Overview
ISO/TR 11633-2:2021, "Health informatics - Information security management for remote maintenance of medical devices and medical information systems - Part 2," is a practical guidance report for implementing an Information Security Management System (ISMS) for remote maintenance services (RMS) in healthcare. It complements ISO/TS 11633-1 by demonstrating concrete risk analysis examples and showing how to protect information assets - especially medical devices, medical information systems and personal health data - when vendors remotely maintain equipment from a remote service centre (RSC).
Key technical topics and requirements
- ISMS framework & PDCA cycle: Implements plan/do/check/act processes, recommending alignment with ISO/IEC 27001 to construct and operate an effective ISMS.
- Scope & coverage: Covers target devices for maintenance, healthcare facility internal networks, the network route to the RSC, RSC internal networks, and equipment management at the RSC. (Certain risks such as general availability, viruses, and staff training issues are noted as out-of-scope.)
- Risk assessment approaches: Describes four methods - baseline, detailed, combined and informal - for analysing threats, likelihood, and impact specific to RMS.
- Documented ISMS elements: Recommends documenting security policy, security measures standards, mapping of policy, selection of solutions, operation execution rules, security auditing standards, and audit trails.
- Security management measures: Guidance on controls and countermeasures for confidentiality, integrity and availability of systems and personal data; includes evaluation of control effectiveness and approval of residual risks.
- Contractual & governance expectations: Advises embedding RMS security obligations in maintenance contracts so healthcare organizations (HCFs) and RMS providers share responsibilities for protecting patient data.
- Security audit: Guidance on conducting security audits of RMS and recommending third-party audits where appropriate.
Practical applications and users
- Who should use it:
- Healthcare facility IT/security teams implementing RMS governance
- Medical device vendors and RMS providers establishing secure remote services
- Compliance officers, clinical engineering departments, and procurement teams
- Auditors and risk managers assessing RMS security controls
- Practical benefits:
- Reduces downtime and maintenance costs while controlling security risks
- Provides documented evidence of RMS security for regulators and stakeholders
- Enables consistent security controls across multiple sites and providers
Related standards
ISO/TR 11633-2:2021 is a hands-on resource for integrating information security management into remote maintenance of medical devices and health information systems, balancing patient safety, privacy and operational efficiency.