SIST EN ISO 27789:2021 PDF
Health informatics -- Audit trails for electronic health records (ISO 27789:2021)
Health informatics -- Audit trails for electronic health records (ISO 27789:2021)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 56
- Дата публикации:
- 15 ноября 2021 г.
- Издание:
- (ISO 27789:2021)
- ICS:
- 35.240.80
This document specifies a common framework for audit trails for electronic health records (EHR), in terms of audit trigger events and audit data, to keep the complete set of personal health information auditable across information systems and domains. It is applicable to systems processing personal health information that create a secure audit record each time a user reads, creates, updates, or archives personal health information via the system. NOTE Such audit records at a minimum uniquely identify the user, uniquely identify the subject of care, identify the function performed by the user (record creation, read, update, etc.), and record the date and time at which the function was performed. This document covers only actions performed on the EHR, which are governed by the access policy for the domain where the electronic health record resides. It does not deal with any personal health information from the electronic health record, other than identifiers, the audit record only containing links to EHR segments as defined by the governing access policy. It does not cover the specification and use of audit logs for system management and system security purposes, such as the detection of performance problems, application flaw, or support for a reconstruction of data, which are dealt with by general computer security standards such as ISO/IEC 15408 (all parts)[9]. Annex A gives examples of audit scenarios. Annex B gives an overview of audit log services.
Abstract
Overview
EN ISO 27789:2021 - Health informatics - Audit trails for electronic health records (ISO 27789:2021) defines a common framework for audit trails for Electronic Health Records (EHR). The standard applies to systems that process personal health information and require a secure audit record each time a user reads, creates, updates, or archives personal health information. EN ISO 27789:2021 supersedes EN ISO 27789:2013 and focuses on making personal health information auditable across systems and domains while respecting access policies.
Key topics and technical requirements
- Audit trigger events: Specifies the events that must generate audit records (access, query, create, update, archive) and the expected contents for each event type.
- Minimum audit record elements: At minimum an audit record must uniquely identify the user, identify the subject of care, identify the function performed (e.g., read, update), and record date and time of the action.
- Audit record structure: Detailed definitions for event identification (event ID, action code, timestamp, outcome), user identification (user ID, role, purpose of use), access point and audit source identification, and participant object identification (EHR segments linked by identifiers).
- Uses of audit data: Governance, supervision, patient rights (subject access and accountability), evidentiary needs and retention considerations.
- Secure management: Requirements and guidance for availability, retention, confidentiality and integrity of audit trails, and controlled access to audit data.
- Scope limits: The standard covers only actions on the EHR governed by domain access policies and does not specify audit logs for system management or general security diagnostics (these are addressed by general IT security standards).
- Informative annexes: Annex A contains audit scenario examples; Annex B overviews audit log services.
Practical applications
- Implementers and health IT vendors can use EN ISO 27789:2021 to design audit logging features in EHR systems that meet interoperability and accountability needs.
- Health system architects and software developers use the standard to define audit data models, event taxonomies, and secure storage/retention policies.
- Privacy officers, compliance teams, and clinical governance bodies use audit data for oversight, investigations, and demonstrating accountability.
- Auditors and forensic analysts rely on standardized audit trails to reconstruct access histories and support legal or regulatory processes.
Who should use this standard
- EHR vendors and health IT product teams
- Hospitals, clinics and healthcare networks deploying EHR systems
- Health informatics architects and integrators
- Privacy/compliance officers and auditors
Related standards
- ISO/IEC 15408 (general computer security standards) - referenced for system security and management logs.
- Note: EN ISO 27789:2021 is produced under ISO/TC 215 and endorsed by CEN for European adoption.
Keywords: EN ISO 27789:2021, audit trails, electronic health records, EHR audit log, health informatics, audit record, audit data, secure audit trails.
Технические детали
- Технический комитет
- ITC - Information technology
- SKU
- SIST EN ISO 27789:2021
Похожие стандарты
Стандарты, упомянутые в описании
ISO 27789:2021
ДействующийHealth informatics — Audit trails for electronic health records
Overview ISO 27789:2021 - Health informatics - Audit trails for electronic health records - specifies a common framework for audit trails in Electronic Health Record (EHR) systems. It applies to syst…
ISO 27789:2013
ОтменёнHealth informatics — Audit trails for electronic health records
SIST EN ISO/IEC 19896-3:2026
ДействующийInformation security, cybersecurity and privacy protection - Requirements for the competence of IT security c…
Overview SIST EN ISO/IEC 19896-3:2026 specifies the requirements for the knowledge and skills of personnel involved in IT security conformance assessment, specifically for evaluators and reviewers op…