Health informatics — Information security management in health using ISO/IEC 27002.
Overview
What is ISO 27799?
ISO 27799 is an international standard that provides information security guidance specifically for healthcare organizations and healthcare information systems.
The standard builds upon the information security controls described in ISO/IEC 27002 and provides additional healthcare-specific guidance for protecting health information, medical records, clinical systems, and related healthcare services.
ISO 27799 helps healthcare organizations manage information security risks while supporting confidentiality, integrity, availability, and appropriate access to health information.
The standard is commonly used alongside ISO/IEC 27001 as part of a broader healthcare information security framework.
Key Themes
What does the standard focus on?
Protection of Health Information
Safeguarding health data, clinical records, and patient-related information against unauthorized access, disclosure, or loss.
Patient Privacy
Ensuring that personally identifiable health information is handled with appropriate confidentiality controls throughout its lifecycle.
Clinical Information Security
Protecting clinical systems, electronic health records, and the integrity of information used in direct patient care.
Healthcare Information Governance
Establishing clear policies and responsibilities for managing health information assets within healthcare organizations.
Access Control
Ensuring that access to health information and clinical systems is granted only to authorized individuals in appropriate contexts.
Information Availability
Maintaining access to health information when required for patient care, while protecting against inappropriate disclosure.
Healthcare Risk Management
Identifying, assessing, and treating information security risks in healthcare contexts, including risks to patient safety.
Confidentiality of Medical Records
Protecting the confidentiality of medical records and sensitive health data throughout storage, transmission, and disposal.
Applicability
Who typically uses ISO 27799?
Hospitals
Large acute care facilities managing extensive clinical records, patient data, and complex healthcare information systems.
Clinics
Outpatient and primary care settings that process patient health information and maintain clinical records.
Healthcare Providers
Organizations providing direct patient care services that rely on the confidentiality and integrity of health information.
Laboratories
Diagnostic and pathology laboratories handling sensitive patient samples and associated health data.
Medical Device Organizations
Manufacturers and suppliers of medical devices that capture, process, or transmit patient health information.
Health Insurance Providers
Insurers and payers processing health claims, medical histories, and other sensitive member health data.
Healthcare Technology Companies
Technology vendors developing software, platforms, and systems designed for healthcare information management.
Electronic Medical Record Providers
Organizations developing and operating electronic health record and clinical information systems for healthcare settings.
Telemedicine Providers
Organizations delivering remote clinical consultations and digital health services that transmit patient health information.
Organizations Processing Health Information
Any organization that handles, stores, or transmits identifiable health information on behalf of healthcare services.
Benefits
Why organizations adopt ISO 27799
Improved Protection of Health Information
Structured guidance for applying appropriate security controls to health data across clinical and administrative environments.
Enhanced Patient Trust
Demonstrates commitment to responsible management of sensitive health information, supporting patient confidence in healthcare services.
Improved Information Security Governance
Supports the development of clear accountability and oversight structures for health information security within organizations.
Support for Healthcare Privacy Programs
Provides a technical and organizational framework that complements privacy obligations relating to health information.
Reduced Information Security Risks
Helps organizations identify, assess, and address information security risks specific to healthcare operating environments.
Improved Protection of Clinical Systems
Strengthens the security posture of systems used in direct patient care, clinical workflows, and health data management.
Better Operational Resilience
Reduces the impact of information security incidents on healthcare operations and patient care continuity.
Support for Regulatory and Compliance Objectives
Provides a recognized international framework that can support alignment with healthcare information security requirements.
Regulatory Context
Why is ISO 27799 important?
Healthcare organizations process highly sensitive information relating to patients, medical conditions, treatments, diagnoses, and healthcare operations. The security and confidentiality of this information is fundamental to patient trust and safe healthcare delivery.
Healthcare information security expectations are frequently driven by:
ISO 27799 provides practical guidance for protecting healthcare information and supporting responsible information security practices within healthcare environments. The standard may support healthcare organizations in demonstrating good security governance, but it does not replace legal, regulatory, or healthcare accreditation requirements.
FAQ
Common questions about ISO 27799
ISO 27799:2016 is an international standard that provides information security guidance specifically for the healthcare sector. It builds upon ISO/IEC 27002 to offer controls and implementation guidance tailored to the protection of health information in healthcare environments.
No. ISO 27799 is a guidance standard and does not provide a standalone certification scheme. Organizations cannot be independently certified against ISO 27799. It is designed to be used alongside ISO/IEC 27001, which is the certifiable management system standard for information security.
ISO/IEC 27001 specifies requirements for an Information Security Management System applicable to any organization and provides a framework for formal certification. ISO 27799 is a guidance document that provides healthcare-specific controls and implementation advice to be applied within that broader information security framework.
ISO 27799 is intended for healthcare organizations and any organization that processes health information. This includes hospitals, clinics, laboratories, health insurance providers, healthcare technology companies, electronic medical record providers, and telemedicine services.
Yes. Healthcare technology companies, software vendors, and cloud service providers that develop or operate systems for healthcare settings can use ISO 27799 to understand and apply appropriate security controls for health information they process or host on behalf of healthcare organizations.
Yes. ISO 27799 addresses the confidentiality and appropriate handling of patient health information as a core concern. While it is primarily an information security standard rather than a privacy standard, its guidance supports the protection of patient data and complements privacy frameworks such as ISO/IEC 27701.
Yes. ISO 27799 provides a structured approach to managing information security risks in healthcare environments and includes guidance relevant to cybersecurity threats affecting clinical systems, medical devices, and health data infrastructure. It is commonly used alongside other cybersecurity frameworks within comprehensive healthcare security programs.
No. ISO 27799 is a voluntary international standard. It does not replace applicable healthcare regulations, privacy laws, or accreditation requirements. Organizations must continue to comply with all relevant legal and regulatory obligations, and should use ISO 27799 as a complement to, not a substitute for, those requirements.
Not necessarily. Organizations can reference ISO 27799 independently to improve their healthcare information security practices. However, the standard is designed to be used alongside ISO/IEC 27001 and ISO/IEC 27002. Organizations with an existing ISO/IEC 27001 framework will generally find it easier to apply ISO 27799 guidance systematically.
Organizations typically begin by identifying and classifying health information assets, understanding clinical and administrative information flows, and assessing current security controls against the guidance provided by ISO 27799. Reviewing the standard alongside ISO/IEC 27001 and ISO/IEC 27002 provides the most complete foundation for a healthcare information security program.