A Privacy Threat Modeling Method for Healthcare Systems under the Brazilian LGPD
The digitalization of healthcare increases privacy risks associated with sensitive data processing. Although the Brazilian General Data Protection Law (LGPD) mandates data protection, healthcare organizations often focus on generic security controls and lack structured privacy engineering to address threats such as linkability and identifiability. This paper proposes a privacy threat modeling method for healthcare systems under the LGPD. The method was evaluated through a case study involving the Nursing Process Application System (SisAPEC), a system deployed within the Brazilian Unified Health System (SUS). The method includes system modeling and systematic threat elicitation steps, which in the case study were implemented using Data Flow Diagrams and the LINDDUN framework. The application of the method identified 14 privacy threats, which were mapped to Privacy-Enhancing Requirements (PERs), establishing traceability between regulatory and technical requirements. The results indicate that the method operationalizes Privacy by Design by establishing traceability between legal requirements and architectural privacy requirements.