EN ISO 27789:2013

Health informatics - Audit trails for electronic health records (ISO 27789:2013) EN ISO 27789:2013

Publication date:   Jul 15, 2013

General information

99.60 Withdrawal effective   Oct 20, 2021

CEN

CEN/TC 251 Health informatics

European Norm

35.240.80   IT applications in health care technology

Buying

Withdrawn

Language in which you want to receive the document.

Scope

ISO 27789:2013 specifies a common framework for audit trails for electronic health records (EHR), in terms of audit trigger events and audit data, to keep the complete set of personal health information auditable across information systems and domains.
It is applicable to systems processing personal health information which, complying with ISO 27799, create a secure audit record each time a user accesses, creates, updates or archives personal health information via the system.
ISO 27789:2013 covers only actions performed on the EHR, which are governed by the access policy for the domain where the electronic health record resides. It does not deal with any personal health information from the electronic health record, other than identifiers, the audit record only containing links to EHR segments as defined by the governing access policy.
It does not cover the specification and use of audit logs for system management and system security purposes, such as the detection of performance problems, application flaw, or support for a reconstruction of data, which are dealt with by general computer security standards such as ISO/IEC 15408-2.

Life cycle

NOW

WITHDRAWN
EN ISO 27789:2013
99.60 Withdrawal effective
Oct 20, 2021

REVISED BY

PUBLISHED
EN ISO 27789:2021