Overview - ISO/TS 23535:2022 (Health informatics)
ISO/TS 23535:2022 provides a core set of requirements for customer‑oriented health cloud service agreements used by hospitals, healthcare organizations and public health centres. Prepared by ISO/TC 215, this Technical Specification describes the matters stakeholders should consider when implementing cloud computing in health and healthcare - for example cloud type, components and key characteristics - to ensure cloud services deliver optimal health and healthcare management functionality. Note: privacy and security features are outside the scope of this document and are covered in ISO/TR 21332.
Key topics and technical requirements
ISO/TS 23535 outlines essential elements that should appear in a health cloud service agreement (CSA), including:
- Roles and responsibilities
- Definitions and obligations for the cloud service customer (CSC) and cloud service provider (CSP).
- Service support and catalogue
- Description of offered services, service coverage, uptime expectations, response times and notification procedures.
- Service model and monitoring
- Supported cloud models (SaaS, PaaS, IaaS) and mechanisms for ongoing service monitoring and reporting.
- Incident reporting and response
- Incident report content, response procedures, repair timeframes and delivery of reports.
- Standards, testing and certification
- Conformity with international standards, compatibility guidelines, compliance testing and certification disclosure.
- Data location and governance
- Cloud service area, relocation policy, backup plans, data maintenance and query history.
- Data security and transfer
- Technical, administrative and physical security measures; data transfer methods, deadlines, approval and deletion procedures.
- Billing, payments and operational policies
- Billing criteria, excess usage charges, payment terms and transparency of billing details.
- Regulatory compliance and version management
- Jurisdictional compliance responsibilities, service update notifications, version control, agreement renewal and expiry.
The document also details service interruption accountability, compensation, subcontractor information and metrics (see annexes for sample catalogues and metrics).
Applications and who should use it
ISO/TS 23535 is practical for:
- Hospital IT managers - to specify contract terms, service SLAs and data governance expectations with CSPs.
- Hospital and healthcare management - to evaluate vendor offerings, financial terms and regulatory alignment.
- Cloud service providers and partners - to design customer‑oriented CSAs tailored to healthcare needs and demonstrate conformity with sector expectations.
Practical use cases include procurement of EHR hosting, analytics platforms, patient engagement portals and other health cloud services.
Related standards
- ISO/TR 21332 - referenced for privacy and security considerations in health cloud services.
- Prepared by ISO/TC 215 (Health informatics); compliance with other applicable international standards and certifications is encouraged and addressed in the specification.
Keywords: ISO/TS 23535:2022, health cloud service agreements, health informatics, cloud computing healthcare, cloud service provider, cloud service customer, data governance, service catalogue, incident reporting.