Logo image
A Quantitative EPSS-Based Risk Scoring Framework for HIPAA Technical Safeguards in Mobile Healthcare Applications
Conference proceeding   Peer reviewed

A Quantitative EPSS-Based Risk Scoring Framework for HIPAA Technical Safeguards in Mobile Healthcare Applications

Md Bajlur Rashid, Shuvo Bardhan, Tasmiah Rahman, MD Abdul Barek, Md Raihan Mia, Hansika Kolli, Naveed Ashfaque, Hossain Shahriar and Sheikh Iqbal Ahamed
Proceedings : annual International Computer Software and Applications Conference, pp.3078-3087
Annual Computers, Software, and Applications Conference (COMPSAC), 50th (Madrid, Spain, 07/07/2026–07/10/2026)
08/2026

Metrics

1 Record Views

Abstract

Android Security Compliance Automation Healthcare Cybersecurity HIPAA Mobile Health Security Risk Scoring Static Analysis EPSS Cybersecurity Health Information Technology Information or Communication Systems
Mobile healthcare applications increasingly process Protected Health Information (PHI) on Android and cloud platforms. However, compliance with the Health Insurance Portability and Accountability Act (HIPAA) technical safeguards is predominantly assessed through checklist-based audits or qualitative scoring. These assessments neither incorporate empirical likelihood of exploitation nor differentiate PHI sensitivity. This paper presents a novel quantitative HIPAA risk scoring framework implemented within the HIPAAChecker static analysis system; and the framework replaces static Common Vulnerability Scoring System (CVSS)-based severity with the Exploit Prediction Scoring System (EPSS) as an empirically calibrated likelihood estimator. Each security control is scored using three inputs-(i) EPSS exploitation probability; (ii) safeguard-specific severity; and (iii) PHI sensitivity weight. These control scores feed into safeguard-level scores through non-linear weighted averaging. In addition, a weighted max-mean hybrid then combines safeguard scores into a single HIPAA risk score, which preserves the dominance of high-impact failures. The framework was tested across 57 Android controls (i.e., covering 11 HIPAA technical safeguard categories). Additionally, the risk outcomes were measurably differentiated across controls; and the critical safeguard failures were not diluted by lower-risk findings. Moreover, the resulting score is interpretable, auditable, and grounded in the NIST SP 800-30 risk assessment principles.

Details

Logo image