Purpose: The growing use of digital technologies in healthcare has significantly increased exposure to cybersecurity risks, creating a need for governance approaches that go beyond traditional control-based security models. This study reviews how Governance, Risk, and Compliance (GRC) frameworks are applied in healthcare cybersecurity, focusing on their effectiveness, implementation challenges, and integration into organizational governance. Methods: Using the PRISMA methodology, literature was collected from PubMed, IEEE Xplore, and ScienceDirect, with 20 studies included in the final analysis and individually quality-appraised against six criteria. Findings: The findings indicate a shift from traditional frameworks to more flexible, integrated governance approaches that account for emerging technologies, including artificial intelligence (AI), cloud computing, and interconnected healthcare systems. While GRC frameworks help improve governance structures, strengthen cybersecurity, and support regulatory compliance, their effectiveness is often limited by factors such as skills shortages, resource constraints, regulatory complexity, and legacy systems. The study also identifies key enablers of successful implementation, including leadership involvement, cross-departmental collaboration, and continuous monitoring. Novelty: Based on these findings, an integrated healthcare cybersecurity governance framework is proposed that aligns regulatory, organizational, and technological dimensions within a unified model and provides practical insights to strengthen resilience in modern healthcare systems. Unlike prior reviews that examine GRC frameworks in isolation, this study also compares quality-appraised evidence across frameworks to show which approaches work best in different organizational contexts, including those governing AI, cloud computing, and other connected health technologies. For example, control-catalog frameworks such as ISO 27001 and COBIT are best suited to larger, well-resourced organizations, whereas AI governance frameworks succeed only once regulatory uncertainty is resolved internally.
Copyrights © 2026