The ISO 27799 standard, which provides guidelines for corporate information security standards and information security management practices in the healthcare sector, was updated in 2025. The changes primarily reflect developments in the ISO/IEC 27002 standard and the current threat landscape in the healthcare sector.
- The key changes in the 2025 version stem from the update to ISO 27002:2022.
- Whilst the 2025 version is a control-focused standard, the 2016 version had a broader management + control interpretation role.
- The 2016 version reflected the ISO 27002:2013 version (e.g. policy, asset management, access control), but in the 2025 version, it has been fully aligned with the structure of ISO 27002:2022, with definitions such as organisational controls, human-related controls, physical controls and technological controls being redefined.
- Whilst the 2016 version contained limited content specific to the healthcare sector, the 2025 version introduces updated healthcare-specific controls and includes updated guidance addressing modern risks (e.g. connected devices, distributed data).
- In the 2016 version, the depth of the healthcare context focused on protecting PHI (privacy, integrity, availability) in various formats, and technology-neutral guidelines were limited. However, the 2025 version makes greater reference to medical devices and healthcare software, interoperability between systems, distributed and cross-border data flows, and striking a balance between patient safety and security.
- The 2025 version reflects modern digital healthcare ecosystems (IoT, EHRs, telehealth).
- The 2016 version contained more limited supplementary content. The 2025 version includes a cybersecurity guide for the healthcare sector and updated examples of security and privacy requirements.
- With the 2025 version, the ISO 27799 standard has been made more compatible with the ISO 81001-1 (healthcare software security) standard, enabling it to respond to the modern ISO ecosystem and digital health standards.
- The 2016 version provided a technology-neutral, relatively stable environment for healthcare information security; the 2025 version takes into account rapidly evolving cyber threats, digital transformation (AI, IoT, cloud, telehealth), and has been developed to be more risk-focused and context-aware.
As healthcare organisations adopt standards such as ISO 27001 and ISO 27799, operational challenges will be mitigated, and controllable measures across complex systems will become sustainable. When selecting and implementing information security controls, the impact on clinical workflows, system availability and patient safety must be taken into account, whilst also complying with applicable legal, regulatory, audit and contractual obligations.
The correct application of the standard and its annexes, by reducing risks such as unauthorised access, excessive data disclosure and misuse, enables electronic health record systems, medical devices and health information systems to exchange data securely beyond organisational boundaries, and will provide a stronger foundation for AI-focused healthcare applications.
The standard is suitable for large and small-scale hospitals, ambulance systems, mobile imaging and diagnostic units, clinics, pharmaceutical warehouses, pharmaceutical manufacturing, and their suppliers.
CFECERT provides audit and training services in healthcare-specific standards such as ISO 27799:2025, ISO 7101, and HIPAA.