Rashed Hamed Alkhudair, Abdullah Alabdrab Alnabi
Abstract
Healthcare web applications occupy a uniquely hostile threat surface because they aggregate three distinct asset classes -patient health information (PHI), paymentcard data, and clinical-decision artefacts -each of which is the target of a different attacker community and a different regulatory framework. We argue that conventionalSecure Software Development Life-cycle (SDLC) practices, while individually wellstudied, are not composed in current healthcare projects in a way that demonstrably defends the full asset surface, and that the result is the recurrent pattern of healthcare breaches reported in the past decade.
Citation format
ALKHUDAIR, Rashed Hamed; ALNABI, Abdullah Alabdrab. MISUSE-CASE-DRIVEN SECURE SDLC FOR HEALTHCARE WEB APPLICATIONS: A METHODOLOGY, AN OBSERVABLE-SECURITY PATTERN, AND a CASE STUDY. International Journal of Information Security, 2026, 5(1): 42–52.