ISO 27799:2008 Standard Provides Information Security Guidelines for Health Sector
September 7, 2008 // Published as a news service by IHS
| |
| IHS Sells Standards & Regulations |
Environment/Safety/Health solutions from IHS include current & historical codes, regs & standards from gov't, int'l & industry sources. Complete this form for a free quote. |
|
| |
The area of personal health information and how to protect its confidentiality and integrity while ensuring its availability for health care delivery is the issue addressed by the newly published International Organization for Standardization (ISO) 27799:2008 - Health informatics - Information security management in health using ISO/International Electrotechnical Commission (IEC) 27002.
ISO 27799:2008 applies to health information in all its aspects - whatever form the information takes, whatever means are used to store it and whatever means are used to transmit it, ISO said.
The standard specifies a set of controls for managing health information security and provides health information security best practice guidelines.
By implementing this international standard, health care organizations and other custodians of health information will be able to ensure a minimum requisite level of security that is appropriate to their size and circumstances, according to ISO.
Health informatics systems must meet unique demands to remain operational in the face of natural disasters, system failures and denial-of-service attacks. At the same time, the data they contain is confidential, and its integrity must be preserved.
Because of these requirements, and regardless of their size, location and model of service delivery, all health care organizations need to have stringent controls in place to protect the health information entrusted to them, ISO said.
According to the organization, the increasing use of wireless and Internet technologies in health care delivery and the consequent growth of electronic exchange of personal health information between health professionals make the need for effective IT security management in health care more urgent and imply a benefit to adopting a common reference for information security management in health care.
ISO 27799:2008 is a companion to ISO/IEC 27002:2005 - Information technology - Security techniques - Code of practice for information security management.
Health sector professionals contributed their expertise to defining guidelines to specifically support the interpretation and implementation of ISO/IEC 27002 in health informatics, ISO said.
A consideration was the adaptability of the guidelines, bearing in mind that many health professionals work as solo health providers or in small clinics that lack dedicated IT resources to manage information security.
Although all of the security control objectives described in ISO/IEC 27002 are relevant to health informatics, some controls require additional explanations with regard to how they can be used to protect the confidentiality, integrity and availability of health information.
Also, there are some additional requirements that are specific to the health sector.
ISO 27799 contains an action plan for implementing ISO/IEC 27002 in a health environment.
Taken together, ISO said, these two standards define what is required in terms of information security in health care. Three annexes are included in the new standard, covering the general threats to health information, tasks and related documents of the information security management system and the advantages of support tools as an aid to implementation.
Source: International Organization for Standardization (ISO).
| Electronic Health Records Standards |
ASTM E 1284 Standard Guide for Construction of a Clinical Nomenclature for Support of Electronic Health Records |
ASTM E 1769 Standard Guide for Properties of Electronic Health Records and Record Systems - (Withdrawn 2004; No Replacement) |
ASTM E 1869 Standard Guide for Confidentiality, Privacy, Access, and Data Security Principles for Health Information Including Electronic Health Records |
ASTM E 2184 Standard Specification for Healthcare Document Formats |
ASTM E 1239 Standard Practice for Description of Reservation/Registration - Admission, Discharge, Transfer (R-ADT) Systems for Electronic Health Record (EHR) Systems |
ASTM E 1384 REV A Standard Practice for Content and Structure of the Electronic Health Record (EHR) |
ASTM E 1633 REV A Standard Specification for Coded Values Used in the Electronic Health Record |
ASTM E 1714 Standard Guide for Properties of a Universal Healthcare Identifier (UHID) |
ASTM E 1744 Standard Practice for View of Emergency Medical Care in the Electronic Health Record |
ASTM E 1762 Standard Guide for Electronic Authentication of Health Care Information |
ASTM E 1769 Standard Guide for Properties of Electronic Health Records and Record Systems-(Withdrawn 2004; No Replacement) |
ASTM E 1869 Standard Guide for Confidentiality, Privacy, Access, and Data Security Principles for Health Information Including Electronic Health Records |
ASTM E 2118 Standard Guide for Coordination of Clinical Laboratory Services within the Electronic Health Record Environment and Networked Architectures |
ASTM E 2171 Standard Practice for Rating-Scale Measures Relevant to the Electronic Health Record |
ASTM E 2183 Standard Guide for XML DTD Design, Architecture and Implementation |
ASTM E 2184 Standard Specification for Healthcare Document Formats |
ASTM E 2211 Standard Specification for Relationship Between a Person (Consumer) and a Supplier of an Electronic Personal (Consumer) Health Record |
ASTM E 2369 Standards Specification for Continuity of Care Record (CCR) |
ASTM E 2473 Standard Practice for the Occupational/Environmental Health View of the Electronic Health Record |
BSI DD ENV 12538 Medical Informatics - Messages for Patient Referral and Discharge |
BSI DD ENV 12612 Medical Informatics - Messages for the Exchange of Healthcare Administrative Information |
BSI DD ENV 13606-1 Health Informatics - Electronic Healthcare Record Communication - Part 1: Extended Architecture |
BSI DD ENV 13606-2 Health Informatics - Electronic Healthcare Record Communication - Part 2: Domain Term List |
BSI DD ENV 13606-3 Health Informatics - Electronic Healthcare Record Communication - Part 3: Distribution Rules |
BSI DD ENV 13606-4 Health Informatics - Electronic Healthcare Record Communication - Part 4: Messages for the Exchange of Information |
BSI DD ISO/TS 18308 Health informatics Requirements for an electronic health record architecture |
CSA ISO/TS 18308:05-CAN/CSA Health informatics Requirements for an electronic health record architecture - First Edition; ISO/TS 18308:2004 |
DIN V ENV 13606-1 Health informatics - Electronic healthcare record communication - Part 1: Extended architecture; English version ENV 13606-1:2000 |
DIN V ENV 13606-2 Health informatics - Electronic healthcare record communication - Part 2: Domain term list; English version ENV 13606-2:2000 |
DIN V ENV 13606-3 Health informatics - Electronic healthcare record communication - Part 3: Distribution rules; English version ENV 13606-3:2000 |
DIN V ENV 13606-4 Health informatics - Electronic healthcare record communication - Part 4: Messages for the exchange of information; English version ENV 13606-4:2000 |
DS DS/ENV 13606-1 Health informatics - Electronic healthcare record communication - Part 1: Extended architecture |
DS DS/ENV 13606-2 Health informatics - Electronic healthcare record communication - Part 2: Domain term list |
DS DS/ENV 13606-3 Health informatics - Electronic healthcare record communication - Part 3: Distribution rules |
DS DS/ENV 13606-4 Health informatics - Electronic healthcare record communication - Part 4: Messages for the exchange of information |
ISO TR 20514 Health informatics Electronic health record Definition, scope and context - First Edition |
ISO TS 18308 Health informatics Requirements for an electronic health record architecture - First Edition |
NCCLS LIS09-A Standard Guide For Coordination Of Clinical Laboratory Information Services Within The Electronic Health Record Environment And Networked Architectures - First Edition |