Overview
EN ISO 25237:2017 (ISO 25237:2017) - Health informatics - Pseudonymisation - establishes principles, requirements and a practical methodology for protecting personal health information through pseudonymization. The standard applies to organizations that perform pseudonymization themselves and to providers that operate or claim trustworthiness for pseudonymization services. It addresses both reversible and irreversible pseudonymization, controlled re‑identification, risk assessment, and operational governance.
Key topics and technical requirements
- Definitions and concepts (Clause 5): a single basic concept for pseudonymization and distinction from de‑identification and anonymization.
- Methodology for pseudonymization services (Clause 6): organizational and technical aspects required to implement pseudonymization processes.
- Policy framework and controlled re‑identification (Clause 7): minimal requirements and procedures that govern when and how re‑identification is permitted.
- Privacy objectives and de‑identification process: treatment of direct and indirect identifiers, classification of payload/observational data, and categories of data subjects.
- Risk assessment for re‑identification (Annex B): guidance for analysing inference and re‑identification risks.
- Use cases and implementation examples: scenarios for reversible/irreversible pseudonymization (Annex A), a sample de‑identification system (Annex C), and informative interoperability requirements (Annex D).
- Trustworthy operation practices (Annex E): policy framework and minimal operational requirements for service providers.
- Scope of content (table of contents): covers identifying data, research data generation and secondary use, genetic information considerations, and re‑identification technical feasibility.
Practical applications and target users
This standard is practical for:
- Healthcare organizations and hospitals implementing data sharing and secondary use of clinical data while protecting patient privacy.
- Pseudonymization service providers designing trustworthy, auditable services for healthcare data.
- Health IT vendors and developers building systems that require technical pseudonymization components and interoperability.
- Research institutions and data stewards preparing datasets for research while managing re‑identification risk.
- Privacy officers and compliance teams who need a policy framework and minimal controls for controlled re‑identification and risk assessment.
Typical applications include clinical research data sharing, registries, clinical data warehouses, and integration layers where patient identities must be protected but linkage or trusted re‑identification may be required.
Related standards and context
- EN ISO 25237:2017 is the European adoption of ISO 25237:2017.
- ISO 25237 complements other health informatics standards and should be applied alongside applicable national data protection laws and organizational privacy policies when designing pseudonymization solutions.
Keywords: ISO 25237:2017, pseudonymisation, pseudonymization services, health informatics, privacy protection, re‑identification risk, de‑identification, trustworthy pseudonymization.