Health informatics. Electronic health record communication - Security

Health informatics. Electronic health record communication - Security

Regular price
£272.00
Sale price
£272.00
Regular price
£136.00
Sold out
Unit price
per 

What is ISO 13606-4 about?  

Electronic health record is used for purposes such as teaching, clinical audit, administration and reporting, service management, research and epidemiology. ISO 13606 is a multipart series, that discusses standards for electronic health record communication.  

ISO 13606-4 describes a methodology for specifying the privileges necessary to access electronic health record (EHR) data. This methodology forms part of the overall electronic health record communications architecture defined in ISO 13606-1. 

ISO 13606-4 seeks to address those requirements uniquely pertaining to EHR communications and to represent and communicate EHR-specific information that will inform an access decision. ISO 13606-4 also refers to general security requirements that apply to EHR communications and points at technical solutions and standards that specify details on services meeting these security needs. 

NOTE: Security requirements for EHR systems not related to the communication of EHRs are not covered by ISO 13606-4

Who is ISO 13606-4 for? 

ISO 13606-4  on electronic health record communication is useful for: 

  •    Manufacturers of EHR systems 
  •    Research and development team 
  •    Healthcare professional  
  •    Healthcare industries 
  •    Healthcare service providers 
  •    Regulatory bodies 

Why should you use ISO 13606-4 

The communication of electronic health records (EHRs) within and across organizational boundaries, and sometimes across national borders, is challenging from a security perspective. Health records should be created, processed and managed in ways that assure the confidentiality of their contents and legitimate control by patients in how they are used. 

ISO 13606-4 defines a basic framework that can be used as a minimum specification of EHR access policy and a richer generic representation for the communication of more fine-grained detailed policy information.  

ISO 13606-4 covers key data flows and security-related business processes. For each key data flow there will be an acknowledgement response, and optionally a rejection may be returned instead of the requested data. 

ISO 13606‑4 defines an EHR_AUDIT_LOG_EXTRACT to communicate the audit log activity history pertaining to part or all of an electronic health record. 

What’s changed since the last update? 

BS EN ISO 13606-4:2019 supersedes BS EN ISO 13606-4:2009. which has been technically revised. BS EN ISO 13606-4:2019 includes some technical changes with respect to BS EN ISO 13606-4:2009. These include:  

  • Some terms for functional roles have been updated to align with CONTSYS 
  • The rules for using this vocabulary now state that jurisdictions can nominate alternatives or specializations of these terms if needed 
  • The access policy model now also permits jurisdictional alternative terms to be used where appropriate 
  • Audit log model