Integrating LLMs into IoT-Driven Smart Healthcare Systems: A Systematic Literature Review and Future Agenda
Abstract
The convergence of Large Language Models (LLMs) with the Internet of Things (IoT) is driving a transformative shift toward a continuous, context-aware smart healthcare ecosystem. Due to its novelty, existing research in this domain remains fragmented, leaving a critical gap in unified frameworks that synthesize domain applications, functional AI deployment roles, network architectures, and security boundaries. Following PRISMA 2020 guidelines, this paper presents a systematic literature review and quantitative analysis evaluating a selected corpus of 61 peer-reviewed and 14 preprint papers in this domain. Methodologically, we assess a novel hybrid article discovery strategy, finding that an AI-powered prompt-based literature search strategy achieves higher precision than traditional keyword-based Boolean queries (86% vs. 42%) on the evaluated search sample, which may reduce screening workloads. We found that the major limitation of AI-based literature search is non-determinism, which is also an inherent property of LLM-powered applications. To address this, we propose methodological guidelines for using an AI-assisted hybrid literature search strategy. Based on the selected literature, we establish a multi-layer taxonomy organizing the IoT-LLM advances in the healthcare domain across four pillars: application domain, LLM role, IoT device type, and architectural deployment pattern. Quantitative synthesis reveals a heavy research concentration in remote patient monitoring and personal health management (representing 59% of the corpus combined), primarily driven by the data accessibility of wearable sensors (64%). Cross-tabulation uncovers a distinct capability–constraint spectrum: cloud-based deployments lean on heavyweight state-of-the-art models (mainly GPT-family models) for complex semantic reasoning, whereas edge, federated, and blockchain-based hybrid systems leverage localized models (BERT and LLaMA families). Patient data privacy and reduced communication overhead were among the main reasons for choosing localized models. Crucially, our assessment reveals a pervasive neglect of LLM-specific vulnerabilities such as prompt injection and jailbreak attacks and a tendency to treat regulatory frameworks (e.g., HIPAA, GDPR) as design features rather than empirically validated compliance metrics. Finally, we propose an actionable future research agenda prioritizing multi-device system orchestration, emergency care integration, privacy-preserving LLMs, and deployment-scale clinical validation.