IHS Inc. The Source for Critical Information and Insight
All Industries |  Change  

Go
 
 

ISO 27799:2008 Standard Provides Information Security Guidelines for Health Sector

September 7, 2008 // Published as a news service by IHS

 
IHS Sells Standards & Regulations
Environment/Safety/Health solutions from IHS include current & historical codes, regs & standards from gov't, int'l & industry sources.
Complete this form for a free quote.
CyberRegs - Compliance library
ASTM / NFPA / ASME / ISO
API / ASSE / AWS / NEMA / UL
Safety Compliance Collection
Environment Compliance Collection
First Name:

Last Name:

Email address:
The area of personal health information and how to protect its confidentiality and integrity while ensuring its availability for health care delivery is the issue addressed by the newly published International Organization for Standardization (ISO) 27799:2008 - Health informatics - Information security management in health using ISO/International Electrotechnical Commission (IEC) 27002.

ISO 27799:2008 applies to health information in all its aspects - whatever form the information takes, whatever means are used to store it and whatever means are used to transmit it, ISO said.

The standard specifies a set of controls for managing health information security and provides health information security best practice guidelines.

By implementing this international standard, health care organizations and other custodians of health information will be able to ensure a minimum requisite level of security that is appropriate to their size and circumstances, according to ISO.

Health informatics systems must meet unique demands to remain operational in the face of natural disasters, system failures and denial-of-service attacks. At the same time, the data they contain is confidential, and its integrity must be preserved.

Because of these requirements, and regardless of their size, location and model of service delivery, all health care organizations need to have stringent controls in place to protect the health information entrusted to them, ISO said.

According to the organization, the increasing use of wireless and Internet technologies in health care delivery and the consequent growth of electronic exchange of personal health information between health professionals make the need for effective IT security management in health care more urgent and imply a benefit to adopting a common reference for information security management in health care.

ISO 27799:2008 is a companion to ISO/IEC 27002:2005 - Information technology - Security techniques - Code of practice for information security management.

Health sector professionals contributed their expertise to defining guidelines to specifically support the interpretation and implementation of ISO/IEC 27002 in health informatics, ISO said.

A consideration was the adaptability of the guidelines, bearing in mind that many health professionals work as solo health providers or in small clinics that lack dedicated IT resources to manage information security.

Although all of the security control objectives described in ISO/IEC 27002 are relevant to health informatics, some controls require additional explanations with regard to how they can be used to protect the confidentiality, integrity and availability of health information.

Also, there are some additional requirements that are specific to the health sector.

ISO 27799 contains an action plan for implementing ISO/IEC 27002 in a health environment.

Taken together, ISO said, these two standards define what is required in terms of information security in health care. Three annexes are included in the new standard, covering the general threats to health information, tasks and related documents of the information security management system and the advantages of support tools as an aid to implementation.

Source: International Organization for Standardization (ISO).


Electronic Health Records Standards
ASTM E 1284
Standard Guide for Construction of a Clinical Nomenclature for Support of Electronic Health Records
ASTM E 1769
Standard Guide for Properties of Electronic Health Records and Record Systems - (Withdrawn 2004; No Replacement)
ASTM E 1869
Standard Guide for Confidentiality, Privacy, Access, and Data Security Principles for Health Information Including Electronic Health Records
ASTM E 2184
Standard Specification for Healthcare Document Formats
ASTM E 1239
Standard Practice for Description of Reservation/Registration - Admission, Discharge, Transfer (R-ADT) Systems for Electronic Health Record (EHR) Systems
ASTM E 1384 REV A
Standard Practice for Content and Structure of the Electronic Health Record (EHR)
ASTM E 1633 REV A
Standard Specification for Coded Values Used in the Electronic Health Record
ASTM E 1714
Standard Guide for Properties of a Universal Healthcare Identifier (UHID)
ASTM E 1744
Standard Practice for View of Emergency Medical Care in the Electronic Health Record
ASTM E 1762
Standard Guide for Electronic Authentication of Health Care Information
ASTM E 1769
Standard Guide for Properties of Electronic Health Records and Record Systems-(Withdrawn 2004; No Replacement)
ASTM E 1869
Standard Guide for Confidentiality, Privacy, Access, and Data Security Principles for Health Information Including Electronic Health Records
ASTM E 2118
Standard Guide for Coordination of Clinical Laboratory Services within the Electronic Health Record Environment and Networked Architectures
ASTM E 2171
Standard Practice for Rating-Scale Measures Relevant to the Electronic Health Record
ASTM E 2183
Standard Guide for XML DTD Design, Architecture and Implementation
ASTM E 2184
Standard Specification for Healthcare Document Formats
ASTM E 2211
Standard Specification for Relationship Between a Person (Consumer) and a Supplier of an Electronic Personal (Consumer) Health Record
ASTM E 2369
Standards Specification for Continuity of Care Record (CCR)
ASTM E 2473
Standard Practice for the Occupational/Environmental Health View of the Electronic Health Record
BSI DD ENV 12538
Medical Informatics - Messages for Patient Referral and Discharge
BSI DD ENV 12612
Medical Informatics - Messages for the Exchange of Healthcare Administrative Information
BSI DD ENV 13606-1
Health Informatics - Electronic Healthcare Record Communication - Part 1: Extended Architecture
BSI DD ENV 13606-2
Health Informatics - Electronic Healthcare Record Communication - Part 2: Domain Term List
BSI DD ENV 13606-3
Health Informatics - Electronic Healthcare Record Communication - Part 3: Distribution Rules
BSI DD ENV 13606-4
Health Informatics - Electronic Healthcare Record Communication - Part 4: Messages for the Exchange of Information
BSI DD ISO/TS 18308
Health informatics Requirements for an electronic health record architecture
CSA ISO/TS 18308:05-CAN/CSA
Health informatics Requirements for an electronic health record architecture - First Edition; ISO/TS 18308:2004
DIN V ENV 13606-1
Health informatics - Electronic healthcare record communication - Part 1: Extended architecture; English version ENV 13606-1:2000
DIN V ENV 13606-2
Health informatics - Electronic healthcare record communication - Part 2: Domain term list; English version ENV 13606-2:2000
DIN V ENV 13606-3
Health informatics - Electronic healthcare record communication - Part 3: Distribution rules; English version ENV 13606-3:2000
DIN V ENV 13606-4
Health informatics - Electronic healthcare record communication - Part 4: Messages for the exchange of information; English version ENV 13606-4:2000
DS DS/ENV 13606-1
Health informatics - Electronic healthcare record communication - Part 1: Extended architecture
DS DS/ENV 13606-2
Health informatics - Electronic healthcare record communication - Part 2: Domain term list
DS DS/ENV 13606-3
Health informatics - Electronic healthcare record communication - Part 3: Distribution rules
DS DS/ENV 13606-4
Health informatics - Electronic healthcare record communication - Part 4: Messages for the exchange of information
ISO TR 20514
Health informatics Electronic health record Definition, scope and context - First Edition
ISO TS 18308
Health informatics Requirements for an electronic health record architecture - First Edition
NCCLS LIS09-A
Standard Guide For Coordination Of Clinical Laboratory Information Services Within The Electronic Health Record Environment And Networked Architectures - First Edition
ENGINEERING STANDARDS & REGULATIONS NEWS
November 5, 2009
ISO, ILAC, IAF Streamline Quality Mgmt. Requirements for Medical Labs
In a joint communiqué by the International Organization for Standardization (ISO), the International Laboratory Accreditation Cooperation (ILAC) ... more
October 30, 2009
ASTM D7558 Addresses Medical Glove Allergens
ASTM International issued a standard that allows rubber glove manufacturers to monitor the level of residual chemicals in their end products ... more
October 30, 2009
ANSI Begins Accreditation Under Toy Safety Certification Program
The American National Standards Institute (ANSI) accredited five certification bodies under the new Toy Industry Association (TIA) Toy Safety ... more
October 23, 2009
EU-China Standards Information Platform Launched
The European Committee for Standardization (CEN) announced the official launch of the new EU-China Standards Information Platform, a project ... more
October 16, 2009
DIN Announces Launch of Germany-China Standards Information Portal
The German Institute for Standardization (Deutsches Institut für Normung e.V., or DIN) announced the launch of the new Germany-China Standards ... more
Show All..