The role of Digital Forensics Incident Response for mitigating insider attacks in the healthcare system D
Contributors
Mervin
Pawan Whig
Keywords
Proceeding
Track
General Track
License
Copyright (c) 2026 Sustainable Global Societies Initiative

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
Abstract
The healthcare sector is gradually becoming the most important prime target for cybercriminals due to the nature of data used in the healthcare sector, including patient data, medical records, usernames, passwords, and so on. This reality underscores the need to protect these data from insider attacks and highlights the importance of digital forensics in the health care sector. This research paper explores digital forensic investigation and responses to mitigate insider attacks, supported by the Digital Forensic Incident Response (DFIR) framework. This framework supports identifying the incident across its phases, including Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned. The CERT datasets have been taken for the analysis, and they have been pre-processed before applying the algorithm. The different machine learning algorithms are incorporated to gain better results, and it produces 97.7% accuracy with AdaBoost. The research concludes that the insider attack can be eliminated in the health care system using the DFIR investigation process.