Overview
ISO/TR 18638:2017 - Health informatics: Guidance on health information privacy education in healthcare organizations provides recommended educational components for building and delivering a privacy education program that supports protection of personal health information (PHI) in healthcare settings. This technical report is intended for those who plan, establish or deliver privacy training and awareness in healthcare organizations and frames privacy education within roles and job responsibilities. The document addresses the concept of information privacy in healthcare, common protection challenges, program components and basic educational content.
Key topics and recommended components
- Concepts and definitions: information privacy, personal health information, confidentiality, access control, anonymization/pseudonymization and related terms used in health informatics.
- Privacy protection context: organizational privacy programs, policies and workforce roles in safeguarding PHI.
- Core components of a privacy education program: role‑based competencies, educational objectives and content mapped to job responsibilities.
- Content modules (examples):
- Introduction to information privacy, confidentiality and security in healthcare
- International guidelines and national legislation/policy
- Patient rights regarding personal health information
- Administrative policies and procedures for privacy protection
- Technical and physical safeguards
- Instructional design and delivery: orientation/on‑boarding, continuing education, patient education, instructors, delivery mechanisms and learning methods.
- Evaluation: suggested approaches for assessing learning outcomes (quizzes, competency checks, program evaluation).
- Supporting annexes: examples of learning objectives, levels by audience, educational methods and sample quiz questions; Annex A lists related ISO/TC 215 standards.
Note: ISO/TR 18638:2017 provides recommended (non‑normative) educational components - it guides design rather than imposing mandatory requirements.
Practical applications
- Develop role‑based privacy training programs for clinicians, administrative staff, IT personnel and managers.
- Create onboarding and continuing education modules to meet regulatory and organizational privacy obligations.
- Design patient‑facing privacy information and consent education.
- Align internal privacy policies and technical safeguards training with international best practices and local legislation.
- Evaluate training effectiveness and demonstrate organizational commitment to information privacy and PHI protection.
Who should use this standard
- Privacy officers, compliance managers and legal teams
- Learning & development and HR professionals in healthcare
- Clinical leaders and department managers responsible for workforce education
- Health IT and security teams implementing technical safeguards
- Policy makers and accreditation bodies developing privacy awareness requirements
Related standards
See Annex A of ISO/TR 18638:2017 for a curated list of ISO/TC 215 health informatics standards relevant to privacy protection and for guidance on integrating those standards into privacy education programs.
Keywords: ISO/TR 18638, health information privacy, privacy education, healthcare organizations, PHI, privacy training, health informatics standards.