Overview
ISO 22857:2013 - Health informatics - Guidelines on data protection to facilitate trans‑border flows of personal health data - provides guidance to organisations that transfer or process personal health data across national or jurisdictional borders. The standard is normative for international or trans‑jurisdictional exchanges of personal health data and informative for in‑country data protection implementations. Its goal is to ensure that health data relating to data subjects (e.g., patients) are adequately protected when sent to, processed in, or accessed from another country or jurisdiction.
Key topics and technical requirements
ISO 22857:2013 addresses both data protection principles and the security policy an organisation should adopt. Major topics include:
- General principles and roles - definitions of responsibilities for controllers, processors and data protection officers in cross‑border settings.
- Legitimising data transfer - concepts of “adequate” data protection and conditions for lawful international transfer.
- Criteria for adequate protection - content principles (data minimisation, purpose limitation), procedural and enforcement mechanisms, and the handling of overriding laws.
- Contracts - model contract clauses and contractual safeguards for controller‑to‑controller and controller‑to‑processor relationships (see Annexes C and D).
- Anonymisation and consent - guidance on when anonymisation is appropriate and on the legitimacy and limits of consent for international processing.
- High‑level security policy - a structured security policy with principles such as executive support, documentation, defined permissions to process, data subject information, prohibition of onward transfer without consent, remedies and compensation, and operational security measures.
- Security controls and measures - recommended measures discussed include encryption and digital signatures for transmission, access controls and authentication, audit trails, physical/environmental security, malware protection, incident and breach handling, and business continuity planning (see Clause 11).
- Handling very sensitive personal health data and non‑electronic formats (Annex E and Clause 12).
Practical applications and who should use it
ISO 22857:2013 is directly applicable to organisations involved in international health information exchange, including:
- Hospitals and healthcare providers sharing patient records across borders
- Research databanks and clinical trial platforms
- Health IT vendors and cloud service providers hosting or processing health data internationally
- Third‑party contractors and system maintenance providers
- Regulators, national standards bodies, privacy officers, and legal teams developing cross‑border data protection policies
Use cases include telemedicine, multinational clinical research, international e‑health services, and cross‑jurisdictional data hosting.
Related standards and references
ISO 22857:2013 situates itself alongside key international instruments and standards such as OECD privacy guidelines, Council of Europe instruments, UN recommendations and EU data protection frameworks. It also cross‑references other ISO/IEC IT security and health informatics standards.
Keywords: ISO 22857:2013, health informatics, data protection, trans‑border flows, personal health data, security policy, anonymisation, consent, international data transfer.