IEC/TS 81001-2-2:2025
Health software and health IT systems safety, effectiveness and security — Part 2-2: Guidance for the implementation, disclosure and communication of security needs, risks and controls
Health software and health IT systems safety, effectiveness and security — Part 2-2: Guidance for the implementation, disclosure and communication of security needs, risks and controls
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 96
- Дата публикации:
- 3 октября 2025 г.
- Издание:
- IEC TS 81001 edition 1 version 1
- ICS:
- 35.030
This document presents an informative set of common, high-level security-related capabilities and additional considerations to be used across the life cycle of health software and health IT systems, for the information exchange between the health software manufacturers (including medical device manufacturers), healthcare delivery organizations (HDOs) and other stakeholders. It is applicable to health software running on any platform and in any environment such as cloud, on premise or hybrid. While important security topics, the following are outside the scope of this document: a) the security policies of the HDO, b) the product and services security policies of the manufacturer, c) determinations of risk tolerance by the HDO or manufacturer, and d) clinical studies where there is a need to secure personal data. As security risks can be caused by any product on health IT systems and health IT Infrastructure, considerations in this document can be applied for other products that are not health software. IEC TS 81001-2-2:2025 withdraws and replaces: – IEC TR 80001-2-2, Application of risk management for IT-networks incorporating medical devices – Part 2-2: Guidance for the communication of medical device security needs, risks and controls – IEC TR 80001-2-8, Application of risk management for IT-networks incorporating medical devices – Part 2-8: Application guidance – Guidance on standards for establishing the security capabilities identified in IEC TR 80001-2-2 This document includes the following significant changes: a) Combines and updates the contents of IEC TR 80001-2-2 and IEC TR 80001-2-8; b) Extends the scope to health software instead to only medical device software; c) Aligns contents and definitions to ISO 81001-1:2021 and the updated IEC 80001-1; d) Removed the Configuration of Security Features (CNFS) capability, as any configurable security capability shall be clearly communicated. e) Provide security control mappings to several new standards, e.g. IEC TR 60601-4-5, IEC 62443-4-2, ISO/IEEE 11073-40102 and the recent versions of previous standards, e.g. ISO/IEC 27002 and NIST 800-53 version 5.
Abstract
Overview
IEC/TS 81001-2-2:2025 - Health software and health IT systems safety, effectiveness and security (Part 2-2) provides guidance for the implementation, disclosure and communication of security needs, risks and controls across the life cycle of health software and health IT systems. This IEC Technical Specification consolidates and updates previous TRs (IEC TR 80001-2-2 and 80001-2-8), extends scope from medical device software to all health software, and aligns with ISO 81001-1:2021 and updated IEC 80001-1. It applies to software on any platform or environment (cloud, on‑premise, hybrid), and is intended for information exchange between manufacturers, healthcare delivery organizations (HDOs) and other stakeholders.
Key Topics
The document organizes a common set of high-level security capabilities and practical guidance for their use in a risk management context. Key technical topics include:
- A catalog of security capabilities such as automatic logoff, audit controls, authorization, person and node authentication, malware detection/protection, transmission confidentiality and integrity, data backup & disaster recovery, emergency access, system/application hardening, and physical locks (see Clause 5).
- Additional supporting information: connectivity capabilities, management of personally identifiable information (PII), remote services, Software Bill of Materials (SBOM), and security guides (Clause 6).
- Guidance on communication and shared responsibility between manufacturers and HDOs, and on applying these capabilities within risk management processes (Clause 4).
- Mappings to established control frameworks and standards including ISO/IEC 27002, NIST SP 800‑53 Rev 5, IEC 62443‑4‑2, IEC TR 60601‑4‑5, and ISO/IEEE 11073‑40102.
- Notable changes: consolidation of prior guidance, removal of the “Configuration of Security Features (CNFS)” capability (requiring explicit communication of configurable features), and expanded disclosure expectations (e.g., SBOM and MDS2 references).
Applications
Who uses IEC/TS 81001-2-2:2025 and why:
- Health software manufacturers and medical device manufacturers: to define, implement and disclose security capabilities and produce consistent security documentation for purchasers and regulators.
- Healthcare Delivery Organizations (HDOs): to evaluate supplier security claims, integrate products safely into clinical networks, and allocate shared security responsibilities.
- Procurement, clinical engineers, cybersecurity teams, integrators and risk managers: for vendor assessment, system integration, incident preparedness and compliance planning.
- Applicable across cloud, on‑premise and hybrid deployments and supports integration into device lifecycles, vulnerability management, and supply‑chain transparency (SBOM).
Related standards
- ISO 81001‑1:2021 (principles and definitions for health software safety, effectiveness and security)
- ISO/IEC 27002; NIST SP 800‑53 Rev 5; IEC 62443‑4‑2; IEC TR 60601‑4‑5; ISO/IEEE 11073‑40102 These mappings help implementers translate IEC/TS 81001-2-2 security capabilities into specific technical controls and organizational measures.
Keywords: IEC/TS 81001-2-2:2025, health software security, health IT systems, security capabilities, SBOM, risk management, HDO, manufacturers, cybersecurity standards.
Технические детали
- Технический комитет
- ISO/TC 215 - Health informatics
- SKU
- IEC/TS 81001-2-2:2025
Похожие стандарты
Стандарты, упомянутые в описании
ISO 81001-1:2021
ДействующийHealth software and health IT systems safety, effectiveness and security — Part 1: Principles and concepts
Overview ISO 81001-1:2021 - "Health software and health IT systems safety, effectiveness and security - Part 1: Principles and concepts" - defines the core principles, concepts, terms and definitions…
ISO TR 80001-2-7:2015
ОтменёнApplication of risk management for IT-networks incorporating medical devices -- Application guidance -- Part…
Overview ISO/TR 80001-2-7:2015 provides practical guidance for Healthcare Delivery Organizations (HDOs) to self-assess conformance with IEC 80001-1 - the international framework for risk management o…
ISO 27799:2016
ОтменёнHealth informatics — Information security management in health using ISO/IEC 27002
Overview ISO 27799:2016 - Health informatics - Information security management in health using ISO/IEC 27002 - provides sector-specific guidance to protect personal health information. It adapts and…
IEC 62443-4-2:2019
ДействующийSecurity for industrial automation and control systems - Part 4-2: Technical security requirements for IACS c…
Overview IEC 62443-4-2:2019 is an international standard published by the International Electrotechnical Commission (IEC) that specifies the technical security requirements for Industrial Automation…