EN ISO 13606-4:2019 PDF
Health informatics - Electronic health record communication - Part 4: Security (ISO 13606-4:2019)
Health informatics - Electronic health record communication - Part 4: Security (ISO 13606-4:2019)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 40
- Дата публикации:
- 3 июля 2019 г.
- Издание:
- CEN EN 13606 edition 2 version 1
- ICS:
- 35.240.80
This document describes a methodology for specifying the privileges necessary to access EHR data. This methodology forms part of the overall EHR communications architecture defined in ISO 13606-1. This document seeks to address those requirements uniquely pertaining to EHR communications and to represent and communicate EHR-specific information that will inform an access decision. It also refers to general security requirements that apply to EHR communications and points at technical solutions and standards that specify details on services meeting these security needs. NOTE Security requirements for EHR systems not related to the communication of EHRs are outside the scope of this document.
Abstract
Overview
EN ISO 13606-4:2019 - Health informatics: Electronic health record communication - Part 4: Security specifies a methodology for defining and communicating the privileges required to access parts of an Electronic Health Record (EHR). As part of the ISO 13606 series, this part focuses on EHR-specific access control and audit information that informs access decisions during EHR communication between systems while pointing to general security requirements and technical solutions. It replaces the 2007 edition and aligns audit logging with ISO 27789.
Key Topics and Requirements
- Access policy model: A structured approach for representing access policies within an EHR_EXTRACT, including an archetype for an access policy COMPOSITION.
- Record component sensitivity: Rules for labeling EHR components with sensitivity metadata that guide access decisions.
- Functional roles: Standardized vocabulary for roles (clinicians, researchers, managers, etc.) and rules for mapping roles to sensitivity and access privileges.
- Policy elements: Representation of policy targets, request criteria, sensitivity constraints, and attestation information to support fine‑grained, context-aware access control.
- Audit log model: A communication-oriented audit trail format (EHR audit log extract and entries) aligned with ISO 27789, containing information about the extract being communicated for compliance and traceability.
- Conformance and extensibility: Guidance on how jurisdictions can nominate alternative or specialized role terms and how implementations can conform to the model.
- Scope constraints: Focuses on security aspects specific to EHR communication; security requirements unrelated to EHR communication fall outside the scope.
Practical Applications
- Designing and implementing EHR interoperability solutions that require secure, auditable record exchange across organizations or borders.
- Embedding access-control metadata within EHR extracts so receiving systems can enforce patient-specified or jurisdictional policies in real time.
- Creating audit and compliance workflows that transmit EHR access logs for regulatory reporting, incident investigation, or cross‑system accountability.
- Supporting consent management and patient-controlled disclosure by mapping patient preferences to access policies used during EHR communication.
Who Should Use This Standard
- Health informatics architects and EHR system designers
- Security architects and access control engineers in healthcare IT
- Health information exchange (HIE) implementers and integrators
- Privacy officers, auditors, and compliance teams
- Standards bodies and vendors building interoperable EHR communication solutions
Related Standards
- ISO 13606-1 (EHR communications architecture)
- ISO 27789 (EHR audit trails)
- ISO 22600-3 and ISO 22857 (consent and cross‑border considerations)
- National and regional health‑IT security regulations and conformance frameworks
Keywords: EN ISO 13606-4:2019, EHR security, electronic health record communication, access control, audit log, health informatics, EHR interoperability.
Технические детали
- Технический комитет
- CEN/TC 251 - Medical informatics
- SKU
- EN ISO 13606-4:2019
Похожие стандарты
Стандарты, упомянутые в описании
ISO 13606-4:2019
ДействующийHealth informatics — Electronic health record communication — Part 4: Security
Overview ISO 13606-4:2019 - part of the ISO 13606 series on electronic health record (EHR) communication - defines a security methodology for specifying privileges required to access EHR data. It sit…
BS EN ISO 13606-4:2019
ДействующийHealth informatics. Electronic health record communication. Security.
SIST EN ISO 27789:2021
ДействующийHealth informatics -- Audit trails for electronic health records (ISO 27789:2021)
Overview EN ISO 27789:2021 - Health informatics - Audit trails for electronic health records (ISO 27789:2021) defines a common framework for audit trails for Electronic Health Records (EHR). The stan…
PD ISO/PAS 24305:2025
ДействующийHealth informatics. Guidelines for implementation of HL7 FHIR based on ISO 13940:2015, ISO 13606-1:2019 and I…
1 Scope This document provides guidance on how four complementary international standards can be used in combination by developers of health ICT systems and infrastructures. These standards, three pu…
SIST EN ISO 22600-3:2015
ДействующийHealth informatics - Privilege management and access control - Part 3: Implementations (ISO/DIS 22600-3:2014)
Overview EN ISO 22600-3:2014 (Health informatics - Privilege management and access control - Part 3: Implementations) defines implementation-level guidance for managing privileges and access control…