Overview
ISO/TR 22696:2020 - "Health informatics - Guidance on the identification and authentication of connectable Personal Healthcare Devices (PHDs)" is a technical report from ISO/TC 215 that provides guidance for securing healthcare services that use connectable personal health devices. The report focuses on identification and authentication between PHDs (including smart devices with mobile healthcare apps) and gateways in both unidirectional and bidirectional connections, with particular attention to homecare settings. It intentionally excludes prescriptive protocols, cryptographic methods, or specific technical solutions.
Key topics
- Scope and applicability: Guidance for PHDs connecting to gateways in homecare and consumer environments; covers both unidirectional uploads and bidirectional clinical use cases.
- Security objectives: Protection of confidentiality, integrity, availability and secure operation of PHDs and gateway interactions.
- Threats and vulnerabilities: Identification of device- and network-level risks (malware, unauthorized access, insider/outside attacks) and how they affect PHDs.
- Identification & authentication:
- Device identification and authentication - lifecycle considerations for uniquely identifying PHDs and gateways.
- Person/entity authentication - user and operator registration procedures and human user authentication.
- Application, firmware and information integrity - ensuring code and data are genuine and unmodified; secure upgrade and input validation.
- Authentication information management: Handling credentials, tokens, and authentication artifacts while minimizing exposure.
- Access control: Secure log-on procedures, emergency accounts, automatic log-off, and device lock mechanisms.
- Lifecycle approach: Consistent application of identification and authentication across manufacture, deployment, operation and maintenance.
Practical applications
- Device manufacturers designing PHDs and mobile health apps can use ISO/TR 22696:2020 to shape product requirements for secure identification and authentication without being constrained to specific protocols.
- Healthcare organizations and homecare service providers can apply the guidance to establish policies for onboarding, authenticating and managing connectable devices and gateways.
- System integrators and security architects can align device lifecycle processes and threat mitigation strategies (secure upgrade, integrity checks, access control) with the standard’s recommendations.
Who should use this standard
- Medical device and PHD manufacturers
- Health IT architects and engineers
- Clinical service operators and homecare providers
- Security officers responsible for connected health systems
Related guidance
- ISO/TR 22696:2020 maps to other health informatics and cybersecurity standards (refer to the report’s Annex A for mapping). Note: this technical report provides guidance only and excludes specific protocol and cryptographic method prescriptions.
Keywords: ISO/TR 22696:2020, health informatics, Personal Healthcare Devices, PHD identification, authentication, gateway security, bidirectional PHD communication, homecare device security.