Hälso- och sjukvårdsinformatik
- +Ämnesområden
- +Informationsteknik, kontorsutrustning (23)
- Informationsteknik: allmänt (0)
- IT-säkerhet (8)
- +Kodning av information (1)
- Programspråk (0)
- Programutveckling och systemdokumentation (0)
- +Öppna system (OSI) (0)
- Nätarkitekturer (0)
- Datorgrafik (0)
- Mikroprocessorsystem (0)
- Terminalutrustning och övrig kringutrustning (0)
- Gränssnitt och anslutningsutrustning (0)
- Molnbaserade datortjänster (0)
- +Datalagringsmedier (0)
- +IT-tillämpningar (16)
- IT-tillämpningar: allmänt (3)
- Datorstödd design (0)
- Identifieringskort och tillhörande läsarenheter (0)
- IT-tillämpningar i kontorsarbete (0)
- IT- tillämpningar inom information, dokumentation och förlagsverksamhet (1)
- IT- tillämpningar inom finansiella system (0)
- IT- tillämpningar inom industrin (0)
- IT- tillämpningar inom transport (5)
- IT-tillämpningar inom handel (0)
- IT- tillämpningar inom bygg- och anläggningsindustri (1)
- IT-tillämpningar inom jordbruk (0)
- IT- tillämpningar inom posttjänster (0)
- IT- tillämpningar inom vetenskap (1)
- Hälso- och sjukvårdsinformatik (2)
- IT- tillämpningar inom utbildning (2)
- Internettillämpningar (0)
- IT- tillämpningar inom övriga områden (1)
- Kontorsutrustning (0)
This document describes a methodology for specifying the privileges necessary to access EHR data. This methodology forms part of the overall EHR communications architecture defined in ISO 13606-1. This document seeks to address those requirements uniquely pertaining to EHR communications and to represent and communicate EHR-specific information that will inform an access decision. It also refers to general security requirements that apply to EHR communications and points at technical solutions and standards that specify details on services meeting these security needs. NOTE Security requirements for EHR systems not related to the communication of EHRs are outside the scope of this document.
ISO 25237:2017 contains principles and requirements for privacy protection using pseudonymization services for the protection of personal health information. This document is applicable to organizations who wish to undertake pseudonymization processes for themselves or to organizations who make a claim of trustworthiness for operations engaged in pseudonymization services. ISO 25237:2017 - defines one basic concept for pseudonymization (see Clause 5), - defines one basic methodology for pseudonymization services including organizational, as well as technical aspects (see Clause 6), - specifies a policy framework and minimal requirements for controlled re-identification (see Clause 7), - gives an overview of different use cases for pseudonymization that can be both reversible and irreversible (see Annex A), - gives a guide to risk assessment for re-identification (see Annex B), - provides an example of a system that uses de-identification (see Annex C), - provides informative requirements to an interoperability to pseudonymization services (see Annex D), and - specifies a policy framework and minimal requirements for trustworthy practices for the operations of a pseudonymization service (see Annex E).