BS ISO 22857-2013 Health informatics Guidelines on data protection to facilitate transborder flows of personal health data《健康信息学 个人卫生信息传输的数据保护指导方针》.pdf
《BS ISO 22857-2013 Health informatics Guidelines on data protection to facilitate transborder flows of personal health data《健康信息学 个人卫生信息传输的数据保护指导方针》.pdf》由会员分享,可在线阅读,更多相关《BS ISO 22857-2013 Health informatics Guidelines on data protection to facilitate transborder flows of personal health data《健康信息学 个人卫生信息传输的数据保护指导方针》.pdf(70页珍藏版)》请在麦多课文档分享上搜索。
1、BSI Standards PublicationBS ISO 22857:2013Health informatics Guidelines on data protectionto facilitate transborder flowsof personal health dataCopyright British Standards Institution Provided by IHS under license with BSI - Uncontrolled Copy Not for ResaleNo reproduction or networking permitted wit
2、hout license from IHS-,-,-BS ISO 22857:2013 BRITISH STANDARDNational forewordThis British Standard is the UK implementation of ISO 22857:2013. Itsupersedes BS ISO 22857:2004 which is withdrawn.The UK participation in its preparation was entrusted to TechnicalCommittee IST/35, Health informatics.A li
3、st of organizations represented on this committee can beobtained on request to its secretary.This publication does not purport to include all the necessaryprovisions of a contract. Users are responsible for its correctapplication. The British Standards Institution 2014. Published by BSI StandardsLim
4、ited 2014ISBN 978 0 580 65294 3ICS 35.240.80Compliance with a British Standard cannot confer immunity fromlegal obligations.This British Standard was published under the authority of theStandards Policy and Strategy Committee on 28 February 2014.Amendments issued since publicationDate Text affectedC
5、opyright British Standards Institution Provided by IHS under license with BSI - Uncontrolled Copy Not for ResaleNo reproduction or networking permitted without license from IHS-,-,-BS ISO 22857:2013 ISO 2013Health informatics Guidelines on data protection to facilitate trans-border flows of personal
6、 health dataInformatique de sant Lignes directrices sur la protection des donnes pour faciliter les flux dinformation sur la sant du personnel de part et dautre des frontiresINTERNATIONAL STANDARDISO22857Second edition2013-12-15Reference numberISO 22857:2013(E)Copyright British Standards Institution
7、 Provided by IHS under license with BSI - Uncontrolled Copy Not for ResaleNo reproduction or networking permitted without license from IHS-,-,-BS ISO 22857:2013ISO 22857:2013(E)ii ISO 2013 All rights reservedCOPYRIGHT PROTECTED DOCUMENT ISO 2013All rights reserved. Unless otherwise specified, no par
8、t of this publication may be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below or ISOs member bo
9、dy in the country of the requester.ISO copyright officeCase postale 56 CH-1211 Geneva 20Tel. + 41 22 749 01 11Fax + 41 22 749 09 47E-mail copyrightiso.orgWeb www.iso.orgPublished in SwitzerlandCopyright British Standards Institution Provided by IHS under license with BSI - Uncontrolled Copy Not for
10、ResaleNo reproduction or networking permitted without license from IHS-,-,-BS ISO 22857:2013ISO 22857:2013(E) ISO 2013 All rights reserved iiiContents PageForeword vIntroduction vi1 Scope . 12 Normative references 13 Terms and definitions . 14 Abbreviated terms 35 Structure of this International Sta
11、ndard . 36 General principles and roles 36.1 General principles 36.2 Roles . 47 Legitimising data transfer 47.1 The concept of “adequate” data protection 47.2 Conditions for legitimate transfer 58 Criteria for ensuring adequate data protection with respect to the transfer of personal health data 68.
12、1 The requirement for adequate data protection 68.2 Content principles 68.3 Procedural/enforcement mechanisms. 98.4 Contracts . 108.5 Overriding laws . 118.6 Anonymisation . 118.7 Legitimacy of consent 129 Security policy 129.1 General 129.2 The purpose of the security policy . 129.3 The “level” of
13、security policy . 139.4 High Level Security Policy: general aspects 1310 High Level Security Policy: the content 1410.1 Principle One: overriding generic principle . 1410.2 Principle Two: chief executive support . 1510.3 Principle Three: documentation of measures and review .1610.4 Principle Four: D
14、ata protection security officer .1610.5 Principle Five: permission to process 1710.6 Principle Six: information about processing 1810.7 Principle Seven: information for the data subject .2010.8 Principle Eight: prohibition of onward data transfer without consent .2010.9 Principle Nine: remedies and
15、compensation . 2110.10 Principle Ten: security of processing 2210.11 Principle Eleven: responsibilities of staff and other contractors .2311 Rationale and observations on measures to support Principle Ten concerning security of processing 2411.1 General 2411.2 Encryption and digital signatures for t
16、ransmission to the data importer 2411.3 Access controls and user authentication . 2411.4 Audit trails . 2511.5 Physical and environmental security . 2511.6 Application management and network management 2511.7 Malicious software 2511.8 Breaches of security 2511.9 Business continuity plan . 25Copyrigh
17、t British Standards Institution Provided by IHS under license with BSI - Uncontrolled Copy Not for ResaleNo reproduction or networking permitted without license from IHS-,-,-BS ISO 22857:2013ISO 22857:2013(E)iv ISO 2013 All rights reserved11.10 Handling very sensitive data 2611.11 Standards 2612 Per
18、sonal health data in non-electronic form .26Annex A (informative) Key primary international documents on data protection 27Annex B (informative) National documented requirements and legal provisions in a range of countries .32Annex C (informative) Exemplar contract clauses: Controller to controller
19、.37Annex D (informative) Exemplar contract clauses: Controller to processor .44Annex E (informative) Handling very sensitive personal health data 53Bibliography .55Copyright British Standards Institution Provided by IHS under license with BSI - Uncontrolled Copy Not for ResaleNo reproduction or netw
20、orking permitted without license from IHS-,-,-BS ISO 22857:2013ISO 22857:2013(E)ForewordISO (the International Organization for Standardization) is a worldwide federation of national standards bodies (ISO member bodies). The work of preparing International Standards is normally carried out through I
21、SO technical committees. Each member body interested in a subject for which a technical committee has been established has the right to be represented on that committee. International organizations, governmental and non-governmental, in liaison with ISO, also take part in the work. ISO collaborates
22、closely with the International Electrotechnical Commission (IEC) on all matters of electrotechnical standardization.The procedures used to develop this document and those intended for its further maintenance are described in the ISO/IEC Directives, Part 1. In particular the different approval criter
23、ia needed for the different types of ISO documents should be noted. This document was drafted in accordance with the editorial rules of the ISO/IEC Directives, Part 2 (see www.iso.org/directives).Attention is drawn to the possibility that some of the elements of this document may be the subject of p
24、atent rights. ISO shall not be held responsible for identifying any or all such patent rights. Details of any patent rights identified during the development of the document will be in the Introduction and/or on the ISO list of patent declarations received (see www.iso.org/patents).Any trade name us
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- BSISO228572013HEALTHINFORMATICSGUIDELINESONDATAPROTECTIONTOFACILITATETRANSBORDERFLOWSOFPERSONALHEALTHDATA

链接地址:http://www.mydoc123.com/p-586459.html