ISO 21298:2017
Health informatics — Functional and structural roles
Health informatics — Functional and structural roles
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 33
- Дата публикации:
- 14 февраля 2017 г.
- Издание:
- ISO IS 21298 edition 1 version 1
- ICS:
- 35.240.80
ISO 21298:2017 defines a model for expressing functional and structural roles and populates it with a basic set of roles for international use in health applications. Roles are generally assigned to entities that are actors. This will focus on roles of persons (e.g. the roles of health professionals) and their roles in the context of the provision of care (e.g. subject of care). Roles can be structural (e.g. licensed general practitioner, non-licensed transcriptionist, etc.) or functional (e.g. a provider who is a member of a therapeutic team, an attending physician, prescriber, etc.). Structural roles are relatively static, often lasting for many years. They deal with relationships between entities expressed at a level of complex concepts. Functional roles are bound to the realization of actions and are highly dynamic. They are normally expressed at a decomposed level of fine-grained concepts. Roles addressed in this document are not restricted to privilege management purposes, though privilege management and access control is one of the applications of this document. This document does not address specifications related to permissions. This document treats the role and the permission as separate constructs. Further details regarding the relationship with permissions, policy, and access control are provided in ISO 22600.
Abstract
Overview
ISO 21298:2017 - "Health informatics - Functional and structural roles" specifies a model for expressing functional and structural roles used in international health applications. The standard populates that model with a basic set of roles focused primarily on persons (for example, health professionals and subjects of care). It distinguishes relatively static structural roles (e.g., licensed general practitioner, non‑licensed transcriptionist) from dynamic functional roles (e.g., attending physician, prescriber, member of a therapeutic team). ISO 21298:2017 treats role and permission as separate constructs and does not define permission specifications; relationships with permissions, policy and access control are addressed in ISO 22600.
Key topics and technical requirements
- Role model definition: A formal model for encoding role information for health actors that supports international and inter‑jurisdictional use.
- Structural vs functional roles: Clear definitions and examples; structural roles reflect long‑term competencies or organizational relations, functional roles are bound to actions and are fine‑grained.
- Architectural context: Guidance on modelling roles within a Generic Component Model and how roles relate to policy and privilege management.
- Certificates and encoding: Use cases for embedding role information in PKI constructs (attribute certificates, role assignment certificates); Annex B provides a sample certificate profile.
- Interoperability mappings: Support for mappings such as ISCO‑08 sample mapping (Annex A) to aid trans‑jurisdiction mapping of professions and specialties.
- Separation of concerns: Explicit separation between role definitions and permission/policy specifications (permissions handled separately, see ISO 22600).
- Use cases and formal modelling: Examples for directories, audit trails, privilege assertions, and practical guidance on assigning and transforming roles.
Applications and who should use it
ISO 21298:2017 is practical for:
- EHR and clinical system vendors implementing role‑based access control (RBAC) or role-aware workflows
- Identity and access management, directory services and PKI implementers encoding health roles in certificates
- Health IT architects and integrators designing secure, interoperable systems across regions
- Healthcare organizations and administrators mapping professional qualifications and specialties for staffing, referrals, billing, and auditing
- Standards bodies and implementers working with HL7, ISO 22600, ISO 21091 and related health informatics profiles
Key practical benefits include consistent role vocabularies for directories, audit trails, PKI certificates, and improved interoperability for cross‑border or multi‑organization care.
Related standards
- ISO 22600 (policy, permissions, access control)
- ISO 21091 (directory services concepts)
- ISO 17090 (PKI for healthcare)
- HL7 and other health‑informatics profiles that reference role concepts
Keywords: ISO 21298:2017, health informatics, functional roles, structural roles, RBAC, privilege management, PKI, healthcare identity management, EHR interoperability.
Технические детали
- Технический комитет
- ISO/TC 215 - Health informatics
- SKU
- ISO 21298:2017
Похожие стандарты
Стандарты, упомянутые в описании
BS EN ISO 22600-1:2014
ДействующийHealth informatics. Privilege management and access control. Overview and policy management.
ISO 21091:2013
ДействующийHealth informatics — Directory services for healthcare providers, subjects of care and other entities
Overview ISO 21091:2013 - Health informatics - Directory services for healthcare providers, subjects of care and other entities - defines minimal, community-focused specifications for healthcare dire…