Skip to main content
Category
Standard
ID
ISO 22600-3:2014
Type
Standard
Version
1
Access
Fees apply to access
Status
Active
Created
Oct 2014
ISO 22600 defines principles and specifies services needed for managing privileges and access control to data and/or functions. It focuses on communication and use of health information distributed across policy domain boundaries. This includes healthcare information sharing across unaffiliated providers of health care, healthcare organisations, health insurance companies, their patients, staff members, and trading partners by both individuals and application systems ranging from a local situation to a regional or even national situation. ISO 22600 specifies the necessary component-based concepts and is intended to support their technical implementation. It will not specify the use of these concepts in particular clinical process pathways.

ISO 22600-3:2014 instantiates requirements for repositories for access control policies and requirements for privilege management infrastructures. It provides implementation examples of the formal models specified in ISO 22600‑2.

Main sections:

· Scope

· Normative references

· Terms and definitions

· Abbreviated terms

· Structures and services for privilege management and access control

· Interpretation of ISO 22600-2 formal models in healthcare settings

· Concept representation for health information systems

· Consent

· Emergency access

· Refinement of the control model

· Refinement of the delegation model

· Annex A: Privilege management infrastructure

· Annex B: Attribute certificate extensions

· Annex C: Terminology comparison

· Annex D: Examples for policy management and policy representation
Access Health informatics — Privilege management and access control — Part 3: Implementations

By accessing this content, you are leaving this website. The Agency takes no responsibility for the accuracy of content on the destination page.