Adaptive and Intelligent Security for Healthcare Databases in the United States: A Critical Narrative Review of Artificial Intelligence and Machine Learning Innovations, Threats and Policy Gaps

Chinyere Nelson Amaeze *

Department of Information Technology, American National University, Salem, Virginia, United States.

Ezekiel Dauda Gambo

Department of Haematology and Blood Transfusion Science, Igbinedion University, Okada, Edo State, Nigeria.

*Author to whom correspondence should be addressed.


Abstract

Background: Healthcare databases in the United States, including electronic health record systems, claims repositories, imaging archives and research data warehouses, have become high-value targets for ransomware, credential theft, insider misuse and privacy attacks. Artificial intelligence and machine learning are widely promoted as the basis for adaptive security that learns from system behaviour, yet the supporting evidence and the fitness of the governing regulatory environment remain uncertain.

Objectives: This review critically appraises evidence on security approaches for healthcare data that are enabled by artificial intelligence and machine learning, examines how the contemporary threat landscape shapes design requirements, and identifies policy gaps specific to the United States healthcare system.

Methods: A critical narrative review was conducted using structured searches of biomedical, multidisciplinary and open scholarly indexes, supplemented by federal regulatory, standards and oversight sources and by citation searching. Evidence was appraised for study design, realism of evaluation data, external validity and relevance to United States healthcare settings, and was synthesised thematically.

Principal Findings: Empirical evidence is strongest for the scale and operational consequences of ransomware and for the inadequacy of de-identification as a stand-alone safeguard. Machine learning methods for detecting inappropriate record access and network intrusions show promising discrimination in retrospective and testbed evaluations, but prospective, multi-site and adversarially tested deployments are rare, and benchmark data often represent clinical environments poorly. Federated learning, differential privacy and cryptographic computation reduce specific exposures without eliminating leakage, and recent work indicates that privacy risk is distributed unevenly across patient groups. Artificial intelligence systems themselves introduce poisoning, prompt injection and membership inference risks. Federal governance remains fragmented: the Security Rule issued under the Health Insurance Portability and Accountability Act is technology-neutral, its proposed modernisation had not been finalised by the end of the review period, and guidance on artificial intelligence is largely voluntary and subject to rapid policy change.

Conclusions: Adaptive security for healthcare databases is technically plausible but empirically immature. Progress will depend on realistic evaluation standards, security assurance for the defensive models themselves, sustained support for under-resourced organisations and clearer regulatory expectations for artificial intelligence that processes or protects health data.

Keywords: Electronic health records, health data breaches, ransomware, anomaly detection, privacy-enhancing technologies, adversarial machine learning, zero trust architecture, health information privacy regulation


How to Cite

Amaeze, Chinyere Nelson, and Ezekiel Dauda Gambo. 2026. “Adaptive and Intelligent Security for Healthcare Databases in the United States: A Critical Narrative Review of Artificial Intelligence and Machine Learning Innovations, Threats and Policy Gaps”. Journal of Scientific Research and Reports 32 (10):56-78. https://doi.org/10.9734/jsrr/2026/v32i104526.

Downloads

Download data is not yet available.