An Integrated Cybersecurity Governance Ecosystem for Healthcare: A Quality-Appraised Systematic Review of Governance, Risk, and Compliance Frameworks for AI, Cloud, and Connected Health Technologies

Authors

  • Chipo Miranda Mukwaira National University of Science and Technology Author
  • Yvonne Chigariro National University of Science and Technology Author
  • Belinda Ndlovu National University of Science and Technology Author https://orcid.org/0000-0001-6046-3240

DOI:

https://doi.org/10.15294/sji.v13i3.49854

Keywords:

Healthcare Cybersecurity Governance, Governance, Risk, and Compliance (GRC), Artificial Intelligence Governance, Cloud Computing Security, Digital Health

Abstract

Purpose: The growing use of digital technologies in healthcare has significantly increased exposure to cybersecurity risks, creating a need for governance approaches that go beyond traditional control-based security models. This study reviews how Governance, Risk, and Compliance (GRC) frameworks are applied in healthcare cybersecurity, focusing on their effectiveness, implementation challenges, and integration into organizational governance.

Methods: Using the PRISMA methodology, literature was collected from PubMed, IEEE Xplore, and ScienceDirect, with 20 studies included in the final analysis and individually quality-appraised against six criteria.

Findings: The findings indicate a shift from traditional frameworks to more flexible, integrated governance approaches that account for emerging technologies, including artificial intelligence (AI), cloud computing, and interconnected healthcare systems. While GRC frameworks help improve governance structures, strengthen cybersecurity, and support regulatory compliance, their effectiveness is often limited by factors such as skills shortages, resource constraints, regulatory complexity, and legacy systems. The study also identifies key enablers of successful implementation, including leadership involvement, cross-departmental collaboration, and continuous monitoring.

Novelty: Based on these findings, an integrated healthcare cybersecurity governance framework is proposed that aligns regulatory, organizational, and technological dimensions within a unified model and provides practical insights to strengthen resilience in modern healthcare systems. Unlike prior reviews that examine GRC frameworks in isolation, this study also compares quality-appraised evidence across frameworks to show which approaches work best in different organizational contexts, including those governing AI, cloud computing, and other connected health technologies. For example, control-catalog frameworks such as ISO 27001 and COBIT are best suited to larger, well-resourced organizations, whereas AI governance frameworks succeed only once regulatory uncertainty is resolved internally.

Downloads

Published

12-08-2026

Article ID

49854

Issue

Section

Articles

How to Cite

An Integrated Cybersecurity Governance Ecosystem for Healthcare: A Quality-Appraised Systematic Review of Governance, Risk, and Compliance Frameworks for AI, Cloud, and Connected Health Technologies. (2026). Scientific Journal of Informatics, 13(3), 617-636. https://doi.org/10.15294/sji.v13i3.49854