Abstract
Healthcare networks increasingly depend on Electronic Health Records (EHRs), cloud computing, telemedicine, and Internet of Medical Things (IoMT) devices to support efficient healthcare delivery, creating interconnected environments that are exposed to diverse cyber threats. Conventional security mechanisms based on signatures and predefined rules often have limited capacity to detect evolving and previously unseen attacks. This study developed an Artificial Intelligence (AI)-driven cyber threat detection and intelligent security evaluation framework for healthcare networks. A synthetic dataset containing 20,000 healthcare network traffic records was generated to represent normal activities and seven cyber threat categories, including DoS/DDoS, brute force, port scanning, malware/botnet, data exfiltration, ransomware, and unauthorized access. The dataset was preprocessed, transformed through feature engineering, and divided into training, validation, and testing subsets. Decision Tree, Random Forest, and XGBoost algorithms were developed and evaluated using accuracy, precision, recall, F1-score, false-positive rate, and detection latency. Random Forest achieved the best overall performance, recording 95.00% accuracy, 90.57% precision, 98.90% recall, and 95.05% F1-score, with an average simulated detection latency of approximately 42 ms. The proposed security evaluation mechanism further converted detected threats into quantitative security scores and risk levels. The findings demonstrate the potential of AI tosupport automated healthcare cyber threat detection and continuous security evaluation, although validation using real or appropriately anonymized healthcare network data is required.

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
Copyright (c) 2026 Tech-Sphere Journal for Pure and Applied Sciences