Skip to main content
Back

CEN ISO/TS 14441:2013

Health informatics - Security and privacy requirements of EHR systems for use in conformity assessment (ISO/TS 14441:2013)

General information

Valid from 04.02.2014
Base Documents
ISO/TS 14441:2013; CEN ISO/TS 14441:2013
Directives or regulations
None

Standard history

Status
Date
Type
Name
04.02.2014
Main
This Technical Specification examines electronic patient record systems at the clinical point of care that are also interoperable with EHRs. Hardware and process controls are out of the scope. This Technical Specification addresses their security and privacy protections by providing a set of security and privacy requirements, along with guidelines and best practice for conformity assessment.
ISO/IEC 15408 (all parts) defines “targets of evaluation” for security evaluation of IT products. This Technical Specification includes a cross-mapping of 82 security and privacy requirements against the Common Criteria categories in ISO/IEC 15408 (all parts). The point-of-service (POS) clinical software is typically part of a larger system, for example, running on top of an operating system, so it must work in concert with other components to provide proper security and privacy. While a Protection Profile (PP) includes requirements for component security functions to support system security services, it does not specify protocols or standards for conformity assessment, and does not address privacy requirements.
This Technical Specification focuses on two main topics:
a)  Security and privacy requirements (Clause 5). Clause 5 is technical and provides a comprehensive set of 82 requirements necessary to protect (information, patients) against the main categories of risks, addressing the broad scope of security and privacy concerns for point of care, interoperable clinical (electronic patient record) systems. These requirements are suitable for conformity assessment purposes.
b)  Best practice and guidance for establishing and maintaining conformity assessment programs (Clause 6). Clause 6 provides an overview of conformity assessment concepts and processes that can be used by governments, local authorities, professional associations, software developers, health informatics societies, patients’ representatives and others, to improve conformity with health software security and privacy requirements. Annex A provides complementary information useful to countries in designing conformity assessment programs such as further material on conformity assessment business models, processes and other considerations, along with illustrative examples of conformity assessment activities in four countries.
Policies that apply to a local, regional or national implementation environment, and procedural, administrative or physical (including hardware) aspects of privacy and security management are outside the scope of this Technical Specification.  Security management is included in the scope of ISO 27799.

Required fields are indicated with *

*
*
*
PDF
39.04 € incl tax
Paper
39.04 € incl tax
Browse standard from 2.44 € incl tax
Standard monitoring

Customers who bought this item also bought

Main

ISO 22857:2013

Health informatics -- Guidelines on data protection to facilitate trans-border flows of personal health data
Newest version Valid from 10.12.2013
Main

EVS-EN ISO 27789:2013

Health informatics - Audit trails for electronic health records (ISO 27789:2013)
Withdrawn from 01.11.2021
Main

EVS-EN ISO 27799:2016

Health informatics - Information security management in health using ISO/IEC 27002 (ISO 27799:2016)
Newest version Valid from 05.09.2016
Main

ISO/TS 21547:2010

Health informatics -- Security requirements for archiving of electronic health records -- Principles
Newest version Valid from 02.02.2010