ISO 17090-1:2021
Health informatics — Public key infrastructure — Part 1: Overview of digital certificate services
Health informatics — Public key infrastructure — Part 1: Overview of digital certificate services
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 41
- Дата публикации:
- 8 марта 2021 г.
- Издание:
- ISO IS 17090 edition 3 version 1
- ICS:
- 35.240.80
This document defines the basic concepts underlying the use of digital certificates in healthcare and provides a scheme of interoperability requirements to establish a digital certificate-enabled secure communication of health information. It also identifies the major stakeholders who are communicating health-related information, as well as the main security services required for health communication where digital certificates can be required. This document gives a brief introduction to public key cryptography and the basic components needed to deploy digital certificates in healthcare. It further introduces different types of digital certificates — identity certificates and associated attribute certificates for relying parties, self-signed certification authority (CA) certificates, and CA hierarchies and bridging structures.
Abstract
Overview
ISO 17090-1:2021 - part of the ISO 17090 series for health informatics - provides an accessible introduction to using public key infrastructure (PKI) and digital certificates in healthcare. The standard defines core concepts, stakeholders (certificate holders and relying parties), and a scheme of interoperability requirements that enable secure, certificate-enabled exchange of health information across organizations and jurisdictions. It also explains basic public key cryptography and the certificate types commonly used in healthcare systems.
Key topics and technical requirements
- Public key cryptography basics: role of asymmetric vs. symmetric cryptography, digital signatures, and private key protection.
- Digital certificate types: identity certificates, attribute certificates, self-signed CA certificates, CA hierarchies and bridging structures.
- Security services in healthcare: authentication, integrity, confidentiality (encipherment), digital signatures, authorization, and access control.
- Deployment components: Certification Authorities (CAs), Registration Authorities (RAs), Certificate Policies (CP) and Certification Practice Statements (CPS).
- Establishing identity and roles: using qualified identity certificates and attribute certificates for specialty/role-based access.
- Interoperability models: options for cross-domain trust such as single CA hierarchies, relying-party-managed trust, cross-recognition, cross-certification, and Bridge CAs.
- Policy and management: healthcare-specific policy requirements, separation of authentication from data encipherment, and security management frameworks for digital certificates.
Applications and practical value
ISO 17090-1 is practical guidance for implementing PKI to secure electronic health records (EHRs), clinical messaging, device communication, patient portals, and cross-organizational information exchange. Typical use cases:
- Enabling authenticated clinician access to patient data across hospitals and clinics.
- Protecting confidentiality of health data in transit (encipherment) and ensuring message integrity.
- Applying digital signatures for clinical orders, prescriptions, and legal audit trails.
- Using attribute certificates for role-based authorization and fine-grained access control.
- Designing cross-border trust frameworks for national health information exchanges.
Who should use this standard
- Healthcare IT architects and CIOs
- Information security officers and compliance teams
- PKI/Cybersecurity vendors and CA operators
- EHR and medical device vendors
- Health data exchange organizations and policymakers
- Registration authorities and relying parties implementing secure health communication
Related standards
ISO 17090-1 is the overview part of the ISO 17090 PKI series (see ISO website for other parts). It was prepared by ISO/TC 215 (Health informatics) and complements broader PKI and health informatics standards that define technical, procedural, and policy requirements for certificate use in healthcare.
Технические детали
- Технический комитет
- ISO/TC 215 - Health informatics
- SKU
- ISO 17090-1:2021
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS ISO 17090-5:2017
ДействующийHealth informatics. Public key infrastructure. Authentication using Healthcare PKI credentials.
BS ISO 17090-1:2021
ДействующийHealth informatics. Public key infrastructure. Overview of digital certificate services.
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…