← Insights

Zero Trust is an architectural principle. In a clinical platform it is also a regulatory one.

Never trust implicitly. Verify continuously. Enforce least privilege at every boundary, and document all of it in your DHF.

The three principles, in a clinical context

  • Never trust. Assume breach. Every request is authenticated regardless of source, even inside the network perimeter.
  • Verify continuously. Short-lived tokens, stateless JWT at the gateway, and every access decision explicit, logged and auditable.
  • Least privilege. Each software item gets the minimum access it requires. The reporting service cannot write clinical data. Ever.

What changes architecturally in a clinical SaMD

  • Network segmentation is not enough. mTLS between services, and a clinical data layer that is unreachable without an explicit, auditable access decision (AAMI SW96).
  • Identity is the new perimeter. Stateless JWT validated at the gateway and cached locally, so an unavailable auth service is Dark Day resilience (an ISO 14971 control).
  • Least privilege is a blast radius boundary. IEC 62304 software item decomposition maps directly to access scope. Each item owns only what it needs.
  • Continuous validation is CAPA infrastructure. Every access is logged, anomalies are detectable and every incident is reconstructable.

Zero trust and regulated software are asking the same question. Who touched this system, when, with what access, and can you prove it?

Seen this differently?

Questions, corrections and counterexamples are welcome.

Related

Keep reading