Overview
ISO/TR 11636:2009 - Health Informatics - provides guidance on using a dynamic on‑demand virtual private network (VPN) to support secure health information infrastructure. Published as a Technical Report by ISO/TC 215, it explains network requirements for healthcare, security considerations for using open networks (for example, the Internet), and minimum guidelines for security management when exchanging health and personal data between independent institutions. The report is informative (not a product specification) and includes threat analysis, practical models and example security measures for dynamic on‑demand VPN deployments.
Key Topics
- Network requirements for healthcare: patterns of expected services (e.g., teleradiology, telepathology, online claims, remote maintenance) and the access/control needs these services impose.
- VPN technologies and tradeoffs: discussion of IPsec + IKE versus SSL/TLS for secure channels, and where each fits in healthcare applications.
- Security zones and definitions: terms such as DMZ (demilitarized zone), HSZ (high security zone), and SZ (security zone) to structure network segmentation.
- Threat analysis and countermeasures: anticipated risks for health information exchange and example mitigation strategies.
- Operational guidance: minimum security management guidelines, technical and operational checklists for evaluating network security.
- Case studies and deployment models: examples of regional cooperation portals, online maintenance, teleradiology/telepathology use-cases, and university–regional hospital models.
- Managed dynamic on‑demand VPN: benefits of a managed service that automates connection parameters and reduces configuration burden on healthcare IT staff.
Applications
ISO/TR 11636:2009 is practical for organizations implementing or evaluating secure healthcare networks:
- Hospitals and clinics planning secure exchange of patient records and remote diagnostics (teleradiology, telepathology).
- Regional health networks and portals coordinating multi‑institution collaboration.
- Medical device vendors and service providers offering remote maintenance or device telemetry.
- Telecommunication carriers and online service providers (OSPs) designing managed VPN services for healthcare customers.
- Health IT and security teams using the checklists and threat analyses for risk assessment, procurement, and operational policies.
Using a dynamic on‑demand VPN can lower costs and operational complexity while enabling secure N‑to‑N connectivity across diverse healthcare partners.
Related standards
This Technical Report complements work by ISO technical committee ISO/TC 215 (Health informatics) and should be used alongside local legal and regulatory requirements for patient privacy and data protection when designing health information infrastructures.