Scientific Journal of Informatics
Vol. 13 No. 3: August 2026

An Integrated Cybersecurity Governance Ecosystem for Healthcare: A Quality-Appraised Systematic Review of Governance, Risk, and Compliance Frameworks for AI, Cloud, and Connected Health Technologies

Chipo Miranda Mukwaira (National University of Science and Technology)
Yvonne Chigariro (National University of Science and Technology)
Belinda Ndlovu (National University of Science and Technology)



Article Info

Publish Date
12 Aug 2026

Abstract

Purpose: The growing use of digital technologies in healthcare has significantly increased exposure to cybersecurity risks, creating a need for governance approaches that go beyond traditional control-based security models. This study reviews how Governance, Risk, and Compliance (GRC) frameworks are applied in healthcare cybersecurity, focusing on their effectiveness, implementation challenges, and integration into organizational governance. Methods: Using the PRISMA methodology, literature was collected from PubMed, IEEE Xplore, and ScienceDirect, with 20 studies included in the final analysis and individually quality-appraised against six criteria. Findings: The findings indicate a shift from traditional frameworks to more flexible, integrated governance approaches that account for emerging technologies, including artificial intelligence (AI), cloud computing, and interconnected healthcare systems. While GRC frameworks help improve governance structures, strengthen cybersecurity, and support regulatory compliance, their effectiveness is often limited by factors such as skills shortages, resource constraints, regulatory complexity, and legacy systems. The study also identifies key enablers of successful implementation, including leadership involvement, cross-departmental collaboration, and continuous monitoring. Novelty: Based on these findings, an integrated healthcare cybersecurity governance framework is proposed that aligns regulatory, organizational, and technological dimensions within a unified model and provides practical insights to strengthen resilience in modern healthcare systems. Unlike prior reviews that examine GRC frameworks in isolation, this study also compares quality-appraised evidence across frameworks to show which approaches work best in different organizational contexts, including those governing AI, cloud computing, and other connected health technologies. For example, control-catalog frameworks such as ISO 27001 and COBIT are best suited to larger, well-resourced organizations, whereas AI governance frameworks succeed only once regulatory uncertainty is resolved internally.

Copyrights © 2026






Journal Info

Abbrev

sji

Publisher

Subject

Computer Science & IT Control & Systems Engineering Decision Sciences, Operations Research & Management Electrical & Electronics Engineering Engineering

Description

Scientific Journal of Informatics (p-ISSN 2407-7658 | e-ISSN 2460-0040) published by the Department of Computer Science, Universitas Negeri Semarang, a scientific journal of Information Systems and Information Technology which includes scholarly writings on pure research and applied research in the ...