Overview
ISO/TR 20055:2018 defines the concept of a person-owned repository (PoR) for health documents used by PHR applications and for health information exchange (HIE). The technical report surveys representative PoR technologies, implementation considerations, classification criteria and potential uses (clinical document exchange, personal health management, clinical research). It is an informative guidance document - not a normative specification - and explicitly does not prescribe document formats, exact communication protocols, or detailed security/privacy controls.
Key topics and technical considerations
- Definition and scope: A PoR is a health document repository owned, managed and controlled by the individual; it aggregates clinical, sensor and self-entered data for sharing under the owner’s control.
- Implementation considerations: Interoperability with EHR systems and provider repositories, trusted flows from provider-owned systems to PoRs, and support for flows back into provider systems.
- Storage types (classification):
- Off-line personal storage (USB, removable media)
- Network-connected personal devices (smartphones, tablets, PCs)
- Network-connected shared storage (cloud-based services)
- Document discovery mechanisms:
- Manual discovery (browsing/search)
- Registry/index based discovery (metadata queries across a network)
- Data reliability and authenticity: The report highlights risks when individuals control content and suggests measures such as PKI-based digital signatures to support trust in PoR-sourced data.
- Privacy/security considerations: Discussed at a high level (access control, authorization, potential de-identification for research) but normative security protocols are out of scope.
Practical applications
- Clinical document exchange: Patients can receive records from providers into their PoR and share them with other clinicians to bridge gaps where provider-centric HIE is not available.
- Personal health management (PHM): PoR data can feed PHM apps for monitoring vitals, medication management, alerts and between-visit care.
- Clinical research: Individuals can act as information providers (CRIPs) for studies, enabling consented sharing of de-identified or raw data.
- Use cases / stakeholders: PHR app developers, HIE architects, healthcare providers, health IT vendors, policymakers and researchers planning patient-centric data flows and interoperable PHR solutions.
Who should use this report
- Health informatics professionals designing patient-centred repositories
- PHR application and mobile health developers
- Architects of interoperability/HIE solutions evaluating patient-controlled data models
- Policy makers and program managers exploring alternatives to provider-centric HIE
Related standards and references
- Mentions HL7 CDA as a commonly used clinical document format (formats themselves are out of scope)
- Cross-references ISO health informatics work (ISO/TC 215) and related terminology standards (e.g., ISO 18308, ISO/TR 14292)
Keywords: ISO/TR 20055, person-owned repository, PoR, PHR applications, health information exchange, patient-controlled health data, personal health record, health informatics, interoperability, PHM.