Citation

BibTex format

@article{Rajput:2026:10.2196/93950,
author = {Rajput, K and Zuberi, S and Elhajj, M and Ochieng, W and Darzi, A and Ghafur, S},
doi = {10.2196/93950},
journal = {J Med Internet Res},
title = {Mapping Machine Learning-Driven Cybersecurity Solutions in Health Care: Scoping Literature Review.},
url = {http://dx.doi.org/10.2196/93950},
volume = {28},
year = {2026}
}

RIS format (EndNote, RefMan)

TY  - JOUR
AB - BACKGROUND: Health care systems face escalating cyberattacks, including the UK Synnovis ransomware attack, which halted pathology services for 14 weeks; the Ascension Health breach affecting 5.6 million patients; and the Change Healthcare breach costing US $2.5 billion. Conventional cybersecurity measures in health care remain reactive and inadequate against evolving threats. Machine learning (ML) offers adaptive, predictive, real-time cyber defense; yet, there is limited clarity on how ML tools are applied across cybersecurity domains, their real-world effectiveness, and where gaps remain. OBJECTIVE: This study aims to map ML applications in health care cybersecurity against the National Institute of Standards and Technology Cybersecurity Framework version 2.0, summarize ML performance, and identify research gaps and implementation considerations. METHODS: A systematic search of Ovid MEDLINE, Embase, and Scopus was conducted on July 30, 2025, for studies between 2019 and 2025. Eligible studies applied ML-based approaches to organizational-level cybersecurity in health care settings, with outcomes related to data privacy or cybersecurity strengthening. Studies on smart devices, blockchain, or those lacking empirical data were excluded. Title and abstract and full-text screening were conducted independently by 2 (KR and SZ) reviewers following the Arksey and O'Malley framework and PRISMA-ScR (Preferred Reporting Items for Systematic Reviews and Meta-Analyses extension for Scoping Reviews) guidelines, with discrepancies resolved by consensus. Data were synthesized narratively and mapped against the 6 National Institute of Standards and Technology Cybersecurity Framework version 2.0 functions (Identify, Protect, Detect, Respond, Recover, and Govern). RESULTS: From 10,348 articles identified, 45 studies across 18 countries were included, applying 80 ML models. Most studies addressed "Protect" (n=22, 48.9%), encompassing federated learning, homomorphic encrypti
AU - Rajput,K
AU - Zuberi,S
AU - Elhajj,M
AU - Ochieng,W
AU - Darzi,A
AU - Ghafur,S
DO - 10.2196/93950
PY - 2026///
TI - Mapping Machine Learning-Driven Cybersecurity Solutions in Health Care: Scoping Literature Review.
T2 - J Med Internet Res
UR - http://dx.doi.org/10.2196/93950
UR - https://www.ncbi.nlm.nih.gov/pubmed/42507996
VL - 28
ER -