This research identifies security vulnerabilities in IoT-based healthcare authentication, specifically replay attacks, session key predictability, and biometric data leakage. We propose enhancements like adaptive timestamp verification and hybrid entropy sources for stronger session keys. Quantum-resistant cryptography and advanced biometric data protection are also recommended.