Overview
ISO 17090-1:2021 - part of the ISO 17090 series for health informatics - provides an accessible introduction to using public key infrastructure (PKI) and digital certificates in healthcare. The standard defines core concepts, stakeholders (certificate holders and relying parties), and a scheme of interoperability requirements that enable secure, certificate-enabled exchange of health information across organizations and jurisdictions. It also explains basic public key cryptography and the certificate types commonly used in healthcare systems.
Key topics and technical requirements
- Public key cryptography basics: role of asymmetric vs. symmetric cryptography, digital signatures, and private key protection.
- Digital certificate types: identity certificates, attribute certificates, self-signed CA certificates, CA hierarchies and bridging structures.
- Security services in healthcare: authentication, integrity, confidentiality (encipherment), digital signatures, authorization, and access control.
- Deployment components: Certification Authorities (CAs), Registration Authorities (RAs), Certificate Policies (CP) and Certification Practice Statements (CPS).
- Establishing identity and roles: using qualified identity certificates and attribute certificates for specialty/role-based access.
- Interoperability models: options for cross-domain trust such as single CA hierarchies, relying-party-managed trust, cross-recognition, cross-certification, and Bridge CAs.
- Policy and management: healthcare-specific policy requirements, separation of authentication from data encipherment, and security management frameworks for digital certificates.
Applications and practical value
ISO 17090-1 is practical guidance for implementing PKI to secure electronic health records (EHRs), clinical messaging, device communication, patient portals, and cross-organizational information exchange. Typical use cases:
- Enabling authenticated clinician access to patient data across hospitals and clinics.
- Protecting confidentiality of health data in transit (encipherment) and ensuring message integrity.
- Applying digital signatures for clinical orders, prescriptions, and legal audit trails.
- Using attribute certificates for role-based authorization and fine-grained access control.
- Designing cross-border trust frameworks for national health information exchanges.
Who should use this standard
- Healthcare IT architects and CIOs
- Information security officers and compliance teams
- PKI/Cybersecurity vendors and CA operators
- EHR and medical device vendors
- Health data exchange organizations and policymakers
- Registration authorities and relying parties implementing secure health communication
Related standards
ISO 17090-1 is the overview part of the ISO 17090 PKI series (see ISO website for other parts). It was prepared by ISO/TC 215 (Health informatics) and complements broader PKI and health informatics standards that define technical, procedural, and policy requirements for certificate use in healthcare.