ISO 27799:2025
Health informatics — Information security controls in health based on ISO/IEC 27002
Health informatics — Information security controls in health based on ISO/IEC 27002
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 72
- Дата публикации:
- 18 декабря 2025 г.
- Издание:
- ISO IS 27799 edition 3 version 1
- ICS:
- 35.030
This document provides information security controls, including implementation guidance, for health organizations. It is based on ISO/IEC 27002:2022 In addition to generic ICT equipment and software used in many other environments, the scope of this document includes software and systems specifically for healthcare, such as electronic health record systems and medical devices incorporating health software. Such medical devices can be programmed or programmable and can contain software, firmware or both. Other digital equipment (such as that for environmental and infection control, building management, and physical security), which can be used in premises where healthcare is provided, is also in scope. This document applies to information in all its aspects, whatever form the information takes (including text and numbers, sound recordings, drawings, images and video), by whatever means it has been acquired or captured, whatever means are used to store it (such as printing or writing on paper or storage electronically), and whatever means are used to transfer or exchange it (orally, by hand, by post, movement of storage media, direct links or networking). This document is for organizations of all types and sizes that provide healthcare or are custodians of personal health information for other reasons. The information that they are responsible for can be stored and processed in many possible ways and locations, including on premises or in the cloud, but remains in scope. This document applies to all physical settings where healthcare is intended to be delivered, such as hospitals, clinics and other locations or facilities designated for healthcare purposes such as ambulances and mobile imaging or diagnostic units. It also applies to care provided elsewhere, such as in residential premises. In addition to the range of settings, this document applies to all methods of service provision including remote or virtual healthcare.
Abstract
Overview
ISO 27799:2025 - Health informatics - Information security controls in health based on ISO/IEC 27002 provides sector‑specific information security controls and implementation guidance tailored to healthcare. Based on ISO/IEC 27002:2022, it adapts generic ICT controls to risks and realities of health data, electronic health record (EHR) systems, medical devices with software/firmware, building and environmental systems used in care settings, cloud services and remote care. The standard applies to information in all forms (paper, electronic, images, audio, video), all transfer methods, and all physical and virtual care settings (hospitals, clinics, ambulances, mobile units, residential care, telehealth).
Key topics and technical requirements
ISO 27799 organizes controls into practical topic groups that align with ISO/IEC 27002 while adding healthcare context. Key areas include:
- Organizational controls: information security policies, roles and responsibilities, asset inventory and classification, supplier and cloud service controls, legal and regulatory requirements.
- People controls: screening, contracts, awareness and training, remote working, incident reporting and disciplinary processes.
- Physical controls: secure perimeters, access control for facilities, equipment protection, secure disposal and off‑premises asset security.
- Technological controls: endpoint security, privileged access management, authentication, vulnerability management, configuration management, malware protection, backups, data masking, data leakage prevention and information deletion.
- Incident management & business continuity: event detection, response, evidence collection, learning and resilience planning.
- Health‑specific guidance (HLT items): uniquely identifying subjects of care, validation of displayed/printed data, publicly available health information, emergency communications and external incident reporting.
The standard explicitly supports use with ISO/IEC 27001:2022 for ISMS implementation and decision‑making on appropriate controls.
Applications - practical value
ISO 27799:2025 is practical for:
- Developing security policies for EHRs, clinical systems and medical devices
- Assessing and contracting third‑party vendors, cloud and managed service providers
- Designing secure telehealth and remote care workflows
- Securing medical devices with embedded software/firmware and associated networks
- Implementing access control, data classification, masking and leakage prevention to protect personal health information (PHI)
- Incident response planning, evidence collection and post‑incident learning in healthcare contexts
Who should use this standard
- CIOs, CISOs and IT/security managers in hospitals and clinics
- Health informatics and interoperability teams
- Medical device manufacturers and integrators
- Cloud and service providers for healthcare customers
- Compliance officers, risk managers and auditors working with personal health information
Related standards
- ISO/IEC 27002:2022 (controls guidance)
- ISO/IEC 27001:2022 (information security management systems)
Keywords: ISO 27799:2025, health informatics, information security controls, healthcare cybersecurity, EHR security, medical device security, personal health information, ISO/IEC 27002.
Технические детали
- Технический комитет
- ISO/TC 215 - Health informatics
- SKU
- ISO 27799:2025
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO 27799:2016
ОтменёнHealth informatics — Information security management in health using ISO/IEC 27002
Overview ISO 27799:2016 - Health informatics - Information security management in health using ISO/IEC 27002 - provides sector-specific guidance to protect personal health information. It adapts and…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…