Skip to main content
Back

EVS-EN ISO 27799:2026

Health informatics - Information security controls in health based on ISO/IEC 27002 (ISO 27799:2025)

General information

Valid from 02.02.2026
Base Documents
ISO 27799:2025; EN ISO 27799:2026
Directives or regulations
None

Standard history

Status
Date
Type
Name
02.02.2026
Main
05.09.2016
Main

ISO 27799 provides information security controls, including implementation guidance, for health organisations. It is based on ISO/IEC 27002:2022

In addition to generic ICT equipment and software used in many other environments, the scope of this standard includes software and systems specifically for healthcare. Such examples are electronic health record systems and medical devices incorporating health software. Medical devices can be programmed or programmable and can contain software, firmware or both. Other digital equipment (such as that for environmental and infection control, building management, and physical security), which can be used in premises where healthcare is provided, is also in scope.

ISO 27799 applies to information in all its forms, regardless of how the information is represented. This includes text, numerical data, sound recordings, drawings, images, and video.

The standard applies irrespective of how the information is acquired or captured, how it is stored (for example, on paper or electronically), or how it is transferred or exchanged, including oral communication, physical delivery, postal services, movement of storage media, direct links, or networked systems.

ISO 27799 is for organisations of all types and sizes that provide healthcare or are custodians of personal health information for other reasons. The information that they are responsible for can be stored and processed in many possible ways and locations, including on premises or in the cloud.

This standard applies to all physical settings where healthcare is intended to be delivered. Examples are hospitals, clinics and other locations or facilities designated for healthcare purposes such as ambulances and mobile imaging or diagnostic units. It also applies to care provided elsewhere, such as in residential premises. In addition to the range of settings, ISO 27799 applies to all methods of service provision including remote or virtual healthcare.

ISO 27799:2025 text has been approved in Europe as EN ISO 27799:2026 without any changes.

Required fields are indicated with *

*
*
*
PDF
32.24 € incl tax
Paper
32.24 € incl tax
Browse standard from 2.48 € incl tax
Standard monitoring

Customers who bought this item also bought

Main + amendment

EVS-EN ISO/IEC 27001:2023+A1:2024

Information security, cybersecurity and privacy protection - Information security management systems - Requirements (ISO/IEC 27001:2022 + ISO/IEC 27001:2022/Amd 1:2024)
Newest version Valid from 16.12.2024
Main

EVS-EN ISO/IEC 27002:2022

Information security, cybersecurity and privacy protection - Information security controls (ISO/IEC 27002:2022)
Newest version Valid from 01.12.2022
Main

EVS-EN ISO 22313:2020

Security and resilience - Business continuity management systems - Guidance on the use of ISO 22301 (ISO 22313:2020)
Newest version Valid from 19.03.2020
Main + amendment

EVS-EN ISO 22301:2019+A1:2024

Security and resilience - Business continuity management systems - Requirements (ISO 22301:2019 + ISO 22301:2019/Amd 1:2024)
Newest version Valid from 16.12.2024