Security threat modelling for IoT-enabled smart healthcare
Jasmina Baraković Husić, Sabina BarakovićThe Internet of Things (IoT)-enabled smart healthcare systems improve quality of life (QoL) but face more threats leading to an increase in abuse of the system. A key security technique is four-step threat modelling during system design, based on the four-layer IoT reference model. The objective of this article is to provide a review of studies published in the period 2014–2025 utilizing Google Scholar, IEEE Xplore and Web of Science. The search was conducted using the following keyword combinations: (threat modelling OR threat analysis) AND (Internet of Things) AND (smart healthcare). The review is based on 19 studies dealing with practical threat modelling or analysis of smart IoT healthcare systems. The reviewed studies reveal that threat modelling is rarely subjected to systematic validation, leaving it largely theoretical rather than practical. This recurring pattern highlights a methodological limitation that reduces the applicability and impact of current research. Moreover, they show that current research seldom addresses higher-level, context-rich layers where privacy, safety and QoL impacts are most significant. This consistent focus on lower layers suggests a systemic limitation, as threats propagate across multiple levels. Lack of automation, reliance on new technologies and no standardized methodology may explain why many studies fail to cover all security layers and threat modelling steps. To tackle IoT-enabled smart healthcare security issues, four solutions are proposed: (i) embedding thorough threat modelling into healthcare policies, (ii) performing comprehensive four-step threat modelling for IoT healthcare systems, (iii) developing a standardized approach and (iv) fostering automated, industry-specific threat modelling frameworks.