<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v2.0 20040830//EN" "journalpublishing.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="2.0" xml:lang="en" article-type="review-article"><front><journal-meta><journal-id journal-id-type="nlm-ta">J Med Internet Res</journal-id><journal-id journal-id-type="publisher-id">jmir</journal-id><journal-id journal-id-type="index">1</journal-id><journal-title>Journal of Medical Internet Research</journal-title><abbrev-journal-title>J Med Internet Res</abbrev-journal-title><issn pub-type="epub">1438-8871</issn><publisher><publisher-name>JMIR Publications</publisher-name><publisher-loc>Toronto, Canada</publisher-loc></publisher></journal-meta><article-meta><article-id pub-id-type="publisher-id">v28i1e93950</article-id><article-id pub-id-type="doi">10.2196/93950</article-id><article-categories><subj-group subj-group-type="heading"><subject>Review</subject></subj-group></article-categories><title-group><article-title>Mapping Machine Learning&#x2013;Driven Cybersecurity Solutions in Health Care: Scoping Literature Review</article-title></title-group><contrib-group><contrib contrib-type="author" corresp="yes"><name name-style="western"><surname>Rajput</surname><given-names>Kunal</given-names></name><degrees>MBChB</degrees><xref ref-type="aff" rid="aff1">1</xref></contrib><contrib contrib-type="author"><name name-style="western"><surname>Zuberi</surname><given-names>Sharukh</given-names></name><degrees>MBBS, BSc</degrees><xref ref-type="aff" rid="aff2">2</xref></contrib><contrib contrib-type="author"><name name-style="western"><surname>Elhajj</surname><given-names>Mireille</given-names></name><degrees>PhD</degrees><xref ref-type="aff" rid="aff3">3</xref><xref ref-type="aff" rid="aff4">4</xref><xref ref-type="aff" rid="aff5">5</xref></contrib><contrib contrib-type="author"><name name-style="western"><surname>Ochieng</surname><given-names>Washington</given-names></name><degrees>BSc, MSc, PhD</degrees><xref ref-type="aff" rid="aff3">3</xref><xref ref-type="aff" rid="aff5">5</xref></contrib><contrib contrib-type="author"><name name-style="western"><surname>Darzi</surname><given-names>Ara</given-names></name><degrees>MBChB, MD</degrees><xref ref-type="aff" rid="aff1">1</xref></contrib><contrib contrib-type="author"><name name-style="western"><surname>Ghafur</surname><given-names>Saira</given-names></name><degrees>MBChB, MSc</degrees><xref ref-type="aff" rid="aff1">1</xref></contrib></contrib-group><aff id="aff1"><institution>Department of Surgery and Cancer, Faculty of Medicine, Imperial College London</institution><addr-line>Faculty Building, South Kensington Campus</addr-line><addr-line>London</addr-line><addr-line>England</addr-line><country>United Kingdom</country></aff><aff id="aff2"><institution>Department of Surgery, The Royal Free Hospital</institution><addr-line>London</addr-line><addr-line>England</addr-line><country>United Kingdom</country></aff><aff id="aff3"><institution>Department of Civil and Environmental Engineering, Faculty of Engineering, Imperial College London</institution><addr-line>London</addr-line><addr-line>England</addr-line><country>United Kingdom</country></aff><aff id="aff4"><institution>Astra-Terra Limited</institution><addr-line>London</addr-line><addr-line>England</addr-line><country>United Kingdom</country></aff><aff id="aff5"><institution>Centre for Active Resilience and Security, Imperial College London</institution><addr-line>London</addr-line><addr-line>England</addr-line><country>United Kingdom</country></aff><contrib-group><contrib contrib-type="editor"><name name-style="western"><surname>Brini</surname><given-names>Stefano</given-names></name></contrib></contrib-group><contrib-group><contrib contrib-type="reviewer"><name name-style="western"><surname>Taiwo</surname><given-names>Peter</given-names></name></contrib><contrib contrib-type="reviewer"><name name-style="western"><surname>Wani</surname><given-names>Tafheem Ahmad</given-names></name></contrib></contrib-group><author-notes><corresp>Correspondence to Kunal Rajput, MBChB, Department of Surgery and Cancer, Faculty of Medicine, Imperial College London, Faculty Building, South Kensington Campus, London, England, SW7 2AZ, United Kingdom, 44 02075895111; <email>k.rajput24@imperial.ac.uk</email></corresp></author-notes><pub-date pub-type="collection"><year>2026</year></pub-date><pub-date pub-type="epub"><day>27</day><month>7</month><year>2026</year></pub-date><volume>28</volume><elocation-id>e93950</elocation-id><history><date date-type="received"><day>22</day><month>02</month><year>2026</year></date><date date-type="rev-recd"><day>18</day><month>06</month><year>2026</year></date><date date-type="accepted"><day>23</day><month>06</month><year>2026</year></date></history><copyright-statement>&#x00A9; Kunal Rajput, Sharukh Zuberi, Mireille Elhajj, Washington Ochieng, Ara Darzi, Saira Ghafur. Originally published in the Journal of Medical Internet Research (<ext-link ext-link-type="uri" xlink:href="https://www.jmir.org">https://www.jmir.org</ext-link>), 27.7.2026. </copyright-statement><copyright-year>2026</copyright-year><license license-type="open-access" xlink:href="https://creativecommons.org/licenses/by/4.0/"><p>This is an open-access article distributed under the terms of the Creative Commons Attribution License (<ext-link ext-link-type="uri" xlink:href="https://creativecommons.org/licenses/by/4.0/">https://creativecommons.org/licenses/by/4.0/</ext-link>), which permits unrestricted use, distribution, and reproduction in any medium, provided the original work, first published in the Journal of Medical Internet Research (ISSN 1438-8871), is properly cited. The complete bibliographic information, a link to the original publication on <ext-link ext-link-type="uri" xlink:href="https://www.jmir.org/">https://www.jmir.org/</ext-link>, as well as this copyright and license information must be included.</p></license><self-uri xlink:type="simple" xlink:href="https://www.jmir.org/2026/1/e93950"/><abstract><sec><title>Background</title><p>Health care systems face escalating cyberattacks, including the UK Synnovis ransomware attack, which halted pathology services for 14 weeks; the Ascension Health breach affecting 5.6 million patients; and the Change Healthcare breach costing US $2.5 billion. Conventional cybersecurity measures in health care remain reactive and inadequate against evolving threats. Machine learning (ML) offers adaptive, predictive, real-time cyber defense; yet, there is limited clarity on how ML tools are applied across cybersecurity domains, their real-world effectiveness, and where gaps remain.</p></sec><sec><title>Objective</title><p>This study aims to map ML applications in health care cybersecurity against the National Institute of Standards and Technology Cybersecurity Framework version 2.0, summarize ML performance, and identify research gaps and implementation considerations.</p></sec><sec sec-type="methods"><title>Methods</title><p>A systematic search of Ovid MEDLINE, Embase, and Scopus was conducted on July 30, 2025, for studies between 2019 and 2025. Eligible studies applied ML-based approaches to organizational-level cybersecurity in health care settings, with outcomes related to data privacy or cybersecurity strengthening. Studies on smart devices, blockchain, or those lacking empirical data were excluded. Title and abstract and full-text screening were conducted independently by 2 (KR and SZ) reviewers following the Arksey and O&#x2019;Malley framework and PRISMA-ScR (Preferred Reporting Items for Systematic Reviews and Meta-Analyses extension for Scoping Reviews) guidelines, with discrepancies resolved by consensus. Data were synthesized narratively and mapped against the 6 National Institute of Standards and Technology Cybersecurity Framework version 2.0 functions (Identify, Protect, Detect, Respond, Recover, and Govern).</p></sec><sec sec-type="results"><title>Results</title><p>From 10,348 articles identified, 45 studies across 18 countries were included, applying 80 ML models. Most studies addressed &#x201C;Protect&#x201D; (n=22, 48.9%), encompassing federated learning, homomorphic encryption, and deidentification pipelines. &#x201C;Detect&#x201D; (n=13, 28.9%) covered intrusion detection and anomaly-based threat detection. &#x201C;Identify&#x201D; (n=8, 17.8%) addressed risk assessment and vulnerability prediction. Only 2 studies addressed &#x201C;Respond,&#x201D; and none addressed &#x201C;Recover&#x201D; or &#x201C;Govern.&#x201D; Classical ML, deep learning, and natural language processing predominated, with intrusion detection being the most common application (n=29). Despite strong controlled performance, only one study demonstrated real-world deployment; most rely on synthetic or outdated benchmark datasets and inconsistent reporting metrics.</p></sec><sec sec-type="conclusions"><title>Conclusions</title><p>To our knowledge, this is the first scoping review to map ML-driven cybersecurity solutions against all six National Institute of Standards and Technology Cybersecurity Framework version 2.0 functions, offering a structured, policy-relevant evidence base. ML applications remain concentrated in preincident functions, with gaps in response, recovery, and governance. This highlights systematic blind spots and priorities for researchers and implementers. The evidence supports a phased implementation approach: beginning with detection systems, where evidence is most established and integration is most feasible, progressing to privacy-preserving architectures, for which the literature currently offers no guidance. Implementation requires sustained investment in infrastructure, representative datasets, explainable AI, and real-world validation. Limitations include language bias, methodological heterogeneity, and exclusion of medical devices and proprietary solutions.</p></sec><sec><title>Trial Registration</title><p>OSF Registries osf.io/4cjmu; https://osf.io/4cjmu/overview</p></sec></abstract><kwd-group><kwd>machine learning</kwd><kwd>artificial intelligence</kwd><kwd>cybersecurity</kwd><kwd>healthcare systems</kwd><kwd>intrusion detection</kwd><kwd>data protection</kwd><kwd>digital health</kwd></kwd-group></article-meta></front><body><sec id="s1" sec-type="intro"><title>Introduction</title><sec id="s1-1"><title>Background</title><p>The digitization of health care through networked health information systems, electronic health record (EHR) infrastructure, cloud storage, and telemedicine has transformed care delivery but simultaneously expanded the attack surface, making the sector increasingly vulnerable to sophisticated cyberattacks [<xref ref-type="bibr" rid="ref1">1</xref>]. Recent high-profile incidents illustrate the scale of disruption. The Synnovis ransomware attack in Southeast London disrupted pathology services across 5 major hospitals and 194 primary care practices, resulting in a 14-wk suspension of blood product processing and delayed clinical diagnostics [<xref ref-type="bibr" rid="ref2">2</xref>]. The Ascension Health ransomware attack affected 5.6 million patients&#x2019; records and led to widespread disruption of clinical services, including delayed treatments and appointments [<xref ref-type="bibr" rid="ref3">3</xref>]. Change Healthcare, a subsidiary of UnitedHealth Group, incurred economic losses estimated at nearly US $2.5 billion due to billing and prescription shutdowns, highlighting the direct financial impact of cyber incidents [<xref ref-type="bibr" rid="ref4">4</xref>]. These incidents demonstrate that cyberattacks in health care can have critical impacts across multiple layers, including patient care, financial stability, and operational continuity.</p><p>Conventional cybersecurity tools, such as firewalls, antivirus software, intrusion detection systems, and access controls, rely on static rules and known threat signatures to identify and block attacks [<xref ref-type="bibr" rid="ref5">5</xref>]. Over time, as health care systems have become increasingly digitalized, these tools have evolved to include more sophisticated features, such as real-time monitoring, automated patch management, and basic anomaly detection. However, their fundamentally reactive design limits their ability to address novel or rapidly evolving cyber threats. In contrast, machine learning (ML)-based systems have shown potential to offer a more adaptive, predictive, and real-time approach to cyber defense. These models can detect anomalies without relying on predefined attack signatures and can automate responses, providing scalable and timely defense. This capability is especially important in health care, where even brief outages can threaten patient safety [<xref ref-type="bibr" rid="ref6">6</xref>].</p><p>AI represents a double-edged sword in cybersecurity. On one edge, malicious actors are increasingly using AI to orchestrate sophisticated cyberattacks capable of propagating quickly across interconnected health care systems and disrupting critical services [<xref ref-type="bibr" rid="ref7">7</xref>,<xref ref-type="bibr" rid="ref8">8</xref>]. Emerging threat intelligence reports suggest that AI tools have been used as autonomous penetration testing orchestrators, achieving high levels of autonomous execution across the cyberattack lifecycle [<xref ref-type="bibr" rid="ref8">8</xref>]. Almost three-quarters of phishing attacks now leverage AI technology, with some estimates suggesting that the majority of phishing emails now incorporate AI in some form, whether for text generation, personalization, or obfuscation [<xref ref-type="bibr" rid="ref9">9</xref>]. Conversely, AI also offers powerful defensive capabilities, enabling health care systems to adopt equally advanced AI-driven defense mechanisms that can detect anomalies in real time and automate responses to emerging threats [<xref ref-type="bibr" rid="ref10">10</xref>,<xref ref-type="bibr" rid="ref11">11</xref>]. This technological arms race, where both attackers and defenders leverage AI, underscores the critical need for health care organizations to not only implement AI-based security solutions but also establish robust governance frameworks and regulatory oversight to ensure these systems are deployed responsibly, monitored continuously, and protected against adversarial exploitation.</p><p>To date, AI adoption in health care has been predominantly concentrated on clinical domains such as medical imaging interpretation, pathology, and predictive analytics, with a strong emphasis on improving diagnostic accuracy and workflow efficiency [<xref ref-type="bibr" rid="ref12">12</xref>]. ML adoption in health care cybersecurity remains limited due to the evolving complexity of cyber threats, fragmented regulation, and reliance on human expertise for real-time decisions [<xref ref-type="bibr" rid="ref13">13</xref>]. Unlike diagnostics, where clear regulatory pathways exist, cybersecurity lacks a unified framework for ML integration. This review focuses specifically on ML, a subset of AI in which systems learn patterns from data, encompassing classical algorithms, deep learning (DL), and natural language processing (NLP). While Internet of Medical Things and smart device security represent a related concern, this review focuses on organizational-level health care systems, where ML-based cybersecurity solutions are most developed.</p><p>The UK&#x2019;s Cyber Security Strategy for Health and Adult Social Care (2023&#x2010;2030) highlights the use of AI for intelligent threat detection and system resilience [<xref ref-type="bibr" rid="ref14">14</xref>]. Similarly, the US National Cybersecurity Strategy (2023) advocates for AI-driven tools to enable real-time anomaly detection and adaptive defense. These policies reflect a growing shift toward proactive, AI-enabled cybersecurity strategies [<xref ref-type="bibr" rid="ref15">15</xref>].</p><p>The National Institute of Standards and Technology Cybersecurity Framework (NIST-CSF) 2.0, released in 2024, reinforces this shift toward proactive and adaptive cyber defense [<xref ref-type="bibr" rid="ref16">16</xref>]. The six pillars &#x201C;Identify,&#x201D; &#x201C;Protect,&#x201D; &#x201C;Detect,&#x201D; &#x201C;Respond,&#x201D; &#x201C;Recover,&#x201D; and &#x201C;Govern&#x201D; together emphasize strategic oversight, continuous improvement, and integration of emerging technologies such as ML. For health care systems, NIST-CSF offers a flexible structure to align cybersecurity efforts with operational demands, providing a domain framework for the adoption of intelligent, AI-enabled tools for real-time detection and response.</p><p>Several reviews have examined the application of AI and ML to cybersecurity more broadly. Wiafe et al [<xref ref-type="bibr" rid="ref17">17</xref>] conducted a systematic mapping of AI for cybersecurity across general computing environments, cataloging techniques across domains including intrusion detection, malware analysis, and network security. Ali et al [<xref ref-type="bibr" rid="ref18">18</xref>] provided a systematic review of AI and ML techniques for cybersecurity, and a subsequent review by the same group focused specifically on DL methods for malware and intrusion detection [<xref ref-type="bibr" rid="ref19">19</xref>]. Dhanushkodi and Thejas [<xref ref-type="bibr" rid="ref20">20</xref>] examined AI-enabled threat detection across general security contexts, highlighting advances in anomaly-based and signature-free detection. While these reviews provide valuable insights into the broader AI-cybersecurity landscape, they are not specific to health care and do not account for the sector&#x2019;s unique constraints such as the sensitivity of patient data, the criticality of service continuity, legacy infrastructure, and the complex regulatory environment governing health systems. Furthermore, existing reviews tend to focus on particular technical domains, such as intrusion detection or malware classification, without offering a comprehensive mapping of how the full breadth of ML tools aligns with an established cybersecurity governance framework applicable to health care [<xref ref-type="bibr" rid="ref21">21</xref>,<xref ref-type="bibr" rid="ref22">22</xref>].</p><p>No prior scoping review has systematically mapped ML applications in health care cybersecurity against the NIST CSF 2.0, which captures all phases of the cyber resilience lifecycle. This review addresses that gap by providing the first governance-aligned, health care&#x2013;specific synthesis of ML cybersecurity evidence organized against NIST CSF 2.0, with the explicit aim of informing organizational implementation priorities and identifying where the evidence base is critically absent.</p></sec><sec id="s1-2"><title>Objectives</title><p>This scoping review aims to systematically map ML applications to health care cybersecurity tools. The specific objectives are to:</p><list list-type="order"><list-item><p>Identify and categorize ML techniques developed in health care cybersecurity</p></list-item><list-item><p>Map ML applications across the six NIST CSF 2.0 functions (Identify, Protect, Detect, Respond, Recover, and Govern)</p></list-item><list-item><p>Characterize the health care environments and systems addressed by these applications</p></list-item><list-item><p>Analyze the methodological approaches to cyber resilience and the geographic distribution of research</p></list-item><list-item><p>Identify implementation considerations and highlight research gaps to inform future ML cybersecurity development in health care settings.</p></list-item></list></sec></sec><sec id="s2" sec-type="methods"><title>Methods</title><p>The structure of this scoping review was guided by the PRISMA-ScR (Preferred Reporting Items for Systematic Reviews and Meta-Analyses extension for Scoping Reviews) checklist (<xref ref-type="supplementary-material" rid="app3">Checklist 1</xref>). In addition, search reporting adhered to the PRISMA-S (Preferred Reporting Items for Systematic Reviews and Meta-Analyses literature search extension) guidelines [<xref ref-type="bibr" rid="ref23">23</xref>]. A completed PRISMA-S checklist is provided in <xref ref-type="supplementary-material" rid="app4">Checklist 2</xref>. The review was registered with Open Science Framework (OSF Registries 4cjmu).</p><p>Studies were selected based on the Population, Intervention, Comparison, Outcome, Study design criteria. Eligible studies were those involving organization-level cybersecurity in a health care setting, including hospitals, clinics, and health networks, where an ML-based approach was applied to enhance cyber resilience through predictive analytics, anomaly detection, and automated response. Outcomes of interest included assessments of data privacy, protection of health care data, or strengthening of cybersecurity practices. Studies primarily focused on smart or wireless health care devices or blockchain-based cybersecurity were excluded, as were nonpeer-reviewed sources including gray literature, conference abstracts, books, editorials, commentaries, case reports<bold>,</bold> review articles, and theoretical or technical concept papers without empirical evaluation.</p><p>A total of 3 electronic databases were searched: Ovid MEDLINE, Embase Classic+ Embase, and Scopus on July 30, 2025. MEDLINE and Embase Classic+ Embase were searched simultaneously via the Ovid platform as a multidatabase search; Scopus was searched separately via its native interface. Ovid MEDLINE and Embase provide comprehensive coverage of the peer-reviewed health care and biomedical literature, while Scopus offers broad multidisciplinary indexing encompassing computer science, engineering, and cybersecurity.</p><p>The search strategy was developed de novo in consultation with an expert librarian at Imperial College London and combined both medical subject headings terms for MEDLINE- and Emtree-controlled vocabulary terms for Embase with free-text terms. Boolean operators (AND, OR) were used to combine concept blocks; truncation using the asterisk wildcard and adjacency operators (adj1, adj2) were applied. Keywords included variations of the following: &#x201C;cybersecurity,&#x201D; &#x201C;cyber resilience,&#x201D; &#x201C;healthcare,&#x201D; &#x201C;health system,&#x201D; &#x201C;artificial intelligence,&#x201D; &#x201C;machine learning,&#x201D; &#x201C;data privacy,&#x201D; &#x201C;vulnerability,&#x201D; &#x201C;threat,&#x201D; and &#x201C;risk.&#x201D; Searches were limited to English language and human studies between 2019 and 2025. Additional studies were identified through reference list screening from included articles. No websites, tables of contents, or print sources were purposefully browsed, and no authors, experts, or manufacturers were contacted to identify additional studies. Gray literature, study registries, and other sources were not searched, and formal peer review of the search strategy was not conducted. Following reviewer and editor feedback, the search strategy was revised and rerun during the revision process; however, the search end date of July 30, 2025, was retained as the fixed time horizon for the review. No email alerts were used. Full search strategies for all 3 databases are available in <xref ref-type="supplementary-material" rid="app1">Multimedia Appendix 1</xref>.</p><p>Study selection was conducted in two phases using the Covidence platform (developed by Veritas Health Innovation). A total of two independent reviewers (KR and SZ) conducted titles or abstracts screening and full-text screening. Any discrepancies were resolved through discussion. In keeping with scoping review methodology, no formal critical appraisal or risk of bias assessment was conducted. Data extraction elements were defined prospectively and refined following preliminary searches to provide a comprehensive overview of ML applications in health care cybersecurity and to capture the breadth of study designs, health care settings, ML techniques, and NIST framework classifications. A standardized data extraction form was developed in Microsoft Excel and validated by research team members with expertise in health care cybersecurity and AI (SG and WO). Data extraction was completed by one author (KR) and independently checked by a second reviewer (SZ), with discrepancies resolved through discussion. The extracted information included study characteristics (lead author, year of publication, study design, and country of authorship), AI model type, training data source, performance metrics (eg, accuracy, precision, recall, <italic>F</italic><sub>1</sub>-score, and area under the receiver operating characteristic), and reported ML-based cyber resilience domain, such as anomaly detection, data privacy protection, intrusion detection, threat analysis, and risk assessment. Performance metrics were extracted as reported by study authors; given heterogeneity in metrics used, validation approaches, and dataset types across studies, cross-study comparison of performance figures was not reported.</p><p>Studies were systematically categorized and mapped against the NIST CSF 2.0 functions as the organizing structure, classifying evidence across the six core functions: Identify, Protect, Detect, Respond, Recover, and Govern. Classification was completed by one author (KR) and independently checked by a second reviewer (SZ), with discrepancies resolved through discussion. Each study was assigned to a single NIST CSF 2.0 function based on its primary cybersecurity objective. Within each thematic domain, studies were compared by ML technique, health care environment, cybersecurity application, study design, and key findings. Results are presented using a combination of narrative description and visual representations.</p></sec><sec id="s3" sec-type="results"><title>Results</title><sec id="s3-1"><title>Study Characteristics</title><p>There were 10,348 articles identified from the database search. After removing 2014 duplicates, the remaining records were screened by title and abstract by two independent reviewers (KR and SZ), resulting in 530 articles selected for full-text review. <xref ref-type="fig" rid="figure1">Figure 1</xref> summarizes the PRISMA-ScR flowchart of the study.</p><fig position="float" id="figure1"><label>Figure 1.</label><caption><p>PRISMA-ScR (Preferred Reporting Items for Systematic reviews and Meta-Analyses for Scoping Reviews) flow diagram illustrating the identification, screening, eligibility assessment, and inclusion of peer-reviewed studies examining machine learning applications in health care cybersecurity, drawn from systematic searches of Ovid MEDLINE, Embase, and Scopus conducted on July 30, 2025 (search period: 2019&#x2010;2025).</p></caption><graphic alt-version="no" mimetype="image" position="float" xlink:type="simple" xlink:href="jmir_v28i1e93950_fig01.png"/></fig><p>Following independent full-text review, 45 [<xref ref-type="bibr" rid="ref24">24</xref>-<xref ref-type="bibr" rid="ref68">68</xref>] global studies (including 1 from citation search) were finalized for analysis. These were conducted across 18 countries and applied 80 ML models to diverse datasets in health care cybersecurity. <xref ref-type="table" rid="table1">Table 1</xref> summarizes the study characteristics of the included studies. China (7/45, 15.6%) and India (7/45, 15.6%) had the highest representation among included studies. The studies were conducted across diverse health care environments, most commonly health care systems (17/45, 37.8%), followed by electronic health records (7/45, 15.6%), medical data (6/45, 13.3%), health care networks (5/45, 11.1%), and others. ML models were trained on diverse sources, including real-world health care data, cybersecurity or network datasets, and synthetic or benchmark datasets. Included studies varied considerably in dataset size and type, encompassing network traffic samples, patient records, email corpora, NLP token sets, and cyberattack event logs, reflecting the heterogeneous data environments across health care cybersecurity research.</p><table-wrap id="t1" position="float"><label>Table 1.</label><caption><p>Characteristics of 45 peer-reviewed studies included in a scoping review of machine learning applications in health care cybersecurity, identified through systematic searches of Ovid MEDLINE, Embase, and Scopus on July 30, 2025 (2019&#x2010;2025), categorized by study design, country of first author, and health care environment.</p></caption><table id="table1" frame="hsides" rules="groups"><thead><tr><td align="left" valign="bottom">Category</td><td align="left" valign="bottom">Number of studies (N=45), n (%)</td><td align="left" valign="bottom">References</td></tr></thead><tbody><tr><td align="left" valign="top" colspan="3">Study type</td></tr><tr><td align="left" valign="top"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Quasi-experimental study</td><td align="left" valign="top">41 (91.1)</td><td align="left" valign="top">Silvestri et al [<xref ref-type="bibr" rid="ref24">24</xref>], Islam et al [<xref ref-type="bibr" rid="ref25">25</xref>], Li and Wang [<xref ref-type="bibr" rid="ref26">26</xref>], Yi et al [<xref ref-type="bibr" rid="ref27">27</xref>], Yusof et al [<xref ref-type="bibr" rid="ref28">28</xref>], Liu et al [<xref ref-type="bibr" rid="ref29">29</xref>], Sheu et al [<xref ref-type="bibr" rid="ref30">30</xref>], Nguyen et al [<xref ref-type="bibr" rid="ref31">31</xref>], Kumar et al [<xref ref-type="bibr" rid="ref32">32</xref>], Almousa et al [<xref ref-type="bibr" rid="ref33">33</xref>], S and S [<xref ref-type="bibr" rid="ref34">34</xref>], Gao et al [<xref ref-type="bibr" rid="ref35">35</xref>], Altalla&#x2019; et al [<xref ref-type="bibr" rid="ref36">36</xref>], Mesfer Aldossary [<xref ref-type="bibr" rid="ref37">37</xref>], Akter et al [<xref ref-type="bibr" rid="ref38">38</xref>], Jonnagaddala et al [<xref ref-type="bibr" rid="ref39">39</xref>], Samiayya et al [<xref ref-type="bibr" rid="ref40">40</xref>], Tabassum et al [<xref ref-type="bibr" rid="ref41">41</xref>], Hurst et al [<xref ref-type="bibr" rid="ref42">42</xref>], Saranya et al [<xref ref-type="bibr" rid="ref43">43</xref>], &#x00D6;zt&#x00FC;rk et al [<xref ref-type="bibr" rid="ref44">44</xref>], Wazid et al [<xref ref-type="bibr" rid="ref45">45</xref>], Sengan et al [<xref ref-type="bibr" rid="ref46">46</xref>], Thanh et al [<xref ref-type="bibr" rid="ref47">47</xref>], Alanazi [<xref ref-type="bibr" rid="ref48">48</xref>], Ahmed and Shakir [<xref ref-type="bibr" rid="ref49">49</xref>], Halman and Alenazi [<xref ref-type="bibr" rid="ref50">50</xref>], Asif et al [<xref ref-type="bibr" rid="ref51">51</xref>], Qiao et al [<xref ref-type="bibr" rid="ref52">52</xref>], Fern&#x00E1;ndez Maim&#x00F3; et al [<xref ref-type="bibr" rid="ref53">53</xref>], Abidi et al [<xref ref-type="bibr" rid="ref54">54</xref>], Huang et al [<xref ref-type="bibr" rid="ref58">58</xref>], An et al [<xref ref-type="bibr" rid="ref59">59</xref>], Bo et al [<xref ref-type="bibr" rid="ref60">60</xref>], Akter et al [<xref ref-type="bibr" rid="ref62">62</xref>], Ganguli et al [<xref ref-type="bibr" rid="ref63">63</xref>], Alzubi et al [<xref ref-type="bibr" rid="ref64">64</xref>], Cabrero-Holgueras et al [<xref ref-type="bibr" rid="ref65">65</xref>], Mohammadi et al [<xref ref-type="bibr" rid="ref66">66</xref>], Goldschmidt et al [<xref ref-type="bibr" rid="ref67">67</xref>], Gwon et al [<xref ref-type="bibr" rid="ref68">68</xref>].</td></tr><tr><td align="left" valign="top"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Observational study</td><td align="left" valign="top">4 (8.9)</td><td align="left" valign="top">Islam et al [<xref ref-type="bibr" rid="ref25">25</xref>], &#x00DC;n&#x00F6;zkan et al [<xref ref-type="bibr" rid="ref55">55</xref>], Dolezel et al [<xref ref-type="bibr" rid="ref56">56</xref>], Gupta et al [<xref ref-type="bibr" rid="ref57">57</xref>].</td></tr><tr><td align="left" valign="top" colspan="3">Country of first author</td></tr><tr><td align="left" valign="top"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>China</td><td align="left" valign="top">7 (15.6)</td><td align="left" valign="top">Li et al [<xref ref-type="bibr" rid="ref26">26</xref>], Yi et al [<xref ref-type="bibr" rid="ref27">27</xref>], Gao et al [<xref ref-type="bibr" rid="ref35">35</xref>], Qiao et al [<xref ref-type="bibr" rid="ref52">52</xref>], Huang et al [<xref ref-type="bibr" rid="ref58">58</xref>], An et al [<xref ref-type="bibr" rid="ref59">59</xref>], Bo et al [<xref ref-type="bibr" rid="ref60">60</xref>].</td></tr><tr><td align="left" valign="top"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>India</td><td align="left" valign="top">7 (15.6)</td><td align="left" valign="top">S and S [<xref ref-type="bibr" rid="ref34">34</xref>], Samiayya et al [<xref ref-type="bibr" rid="ref40">40</xref>], Saranya et al [<xref ref-type="bibr" rid="ref43">43</xref>], Wazid et al [<xref ref-type="bibr" rid="ref45">45</xref>], Sengan et al [<xref ref-type="bibr" rid="ref46">46</xref>], Gupta et al [<xref ref-type="bibr" rid="ref57">57</xref>], Kaur et al [<xref ref-type="bibr" rid="ref61">61</xref>].</td></tr><tr><td align="left" valign="top"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Saudi Arabia</td><td align="left" valign="top">5 (11.1)</td><td align="left" valign="top">Almousa and Uliyan [<xref ref-type="bibr" rid="ref33">33</xref>], Mesfer Aldossary [<xref ref-type="bibr" rid="ref37">37</xref>], Alanazi [<xref ref-type="bibr" rid="ref48">48</xref>], Halman and Alenazi [<xref ref-type="bibr" rid="ref50">50</xref>], Abidi et al [<xref ref-type="bibr" rid="ref54">54</xref>].</td></tr><tr><td align="left" valign="top"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Australia</td><td align="left" valign="top">5 (11.1)</td><td align="left" valign="top">Liu et al [<xref ref-type="bibr" rid="ref29">29</xref>], Nguyen et al [<xref ref-type="bibr" rid="ref31">31</xref>], Akter et al [<xref ref-type="bibr" rid="ref38">38</xref>], Jonnagaddala et al [<xref ref-type="bibr" rid="ref39">39</xref>], Akter et al [<xref ref-type="bibr" rid="ref62">62</xref>].</td></tr><tr><td align="left" valign="top"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>United Kingdom</td><td align="left" valign="top">3 (6.7)</td><td align="left" valign="top">Islam et al [<xref ref-type="bibr" rid="ref25">25</xref>], Tabassum et al [<xref ref-type="bibr" rid="ref41">41</xref>], Hurst et al [<xref ref-type="bibr" rid="ref42">42</xref>].</td></tr><tr><td align="left" valign="top"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Turkey</td><td align="left" valign="top">2 (4.4)</td><td align="left" valign="top">&#x00D6;zt&#x00FC;rk et al [<xref ref-type="bibr" rid="ref44">44</xref>], Wazid et al [<xref ref-type="bibr" rid="ref45">45</xref>].</td></tr><tr><td align="left" valign="top"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>United States</td><td align="left" valign="top">2 (4.4)</td><td align="left" valign="top">Dolezel et al [<xref ref-type="bibr" rid="ref56">56</xref>], Ganguli et al [<xref ref-type="bibr" rid="ref63">63</xref>].</td></tr><tr><td align="left" valign="top"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Jordan</td><td align="left" valign="top">2 (4.4)</td><td align="left" valign="top">[<xref ref-type="bibr" rid="ref36">36</xref>,<xref ref-type="bibr" rid="ref64">64</xref>] Altalla&#x2019; et al [<xref ref-type="bibr" rid="ref36">36</xref>], Alzubi et al [<xref ref-type="bibr" rid="ref64">64</xref>].</td></tr><tr><td align="left" valign="top"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Spain</td><td align="left" valign="top">2 (4.4)</td><td align="left" valign="top">Fern&#x00E1;ndez Maim&#x00F3; et al [<xref ref-type="bibr" rid="ref53">53</xref>], Cabrero-Holgueras [<xref ref-type="bibr" rid="ref65">65</xref>].</td></tr><tr><td align="left" valign="top"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Other countries</td><td align="left" valign="top">10 (22.2)</td><td align="left" valign="top">Silvestri et al [<xref ref-type="bibr" rid="ref24">24</xref>], Yusof et al [<xref ref-type="bibr" rid="ref28">28</xref>], Sheu et al [<xref ref-type="bibr" rid="ref30">30</xref>], Kumar et al [<xref ref-type="bibr" rid="ref32">32</xref>], Thanh et al [<xref ref-type="bibr" rid="ref47">47</xref>], Ahmed and Shakir [<xref ref-type="bibr" rid="ref49">49</xref>], Asif et al [<xref ref-type="bibr" rid="ref51">51</xref>], Mohammadi et al [<xref ref-type="bibr" rid="ref66">66</xref>], Goldschmidt et al [<xref ref-type="bibr" rid="ref67">67</xref>], Gwon et al [<xref ref-type="bibr" rid="ref68">68</xref>].</td></tr><tr><td align="left" valign="top" colspan="3">Health care environment</td></tr><tr><td align="left" valign="top"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Health care systems</td><td align="left" valign="top">17 (37.8)</td><td align="left" valign="top">Akter et al [<xref ref-type="bibr" rid="ref38">38</xref>], Jonnagaddala et al, &#x00D6;zt&#x00FC;rk et al [<xref ref-type="bibr" rid="ref44">44</xref>], Wazid et al [<xref ref-type="bibr" rid="ref45">45</xref>], Sengan et al [<xref ref-type="bibr" rid="ref46">46</xref>], Alanazi [<xref ref-type="bibr" rid="ref48">48</xref>], Ahmed and Shakir [<xref ref-type="bibr" rid="ref49">49</xref>], Halman and Alenazi [<xref ref-type="bibr" rid="ref50">50</xref>], Asif et al [<xref ref-type="bibr" rid="ref51">51</xref>], Abidi et al [<xref ref-type="bibr" rid="ref54">54</xref>], &#x00DC;n&#x00F6;zkan et al [<xref ref-type="bibr" rid="ref55">55</xref>], Dolezel et al [<xref ref-type="bibr" rid="ref56">56</xref>], An et al [<xref ref-type="bibr" rid="ref59">59</xref>], Kaur et al [<xref ref-type="bibr" rid="ref61">61</xref>], Akter et al [<xref ref-type="bibr" rid="ref62">62</xref>], Ganguli et al [<xref ref-type="bibr" rid="ref63">63</xref>], Mohammadi et al [<xref ref-type="bibr" rid="ref66">66</xref>].</td></tr><tr><td align="left" valign="top"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Electronic health records</td><td align="left" valign="top">7 (15.6)</td><td align="left" valign="top">Liu et al [<xref ref-type="bibr" rid="ref29">29</xref>], Kumar et al [<xref ref-type="bibr" rid="ref32">32</xref>], Tabassum et al [<xref ref-type="bibr" rid="ref41">41</xref>], Hurst et al [<xref ref-type="bibr" rid="ref42">42</xref>], Gupta et al [<xref ref-type="bibr" rid="ref57">57</xref>], Goldschmidt et al [<xref ref-type="bibr" rid="ref67">67</xref>], Gwon et al [<xref ref-type="bibr" rid="ref68">68</xref>]. Jonnagaddala et al [<xref ref-type="bibr" rid="ref39">39</xref>].</td></tr><tr><td align="left" valign="top"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Medical data</td><td align="left" valign="top">6 (13.3)</td><td align="left" valign="top">Sheu et al [<xref ref-type="bibr" rid="ref30">30</xref>], Nguyen et al [<xref ref-type="bibr" rid="ref31">31</xref>], Gao et al [<xref ref-type="bibr" rid="ref35">35</xref>], Altalla&#x2019; et al [<xref ref-type="bibr" rid="ref36">36</xref>], Alzubi et al [<xref ref-type="bibr" rid="ref64">64</xref>], Cabrero-Holgueras et al [<xref ref-type="bibr" rid="ref65">65</xref>].</td></tr><tr><td align="left" valign="top"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Health care networks</td><td align="left" valign="top">5 (11.1)</td><td align="left" valign="top">Li et al [<xref ref-type="bibr" rid="ref26">26</xref>], Samiayya et al [<xref ref-type="bibr" rid="ref40">40</xref>], Saranya et al [<xref ref-type="bibr" rid="ref43">43</xref>], Thanh et al [<xref ref-type="bibr" rid="ref47">47</xref>], Qiao et al [<xref ref-type="bibr" rid="ref52">52</xref>].</td></tr><tr><td align="left" valign="top"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Medical images and imaging systems</td><td align="left" valign="top">4 (8.9)</td><td align="left" valign="top">S and S [<xref ref-type="bibr" rid="ref34">34</xref>], Mesfer Aldossary [<xref ref-type="bibr" rid="ref37">37</xref>], Huang et al [<xref ref-type="bibr" rid="ref58">58</xref>], Bo et al [<xref ref-type="bibr" rid="ref60">60</xref>].</td></tr><tr><td align="left" valign="top"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Cyber-physical systems</td><td align="left" valign="top">3 (6.7)</td><td align="left" valign="top">Silvestri et al [<xref ref-type="bibr" rid="ref24">24</xref>], Yi et al [<xref ref-type="bibr" rid="ref27">27</xref>], Fern&#x00E1;ndez et al [<xref ref-type="bibr" rid="ref53">53</xref>].</td></tr><tr><td align="left" valign="top"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Health care infrastructure</td><td align="left" valign="top">1 (2.2)</td><td align="left" valign="top">Yusof et al [<xref ref-type="bibr" rid="ref28">28</xref>].</td></tr><tr><td align="left" valign="top"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Employee email</td><td align="left" valign="top">1 (2.2)</td><td align="left" valign="top">Almousa et al [<xref ref-type="bibr" rid="ref33">33</xref>].</td></tr><tr><td align="left" valign="top"><named-content content-type="indent">&#x00A0;&#x00A0;&#x00A0;&#x00A0;</named-content>Supply chain</td><td align="left" valign="top">1 (2.2)</td><td align="left" valign="top">Islam et al [<xref ref-type="bibr" rid="ref25">25</xref>].</td></tr></tbody></table></table-wrap><p><xref ref-type="fig" rid="figure2">Figure 2</xref> presents the annual publication volumes. Notably, between 2019 and 2021, the number of publications examining ML and cybersecurity in health care remained consistently low. However, 2022 marked a turning point, with a sharp increase in publications. This upward trend persisted through 2024.</p><p>The distribution of ML techniques across cybersecurity applications is summarized in <xref ref-type="fig" rid="figure3">Figure 3</xref>. Classical ML (n=33) and DL (n=27) demonstrated the widest application breadth, with both predominantly used for privacy prevention (n=14) and intrusion detection (n=15). Overall, intrusion detection represented the most common application across all techniques (n=29).</p><fig position="float" id="figure2"><label>Figure 2.</label><caption><p>Annual publication trend of 45 peer-reviewed studies examining machine learning applications in health care cybersecurity, identified through systematic searches of Ovid MEDLINE, Embase, and Scopus (search period: 2019&#x2010;2025; search date: July 30, 2025), illustrating year-on-year growth in research output from 2019 to 2025.</p></caption><graphic alt-version="no" mimetype="image" position="float" xlink:type="simple" xlink:href="jmir_v28i1e93950_fig02.png"/></fig><fig position="float" id="figure3"><label>Figure 3.</label><caption><p>Distribution of machine learning technique categories (classical machine learning, deep learning, natural language processing, and federated learning) across cybersecurity application domains (privacy-preserving, intrusion detection, risk assessment, threat analysis, and data leakage prevention) in 45 peer-reviewed studies of health care cybersecurity (2019&#x2010;2025). Multiple ML models were applied in most studies; therefore, the total number of ML techniques (n=80) exceeds the number of reviewed papers (n=45). CML: classic machine learning; DL: deep learning; FL: federated learning; NLP: natural language processing.</p></caption><graphic alt-version="no" mimetype="image" position="float" xlink:type="simple" xlink:href="jmir_v28i1e93950_fig03.png"/></fig></sec><sec id="s3-2"><title>Distribution of ML Applications Across NIST Cybersecurity Framework Functions</title><p>The distribution reveals a pronounced concentration in preincident functions, with Protect, Detect, and Identify collectively accounting for 43 [<xref ref-type="bibr" rid="ref23">23</xref>-<xref ref-type="bibr" rid="ref52">52</xref>, <xref ref-type="bibr" rid="ref55">55</xref>-<xref ref-type="bibr" rid="ref67">67</xref>] of the 45 included studies (95.6%). The &#x201C;Protect&#x201D; function (22/45, 48.9%) emerged as the most prominent area of ML application, with applications centered on privacy-preserving technologies, data leakage prevention, sensitive information identification, physical isolation mechanisms, asynchronous transfer protocols, and antispoofing measures. Notable among these were privacy-preserving ML techniques, including federated learning approaches. The &#x201C;Detect&#x201D; function (13/45, 28.9%) represented the second major application area, encompassing intrusion detection and mitigation, anomaly-based threat detection, spear phishing attack detection, and impact mitigation. The &#x201C;Identify&#x201D; function (8/45, 17.8%) showed moderate representation, with studies focusing on risk assessment and prioritization, predictive analytics, threat prediction and analysis, vulnerability detection, and predictive analysis models. These applications demonstrated a proactive approach to cybersecurity through anticipatory capabilities.</p><p>The &#x201C;Respond&#x201D; function received limited attention, with only two specific applications identified: ransomware spread mitigation and threat detection and blocking. The &#x201C;Recover&#x201D; and &#x201C;Govern&#x201D; functions received no representation from the reviewed literature (<xref ref-type="fig" rid="figure4">Figure 4</xref>). Classical ML and DL dominated across all represented functions, concentrated within Protect and Detect; no ML technique was applied to the Govern or Recover functions (<xref ref-type="fig" rid="figure5">Figure 5</xref>). Detailed findings for the studies included in each function are presented in the following sections. <xref ref-type="supplementary-material" rid="app2">Multimedia Appendix 2</xref> [<xref ref-type="bibr" rid="ref24">24</xref>-<xref ref-type="bibr" rid="ref68">68</xref>] provides a table that summarizes the included studies with the lead author, year of publication, and main author country of authorship.</p><fig position="float" id="figure4"><label>Figure 4.</label><caption><p>Distribution of 45 peer-reviewed studies examining machine learning&#x2013;based cyber resilience tools in healthcare settings (2019&#x2010;2025) across the six core functions of the National Institute of Standards and Technology Cybersecurity Framework, version 2.0 (NIST CSF 2.0) [<xref ref-type="bibr" rid="ref16">16</xref>]: Identify, Protect, Detect, Respond, Recover, and Govern. Studies were identified through systematic searches of Ovid MEDLINE, Embase, and Scopus conducted on July 30, 2025. NIST: National Institute of Standards and Technology.</p></caption><graphic alt-version="no" mimetype="image" position="float" xlink:type="simple" xlink:href="jmir_v28i1e93950_fig04.png"/></fig><fig position="float" id="figure5"><label>Figure 5.</label><caption><p>Bubble chart mapping machine learning technique categories against NIST CSF 2.0 (National Institute of Standards and Technology Cybersecurity framework 2.0) functions, with bubble size proportional to the number of included studies (range: 1&#x2010;23). Classical machine learning applied to threat detection (n=23) and deep learning applied to protective controls (n=18) dominated the evidence base. No studies addressed the Govern or Recover functions, representing critical gaps in the application of machine learning to health care cybersecurity governance and resilience. CST: Cybersecurity framework; ML: Machine learning; NIST: National Institute of Standards and Technology [<xref ref-type="bibr" rid="ref16">16</xref>].</p></caption><graphic alt-version="no" mimetype="image" position="float" xlink:type="simple" xlink:href="jmir_v28i1e93950_fig05.png"/></fig></sec><sec id="s3-3"><title>Protect Function</title><p>Of the 45 studies, 22 studies [<xref ref-type="bibr" rid="ref29">29</xref>-<xref ref-type="bibr" rid="ref39">39</xref>,<xref ref-type="bibr" rid="ref57">57</xref>-<xref ref-type="bibr" rid="ref60">60</xref>,<xref ref-type="bibr" rid="ref62">62</xref>-<xref ref-type="bibr" rid="ref68">68</xref>] focused on the &#x201C;Protect&#x201D; function, collectively encompassing 295,201 patient records, 1,073,101 public data samples, 38,514 discharge summaries, and 100 test instances. The main focus was on privacy-preserving and data protection techniques (n=19), with some studies addressing physical or network isolation and antispoofing measures.</p><p>Techniques clustered around cryptographic and decentralized learning approaches include computation on encrypted data [<xref ref-type="bibr" rid="ref32">32</xref>] using homomorphic encryption (HE) variants, attribute-based schemes, and elliptic-curve methods [<xref ref-type="bibr" rid="ref29">29</xref>,<xref ref-type="bibr" rid="ref39">39</xref>,<xref ref-type="bibr" rid="ref57">57</xref>]. Deidentification pipelines such as Open De-Identification and hybrid NLP or ML approaches that remove or replace sensitive health information with realistic surrogates. Generative models such as generative adversarial networks (GANs), deepGAN [<xref ref-type="bibr" rid="ref34">34</xref>,<xref ref-type="bibr" rid="ref37">37</xref>], and local differentially private GANs [<xref ref-type="bibr" rid="ref68">68</xref>] that produce synthetic medical data unlinked to individuals. Additionally, federated learning (FL), which enables collaborative model training across decentralized data sources without centralizing raw data, is further enhanced by differential-privacy extensions [<xref ref-type="bibr" rid="ref31">31</xref>,<xref ref-type="bibr" rid="ref66">66</xref>].</p><p>HE enabled computation on encrypted data (including packed [<xref ref-type="bibr" rid="ref65">65</xref>] and fully HE variants [<xref ref-type="bibr" rid="ref30">30</xref>] for medical images); FL and decentralized or relay frameworks preserved data sovereignty while supporting collaborative model training [<xref ref-type="bibr" rid="ref38">38</xref>,<xref ref-type="bibr" rid="ref59">59</xref>,<xref ref-type="bibr" rid="ref60">60</xref>]. Ensemble techniques targeted data leakage and integrity (NLP and artificial neural network) [<xref ref-type="bibr" rid="ref67">67</xref>] and automated phishing detection (Multinomial Na&#x00EF;ve Bayes, support vector machine [SVM], convolutional neural network [CNN], long short-term memory [LSTM]) [<xref ref-type="bibr" rid="ref33">33</xref>]. Network flow watermarking techniques have been used for real-time privacy and data leakage detection methods in digital health care systems, with particular application in medical image protection [<xref ref-type="bibr" rid="ref58">58</xref>]. ChatGPT-3.5 and GPT-4 (OpenAI) were tested for clinical note deidentification and synthetic data generation [<xref ref-type="bibr" rid="ref36">36</xref>]. Unlike locally deployed open-weight models, these are application programming interface&#x2013;based systems without publicly available weights; testing on clinical text therefore involves transmitting potentially identifiable data to third-party infrastructure, a data governance exposure that is absent when using locally hosted alternatives.</p><p>Reported outcomes were generally strong, with FL studies commonly reporting accuracies in the 90%&#x2010;99% range, under controlled or simulated conditions [<xref ref-type="bibr" rid="ref31">31</xref>,<xref ref-type="bibr" rid="ref38">38</xref>,<xref ref-type="bibr" rid="ref59">59</xref>,<xref ref-type="bibr" rid="ref62">62</xref>,<xref ref-type="bibr" rid="ref66">66</xref>]. Open De-Identification and NLP pipelines achieved high precision and <italic>F</italic><sub>1</sub>-scores (eg, Open De-Identification: precision 95.4%, <italic>F</italic><sub>1</sub>-score 92.2%) [<xref ref-type="bibr" rid="ref29">29</xref>,<xref ref-type="bibr" rid="ref39">39</xref>,<xref ref-type="bibr" rid="ref57">57</xref>,<xref ref-type="bibr" rid="ref67">67</xref>,<xref ref-type="bibr" rid="ref68">68</xref>]. Several GAN or large language model approaches reported accuracies over 82% up to &#x2248;99% [<xref ref-type="bibr" rid="ref35">35</xref>,<xref ref-type="bibr" rid="ref37">37</xref>,<xref ref-type="bibr" rid="ref60">60</xref>,<xref ref-type="bibr" rid="ref63">63</xref>]. Large-scale phishing detection achieved &#x2248;99.4% accuracy across 525,754 emails, as reported by study authors [<xref ref-type="bibr" rid="ref33">33</xref>]. Notably, an Open De-Identification pipeline was reported to be deployed in real time at a tertiary hospital and demonstrated more than 90% performance on privacy tasks using real EHR datasets [<xref ref-type="bibr" rid="ref29">29</xref>]. Reported outcomes suggest strong technical performance for privacy tasks; however, evaluations were heterogeneous, metrics were inconsistently reported, and few studies included external or operational validation.</p></sec><sec id="s3-4"><title>Detect Function</title><p>There were 13 studies belonging to the &#x201C;Detect&#x201D; function. These include a total of 1,070,777 EHR entries, 41,403 attack events, and 777,983 public data records [<xref ref-type="bibr" rid="ref40">40</xref>-<xref ref-type="bibr" rid="ref52">52</xref>]. Cyber resilience techniques include intrusion detection (n=8), intrusion detection with mitigation or prevention (n=2), and other single-instance methods such as anomaly, insider-threat, spear phishing, and impact-mitigation detection.</p><p>Classical ML techniques such as SVM, decision tree (DT), random forest (RF), K-nearest neighbor (KNN), Na&#x00EF;ve Bayes, logistic regression, and gradient-boosted learners such as extreme gradient boosting (XGBoost) or adaptive boosting [<xref ref-type="bibr" rid="ref42">42</xref>,<xref ref-type="bibr" rid="ref44">44</xref>,<xref ref-type="bibr" rid="ref49">49</xref>,<xref ref-type="bibr" rid="ref50">50</xref>] formed the backbone of many studies and were used to detect EHR data misuse and to classify different attack types. Ensemble and hybrid schemes combined multiple classical learners (eg, a combination of SVM, KNN, DT, or RF ensembles) and reported that ensemble approaches delivered competitive accuracy with added stability across attack types in simulated evaluations [<xref ref-type="bibr" rid="ref45">45</xref>]. DL Architectures (CNNs, LSTMs, gated recurrent units) and bespoke neural networks such as ImmuneNet and hybrid deep frameworks predominated where high-dimensional or sequential inputs were required (network flows, email text, and time-series vitals) [<xref ref-type="bibr" rid="ref40">40</xref>,<xref ref-type="bibr" rid="ref47">47</xref>,<xref ref-type="bibr" rid="ref48">48</xref>]. These models frequently produced near-perfect benchmark scores (many reports more than 99% accuracy on public datasets under controlled testing conditions) at the cost of greater computational complexity. Unsupervised and semisupervised methods (isolation forest, local outlier factor, and other anomaly detectors) were used either standalone for novelty detection or as prelabeling steps to bootstrap supervised training; studies that combined unsupervised labeling with downstream classifiers showed strong sensitivity for contextual anomalies [<xref ref-type="bibr" rid="ref41">41</xref>,<xref ref-type="bibr" rid="ref45">45</xref>]. Studies also explored specialized multimodal fusion architectures integrating CNN, LSTM, or gated recurrent units feature streams for richer representation detection rate on the publicly available dataset, and bio-inspired or swarm-intelligence methods (eg, swarm-based network watermarking) for robust, low-overhead detection and real-time data-leakage protection [<xref ref-type="bibr" rid="ref52">52</xref>].</p></sec><sec id="s3-5"><title>Identify Function</title><p>There were eight studies in the &#x201C;Identify&#x201D; function, including 352 cyberattack events, 51 expert annotations, 514,220 NLP tokens, 1000 execution paths, 65,536 network packets, and 825 county-level data points [<xref ref-type="bibr" rid="ref24">24</xref>-<xref ref-type="bibr" rid="ref28">28</xref>,<xref ref-type="bibr" rid="ref55">55</xref>,<xref ref-type="bibr" rid="ref56">56</xref>,<xref ref-type="bibr" rid="ref61">61</xref>]. Studies focused primarily on risk assessment (n=5) and predictive analysis (n=3).</p><p>Studies demonstrated ML applications across cybersecurity risk assessment and vulnerability prediction in health care settings. Predictive models for hospital data breaches and security vulnerability assessment and their potential to evolve into usable exploits were developed from classical learners (KNN, SVM, DT, RF) [<xref ref-type="bibr" rid="ref25">25</xref>,<xref ref-type="bibr" rid="ref55">55</xref>,<xref ref-type="bibr" rid="ref56">56</xref>]. Probabilistic approaches such as Bayesian networks [<xref ref-type="bibr" rid="ref28">28</xref>] and fuzzy or knowledge-based systems (adaptive neuro-fuzzy inference system) [<xref ref-type="bibr" rid="ref61">61</xref>] were applied to security risk assessment during health care web application development, reporting strong performance on the datasets evaluated. Deep neural networks (stacked autoencoders and deep neural networks) developed a hospital computer network information security risk assessment [<xref ref-type="bibr" rid="ref26">26</xref>,<xref ref-type="bibr" rid="ref28">28</xref>]. An intelligent vulnerability detector for healthcare cyber-physical systems used recurrent neural network/LSTM architectures to identify vulnerabilities [<xref ref-type="bibr" rid="ref27">27</xref>]. NLP pipelines were applied to large text corpora to extract threat and vulnerability intelligence [<xref ref-type="bibr" rid="ref26">26</xref>]. However, these studies were simulation-based, used heterogeneous datasets, and inconsistently reported evaluation metrics, limiting cross-study comparability. Where provided, point estimates included KNN &#x2248;87% (prediction accuracy), a top NLP study reporting 99.8% accuracy (with precision 96.6% and <italic>F</italic><sub>1</sub>-score 87.5%), a Bayesian network reporting 75% accuracy (recall 73%), and an SVM model achieving 83.1% accuracy (precision 65.1%, recall 58.3%, and <italic>F</italic><sub>1</sub>-score 61.5%).</p></sec><sec id="s3-6"><title>Respond Function</title><p>A total of Two studies belonged to the &#x201C;Respond&#x201D; function of the NIST-CSF 2.0. One study explored ransomware spread mitigation involving 150,537 ransomware datasets, and the other focused on intrusion mitigation using 16,000 patient vital signs [<xref ref-type="bibr" rid="ref53">53</xref>,<xref ref-type="bibr" rid="ref54">54</xref>]. A real-time ransomware detection system used SVM for anomaly detection and Na&#x00EF;ve Bayes for classification. Integrating software-defined networking and network function virtualization, it isolated and replaced infected systems, mitigating attacks in under 30 seconds, faster than the typical 1-minute spread [<xref ref-type="bibr" rid="ref53">53</xref>]. The second study proposed a crossover-based multilayer perceptron model&#x2013;detected attacks on EHR and promptly alerted health care professionals to prevent data leakage. Experimental results on synthetic and real-world datasets showed the crossover-based multilayer perceptron model outperformed existing methods using DL and CNN, with 97% accuracy, 93% precision, 92% recall, and 92% <italic>F</italic><sub>1</sub>-score, while also exhibiting lower computational complexity [<xref ref-type="bibr" rid="ref54">54</xref>].</p></sec></sec><sec id="s4" sec-type="discussion"><title>Discussion</title><sec id="s4-1"><title>Principal Findings</title><p>This review maps ML-driven cybersecurity applications in health care against the NIST CSF 2.0 to identify where evidence clusters and gaps persist. In doing so, it provides the first structured, health care&#x2013;specific synthesis of ML cybersecurity evidence aligned to this framework. Classical algorithms, DL, NLP, and FL were the predominant technique categories, applied across diverse health care environments internationally, with research output accelerating sharply from 2022 [<xref ref-type="bibr" rid="ref69">69</xref>-<xref ref-type="bibr" rid="ref71">71</xref>]. The evidence base is heavily concentrated in preincident functions, with Protect, Detect, and Identify collectively accounting for the substantial majority of included studies, while Respond was underrepresented; Recover and Govern remain entirely absent. Despite high technical accuracy under controlled conditions, real-world deployment was almost entirely absent, with barriers around dataset generalizability, explainability, and regulatory readiness persisting across the literature. These findings have direct implications for how health care organizations might prioritize ML adoption.</p></sec><sec id="s4-2"><title>Overall Contribution and Landscape of Included Studies</title><p>Prior reviews by Wiafe et al [<xref ref-type="bibr" rid="ref17">17</xref>], Ali et al [<xref ref-type="bibr" rid="ref18">18</xref>], and Dhanushkodi and Thejas [<xref ref-type="bibr" rid="ref20">20</xref>] examined ML and AI for cybersecurity across general computing environments, cataloging techniques such as intrusion detection, malware analysis, and anomaly detection, but none were specific to health care or mapped findings against an established governance framework [<xref ref-type="bibr" rid="ref17">17</xref>-<xref ref-type="bibr" rid="ref20">20</xref>]. The global landscape of medical AI has evolved rapidly, with China emerging as a leading contributor in health care AI research, surpassing the United States in the number of publications over the past two years [<xref ref-type="bibr" rid="ref72">72</xref>]. Nonetheless, this review also likely underestimates China&#x2019;s contributions because of the language limitations in the search strategy.</p><p>This growth in research output reflects a scientific response to an expanding threat landscape, further accelerated by the COVID-19 pandemic, which drove rapid digitization of mission-critical health care services [<xref ref-type="bibr" rid="ref73">73</xref>,<xref ref-type="bibr" rid="ref74">74</xref>]. The shift to interconnected health infrastructure, telehealth, and widespread adoption of connected medical devices expanded the attack surface. The escalation of cyberattacks from 2022 onward, fueled by the high value of patient data for identity theft and insurance fraud, further intensified the urgency for ML-driven solutions [<xref ref-type="bibr" rid="ref75">75</xref>,<xref ref-type="bibr" rid="ref76">76</xref>]. Health care organizations have been identified as prime targets for financially motivated attackers, partly because the criticality of patient care services creates pressure to restore operations rapidly [<xref ref-type="bibr" rid="ref77">77</xref>].</p><p>The dominance of the &#x201C;Protect&#x201D; function is consistent with the heightened regulatory and ethical scrutiny surrounding patient data in health care, where data protection obligations create strong institutional incentives for this class of solution [<xref ref-type="bibr" rid="ref78">78</xref>]. The prominence of the Detect function likely reflects the technical tractability of intrusion detection as a well-defined, benchmarkable problem with established datasets [<xref ref-type="bibr" rid="ref79">79</xref>]. By contrast, the near-absence of Respond and the complete absence of Recover and Govern studies suggest that the research literature has not yet engaged substantively with the organizational dimensions of cyber resilience through ML approaches [<xref ref-type="bibr" rid="ref2">2</xref>,<xref ref-type="bibr" rid="ref16">16</xref>,<xref ref-type="bibr" rid="ref69">69</xref>].</p><p>Across the broader cybersecurity literature, governance tasks such as risk monitoring, automated compliance, and auditability have received comparatively limited attention relative to detection and protection [<xref ref-type="bibr" rid="ref80">80</xref>,<xref ref-type="bibr" rid="ref81">81</xref>]. On the other hand, studies in other critical infrastructures have demonstrated automated root cause analysis and self-healing mechanisms achieving zero-downtime recovery [<xref ref-type="bibr" rid="ref82">82</xref>], highlighting the translational opportunity for health care. Governance and risk management are therefore essential to guide the responsible deployment of ML models and organizational resilience [<xref ref-type="bibr" rid="ref16">16</xref>].</p></sec><sec id="s4-3"><title>Performance of ML Techniques</title><p>DL and hybrid models consistently demonstrated strong detection performance in controlled evaluations, with CNN and LSTM architectures predominating, consistent with the systematic review by Ali et al [<xref ref-type="bibr" rid="ref18">18</xref>], though results derive predominantly from synthetic or benchmark datasets and lack operational validation. Similarly, classical learners (RF, DT, and SVM) remained competitive in controlled evaluations, though real-world deployment performance was not assessed in the included studies [<xref ref-type="bibr" rid="ref40">40</xref>,<xref ref-type="bibr" rid="ref41">41</xref>,<xref ref-type="bibr" rid="ref47">47</xref>-<xref ref-type="bibr" rid="ref49">49</xref>]. Supervised ML algorithms, particularly ensemble SVMs and ANNs, have dominated academic literature. Similar findings were reported by Mukkamalla et al [<xref ref-type="bibr" rid="ref83">83</xref>]. Likewise, the broader mapping study by Wiafe et al [<xref ref-type="bibr" rid="ref17">17</xref>] identified rising SVM usage between 2013 and 2018, attributed to their suitability for small, high-dimensional, and nonlinear datasets.</p><p>Ensemble deidentification approaches, HE combined with other ML models, and FL were the most frequently adopted techniques. FL allows different institutions to train ML models on their local data and share only model parameters with a central server or other nodes, rather than sensitive raw data [<xref ref-type="bibr" rid="ref31">31</xref>,<xref ref-type="bibr" rid="ref66">66</xref>,<xref ref-type="bibr" rid="ref84">84</xref>]. FL has been proposed as particularly suited to dynamic health care networks because it enables real-time updates and scales across institutions without raw data sharing. However, challenges such as institutional data heterogeneity, communication costs, model aggregation vulnerabilities, and potential biases limit real-world reliability [<xref ref-type="bibr" rid="ref85">85</xref>]. These aggregation vulnerabilities include gradient reconstruction attacks, in which shared model updates are exploited to recover original training data, and model poisoning, in which malicious local updates corrupt the global model [<xref ref-type="bibr" rid="ref86">86</xref>,<xref ref-type="bibr" rid="ref87">87</xref>]. Combining FL with HE strengthens the privacy-preserving architecture, as model updates remain encrypted during transfer [<xref ref-type="bibr" rid="ref88">88</xref>].</p><p>Proactive risk assessment applications demonstrated that both data-driven and knowledge-based ML approaches can identify vulnerabilities and predict breaches in health care settings, though all evaluations were simulation-based and none approached operational readiness [<xref ref-type="bibr" rid="ref25">25</xref>,<xref ref-type="bibr" rid="ref26">26</xref>,<xref ref-type="bibr" rid="ref61">61</xref>]. In health care network environments, where the vast majority of traffic is benign, class imbalance means that high accuracy can be achieved even by models that fail to detect most attacks [<xref ref-type="bibr" rid="ref89">89</xref>]. Metrics such as precision, recall, and <italic>F</italic><sub>1</sub>-score provide a more complete picture, but these too were inconsistently reported across the included studies [<xref ref-type="bibr" rid="ref81">81</xref>]. The asymmetric cost of errors is particularly consequential in clinical settings: false negatives carry direct patient safety implications, while high false positive rates risk alert fatigue among already stretched clinical and information technology teams, potentially causing genuine threats to be overlooked [<xref ref-type="bibr" rid="ref90">90</xref>]. The absence of standardized, clinically contextualized evaluation frameworks across the included studies therefore limits the extent to which reported performance figures can be used to judge real-world effectiveness [<xref ref-type="bibr" rid="ref91">91</xref>].</p></sec><sec id="s4-4"><title>Barriers to Real-World Applicability</title><p>Many studies relied on outdated or non&#x2013;health care network datasets (CICIDS-2017, NSLKDDCup99, Kaggle), with the oldest exceeding over 20 years old [<xref ref-type="bibr" rid="ref92">92</xref>]. Methodological inconsistencies, including nonstandardized metrics, varying preprocessing techniques, undocumented hyperparameter tuning, and an absence of benchmarking against established cybersecurity tools, further undermine reproducibility [<xref ref-type="bibr" rid="ref81">81</xref>,<xref ref-type="bibr" rid="ref89">89</xref>].</p><p>These patterns have substantive implications for the maturity and reliability of the evidence base. First, the near-exclusive reliance on synthetic or benchmark datasets raises questions about generalizability, as models optimized on static, historical network traffic data are unlikely to perform reliably against the dynamic, heterogeneous threat environments of modern health care infrastructure [<xref ref-type="bibr" rid="ref92">92</xref>]. Second, the absence of external or prospective validation means that reported performance figures cannot currently be taken as indicators of deployment readiness; high benchmark accuracy is a necessary but insufficient condition for clinical adoption without validation on representative, real-world data [<xref ref-type="bibr" rid="ref89">89</xref>,<xref ref-type="bibr" rid="ref91">91</xref>]. Third, heterogeneous evaluation practices, including inconsistent metric selection, varying dataset splits, and undocumented tuning, make cross-study comparison unreliable and limit the conclusions that health care organizations or policymakers can draw [<xref ref-type="bibr" rid="ref81">81</xref>,<xref ref-type="bibr" rid="ref89">89</xref>]. The evidence base is therefore best characterized as exploratory rather than confirmatory. It demonstrates that ML techniques can achieve strong results under controlled conditions but are not yet sufficient to establish deployment readiness in clinical environments.</p><p>On an institutional level, health care organizations lack the technical infrastructure and interdisciplinary expertise to implement and maintain ML-driven cybersecurity systems effectively [<xref ref-type="bibr" rid="ref90">90</xref>,<xref ref-type="bibr" rid="ref93">93</xref>]. This challenge is compounded by the fact that explainable AI, intended to make AI understandable, remains poorly defined, with terms like interpretability and transparency often used interchangeably [<xref ref-type="bibr" rid="ref94">94</xref>]. Explainable AI has been proposed to build clinician trust, support regulatory approval, and improve communications between clinicians and cybersecurity teams [<xref ref-type="bibr" rid="ref95">95</xref>]. Several studies noted the absence of explainability as a barrier to clinical trust, pointing to explainable AI as a potential avenue for future research, though its practical integration into health care cybersecurity remains undemonstrated in the included literature [<xref ref-type="bibr" rid="ref30">30</xref>,<xref ref-type="bibr" rid="ref48">48</xref>].</p><p>Ethical, regulatory, and infrastructural challenges hinder ML adoption in health care [<xref ref-type="bibr" rid="ref96">96</xref>]. Access to sensitive patient data raises concerns around privacy, consent, and compliance with regulations [<xref ref-type="bibr" rid="ref15">15</xref>,<xref ref-type="bibr" rid="ref97">97</xref>,<xref ref-type="bibr" rid="ref98">98</xref>]. Rapid development and simulation of ML models have outpaced regulatory frameworks, creating a gray area that increases compliance burdens and delays clinical deployment. Recent policy initiatives, including the National Health Service Innovation Accelerator [<xref ref-type="bibr" rid="ref99">99</xref>] and the US AI Action Plan [<xref ref-type="bibr" rid="ref15">15</xref>], signal growing governmental recognition of AI&#x2019;s role in health care cybersecurity and could provide implementation pathways for organizations navigating this landscape. Parallel efforts from the European Commission&#x2019;s hospital cybersecurity action plan and the WHO&#x2019;s AI for health framework similarly reflect an emerging international consensus on AI-enabled cyber resilience in health care [<xref ref-type="bibr" rid="ref100">100</xref>,<xref ref-type="bibr" rid="ref101">101</xref>].</p></sec><sec id="s4-5"><title>Limitations of This Review</title><p>This review has several limitations. First, language and publication bias may have excluded non-English or nonindexed studies, and gray literature was not systematically searched. Second, the rapid evolution of ML and cyber threats means findings become outdated within a short timeframe. Third, heterogeneity in study designs, datasets, and evaluation metrics limited direct cross-study comparison. Fourth, the review excluded medical devices to focus on institutional cybersecurity, potentially omitting insights into device-specific risks, and proprietary AI-based cybersecurity products were not included due to limited methodological transparency, which may restrict understanding of current real-world implementations. Additionally, classification of studies against NIST CSF 2.0 functions was conducted by the review team and, while guided by each study&#x2019;s primary cybersecurity objective, remains inherently interpretive. Studies addressing multiple cybersecurity tasks may reasonably be mapped to more than one function, and alternative classifications by other reviewers are possible. Finally, the search was conducted till July 30, 2025, as prespecified in the registered protocol (OSF Registries 4cjmu); studies published after this date are not captured, and an updated review is recommended within two years given the pace of publication in this field.</p></sec><sec id="s4-6"><title>Future Directions and Operational Implications</title><p>Health care organizations face the dual challenge of implementing ML-driven cybersecurity while managing legacy infrastructure, limited budgets, and regulatory uncertainty. Current national and international cybersecurity strategies consistently call for AI-driven detection, privacy-preserving architectures, and governance frameworks, yet this review demonstrates that the research base supporting the latter two remains markedly underdeveloped [<xref ref-type="bibr" rid="ref14">14</xref>,<xref ref-type="bibr" rid="ref15">15</xref>,<xref ref-type="bibr" rid="ref99">99</xref>].</p><p>Based on the distribution of evidence identified in this review, a set of priorities for pilot testing can be outlined for health care organizations. These priorities are presented as hypotheses for consideration rather than a validated deployment model. The relative maturity of evidence in the &#x201C;Detect&#x201D; function, with intrusion detection representing the most studied application, represents a more tractable starting point for organizations considering ML pilot testing [<xref ref-type="bibr" rid="ref40">40</xref>-<xref ref-type="bibr" rid="ref42">42</xref>,<xref ref-type="bibr" rid="ref44">44</xref>,<xref ref-type="bibr" rid="ref45">45</xref>,<xref ref-type="bibr" rid="ref47">47</xref>-<xref ref-type="bibr" rid="ref50">50</xref>,<xref ref-type="bibr" rid="ref52">52</xref>]. However, as Heine et al [<xref ref-type="bibr" rid="ref91">91</xref>] highlight, despite excellent results on benchmark datasets, ML-based intrusion detection systems remain difficult to deploy in practice, with current simulation-based evaluation methodologies poorly reflecting real-world performance.</p><p>The growing volume of studies addressing privacy-preserving techniques, particularly FL and HE, indicates an emerging evidence base that may support a subsequent pilot-testing priority, particularly for organizations managing multisite data under strict privacy regulation, though operational implementation evidence remains sparse [<xref ref-type="bibr" rid="ref31">31</xref>,<xref ref-type="bibr" rid="ref66">66</xref>,<xref ref-type="bibr" rid="ref92">92</xref>]. The absence of any studies addressing the Govern or Recover functions represents the most significant gap identified by this review, underscoring that governance frameworks and recovery protocols for ML-driven cybersecurity in health care remain open research priorities rather than established practice.</p><p>The absence of real-world implementation evidence has direct resource implications for health care organizations considering ML adoption. These span AI procurement, infrastructure upgrades, staff training, and ongoing model monitoring, maintenance, and external validation. Pilot programs with careful cost tracking, rigorous documentation, and a primary focus on safety are needed to bridge the gap between experimental research and operational deployment. Without this foundation, policy ambition will continue to outpace the evidence needed to deploy ML-driven cybersecurity safely in clinical environments. The gap between policy ambition and operational evidence is unlikely to remain static. Anticipated advances in quantum computing represent a longer-term threat vector with the potential to render current cryptographic protections obsolete, reinforcing the case for sustained investment in health care&#x2013;specific cybersecurity research and the development of adaptive defensive architectures [<xref ref-type="bibr" rid="ref102">102</xref>-<xref ref-type="bibr" rid="ref104">104</xref>].</p></sec><sec id="s4-7"><title>Conclusions</title><p>By mapping ML-driven cybersecurity in health care against all 6 functions of the NIST CSF 2.0, this review offers a governance-aligned synthesis that complements prior reviews organized by attack type or ML architecture [<xref ref-type="bibr" rid="ref17">17</xref>-<xref ref-type="bibr" rid="ref20">20</xref>,<xref ref-type="bibr" rid="ref105">105</xref>]. The NIST CSF 2.0 framework, commonly used to evaluate organizational cyber resilience, makes findings translatable into implementation priorities for organizations. Evidence clusters in Identify, Protect, and Detect; Respond, Recover, and Govern remain unaddressed; and real-world deployment was almost entirely absent. These later functions precisely determine whether a health care organization can contain, recover from, and build lasting organizational cyber resilience from an attack.</p><p>The relative maturity of intrusion detection and privacy-preserving methods offers a defensible entry point for ML adoption, but organizations pursuing end-to-end cyber resilience cannot yet draw on a validated evidence base for governance or recovery. Until sustained investment in governance research and real-world validation with representative datasets addresses these gaps, ML in health care cybersecurity will remain a promising experimental tool rather than a trusted operational safeguard.</p></sec></sec></body><back><notes><sec><title>Funding</title><p>The authors declared no financial support was received for this work.</p></sec><sec><title>Data Availability</title><p>This scoping review synthesizes existing published literature; no new primary data were collected. All data extraction and synthesis are presented in the manuscript tables and figures.</p></sec></notes><fn-group><fn fn-type="con"><p>Conceptualization, methodology, investigation, data curation, formal analysis, visualization, writing &#x2013; original draft, writing &#x2013; review &#x0026; editing, project administration: KR.</p><p>SZ: Methodology, Investigation, Data curation, Formal analysis, Writing &#x2013; original draft, Writing &#x2013; review &#x0026; editing. SG: Conceptualization, Validation, Writing &#x2013; review &#x0026; editing, Supervision. ME: Writing &#x2013; review &#x0026; editing, Supervision. WO: Writing &#x2013; review &#x0026; editing, Supervision. AD: Writing &#x2013; review &#x0026; editing, Supervision. All authors read and approved the final manuscript.</p></fn><fn fn-type="conflict"><p>None declared.</p></fn></fn-group><glossary><title>Abbreviations</title><def-list><def-item><term id="abb1">CNN</term><def><p>convolutional neural network</p></def></def-item><def-item><term id="abb2">DL</term><def><p>deep learning</p></def></def-item><def-item><term id="abb3">DT</term><def><p>decision tree</p></def></def-item><def-item><term id="abb4">EHR</term><def><p>electronic health record</p></def></def-item><def-item><term id="abb5">FL</term><def><p>federated learning</p></def></def-item><def-item><term id="abb6">GAN</term><def><p>generative adversarial network</p></def></def-item><def-item><term id="abb7">HE</term><def><p>homomorphic encryption</p></def></def-item><def-item><term id="abb8">KNN</term><def><p>K-nearest neighbor</p></def></def-item><def-item><term id="abb9">LSTM</term><def><p>long short-term memory</p></def></def-item><def-item><term id="abb10">ML</term><def><p>machine learning</p></def></def-item><def-item><term id="abb11">NIST CSF 2.0</term><def><p>National Institute of Standards and Technology Cybersecurity Framework 2.0</p></def></def-item><def-item><term id="abb12">NLP</term><def><p>natural language processing</p></def></def-item><def-item><term id="abb13">PRISMA-S</term><def><p>Preferred Reporting Items for Systematic Reviews and Meta-Analyses literature search extension</p></def></def-item><def-item><term id="abb14">PRISMA-ScR</term><def><p>Preferred Reporting Items for Systematic Reviews and Meta-Analyses extension for Scoping Reviews</p></def></def-item><def-item><term id="abb15">RF</term><def><p>random forest</p></def></def-item><def-item><term id="abb16">SVM</term><def><p>support vector machine</p></def></def-item><def-item><term id="abb17">XGBoost</term><def><p>extreme gradient boosting</p></def></def-item></def-list></glossary><ref-list><title>References</title><ref id="ref1"><label>1</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Coventry</surname><given-names>L</given-names> </name><name name-style="western"><surname>Branley</surname><given-names>D</given-names> </name></person-group><article-title>Cybersecurity in healthcare: a narrative review of trends, threats and ways forward</article-title><source>Maturitas</source><year>2018</year><month>07</month><volume>113</volume><fpage>48</fpage><lpage>52</lpage><pub-id pub-id-type="doi">10.1016/j.maturitas.2018.04.008</pub-id><pub-id pub-id-type="medline">29903648</pub-id></nlm-citation></ref><ref id="ref2"><label>2</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Rajput</surname><given-names>K</given-names> </name><name name-style="western"><surname>Darzi</surname><given-names>A</given-names> </name><name name-style="western"><surname>Ghafur</surname><given-names>S</given-names> </name></person-group><article-title>Overlooked and under-reported: the impact of cyberattacks on primary care in the UK National Health Service</article-title><source>Lancet Digit Health</source><year>2025</year><month>07</month><volume>7</volume><issue>7</issue><fpage>100879</fpage><pub-id pub-id-type="doi">10.1016/j.landig.2025.100879</pub-id><pub-id pub-id-type="medline">40414783</pub-id></nlm-citation></ref><ref id="ref3"><label>3</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Alder</surname><given-names>S</given-names> </name></person-group><article-title>Ascension Ransomware Attack Affects 5.6 Million Patients</article-title><source>The HIPAA Journal</source><year>2024</year><month>08</month><access-date>2026-07-23</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://www.hipaajournal.com/ascension-cyberattack-2024">https://www.hipaajournal.com/ascension-cyberattack-2024</ext-link></comment></nlm-citation></ref><ref id="ref4"><label>4</label><nlm-citation citation-type="web"><article-title>Understanding the Change Healthcare breach and its impact on security compliance</article-title><source>Hyperproof</source><access-date>2026-06-29</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://hyperproof.io/resource/understanding-the-change-healthcare-breach">https://hyperproof.io/resource/understanding-the-change-healthcare-breach</ext-link></comment></nlm-citation></ref><ref id="ref5"><label>5</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Aldosari</surname><given-names>B</given-names> </name></person-group><article-title>Cybersecurity in healthcare: new threat to patient safety</article-title><source>Cureus</source><year>2025</year><month>05</month><volume>17</volume><issue>5</issue><fpage>e83614</fpage><pub-id pub-id-type="doi">10.7759/cureus.83614</pub-id><pub-id pub-id-type="medline">40486340</pub-id></nlm-citation></ref><ref id="ref6"><label>6</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Zeadally</surname><given-names>S</given-names> </name><name name-style="western"><surname>Adi</surname><given-names>E</given-names> </name><name name-style="western"><surname>Baig</surname><given-names>Z</given-names> </name><name name-style="western"><surname>Khan</surname><given-names>IA</given-names> </name></person-group><article-title>Harnessing artificial intelligence capabilities to improve cybersecurity</article-title><source>IEEE Access</source><year>2020</year><volume>8</volume><fpage>23817</fpage><lpage>23837</lpage><pub-id pub-id-type="doi">10.1109/ACCESS.2020.2968045</pub-id></nlm-citation></ref><ref id="ref7"><label>7</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Guembe</surname><given-names>B</given-names> </name><name name-style="western"><surname>Azeta</surname><given-names>A</given-names> </name><name name-style="western"><surname>Misra</surname><given-names>S</given-names> </name><name name-style="western"><surname>Osamor</surname><given-names>VC</given-names> </name><name name-style="western"><surname>Fernandez-Sanz</surname><given-names>L</given-names> </name><name name-style="western"><surname>Pospelova</surname><given-names>V</given-names> </name></person-group><article-title>The emerging threat of Ai-driven cyber attacks: a review</article-title><source>Appl Artif Intell</source><year>2022</year><month>12</month><day>31</day><volume>36</volume><issue>1</issue><fpage>2037254</fpage><pub-id pub-id-type="doi">10.1080/08839514.2022.2037254</pub-id></nlm-citation></ref><ref id="ref8"><label>8</label><nlm-citation citation-type="report"><article-title>Disrupting the first reported AI-orchestrated cyber espionage campaign</article-title><year>2025</year><access-date>2026-06-29</access-date><publisher-name>Anthropic</publisher-name><comment><ext-link ext-link-type="uri" xlink:href="https://assets.anthropic.com/m/ec212e6566a0d47/original/Disrupting-the-first-reported-AI-orchestrated-cyber-espionage-campaign.pdf">https://assets.anthropic.com/m/ec212e6566a0d47/original/Disrupting-the-first-reported-AI-orchestrated-cyber-espionage-campaign.pdf</ext-link></comment></nlm-citation></ref><ref id="ref9"><label>9</label><nlm-citation citation-type="web"><article-title>AI cyber attack statistics 2025</article-title><source>Tech Advisors</source><year>2025</year><access-date>2026-06-29</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://tech-adv.com/blog/ai-cyber-attack-statistics">https://tech-adv.com/blog/ai-cyber-attack-statistics</ext-link></comment></nlm-citation></ref><ref id="ref10"><label>10</label><nlm-citation citation-type="book"><person-group person-group-type="editor"><name name-style="western"><surname>Solaiman</surname><given-names>BC</given-names> </name><name name-style="western"><surname>Cohen</surname><given-names>I</given-names></name></person-group><article-title>Cybersecurity of AI medical devices: risks, legislation, and challenges</article-title><source>Research Handbook on Health, AI and the Law</source><year>2024</year><publisher-name>Edward Elgar Publishing Ltd</publisher-name><pub-id pub-id-type="doi">10.4337/9781802205657.ch04</pub-id></nlm-citation></ref><ref id="ref11"><label>11</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Arefin</surname><given-names>S</given-names> </name><name name-style="western"><surname>Simcox</surname><given-names>M</given-names> </name></person-group><article-title>AI-Driven Solutions for Safeguarding Healthcare Data: Innovations in Cybersecurity</article-title><source>IBR</source><year>2024</year><volume>17</volume><issue>6</issue><fpage>74</fpage><pub-id pub-id-type="doi">10.5539/ibr.v17n6p74</pub-id></nlm-citation></ref><ref id="ref12"><label>12</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Yu</surname><given-names>KH</given-names> </name><name name-style="western"><surname>Beam</surname><given-names>AL</given-names> </name><name name-style="western"><surname>Kohane</surname><given-names>IS</given-names> </name></person-group><article-title>Artificial intelligence in healthcare</article-title><source>Nat Biomed Eng</source><year>2018</year><month>10</month><volume>2</volume><issue>10</issue><fpage>719</fpage><lpage>731</lpage><pub-id pub-id-type="doi">10.1038/s41551-018-0305-z</pub-id><pub-id pub-id-type="medline">31015651</pub-id></nlm-citation></ref><ref id="ref13"><label>13</label><nlm-citation citation-type="confproc"><person-group person-group-type="author"><name name-style="western"><surname>Gopalan</surname><given-names>SS</given-names> </name><name name-style="western"><surname>Raza</surname><given-names>A</given-names> </name><name name-style="western"><surname>Almobaideen</surname><given-names>W</given-names> </name></person-group><article-title>IoT security in healthcare using AI: a survey</article-title><conf-name>2020 International Conference on Communications, Signal Processing, and their Applications (ICCSPA)</conf-name><conf-date>Mar 16-18, 2021</conf-date><pub-id pub-id-type="doi">10.1109/ICCSPA49915.2021.9385711</pub-id></nlm-citation></ref><ref id="ref14"><label>14</label><nlm-citation citation-type="web"><article-title>A cyber resilient health and adult social care system in England: cyber security strategy to 2030</article-title><source>Gov.UK</source><year>2023</year><access-date>2026-06-29</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://www.gov.uk/government/publications/cyber-security-strategy-for-health-and-social-care-2023-to-2030/a-cyber-resilient-health-and-adult-social-care-system-in-england-cyber-security-strategy-to-2030">https://www.gov.uk/government/publications/cyber-security-strategy-for-health-and-social-care-2023-to-2030/a-cyber-resilient-health-and-adult-social-care-system-in-england-cyber-security-strategy-to-2030</ext-link></comment></nlm-citation></ref><ref id="ref15"><label>15</label><nlm-citation citation-type="web"><article-title>Winning the race: America&#x2019;s AI action plan</article-title><source>Executive Office of the President of The United States</source><year>2025</year><access-date>2026-07-11</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://www.whitehouse.gov/wp-content/uploads/2025/07/Americas-AI-Action-Plan.pdf">https://www.whitehouse.gov/wp-content/uploads/2025/07/Americas-AI-Action-Plan.pdf</ext-link></comment></nlm-citation></ref><ref id="ref16"><label>16</label><nlm-citation citation-type="report"><person-group person-group-type="author"><name name-style="western"><surname>Pascoe</surname><given-names>C</given-names> </name><name name-style="western"><surname>Quinn</surname><given-names>S</given-names> </name><name name-style="western"><surname>Scarfone</surname><given-names>K</given-names> </name></person-group><article-title>The NIST cybersecurity framework (CSF) 2.0</article-title><year>2024</year><publisher-name>National Institute of Standards and Technology</publisher-name><pub-id pub-id-type="doi">10.6028/NIST.CSWP.29</pub-id></nlm-citation></ref><ref id="ref17"><label>17</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Wiafe</surname><given-names>I</given-names> </name><name name-style="western"><surname>Koranteng</surname><given-names>FN</given-names> </name><name name-style="western"><surname>Obeng</surname><given-names>EN</given-names> </name><name name-style="western"><surname>Assyne</surname><given-names>N</given-names> </name><name name-style="western"><surname>Wiafe</surname><given-names>A</given-names> </name><name name-style="western"><surname>Gulliver</surname><given-names>SR</given-names> </name></person-group><article-title>Artificial intelligence for cybersecurity: a systematic mapping of literature</article-title><source>IEEE Access</source><year>2020</year><volume>8</volume><fpage>146598</fpage><lpage>146612</lpage><pub-id pub-id-type="doi">10.1109/ACCESS.2020.3013145</pub-id></nlm-citation></ref><ref id="ref18"><label>18</label><nlm-citation citation-type="confproc"><person-group person-group-type="author"><name name-style="western"><surname>Ali</surname><given-names>R</given-names> </name><name name-style="western"><surname>Ali</surname><given-names>A</given-names> </name><name name-style="western"><surname>Iqbal</surname><given-names>F</given-names> </name><name name-style="western"><surname>Khattak</surname><given-names>AM</given-names> </name></person-group><person-group person-group-type="editor"><name name-style="western"><surname>Aleem</surname><given-names>S</given-names> </name></person-group><article-title>A systematic review of artificial intelligence and machine learning techniques for cyber security</article-title><conf-name>International Conference on Big Data and Security</conf-name><conf-date>2019</conf-date><pub-id pub-id-type="doi">10.1007/978-981-15-7530-3_44</pub-id></nlm-citation></ref><ref id="ref19"><label>19</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Ali</surname><given-names>R</given-names> </name><name name-style="western"><surname>Ali</surname><given-names>A</given-names> </name><name name-style="western"><surname>Iqbal</surname><given-names>F</given-names> </name><name name-style="western"><surname>Hussain</surname><given-names>M</given-names> </name><name name-style="western"><surname>Ullah</surname><given-names>F</given-names> </name></person-group><article-title>Deep learning methods for malware and intrusion detection: a systematic literature review</article-title><source>Secur Commun Netw</source><year>2022</year><month>10</month><day>10</day><volume>2022</volume><issue>1</issue><fpage>1</fpage><lpage>31</lpage><pub-id pub-id-type="doi">10.1155/2022/2959222</pub-id></nlm-citation></ref><ref id="ref20"><label>20</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Dhanushkodi</surname><given-names>K</given-names> </name><name name-style="western"><surname>Thejas</surname><given-names>S</given-names> </name></person-group><article-title>AI enabled threat detection: leveraging artificial intelligence for advanced security and cyber threat mitigation</article-title><source>IEEE Access</source><year>2024</year><volume>12</volume><fpage>173127</fpage><lpage>173136</lpage><pub-id pub-id-type="doi">10.1109/ACCESS.2024.3493957</pub-id></nlm-citation></ref><ref id="ref21"><label>21</label><nlm-citation citation-type="web"><person-group person-group-type="author"><name name-style="western"><surname>Angelo</surname><given-names>DD</given-names> </name><name name-style="western"><surname>Mehta</surname><given-names>T</given-names></name></person-group><article-title>AI provides an Rx for cybersecurity in healthcare</article-title><source>Paloalto</source><access-date>2026-06-29</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://www.paloaltonetworks.com/blog/2024/07/ai-provides-an-rx-for-cybersecurity-in-healthcare">https://www.paloaltonetworks.com/blog/2024/07/ai-provides-an-rx-for-cybersecurity-in-healthcare</ext-link></comment></nlm-citation></ref><ref id="ref22"><label>22</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Pendyala</surname><given-names>SK</given-names> </name></person-group><article-title>Strengthening healthcare cybersecurity: leveraging multi-cloud and AI solutions</article-title><source>J Comput Sci Appl Inf Technol</source><year>2025</year><volume>10</volume><issue>1</issue><fpage>1</fpage><lpage>8</lpage><comment><ext-link ext-link-type="uri" xlink:href="https://symbiosisonlinepublishing.com/computer-science-technology/volume10-issue1-jcsait.php">https://symbiosisonlinepublishing.com/computer-science-technology/volume10-issue1-jcsait.php</ext-link></comment><pub-id pub-id-type="doi">10.15226/2474-9257/10/1/00163</pub-id></nlm-citation></ref><ref id="ref23"><label>23</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Rethlefsen</surname><given-names>ML</given-names> </name><name name-style="western"><surname>Kirtley</surname><given-names>S</given-names> </name><name name-style="western"><surname>Waffenschmidt</surname><given-names>S</given-names> </name><etal/></person-group><article-title>PRISMA-S: an extension to the PRISMA statement for reporting literature searches in systematic reviews</article-title><source>Syst Rev</source><year>2021</year><month>01</month><day>26</day><volume>10</volume><issue>1</issue><fpage>39</fpage><pub-id pub-id-type="doi">10.1186/s13643-020-01542-z</pub-id><pub-id pub-id-type="medline">33499930</pub-id></nlm-citation></ref><ref id="ref24"><label>24</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Silvestri</surname><given-names>S</given-names> </name><name name-style="western"><surname>Islam</surname><given-names>S</given-names> </name><name name-style="western"><surname>Papastergiou</surname><given-names>S</given-names> </name><name name-style="western"><surname>Tzagkarakis</surname><given-names>C</given-names> </name><name name-style="western"><surname>Ciampi</surname><given-names>M</given-names> </name></person-group><article-title>A machine learning approach for the NLP-based analysis of cyber threats and vulnerabilities of the healthcare ecosystem</article-title><source>Sensors (Basel)</source><year>2023</year><month>01</month><day>6</day><volume>23</volume><issue>2</issue><fpage>651</fpage><pub-id pub-id-type="doi">10.3390/s23020651</pub-id><pub-id pub-id-type="medline">36679446</pub-id></nlm-citation></ref><ref id="ref25"><label>25</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Islam</surname><given-names>S</given-names> </name><name name-style="western"><surname>Abba</surname><given-names>A</given-names> </name><name name-style="western"><surname>Ismail</surname><given-names>U</given-names> </name><name name-style="western"><surname>Mouratidis</surname><given-names>H</given-names> </name><name name-style="western"><surname>Papastergiou</surname><given-names>S</given-names> </name></person-group><article-title>Vulnerability prediction for secure healthcare supply chain service delivery</article-title><source>Integr Comput Aided Eng</source><year>2022</year><volume>29</volume><issue>4</issue><fpage>389</fpage><lpage>409</lpage><pub-id pub-id-type="doi">10.3233/ICA-220689</pub-id></nlm-citation></ref><ref id="ref26"><label>26</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Li</surname><given-names>G</given-names> </name><name name-style="western"><surname>Dong</surname><given-names>Z</given-names> </name><name name-style="western"><surname>Wang</surname><given-names>Y</given-names> </name></person-group><article-title>Information security of hospital computer network based on SAE deep neural network</article-title><source>Appl Math Nonlinear Sci</source><year>2024</year><month>01</month><day>1</day><volume>9</volume><issue>1</issue><pub-id pub-id-type="doi">10.2478/amns.2023.1.00466</pub-id></nlm-citation></ref><ref id="ref27"><label>27</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Yi</surname><given-names>X</given-names> </name><name name-style="western"><surname>Wu</surname><given-names>J</given-names> </name><name name-style="western"><surname>Li</surname><given-names>G</given-names> </name><name name-style="western"><surname>Bashir</surname><given-names>AK</given-names> </name><name name-style="western"><surname>Li</surname><given-names>J</given-names> </name><name name-style="western"><surname>Ali</surname><given-names>A</given-names></name></person-group><article-title>Recurrent semantic learning-driven fast binary vulnerability detection in healthcare cyber physical systems</article-title><source>IEEE Trans Netw Sci Eng</source><year>2023</year><volume>10</volume><issue>5</issue><fpage>2537</fpage><lpage>2550</lpage><pub-id pub-id-type="doi">10.1109/TNSE.2022.3199990</pub-id></nlm-citation></ref><ref id="ref28"><label>28</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Yusof</surname><given-names>MHM</given-names> </name><name name-style="western"><surname>Zin</surname><given-names>AM</given-names> </name><name name-style="western"><surname>Satar</surname><given-names>NSM</given-names> </name></person-group><article-title>Behavioral intrusion prediction model on Bayesian network over healthcare infrastructure</article-title><source>Comput Mater Contin</source><year>2022</year><volume>72</volume><issue>2</issue><fpage>2445</fpage><lpage>2466</lpage><pub-id pub-id-type="doi">10.32604/cmc.2022.023571</pub-id></nlm-citation></ref><ref id="ref29"><label>29</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Liu</surname><given-names>J</given-names> </name><name name-style="western"><surname>Gupta</surname><given-names>S</given-names> </name><name name-style="western"><surname>Chen</surname><given-names>A</given-names> </name><etal/></person-group><article-title>OpenDeID pipeline for unstructured electronic health record text notes based on rules and transformers: deidentification algorithm development and validation study</article-title><source>J Med Internet Res</source><year>2023</year><month>12</month><day>6</day><volume>25</volume><fpage>e48145</fpage><pub-id pub-id-type="doi">10.2196/48145</pub-id><pub-id pub-id-type="medline">38055317</pub-id></nlm-citation></ref><ref id="ref30"><label>30</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Sheu</surname><given-names>RK</given-names> </name><name name-style="western"><surname>Lin</surname><given-names>YC</given-names> </name><name name-style="western"><surname>Pardeshi</surname><given-names>MS</given-names> </name><etal/></person-group><article-title>Adaptive autonomous protocol for secured remote healthcare using fully homomorphic encryption (AutoPro-RHC)</article-title><source>Sensors (Basel)</source><year>2023</year><month>10</month><day>16</day><volume>23</volume><issue>20</issue><fpage>8504</fpage><pub-id pub-id-type="doi">10.3390/s23208504</pub-id><pub-id pub-id-type="medline">37896596</pub-id></nlm-citation></ref><ref id="ref31"><label>31</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Nguyen</surname><given-names>TV</given-names> </name><name name-style="western"><surname>Dakka</surname><given-names>MA</given-names> </name><name name-style="western"><surname>Diakiw</surname><given-names>SM</given-names> </name><etal/></person-group><article-title>A novel decentralized federated learning approach to train on globally distributed, poor quality, and protected private medical data</article-title><source>Sci Rep</source><year>2022</year><month>05</month><day>25</day><volume>12</volume><issue>1</issue><fpage>8888</fpage><pub-id pub-id-type="doi">10.1038/s41598-022-12833-x</pub-id><pub-id pub-id-type="medline">35614106</pub-id></nlm-citation></ref><ref id="ref32"><label>32</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Kumar</surname><given-names>S</given-names> </name><name name-style="western"><surname>Wajeed</surname><given-names>MA</given-names> </name><name name-style="western"><surname>Kunabeva</surname><given-names>R</given-names> </name><etal/></person-group><article-title>Novel method for safeguarding personal health record in cloud connection using deep learning models</article-title><source>Comput Intell Neurosci</source><year>2022</year><volume>2022</volume><fpage>3564436</fpage><pub-id pub-id-type="doi">10.1155/2022/3564436</pub-id><pub-id pub-id-type="medline">35345805</pub-id></nlm-citation></ref><ref id="ref33"><label>33</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Almousa</surname><given-names>BN</given-names> </name><name name-style="western"><surname>Uliyan</surname><given-names>DM</given-names> </name></person-group><article-title>Anti-spoofing in medical employee&#x2019;s email using machine learning uclassify algorithm</article-title><source>Int J Adv Comput Sci Appl</source><year>2023</year><volume>14</volume><issue>7</issue><pub-id pub-id-type="doi">10.14569/IJACSA.2023.0140727</pub-id></nlm-citation></ref><ref id="ref34"><label>34</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>S</surname><given-names>G</given-names> </name><name name-style="western"><surname>S</surname><given-names>G</given-names> </name></person-group><article-title>Securing medical image privacy in cloud using deep learning network</article-title><source>J Cloud Comput</source><year>2023</year><volume>12</volume><issue>1</issue><pub-id pub-id-type="doi">10.1186/s13677-023-00422-w</pub-id></nlm-citation></ref><ref id="ref35"><label>35</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Gao</surname><given-names>X</given-names> </name><name name-style="western"><surname>Mi</surname><given-names>W</given-names> </name><name name-style="western"><surname>Feng</surname><given-names>X</given-names> </name></person-group><article-title>Personal health data protection and intelligent healthcare applications under generative adversarial network</article-title><source>Sci Rep</source><year>2025</year><month>05</month><day>13</day><volume>15</volume><issue>1</issue><fpage>16558</fpage><pub-id pub-id-type="doi">10.1038/s41598-025-01575-1</pub-id><pub-id pub-id-type="medline">40360631</pub-id></nlm-citation></ref><ref id="ref36"><label>36</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Altalla&#x2019;</surname><given-names>B</given-names> </name><name name-style="western"><surname>Abdalla</surname><given-names>S</given-names> </name><name name-style="western"><surname>Altamimi</surname><given-names>A</given-names> </name><etal/></person-group><article-title>Evaluating GPT models for clinical note de-identification</article-title><source>Sci Rep</source><year>2025</year><month>01</month><day>31</day><volume>15</volume><issue>1</issue><fpage>3852</fpage><pub-id pub-id-type="doi">10.1038/s41598-025-86890-3</pub-id><pub-id pub-id-type="medline">39890969</pub-id></nlm-citation></ref><ref id="ref37"><label>37</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Mesfer Aldossary</surname><given-names>S</given-names> </name></person-group><article-title>DeepGan-privacy preserving of healthcare system using DL</article-title><source>Intell Autom Soft Comput</source><year>2023</year><volume>37</volume><issue>2</issue><fpage>2199</fpage><lpage>2212</lpage><pub-id pub-id-type="doi">10.32604/iasc.2023.038243</pub-id></nlm-citation></ref><ref id="ref38"><label>38</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Akter</surname><given-names>M</given-names> </name><name name-style="western"><surname>Moustafa</surname><given-names>N</given-names> </name><name name-style="western"><surname>Turnbull</surname><given-names>B</given-names> </name></person-group><article-title>SPEI-FL: serverless privacy edge intelligence-enabled federated learning in smart healthcare systems</article-title><source>Cogn Comput</source><year>2024</year><month>09</month><volume>16</volume><issue>5</issue><fpage>2626</fpage><lpage>2641</lpage><pub-id pub-id-type="doi">10.1007/s12559-024-10310-3</pub-id></nlm-citation></ref><ref id="ref39"><label>39</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Jonnagaddala</surname><given-names>J</given-names> </name><name name-style="western"><surname>Chen</surname><given-names>A</given-names> </name><name name-style="western"><surname>Batongbacal</surname><given-names>S</given-names> </name><name name-style="western"><surname>Nekkantti</surname><given-names>C</given-names> </name></person-group><article-title>The OpenDeID corpus for patient de-identification</article-title><source>Sci Rep</source><year>2021</year><month>10</month><day>7</day><volume>11</volume><issue>1</issue><fpage>19973</fpage><pub-id pub-id-type="doi">10.1038/s41598-021-99554-9</pub-id><pub-id pub-id-type="medline">34620985</pub-id></nlm-citation></ref><ref id="ref40"><label>40</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Samiayya</surname><given-names>D</given-names> </name><name name-style="western"><surname>Vincent</surname><given-names>P</given-names> </name><name name-style="western"><surname>Srinivasan</surname><given-names>K</given-names> </name><name name-style="western"><surname>Chang</surname><given-names>CY</given-names> </name><name name-style="western"><surname>Ganesh</surname><given-names>H</given-names> </name><name name-style="western"><surname>Kumaar</surname><given-names>MA</given-names> </name></person-group><article-title>A hybrid framework for intrusion detection in healthcare systems using deep learning</article-title><source>Front Public Health</source><year>2021</year><volume>9</volume><fpage>824898</fpage><pub-id pub-id-type="doi">10.3389/fpubh.2021.824898</pub-id><pub-id pub-id-type="medline">35096763</pub-id></nlm-citation></ref><ref id="ref41"><label>41</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Tabassum</surname><given-names>M</given-names> </name><name name-style="western"><surname>Mahmood</surname><given-names>S</given-names> </name><name name-style="western"><surname>Bukhari</surname><given-names>A</given-names> </name><name name-style="western"><surname>Alshemaimri</surname><given-names>B</given-names> </name><name name-style="western"><surname>Daud</surname><given-names>A</given-names> </name><name name-style="western"><surname>Khalique</surname><given-names>F</given-names> </name></person-group><article-title>Anomaly-based threat detection in smart health using machine learning</article-title><source>BMC Med Inform Decis Mak</source><year>2024</year><month>11</month><day>19</day><volume>24</volume><issue>1</issue><fpage>347</fpage><pub-id pub-id-type="doi">10.1186/s12911-024-02760-4</pub-id><pub-id pub-id-type="medline">39563355</pub-id></nlm-citation></ref><ref id="ref42"><label>42</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Hurst</surname><given-names>W</given-names> </name><name name-style="western"><surname>Tekinerdogan</surname><given-names>B</given-names> </name><name name-style="western"><surname>Alskaif</surname><given-names>T</given-names> </name><name name-style="western"><surname>Boddy</surname><given-names>A</given-names> </name><name name-style="western"><surname>Shone</surname><given-names>N</given-names> </name></person-group><article-title>Securing electronic health records against insider-threats: a supervised machine learning approach</article-title><source>Smart Health</source><year>2022</year><month>12</month><volume>26</volume><fpage>100354</fpage><pub-id pub-id-type="doi">10.1016/j.smhl.2022.100354</pub-id></nlm-citation></ref><ref id="ref43"><label>43</label><nlm-citation citation-type="confproc"><person-group person-group-type="author"><name name-style="western"><surname>Saranya</surname><given-names>N</given-names> </name><name name-style="western"><surname>Abbinavu</surname><given-names>T</given-names> </name><name name-style="western"><surname>Kumar</surname><given-names>PA</given-names> </name><name name-style="western"><surname>Gnanasekar</surname><given-names>R</given-names> </name><name name-style="western"><surname>Prasanth</surname><given-names>PG</given-names> </name><name name-style="western"><surname>Subha</surname><given-names>R</given-names> </name></person-group><article-title>Retracted: RTIDS: a robust transformer-based approach for intrusion detection system</article-title><conf-name>2024 10th International Conference on Advanced Computing and Communication Systems (ICACCS)</conf-name><conf-date>Mar 14-15, 2024</conf-date><conf-loc>Coimbatore, India</conf-loc><fpage>1461</fpage><lpage>1464</lpage><pub-id pub-id-type="doi">10.1109/ICACCS60874.2024.10717109</pub-id></nlm-citation></ref><ref id="ref44"><label>44</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>&#x00D6;zt&#x00FC;rk</surname><given-names>T</given-names> </name><name name-style="western"><surname>Turgut</surname><given-names>Z</given-names> </name><name name-style="western"><surname>Akg&#x00FC;n</surname><given-names>G</given-names> </name><name name-style="western"><surname>K&#x00F6;se</surname><given-names>C</given-names> </name></person-group><article-title>Machine learning-based intrusion detection for SCADA systems in healthcare</article-title><source>Netw Model Anal Health Inform Bioinforma</source><year>2022</year><month>12</month><volume>11</volume><issue>1</issue><pub-id pub-id-type="doi">10.1007/s13721-022-00390-2</pub-id></nlm-citation></ref><ref id="ref45"><label>45</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Wazid</surname><given-names>M</given-names> </name><name name-style="western"><surname>Singh</surname><given-names>J</given-names> </name><name name-style="western"><surname>Das</surname><given-names>AK</given-names> </name><name name-style="western"><surname>Rodrigues</surname><given-names>JJPC</given-names> </name></person-group><article-title>An ensemble-based machine learning-envisioned intrusion detection in Industry 5.0-driven healthcare applications</article-title><source>IEEE Trans Consumer Electron</source><year>2024</year><volume>70</volume><issue>1</issue><fpage>1903</fpage><lpage>1912</lpage><pub-id pub-id-type="doi">10.1109/TCE.2023.3318850</pub-id></nlm-citation></ref><ref id="ref46"><label>46</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Sengan</surname><given-names>S</given-names> </name><name name-style="western"><surname>Khalaf</surname><given-names>OI</given-names> </name><name name-style="western"><surname>Sharma</surname><given-names>DK</given-names> </name><name name-style="western"><surname>Hamad</surname><given-names>AA</given-names> </name></person-group><article-title>Secured and privacy-based IDS for healthcare systems on e-medical data using machine learning approach</article-title><source>Int J Reliab Qual E Healthc</source><year>2022</year><month>07</month><volume>11</volume><issue>3</issue><fpage>1</fpage><lpage>11</lpage><pub-id pub-id-type="doi">10.4018/IJRQEH.289175</pub-id></nlm-citation></ref><ref id="ref47"><label>47</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Thanh Nguyen</surname><given-names>P</given-names> </name><name name-style="western"><surname>Dang Bich Huynh</surname><given-names>V</given-names> </name><name name-style="western"><surname>Dang Vo</surname><given-names>K</given-names> </name><name name-style="western"><surname>Thanh Phan</surname><given-names>P</given-names> </name><name name-style="western"><surname>Elhoseny</surname><given-names>M</given-names> </name><name name-style="western"><surname>Le</surname><given-names>DN</given-names> </name></person-group><article-title>Deep learning based optimal multimodal fusion framework for intrusion detection systems for healthcare data</article-title><source>Comput Mater Contin</source><year>2021</year><volume>66</volume><issue>3</issue><fpage>2555</fpage><lpage>2571</lpage><pub-id pub-id-type="doi">10.32604/cmc.2021.012941</pub-id></nlm-citation></ref><ref id="ref48"><label>48</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Alanazi</surname><given-names>SA</given-names> </name></person-group><article-title>ML-SPAs: fortifying healthcare cybersecurity leveraging varied machine learning approaches against spear phishing attacks</article-title><source>Comput Mater Contin</source><year>2024</year><volume>81</volume><issue>3</issue><fpage>4049</fpage><lpage>4080</lpage><pub-id pub-id-type="doi">10.32604/cmc.2024.057211</pub-id></nlm-citation></ref><ref id="ref49"><label>49</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Ahmed</surname><given-names>SS</given-names> </name><name name-style="western"><surname>Shakir</surname><given-names>HR</given-names> </name></person-group><article-title>Enhancement of secure hospital healthcare monitoring system based&#x2013;software defined network (SDN) with machine learning</article-title><source>Int J Inform Vis</source><year>2024</year><volume>8</volume><issue>4</issue><fpage>2305</fpage><pub-id pub-id-type="doi">10.62527/joiv.8.4.2425</pub-id></nlm-citation></ref><ref id="ref50"><label>50</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Halman</surname><given-names>LM</given-names> </name><name name-style="western"><surname>Alenazi</surname><given-names>MJF</given-names> </name></person-group><article-title>MCAD: a machine learning based cyberattacks detector in software-defined networking (SDN) for healthcare systems</article-title><source>IEEE Access</source><year>2023</year><volume>11</volume><fpage>37052</fpage><lpage>37067</lpage><pub-id pub-id-type="doi">10.1109/ACCESS.2023.3266826</pub-id></nlm-citation></ref><ref id="ref51"><label>51</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Asif</surname><given-names>MW</given-names> </name><name name-style="western"><surname>Aqdus</surname><given-names>A</given-names> </name><name name-style="western"><surname>Amin</surname><given-names>R</given-names> </name><name name-style="western"><surname>Chaudhry</surname><given-names>SA</given-names> </name><name name-style="western"><surname>Alsubaei</surname><given-names>FS</given-names> </name><name name-style="western"><surname>Iqbal</surname><given-names>S</given-names> </name></person-group><article-title>An efficient intrusion detection system using advanced machine learning techniques in SDN for healthcare system</article-title><source>IEEE J Biomed Health Inform</source><year>2026</year><month>05</month><volume>30</volume><issue>5</issue><fpage>3651</fpage><lpage>3664</lpage><pub-id pub-id-type="doi">10.1109/JBHI.2025.3530563</pub-id><pub-id pub-id-type="medline">40030900</pub-id></nlm-citation></ref><ref id="ref52"><label>52</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Qiao</surname><given-names>S</given-names> </name><name name-style="western"><surname>Guo</surname><given-names>Q</given-names> </name><name name-style="western"><surname>Shi</surname><given-names>F</given-names> </name><etal/></person-group><article-title>SIBW: a swarm intelligence-based network flow watermarking approach for privacy leakage detection in digital healthcare systems</article-title><source>IEEE J Biomed Health Inform</source><year>2026</year><month>03</month><volume>30</volume><issue>3</issue><fpage>1912</fpage><lpage>1924</lpage><pub-id pub-id-type="doi">10.1109/JBHI.2025.3542561</pub-id><pub-id pub-id-type="medline">40036416</pub-id></nlm-citation></ref><ref id="ref53"><label>53</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Fern&#x00E1;ndez Maim&#x00F3;</surname><given-names>L</given-names> </name><name name-style="western"><surname>Huertas Celdr&#x00E1;n</surname><given-names>A</given-names> </name><name name-style="western"><surname>Perales G&#x00F3;mez</surname><given-names>&#x00C1;L</given-names> </name><name name-style="western"><surname>Garc&#x00ED;a Clemente</surname><given-names>FJ</given-names> </name><name name-style="western"><surname>Weimer</surname><given-names>J</given-names> </name><name name-style="western"><surname>Lee</surname><given-names>I</given-names> </name></person-group><article-title>Intelligent and dynamic ransomware spread detection and mitigation in integrated clinical environments</article-title><source>Sensors (Basel)</source><year>2019</year><month>03</month><day>5</day><volume>19</volume><issue>5</issue><fpage>1114</fpage><pub-id pub-id-type="doi">10.3390/s19051114</pub-id><pub-id pub-id-type="medline">30841592</pub-id></nlm-citation></ref><ref id="ref54"><label>54</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Abidi</surname><given-names>MH</given-names> </name><name name-style="western"><surname>Alkhalefah</surname><given-names>H</given-names> </name><name name-style="western"><surname>Aboudaif</surname><given-names>MK</given-names> </name></person-group><article-title>Enhancing healthcare data security and disease detection using crossover-based multilayer perceptron in smart healthcare systems</article-title><source>Comput Model Eng Sci</source><year>2024</year><volume>139</volume><issue>1</issue><fpage>977</fpage><lpage>997</lpage><pub-id pub-id-type="doi">10.32604/cmes.2023.044169</pub-id></nlm-citation></ref><ref id="ref55"><label>55</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>&#x00DC;n&#x00F6;zkan</surname><given-names>H</given-names> </name><name name-style="western"><surname>Ertem</surname><given-names>M</given-names> </name><name name-style="western"><surname>Bendak</surname><given-names>S</given-names> </name></person-group><article-title>Using attack graphs to defend healthcare systems from cyberattacks: a longitudinal empirical study</article-title><source>Netw Model Anal Health Inform Bioinform</source><year>2022</year><volume>11</volume><issue>1</issue><fpage>52</fpage><pub-id pub-id-type="doi">10.1007/s13721-022-00391-1</pub-id><pub-id pub-id-type="medline">36408329</pub-id></nlm-citation></ref><ref id="ref56"><label>56</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Dolezel</surname><given-names>D</given-names> </name><name name-style="western"><surname>Beauvais</surname><given-names>B</given-names> </name><name name-style="western"><surname>Stigler Granados</surname><given-names>P</given-names> </name><name name-style="western"><surname>Fulton</surname><given-names>L</given-names> </name><name name-style="western"><surname>Kruse</surname><given-names>CS</given-names> </name></person-group><article-title>Effects of internal and external factors on hospital data breaches: quantitative study</article-title><source>J Med Internet Res</source><year>2023</year><month>12</month><day>21</day><volume>25</volume><fpage>e51471</fpage><pub-id pub-id-type="doi">10.2196/51471</pub-id><pub-id pub-id-type="medline">38127426</pub-id></nlm-citation></ref><ref id="ref57"><label>57</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Gupta</surname><given-names>S</given-names> </name><name name-style="western"><surname>Liu</surname><given-names>J</given-names> </name><name name-style="western"><surname>Wong</surname><given-names>ZSY</given-names> </name><name name-style="western"><surname>Jonnagaddala</surname><given-names>J</given-names> </name></person-group><article-title>Preliminary evaluation of fine-tuning the OpenDeLD deidentification pipeline across multi-center corpora</article-title><source>Stud Health Technol Inform</source><year>2024</year><month>08</month><day>22</day><volume>316</volume><fpage>719</fpage><lpage>723</lpage><pub-id pub-id-type="doi">10.3233/SHTI240515</pub-id><pub-id pub-id-type="medline">39176896</pub-id></nlm-citation></ref><ref id="ref58"><label>58</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Huang</surname><given-names>T</given-names> </name><name name-style="western"><surname>Xu</surname><given-names>J</given-names> </name><name name-style="western"><surname>Tu</surname><given-names>S</given-names> </name><name name-style="western"><surname>Han</surname><given-names>B</given-names> </name></person-group><article-title>Robust zero-watermarking scheme based on a depthwise overparameterized VGG network in healthcare information security</article-title><source>Biomed Signal Process Control</source><year>2023</year><month>03</month><volume>81</volume><fpage>104478</fpage><pub-id pub-id-type="doi">10.1016/j.bspc.2022.104478</pub-id></nlm-citation></ref><ref id="ref59"><label>59</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>An</surname><given-names>Z</given-names> </name><name name-style="western"><surname>Zhang</surname><given-names>J</given-names> </name><name name-style="western"><surname>Jiang</surname><given-names>Z</given-names> </name><name name-style="western"><surname>Du</surname><given-names>J</given-names> </name><name name-style="western"><surname>Yin</surname><given-names>Z</given-names> </name><name name-style="western"><surname>Li</surname><given-names>C</given-names> </name></person-group><article-title>FedMCC: federated multi-center clustering algorithm to improve privacy healthcare</article-title><source>Methods</source><year>2023</year><month>10</month><volume>218</volume><fpage>94</fpage><lpage>100</lpage><pub-id pub-id-type="doi">10.1016/j.ymeth.2023.07.006</pub-id><pub-id pub-id-type="medline">37507060</pub-id></nlm-citation></ref><ref id="ref60"><label>60</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Bo</surname><given-names>ZH</given-names> </name><name name-style="western"><surname>Guo</surname><given-names>Y</given-names> </name><name name-style="western"><surname>Lyu</surname><given-names>J</given-names> </name><etal/></person-group><article-title>Relay learning: a physically secure framework for clinical multi-site deep learning</article-title><source>NPJ Digit Med</source><year>2023</year><month>11</month><day>4</day><volume>6</volume><issue>1</issue><fpage>204</fpage><pub-id pub-id-type="doi">10.1038/s41746-023-00934-4</pub-id><pub-id pub-id-type="medline">37925578</pub-id></nlm-citation></ref><ref id="ref61"><label>61</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Kaur</surname><given-names>J</given-names> </name><name name-style="western"><surname>Khan</surname><given-names>AI</given-names> </name><name name-style="western"><surname>Abushark</surname><given-names>YB</given-names> </name><etal/></person-group><article-title>Security risk assessment of healthcare web application through adaptive neuro-fuzzy inference system: a design perspective</article-title><source>Risk Manag Healthc Policy</source><year>2020</year><volume>13</volume><fpage>355</fpage><lpage>371</lpage><pub-id pub-id-type="doi">10.2147/RMHP.S233706</pub-id><pub-id pub-id-type="medline">32425625</pub-id></nlm-citation></ref><ref id="ref62"><label>62</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Akter</surname><given-names>M</given-names> </name><name name-style="western"><surname>Moustafa</surname><given-names>N</given-names> </name><name name-style="western"><surname>Lynar</surname><given-names>T</given-names> </name><name name-style="western"><surname>Razzak</surname><given-names>I</given-names> </name></person-group><article-title>Edge intelligence: federated learning-based privacy protection framework for smart healthcare systems</article-title><source>IEEE J Biomed Health Inform</source><year>2022</year><month>12</month><volume>26</volume><issue>12</issue><fpage>5805</fpage><lpage>5816</lpage><pub-id pub-id-type="doi">10.1109/JBHI.2022.3192648</pub-id><pub-id pub-id-type="medline">35857737</pub-id></nlm-citation></ref><ref id="ref63"><label>63</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Ganguli</surname><given-names>R</given-names> </name><name name-style="western"><surname>Lad</surname><given-names>R</given-names> </name><name name-style="western"><surname>Lin</surname><given-names>A</given-names> </name><name name-style="western"><surname>Yu</surname><given-names>X</given-names> </name></person-group><article-title>Novel generative recurrent neural network framework to produce accurate, applicable, and deidentified synthetic medical data for patients with metastatic cancer</article-title><source>JCO Clin Cancer Inform</source><year>2023</year><month>05</month><volume>7</volume><issue>7</issue><fpage>e2200125</fpage><pub-id pub-id-type="doi">10.1200/CCI.22.00125</pub-id><pub-id pub-id-type="medline">37130342</pub-id></nlm-citation></ref><ref id="ref64"><label>64</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Alzubi</surname><given-names>JA</given-names> </name><name name-style="western"><surname>Alzubi</surname><given-names>OA</given-names> </name><name name-style="western"><surname>Beseiso</surname><given-names>M</given-names> </name><name name-style="western"><surname>Budati</surname><given-names>AK</given-names> </name><name name-style="western"><surname>Shankar</surname><given-names>K</given-names> </name></person-group><article-title>Optimal multiple key&#x2010;based homomorphic encryption with deep neural networks to secure medical data transmission and diagnosis</article-title><source>Expert Systems</source><year>2022</year><month>05</month><volume>39</volume><issue>4</issue><pub-id pub-id-type="doi">10.1111/exsy.12879</pub-id></nlm-citation></ref><ref id="ref65"><label>65</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Cabrero-Holgueras</surname><given-names>J</given-names> </name><name name-style="western"><surname>Pastrana</surname><given-names>S</given-names> </name></person-group><article-title>Towards realistic privacy-preserving deep learning over encrypted medical data</article-title><source>Front Cardiovasc Med</source><year>2023</year><volume>10</volume><fpage>1117360</fpage><pub-id pub-id-type="doi">10.3389/fcvm.2023.1117360</pub-id><pub-id pub-id-type="medline">37187785</pub-id></nlm-citation></ref><ref id="ref66"><label>66</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Mohammadi</surname><given-names>N</given-names> </name><name name-style="western"><surname>Rezakhani</surname><given-names>A</given-names> </name><name name-style="western"><surname>Haj Seyyed Javadi</surname><given-names>H</given-names> </name><name name-style="western"><surname>asghari</surname><given-names>P</given-names> </name></person-group><article-title>FLHB-AC: federated learning history-based access control using deep neural networks in healthcare system</article-title><source>J Inf Syst Telecommun</source><year>2024</year><volume>12</volume><issue>46</issue><fpage>90</fpage><lpage>104</lpage><pub-id pub-id-type="doi">10.61186/jist.44500.12.46.90</pub-id></nlm-citation></ref><ref id="ref67"><label>67</label><nlm-citation citation-type="confproc"><person-group person-group-type="author"><name name-style="western"><surname>Goldschmidt</surname><given-names>G</given-names> </name><name name-style="western"><surname>Zeiser</surname><given-names>FA</given-names> </name><name name-style="western"><surname>Righi</surname><given-names>RDR</given-names> </name><name name-style="western"><surname>Da Costa</surname><given-names>CA</given-names> </name></person-group><article-title>ARTERIAL: a natural language processing model for prevention of information leakage from electronic health records</article-title><conf-name>2023 XIII Brazilian Symposium on Computing Systems Engineering (SBESC)</conf-name><conf-date>Nov 21-24, 2023</conf-date><conf-loc>Porto Alegre, Brazil</conf-loc><fpage>1</fpage><lpage>6</lpage><pub-id pub-id-type="doi">10.1109/SBESC60926.2023.10324212</pub-id></nlm-citation></ref><ref id="ref68"><label>68</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Gwon</surname><given-names>H</given-names> </name><name name-style="western"><surname>Ahn</surname><given-names>I</given-names> </name><name name-style="western"><surname>Kim</surname><given-names>Y</given-names> </name><etal/></person-group><article-title>LDP-GAN: generative adversarial networks with local differential privacy for patient medical records synthesis</article-title><source>Comput Biol Med</source><year>2024</year><month>01</month><volume>168</volume><fpage>107738</fpage><pub-id pub-id-type="doi">10.1016/j.compbiomed.2023.107738</pub-id><pub-id pub-id-type="medline">37995536</pub-id></nlm-citation></ref><ref id="ref69"><label>69</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Ghafur</surname><given-names>S</given-names> </name><name name-style="western"><surname>Kristensen</surname><given-names>S</given-names> </name><name name-style="western"><surname>Honeyford</surname><given-names>K</given-names> </name><name name-style="western"><surname>Martin</surname><given-names>G</given-names> </name><name name-style="western"><surname>Darzi</surname><given-names>A</given-names> </name><name name-style="western"><surname>Aylin</surname><given-names>P</given-names> </name></person-group><article-title>A retrospective impact analysis of the WannaCry cyberattack on the NHS</article-title><source>NPJ Digit Med</source><year>2019</year><volume>2</volume><issue>1</issue><fpage>98</fpage><pub-id pub-id-type="doi">10.1038/s41746-019-0161-6</pub-id><pub-id pub-id-type="medline">31602404</pub-id></nlm-citation></ref><ref id="ref70"><label>70</label><nlm-citation citation-type="web"><person-group person-group-type="author"><name name-style="western"><surname>Alder</surname><given-names>S</given-names> </name></person-group><article-title>Hospital ransomware attack results in patient death</article-title><source>The HIPAA Journal</source><year>2020</year><access-date>2026-07-11</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://www.hipaajournal.com/hospital-ransomware-attack-results-in-patient-death">https://www.hipaajournal.com/hospital-ransomware-attack-results-in-patient-death</ext-link></comment></nlm-citation></ref><ref id="ref71"><label>71</label><nlm-citation citation-type="report"><person-group person-group-type="author"><name name-style="western"><surname>Ghafur</surname><given-names>S</given-names> </name><name name-style="western"><surname>Fontana</surname><given-names>G</given-names> </name><name name-style="western"><surname>Martin</surname><given-names>G</given-names> </name><name name-style="western"><surname>Grass</surname><given-names>E</given-names> </name><name name-style="western"><surname>Goodman</surname><given-names>J</given-names> </name><name name-style="western"><surname>Darzi</surname><given-names>A</given-names> </name></person-group><article-title>Improving cyber security in the NHS</article-title><year>2019</year><access-date>2026-07-19</access-date><publisher-name>Imperial College London&#x2019;s Institute of Global Health Innovation</publisher-name><comment><ext-link ext-link-type="uri" xlink:href="https://www.imperial.ac.uk/media/imperial-college/institute-of-global-health-innovation/Cyber-report-2020.pdf">https://www.imperial.ac.uk/media/imperial-college/institute-of-global-health-innovation/Cyber-report-2020.pdf</ext-link></comment></nlm-citation></ref><ref id="ref72"><label>72</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Qiu</surname><given-names>Y</given-names> </name><name name-style="western"><surname>Ma</surname><given-names>W</given-names> </name><name name-style="western"><surname>Wang</surname><given-names>H</given-names> </name><name name-style="western"><surname>Tham</surname><given-names>YC</given-names> </name><name name-style="western"><surname>Wong</surname><given-names>TY</given-names> </name></person-group><article-title>The landscape of medical AI in China</article-title><source>NEJM AI</source><year>2025</year><month>06</month><day>26</day><volume>2</volume><issue>7</issue><fpage>AIp2401234</fpage><pub-id pub-id-type="doi">10.1056/AIp2401234</pub-id></nlm-citation></ref><ref id="ref73"><label>73</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Wasserman</surname><given-names>L</given-names> </name><name name-style="western"><surname>Wasserman</surname><given-names>Y</given-names> </name></person-group><article-title>Hospital cybersecurity risks and gaps: Review (for the non-cyber professional)</article-title><source>Front Digit Health</source><year>2022</year><volume>4</volume><fpage>862221</fpage><pub-id pub-id-type="doi">10.3389/fdgth.2022.862221</pub-id><pub-id pub-id-type="medline">36033634</pub-id></nlm-citation></ref><ref id="ref74"><label>74</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>He</surname><given-names>Y</given-names> </name><name name-style="western"><surname>Aliyu</surname><given-names>A</given-names> </name><name name-style="western"><surname>Evans</surname><given-names>M</given-names> </name><name name-style="western"><surname>Luo</surname><given-names>C</given-names> </name></person-group><article-title>Health care cybersecurity challenges and solutions under the climate of COVID-19: scoping review</article-title><source>J Med Internet Res</source><year>2021</year><month>04</month><day>20</day><volume>23</volume><issue>4</issue><fpage>e21747</fpage><pub-id pub-id-type="doi">10.2196/21747</pub-id><pub-id pub-id-type="medline">33764885</pub-id></nlm-citation></ref><ref id="ref75"><label>75</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Chigada</surname><given-names>J</given-names> </name><name name-style="western"><surname>Madzinga</surname><given-names>R</given-names> </name></person-group><article-title>Cyberattacks and threats during COVID-19: a systematic literature review</article-title><source>S Afr J Inf Manage</source><year>2021</year><volume>23</volume><issue>1</issue><fpage>1</fpage><lpage>11</lpage><pub-id pub-id-type="doi">10.4102/sajim.v23i1.1277</pub-id></nlm-citation></ref><ref id="ref76"><label>76</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Monteith</surname><given-names>S</given-names> </name><name name-style="western"><surname>Bauer</surname><given-names>M</given-names> </name><name name-style="western"><surname>Alda</surname><given-names>M</given-names> </name><name name-style="western"><surname>Geddes</surname><given-names>J</given-names> </name><name name-style="western"><surname>Whybrow</surname><given-names>PC</given-names> </name><name name-style="western"><surname>Glenn</surname><given-names>T</given-names> </name></person-group><article-title>Increasing cybercrime since the pandemic: concerns for psychiatry</article-title><source>Curr Psychiatry Rep</source><year>2021</year><month>03</month><day>3</day><volume>23</volume><issue>4</issue><fpage>18</fpage><pub-id pub-id-type="doi">10.1007/s11920-021-01228-w</pub-id><pub-id pub-id-type="medline">33660091</pub-id></nlm-citation></ref><ref id="ref77"><label>77</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Minnaar</surname><given-names>A</given-names> </name><name name-style="western"><surname>Herbig</surname><given-names>FJ</given-names> </name></person-group><article-title>Cyberattacks and the cybercrime threat of ransomware to hospitals and healthcare services during the COVID-19 pandemic</article-title><source>Acta Criminol</source><year>2021</year><access-date>2026-07-23</access-date><volume>34</volume><issue>3</issue><fpage>155</fpage><lpage>185</lpage><comment><ext-link ext-link-type="uri" xlink:href="https://journals.co.za/doi/10.10520/ejc-crim_v34_n3_a10">https://journals.co.za/doi/10.10520/ejc-crim_v34_n3_a10</ext-link></comment></nlm-citation></ref><ref id="ref78"><label>78</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Khalid</surname><given-names>N</given-names> </name><name name-style="western"><surname>Qayyum</surname><given-names>A</given-names> </name><name name-style="western"><surname>Bilal</surname><given-names>M</given-names> </name><name name-style="western"><surname>Al-Fuqaha</surname><given-names>A</given-names> </name><name name-style="western"><surname>Qadir</surname><given-names>J</given-names> </name></person-group><article-title>Privacy-preserving artificial intelligence in healthcare: techniques and applications</article-title><source>Comput Biol Med</source><year>2023</year><month>05</month><volume>158</volume><fpage>106848</fpage><pub-id pub-id-type="doi">10.1016/j.compbiomed.2023.106848</pub-id><pub-id pub-id-type="medline">37044052</pub-id></nlm-citation></ref><ref id="ref79"><label>79</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Hady</surname><given-names>AA</given-names> </name><name name-style="western"><surname>Ghubaish</surname><given-names>A</given-names> </name><name name-style="western"><surname>Salman</surname><given-names>T</given-names> </name><name name-style="western"><surname>Unal</surname><given-names>D</given-names> </name><name name-style="western"><surname>Jain</surname><given-names>R</given-names> </name></person-group><article-title>Intrusion detection system for healthcare systems using medical and network data: a comparison study</article-title><source>IEEE Access</source><year>2020</year><volume>8</volume><fpage>106576</fpage><lpage>106584</lpage><pub-id pub-id-type="doi">10.1109/ACCESS.2020.3000421</pub-id></nlm-citation></ref><ref id="ref80"><label>80</label><nlm-citation citation-type="other"><person-group person-group-type="author"><name name-style="western"><surname>Mohammed</surname><given-names>A</given-names> </name></person-group><article-title>AI in cybersecurity: enhancing audits and compliance automation</article-title><source>SSRN</source><access-date>2026-07-23</access-date><comment>Preprint posted online on  Feb 11, 2025</comment><comment><ext-link ext-link-type="uri" xlink:href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5066097">https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5066097</ext-link></comment></nlm-citation></ref><ref id="ref81"><label>81</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Kaur</surname><given-names>R</given-names> </name><name name-style="western"><surname>Gabrijel&#x010D;i&#x010D;</surname><given-names>D</given-names> </name><name name-style="western"><surname>Klobu&#x010D;ar</surname><given-names>T</given-names> </name></person-group><article-title>Artificial intelligence for cybersecurity: literature review and future research directions</article-title><source>Information Fusion</source><year>2023</year><month>09</month><volume>97</volume><fpage>101804</fpage><pub-id pub-id-type="doi">10.1016/j.inffus.2023.101804</pub-id></nlm-citation></ref><ref id="ref82"><label>82</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Jha</surname><given-names>NN</given-names> </name><name name-style="western"><surname>Manwani</surname><given-names>P</given-names> </name></person-group><article-title>Self-healing payment systems via AI-driven anomaly recovery: a zero-downtime framework for secure and reliable transactions</article-title><source>Int J Comput Eng Technol</source><year>2025</year><volume>16</volume><issue>2</issue><fpage>200</fpage><lpage>212</lpage><pub-id pub-id-type="doi">10.34218/IJCET_16_02_014</pub-id></nlm-citation></ref><ref id="ref83"><label>83</label><nlm-citation citation-type="confproc"><person-group person-group-type="editor"><name name-style="western"><surname>Mukkamala</surname><given-names>S</given-names> </name><name name-style="western"><surname>Janoski</surname><given-names>G</given-names> </name><name name-style="western"><surname>Sung</surname><given-names>A</given-names> </name></person-group><article-title>Intrusion detection using neural networks and support vector machines</article-title><conf-name>Proceedings of the 2002 International Joint Conference on Neural Networks IJCNN&#x2019;02 (Cat No02CH37290)</conf-name><conf-date>May 12-17, 2002</conf-date><pub-id pub-id-type="doi">10.1109/IJCNN.2002.1007774</pub-id></nlm-citation></ref><ref id="ref84"><label>84</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Ghimire</surname><given-names>B</given-names> </name><name name-style="western"><surname>Rawat</surname><given-names>DB</given-names> </name></person-group><article-title>Recent advances on federated learning for cybersecurity and cybersecurity for federated learning for internet of things</article-title><source>IEEE Internet Things J</source><year>2022</year><volume>9</volume><issue>11</issue><fpage>8229</fpage><lpage>8249</lpage><pub-id pub-id-type="doi">10.1109/JIOT.2022.3150363</pub-id></nlm-citation></ref><ref id="ref85"><label>85</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Alazab</surname><given-names>A</given-names> </name><name name-style="western"><surname>Khraisat</surname><given-names>A</given-names> </name><name name-style="western"><surname>Singh</surname><given-names>S</given-names> </name><name name-style="western"><surname>Jan</surname><given-names>T</given-names> </name></person-group><article-title>Enhancing privacy-preserving intrusion detection through federated learning</article-title><source>Electronics (Basel)</source><year>2023</year><volume>12</volume><issue>16</issue><fpage>3382</fpage><pub-id pub-id-type="doi">10.3390/electronics12163382</pub-id></nlm-citation></ref><ref id="ref86"><label>86</label><nlm-citation citation-type="confproc"><person-group person-group-type="author"><name name-style="western"><surname>Veit</surname><given-names>A</given-names> </name><name name-style="western"><surname>Estrin</surname><given-names>D</given-names> </name><name name-style="western"><surname>Hua</surname><given-names>Y</given-names> </name><name name-style="western"><surname>Shmatikov</surname><given-names>V</given-names> </name><name name-style="western"><surname>Bagdasaryan</surname><given-names>E</given-names> </name></person-group><article-title>How to backdoor federated learning</article-title><conf-name>23rd International Conference on Artificial Intelligence and Statistics</conf-name><conf-date>Aug 26-28, 2020</conf-date></nlm-citation></ref><ref id="ref87"><label>87</label><nlm-citation citation-type="confproc"><person-group person-group-type="author"><name name-style="western"><surname>Zhu</surname><given-names>L</given-names> </name><name name-style="western"><surname>Liu</surname><given-names>Z</given-names> </name><name name-style="western"><surname>Han</surname><given-names>S</given-names> </name></person-group><article-title>Deep leakage from gradients</article-title><conf-name>Proceedings of the 33rd International Conference on Neural Information Processing Systems</conf-name><conf-date>Dec 8-14, 2019</conf-date></nlm-citation></ref><ref id="ref88"><label>88</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Pulido-Gaytan</surname><given-names>B</given-names> </name><name name-style="western"><surname>Tchernykh</surname><given-names>A</given-names> </name><name name-style="western"><surname>Cort&#x00E9;s-Mendoza</surname><given-names>JM</given-names> </name><etal/></person-group><article-title>Privacy-preserving neural networks with homomorphic encryption: challenges and opportunities</article-title><source>Peer-to-Peer Netw Appl</source><year>2021</year><month>05</month><volume>14</volume><issue>3</issue><fpage>1666</fpage><lpage>1691</lpage><pub-id pub-id-type="doi">10.1007/s12083-021-01076-8</pub-id></nlm-citation></ref><ref id="ref89"><label>89</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Apruzzese</surname><given-names>G</given-names> </name><name name-style="western"><surname>Laskov</surname><given-names>P</given-names> </name><name name-style="western"><surname>Montes de Oca</surname><given-names>E</given-names> </name><etal/></person-group><article-title>The role of machine learning in cybersecurity</article-title><source>Digit Threats Res Pract</source><year>2023</year><month>03</month><day>31</day><volume>4</volume><issue>1</issue><fpage>1</fpage><lpage>38</lpage><pub-id pub-id-type="doi">10.1145/3545574</pub-id></nlm-citation></ref><ref id="ref90"><label>90</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Bajwa</surname><given-names>J</given-names> </name><name name-style="western"><surname>Munir</surname><given-names>U</given-names> </name><name name-style="western"><surname>Nori</surname><given-names>A</given-names> </name><name name-style="western"><surname>Williams</surname><given-names>B</given-names> </name></person-group><article-title>Artificial intelligence in healthcare: transforming the practice of medicine</article-title><source>Futur Healthc J</source><year>2021</year><month>07</month><volume>8</volume><issue>2</issue><fpage>e188</fpage><lpage>e194</lpage><pub-id pub-id-type="doi">10.7861/fhj.2021-0095</pub-id></nlm-citation></ref><ref id="ref91"><label>91</label><nlm-citation citation-type="confproc"><person-group person-group-type="author"><name name-style="western"><surname>Heine</surname><given-names>F</given-names> </name><name name-style="western"><surname>Laue</surname><given-names>T</given-names> </name><name name-style="western"><surname>Kleiner</surname><given-names>C</given-names> </name></person-group><article-title>On the evaluation and deployment of machine learning approaches for intrusion detection</article-title><conf-name>2020 IEEE International Conference on Big Data (Big Data)</conf-name><conf-date>Dec 10-13, 2020</conf-date><pub-id pub-id-type="doi">10.1109/BigData50022.2020.9378479</pub-id></nlm-citation></ref><ref id="ref92"><label>92</label><nlm-citation citation-type="confproc"><person-group person-group-type="author"><name name-style="western"><surname>Moustafa</surname><given-names>N</given-names> </name><name name-style="western"><surname>Slay</surname><given-names>J</given-names> </name></person-group><article-title>UNSW-nb15: a comprehensive data set for network intrusion detection systems (UNSW-nb15 network data set)</article-title><conf-name>2015 Military Communications and Information Systems Conference</conf-name><conf-date>Nov 10-12, 2015</conf-date><pub-id pub-id-type="doi">10.1109/MilCIS.2015.7348942</pub-id></nlm-citation></ref><ref id="ref93"><label>93</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Ameen</surname><given-names>AH</given-names> </name><name name-style="western"><surname>Mohammed</surname><given-names>MA</given-names> </name><name name-style="western"><surname>Rashid</surname><given-names>AN</given-names> </name></person-group><article-title>Dimensions of artificial intelligence techniques, blockchain, and cyber security in the internet of medical things: opportunities, challenges, and future directions</article-title><source>J Intell Syst</source><year>2023</year><month>01</month><day>12</day><volume>32</volume><issue>1</issue><pub-id pub-id-type="doi">10.1515/jisys-2022-0267</pub-id><pub-id pub-id-type="medline">20220267</pub-id></nlm-citation></ref><ref id="ref94"><label>94</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Reynaud</surname><given-names>S</given-names> </name><name name-style="western"><surname>Roxin</surname><given-names>A</given-names> </name></person-group><article-title>Review of eXplainable artificial intelligence for cybersecurity systems</article-title><source>Discover Artif Intell</source><year>2025</year><volume>5</volume><issue>1</issue><fpage>78</fpage><pub-id pub-id-type="doi">10.1007/s44163-025-00318-5</pub-id></nlm-citation></ref><ref id="ref95"><label>95</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Zhang</surname><given-names>Z</given-names> </name><name name-style="western"><surname>Hamadi</surname><given-names>HA</given-names> </name><name name-style="western"><surname>Damiani</surname><given-names>E</given-names> </name><name name-style="western"><surname>Yeun</surname><given-names>CY</given-names> </name><name name-style="western"><surname>Taher</surname><given-names>F</given-names> </name></person-group><article-title>Explainable artificial intelligence applications in cyber security: state-of-the-art in research</article-title><source>IEEE Access</source><year>2022</year><volume>10</volume><fpage>93104</fpage><lpage>93139</lpage><pub-id pub-id-type="doi">10.1109/ACCESS.2022.3204051</pub-id></nlm-citation></ref><ref id="ref96"><label>96</label><nlm-citation citation-type="book"><person-group person-group-type="author"><name name-style="western"><surname>Booven</surname><given-names>DV</given-names> </name><name name-style="western"><surname>Cheng-Bang</surname><given-names>C</given-names> </name><name name-style="western"><surname>Meenakshy</surname><given-names>M</given-names> </name></person-group><person-group person-group-type="editor"><name name-style="western"><surname>Arora</surname><given-names>H</given-names> </name></person-group><article-title>Limitations of artificial intelligence in healthcare</article-title><source>Artificial Intelligence in Urologic Malignancies</source><year>2025</year><publisher-name>Academic Press</publisher-name><fpage>231</fpage><lpage>246</lpage><pub-id pub-id-type="doi">10.1016/B978-0-443-15504-8.00008-9</pub-id></nlm-citation></ref><ref id="ref97"><label>97</label><nlm-citation citation-type="report"><person-group person-group-type="author"><name name-style="western"><surname>Edwards</surname><given-names>L</given-names> </name></person-group><article-title>The EU AI act: a summary of its significance and scope</article-title><year>2021</year><access-date>2026-06-23</access-date><publisher-name>Ada Lovelace Institute</publisher-name><fpage>1</fpage><lpage>25</lpage><comment><ext-link ext-link-type="uri" xlink:href="https://www.adalovelaceinstitute.org/wp-content/uploads/2022/04/Expert-explainer-The-EU-AI-Act-11-April-2022.pdf">https://www.adalovelaceinstitute.org/wp-content/uploads/2022/04/Expert-explainer-The-EU-AI-Act-11-April-2022.pdf</ext-link></comment></nlm-citation></ref><ref id="ref98"><label>98</label><nlm-citation citation-type="web"><article-title>Artificial intelligence (regulation) bill [HL]</article-title><source>UK Parliament</source><access-date>2026-06-29</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://bills.parliament.uk/bills/3942">https://bills.parliament.uk/bills/3942</ext-link></comment></nlm-citation></ref><ref id="ref99"><label>99</label><nlm-citation citation-type="web"><article-title>NHS innovation accelerator</article-title><source>NHS England</source><access-date>2026-06-29</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://www.england.nhs.uk/aac/what-we-do/how-can-the-aac-help-me/nhs-innovation-accelerator">https://www.england.nhs.uk/aac/what-we-do/how-can-the-aac-help-me/nhs-innovation-accelerator</ext-link></comment></nlm-citation></ref><ref id="ref100"><label>100</label><nlm-citation citation-type="web"><article-title>European action plan on the cybersecurity of hospitals and healthcare providers</article-title><source>European Commission</source><access-date>2026-06-29</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://health.ec.europa.eu/ehealth-digital-health-and-care/digital-health-and-care/european-action-plan-cybersecurity-hospitals-and-healthcare-providers_en">https://health.ec.europa.eu/ehealth-digital-health-and-care/digital-health-and-care/european-action-plan-cybersecurity-hospitals-and-healthcare-providers_en</ext-link></comment></nlm-citation></ref><ref id="ref101"><label>101</label><nlm-citation citation-type="web"><article-title>Harnessing artificial intelligence for health</article-title><source>World Health Organization</source><access-date>2026-06-29</access-date><comment><ext-link ext-link-type="uri" xlink:href="https://www.who.int/teams/digital-health-and-innovation/harnessing-artificial-intelligence-for-health">https://www.who.int/teams/digital-health-and-innovation/harnessing-artificial-intelligence-for-health</ext-link></comment></nlm-citation></ref><ref id="ref102"><label>102</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Mosca</surname><given-names>M</given-names> </name></person-group><article-title>Cybersecurity in an era with quantum computers: will we be ready?</article-title><source>IEEE Secur Privacy</source><year>2018</year><volume>16</volume><issue>5</issue><fpage>38</fpage><lpage>41</lpage><pub-id pub-id-type="doi">10.1109/MSP.2018.3761723</pub-id></nlm-citation></ref><ref id="ref103"><label>103</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Ovabor</surname><given-names>K</given-names> </name><name name-style="western"><surname>Owolabi</surname><given-names>OO</given-names> </name><name name-style="western"><surname>Atkison</surname><given-names>T</given-names> </name><etal/></person-group><article-title>Quantum-driven predictive cybersecurity framework for safeguarding electronic health records (EHR) and enhancing patient data privacy in healthcare systems</article-title><source>World J Adv Res Rev</source><year>2025</year><volume>25</volume><issue>1</issue><fpage>1015</fpage><lpage>1023</lpage><pub-id pub-id-type="doi">10.30574/wjarr.2025.25.1.0124</pub-id></nlm-citation></ref><ref id="ref104"><label>104</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Gupta</surname><given-names>K</given-names> </name><name name-style="western"><surname>Saxena</surname><given-names>D</given-names> </name><name name-style="western"><surname>Rani</surname><given-names>P</given-names> </name><etal/></person-group><article-title>An intelligent quantum cyber-security framework for healthcare data management</article-title><source>IEEE Trans Automat Sci Eng</source><year>2025</year><volume>22</volume><fpage>6884</fpage><lpage>6895</lpage><pub-id pub-id-type="doi">10.1109/TASE.2024.3456209</pub-id></nlm-citation></ref><ref id="ref105"><label>105</label><nlm-citation citation-type="journal"><person-group person-group-type="author"><name name-style="western"><surname>Nguyen</surname><given-names>TT</given-names> </name><name name-style="western"><surname>Reddi</surname><given-names>VJ</given-names> </name></person-group><article-title>Deep reinforcement learning for cyber security</article-title><source>IEEE Trans Neural Netw Learning Syst</source><year>2021</year><volume>34</volume><issue>8</issue><fpage>3779</fpage><lpage>3795</lpage><pub-id pub-id-type="doi">10.1109/TNNLS.2021.3121870</pub-id></nlm-citation></ref></ref-list><app-group><supplementary-material id="app1"><label>Multimedia Appendix 1</label><p>Detailed search strategy, inclusion and exclusion criteria.</p><media xlink:href="jmir_v28i1e93950_app1.docx" xlink:title="DOCX File, 24 KB"/></supplementary-material><supplementary-material id="app2"><label>Multimedia Appendix 2</label><p>Supplementary tables outlining data charting.</p><media xlink:href="jmir_v28i1e93950_app2.docx" xlink:title="DOCX File, 88 KB"/></supplementary-material><supplementary-material id="app3"><label>Checklist 1</label><p>PRISMA-ScR Checklist.</p><media xlink:href="jmir_v28i1e93950_app3.docx" xlink:title="DOCX File, 111 KB"/></supplementary-material><supplementary-material id="app4"><label>Checklist 2</label><p>PRISMA-S checklist.</p><media xlink:href="jmir_v28i1e93950_app4.docx" xlink:title="DOCX File, 19 KB"/></supplementary-material></app-group></back></article>