Skip to main content
Back

EVS-EN ISO 27789:2013

Health informatics - Audit trails for electronic health records (ISO 27789:2013)

General information

Withdrawn from 01.11.2021
Base Documents
ISO 27789:2013; EN ISO 27789:2013
Directives or regulations
None

Standard history

Status
Date
Type
Name
01.11.2021
Main
02.04.2013
Main
This International Standard specifies a common framework for audit trails for electronic health records (EHR), in terms of audit trigger events and audit data, to keep the complete set of personal health information auditable across information systems and domains. It is applicable to systems processing personal health information which, complying with ISO 27799, create a secure audit record each time a user accesses, creates, updates or archives personal health information via the system. NOTE Such audit records, at a minimum, uniquely identify the user, uniquely identify the subject of care, identify the function performed by the user (record creation, access, update, etc.), and record the date and time at which the function was performed. This International Standard covers only actions performed on the EHR, which are governed by the access policy for the domain where the electronic health record resides. It does not deal with any personal health information from the electronic health record, other than identifiers, the audit record only containing links to EHR segments as defined by the governing access policy. It does not cover the specification and use of audit logs for system management and system security purposes, such as the detection of performance problems, application flaw, or support for a reconstruction of data, which are dealt with by general computer security standards such as ISO/IEC 15408-2[9]. Annex A gives examples of audit scenarios. Annex B gives an overview of audit log services.

Required fields are indicated with *

*
*
*
PDF
26.84 € incl tax
Paper
26.84 € incl tax
Browse standard from 2.44 € incl tax
Standard monitoring

Customers who bought this item also bought

Main

EVS-EN ISO 27799:2016

Health informatics - Information security management in health using ISO/IEC 27002 (ISO 27799:2016)
Newest version Valid from 05.09.2016
Main

ISO/TS 21547:2010

Health informatics -- Security requirements for archiving of electronic health records -- Principles
Newest version Valid from 02.02.2010
Main

EVS-ISO 15489-1:2017

Information and documentation - Records management - Part 1: Concepts and principles (ISO 15489-1:2016)
Newest version Valid from 02.03.2017
Main

ISO/IEC 27004:2016

Information technology -- Security techniques -- Information security management -- Monitoring, measurement, analysis and evaluation
Newest version Valid from 15.12.2016