General Information

Abstract

This document specifies requirements and recommendations for remote maintenance services (RMSs) of medical devices and medical information systems in healthcare facilities (HCFs). This document is applicable to HCFs and remote service centres (RSCs) providing remote maintenance services for medical devices and medical information systems. This document specifies the risk assessment necessary to protect remote maintenance activities, taking into consideration the special characteristics of the healthcare field such as patient safety, regulations and privacy protections. This document provides practical examples of risk analysis to protect both the HCF and RMS provider information assets in a safe and efficient (i.e. economical) manner. These assets are primarily the information system itself and personal health data held in the information system.

Status
Published
Publication Date
01-Sep-2026
Current Stage
6060 - International Standard published
Start Date
02-Sep-2026
Due Date
20-Nov-2026
Completion Date
02-Sep-2026

Buy Documents

Technical specification

ISO/TS 11633-1:2026 - Health informatics — Information security management for remote maintenance of medical devices and medical information systems — Part 1: Requirements and risk analysis

Release Date:02-Sep-2026
English language (19 pages)
sale 15% off
Preview
sale 15% off
Preview

Overview

ISO/TS 11633-1:2026, published by the International Organization for Standardization (ISO), addresses information security management requirements for remote maintenance services (RMSs) in the context of medical devices and medical information systems. This technical specification outlines essential requirements and provides guidance on risk analysis to ensure secure, safe, and efficient maintenance operations involving external vendors and service providers within healthcare facilities (HCFs).

As healthcare systems become increasingly networked, remote maintenance of connected devices and information systems is pivotal for reducing downtime and achieving operational efficiency. However, expanded connectivity also introduces new risks relating to confidentiality, integrity, and availability of sensitive patient data and the systems themselves. ISO/TS 11633-1:2026 provides a structured approach to identifying, assessing, and mitigating these risks while adhering to applicable privacy and regulatory requirements.

Key Topics

  • Requirements for Remote Maintenance: Specifies technical and organizational controls for maintaining medical devices and information systems remotely, emphasizing secure communication and robust user authentication.
  • Risk Assessment: Details methodologies for risk analysis, including threat identification, likelihood estimation, and impact assessment, following international standards such as ISO 31000 and ISO/IEC 27005.
  • Security Controls and Measures: Recommends a range of countermeasures for telephone and internet-based remote connections, including firewalls, anti-virus, VPNs, and multifactor authentication.
  • Information Asset Protection: Focuses on safeguarding not only systems but also personal health information (PHI) and other data assets throughout the maintenance lifecycle.
  • Roles and Responsibilities: Defines distinct obligations for healthcare facilities, remote service centres, and third parties, including contractual arrangements and operational compliance.
  • Privacy and Regulatory Considerations: Addresses national and regional obligations for personal health information protection, including requirements for contracts, incident reporting, and secure data handling.

Applications

ISO/TS 11633-1:2026 is relevant for:

  • Healthcare Facilities (HCFs): Hospitals, clinics, and other healthcare organizations utilizing medical devices and integrated information systems that require ongoing, often remote, maintenance.
  • Remote Service Centres (RSCs): Third-party vendors and service providers offering RMS to healthcare organizations, needing to align with healthcare regulations and security best practices.
  • Medical Device Manufacturers: Entities developing devices that are subject to remote updates, troubleshooting, or surveillance, requiring secure design and maintenance protocols.
  • Regulators and Auditors: Bodies overseeing healthcare security compliance, relying on standardized methods for risk assessment and management.

Practical use cases addressed by the standard include:

  • Troubleshooting and outage resolution: Securely connecting to devices for urgent repairs.
  • Scheduled maintenance and software updates: Periodic, risk-aware updates that ensure device functionality and compliance.
  • Performance monitoring: Ongoing, remote surveillance of device performance aligned with security expectations.

Implementing ISO/TS 11633-1:2026 helps healthcare organizations reduce maintenance costs, minimize downtime, and ensure the trust and safety of patient care through effective information security management.

Related Standards

  • ISO/TR 11633-2: Provides additional examples and detailed processes for applying risk assessment to RMS in healthcare.
  • ISO/IEC 27001: Sets out requirements for information security management systems (ISMS), forming the foundation for broader organizational security governance.
  • ISO/IEC 27002: Offers guidance on implementing specific information security controls.
  • ISO 31000: Describes risk management principles and guidelines, referenced for comprehensive risk analysis.
  • ISO/IEC 27005: Focuses on information security risk management, supporting risk assessment and treatment processes.

These related standards create a holistic framework for managing security, privacy, and operational risks in healthcare environments with remote-maintained medical devices and systems.


Keywords: ISO/TS 11633-1:2026, remote maintenance, medical devices, health informatics, information security, healthcare facilities, risk analysis, patient data protection, RMS security compliance.

Relations

Effective Date
02-Dec-2023

Buy Documents

Technical specification

ISO/TS 11633-1:2026 - Health informatics — Information security management for remote maintenance of medical devices and medical information systems — Part 1: Requirements and risk analysis

Release Date:02-Sep-2026
English language (19 pages)
sale 15% off
Preview
sale 15% off
Preview

Get Certified

Connect with accredited certification bodies for this standard

BSI Group

BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

UKAS United Kingdom Verified

NYCE

Mexican standards and certification body.

EMA Mexico Verified

Sponsored listings

Frequently Asked Questions

ISO/TS 11633-1:2026 is a technical specification published by the International Organization for Standardization (ISO). Its full title is "Health informatics — Information security management for remote maintenance of medical devices and medical information systems — Part 1: Requirements and risk analysis". This standard covers: This document specifies requirements and recommendations for remote maintenance services (RMSs) of medical devices and medical information systems in healthcare facilities (HCFs). This document is applicable to HCFs and remote service centres (RSCs) providing remote maintenance services for medical devices and medical information systems. This document specifies the risk assessment necessary to protect remote maintenance activities, taking into consideration the special characteristics of the healthcare field such as patient safety, regulations and privacy protections. This document provides practical examples of risk analysis to protect both the HCF and RMS provider information assets in a safe and efficient (i.e. economical) manner. These assets are primarily the information system itself and personal health data held in the information system.

This document specifies requirements and recommendations for remote maintenance services (RMSs) of medical devices and medical information systems in healthcare facilities (HCFs). This document is applicable to HCFs and remote service centres (RSCs) providing remote maintenance services for medical devices and medical information systems. This document specifies the risk assessment necessary to protect remote maintenance activities, taking into consideration the special characteristics of the healthcare field such as patient safety, regulations and privacy protections. This document provides practical examples of risk analysis to protect both the HCF and RMS provider information assets in a safe and efficient (i.e. economical) manner. These assets are primarily the information system itself and personal health data held in the information system.

ISO/TS 11633-1:2026 is classified under the following ICS (International Classification for Standards) categories: 35.240.80 - IT applications in health care technology. The ICS classification helps identify the subject area and facilitates finding related standards.

ISO/TS 11633-1:2026 has the following relationships with other standards: It is inter standard links to ISO/TS 11633-1:2019. Understanding these relationships helps ensure you are using the most current and applicable version of the standard.

ISO/TS 11633-1:2026 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


Technical
Specification
ISO/TS 11633-1
Second edition
Health informatics — Information
2026-09
security management for remote
maintenance of medical devices and
medical information systems —
Part 1:
Requirements and risk analysis
Informatique de santé — Management de la sécurité de
l'information pour la maintenance à distance des dispositifs
médicaux et des systèmes d'information médicale —
Partie 1: Exigences et analyse du risque
Reference number
© ISO 2026
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms, definitions and abbreviated terms . 1
3.1 Terms and definitions .1
3.2 Abbreviated terms .3
4 Contents of RMS of medical devices and medical information systems . 3
4.1 Assumed RMS architecture .3
4.2 RMS using one to one communication on telephone network .4
4.2.1 One to one communication on telephone network features.4
4.2.2 Security features for one to one communication on telephone network .4
4.3 RMS using the Internet connections .5
4.3.1 Internet connections features .5
4.3.2 Security features for internet connections.5
5 Security requirement and risk analysis of RMS of medical devices and medical
information systems . 5
5.1 Risk analysis .5
5.2 Security measures in RMS operation .6
5.3 Contracts involving HCF, RSC, and necessary third parties .6
5.4 Protection of personal information .6
5.5 Management measures .7
Annex A (informative) Use cases of RMSs . 8
Annex B (informative) Examples of threats by assets of remote maintenance services .13
Annex C (informative) Example of how to conduct risk analysis .18
Bibliography . 19

iii
Foreword
ISO (the International Organization for Standardization) is a worldwide federation of national standards
bodies (ISO member bodies). The work of preparing International Standards is normally carried out through
ISO technical committees. Each member body interested in a subject for which a technical committee
has been established has the right to be represented on that committee. International organizations,
governmental and non-governmental, in liaison with ISO, also take part in the work. ISO collaborates closely
with the International Electrotechnical Commission (IEC) on all matters of electrotechnical standardization.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of ISO documents should be noted. This document was drafted in accordance with the editorial rules of the
ISO/IEC Directives, Part 2 (see www.iso.org/directives).
ISO draws attention to the possibility that the implementation of this document may involve the use of (a)
patent(s). ISO takes no position concerning the evidence, validity or applicability of any claimed patent
rights in respect thereof. As of the date of publication of this document, ISO had not received notice of (a)
patent(s) which may be required to implement this document. However, implementers are cautioned that
this may not represent the latest information, which may be obtained from the patent database available at
www.iso.org/patents. ISO shall not be held responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO’s adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT), see www.iso.org/iso/foreword.html.
This document was prepared by Technical Committee ISO/TC 215, Health informatics.
This second edition cancels and replaces the first edition (ISO/TS 11633-1:2019), which has been technically
revised.
The main changes are as follows:
— complete revision to correspond to the latest editions of ISO/IEC 27001 and ISO/IEC 27002;
— revision of the clause structure;
— update of Clause 3 and the Bibliography.
A list of all parts in the ISO 11633 series can be found on the ISO website.
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www.iso.org/members.html.

iv
Introduction
Advancement of information and communications technology (ICT) has changed how networks are
used in society. Similarly, in healthcare, information systems which were once closed in each healthcare
facility (HCF) are now connected to the outside by networks and are progressing to the point of being
able to facilitate sharing and exchange of health information accumulated in these information systems.
Such information and communication networks are spreading not only in between HCFs but also between
HCFs and vendors of medical devices and healthcare information systems. Maintenance of such systems
is paramount to keeping them up-to-date. By practicing remote maintenance services (RMS), it becomes
possible to reduce down-time and lower costs for this maintenance activity.
While there are benefits to remote maintenance, such remote connections with external organizations also
expose HCFs and vendors to risks regarding confidentiality, integrity and availability of information and
systems, risks which previously received scant consideration.
Although normal remote maintenance is generally done on a contract basis, in the case of medical devices,
risk assessment is commonly a legal prerequisite. Therefore, it is necessary to implement appropriate risk
assessment where remote maintenance is provided in any healthcare context. The risk assessment examples
provided in ISO/TR 11633-2 provide support for HCFs and RMS providers to implement risk assessment
effectively.
By implementing the risk assessment process and employing controls referencing ISO/TR 11633-2, HCFs
owners and RMS providers will be able to obtain the following benefits:
— Risk assessment can result in improved efficiency. If the risk assessment document created through the
use of ISO/TR 11633-2 does not fully conform to ISO/IEC 27001, it can be used in part in a risk assessment
of an incompatible area, thus reducing the risk assessment effort required.
— Documented validity of the RMS security countermeasures in place will be available to third parties.
If providing RMS to two or more sites, the provider can apply countermeasures consistently and effectively.

v
Technical Specification ISO/TS 11633-1:2026(en)
Health informatics — Information security management
for remote maintenance of medical devices and medical
information systems —
Part 1:
Requirements and risk analysis
1 Scope
This document specifies requirements and recommendations for remote maintenance services (RMSs) of
medical devices and medical information systems in healthcare facilities (HCFs). This document is applicable
to HCFs and remote service centres (RSCs) providing remote maintenance services for medical devices and
medical information systems.
This document specifies the risk assessment necessary to protect remote maintenance activities, taking
into consideration the special characteristics of the healthcare field such as patient safety, regulations and
privacy protections.
This document provides practical examples of risk analysis to protect both the HCF and RMS provider
information assets in a safe and efficient (i.e. economical) manner. These assets are primarily the information
system itself and personal health data held in the information system.
2 Normative references
There are no normative references in this document.
3 Terms, definitions and abbreviated terms
For the purposes of this document, the following terms and definitions apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https:// www .iso .org/ obp
— IEC Electropedia: available at https:// www .electropedia .org/
3.1 Terms and definitions
3.1.1
asset
anything that has value to the organization
Note 1 to entry: In the context of health information security (3.1.4), information assets include:
a) health information;
b) technical information (credentials, passwords, calibration data, etc.);
c) non-health information (e.g. financials, administrative, legal, human resources);
d) IT services;
e) hardware;
f) software;
g) communications facilities;
h) media;
i) IT facilities;
j) medical devices that record or report data.
[SOURCE: ISO/IEC 21827:2008, 3.4, modified — Note 1 to entry was added.]
3.1.2
availability
property of being accessible and usable upon demand by an authorized entity
[SOURCE: ISO/IEC 27000:2018, 3.7]
3.1.3
confidentiality
property that information is not made available or disclosed to unauthorized individuals, entities, or
processes
[SOURCE: ISO/IEC 21827:2008, 3.13]
3.1.4
information security
preservation of confidentiality (3.1.3), integrity and availability (3.1.2) of information
Note 1 to entry: In addition, other properties, such as authenticity, accountability, non-repudiation, and reliability can
also be involved.
Note 2 to entry: Other properties, particularly accountability of users, but also authenticity, non-repudiation, and
reliability are often mentioned as aspects of information security but could be considered as derived from the three
core properties in the definition.
[SOURCE: ISO/IEC 27000:2018, 3.28, modified — Note 2 to entry was added.]
3.1.5
risk
effect of uncertainty on objectives
Note 1 to entry: An effect is a deviation from the expected. It can be positive, negative or both, and can address, create
or result in opportunities and threats (3.1.8).
Note 2 to entry: Objectives can have different aspects and categories, and can be applied at different levels.
Note 3 to entry: Risk is usually expressed in terms of risk sources, potential events, their consequences and their
likelihood.
[SOURCE: ISO 31000:2018, 3.1]
3.1.6
risk analysis
process to comprehend the nature of risk (3.1.5) and to determine the level of risk
Note 1 to entry: Risk analysis provides the basis for risk evaluation and decisions about risk treatment.
Note 2 to entry: Risk analysis includes risk estimation.
[SOURCE: ISO 31073:2022, 3.3.15, modified — Note 2 to entry was added.]

3.1.7
risk assessment
overall process of risk identification, risk analysis (3.1.6), and risk evaluation
[SOURCE: ISO 13131:2021, 3.4.13, modified — Note 1 to entry was removed.]
3.1.8
threat
potential cause of an unwanted incident, which can result in harm to a system or organization
3.2 Abbreviated terms
HCF healthcare facility
ISMS information security management system
ISP internet service provider
NTP network time protocol
PHI protected health information
PSTN public switched telephone network
RSC remote service centre
RMS remote maintenance service
VPN virtual private network
4 Contents of RMS of medical devices and medical information systems
4.1 Assumed RMS architecture
The following architectural configuration is assumed in this document (Figure 1):
— target device;
— internal network within a HCF;
— external network connecting a HCF and RSC;
— internal network within a RSC;
— equipment and services in the RSC.

Figure 1 — Assumed RMS architecture
This document introduces potential types of RMSs and provides options for appropriate security controls to
be considered during the risk analysis phase.
Use cases of RMSs are provided in Annex A.
The types of RMS and technical security measures related to each type are specified in 4.2 and 4.3.
4.2 RMS using one to one communication on telephone network
4.2.1 One to one communication on telephone network features
In the past, dial-up server functions typically used public switched telephone network (PSTN) with a modem.
More recently, cellular networks such as 3G, 4G, and 5G have become more commonly utilized.
Telephone network and telecommunication lines have the following features:
— one to one communication pathway between a HCF and the RSC which can be secured;
— tapping of the communication line is difficult because a PSTN is fully digitalized.
4.2.2 Security features for one to one communication on telephone network
The following security features should be applied as appropriate:
— use of caller number identification and call back function;
— user verification such as one-time password;
— review and audits of communication logs to identify illegal access.

4.3 RMS using the Internet connections
4.3.1 Internet connections features
Internet connections have the following features:
— worldwide accessibility: enabling access to devices worldwide, transcending national and regional
boundaries;
— multimedia: supporting a variety of formats, including text, images, audio, and video;
— economical: enabling the transmission of large volumes of information at low cost compared to traditional
communication methods.
4.3.2 Security features for internet connections
The following security features should be used as appropriate:
— use of suitable firewall;
— deployment of anti-virus software;
— use of virtual private network (VPN) for encryption of communication path;
— application of user authentication methods such as one-time passwords, multi-factor authentication and
digital certificates
The use of the latest technologies for RMS, such as cloud services, should require the implementation of
additional security controls.
5 Security requirement and risk analysis of RMS of medical devices and medical
information systems
5.1 Risk analysis
A typical risk assessment involves the following:
— identifying threats to information assets;
— estimating likelihood and frequency;
— assessing impact if threats occur.
Risk analysis should follow ISO 31000 and ISO/IEC 27005 methodology.
In addition to the above, because RMS is an operation that spans two different organizations, HCF and RSC,
risk analysis shall also be conducted by both parties and the results shall be agreed upon.
This document models typical use cases assumed for RMSs in Annex A and provides an example risk
assessment for the model. Using the results of this risk assessment makes it possible to perform risk analysis
using a baseline approach or a combination approach.
Examples of threats by assets of RMSs are provided in Annex B and an example of how to conduct risk
analysis in Annex C.
Examples of risk analysis are shown in ISO/TR 11633-2.

5.2 Security measures in RMS operation
When setting up RMS operations, the following points shall be considered:
— identification and security issues regarding data accessible by the RSC operator;
— implementation of controls to prevent unauthorised access to the system and data;
— protection of communication routes;
— security management for RSC devices;
— identification and use of third parties in the service provision by RMS;
— monitoring unauthorized access and operations through logs and audit trails, and regular audits;
— ensuring secure time synchroniza
...