Electronic Health Records (EHR) are increasingly hosted across hybrid and multi-cloud infrastructures to support scalable analytics, cross-institution collaboration, and distributed care delivery. While these deployments enable high availability and integration of diverse digital services, they also introduce a broader attack surface in which authentication, service communication, and deployment operations become persistent security risks. Zero-Trust DevOps extends the classical DevOps life cycle with a security model that assumes no implicit trust for users, services, or network boundaries, mandating continuous verification throughout CI/CD execution, identity management, and infrastructure orchestration. This work proposes a continuous verification framework for secure EHR deployments, incorporating runtime service attestation, policy-driven identity controls, multi-cloud trust segmentation, and immutable audit trails that enforce defensive guarantees during both deployment and operation. The proposed approach integrates Zero-Trust principles into DevOps workflows to harden the EHR ecosystem against evolving threats without compromising interoperability or system agility.
@artical{n1292023ijsea12091049,
Title = "Zero-Trust DevOps for Electronic Health Records: Continuous Verification in Multi-Cloud Environments",
Journal ="International Journal of Science and Engineering Applications (IJSEA)",
Volume = "12",
Issue ="9",
Pages ="169 - 176",
Year = "2023",
Authors ="Nagarjuna Nellutla"}