Draft
International Standard
ISO/DIS 25237
Health informatics — Pseudonymization
Reference number
ISO/DIS 25237
Edition 2
Draft International Standard
Read sample
ISO/DIS 25237
86409
This Draft International Standard is in the enquiry phase with ISO members.
Will replace ISO 25237:2017

ISO/DIS 25237

ISO/DIS 25237
86409
Language
Format
CHF 67

Abstract

ISO 25237:2017 contains principles and requirements for privacy protection using pseudonymization services for the protection of personal health information. This document is applicable to organizations who wish to undertake pseudonymization processes for themselves or to organizations who make a claim of trustworthiness for operations engaged in pseudonymization services.

ISO 25237:2017

- defines one basic concept for pseudonymization (see Clause 5),

- defines one basic methodology for pseudonymization services including organizational, as well as technical aspects (see Clause 6),

- specifies a policy framework and minimal requirements for controlled re-identification (see Clause 7),

- gives an overview of different use cases for pseudonymization that can be both reversible and irreversible (see Annex A),

- gives a guide to risk assessment for re-identification (see Annex B),

- provides an example of a system that uses de-identification (see Annex C),

- provides informative requirements to an interoperability to pseudonymization services (see Annex D), and

- specifies a policy framework and minimal requirements for trustworthy practices for the operations of a pseudonymization service (see Annex E).

General information

  •  : Under development

    You can help develop this draft international standard by contacting your national member

    : DIS ballot initiated: 12 weeks [40.20]
  •  : 2
     : 44
  • ISO/TC 215
    35.240.80 
  • RSS updates

Sustainable Development Goals

This standard contributes to the following Sustainable Development Goal

Got a question?

Check out our Help and Support