Overview - ISO/TS 22691:2021 (Token-based health information sharing)
ISO/TS 22691:2021 defines the data element content and exchange format for health information tokens (HI‑TOKENs) used in token‑based health information sharing. The Technical Specification standardizes the metadata that identifies clinical documents in a repository and the allowed exchange formats (electronic, machine‑readable optical like QR codes, and printed text). It addresses conceptual architecture, token content and value representations, pseudonymization options, and governance considerations for HI‑communities. Data transport architectures, encryption methods and detailed governance rules are explicitly out of scope.
Key topics and technical requirements
- HI‑TOKEN data items: standardized metadata groups such as HI‑community identifier (CMID as an ISO OID), sender/recipient identifiers and names, creation timestamp, document identifier (DMID - required), patient identifiers and demographics, and a boolean for anonymized/pseudonymized data.
- Value representations and data types: specifies data type formats (e.g., OID, id, dateTime, boolean, code, string) and short forms for compact token encodings (useful for QR codes).
- Exchange formats: supports electronic representations, machine‑readable optical symbols (e.g., QR codes - see ISO/IEC 18004), and printed text for physical media (USB, CD/DVD, paper).
- Security considerations and governance guidance: high‑level guidance for security, authentication/authorization, logging and HI‑community policies; the standard does not prescribe specific encryption or transport protocols.
- Roles and workflow: describes roles of patients, referring and referred healthcare providers, and health research institutions in token‑based sharing.
Practical applications and users
- Use cases:
- Rapid retrieval of a specific clinical document by presenting an HI‑TOKEN (no search by patient identifiers required).
- Patient‑mediated exchange where patients carry the token to a referred facility, enabling implicit consent flows.
- Low‑infrastructure scenarios where full XDS infrastructure is impractical but secure document referencing is needed (physical media, QR code transfers).
- Who benefits / implements:
- Health IT vendors building EHR connectors, document repositories, or patient‑facing apps
- Hospitals, clinics and referral networks forming HI‑communities
- Health information managers and interoperability architects designing metadata schemes
- Research institutions that need pseudonymized access patterns without exposing patient identifiers
Related standards
- IHE Cross‑enterprise Document Sharing (XDS/XDR) - alternative architecture for cross‑enterprise document access
- ISO/IEC 18004 - QR code specifications (machine‑readable optical representation)
- ISO 3166‑1 - country code values referenced for nationality fields
ISO/TS 22691:2021 is a practical metadata specification enabling interoperable, token‑based document referencing and patient‑centric information exchange while leaving transport and cryptography choices to implementers.