Skip to main content

ISO 27799

ISO 27799 — Health informatics: Information security management in health using ISO/IEC 27002 translates general information security controls into the healthcare context.

It does not replace ISO 27001. ISO 27001 defines the management system; ISO 27002 describes controls; ISO 27799 explains what those controls mean when the information is personal health information (PHI).


Why health needs its own guidance​

Health data has properties that generic security guidance does not anticipate:

  • It cannot be reissued. A leaked password is replaced; a leaked diagnosis is permanent.
  • Availability can be a safety issue. A locked record during an emergency is a clinical risk, not only an operational one.
  • Access is broad and shifting. Clinicians, nurses, laboratory staff, pharmacists, administrators and researchers all have legitimate but different needs.
  • Emergency override is required. Systems must allow break-glass access — and must make it visible afterwards.
  • Retention is measured in decades, often for a lifetime.
  • Secondary use is normal — reporting, research, public health — and each use needs its own basis.

Themes it emphasises​

Access control​

Role-based access aligned to care relationships, with break-glass procedures that are logged, reviewed and explained to staff in advance.

Audit and accountability​

Comprehensive, tamper-resistant logging of who accessed which record and when. In healthcare, unauthorized reading is a common incident type, so read access must be auditable, not only writes.

Unique identification​

Every user individually identified. Shared clinical logins destroy accountability and are still common in busy wards.

Data integrity and continuity​

Clinical decisions rest on record accuracy. Backup, recovery and continuity planning are patient-safety controls.

Third parties​

Suppliers, hosting providers and integration partners handling PHI are bound by equivalent obligations, with the right to verify.

Disclosure and secondary use​

Documented rules for de-identification, minimum necessary disclosure, and the lawful basis for each secondary use.


Using it in practice​

  1. Run the ISO 27001 risk assessment with clinical safety in the impact criteria, not just financial and reputational loss.
  2. Use ISO 27799 when writing the Statement of Applicability — it explains what "adequate" looks like for PHI.
  3. Map controls to the applicable legal regime (GDPR, national health data law).
  4. Involve clinicians. Controls that obstruct care get bypassed, and a bypassed control protects nothing.


References​