Abstract
The Internet of Things (IoT)-enabled smart healthcare systems improve quality of life (QoL) but face more threats leading to an increase in abuse of the system. A key security technique is four-step threat modelling during system design, based on the four-layer IoT reference model. The objective of this article is to provide a review of studies published in the period 2014–2025 utilizing Google Scholar, IEEE Xplore and Web of Science. The search was conducted using the following keyword combinations: (threat modelling OR threat analysis) AND (Internet of Things) AND (smart healthcare). The review is based on 19 studies dealing with practical threat modelling or analysis of smart IoT healthcare systems. The reviewed studies reveal that threat modelling is rarely subjected to systematic validation, leaving it largely theoretical rather than practical. This recurring pattern highlights a methodological limitation that reduces the applicability and impact of current research. Moreover, they show that current research seldom addresses higher-level, context-rich layers where privacy, safety and QoL impacts are most significant. This consistent focus on lower layers suggests a systemic limitation, as threats propagate across multiple levels. Lack of automation, reliance on new technologies and no standardized methodology may explain why many studies fail to cover all security layers and threat modelling steps. To tackle IoT-enabled smart healthcare security issues, four solutions are proposed: (i) embedding thorough threat modelling into healthcare policies, (ii) performing comprehensive four-step threat modelling for IoT healthcare systems, (iii) developing a standardized approach and (iv) fostering automated, industry-specific threat modelling frameworks.
Introduction
Internet of Things (IoT) is an interconnected set of electronic devices, mechanical and digital machines, objects, animals or people that have unique identifiers and allow data to be transmitted over a network without requiring human interaction or intervention. With the advent of IoT, multiple devices, from home appliances to industrial machinery, are connected to communication networks and can be controlled remotely without the need for human presence or intervention (Echeverría et al., 2021).
IoT is becoming integrated in many everyday life areas such as smart cities, waste management, traffic congestion, logistics, medicine and healthcare, emergency services, security, industrial control and so on, thereby vastly influencing our quality of life (QoL) through reducing costs, better resource management, improving quality of experience and many other ways (Islam et al., 2015). It is fundamentally transforming urban environments by enabling the development of smart cities, which leverage interconnected devices to enhance urban living. However, medical and health care are one of the most attractive application areas for urban IoT due to many reasons. For example, one of them is an ageing population worldwide, which causes serious resource deficits in terms of taking care of the elderly and can be partially eased with IoT technology in smart cities. Therefore, IoT in city healthcare has received wide attention from the research community in the last few years, resulting in various applications, services, platforms, sensors, networks and so on (Baker et al., 2017). In the smart city, healthcare requires the integration of IoT with various technologies (e.g. artificial intelligence (AI), machine learning (ML), blockchain, cloud computing, etc.). However, it also introduces several challenges where security and privacy issues call for special attention (Bastos et al., 2024).
The health sector experiences a significant number of security incidents, with a 53% share in the total incidents (Aljaz et al., 2023). Ransomware emerged as one of the primary threats in the health sector (54% of incidents), and it is likely to continue since healthcare organizations do not invest in security or defense programmes. Additionally, attackers extort both health organizations and patients, threatening to disclose data, personal or sensitive in nature in order to gain financial benefits. Alarmingly, nearly half of all incidents (46%) aimed to steal or leak health organizations’ data. Also, the incidents have significant consequences for healthcare organizations, including data breaches, disruptions to healthcare services, and disruptions to non-healthcare services. Regardless of organization, patients are at risk since the disruption of the services can cause delays in triage and treatment, or wrong diagnoses and consequently faulty treatments (European Union Agency for Cybersecurity, 2023).
Therefore, in today's very challenging cybersecurity environment, the security of IoT-enabled systems in the healthcare sector, important for urban living, is the most important issue for patients’ safety and privacy, effective treatment and their data (Karunarathne et al., 2021). This is due to very serious problems in the architecture of the IoT which require the implementation of the ‘security and privacy by design’ concept. Security and privacy are crucial for broader adoption of IoT in healthcare because, as already stated, there is a wide range of threats and vulnerabilities that may affect the usage of these systems (Baraković et al., 2020). In order to utilize the full potential of IoT in healthcare, one must ensure that this technology will not negatively influence users and positively influence their QoL. One of the ways to accomplish that is to do threat modelling of those systems.
Threat modelling can be described as the use of abstraction to facilitate the consideration of risks (Tarandach and Coles, 2021). While the term ‘threat modelling’ encompasses various meanings, particularly in the realm of IoT-enabled smart healthcare security, it serves as a technique for identifying threats, attacks, vulnerabilities and corresponding countermeasures. It can encompass two interpretations, either involving the depiction of security threats during the design phase or a collection of potential attacks to concentrate on for a specific system segment (Xiaong and Lagerstrom, 2019). It is a structured approach for identifying threats and countermeasures focused on understanding the architecture and applications. It is an iterative process that is associated with the phases of designing and developing systems.
Threat modelling offers several benefits, such as minimizing the attack surface (Bodeau and Graubart, 2013), prioritizing threats and countermeasures, eradicating vulnerabilities and enhancing the overall security stance of both organizations and applications (Tarandach and Coles, 2021). Its utmost value is realized during the design phase. A meticulously developed threat model not only identifies security requirements but also directs attention towards energy, security features and meaningful functionalities. Moreover, it facilitates discussions that may spark innovative ideas and help in categorizing challenges unique to each system that may remain unresolved through alternative methods.
Considering the abovementioned, this article tends to contribute to the research activities done in the combination of challenging fields of smart environment, healthcare and cybersecurity. The aim is to tackle the issues in the security of IoT smart healthcare by taking a combined fashion two ways, that is, a security framework and threat modelling. This approach is realized through a systematic review of practical studies on threat modelling in IoT-enabled smart healthcare systems. The review is conducted based on the proposed security framework (in terms of layer coverage) and threat modelling (in terms of threat modelling steps, styles, methods and methodologies). Therefore, the objective of this study is to identify limitations in layer coverage, as well as the threat modelling steps, styles, methods and methodologies used in this specific and potent domain in order to get a clear picture of the state-of-the-art research and identify open gaps for future research activities.
Security framework
An effective security framework is crucial for managing threats in today's digital environment. These frameworks bring together various elements that improve the ability to detect, address and recover from cyber threats. Cyberattacks on smart healthcare environments can compromise sensitive information, disrupt critical services and pose threats to lives (Otorkpa et al., 2024). Therefore, it is important to adopt a robust security framework to protect these smart healthcare environments from malicious threats. To enhance the security of smart healthcare environments, several cybersecurity frameworks can be implemented (Taherdoost, 2022).
Within this context, Medical IoT Lightweight Authenticated Encryption with Associated Data Protocol (MedIoT-LAP; Tanveer and Aldossari, 2025), Physically Unclonable Function and Authenticated Encryption Based Authentication Framework for the IoT-Enabled Smart Healthcare System (PAAF-SHS; Aldosary and Tanveer, 2024) and Secure and Efficient Authentication Mechanism for Vehicular Digital Twins (SecTwin; Tanveer et al., 2025) represent three emerging frameworks that address critical aspects of IoT-enabled healthcare security. Together, they illustrate how lightweight cryptography, hardware-rooted trust and digital twin simulations can strengthen threat modelling in medical environments.
MedIoT-LAP is designed to secure resource-constrained medical devices such as wearables and implantables. Its design principle emphasizes Authenticated Encryption with Associated Data, ensuring both confidentiality and integrity while maintaining low computational overhead. A distinctive feature of MedIoT-LAP is its use of physical unclonable functions (PUFs), which generate device-specific cryptographic keys dynamically, eliminating the need for plaintext storage. This hardware-rooted approach directly addresses threat models concerned with insider attacks and key leakage, making MedIoT-LAP particularly relevant for lightweight medical IoT environments (Tanveer and Aldossari, 2025).
Expanding beyond device-level security, PAAF-SHS provides a scalable solution for IoT-enabled healthcare networks. It integrates PUF-based identity binding with authenticated encryption to establish mutual authentication between patients, devices and healthcare servers. By mitigating replay, impersonation and Man-in-the-Middle (MitM) attacks, PAAF-SHS strengthens identity-centric threat models and ensures secure communication across large healthcare infrastructures. Its scalability makes it particularly suitable for smart healthcare systems where multiple devices interact simultaneously, and where authentication failures could compromise sensitive patient data (Aldosary and Tanveer, 2024).
In contrast, SecTwin adopts a proactive defense strategy by leveraging digital twin technology. Each physical IoT device is mirrored by a virtual counterpart that continuously simulates and monitors system behaviour. This enables real-time anomaly detection and predictive modelling of potential attack vectors. Unlike traditional reactive frameworks, SecTwin integrates directly into dynamic threat modelling, allowing healthcare systems to anticipate zero-day exploits and advanced persistent threats before they materialize. While computationally more demanding, SecTwin's emphasis on simulation-based defense provides resilience for complex cyberphysical healthcare ecosystems, where predictive security is increasingly vital (Tanveer et al., 2025).
Collectively, these frameworks highlight the evolving landscape of healthcare IoT security. MedIoT-LAP addresses lightweight device-level vulnerabilities (Tanveer and Aldossari, 2025), PAAF-SHS secures scalable healthcare networks through strong authentication (Aldosary and Tanveer, 2024) and SecTwin advances predictive defense via digital twin simulations (Tanveer et al., 2025). Their complementary design principles demonstrate the importance of tailoring security mechanisms to specific threat models, ranging from constrained devices to systemic, network-wide risks. As healthcare systems continue to digitize, the integration of such frameworks will be essential for safeguarding patient data and ensuring trust in IoT-enabled medical care.
Since IoT is viewed as a key enabler for creating new services and enhancing overall QoL, we adopted the standardized IoT reference model developed by International Telecommunication Union (ITU) as the basis for describing the security framework in the context of IoT-enabled smart healthcare. As shown in Figure 1, this framework consists of four layers (Recommendation ITU-T Y.2060:2012), that is, device, network, service and application, which correspond directly to the ITU reference architecture.

Security framework architecture. Note: 5G: The Fifth Generation; 6G: The Sixth Generation.
The device layer includes sensors/wearables and gateways. Sensors/wearables continuously collect essential patient information to facilitate real-time observation and monitoring, whereas gateways collect data from sensors and enable communication with cloud platforms. The network layer is used for transmission of data collected from the device layer to the service layer via next-generation communication technologies, such as fog computing, Software-Defined Networking, Network Function Virtualization and so on. At the service layer, there are cloud platforms providing storage, data processing and data analytics features, enabling remote patient monitoring or sharing of information among healthcare providers. Advanced analytics tools analyse the collected data to generate insights, aid in clinical decision-making and enhance patient outcomes. The application layer provides the interface for users, such as healthcare providers and patients, to interact with the smart healthcare system. It includes applications for remote patient monitoring, telemedicine, health management and so on.
This security framework is not intended to represent a novel architectural contribution but to serve as a conceptual scaffold that facilitates a systematic description of the threat modelling process. By aligning security considerations with the established IoT layers, this security framework ensures coherence and consistency in analysing vulnerabilities and threats across different components of IoT systems. Thus, the contribution lies not in proposing a new architecture but in applying the ITU reference model to structure and guide the threat modelling process for smart healthcare applications.
As healthcare systems embrace these smart technologies, they attract cyber criminals, resulting in considerable vulnerabilities. Major threats include ransomware, phishing, multiple forms of IoT device attacks and MitM attacks, all of which can jeopardize patient data and disrupt healthcare services (Alabdulatif and Thilakarathne, 2024; Ali and Mijwil, 2024; Otorkpa et al., 2024). Therefore, security should be integrated into IoT-enabled smart healthcare right from the design phase and implemented across all layers: device, network, service and application. That is the main assumption of threat modelling as a technique for improving security. It is crucial to understand what needs to be secured to develop advanced security measures to protect the IoT-enabled smart healthcare infrastructure. It includes all data in the healthcare system, communication links, component hardware and software (Nava et al., 2018).
Securing smart healthcare involves a combination of advanced technologies (e.g. blockchain (Jain et al., 2024); AI (Alexander, 2024); ML (Akinyemi et al., 2024), etc.) to ensure confidentiality, integrity and availability. However, these advanced technologies encounter several issues, such as energy consumption of ML (Kareem and Quazi, 2024), vulnerabilities within ML systems (Mozaffari-Kermani et al., 2015), optimizing performance metrics (Sanka et al., 2021), developing consensus algorithms (Hasselgren et al., 2020) and dealing with post-quantum technologies (Sanka et al., 2021). These issues should be considered when developing new security smart healthcare systems.
Threat modelling can be considered as one approach to address cybersecurity issues in smart healthcare. By understanding threat modelling, that is, approaches, methodologies and processes, we can work towards creating more secure healthcare systems that are based on IoT.
Threat modelling can be approached in an unstructured and structured manner. The unstructured approach is characterized by brainstorming, while the structured approach is characterized by four types of methods (Shostack, 2014; Wynn et al., 2011): (i) attacker-centric, (ii) software-centric, (iii) asset-centric and (iv) defense-centric methods.
Furthermore, there are numerous threat modelling methodologies used to create conceptual versions of systems, profiles of potential attackers and lists of threats (Dervišević et al., 2020; Kulović et al., 2020). Part of these methodologies is focused on risk or privacy management, while others are focused on abstraction or individuals involved in the implementation or resolution of threats (Shevchenko et al., 2018). The most important threat modelling methodologies can be summarized as follows: (i) Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege (STRIDE; Hajrić et al., 2020; Shevchenko et al., 2018) (ii) Common Vulnerability Scoring System (Forum of Incident Response and Security Teams, 2023; Hajrić et al., 2020; Shevchenko et al., 2018) (iii) Process for Attack Simulation and Threat Analysis (Open Web Application Security Project, 2005; Shevchenko et al., 2018; ThreatModeler, 2019; Uceda Velez and Morana, 2015) (iv) attack trees (Shevchenko et al., 2018; Shostack, 2014), (v) Operationally Critical Threat, Asset and Vulnerability Evaluation (Caralli et al., 2007; Shevchenko et al., 2018), (vi) Linkability, Identifiability, Non-repudiation, Detectability, Disclosure of Information, Unawareness, Non-compliance (DistriNet Research Group, 2025; Shevchenko et al., 2018) (vii) Visual, Agile, and Simple Threat Modelling (Shevchenko et al., 2018; ThreatModeler, 2019), (viii) Trike (Shevchenko et al., 2018; ThreatModeler, 2019; Trike Contributors), (ix) Persona non-Grata (Cleland-Huang, 2014; Mead et al., 2018), (x) Security cards (Denning et al., 2013; Mead et al., 2018; Shevchenko et al., 2018), (xi) Quantitative Threat Modelling Method (Potteiger et al., 2016; Shevchenko et al., 2018) and (xii) hybrid Threat Modeling Method (Mead et al., 2018).
Threat modelling is an iterative process initiated in the early stages of system development and lasts throughout the system's lifecycle (Popaja et al., 2021). This approach is adopted for two primary reasons. Firstly, attempting to identify all potential threats in a single iteration is impractical. Secondly, the threat modelling process must be revisited during system development due to its dynamic nature (Shostack, 2014). The process of threat modelling comprises four steps that are described as follows.
Understanding the system is the first step (Step 1) of the threat modelling process, which involves identifying security objectives and system resources, documenting the system architecture and decomposing the system (OWASP Foundation, 2025; Perez, 2019). Identification of threats is the second step (Step 2) of the threat modelling process, which includes identifying and categorizing threats and vulnerabilities (MITRE Corporation, 2023; Shostack, 2014). Consideration of threats is the third step (Step 3) of the threat modelling process, which involves addressing, assessing, monitoring and documenting threats and vulnerabilities (EC-Council, 2022). Finally, validation of threat models is the fourth step (Step 4) in the threat modelling process and pertains to the creation and management of tests (Shostack, 2014).
Materials and methods
Research questions
Based on the provided background, that is, security framework and threat modelling, we have formulated the following Research Questions (RQs):
RQ1: Are all security framework layers addressed by the existing studies?
RQ2: Which threat modelling styles are used by the existing studies?
RQ3: Which threat modelling methods are used by the existing studies?
RQ4: Which threat modelling methodologies are used by the existing studies?
RQ5: Are all threat modelling process steps used by the existing studies?
Review methodology
To summarize the existing work and studies in the domain of threat modelling of IoT-enabled smart systems in healthcare and answer the posed research question, we have followed a detailed methodology for conducting the review comprising four main steps is given in Figure 2, which relies on the procedures given by Kitchenham (2004). We also incorporated the Preferred Reporting Items for Systematic Review and Meta-Analysis approach that distinguishes separate stages of systematic reviews. These stages are the collection of papers, scanning of papers’ text, evaluation of eligibility of papers and meta-analysis (Figure 3).

Used review methodology.

Preferred Reporting Items for Systematic Review and Meta-Analysis (PRISMA) review workflow reflecting the number of articles identified, screened, processed and removed in each step.
After the first step, when we defined a review scope and formed a research question, we were faced with an undetermined number of studies to analyse. In the second step, we selected the review period, research databases and a key search words combination. The review period from 2014 to 2025 was selected to capture the evolution of IoT-enabled healthcare systems from early adoption to mature, large-scale deployment.
Around 2014, IoT technologies began to be actively integrated into healthcare environments, accompanied by the emergence of security concerns and initial threat modelling approaches. The period also aligns with key regulatory developments, such as the introduction of the General Data Protection Regulation and cybersecurity guidance for medical devices, which significantly influenced research in this domain. Extending the review to 2025 ensures inclusion of the most recent advancements. The scientific bases on which we conducted the search are Google Scholar, Institute of Electrical and Electronics Engineers (IEEE) Xplore and Web of Science. They are selected to ensure comprehensive and unbiased coverage of the domain. Google Scholar was included to capture a broad range of academic and grey literature, maximizing recall. IEEE Xplore was selected due to its strong focus on engineering and cybersecurity research, which is central to IoT threat modelling. Web of Science was used to ensure inclusion of high-quality, peer-reviewed journal articles and to support citation-based analysis. The combination of these databases provides complementary strengths, balancing breadth and quality while minimizing the risk of missing relevant studies. Thereby, we have ensured complementary coverage of the research domain, balance between breadth and quality, coverage of both journal and conference literature and mitigation of database-specific bias. Databases were searched with the following combinations of keywords: (threat modelling OR threat analysis) AND (Internet of Things) AND (smart healthcare). The search string (‘threat modelling’ OR ‘threat analysis’) AND (‘Internet of Things’) AND (‘smart healthcare’) was developed using a concept-based approach, reflecting the three key dimensions of the study: security methodology, enabling technology and application domain. Synonyms were incorporated using the OR operator to account for variations in terminology across literature and to maximize retrieval of relevant studies. The AND operator was used to ensure that only studies addressing all three aspects were included, thereby improving precision. The term ‘Internet of Things’ was selected to ensure consistency across databases, while ‘smart healthcare’ was used to capture IoT-enabled and digitally integrated healthcare systems. This combination provides a balanced trade-off between comprehensiveness and specificity, while ensuring reproducibility of the search process.
After applying the initial selection items to our research, such as review period, databases and keywords, the resulting number of papers was 76. Then, we applied the inclusion and exclusion criteria to screened articles in Step 3 to reduce the number of studies.
The inclusion criteria are as follows:
journal and conference articles primarily dealing with practical threat modelling or analysis of smart healthcare systems that are based on IoT, articles in English, articles that focus on threat modelling and threat analysis.
The exclusion criteria are as follows:
review papers, books, theses or other types of publications, articles not in English, articles dealing with security and privacy issues in general in this environment, as well as intrusion and anomaly detection.
In the end, after undergoing the filtering process (inclusion and exclusion criteria stated previously, as well as duplicate removal), we were left with 19 articles (Figure 3). It is important to state that this article selection process has limitations. The selection and analysis are conducted based on authors’ understanding of the papers, and subjectivity cannot be excluded. It is important to note that the articles were selected for consideration only if both authors were in agreement. Also, we cannot rule out that there are additional studies describing the threat modelling of IoT-enabled smart healthcare systems not included in this review, due to our exclusion criteria. However, we believe that this set of papers is representative, and the conclusions made based on it can be extrapolated to the whole area.
In order to review the selected case studies, we have analysed them based on several following attributes (Step 4): security framework layer (device, network, service, application) for RQ1, used threat modelling style (e.g. automated, unautomated or machine learning) for RQ2 and method (as described in previous sections) for RQ3, used methodology (as listed in previous sections) for RQ4, as well as the steps conducted in the process of the analysis, that is, understanding, identification, consideration and validity verification for RQ5.
The review of studies addressing threat modelling of IoT-enabled smart systems in healthcare is given in Table 1.
Review of studies addressing threat modelling of IoT-enabled smart systems in healthcare.
Review of studies addressing threat modelling of IoT-enabled smart systems in healthcare.
CRR: Cyber Resilience Review; ENISA: European Union Agency for Cybersecurity; IoT: Internet of Things; LINDDUN: Linkability, Identifiability, Non-repudiation, Detectability, Disclosure of Information, Unawareness, Non-compliance; ML: Machine Learning; NIST: National Institute of Standards and Technology; NLP: Natural Language Processing; OWASP: Open Web Application Security Project; SHL: Saville and Holdsworth Limited; STRIDE: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege.
When it comes to smart cyber security framework layers addressed in reviewed studies, 14 of them threat modelled on the device layer, 13 on the network layer, 13 on the service layer and 10 included the application layer. All four layers have been considered by 43.75% of studies, 37.5% of studies addressed only one layer, while the remaining 18.75% addressed two layers.
Most studies addressed in this review, that is, 47.4%, conducted threat modelling without using any software (unautomated), 42.1% used some kind of software to identify threats (automated) and only two studies (10.5%) used machine learning or NLP. When it comes to the method used, 14 studies used software/system-centric approach and 5 different one. Haque et al. (2024); Ayub and alShawa (2024) and Huda et al. (2024) used an attacker-centric approach. Czekster et al. (2025) used a simulation-based approach, while Vakhter et al. (2022) used a currently not defined user-centric approach. In terms of methodology, 47.3% of cases used mature STRIDE, while the remaining studies have not stated the used methodology or they used self-proposed non-established frameworks (European Network and Information Security Agency framework, domain-specific qualitative–quantitative, SHLChecker, etc.).
When analysing the process of threat modelling, as given in Table 1, one can conclude that none of the considered studies conducted all four steps, that is, understanding the system, identification of threats, consideration of threats and verification of validity of the proposed threat model. The first three steps of the process (without the fourth) were conducted by 63.15% of the analysed works, while the rest of the papers conducted the first two steps, the second two steps or only the second step. Two-thirds of the studies elaborated on system understanding as a first step up to a different level from superficial (Treacy et al., 2020) to detailed (Popaja et al., 2021). The second step, that is, identification of threats, has been performed by all considered studies. The third step, that is, consideration of threats, has also been conducted by three-quarters of the selected works up to a different level.
For example, Omotosho et al. (2019) proposed detailed mitigation strategies and countermeasures for identified threats on their IoT health devices, while Tseng et al. (2019) assessed the risk for the identified threats without proposing any countermeasures, which can be considered as a superficial consideration. The final fourth step of the threat modelling process, which includes the validity verification of the proposed model, has not been done by the analysed studies. Some of the addressed studies (published in 2024 and 2025) have tested their models in certain environments (case studies), but that does not represent validation of the models in terms of the description offered in this article.
The summary of the answers to the research questions is given in Table 2.
Summary of answers to research questions.
NLP: Natural Language Processing; RQ: Research Question; STRIDE: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege.
IoT-enabled smart systems in healthcare are very important, and one of the key findings from our review is that a very limited amount of research has been conducted in terms of modelling the threats for those systems. Moreover, among those few studies, only several of them threat-modelled on all layers of the proposed security framework, that is, they encompassed device, network, service and application layers. Therefore, to increase the security of these critical systems, which will be more complex in the future period as technology and medicine merge, much more research in this domain needs to be done. Thus, we propose having threat modelling incorporated in security policies of healthcare service delivery chain stakeholders. This means that to implement the IoT-enabled smart healthcare system in an institution, all actors must do detailed prior threat modelling for the subject system.
Furthermore, the proposal refers to the conduction of comprehensive threat modelling on all four layers of the security framework simultaneously. The results clearly show a fragmented approach to threat modelling of IoT-enabled healthcare systems and indicate that the current approaches are largely reductionist. Namely, the researchers prioritize low-level technical layers (device/network) and neglect higher-level, context-rich layers where privacy, safety and QoL impacts are most critical. This creates a systemic blind spot since the threats in IoT healthcare are cross-layer by nature, and ignoring one layer leads to an incomplete threat model and consequently to low security. The current studies in this domain focus mostly on isolated system components rather than the interconnected nature of IoT-enabled healthcare systems, which are inherently multilayered and interdependent. In other words, comprehensive threat modelling should include simultaneous threat treatment for, for example, sensors and wearables (device layer), 5G/6G networks (network layer), cloud storage or AI (service layer) and remote patient monitoring (application layer). Excluding any layer of the proposed security framework for threat modelling leads to missing various threats and vulnerabilities that will be more complex in the future of IoT smart healthcare systems, thus faulty threat models, and consequently a lack of security and a bad influence on QoL.
As already concluded, the complete process of threat modelling of IoT-enabled smart healthcare systems is not performed. All studies lack threat model validity verification, which characterizes process incompleteness. The last step of threat modelling, that is, validation of the threat model, checks threat mitigations and ensures that everything is identified and covered by the analysis. This step is as important as threat modelling itself since it tests the model, that is, it ensures that identified steps are complete, correctly mapped to system components, that the model reflects the real operational environment and that the proposed mitigations are effective and sufficient. The reviewed studies suggest that threat modelling is frequently approached as a static rather than iterative process, with limited evidence of systematic validation. This recurring tendency reflects a methodological limitation that may restrict its effectiveness as an applied security approach. This can complicate effective detection and solving security threats in this domain, since threat analysis is an iterative process, and one must ensure that the model is compatible with the system and that all threats are truly identified and mitigated. Without validation, models may miss threats, include false positives, or not reflect real systems. A lack of threat model validation undermines the practical applicability and trustworthiness of results. In fact, without a validation step, a threat model is merely a hypothesis about possible threats.
The consequences of missing a validation step include incomplete threat coverage, which is particularly important in IoT healthcare where systems are heterogenous and interconnected, and threats propagate across layers. Also, unvalidated models suggest that the system is ‘secure enough’, which can lead stakeholders to deploy systems with undetected vulnerabilities. This can cause dangerous errors impacting directly patient safety and QoL. Without validation, models are not tested against real-world scenarios and real system behaviour, and there is no evidence that mitigation strategies work. This indicates that there is limited adoption of those threat models in real healthcare environments. If one misses validation, then threat modelling becomes a one-time analysis, and it cannot adapt to new devices, new attack vectors or evolving systems.
Possible reasons for researchers excluding the validation of the threat model are various. IoT-enabled healthcare systems are complex and multilayered, and validating the threat model across all layers simultaneously is difficult. Then, there is no agreed methodology for verifying completeness and measuring accuracy of threat models. Also, a possible reason could be that validation of threat modelling is a time-consuming process and there are no automated validation tools to help accelerate the process. Furthermore, most researchers are interested in identifying the threats rather than whether those threats are correct, complete and realistic. Our findings also show the imbalance in threat modelling steps, where the strong focus is on threat identification while other steps do not receive that kind of attention. This suggests that researchers have a checklist mentality, that is, they prioritize listing the threats rather than understanding the whole system context and validating outcomes needed for the holistic approach to security. This consequently leads to superficial models and the lack of real-work applicability, which gravely influences security.
Another important reason for this critical behaviour is that threat modelling is prone to human ego challenges. Namely, the development of IoT-enabled healthcare systems and threat models for those systems are very challenging tasks. Design and security engineers involved in the process naturally have a hard time considering the flaws in the systems and models they developed. The main pitfall is that considering bugs, misconfigurations and errors can hurt them, since there is a realistic chance that something they have invested their efforts in can be flawed. However, experienced engineers know how to overcome these challenges by including not only security and privacy but also tests and validations in the design of the system and threat model. Validation of the threat model ensures that it coincides with the system and that all threats are identified and mitigated.
Therefore, we would propose to plan and conduct the proposed full four-step threat modelling for IoT-enabled smart healthcare systems on four layers of the security framework. This process can be subjected to certain contextual adjustments for the purpose of gaining a deeper understanding of threats and relationships in the healthcare field.
Also, there is a lack of use of automated means in the threat modelling process, or AI or ML, which, considering the capacities of new technologies, should be changed. The field is still dominated by manual or semi-manual approaches, which are not scalable and are prone to human bias and omission. This explains why many studies fail to cover all security layers and all threat modelling steps. The limited adoption of AI/ML-based approaches suggests that current threat modelling practices are not keeping pace with the increasing complexity and scale of IoT-enabled healthcare systems, leading to potentially incomplete and inefficient threat identification and management. The capacities of new technologies should be used not only to accelerate the process of threat modelling but also to have more effective threat management. Namely, threat analysis in the healthcare field relies on characterizing the system, vulnerabilities and attackers without clear metrics and without the inclusion of the environmental and other contextual factors (Aljaz et al., 2023). New technologies, by offering greater capacities, can aid the threat analysis process in many ways: automated broader factor consideration, a holistic approach to used systems, since currently the most represented approaches are based on individual system components, capturing and identification of complex threats, integration of technical and non-technical views in terms of the complex healthcare domain and so on. Therefore, we support the motivation for the development and usage of automated comprehensive threat modelling and validation frameworks specialized for the IoT-based healthcare industry.
Our findings show that the STRIDE methodology dominates not only the field as the most mature one, which indicates reliance on traditional models, but also nearly half of the considered studies use non-standard or unspecified methods. This reveals a lack of methodological consensus, that is, there is no domain-specific standard for IoT healthcare threat modelling. Also, this raises several problems: the results are not comparable, and it is difficult to build cumulative knowledge. The co-existence of widely used frameworks such as STRIDE with numerous ad hoc or unspecified approaches highlights the absence of a standardized methodology tailored to IoT-enabled healthcare systems, limiting reproducibility and comparability across studies. Therefore, we support the development of a standardized IoT-enabled healthcare threat modelling methodology.
Finally, our review stresses the importance of threat modelling for IoT-enabled smart healthcare on device, network, service and application layer. Many of the threats in this environment are the consequence of rapid interconnection and merging of new technologies and healthcare, which constructs a challenging security field that inherits vulnerabilities from both domains and creates novel ones. To successfully manage all those threats, it is necessary to take a comprehensive and holistic approach to threat analysis and try to address both horizontal threats, which are the consequence of combining these fields, as well as vertical threats, which stem from each of the system components. Thereby, we would be able to offer all stakeholders and users in the healthcare domain better and more secure services.
Conclusion
Concluding remarks
Addressing security issues in healthcare requires a comprehensive strategy that integrates both technical and policy-driven solutions. In this regard, IoT-enabled smart healthcare systems are a very potent field of research and implementation. However, in today’s very challenging cybersecurity environment, security of IoT-enabled systems in the healthcare sector is the most important issue for their reliability and the successful adoption of technology. One of the ways to accomplish security in IoT-enabled smart healthcare systems and thereby improve our QoL, despite many current and evolving threats and vulnerabilities coming from the combination of IoT and healthcare as well as from each field, is to conduct comprehensive threat modelling for those systems simultaneously on device, network, service and application layer (security framework).
Therefore, to contribute to the field, we have done the following. Firstly, we have combined a security framework for smart IoT healthcare comprising the threat modelling approach. Then, we have presented the process of threat modelling and listed currently existing threat modelling methods and methodologies, thereby summarizing the main knowledge for the potential stakeholders in terms of the threat modelling process. This step concludes that there is not much work on threat modelling of IoT-enabled healthcare systems.
Third, we have conducted a review of the existing threat models for IoT-enabled smart healthcare systems, thereby creating an insight into the current state in the field for interested parties. The analysis suggests that current studies in the field often do not engage in validation of threat modelling, which results in its treatment as a largely theoretical construct rather than an applied security approach. This recurring tendency reflects a methodological limitation that may constrain the broader applicability of existing research. Also, the reviewed studies indicate that current work in the field seldom addresses higher-level, context-rich layers where privacy, safety and QoL impacts are most pronounced. This consistent focus on lower layers suggests a systemic limitation, as threats propagate across multiple levels of analysis. In addition, the lack of automation and reliance on new technologies, as well as the lack of a standardized methodology, may contribute to why many studies fail to cover all security layers and all threat modelling steps.
Fourth, based on the results of the review, we have formed the following proposals:
Comprehensive threat modelling simultaneously on all layers of the security framework (device, network, service and application) should be incorporated in the security policies of healthcare service delivery chain stakeholders; Full four-step threat modelling for IoT-enabled smart healthcare systems should be planned and conducted; Standardized approach to threat modelling should be developed; and Development and usage of automated threat modelling and validation frameworks specialized for the IoT-based healthcare industry should be supported and motivated.
Given that this study is a systematic review, the implications are both practical (for healthcare stakeholders, developers and policymakers) and research/theoretical (for academia and future studies).
In practical terms, our findings show that current threat modelling practices are incomplete and mostly layer-specific. This means that healthcare institutions can adopt comprehensive, four-layer threat modelling (device, network, service, application) to anticipate and mitigate complex threats before deployment. Also, as healthcare increasingly adopts IoT devices such as wearables or remote monitors and integrates AI/ML in their systems, it is of great importance to analyse all layers holistically. Thereby, hospitals and service providers can better integrate new technologies safely, minimizing patient data breaches or system failures. The findings of the study highlight a lack of automated threat modelling, which provides an opportunity for developers to use AI/ML to speed up threat identification, include contextual factors and improve the reliability of models. In addition, the results of the study are important for stakeholders and policymakers in terms of training programmes or policy guidelines that need to be developed, ensuring that systematic threat modelling becomes a standard practice.
In research terms, this study identified research gaps, making them a clear direction for future research activities. This means that researchers can develop new threat modelling frameworks to address these gaps. Upcoming research activities can also adopt this proposed framework to ensure comparability across studies, leading to cumulative knowledge. In addition, by emphasizing both a horizontal approach (cross-system interactions) and a vertical approach (within a system layer), this study promotes a more comprehensive analytical approach that can be further used.
Finally, in addition to the proposed concluding actions, the results of this study can influence healthcare information technology standards and compliance, since regulators should require mandatory multi-layer threat modelling for IoT-enabled healthcare systems before certification or deployment. This consequently supports risk management policies and patient safety regulations in smart healthcare environments.
Limitations
This study has several limitations. First, the review focused on a limited set of 19 practical studies, potentially excluding relevant research in other languages or less-indexed sources. Second, our analysis relied on information reported in the selected studies, which may vary in detail, particularly regarding threat model validation, automation and layer coverage. Furthermore, decisions on selecting the papers for the analysis are subjectively driven. Third, the review focuses specifically on device, network, service and application layers of IoT-enabled healthcare systems, which may not capture organizational or human-factor considerations. Finally, given the rapid evolution of IoT technologies and threat modelling methods, new approaches emerging after the review period may not be included. Also, conclusions made in this study are specific to IoT-enabled smart healthcare systems and may not be generalized to other smart IoT environments. Despite these limitations, the study provides a structured overview of current gaps and practical guidance for improving threat modelling in smart healthcare environments.
Future work
Future work in this domain should include the realization of previously listed proposals and overcoming the limitations, resulting in the popularization of threat modelling in this domain, as well as adopting and implementing a more serious, comprehensive and holistic view and approach to threat analysis in the field of healthcare where IoT-enabled smart systems are used. The results of this study provide a roadmap for healthcare institutions, developers and researchers to implement comprehensive, validated and automated threat modelling frameworks, ensuring more secure IoT-enabled smart healthcare systems, guiding future research and informing policy and regulatory standards.
Footnotes
Ethical considerations
This article does not contain any studies with human or animal participants.
Informed consent
There are no human participants in this article, and informed consent is not required.
Author contributions
Conceptualization: Jasmina Baraković Husić and Sabina Baraković; Methodology: Sabina Baraković; Formal analysis: Jasmina Baraković Husić; Investigation: Jasmina Baraković Husić and Sabina Baraković; Writing – original draft preparation: Jasmina Baraković Husić and Sabina Baraković; Writing – review and editing: Jasmina Baraković Husić and Sabina Baraković.
All authors have read and agreed to the published version of the manuscript.
Funding
The authors received no financial support for the research, authorship, and/or publication of this article.
Declaration of conflicting interests
The authors declared no potential conflicts of interest with respect to the research, authorship, and/or publication of this article.
