Related Experiment Videos
Mapping Machine Learning-Driven Cybersecurity Solutions in Health Care: Scoping Literature Review
Kunal Rajput1, Sharukh Zuberi2, Mireille Elhajj3,4,5
1Department of Surgery and Cancer, Faculty of Medicine, Imperial College London, Faculty Building, South Kensington Campus, London, England, SW7 2AZ, United Kingdom, 44 02075895111.
Journal of Medical Internet Research
|July 27, 2026
Summary
Machine learning (ML) enhances healthcare cybersecurity, but applications are concentrated in pre-incident functions like threat detection and protection. Significant gaps exist in ML for incident response, recovery, and governance, requiring focused research and investment for effective implementation.
Area of Science:
- Health Informatics
- Cybersecurity
- Artificial Intelligence
Background:
- Healthcare systems are increasingly targeted by sophisticated cyberattacks, necessitating advanced defense mechanisms.
- Conventional cybersecurity approaches are often reactive and insufficient against evolving threats.
- Machine learning (ML) presents an opportunity for adaptive, real-time cyber defense in healthcare, but its application landscape is unclear.
Purpose of the Study:
- To systematically map ML applications in healthcare cybersecurity against the NIST Cybersecurity Framework v2.0.
- To evaluate the performance and identify research gaps in ML-driven healthcare cybersecurity.
- To provide insights for future research and implementation strategies.
Main Methods:
- A systematic literature search was conducted across Ovid MEDLINE, Embase, and Scopus (2019-2025).
- Studies applying ML to organizational healthcare cybersecurity were included, excluding those on smart devices or lacking empirical data.
- Data were synthesized and mapped against the six functions of the NIST Cybersecurity Framework v2.0.
Main Results:
- 45 studies across 18 countries utilized 80 ML models, primarily focusing on 'Protect' (48.9%) and 'Detect' (28.9%) functions.
- Intrusion detection was the most common application (29 studies); 'Respond,' 'Recover,' and 'Govern' functions were significantly underrepresented.
- Most studies showed strong performance in controlled settings, but only one reported real-world deployment, often using synthetic data and inconsistent metrics.
Conclusions:
- This scoping review provides the first comprehensive mapping of ML in healthcare cybersecurity against all NIST CSF v2.0 functions.
- Current ML applications are heavily skewed towards pre-incident phases, revealing critical gaps in post-incident response, recovery, and governance.
- Phased implementation, starting with detection systems and progressing to privacy-preserving architectures, is recommended, alongside investment in infrastructure, data, explainable AI, and real-world validation.