Overview
EN ISO 22600-1:2014 (Health informatics - Privilege management and access control - Part 1: Overview and policy management) defines principles and services for managing privileges and access control to health data and functions. The standard focuses on secure healthcare information sharing across policy domain boundaries - between unaffiliated providers, health organizations, insurers, patients, staff and trading partners - and supports component-based concepts intended for technical implementation. It includes a template for a policy agreement to enable comparable documentation among parties involved in information exchange.
Key topics and technical requirements
The standard outlines essential topics and requirements for interoperable access control and privilege management:
- Policy agreement: template and elements required to document cross-domain rules for information exchange.
- Identification and authentication: requirements for identifying users, roles and authentication of users/roles.
- Authorization and role structures: defining roles, delegation rights, assignment and attestation authorities.
- Patient consent and privacy: documenting consent, privacy expectations and ethical considerations.
- Information governance: identification, location, integrity and security of exchanged health information.
- Access rules and validity: access conditions, validity times and policy agreement validity periods.
- Audit and accountability: requirements for secure audit trails and audit checks.
- Risk and continuity: risk analysis, continuity and disaster management, and planning for future system developments.
- Documentation: recommended documentation templates (Annex A) and example information exchange policy agreements (Annex B).
Applications and who uses it
EN ISO 22600-1 is intended for organizations and professionals responsible for secure health information exchange and access control:
- Health IT architects and system integrators designing cross-organizational access control.
- Hospitals, health information exchanges (HIEs), insurers and regional/national health authorities establishing interoperable policies.
- Security architects and identity/access management teams implementing privilege management services.
- Privacy officers and compliance/legal teams drafting policy agreements and consent management.
- Vendors of clinical and administrative applications aligning implementations with agreed policies.
Practically, the standard helps bridge differing local security policies, document mutual agreements, and provide a pathway toward interoperable technical implementations of privilege management in distributed healthcare environments.
Related standards
- ISO 22600 series: Part 2 (Formal models) and Part 3 (Implementations) - complementary documents that provide formal modeling and implementation guidance to accompany Part 1’s policy and overview.