Overview
ISO/TS 21089:2018 - Health informatics - Trusted end-to-end information flows - is a Technical Specification that defines how health data and health record entries are to be managed in a trusted, consistent manner across their full lifespan. It describes lifecycle events for discrete record entries originating in systems such as EHRs (electronic health records), PHRs (personal health records) or devices, and specifies requirements to maintain trust whether data is at rest or in motion across multiple systems.
This first edition (2018) replaces ISO/TR 21089:2004 and aligns closely with ISO/HL7 10781:2015 and HL7 FHIR resources, including Record Lifecycle Event guidance.
Key Topics
- Record lifecycle management - defined events such as originate/retain, update/amend, attest, disclose, transmit, receive, access/view, and many others (e.g., de-identify, pseudonymize, re-identify, archive, destroy).
- Trust characteristics - provenance, authenticity, integrity, confidentiality, permanence, indelibility and chain of trust.
- Accountability and identity - roles for human and software/device agents, stewardship responsibilities and scope of accountability for record entries.
- Auditability and metadata - requirements for capturing lifecycle metadata, provenance and audit events to support traceability.
- Interoperability foundations - principles to ensure consistent behavior across systems and reference mappings to HL7 FHIR resources (informative annexes provide FHIR examples).
- Contexts for records - identity, clinical, data-integrity, administrative/operational and accountability contexts that must be preserved over lifecycle events.
Practical Applications
Who uses ISO/TS 21089:2018 and why:
- EHR and PHR vendors - to design systems that preserve provenance, integrity and audit trails for record entries.
- Health IT architects and integrators - to implement trusted end-to-end information flows across interoperable systems.
- Clinical informaticians and CIOs - to define policies for stewardship, access control, and lifecycle event handling.
- Data governance, privacy and compliance teams - to ensure traceability and support regulatory obligations around data authenticity and retention.
- Health researchers and genomic data managers - to manage sensitive clinical genomics data with required provenance and lifecycle controls.
Practical benefits include stronger data trustworthiness, improved audit trails, consistent handling of record instances across systems, and clearer roles/responsibilities for data stewardship.
Related Standards
- ISO/HL7 10781:2015 (record lifecycle alignment)
- HL7 Fast Health Interoperable Resources (FHIR) - guidance and Annex mappings (AuditEvent, Provenance, RLE IG)
Keywords: ISO/TS 21089:2018, trusted end-to-end information flows, health informatics, EHR, PHR, record lifecycle, provenance, auditability, HL7 FHIR.