiality.

[0055] The attacker's tactics may include the simultaneous execution of Q1 and Q2. This involves not only modifying manipulated data but also disseminating it widely, thus amplifying the impact of the security breach. To counter these threats, an intelligent and adaptive security framework is required, integrated within the R domain and utilizing AIML-driven mechanisms for proactive threat mitigation.

[0056] The countermeasure against Q1 involves the use of an anomaly detection system that continuously monitors data integrity and system behavior. This intelligent mechanism detects deviations from predefined patterns, immediately identifies unauthorized changes, and initiates corrective actions to maintain data authenticity. To combat Q2, an intrusion detection system (IDS) is integrated that monitors network activity in real time to identify abnormal access attempts. Upon detecting suspicious behavior, the IDS isolates the affected segment. This effectively prevents further data dissemination and protects confidential information.

[0057] Blockchain technology significantly improves data security. The Secure Data Block system is embedded in the hospital's digital infrastructure and provides an immutable and decentralized framework for protecting patient records. This architecture ensures that all access attempts are transparently recorded and traceable, thus preventing unauthorized modifications. The integration of NLP and OCR (Optical Character Recognition) techniques facilitates the masking of personally identifiable information (PII), thereby maintaining medical accuracy and protecting sensitive data from unauthorized disclosure.

[0058] The hospital's cybersecurity framework is enhanced by improving existing antivirus measures and patch updates, thus establishing a comprehensive security paradigm. By implementing this advanced security model, the hospital's digital ecosystem achieves an unprecedented level of resilience and ensures that medical data remains protected from manipulation and disclosure. This transformation strengthens trust in the healthcare system and ensures that sensitive patient data remains accessible only to authorized personnel. At the same time, it sets a new standard for security and integrity in IoT-enabled healthcare facilities.

[0059] Fig. Figure 4 shows a schematic diagram illustrating the transmission flow of cyberattacks in the hospital data set according to one embodiment of the present disclosure.

[0060] In an IoT-enabled hospital network, cybercriminals target interconnected computers, known as nodes, to gain access to sensitive patient data using malware. Among the various forms of malware, information-stealing malware poses a significant threat because it intercepts and exfiltrates login credentials, thus enabling unauthorized access to healthcare systems.

[0061] The proposed system uses a mathematical model in which all nodes in the hospital's computer network are initially considered vulnerable to cyberattacks and assigned a vulnerability rating of S1. To minimize threats, the nodes are equipped with antivirus software and assigned to S2. However, infections can still spread within S2 if malware bypasses protection due to outdated or infrequently updated antivirus software. The infection spreads between these nodes at a rate of β, causing a portion of S2 to transition into an infectious state represented by Class I.

[0062] Nodes within zone I that exhibit mild attack symptoms—such as restricted access to files, applications, or services, unexplained network slowdowns, or the appearance of unauthorized files and pop-ups—are isolated from the network and assigned to class Q1 at a recovery rate of α. These quarantined nodes receive antivirus updates, allowing them to recover and move to class R at a recovery rate of η. However, if recovery to Q1 is not achieved, additional measures are required to move them to class Q2 at a recovery rate of δ.

[0063] A subset of Class I nodes exhibiting severe infections—such as remote control hijacking, system lockouts with ransom demands, unauthorized email transmissions, or unexpected security breaches—are directly reclassified into Class Q2 at a rate of γ. Class Q2 nodes undergo comprehensive remediation until full recovery is achieved. This allows them to transition to Class R at a recovery rate of ϕ.

[0064] In cyberspace, immunity to malware is not absolute. Recovered nodes remain vulnerable to future cyberattacks and fall back into the category of vulnerable nodes with a recurrence rate of ε. Furthermore, system failures due to hardware errors can occur with a rate of d1, while severe malware attacks can lead to complete system crashes with a rate of d2.

[0065] Based on our assumptions and the transmission flow of cyberattacks in the hospital dataset, as described in Fig. As shown in section 4, a mathematical model is developed.

[0066] The proposed system implements an algorithm based on AIML blockchain security to integrate AI-based anomaly detection using Isolation Forest. This allows for monitoring access patterns, identifying suspicious activity, and dynamically adjusting data visibility based on user permissions and contextual authorization.

[0067] Numerous simulation-based experiments were conducted to verify the proposed system. The results demonstrated that the immutability and transparency of the blockchain, combined with AI-supported security measures such as anomaly and intrusion detection, offer robust protection against data leaks. The findings of this invention show that masking personally identifiable information (PII) enhances data privacy while ensuring data usability. This guarantees that patient information remains confidential and secure throughout its entire lifecycle. With this comprehensive approach, healthcare organizations not only comply with legal regulations but also ensure the highest level of data protection for patient information.

[0068] This invention is based on a novel epidemic-based system for analyzing quarantine measures related to ransomware transmission in IoT-enabled hospitals. The model's reproduction number serves as a key metric for assessing the extent of infection spread and determining asymptotic stability under various conditions. This framework enables a comprehensive evaluation of potential patient data breaches and specifically examines the risks of unauthorized data manipulation. The attacker's goal is to manipulate critical information, which includes unauthorized changes and modifications that compromise patient safety. Furthermore, unauthorized access leads to the distribution of multiple copies of the manipulated data via public platforms, exacerbating security vulnerabilities.To minimize these threats, an integrated defense mechanism is implemented, including regular updates for software and hardware components to ensure they comply with the latest security patches. The architecture is further enhanced by an advanced firewall and antivirus system, significantly increasing its resilience against potential cyber threats. A version control system (VCS), such as a Global Information Tracker (GIT), provides a structured and auditable record of updates, thus enabling an organized security approach. Within recovery class R, a risk mitigation strategy is developed that utilizes advanced artificial intelligence (AI) and machine learning (ML) techniques. The implementation of intrusion detection systems (IDS) and anomaly detection mechanisms strengthens threat detection and response capabilities.Additionally, the integration of a Secure Data Block system, based on blockchain technology, creates a protected environment for recovered patient data. This innovation minimizes future attack risks by masking personally identifiable information (PII), improving data privacy while maintaining data usability. The lifecycle of sensitive information remains protected, ensuring confidentiality and integrity within the healthcare network. A numerical simulation analyzes infection endemic equilibrium points both with and without security measures such as vaccinations. Time series analysis and simulation observe fluctuations in the number of infectious nodes. However, the phased vaccination of vulnerable units, combined with updated antivirus measures, firewalls, and the secure data block system, results in a controlled security landscape.It is crucial that no repetition of similar attacks is detected. This comparison illustrates that even in scenarios where the reproduction number is initially above one, an otherwise successful attack is rendered ineffective by the systematic inoculation of vulnerable nodes. The implemented defense infrastructure represents a transformative advancement, positioning the S2 compartment as a next-generation security system that effectively protects patient data. The hospital's digital infrastructure is evolving into a protected data privacy space, setting an unprecedented security standard in IoT-enabled healthcare ecosystems. This implementation ensures that patient records remain accessible only to authorized personnel while guaranteeing the highest level of data security and integrity.The implementation of this comprehensive security architecture enables healthcare organizations to exceed regulatory requirements while ensuring unprecedented data protection for patient information. Future advancements will focus on implementing compartmentalized models using fractional inferences to enable deeper analysis of historical cyberattacks and predict potential threats. These insights will contribute to the continuous development of a highly resilient cybersecurity framework.

[0069] The drawings and the preceding description show examples of embodiments. Those skilled in the art will recognize that one or more of the described elements can be combined to form a single functional element. Alternatively, certain elements can be divided into several functional elements. Elements of one embodiment can be added to another embodiment. For example, the sequence of the processes described here can be changed and is not limited to the manner described herein. Furthermore, the actions of a flowchart need not be performed in the sequence shown; nor does it necessarily have to be performed all actions. Actions that are not dependent on other actions can also be performed in parallel with the other actions. The scope of the embodiments is in no way limited by these specific examples.Numerous variations are possible, whether explicitly stated in the specification or not, such as differences in structure, dimensions, and material usage. The range of embodiments is at least as broad as specified in the following claims.

[0070] Advantages, further benefits, and problem solutions have been described above with reference to specific embodiments. However, the advantages, benefits, problem solutions, and all components that can lead to or enhance an advantage, benefit, or solution are not to be understood as critical, necessary, or essential features or components of any or all claims. REFERENCES 100 A system for securing patient data in IoT-enabled hospitals. 102 Network of IoT-Enabled Medical Devices 104 Blockchain Network 104a Distributed ledger 106 AIML module 106a Isolation Forest Module 106b Natural Language Processing Engine 108 Secure Data Block Storage 108a Version control system 110 Malware Detection Module 110a compartment analysis system 112 Defense Framework 112a Quarantine module 112b Vaccination module 114 Recovery Module 118 Monitoring Dashboard 202 Blockchain 204 Security of Patient Data 206 Traceability of Medicines and Supply Chain Security 208 Identity Management and Access Control 302 Updates and Firewall 304 Compromised Data 306 Malicious attack 308 Unauthorized Access 310 Data Manipulation 312 Assembly Detection 314 1st Quarter 316 Public access 318 Spread 320 Intrusion Detection System 322 encryption 324 Secured Data Block 326 Robust System 314 Public access 316 Spread 318 Intrusion Detection System 320 encryption 322 Secured Data Block 324 Robust System

Claims

[1] A system for securing patient data in IoT-enabled hospitals, consisting of: a network of IoT-enabled medical devices configured to collect and transmit patient data; a blockchain network associated with said medical devices, configured to create an immutable ledger of patient data transactions, implement smart contracts for access control, and maintain a decentralized log of data access attempts; an Artificial Intelligence and Machine Learning (AIML) module configured to: monitor blockchain activity for anomalous patterns, implement intrusion detection using machine learning algorithms, perform predictive analytics for threat detection, and perform natural language processing to identify personal data; a secure data block storage configured to: implement PII data masking for confidential patient information, maintain masked data utility for authorized users, and store encrypted patient records; a malware detection module configured to detect unauthorized attempts to manipulate data, identify exponential data distribution patterns, monitor system vulnerabilities, and track malware transmission behavior; and a defense framework configured to: implement compartmental epidemic modeling for attack analysis, calculate reproduction numbers for malware distribution, adapt security measures based on threat levels, and maintain version control of security updates. [2] The system of claim 1, wherein the AIML module comprises an isolation forest module configured to: detect anomalies in access patterns, identify suspicious activities, and dynamically adjust data visibility based on user permissions. [3] The system of claim 1, wherein the defense framework further comprises a quarantine module configured to isolate infected system components, implement asymptotic stability measures, and perform recovery procedures based on reproduction number calculations. [4] The system of claim 1, wherein the blockchain network further comprises a distributed ledger configured to: maintain transparent audit trails; record all data access attempts; implement consensus mechanisms for data validation; and manage cryptographic keys for authorized access. [5] The system of claim 1, wherein the secure data block storage associated with the distributed ledger further comprises a version control system configured to: maintain logs of data changes, track implementations of security updates, and provide rollback capabilities for compromised data. [6] The system of claim 1, wherein the malware detection module further comprises a compartmental analysis system configured to classify threats into tampering and distribution categories, monitor infection endemic balance points, and analyze the local stability of security measures. [7] The system of claim 1, further comprising a recovery module configured to: implement intrusion detection systems; execute anomaly detection protocols; restore compromised data from secure backups; and implement security enhancements following an attack. [8] The system of claim 1, wherein the defense framework further comprises an inoculation module configured to: implement preventative security measures; update anti-virus signatures; deploy security patches; and maintain firewall configurations. [9] The system of claim 1, wherein the AIML module further comprises a natural language processing engine configured to: analyze unstructured medical text, identify confidential information, apply appropriate masking levels, and maintain data usability for authorized users. [10] The system of claim 1, further comprising a monitoring dashboard configured to display real-time security status, track replication numbers, visualize attack patterns, and generate security audit reports.