Overview
ISO/TR 21548:2010 - Health informatics - Security requirements for archiving of electronic health records - Guidelines - is an informative Technical Report that guides implementation of ISO/TS 21547. It provides a practical methodology and checklist-style guidance to help organizations securely archive electronic health records (EHRs) for long‑term preservation, ensuring availability, integrity, confidentiality and non‑repudiation over extended retention periods.
This report is implementation-focused (informative, not normative). It explains the eArchive concept, the end‑to‑end eArchiving process, and organizational factors to consider when applying the security requirements defined in ISO/TS 21547.
Key topics and technical requirements
ISO/TR 21548 covers a broad set of topics needed to plan and operate secure EHR archiving:
- eArchive and eArchiving process
- Definitions of eArchive, archival packet creation, semantic mapping, extraction and restoration workflows.
- Security services across the archiving lifecycle
- Capture, transfer, preservation, disclosure, viewing/restoration and non‑repudiation.
- Backup and recovery
- Multiple copies, dispersed storage and ensuring integrity/confidentiality/availability of archived EHRs.
- Environment, responsibilities and policies
- Roles, governance, policy definition and documentation of participants (health providers, eArchive operators, TTPs).
- Design and implementation
- Business model analysis, legal/ethical impact assessment, risk analysis of existing and new systems.
- Security and privacy controls
- Selection and implementation of security instruments (e.g., PKI, audit logs, metadata, privacy protection measures).
- Operational topics
- Metadata management, registration services, destruction/retention rules, dynamic content handling, education and training.
Practical applications and users
ISO/TR 21548 is targeted at organizations and professionals responsible for long‑term EHR preservation, including:
- Hospitals, clinics and general practitioners planning eArchiving strategies
- Health IT vendors and EHR system designers (for archive interfaces and archival packet formats)
- National/regional health archives and federated archive operators
- Records managers, CIOs, information security managers and compliance officers
- Trusted Third Parties (TTPs) and PACS/RIS administrators
Using this guidance helps organizations meet regulatory and ethical obligations, maintain semantic interoperability (e.g., HL7/CDA, EN 13606 extracts), and reduce risks related to format obsolescence, data loss and unauthorized access.
Related standards
- ISO/TS 21547 (security requirements for EHR archiving) - primary normative reference
- ISO 15489 (records management), relevant health‑IT standards and messaging formats (HL7, CDA, EN 13606) are referenced for interoperability and recordkeeping context.
Keywords: ISO/TR 21548:2010, eArchive, EHR archiving, electronic health records, health informatics, security requirements, long-term preservation, archiving guidelines.