ISO 22857:2013
Health informatics — Guidelines on data protection to facilitate trans-border flows of personal health data
Health informatics — Guidelines on data protection to facilitate trans-border flows of personal health data
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 56
- Дата публикации:
- 10 декабря 2013 г.
- Издание:
- ISO IS 22857 edition 2 version 1
- ICS:
- 35.240.80
ISO 22857:2013 provides guidance on data protection requirements to facilitate the transfer of personal health data across national or jurisdictional borders. It is normative only in respect of international or trans-jurisdictional exchange of personal health data. However it can be informative with respect to the protection of health information within national/jurisdictional boundaries and provide assistance to national or jurisdictional bodies involved in the development and implementation of data protection principles. ISO 22857:2013 covers both the data protection principles that apply to international or trans-jurisdictional transfers and the security policy which an organization adopts to ensure compliance with those principles. ISO 22857:2013 aims to facilitate international and trans-jurisdictional health-related applications involving the transfer of personal health data. It seeks to provide the means by which health data relating to data subjects, such as patients, will be adequately protected when sent to, and processed in, another country/jurisdiction.
Abstract
Overview
ISO 22857:2013 - Health informatics - Guidelines on data protection to facilitate trans‑border flows of personal health data - provides guidance to organisations that transfer or process personal health data across national or jurisdictional borders. The standard is normative for international or trans‑jurisdictional exchanges of personal health data and informative for in‑country data protection implementations. Its goal is to ensure that health data relating to data subjects (e.g., patients) are adequately protected when sent to, processed in, or accessed from another country or jurisdiction.
Key topics and technical requirements
ISO 22857:2013 addresses both data protection principles and the security policy an organisation should adopt. Major topics include:
- General principles and roles - definitions of responsibilities for controllers, processors and data protection officers in cross‑border settings.
- Legitimising data transfer - concepts of “adequate” data protection and conditions for lawful international transfer.
- Criteria for adequate protection - content principles (data minimisation, purpose limitation), procedural and enforcement mechanisms, and the handling of overriding laws.
- Contracts - model contract clauses and contractual safeguards for controller‑to‑controller and controller‑to‑processor relationships (see Annexes C and D).
- Anonymisation and consent - guidance on when anonymisation is appropriate and on the legitimacy and limits of consent for international processing.
- High‑level security policy - a structured security policy with principles such as executive support, documentation, defined permissions to process, data subject information, prohibition of onward transfer without consent, remedies and compensation, and operational security measures.
- Security controls and measures - recommended measures discussed include encryption and digital signatures for transmission, access controls and authentication, audit trails, physical/environmental security, malware protection, incident and breach handling, and business continuity planning (see Clause 11).
- Handling very sensitive personal health data and non‑electronic formats (Annex E and Clause 12).
Practical applications and who should use it
ISO 22857:2013 is directly applicable to organisations involved in international health information exchange, including:
- Hospitals and healthcare providers sharing patient records across borders
- Research databanks and clinical trial platforms
- Health IT vendors and cloud service providers hosting or processing health data internationally
- Third‑party contractors and system maintenance providers
- Regulators, national standards bodies, privacy officers, and legal teams developing cross‑border data protection policies
Use cases include telemedicine, multinational clinical research, international e‑health services, and cross‑jurisdictional data hosting.
Related standards and references
ISO 22857:2013 situates itself alongside key international instruments and standards such as OECD privacy guidelines, Council of Europe instruments, UN recommendations and EU data protection frameworks. It also cross‑references other ISO/IEC IT security and health informatics standards.
Keywords: ISO 22857:2013, health informatics, data protection, trans‑border flows, personal health data, security policy, anonymisation, consent, international data transfer.
Технические детали
- Технический комитет
- ISO/TC 215 - Health informatics
- SKU
- ISO 22857:2013
Похожие стандарты
Другие стандарты ISO
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…
ISO 15638-15:2014
ДействующийIntelligent transport systems — Framework for cooperative telematics applications for regulated vehicles (TAR…
Overview - ISO 15638-15:2014 (Vehicle location monitoring, TARV) ISO 15638-15:2014 is part of the ISO 15638 suite for Intelligent Transport Systems (ITS) and defines the framework and data specificat…