ISO 25237:2017
Health informatics — Pseudonymization
Health informatics — Pseudonymization
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 62
- Дата публикации:
- 3 января 2017 г.
- Издание:
- ISO IS 25237 edition 1 version 1
- ICS:
- 35.240.80
ISO 25237:2017 contains principles and requirements for privacy protection using pseudonymization services for the protection of personal health information. This document is applicable to organizations who wish to undertake pseudonymization processes for themselves or to organizations who make a claim of trustworthiness for operations engaged in pseudonymization services. ISO 25237:2017 - defines one basic concept for pseudonymization (see Clause 5), - defines one basic methodology for pseudonymization services including organizational, as well as technical aspects (see Clause 6), - specifies a policy framework and minimal requirements for controlled re-identification (see Clause 7), - gives an overview of different use cases for pseudonymization that can be both reversible and irreversible (see Annex A), - gives a guide to risk assessment for re-identification (see Annex B), - provides an example of a system that uses de-identification (see Annex C), - provides informative requirements to an interoperability to pseudonymization services (see Annex D), and - specifies a policy framework and minimal requirements for trustworthy practices for the operations of a pseudonymization service (see Annex E).
Abstract
Overview
ISO 25237:2017 - Health informatics - Pseudonymization provides principles, requirements and guidance for protecting personal health information through pseudonymization. It is intended for organizations that perform pseudonymization themselves and for providers that claim trustworthiness as pseudonymization services. The standard defines core concepts and a practical methodology to reduce identifiability while supporting controlled re-identification when necessary.
Key topics and technical requirements
- Conceptual definition (Clause 5): establishes the standard concept of pseudonymization and distinguishes it from anonymization and de-identification.
- Methodology (Clause 6): prescribes a combined organizational and technical approach to implement pseudonymization services, addressing direct and indirect identifiers, structured and unstructured data, and inference risks.
- Controlled re-identification (Clause 7): specifies a policy framework and minimal requirements for when and how re-identification may be performed under controlled conditions.
- Risk assessment guidance (Annex B): outlines procedures to assess re-identification risk and residual identifiability.
- Use cases and implementations (Annex A, C): provides illustrative pseudonymization scenarios, examples of de-identification systems, and reversible/irreversible use cases.
- Interoperability (Annex D): informative requirements to support consistent integration of pseudonymization services across systems.
- Trustworthy operations (Annex E): policy framework and minimum requirements to ensure reliable, auditable pseudonymization services.
- Normative reference: aligns with ISO 27799 (information security management in health), reinforcing the link between pseudonymization and broader health IT security controls.
Practical applications and who should use it
ISO 25237:2017 applies to:
- Healthcare providers and health IT vendors implementing patient data sharing and identity protection
- Research organizations and clinical trial sponsors preparing datasets for secondary use
- Public health agencies and registries needing privacy-preserving surveillance and reporting
- Pharmacovigilance, patient-safety reporting, quality assessment, and peer review programs
- Trusted third‑party pseudonymization service providers and auditors
Typical applications include pseudonymous care, research datasets, de-identified data exchange, patient identifier management, public health monitoring, and confidential incident reporting.
Related standards
- ISO 27799 - Health informatics: information security management in health (normative reference in ISO 25237)
- Relevant ISO/IEC privacy and information-security standards for context and alignment
ISO 25237:2017 is a practical, implementation-focused standard for organizations that must balance data utility and patient privacy through robust pseudonymization and controlled re-identification practices. Keywords: ISO 25237:2017, pseudonymization, health informatics, data privacy, de-identification, re-identification, pseudonymization services, privacy risk assessment.
Технические детали
- Технический комитет
- ISO/TC 215 - Health informatics
- SKU
- ISO 25237:2017
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO 27799:2016
ОтменёнHealth informatics — Information security management in health using ISO/IEC 27002
Overview ISO 27799:2016 - Health informatics - Information security management in health using ISO/IEC 27002 - provides sector-specific guidance to protect personal health information. It adapts and…
BS EN ISO 25237:2017
ДействующийHealth informatics. Pseudonymization.
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…