Overview
ISO 13606-4:2019 - part of the ISO 13606 series on electronic health record (EHR) communication - defines a security methodology for specifying privileges required to access EHR data. It sits inside the EHR communications architecture described in ISO 13606-1 and focuses specifically on access-control information and the representation of EHR-specific security metadata that can inform automated access decisions. The standard addresses how to represent access policy and audit information within an EHR_EXTRACT but does not prescribe organizational access rules or security measures unrelated to EHR communication.
Key topics and technical requirements
- Access policy modelling: A framework for representing fine‑grained access policies and sensitivity labels within EHR extracts so that requesters and providers can negotiate access consistently.
- Functional roles and sensitivity mapping: Definitions and a vocabulary for functional roles and mechanisms to map those roles to record-component sensitivity levels; jurisdictions may extend or adapt terms (aligned with CONTSYS vocabulary practices).
- Representation within EHR_EXTRACT: Structured information elements (access policy composition, targets, request criteria, sensitivity constraints, attestation information) for embedding policy metadata in exchanged EHR content.
- Audit log representation: A model for audit log extracts aligned with ISO 27789 (EHR audit trails), expanded to include EHR-extract-specific information required when communicating records.
- Conformance and interoperability guidance: Rules for conformance and references to technical solutions and other standards for implementing services that meet these security needs.
- Scope limitations: Security aspects not specific to EHR communication (e.g., internal system security controls) are outside this part.
Practical applications and users
ISO 13606-4:2019 is used to enable secure, interoperable exchange of EHR data where access decisions need to be auditable and automatable:
- EHR and health information system vendors implementing access-control metadata in exchanged records.
- Health IT architects and integrators designing interoperable EHR exchange workflows that respect patient consent and sensitivity constraints.
- Security engineers and privacy officers creating audit logging and disclosure-tracking mechanisms for shared EHRs.
- Policymakers and standards bodies defining national or cross‑border EHR exchange rules and consent models.
Related standards
- ISO 13606-1 (EHR communication architecture)
- ISO 13606 series (other parts)
- ISO 22600 (privilege management and access control / consent context)
- ISO 27789 (audit trail taxonomy for digital health records)
- ISO 22857 (cross-border EHR security guidance)
- CONTSYS (vocabulary alignment for functional roles)
ISO 13606-4:2019 supports secure, auditable EHR communication by standardizing how access privileges, sensitivity, and audit information are represented - enabling automated, interoperable access decisions while leaving policy choices to jurisdictions and care providers.