Overview
ISO/TS 6268-2:2025 - Health informatics - Cybersecurity framework for telehealth environments - Part 2: Cybersecurity reference model of telehealth - defines a reference model to support telehealth cybersecurity. The Technical Specification describes factors driving telehealth cybersecurity threats, how security risks relate to patient safety, methods for defining security levels in telehealth services, and the core components of a telehealth cybersecurity reference model. It does not define specific telehealth service types.
Key topics
- Telehealth cybersecurity reference model: Focus on telehealth activities (encounter, observation, intervention), classification, risk analysis and cybersecurity requirements.
- Threat factors: Identification of threats unique to telehealth such as remote environment risks, device loss/theft, unauthorized actors off-camera, and communication interruptions.
- Security–safety relationships: Examination of how cybersecurity risks can impact clinical safety in remote care.
- Security level methodology: Guidance on schemes and methodologies for defining cybersecurity levels appropriate to telehealth services.
- Controls and requirements: Emphasis on organizational, people, physical and technological requirements (aligned with ISO 27799) and the need for redundancy and incident recovery strategies.
- Managing heterogeneous environments: Guidance for compensating gaps where telehealth actors operate in different security-posture environments (e.g., patient home vs. health delivery organization).
Applications
ISO/TS 6268-2:2025 is practical for organizations that design, deploy or operate telehealth systems and services:
- Health delivery organizations (HDOs) and hospitals integrating telehealth into existing cybersecurity programs.
- Telehealth platform providers and vendors building secure telemedicine applications, cloud services or mobile health (mHealth) solutions.
- Healthcare IT, risk managers and security architects who define security levels, perform telehealth risk analysis and develop incident recovery plans.
- Medical device and digital health teams concerned with device loss/theft, data protection and remote patient safety.
- Policy makers and compliance teams seeking a reference model to align organizational policies with remote-care cybersecurity needs.
Practical uses include scoping telehealth risk assessments, setting security level criteria for telehealth workflows, designing secure encounters/observations/interventions, and guiding compensating controls where physical access and environment cannot be controlled.
Related standards
- ISO 6268 series (Part 1: Overview & concepts; Part 3: Cybersecurity requirements)
- ISO 27799 (health information security guidance)
- ISO/IEC 27005 (information security risk management)
- AAMI TIR57 (medical device cybersecurity)
- ISO/IEEE 11073 family (personal health device data models)
- ISO 13131 (telehealth use cases referenced in Annex A)
Keywords: telehealth cybersecurity, cybersecurity framework, ISO/TS 6268-2:2025, telehealth services, security levels, telemedicine security.