SR EN ISO 27799:2026

Health informatics - Information security controls in health based on ISO/IEC 27002 (ISO 27799:2025)

This document provides information security controls, including implementation guidance, for health organizations. It is based on ISO/IEC 27002:2022 In addition to generic ICT equipment and software used in many other environments, the scope of this document includes software and systems specifically for healthcare, such as electronic health record systems and medical devices incorporating health software. Such medical devices can be programmed or programmable and can contain software, firmware or both. Other digital equipment (such as that for environmental and infection control, building management, and physical security), which can be used in premises where healthcare is provided, is also in scope. This document applies to information in all its aspects, whatever form the information takes (including text and numbers, sound recordings, drawings, images and video), by whatever means it has been acquired or captured, whatever means are used to store it (such as printing or writing on paper or storage electronically), and whatever means are used to transfer or exchange it (orally, by

71.87

Status : Valid
Approval date : 2/27/2026
Number of pages : 86
ICS : 35.030 IT Security,35.240.80 IT applications in health care technology
Technical Committee : 319 - Health informatics

Relations with other standards: