EN 12251:2004
(Main)Health informatics - Secure User Identification for Health Care - Management and Security of Authentication by Passwords
Health informatics - Secure User Identification for Health Care - Management and Security of Authentication by Passwords
This document is designed to improve the authentication of individual users of health care IT systems, by strengthening the automatic software procedures associated with the management of user identifiers and passwords, without resorting to additional hardware facilities.
This document applies to all information systems (hereafter called systems) within the health care environment that handle or store sensitive person identifiable health information, using passwords as the only means of authenticating the entered user identifier, i.e., verifying the claimed identity of a user. Systems that fall within the scope of this document include for example electronic patient record systems, patient administrative systems and laboratory systems, containing personal health information.
This document does not apply to systems outside the health care environment. Neither does it apply to systems within the health care environment that use other means of identification and authentication, such as smart cards, biometric methods or other technical facilities.
Medizinische Informatik - Sichere Nutzeridentifikation im Gesundheitswesen - Management und Sicherheit für die Authentifizierung durch Passwörter
Informatique de santé - Sécurité de l'identification de l'utilisateur des soins de santé - Gestion et sécurité de l'authentification des mots de passe
Zdravstvena informatika – Varna identifikacija uporabnikov v zdravstvenem varstvu – Upravljanje in varnost avtentikacije z gesli
General Information
Relations
Standards Content (Sample)
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.Zdravstvena informatika – Varna identifikacija uporabnikov v zdravstvenem varstvu – Upravljanje in varnost avtentikacije z gesliMedizinische Informatik - Sichere Nutzeridentifikation im Gesundheitswesen - Management und Sicherheit für die Authentifizierung durch PasswörterInformatique de santé - Sécurité de l'identification de l'utilisateur des soins de santé - Gestion et sécurité de l'authentification des mots de passeHealth informatics - Secure User Identification for Health Care - Management and Security of Authentication by Passwords35.240.80Uporabniške rešitve IT v zdravstveni tehnikiIT applications in health care technologyICS:Ta slovenski standard je istoveten z:EN 12251:2004SIST EN 12251:2005en01-januar-2005SIST EN 12251:2005SLOVENSKI
STANDARDSIST ENV 12251:20031DGRPHãþD
EUROPEAN STANDARDNORME EUROPÉENNEEUROPÄISCHE NORMEN 12251August 2004ICS 35.240.80 English versionHealth informatics - Secure User Identification for Health Care -Management and Security of Authentication by PasswordsInformatique de santé - Sécurité de l'identification del'utilisateur des soins de santé - Gestion et sécurité del'authentification des mots de passeMedizinische Informatik - Sichere Nutzeridentifikation imGesundheitswesen - Management und Sicherheit für dieAuthentifizierung durch PasswörterThis European Standard was approved by CEN on 21 June 2004.CEN members are bound to comply with the CEN/CENELEC Internal Regulations which stipulate the conditions for giving this EuropeanStandard the status of a national standard without any alteration. Up-to-date lists and bibliographical references concerning such nationalstandards may be obtained on application to the Central Secretariat or to any CEN member.This European Standard exists in three official versions (English, French, German). A version in any other language made by translationunder the responsibility of a CEN member into its own language and notified to the Central Secretariat has the same status as the officialversions.CEN members are the national standards bodies of Austria, Belgium, Cyprus, Czech Republic, Denmark, Estonia, Finland, France,Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Slovakia,Slovenia, Spain, Sweden, Switzerland and United Kingdom.EUROPEAN COMMITTEE FOR STANDARDIZATIONCOMITÉ EUROPÉEN DE NORMALISATIONEUROPÄISCHES KOMITEE FÜR NORMUNGManagement Centre: rue de Stassart, 36
B-1050 Brussels© 2004 CENAll rights of exploitation in any form and by any means reservedworldwide for CEN national Members.Ref. No. EN 12251:2004: ESIST EN 12251:2005
Potential password complexity requirements.10 Annex B (informative)
User responsibilities.11 Annex C (informative)
Password communication.12 Bibliography.13
1 Scope This document is designed to improve the authentication of individual users of health care IT systems, by strengthening the automatic software procedures associated with the management of user identifiers and passwords, without resorting to additional hardware facilities. This document applies to all information systems (hereafter called systems) within the health care environment that handle or store sensitive person identifiable health information, using passwords as the only means of authenticating the entered user identifier, i.e., verifying the claimed identity of a user. Systems that fall within the scope of this document include for example electronic patient record systems, patient administrative systems and laboratory systems, containing personal health information. This document does not apply to systems outside the health care environment. Neither does it apply to systems within the health care environment that use other means of identification and authentication, such as smart cards, biometric methods or other technical facilities. 2 Normative references
The following referenced documents are indispensable for the application of this document. For dated references, only the edition cited applies. For undated references, the latest edition of the referenced document (including any amendments) applies.
ISO 7498-2, Information processing systems – Open systems interconnection – Basic reference model – Part 2: Security architecture 3 Terms and definitions For the purposes of this document, the following terms and definitions apply. 3.1
access control prevention of unauthorised use of a resource, including the prevention of use of a resource in an unauthorised manner 3.2 authentication process of verifying a claimed user identity, in this document on the basis of an entered user identifier and password 3.3 authentication information information used to establish the validity of a claimed identity [ISO 7498-2] 3.4
authorised user person who is given access rights to the system, i.e., person who is given a unique user identifier and an initial password, and by this is given the right to log-on to the system, in order to perform the functions or access to the data the user is entitled to 3.5
default password initial password, provided by the system on installation, to enable initial use SIST EN 12251:2005
identification process that enables recognition of an authorised user described to the system, by the use of a unique user identifier 3.7 password confidential authentication information composed of a string of characters [ISO 7498-2] 3.8 security administration act of controlling and administering all relevant security issues in the system. It can be performed by one or more specially authorised users through the assignment of security relevant access rights NOTE These users are called security administrators. 3.9 site-specifiable
site-modifiable specifiable (or modifiable) by the local security administrators after purchase of the system 3.10 system combination of computer hardware and software, used in this document as the system as it is perceived by the user 3.11 user identifier information, composed of a string of characters, uniquely identifying an authorised user of the information system 4 Requirements 4.1 Unique identification and authentication The system shall use user identifiers to uniquely identify and authenticate users. 4.2 Identification and authentication prior to all other interactions Identification and authentication shall take place prior to all other interactions between the system and the user, apart from the system provided log-on message (see 4.5). Other interactions shall only be possible after successful identification and authentication, i.e., identification and authentication leading to system access, of an authorised user. 4.3 Associating unique identity with users The system shall provide a mechanism which allows site-defined attributes, e.g. name and affiliation, to be associated with each user identifier, for the purpose of uniquely identifying the person. 4.4 Maintaining the identity of active users The system shall maintain the identity of all users currently logged on. SIST EN 12251:2005
...
Questions, Comments and Discussion
Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.