ISO 27799
ISO 27799 — Health informatics: Information security management in health using ISO/IEC 27002 translates general information security controls into the healthcare context.
It does not replace ISO 27001. ISO 27001 defines the management system; ISO 27002 describes controls; ISO 27799 explains what those controls mean when the information is personal health information (PHI).
Why health needs its own guidance
Health data has properties that generic security guidance does not anticipate:
- It cannot be reissued. A leaked password is replaced; a leaked diagnosis is permanent.
- Availability can be a safety issue. A locked record during an emergency is a clinical risk, not only an operational one.
- Access is broad and shifting. Clinicians, nurses, laboratory staff, pharmacists, administrators and researchers all have legitimate but different needs.
- Emergency override is required. Systems must allow break-glass access — and must make it visible afterwards.
- Retention is measured in decades, often for a lifetime.
- Secondary use is normal — reporting, research, public health — and each use needs its own basis.
Themes it emphasises
Access control
Role-based access aligned to care relationships, with break-glass procedures that are logged, reviewed and explained to staff in advance.
Audit and accountability
Comprehensive, tamper-resistant logging of who accessed which record and when. In healthcare, unauthorized reading is a common incident type, so read access must be auditable, not only writes.
Unique identification
Every user individually identified. Shared clinical logins destroy accountability and are still common in busy wards.
Data integrity and continuity
Clinical decisions rest on record accuracy. Backup, recovery and continuity planning are patient-safety controls.
Third parties
Suppliers, hosting providers and integration partners handling PHI are bound by equivalent obligations, with the right to verify.
Disclosure and secondary use
Documented rules for de-identification, minimum necessary disclosure, and the lawful basis for each secondary use.
Using it in practice
- Run the ISO 27001 risk assessment with clinical safety in the impact criteria, not just financial and reputational loss.
- Use ISO 27799 when writing the Statement of Applicability — it explains what "adequate" looks like for PHI.
- Map controls to the applicable legal regime (GDPR, national health data law).
- Involve clinicians. Controls that obstruct care get bypassed, and a bypassed control protects nothing.
Related
- ISO 27001 — the management system
- Data governance — decision rights over data
- GDPR — legal obligations for personal data
- Health data — what is being protected
References
- ISO 27799 — https://www.iso.org/standard/62777.html
- ISO/IEC 27002:2022 — information security controls