Healthcare Internet of Medical Things (IoMT) environments require intrusion detection systems that not only identify cyberattacks accurately but also provide forensic accountability, auditability, and rapid response capabilities. Conventional intrusion detection approaches primarily emphasize classification performance while offering limited support for tamper-proof event recording and post-incident investigation. This study presents a forensic-aware intrusion detection framework that integrates an Extended Bidirectional Long Short-Term Memory (BiLSTM) network with a permissioned blockchain layer to support real-time detection, secure logging, and automated mitigation in healthcare IoMT systems. The protocol combines data preprocessing, AQU-IMF-RFE feature selection, temporal sequence modeling, attention-based learning, residual connections, and blockchain-based event recording. The Extended BiLSTM model was trained and evaluated independently on the UNSW-NB15, CICIDS2017, and Bot-IoT benchmark datasets using reproducible preprocessing, stratified data partitioning, and fixed random seeds. Intrusion events detected by the model were recorded on a Proof-of-Authority blockchain through smart contracts that enabled immutable logging and automated response actions. Experimental results demonstrated high intrusion detection performance with low false-positive rates across all evaluated datasets while maintaining forensic traceability and real-time response capability. The blockchain layer provided tamper-resistant audit records and automated mitigation without introducing prohibitive computational overhead. These findings demonstrate that integrating deep-learning-based intrusion detection with blockchain-enabled forensic logging improves the trustworthiness, accountability, and practical deployability of healthcare cybersecurity systems.