Related Experiment Videos
Mapping Machine Learning-Driven Cybersecurity Solutions in Health Care: Scoping Literature Review
Kunal Rajput1, Sharukh Zuberi2, Mireille Elhajj3,4,5
1Department of Surgery and Cancer, Faculty of Medicine, Imperial College London, Faculty Building, South Kensington Campus, London, England, SW7 2AZ, United Kingdom, 44 02075895111.
Background:
Health care systems face escalating cyberattacks, including the UK Synnovis ransomware attack, which halted pathology services for 14 weeks; the Ascension Health breach affecting 5.6 million patients; and the Change Healthcare breach costing US $2.5 billion. Conventional cybersecurity measures in health care remain reactive and inadequate against evolving threats. Machine learning (ML) offers adaptive, predictive, real-time cyber defense; yet, there is limited clarity on how ML tools are applied across cybersecurity domains, their real-world effectiveness, and where gaps remain.
Objective:
This study aims to map ML applications in health care cybersecurity against the National Institute of Standards and Technology Cybersecurity Framework version 2.0, summarize ML performance, and identify research gaps and implementation considerations.
Methods:
A systematic search of Ovid MEDLINE, Embase, and Scopus was conducted on July 30, 2025, for studies between 2019 and 2025. Eligible studies applied ML-based approaches to organizational-level cybersecurity in health care settings, with outcomes related to data privacy or cybersecurity strengthening. Studies on smart devices, blockchain, or those lacking empirical data were excluded. Title and abstract and full-text screening were conducted independently by 2 (KR and SZ) reviewers following the Arksey and O'Malley framework and PRISMA-ScR (Preferred Reporting Items for Systematic Reviews and Meta-Analyses extension for Scoping Reviews) guidelines, with discrepancies resolved by consensus. Data were synthesized narratively and mapped against the 6 National Institute of Standards and Technology Cybersecurity Framework version 2.0 functions (Identify, Protect, Detect, Respond, Recover, and Govern).
Results:
From 10,348 articles identified, 45 studies across 18 countries were included, applying 80 ML models. Most studies addressed "Protect" (n=22, 48.9%), encompassing federated learning, homomorphic encryption, and deidentification pipelines. "Detect" (n=13, 28.9%) covered intrusion detection and anomaly-based threat detection. "Identify" (n=8, 17.8%) addressed risk assessment and vulnerability prediction. Only 2 studies addressed "Respond," and none addressed "Recover" or "Govern." Classical ML, deep learning, and natural language processing predominated, with intrusion detection being the most common application (n=29). Despite strong controlled performance, only one study demonstrated real-world deployment; most rely on synthetic or outdated benchmark datasets and inconsistent reporting metrics.
Conclusions:
To our knowledge, this is the first scoping review to map ML-driven cybersecurity solutions against all six National Institute of Standards and Technology Cybersecurity Framework version 2.0 functions, offering a structured, policy-relevant evidence base. ML applications remain concentrated in preincident functions, with gaps in response, recovery, and governance. This highlights systematic blind spots and priorities for researchers and implementers. The evidence supports a phased implementation approach: beginning with detection systems, where evidence is most established and integration is most feasible, progressing to privacy-preserving architectures, for which the literature currently offers no guidance. Implementation requires sustained investment in infrastructure, representative datasets, explainable AI, and real-world validation. Limitations include language bias, methodological heterogeneity, and exclusion of medical devices and proprietary solutions.