SIST-TS CEN ISO/TS 14441:2014 PDF
Health informatics - Security and privacy requirements of EHR systems for use in conformity assessment (ISO/TS 14441:2013)
Health informatics - Security and privacy requirements of EHR systems for use in conformity assessment (ISO/TS 14441:2013)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 122
- Дата публикации:
- 17 февраля 2014 г.
- ICS:
- 35.030
- Технический комитет:
- ITC - Information technology
ISO/TS 14441:2013 examines electronic patient record systems at the clinical point of care that are also interoperable with EHRs. ISO/TS 14441:2013 addresses their security and privacy protections by providing a set of security and privacy requirements, along with guidelines and best practice for conformity assessment. ISO/TS 14441:2013 includes a cross-mapping of 82 security and privacy requirements against the Common Criteria categories in ISO/IEC 15408 (all parts).
Abstract
Overview
CEN ISO/TS 14441:2013 (ISO/TS 14441:2013) is a technical specification in health informatics that defines security and privacy requirements for electronic patient record systems at the point of care (POS clinical systems) that are interoperable with regional or national EHR infrastructures. The document is intended for use in conformity assessment (certification and conformance testing) and provides both a comprehensive requirements set and guidance for establishing and maintaining assessment programs.
Key topics and technical requirements
- Scope: Focuses on clinical point-of-care electronic patient record systems that receive, store, process, display and exchange clinical and administrative data. Hardware and organizational process controls are out of scope.
- Security & privacy requirements: The specification identifies a comprehensive set of 82 security and privacy requirements designed to protect patient information and mitigate principal categories of attack. These requirements are intended for use in conformity assessment.
- Common Criteria mapping: All 82 requirements are cross-mapped against the ISO/IEC 15408 (Common Criteria) categories to support formal security evaluation and target-of-evaluation (TOE) development.
- Theoretical foundation: Discusses the underlying security and privacy principles that justify the requirements and how they apply in interoperable clinical settings.
- Conformity assessment guidance: Best practice and operational guidance for designing, running and maintaining certification/conformance programs, including process models and illustrative examples.
- Supplementary material: Annex A provides design considerations and international examples of conformity programs; Annex B compares jurisdictional privacy and security requirements.
Practical applications and who uses it
This technical specification is practical for:
- Conformity assessment bodies and accreditation agencies designing or operating EHR certification programs.
- Health software vendors and developers producing POS clinical systems who need to demonstrate compliance with recognized security and privacy criteria.
- Purchasers and procurers (healthcare providers, hospitals, clinics) seeking assurance that products meet security and privacy requirements for interoperability with EHR infrastructures.
- Government bodies, standards organizations and health informatics professionals creating policy, procurement rules or national certification schemes.
- Auditors and security assessors performing evaluations referencing Common Criteria mappings.
Related standards
- ISO/IEC 15408 (Common Criteria) - cross-mapped to the 82 requirements
- ISO/IEC 27001 - referenced for information security management alignment
- ISO/IEC 17000 series (CASCO) - conformity assessment principles
- ISO/TC 215 work on EHR and health informatics
Keywords: ISO/TS 14441, EHR security, EHR privacy, conformity assessment, Common Criteria, point-of-care systems, health informatics, electronic patient record.
Технические детали
- SKU
- SIST-TS CEN ISO/TS 14441:2014
Похожие стандарты
Стандарты, упомянутые в описании
SIST EN ISO/IEC 19896-3:2026
ДействующийInformation security, cybersecurity and privacy protection - Requirements for the competence of IT security c…
Overview SIST EN ISO/IEC 19896-3:2026 specifies the requirements for the knowledge and skills of personnel involved in IT security conformance assessment, specifically for evaluators and reviewers op…
ISO/IEC 27001:2022/Amd 1:2024
ДействующийInformation security, cybersecurity and privacy protection — Information security management systems — Requir…
Overview ISO/IEC 27001:2022/Amd 1:2024 is the latest amendment to the internationally recognized ISO/IEC 27001 standard, which establishes requirements for information security management systems (IS…
SIST EN ISO/IEC 17000:2020
ДействующийConformity assessment - Vocabulary and general principles (ISO/IEC 17000:2020, Corrected version 2020-12)
Overview EN ISO/IEC 17000:2020 (ISO/IEC 17000:2020, Corrected version 2020-12) is the international vocabulary and general-principles standard for conformity assessment. Published by CEN/ISO/IEC, it…