Overview
EN ISO 22600-2:2014 - Health informatics: Privilege management and access control, Part 2: Formal models defines formal, high‑level models that underpin privilege management and access control for distributed health information systems. Part 2 of the ISO 22600 series specifies component-based concepts to support technical implementation of cross‑domain healthcare information sharing and access control. It is based on ISO/IEC 10746 (all parts) and focuses on architecture and model definitions rather than clinical workflows or cryptographic protocols (these are out of scope).
Key topics and technical requirements
The standard introduces and formalizes multiple models used to express policies and enforce access control across policy domain boundaries:
- Component paradigm - a component‑based approach for building interoperable access control services.
- Domain model - structural representation of participating policy domains and actors.
- Document model - classification and sensitivity metadata for health information objects.
- Policy model - formal representation of access policies and policy agreements between parties.
- Role model - definition of functional and structural roles and role relationships.
- Authorization model - mechanisms for role-to-privilege assignment and authorization decisions.
- Delegation model - rules and constraints for delegation of privileges between actors.
- Control model & Access control model - formal control flows and access decision logic to evaluate requests across domains.
Other notable points:
- Emphasis on policy bridging and interoperability where local authorization servers and cross‑border policy repositories coordinate access decisions.
- Support for specifying purpose of use, requester identity, and target sensitivity in access decisions.
- References to broader standards and profiles (ISO, CEN and other industry specifications) for integration.
Practical applications and users
EN ISO 22600-2 is intended for organizations and professionals designing secure, interoperable health IT systems that exchange sensitive patient data across organizational or national boundaries. Typical users include:
- Health IT architects and solution designers implementing SOA or distributed EHR systems
- Security engineers and access control implementers (authorization servers, policy repositories, directories)
- System integrators and vendors building interoperable healthcare applications
- Policy makers, privacy officers and technical leads drafting cross‑organization policy agreements
- Healthcare organizations and insurers coordinating data sharing with unaffiliated providers
Implementing the formal models helps organizations manage complex role mappings, delegation, privacy constraints and legal/ethical considerations while improving interoperability and auditability.
Related standards
Keywords: EN ISO 22600-2:2014, health informatics, privilege management, access control, formal models, policy model, role model, authorization, delegation, interoperability, healthcare information sharing.