Overview
ISO 17090-2:2015 - Health informatics - Public key infrastructure - Part 2: Certificate profile - defines certificate profiles and technical requirements for using digital certificates in healthcare. It specifies how X.509-based certificates (per IETF/RFC 5280) should be structured to support secure exchange of healthcare information within organizations, across organizations and across jurisdictional boundaries. The standard focuses on healthcare-specific issues to enable interoperability, privacy, authentication and data integrity for electronic health records and other clinical systems.
Key topics and technical requirements
- Certificate types: profiles for CA certificates (root and subordinate), cross/bridge certificates and multiple end-entity certificates (individual identity, organization identity, device identity, application, AC and role certificates) are defined.
- Common certificate fields: mandatory and optional fields for issuer, subject, validity, subject public key information and signature are specified to ensure consistency.
- Certificate extensions: usage and format requirements for standard X.509 extensions such as authorityKeyIdentifier, subjectKeyIdentifier, keyUsage, privateKeyUsagePeriod, certificatePolicies, subjectAltName, basicConstraints, CRLDistributionPoints, ExtKeyUsage, Authority Information Access and Subject Information Access.
- Healthcare-specific attributes: support for subject directory attributes (including an hcRole attribute) and qualified certificate statements to represent healthcare roles and qualifications.
- Compliance and interoperability: alignment with X.509/RFC 5280 profiles and guidance to enable cross-domain and cross-jurisdiction trust frameworks.
Practical applications and who uses it
ISO 17090-2 is intended for organizations and professionals implementing PKI for healthcare:
- Healthcare IT architects and CISOs designing secure messaging, EHR access, telehealth and HIE (health information exchange).
- Certificate Authorities (CAs) and Registration Authorities (RAs) issuing healthcare certificates that must interoperate across vendors and borders.
- EMR/EHR vendors, medical device manufacturers and application developers embedding certificate validation, encryption and digital signatures.
- National health authorities and regulators establishing trusted identity frameworks and cross-border interoperability for patient data.
Practical uses include secure clinical messaging, authentication of clinicians and devices, digitally signed clinical documents and encrypted exchange of patient records.
Related standards
- ISO 17090-1: Overview of digital certificate services (interoperability framework)
- ISO 17090-3: Policy management of certification authority
- ISO 17090-4: Digital signatures for healthcare documents
- IETF RFC 5280 and ITU-T X.509 (certificate and extension profiles)
ISO 17090-2 is a technical foundation for deploying healthcare PKI, helping organizations implement standardized, interoperable digital certificates for secure health information exchange.