INET 4007 · risk assessment

Healthcare cloud security risk assessment

Our team developed a Cloud Security Risk Management Framework to evaluate and mitigate major threats impacting healthcare operations in the cloud. The purpose of the proposal was to present data driven findings from our Monte Carlo analysis and request funding to implement solutions that reduce financial loss, improve compliance, and strengthen patient data protection.

Status complete
Started Fall 2025
Source GitHub ↗

Problem

Healthcare is a large and vital sector in Minnesota; this makes it a larger target for attacks and increases the severity of service disruptions. Cloud adoption provides solutions for many problems but also introduces new ones that must be addressed. No solution is ever foolproof, but the best way to ensure longevity is through mitigation. The question remains, how is the decision made for what to prioritized? Quantitative data provides a solution and visualizes the impact of many simulated scenarios. This data provides the structure to allocate funds in a meaningful and precise manner to decrease the risk to the state financially through mitigation expenses which in turn improves outcomes for those relying on the system.

Roles and Responsibilities

Enterprise Architect – Seth Breuer

Vendor Breach – Relying on partners means entrusting the security of data to them. A breach of their system could place our data at risk. As the Enterprise Architect, I ensure that systems isolate critical data and integration with vendors is secure. This reduces our liability during and ability to operate in the case of a vendor being compromised.

Ransomware Attack – Ransomware poses a serious threat to critical health systems, disruption of care, and public health operations. As Enterprise Architect, I must ensure that systems are resilient and segmented to decrease downtime during the recovery process.

Cloud Provider Outage – An outage from a cloud provider could make critical applications unavailable, impacting operations and critical functions. As Enterprise Architect, I design multi-cloud and multi-region systems that prioritize redundancy, failover performance to ensure normal operations of systems during provider disruption.

Chief Information Security Officer (CISO)

Cloud Data Breach – If someone access PHI because they have access to misconfigured cloud storage or compromised credentials, it would violate regulations under HIPAA and damage trust in our organization. As the CISO, I put in place encryption, multi-factor authentication, and continuous monitoring to mitigate this risk.

Insider Threat – Internal users can access or exfiltrate data without having it pass through the perimeter. In response I will make sure that privileged access and identity management is enforced across the enterprise, that employees are trained on how to identify threats and behavior analytic tools are made available across all systems.

API Security Vulnerabilities – Lack of security or excessive security of APIs can expose backend systems for exploitation. This is critical to the CISO role as modern health care apps often depend on APIs for interoperability. Mitigating this exposure can be accomplished by deploying token validation, zero-trust design, and API Gateways.

Chief Compliance Officer

HIPAA Noncompliance – Noncompliance with HIPAA regulations could result in major fines and reputational damage if patient data is mishandled in the cloud. This risk is crucial for the CISO because maintaining regulatory alignment directly impacts the organization's trust and legal standing.

Data Mismanagement – Inadequate data governance, such as improper classification or access control, could lead to data leaks or breaches. The CISO must ensure that privacy controls, encryption, and audit mechanisms are in place to safeguard sensitive health information.

Third-Party Compliance Failure – If cloud vendors or partners fail to meet compliance requirements, the organization remains liable. The CISO must manage vendor assessments and ensure contractual compliance to reduce supply chain risk.

VP Marketing

Reputation Damage and Patient Trust – Patients truly lose trust in the company when they learn that health medical care has been impacted due to data breaches. They may decide not to submit personal information or switch providers as a result. In my role as vice president of marketing, I would concentrate on restoring that trust by open communication, community involvement, and understanding information regarding the security of patient data.

Communication Damage during incident response – In the event of a data incident, a company's inability to effectively communicate can cause fear to spread immediately. They begin to believe the worst, which damages the company's reputation. It is important that I help plan communications that are clear and easy for both employees and the general public to understand.

Employee awareness and public Education gaps – Only a few people completely understand how cybersecurity protects them. This could result in the spread of misinformation so it's important that individuals know this. I would lead educational initiatives on the importance of compliance, security measures, and data protection in an understandable way.

54.4%
Pre-mitigation probability of exceeding $10M in annual losses
7.8%
Post-mitigation probability after implementing all controls
$14.4M → $4.2M
Expected inherent loss reduced by 70.6% across all 12 risks

Pre-implementation risk portfolio

The current risk is far above the level that should be tolerated at a level that it poses a significant threat to the operations of the state. Currently the state faces a 54.4% chance of a loss exceeding $10 million for the year. Solutions should not only decrease the risk this year, but also decrease the cost of protection for future years so that the initial investment is proportional to the actual benefits it provides. Due to the nature of the loss exceedance tolerance curve decreasing quickly which means that there is a greater tolerance for small loss rather than a large one, although at the extremely high end the risk falls below the curve, it does not fall beneath the curve quick enough.

Risk Prob. Range (90% CI) Expected loss
Cloud data breach
CISO
35% $2M – $25M $3,323,179
Ransomware attack
Enterprise Architect
15% $5M – $40M $2,590,412
Data mismanagement
CCO
30% $1.5M – $10M $1,372,088
Reputation damage
VP Marketing
18% $2M – $15M $1,189,306
Vendor breach
Enterprise Architect
12% $2.5M – $20M $1,036,165
Insider threat
CISO
25% $1M – $10M $1,010,003
HIPAA noncompliance
CCO
25% $1M – $8M $863,471
Cloud provider outage
Enterprise Architect
8% $3M – $24M $828,932
API security failure
CISO
20% $500K – $8M $570,564
Communication failure
VP Marketing
14% $1.5M – $8M $552,007
Third-party compliance
CCO
20% $800K – $6M $528,581
Awareness gap
VP Marketing
20% $1M – $5M $504,068
Total expected inherent loss $14,368,776

Solutions

CISO – Cloud Data Breach – Encryption

Monte Carlo simulations reveal that data breaches to the cloud are one of the significant expected annual losses for our organization ranging from $2 million to $25 million depending on level of severity and data exposure. Adding encryption and identity controls will decrease the probability of loss (or "exposure") by approximately 45%, saving millions of dollars in potential fines (from regulatory bodies) and recovery costs. This finding is consistent with recent reports on healthcare security indicating that data breaches are still the most costly threat, averaging over $10 million per event in the U.S. healthcare market (IBM, 2024).

Enterprise Architect – Seth Breuer – Ransomware Attack – Logical Segmentation

Monte Carlo calculations show that ransomware attacks can result in losses ranging from $5 to $40 million each year. To reduce this impact, I would implement logical network segmentation, air-gapped backups, endpoint protection, and zero trust architecture. These measures would reduce the probability of a successful attack by 50% and significantly limit the blast radius of any breach that does occur.

Eddy (2024) states that 70% of cyberattacks on healthcare stem from Ransomware, this number highlights the high potential for the attacks and why it must be addressed. Due to the nature of these attacks, healthcare facilities lose operational capacity and prevent healthcare workers from providing life-saving care. The nature of the care provided is time sensitive, delays in action drastically decrease the likelihood of survival.

In the quantitative framework, ransomware attacks represent the highest-impact risk. The probability of 15% stemming from attackers focuses on the sector and the lower bound of $5 million combined with the $40 million upper bound for loss which results from the critical nature of the sector and officials being forced to negotiate with attackers makes it a primary driver of expected loss on the baseline curve. Based on the simulation, the cost of control of $800,000 is less than half of the expected annual risk reduction of approximately $1.3 million, which highlights the benefit of mitigation and the price effectiveness of our solutions. On top of this, it drastically decreases the worst-case scenario for the risk, decreasing it by 50%.

By implementing the measures suggested, the probability of loss decreases to 7.5%, a 50% drop. The lower bound decreases by 50% due to better data separation and policies that isolate different areas. Due to these solutions, the upper bound drops by 50%. The expected inherent loss due to the risk drops to roughly $648,000 and the loss exceedance curve closes sharply and places the inherent risk associated with the event below the loss exceedance tolerance.

VP Marketing – Reputation Damage and Communication

Depending on the extent of the impact, Monte Carlo simulations show that reputational costs resulting from a data leak could reach $15 million or more. Because it affects patient trust and retention, this is one of the biggest non-technical threats in healthcare. Applying communication and awareness tactics minimizes the likelihood of loss by approximately 55%. This, in turn, helps to rebuild trust and ensures brand stability (IBM, 2025; Edelman, 2024).

Chief Compliance Officer – HIPAA Noncompliance – Compliance Automation

Monte Carlo simulations show that HIPAA noncompliance can cost between $1 million and $10 million annually through fines and lost reputation. Automating compliance checks and audit logging can lower that risk by about 40% by detecting violations early. This aligns with current healthcare trends showing that automated monitoring cuts audit failures in half and helps maintain trust with patients and regulators while reducing the chance of costly penalties.

Post-implementation risk portfolio

The overall probability of loss exceeding $10 million drops from 54.4% to 7.8% after all controls are implemented. Solutions should not only decrease the risk this year, but also decrease the cost of protection for future years so that the initial investment is proportional to the actual benefits it provides.

Risk Prob. Range (90% CI) Expected loss
Cloud data breach 19% $1M – $14M $980,760
Ransomware attack 7.5% $2.5M – $20M $647,603
Data mismanagement 20% $1M – $6.5M $599,497
Insider threat 15% $500K – $6M $345,580
HIPAA noncompliance 15% $500K – $5M $303,001
Vendor breach 6% $1.25M – $10M $259,041
Reputation damage 8% $1M – $7M $252,125
Third-party compliance 14% $500K – $4M $241,772
API security failure 12% $300K – $5M $211,859
Communication failure 7% $750K – $4M $138,002
Cloud provider outage 3% $1.2M – $10M $127,913
Awareness gap 9% $500K – $2.5M $113,415
Total expected inherent loss $4,220,568

Loss exceedance

By implementing the solutions provided, the risk of losing more than $10 million shrinks to 7.8% for the year. Although risk exceeds the tolerance curve at the low end, meaning that small losses exceed the loss curve, importantly potential losses do not exceed the threshold at more serious levels being those over $10 million.

100% 80% 60% 54.4% 40% 20% 0% $0 $5M $10M $15M $20M $25M Aggregate annual loss $10M threshold 54.4% 7.8% Pre-mitigation Post-mitigation

Fig. 1 — Loss exceedance curve, 1,000-trial Monte Carlo simulation. Pre-mitigation (red) vs. post-mitigation (green).

Methodology

Each risk was modeled as a Bernoulli trial asking whether the event occurs this year, combined with a lognormal impact distribution bounded by expert-estimated 5th and 95th percentile values. The simulation aggregated all 12 risks per trial, ran 1,000 iterations, and produced the loss exceedance curve. Control effectiveness was applied as a percentage reduction in probability and residual risk was recalculated to show post-mitigation outcomes. Findings were mapped to NIST Cybersecurity Framework controls so that each identified gap tied directly to a recognized control area.

Outcome

We request approval, funding, and dedicated time to implement these risk mitigation measures. Investing in these controls now will significantly reduce long-term financial exposure, ensure compliance with HIPAA, and protect the continuity of healthcare services for our organization and the public.

Tools

Monte Carlo simulation

1,000-trial loss modeling

NIST CSF

Control mapping

Excel

OneforOne substitution model & data tables

Lognormal distributions

Impact range modeling

What I learned

Translating risk into a distribution of dollar outcomes changed the conversation entirely. The most valuable part of the exercise was not the final number but discovering that several initial mitigation proposals cost more than the risks they addressed. We had to restructure the controls until every one had a positive return. Numbers are the key to the game, without them it is just a debate over labels.