Developing a Framework for Compliance with US Data Protection Regulations (HIPAA, GDPR) in IoT Environments: A Comprehensive Compliance Architecture and Implementation Roadmap
DOI:
https://doi.org/10.61424/jcsit.v3i2.1055Keywords:
IoT Security, HIPAA Compliance, GDPR, Data Protection, Zero-Trust Architecture, Privacy Engineering, Regulatory FrameworksAbstract
The proliferation of Internet of Things (IoT) devices across healthcare, critical infrastructure, and consumer sectors has introduced profound challenges for data protection compliance. Existing regulatory instruments, most notably the Health Insurance Portability and Accountability Act (HIPAA), the General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA/CPRA), were conceived in pre-IoT legislative environments and impose obligations that are difficult to operationalize across heterogeneous, resource-constrained device ecosystems. This article develops a unified, layered compliance framework that systematically maps regulatory requirements to IoT-specific technical and organizational controls. Drawing upon the NIST Cybersecurity Framework (CSF) 2.0, NIST SP 800-213, and ISO/IEC 27400:2022 as architectural anchors, we propose a five-domain compliance model encompassing device identity, data lifecycle governance, network security, incident response, and supply chain risk management. We further introduce a risk-tiered assessment methodology and a phased 18-month implementation roadmap validated against representative IoT deployment scenarios in healthcare and smart-building contexts. Our analysis reveals that while a universal compliance alignment is achievable, organizations must navigate substantive jurisdictional tensions, particularly between HIPAA's entity-specific model and GDPR's rights-based paradigm requiring adaptive policy architectures. This framework contributes both a practical governance instrument and a basis for future empirical compliance research in IoT environments.
References
Alrawais, A., Alhothaily, A., Hu, C., & Cheng, X. (2017). Fog computing for the Internet of Things: Security and privacy issues. IEEE Internet Computing, 21(2), 34–42. https://doi.org/10.1109/MIC.2017.37
Article 29 Data Protection Working Party. (2017). Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is 'likely to result in a high risk' for the purposes of Regulation 2016/679 (WP 248 Rev. 01). European Data Protection Board. https://ec.europa.eu/newsroom/article29/items/611236
Atluri, V., Chun, S. A., & Mazzoleni, P. (2022). A semantic web services architecture for IoT healthcare. ACM Transactions on Internet Technology, 22(1), 1–28.
California Attorney General. (2023). California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA) enforcement resources. State of California Department of Justice. https://oag.ca.gov/privacy/ccpa
ENISA. (2023). ENISA threat landscape for the Internet of Things 2023. European Union Agency for Cybersecurity. https://doi.org/10.2824/641860
European Parliament and Council of the European Union. (2016). Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation). Official Journal of the European Union, L 119, 1–88.
Frustaci, M., Pace, P., Aloi, G., & Fortino, G. (2018). Evaluating critical security issues of the IoT world: Present and future challenges. IEEE Internet of Things Journal, 5(4), 2483–2495. https://doi.org/10.1109/JIOT.2017.2767291
International Organization for Standardization. (2022). ISO/IEC 27400:2022 – Cybersecurity: IoT security and privacy guidelines. ISO/IEC. https://www.iso.org/standard/44373.html
IoT Analytics. (2024). State of IoT 2024: Number of connected IoT devices growing 13% to 18.8 billion globally. IoT Analytics GmbH. https://iot-analytics.com/number-connected-iot-devices/
Michael Akintomiwa Oyedeji; Itanyi Akoh Isaiah. "Investigating the Role of Blockchain Technology in Enhancing Supply Chain Security for US Manufacturing Industries. Volume 4 Issue 8, August 2026. International Journal of Modern Science and Research Technology (IJMSRT), www.ijmsrt.com. PP:- 581-596, https://doi.org/10.5281/zenodo.22114214
National Institute of Standards and Technology. (2022). NIST Special Publication 800-213: IoT device cybersecurity guidance for the federal government – Establishing IoT device cybersecurity requirements. U.S. Department of Commerce. https://doi.org/10.6028/NIST.SP.800-213
National Institute of Standards and Technology. (2024a). The NIST Cybersecurity Framework 2.0. U.S. Department of Commerce. https://doi.org/10.6028/NIST.CSWP.29
National Institute of Standards and Technology. (2024b). NIST Special Publication 800-207A: A zero trust architecture model for access control in cloud-native systems in multi-cloud environments. U.S. Department of Commerce. https://doi.org/10.6028/NIST.SP.800-207A
National Institute of Standards and Technology. (2012). NIST Special Publication 800-30 Revision 1: Guide for conducting risk assessments. U.S. Department of Commerce. https://doi.org/10.6028/NIST.SP.800-30r1
Nurse, J. R. C., Creese, S., & De Roure, D. (2020). Security risk assessment in Internet of Things systems. IT Professional, 19(5), 20–26. https://doi.org/10.1109/MITP.2017.3680959
Office for Civil Rights, U.S. Department of Health and Human Services. (2013). Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules under the Health Information Technology for Economic and Clinical Health Act and the Genetic Information Nondiscrimination Act. Federal Register, 78(17), 5566–5702.
Office for Civil Rights, U.S. Department of Health and Human Services. (2016). HIPAA cloud computing guidance. HHS.gov. https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html
Ponemon Institute. (2023). State of cybersecurity in healthcare 2023. Ponemon Institute LLC. https://www.ponemon.org/research/ponemon-library/security/state-of-cybersecurity-in-healthcare-2023.html
Sicari, S., Rizzardi, A., Grieco, L. A., & Coen-Porisini, A. (2015). Security, privacy and trust in Internet of Things: The road ahead. Computer Networks, 76, 146–164. https://doi.org/10.1016/j.comnet.2014.11.008
U.S. Congress. (2020). IoT Cybersecurity Improvement Act of 2020, Pub. L. 116-207. https://www.congress.gov/bill/116th-congress/house-bill/1668
Weber, R. H., & Studer, E. (2016). Cybersecurity in the Internet of Things: Legal aspects. Computer Law & Security Review, 32(5), 715–728. https://doi.org/10.1016/j.clsr.2016.07.002
Yousuf, T., Mahmoud, R., Aloul, F., & Zualkernan, I. (2015). Internet of Things (IoT) security: Current status, challenges, and prospective measures. 10th International Conference for Internet Technology and Secured Transactions, 336–341. https://doi.org/10.1109/ICITST.2015.7412116
Zhao, K., & Ge, L. (2013). A survey on the Internet of Things security. 9th International Conference on Computational Intelligence and Security (CIS), 663–667. https://doi.org/10.1109/CIS.2013.145
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Tinuade Dawotola, Michael Akintomiwa Oyedeji, Omobolaji Olakunle Oladapo

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.