IEC/TS 81001-2-2:2025

International Standard   Current Edition · Approved on 03 October 2025

Health software and health IT systems safety, effectiveness and security — Part 2-2: Guidance for the implementation, disclosure and communication of security needs, risks and controls

IEC/TS 81001-2-2:2025 Files

English 96 Pages
Current Edition

IEC/TS 81001-2-2:2025 Scope

This document presents an informative set of common, high-level security-related capabilities and additional considerations to be used across the life cycle of health software and health IT systems, for the information exchange between the health software manufacturers (including medical device manufacturers), healthcare delivery organizations (HDOs) and other stakeholders. It is applicable to health software running on any platform and in any environment such as cloud, on premise or hybrid. While important security topics, the following are outside the scope of this document: a) the security policies of the HDO, b) the product and services security policies of the manufacturer, c) determinations of risk tolerance by the HDO or manufacturer, and d) clinical studies where there is a need to secure personal data. As security risks can be caused by any product on health IT systems and health IT Infrastructure, considerations in this document can be applied for other products that are not health software. IEC TS 81001-2-2:2025 withdraws and replaces: – IEC TR 80001-2-2, Application of risk management for IT-networks incorporating medical devices – Part 2-2: Guidance for the communication of medical device security needs, risks and controls – IEC TR 80001-2-8, Application of risk management for IT-networks incorporating medical devices – Part 2-8: Application guidance – Guidance on standards for establishing the security capabilities identified in IEC TR 80001-2-2 This document includes the following significant changes: a) Combines and updates the contents of IEC TR 80001-2-2 and IEC TR 80001-2-8; b) Extends the scope to health software instead to only medical device software; c) Aligns contents and definitions to ISO 81001-1:2021 and the updated IEC 80001-1; d) Removed the Configuration of Security Features (CNFS) capability, as any configurable security capability shall be clearly communicated. e) Provide security control mappings to several new standards, e.g. IEC TR 60601-4-5, IEC 62443-4-2, ISO/IEEE 11073-40102 and the recent versions of previous standards, e.g. ISO/IEC 27002 and NIST 800-53 version 5.

Best Sellers

GSO 150-2:2013
 
Gulf Standard
Expiration dates for food products - Part 2 : Voluntary expiration dates
BH GSO 150-2:2015
GSO 150-2:2013 
Bahraini Standard
Expiration dates for food products - Part 2 : Voluntary expiration dates
BH GSO 2055-1:2016
GSO 2055-1:2015 
Bahraini Technical Regulation
HALAL FOOD - Part 1 : General Requirements
GSO 2055-1:2015
 
Gulf Technical Regulation
HALAL FOOD - Part 1 : General Requirements

Recently Published

ISO/TS 14742:2025
 
International Standard
Financial services — Recommendations and requirements on cryptographic algorithms and their use
ISO/IEC 9995-10:2025
 
International Standard
Information technology — Keyboard layouts for text and office systems — Part 10: Conventional symbols and methods to represent graphic characters not uniquely recognizable by their glyph on keyboards and in documentation
ISO 80601-2-70:2025
 
International Standard
Medical electrical equipment — Part 2-70: Particular requirements for basic safety and essential performance of sleep apnoea breathing therapy equipment
ISO 18192-3:2025
 
International Standard
Implants for surgery — Wear of total intervertebral spinal disc prostheses — Part 3: Impingement-wear testing and corresponding environmental conditions for test of lumbar and cervical prostheses