Abstract

This document provides telehealth cybersecurity controls of the overall security framework for systems and services applied to telehealth, specifically addressing cybersecurity controls uniquely applicable to telehealth, while general elements relevant to health delivery organizations (HDOs) can be referenced from ISO 27799. It also includes Annex A, which, for informative purposes, provides a mapping of the controls in 4.2 to 4.5 of this document to the security controls in ISO 27799:2025.

Status
Published
Publication Date
08-Oct-2026
Current Stage
6060 - International Standard published
Start Date
09-Oct-2026
Completion Date
09-Oct-2026

Buy Documents

Technical specification

ISO/TS 6268-3:2026 - Health informatics — Cybersecurity framework for telehealth environments — Part 3: Cybersecurity controls of telehealth

Release Date:09-Oct-2026
English language (21 pages)
sale 15% off
Preview
sale 15% off
Preview

ISO/TS 6268-3:2026 is an ISO Technical Specification in the Health informatics series. It sets cybersecurity controls for systems and services used in telehealth, focusing on controls that are specific to telehealth while pointing general health delivery organization (HDO) elements to ISO 27799. The document is written for organizations and service participants who design, operate, support, manage or use telehealth services across remote, shared and cross-jurisdiction environments.

What does ISO/TS 6268-3:2026 specify?

ISO/TS 6268-3:2026 specifies telehealth cybersecurity controls as part of the overall security framework for telehealth systems and services. It concentrates on the telehealth-specific controls in Clause 4 and leaves broader HDO-wide security matters to ISO 27799-based practices.

Clause 4 is organized into four control groups:

  • Organizational controls
  • People controls
  • Physical controls
  • Technological controls

Annex A is informative and maps the controls in 4.2 to 4.5 to the security controls in ISO 27799:2025.

AnnexWhat it covers
Annex AInformative alignment of telehealth cybersecurity controls with ISO 27799:2025

What are the key requirements of ISO/TS 6268-3:2026?

Clause 4 frames telehealth security around the realities of remote care: different environments, shared devices, cross-border delivery, and limited physical control. In practice, the standard asks organizations to align participants, protect data and devices, prepare for incidents, and make identity and access decisions traceable.

Organizational controls

  • Cybersecurity alignment and gap management (4.2.1) - Telehealth service participants should identify cybersecurity gaps among participants and manage them with coordinated policies and compensating controls. This matters when a service links organizations with different security maturity, because the weakest environment can affect the whole service.
  • Contact with authorities and support systems (4.2.2) - Participants should maintain contact details and escalation paths for authorities and technical support across jurisdictions and languages. This supports rapid reporting and coordinated incident response when telehealth spans regions or organizations.
  • Asset identification and management, and cybersecurity level alignment (4.2.3, 4.2.4) - Participants should inventory connected systems, devices, services and interfaces, then ensure shared information and services keep an appropriate cybersecurity level. In practice, this means knowing what connects to telehealth and setting minimum controls for externally connected assets.
  • Secure exchange of telehealth information and shared identity management (4.2.5, 4.2.6) - Approved communication platforms should be used for telehealth-related communications, and access rights should be managed when caregivers, family members or other persons act on behalf of the subject of care. This is the basis for protecting privacy while keeping delegated access accountable.
  • Incident planning, legal differences, record protection and operating procedures (4.2.7 to 4.2.10) - The standard calls for incident planning that reflects different environments and legal requirements, protection of records across jurisdictions, and documented operating procedures that are available to relevant participants. In practice, organizations need documented fallback actions, record handling rules and user-facing guidance.
  • Unique identification and authentication (4.2.11) - Subjects of care, their devices and software applications should be uniquely identified and authenticated when interacting with telehealth participants. This reduces misattribution and helps trace data back to its source.

People controls

  • Identification of participating persons (4.3.1) - Persons participating in telehealth services should be identified, authenticated and approved. This is important where the provider cannot directly see everyone present in the remote environment.
  • Awareness, education and training, and social engineering (4.3.2, 4.3.3) - Participants should receive suitable cybersecurity awareness and training, and telehealth-specific countermeasures should address social engineering. In practice, people need to know how to avoid unsafe networks, untrusted apps, unauthorized observation and deceptive requests.

Physical controls

  • Physical security perimeters and private non-clinical spaces (4.4.1, 4.4.2) - Telehealth service areas should be protected, including home or other non-clinical environments where privacy and physical control may be limited. This means reducing the risk of being overheard, observed or interrupted during care.
  • Real-time services and equipment management (4.4.3, 4.4.4) - Critical real-time telehealth services should be protected from physical and environmental threats, and devices used outside controlled healthcare environments should be protected against loss, theft, tampering and misuse. This is especially relevant for remote monitoring and other services that must keep working during disruption.

Technological controls

  • Personally-managed telehealth devices and authorized patient assistants (4.5.1, 4.5.2) - Information on personally managed devices should be protected, and caregivers or family members accessing systems on behalf of a patient should be properly authorized and linked to that patient. In practice, this means securing personal devices and controlling delegated access.
  • Home monitoring devices and configuration for critical telehealth services (4.5.3, 4.5.4) - Shared home monitoring data needs validation and attribution measures, and critical telehealth configurations should be protected from unauthorized or unsafe changes. This matters when data comes from shared household devices or when configurations can affect patient safety.

What terms does ISO/TS 6268-3:2026 define?

  • Cybersecurity gap - A difference in cybersecurity maturity among telehealth participants that can be exploited if not managed.
  • Cybersecurity alignment - A coordinated state where participants’ policies, processes, controls and practices support safe and secure telehealth services.
  • Telehealth service participant - Any entity involved in providing, operating, supporting, managing or using a telehealth service, including people, devices and systems.
  • Health delivery organization (HDO) - The organization context used for broader health service security controls beyond telehealth-specific measures.
  • Information and communications technology (ICT) - The technology used to support telehealth services, including network-based and digital applications.
  • Role-based access control (RBAC) - An access control approach that limits configuration or other privileges to authorized roles.

Who uses ISO/TS 6268-3:2026?

ISO/TS 6268-3:2026 is used by telehealth service providers, telehealth platform providers, HDOs, clinicians, patients, caregivers and technical support teams. It is also relevant to security, privacy, risk, legal and compliance teams that need to set rules for identity, access, communications, records, incident response and device protection.

The document is especially useful where telehealth involves:

  • home monitoring
  • remote consultations
  • patient-owned or personally managed devices
  • shared care settings
  • cross-organization or cross-border delivery
  • services that need clear identity, accountability and fallback procedures

Which standards are used with ISO/TS 6268-3:2026?

ISO/TS 6268-3:2026 cites ISO/TS 6268-1 and ISO/TS 6268-2 as the companion parts for the telehealth cybersecurity framework.

  • ISO/TS 6268-1 - Provides the overview and concepts for the telehealth cybersecurity framework.
  • ISO/TS 6268-2 - Provides the cybersecurity reference model of telehealth.
  • ISO 27799:2025 - Supplies the health-information security control baseline that Clause 4 builds on and that Annex A maps to.

What does the ISO/TS 6268-3:2026 document contain?

ISO/TS 6268-3:2026 contains a Clause 4 control structure with control, purpose and guidance text for organizational, people, physical and technological telehealth cybersecurity measures. It covers policies, inventories, secure communications, identity and authentication, incident preparation, legal and contractual differences, record protection, operating procedures and device protection.

Annex A provides a mapping table between the telehealth controls in 4.2 to 4.5 and ISO 27799:2025 security controls. The bibliography points readers to related health informatics, cybersecurity, medical device security and telehealth references for implementation, risk management and supporting practices.

Buy Documents

Technical specification

ISO/TS 6268-3:2026 - Health informatics — Cybersecurity framework for telehealth environments — Part 3: Cybersecurity controls of telehealth

Release Date:09-Oct-2026
English language (21 pages)
sale 15% off
Preview
sale 15% off
Preview

Get Certified

Connect with accredited certification bodies for this standard

BSI Group

BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

UKAS United Kingdom Verified

NYCE

Mexican standards and certification body.

EMA Mexico Verified

Sponsored listings

Frequently Asked Questions

ISO/TS 6268-3:2026 is a technical specification published by the International Organization for Standardization (ISO). Its full title is "Health informatics — Cybersecurity framework for telehealth environments — Part 3: Cybersecurity controls of telehealth". This standard covers: This document provides telehealth cybersecurity controls of the overall security framework for systems and services applied to telehealth, specifically addressing cybersecurity controls uniquely applicable to telehealth, while general elements relevant to health delivery organizations (HDOs) can be referenced from ISO 27799. It also includes Annex A, which, for informative purposes, provides a mapping of the controls in 4.2 to 4.5 of this document to the security controls in ISO 27799:2025.

This document provides telehealth cybersecurity controls of the overall security framework for systems and services applied to telehealth, specifically addressing cybersecurity controls uniquely applicable to telehealth, while general elements relevant to health delivery organizations (HDOs) can be referenced from ISO 27799. It also includes Annex A, which, for informative purposes, provides a mapping of the controls in 4.2 to 4.5 of this document to the security controls in ISO 27799:2025.

ISO/TS 6268-3:2026 is classified under the following ICS (International Classification for Standards) categories: 35.240.80 - IT applications in health care technology. The ICS classification helps identify the subject area and facilitates finding related standards.

ISO/TS 6268-3:2026 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


Technical
Specification
ISO/TS 6268-3
First edition
Health informatics — Cybersecurity
2026-10
framework for telehealth
environments —
Part 3:
Cybersecurity controls of telehealth
Informatique de santé — Cadre en matière de cybersécurité pour
les environnements de télésanté —
Partie 3: Contrôles de cybersécurité en télésanté
Reference number
© ISO 2026
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms, definitions and abbreviated terms . 1
3.1 Terms and definitions .1
3.2 Abbreviated terms .2
4 Cybersecurity controls for telehealth services . 2
4.1 General .2
4.2 Organizational controls .3
4.2.1 Cybersecurity alignment and gap management .3
4.2.2 Contact with authorities and support systems .3
4.2.3 Asset identification and management .4
4.2.4 Cybersecurity level alignment .5
4.2.5 Secure exchange of telehealth information .5
4.2.6 Shared identity management .6
4.2.7 Telehealth incident management planning and preparation .7
4.2.8 Differences in legal, statutory, regulatory and contractual requirements .7
4.2.9 Protection of records .8
4.2.10 Documented operating procedures.8
4.2.11 Unique identification and authentication .9
4.3 People controls .10
4.3.1 Identification of participating persons .10
4.3.2 Awareness, education and training for persons participating in telehealth
services .10
4.3.3 Social engineering .11
4.4 Physical controls . 12
4.4.1 Physical security perimeters. 12
4.4.2 Telehealth services in private non-clinical spaces . 13
4.4.3 Protecting real-time services against physical and environmental threats . 13
4.4.4 Telehealth equipment management .14
4.5 Technological controls . 15
4.5.1 Personally-managed telehealth devices . 15
4.5.2 Authentication of authorized patient assistants . 15
4.5.3 Home monitoring devices in telehealth environments .16
4.5.4 Configuration for critical telehealth services.17
Annex A (informative) Alignment of telehealth cybersecurity controls with ISO 27799:2025 .18
Bibliography .20

iii
Foreword
ISO (the International Organization for Standardization) is a worldwide federation of national standards
bodies (ISO member bodies). The work of preparing International Standards is normally carried out through
ISO technical committees. Each member body interested in a subject for which a technical committee
has been established has the right to be represented on that committee. International organizations,
governmental and non-governmental, in liaison with ISO, also take part in the work. ISO collaborates closely
with the International Electrotechnical Commission (IEC) on all matters of electrotechnical standardization.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of ISO documents should be noted. This document was drafted in accordance with the editorial rules of the
ISO/IEC Directives, Part 2 (see www.iso.org/directives).
ISO draws attention to the possibility that the implementation of this document may involve the use of (a)
patent(s). ISO takes no position concerning the evidence, validity or applicability of any claimed patent
rights in respect thereof. As of the date of publication of this document, ISO had not received notice of (a)
patent(s) which may be required to implement this document. However, implementers are cautioned that
this may not represent the latest information, which may be obtained from the patent database available at
www.iso.org/patents. ISO shall not be held responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO’s adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT), see www.iso.org/iso/foreword.html.
This document was prepared by Technical Committee ISO/TC 215, Health informatics.
A list of all parts in the ISO 6268 series can be found on the ISO website.
Any feedback or questions on this document should be directed to the user’s national standards body. A
complete listing of these bodies can be found at www.iso.org/members.html.

iv
Introduction
Telehealth once provided a limited range of services to subjects of care in specific environments. However,
the scope of telehealth services is rapidly expanding through advanced information and communication
technologies (ICT) such as mobile-based, cloud-based and other network-based applications. Additionally,
emerging global pandemics have acutely increased the need to diagnose, prevent, monitor, treat or mitigate
diseases and injuries without face-to-face, in-person contact between subjects of care and care providers,
making telehealth a more commonly-accepted medical practice.
These services are described as telehealth services because they use ICT services to support healthcare
activities. Telehealth services include, but are not limited to, telemedicine, telecare, mHealth (healthcare
supported by mobile devices), remote use of medical applications, tele-monitoring, tele-diagnostics and
virtual care. Examples of health services include, but are not limited to, tele-pathology, tele-dermatology,
tele-cardiology, tele-rehabilitation, tele-oncology and tele-orthopaedics. Healthcare activities that directly
or indirectly support care recipients include, but are not limited to, teleconsultation, telephone advice, health
alarm systems and health status monitoring at home. Telehealth services can support immediate healthcare
activities using synchronous communications services such as a telephone or video conversation, or delayed
health care activities using asynchronous communications services such as messaging services.
Furthermore, depending on the perspective from which telehealth is viewed, the subcategories of telehealth
can vary. Physicians are familiar with the division of telehealth into medical departments. Medical IT
experts will look at telehealth according to system topology and network. When it comes to telehealth in
cybersecurity, telehealth actors, interactions between each actor, data flow, service environment and
technology should be considered. Therefore, establishing concept and models of telehealth cybersecurity
would be the first step to build a framework for cybersecurity in telehealth environment.
Telehealth cybersecurity concepts and models serve as a baseline for the analysis of cybersecurity threats
and to determine countermeasures. Telehealth cybersecurity countermeasures need to consider not only
technical aspects, but also management and physical approaches to operating telehealth services. This is
because telehealth cybersecurity involves interactions between multiple actors situated in environments
with different levels of cybersecurity. The cybersecurity policies and processes act as variables that
influence the overall cybersecurity posture of telehealth.
People-related and physical security controls require particular consideration in telehealth cybersecurity
because telehealth service participants can operate in physically separate and uncontrolled environments.
Unlike conventional healthcare environments, telehealth service participants can have limited ability to
directly observe, verify, intervene in, or physically respond to situations occurring in remote environments.
Ensuring that telehealth services achieve levels of safety, security and reliability comparable to conventional
healthcare services can require additional operational, organizational, physical and cybersecurity controls.
Telehealth service participants should consider risks arising from limited visibility and limited physical
control over remote environments, including situations occurring outside the camera view or beyond the
direct awareness of telehealth service participants. Physical intrusion, theft, vandalism, unauthorized
observation, device disconnection, impersonation, deception or tampering can present significant risks in
telehealth environments and should be addressed through appropriate countermeasures.
The cybersecurity framework for telehealth environment is structured as follows:
— Part 1: Overview and concepts;
— Part 2: Cybersecurity reference models of telehealth;
— Part 3: Cybersecurity controls of telehealth.
This document provides telehealth cybersecurity controls of the overall security framework for systems
and services applied to telehealth.

v
Technical Specification ISO/TS 6268-3:2026(en)
Health informatics — Cybersecurity framework for telehealth
environments —
Part 3:
Cybersecurity controls of telehealth
1 Scope
This document provides telehealth cybersecurity controls of the overall security framework for systems
and services applied to telehealth, specifically addressing cybersecurity controls uniquely applicable to
telehealth, while general elements relevant to health delivery organizations (HDOs) can be referenced from
ISO 27799.
It also includes Annex A, which, for informative purposes, provides a mapping of the controls in 4.2 to 4.5 of
1)
this document to the security controls in ISO 27799:2025 .
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content constitutes
requirements of this document. For dated references, only the edition cited applies. For undated references,
the latest edition of the referenced document (including any amendments) applies.
ISO/TS 6268-1, Health informatics — Cybersecurity framework for telehealth environments — Part 1: Overview
and concepts
ISO/TS 6268-2, Health informatics — Cybersecurity framework for telehealth environments — Part 2:
Cybersecurity reference model of telehealth
3 Terms, definitions and abbreviated terms
3.1 Terms and definitions
For the purposes of this document, the terms and definitions given in ISO/TS 6268-1, ISO/TS 6268-2 and the
following apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https:// www .iso .org/ obp
— IEC Electropedia: available at http:// www .electropedia .org/
3.1.1
cybersecurity gap
disparity in cybersecurity maturity levels among participants in telehealth services
Note 1 to entry: Cybersecurity gaps enable attackers to exploit vulnerabilities and compromise organizations
with robust security policies and processes, for example, attackers targeting a hospital with an advanced security
management framework can first breach a less secure clinic connected to the hospital’s network through telehealth
services. Therefore, compensating for the cybersecurity gap among telehealth service participants is critical to
ensuring the safety and security of telehealth services.

3.1.2
cybersecurity alignment
state in which cybersecurity policies, processes, controls and practices among telehealth service participants
are coordinated to ensure safe and secure telehealth services
Note 1 to entry: Coordinated alignment addresses and compensates for the cybersecurity gaps resulting from differing
organizational sizes, technical capabilities and regulatory frameworks of the participants.
3.1.3
telehealth service participant
entity that participates in the provision, operation, support, management or use of a telehealth service
Note 1 to entry: A telehealth service participant can include a healthcare provider, patient, caregiver, telehealth
application, device or supporting system involved in the telehealth service.
3.2 Abbreviated terms
ABAC attribute based access control
ATNA audit trail and node authentication
CCTV closed circuit television
CIA confidentiality, integrity and availability
FHIR fast healthcare interoperability resource
HDO health delivery organization
ICT information and communications technology
IHE integrating the healthcare enterprise
RBAC role based access control
XUA cross enterprise user assertion
4 Cybersecurity controls for telehealth services
4.1 General
Cybersecurity controls for secure telehealth services are categorized into organizational, people, physical
and technological controls based on ISO 27799, including cybersecurity control, purpose and guidance.
Telehealth services are often operated as part of the entire healthcare service of a HDO; in this cases,
telehealth cybersecurity controls are derived from and managed under the HDO-wide cybersecurity control
framework. Even in the case of telehealth centres, cybersecurity controls of general HDOs are tailored based
on ISO 27799 first, and then the additional specialized controls for telehealth services are considered.
Clause 4 in this document defines telehealth-specific cybersecurity controls reflecting telehealth contexts
from an operational perspective. Cybersecurity controls not addressed in this clause are subject to the
general policies and processes of the organizations involved in the telehealth service. 4.2 to 4.5 provide
categorized telehealth cybersecurity controls into organizational, people, physical and technological
aspects.
4.2 Organizational controls
4.2.1 Cybersecurity alignment and gap management
4.2.1.1 General
The controls for cybersecurity aspects are found in ISO 27799:2025, 5.1 and 6.7. 4.2.1.2 to 4.2.1.4 in this
document provide additional telehealth considerations beyond the controls listed in ISO 27799.
4.2.1.2 Control
Telehealth service participants should establish and manage policies and processes to identify, assess and
manage cybersecurity gaps among participants and to align cybersecurity requirements and practices
across participating organizations in order to maintain safe and secure telehealth services.
4.2.1.3 Purpose
To maintain end-to-end cybersecurity for telehealth services across telehealth service participants
operating in disparate cybersecurity environments.
4.2.1.4 Guidance
Telehealth service policies and processes should consider differences in cybersecurity capabilities, policies,
processes, technologies and operating environments among telehealth service participants that could affect
the cybersecurity capability of telehealth services.
To establish and manage effective policies and processes for cybersecurity alignment and gap management,
telehealth service participants should:
a) identify all telehealth service participants, including telehealth service provider, telehealth platform
provider, telehealth service recipients, etc.;
b) identify cybersecurity gaps among telehealth service participants that can directly affect telehealth
services;
c) assess cybersecurity risks arising from the identified gaps of telehealth service participants;
d) identify and implement cybersecurity controls to compensate for these gaps and to maintain the
cybersecurity capability of telehealth services.
Jurisdiction-specific or local regulations should be evaluated, as telehealth platforms frequently interconnect
systems across different regulatory boundaries.
Telehealth service participants should implement proactive countermeasures to mitigate risks associated
with connecting to participants operating in environments with lower cybersecurity capabilities. To
ensure safe and secure telehealth services, telehealth service participants should consider implementing
cybersecurity controls and protections aligned with the highest cybersecurity requirements among
participating entities.
4.2.2 Contact with authorities and support systems
4.2.2.1 General
The controls for cybersecurity aspects are found in ISO 27799:2025, 5.5, 5.6 and 6.7. 4.2.2.2 to 4.2.2.4 in this
document provide additional telehealth considerations beyond the controls listed in ISO 27799:2025.

4.2.2.2 Control
Telehealth service participants should establish, maintain and make available contact information for
relevant authorities and technical support personnel to support coordination and incident response among
telehealth service participants operating across different jurisdictions, geographical regions, organizational
environments and linguistic environments.
4.2.2.3 Purpose
To ensure compliance with applicable legal and regulatory requirements, and to enable coordinated and
prompt responses to cybersecurity incidents among telehealth service participants operating across
different jurisdictions and environments.
4.2.2.4 Guidance
Telehealth service participants should establish contact arrangements to support reporting, notification,
coordination and support requests among telehealth service participants operating in different jurisdictions,
geographical regions, organizational environments or linguistic environments.
Contact information for relevant authorities, technical support personnel and other parties responsible for
incident response or operational support, together with procedures for obtaining assistance and escalating
issues, should be maintained and made available to relevant telehealth service participants.
Emergency contact arrangements should be established for situations where cybersecurity incidents,
service disruptions or service failures can pose an immediate risk to the health or safety of the subject of
care.
4.2.3 Asset identification and management
4.2.3.1 General
The controls for cybersecurity aspects are found in ISO 27799:2025, 5.9, 5.10, 5.11 and 6.7. 4.2.3.2 to 4.2.3.4
in this document provide additional telehealth considerations beyond the controls listed in ISO 27799.
4.2.3.2 Control
Telehealth service participants should identify, maintain and manage inventories of systems, services,
devices and connections accessible to or connected by external telehealth service participants, and conduct
risk management for such access and connectivity.
4.2.3.3 Purpose
To identify and manage cybersecurity risks associated with external access to organizational systems,
services, information and other assets, and to implement appropriate cybersecurity controls for telehealth
services.
4.2.3.4 Guidance
Telehealth service participants should develop and maintain inventories of systems, services, devices
and connections accessible to or connected by external telehealth service participants, and conduct risk
assessments for associated telehealth operations. Special attention should be given to identifying and
managing systems, services, devices, connections, interfaces and data flows operated in environments with
lower cybersecurity capabilities.
Telehealth service participants should consider maintaining inventories of external systems, services,
devices and connections and defining minimum cybersecurity controls for external systems, services,
devices and connections accessing organizational systems and services used for telehealth services.
Examples of minimum cybersecurity controls include identification and authentication mechanisms, access

control measures, secure communication protections, vulnerability and patch management processes,
logging and monitoring capabilities, and incident reporting procedures.
Telehealth service participants should consider obtaining assurance that external systems, services, devices
and connections conform to applicable minimum cybersecurity controls.
Inventory management processes should consider relevant threat intelligence and ensure that modifications,
replacements, disposals and cybersecurity incident-related actions are appropriately documented and
reflected in inventories.
For high-risk telehealth services, telehealth service participants should establish measures to minimize
adverse impacts on the health or safety of the subject of care when disconnecting systems, services, devices
or connections in response to cybersecurity incidents.
4.2.4 Cybersecurity level alignment
4.2.4.1 General
The controls for cybersecurity aspects are found in ISO 27799:2025, 5.12 and 6.7. 4.2.4.2 to 4.2.4.4 in this
document provide additional telehealth considerations beyond the controls listed in ISO 27799.
4.2.4.2 Control
Telehealth service participants should ensure that telehealth-related information, systems and services
shared or connected among participants maintain a consistent and appropriate level of cybersecurity.
4.2.4.3 Purpose
To ensure a consistent and appropriate level of cybersecurity for telehealth-related information, systems and
services shared among telehealth service participants operating in different cybersecurity environments.
4.2.4.4 Guidance
One of the significant cybersecurity risks in telehealth services is the exchange of telehealth-related
information and the interconnection of systems and services among telehealth service participants
operating in different cybersecurity environments. Cybersecurity weaknesses in one participant
environment can affect interconnected participants, systems and services. Telehealth service participants
should therefore assess and mitigate cybersecurity risks associated with interconnected environments,
including connections involving participants operating with lower cybersecurity capabilities. Examples
include telehealth services involving patient-owned devices, home networks, long-term care facilities,
community telehealth locations or other environments where cybersecurity controls can be less mature
than those implemented by healthcare organizations.
Telehealth-related information, systems and services shared or connected among participants should
maintain a level of cybersecurity appropriate to the risks associated with the telehealth services and
interconnected participant environments. Telehealth service participants should consider implementing
cybersecurity controls and protections aligned with the highest cybersecurity requirements among
participating entities to ensure safe and secure telehealth services. Consideration should be given to aligning
authentication, access control, information protection, audit logging, endpoint security requirements,
incident response processes, vulnerability management activities and monitoring capabilities across
participating environments.
4.2.5 Secure exchange of telehealth information
4.2.5.1 General
The controls for cybersecurity aspects are found in ISO 27799:2025, 5.14. 4.2.5.2 to 4.2.5.4 in this document
provide additional telehealth considerations beyond the controls listed in ISO 27799.

4.2.5.2 Control
Telehealth service participants should use approved and secure communication platforms for telehealth-
related communications and exchanges of personal health and clinical information.
4.2.5.3 Purpose
To ensure that telehealth-related communications and information exchange are conducted through
communication platforms appropriate to applicable cybersecurity, privacy and telehealth service
requirements.
4.2.5.4 Guidance
Telehealth service participants should ensure that communication platforms used for telehealth services are
managed and operated in accordance with applicable cybersecurity, privacy, legal, regulatory and telehealth
service requirements.
Telehealth service participants should assess and manage cybersecurity and privacy risks associated with
communication platforms used for telehealth services, including risks related to access control, transmission
security, recording, storage, sharing and unauthorized disclosure of information. Consideration should be
given to communication platform capabilities that support authentication, access control, transmission
security and protection against unauthorized access or disclosure. Relevant guidance related to health
information in telehealth services, including ISO 13131, should also be considered.
The use of unmanaged or publicly available communication platforms for telehealth-related communications
and information exchange should be evaluated in accordance with organizational policies, applicable
regulations and cybersecurity requirements. Recording, storing or sharing telehealth sessions, messages,
images or related information should be performed in accordance with applicable consent, privacy, security,
and retention requirements.
Telehealth service participants should consider providing approved or organization-managed
communication platforms and secure alternatives for telehealth services.
4.2.6 Shared identity management
4.2.6.1 General
The controls for cybersecurity aspects are found in ISO 27799:2025, 5.16, 5.18 and 6.7. 4.2.6.2 to 4.2.6.4 in
this document provide additional telehealth considerations beyond the controls listed in ISO 27799.
4.2.6.2 Control
Policies and processes should be established to manage access to telehealth services when persons, devices
or systems are shared or used on behalf of the subject of care.
4.2.6.3 Purpose
To ensure safe, secure, and accountable access to telehealth services when persons, devices or systems are
shared or used on behalf of the subject of care.
4.2.6.4 Guidance
Subjects of care can access telehealth services in diverse situations and environments, including
circumstances where caregivers, family members or other authorized persons assist or access telehealth
services on behalf of the subject of care. Where telehealth services are accessed by caregivers, family
members or other authorized persons, or through devices or systems belonging to them, policies and
processes should be established for the creation, use, management and removal of associated access rights
and related records.
Telehealth service participants should consider risks associated with shared persons, devices or systems
used to access telehealth services, including risks related to identification, authentication, authorization,
traceability and accountability.
Telehealth service participants should consider methods to distinguish and trace individual users accessing
telehealth services through shared persons, devices or systems.
4.2.7 Telehealth incident management planning and preparation
4.2.7.1 General
The controls for cybersecurity aspects are found in ISO 27799:2025, 5.24, 5.25, 5.26, 5.27, 5.28, 5.29, 5.30,
5.42, 5.43 and 6.7. 4.2.7.2 to 4.2.7.4 in this document provide additional telehealth considerations beyond the
controls listed in ISO 27799.
4.2.7.2 Control
Incident response planning and preparation should consider differences in cybersecurity capabilities and
environments among telehealth service participants.
4.2.7.3 Purpose
To ensure coordinated and timely responses to cybersecurity incidents affecting telehealth services
operating across different cybersecurity environments, jurisdictions, service locations, languages.
4.2.7.4 Guidance
Telehealth cybersecurity incident planning and preparation should consider differences in cybersecurity
capabilities, operating environments, languages and applicable legal or regulatory requirements among
telehealth service participants.
Telehealth service participants should establish communication and coordination procedures to ensure
timely responses to cybersecurity incidents affecting telehealth services involving multiple organizations,
remote participants or cross-border operations.
Planning and preparation activities should include measures to ensure essential telehealth and clinical
functions during cybersecurity incidents, network failures, communication disruptions or the unavailability
of supporting systems or services.
Telehealth service participants should consider alternative communication methods, fallback procedures
and contingency measures to minimize impacts on the health or safety of the subject of care during
cybersecurity incidents.
4.2.8 Differences in legal, statutory, regulatory and contractual requirements
4.2.8.1 General
The controls for cybersecurity aspects are found in ISO 27799:2025, 5.31, 5.32, 5.33, 5.34, 5.36 and 6.7.
4.2.8.2 to 4.2.8.4 in this document provide additional telehealth considerations beyond the controls listed in
ISO 27799.
4.2.8.2 Control
Countermeasures should be established to address differences in legal, statutory, regulatory and contractual
requirements across participating jurisdictions.

4.2.8.3 Purpose
To ensure compliance with differing legal, statutory, regulatory and contractual requirements applicable to
telehealth services across participating jurisdictions.
4.2.8.4 Guidance
Telehealth service participants should identify and regularly review differences in legal, statutory,
regulatory and contractual requirements arising from participating jurisdictions to ensure compliance and
minimize legal or regulatory conflicts during telehealth service delivery. Where participating jurisdictions
or organizations impose more stringent legal, statutory, regulatory or contractual requirements, telehealth
service participants should consider measures to ensure compliance with those requirements.
4.2.9 Protection of records
4.2.9.1 General
The controls for cybersecurity aspects are found in ISO 27799:2025, 5.33 and 6.7. 4.2.9.2 to 4.2.9.4 in this
document provide additional telehealth considerations beyond the controls listed in ISO 27799.
4.2.9.2 Control
Records related to telehealth services should be protected from loss, destruction, falsification, unauthorized
access and unauthorized disclosure across physically distributed telehealth service environments and
jurisdictions.
4.2.9.3 Purpose
To ensure the integrity, authenticity, availability and protection of telehealth service records in accordance
with applicable legal, statutory, regulatory and contractual requirements.
4.2.9.4 Guidance
Telehealth service participants should consider risks associated with storing, processing, transmitting or
maintaining telehealth service records across jurisdictions with differing legal, regulatory or governmental
access requirements.
Particular consideration should be given to situations where telehealth service participants can have limited
ability to verify the deletion, destruction, return or continued protection of telehealth service records stored
or processed in external or foreign jurisdictions.
Telehealth service participants should consider legal, operational and technical measures to address risks
related to unauthorized governmental access, limited enforcement capabilities, cross-border data retention
requirements or insufficient assurance regarding the disposal of telehealth service records.
Where telehealth service records are processed or stored by external organizations or across jurisdictions,
telehealth service participants should consider mechanisms to ensure traceability, accountability,
contractual protection and verification of record management activities.
4.2.10 Documented operating procedures
4.2.10.1 General
The controls for cybersecurity aspects are found in ISO 27799:2025, 5.37. 4.2.10.2 to 4.2.10.4 in this
document provide additional telehealth considerations beyond the controls listed in ISO 27799.

4.2.10.2 Control
Operating procedures for telehealth facilities should be documented and made available to relevant
telehealth service participants, including healthcare personnel, patients and caregivers.
4.2.10.3 Purpose
To ensure the safe, secure and consistent operation of telehealth facilities.
4.2.10.4 Guidance
Operating procedures and security guidance for telehealth services should be documented and made
available in forms, formats and delivery methods appropriate to the technical knowledge, responsibilities
and capabilities of the intended telehealth service participants, including healthcare personnel, patients and
caregivers. Examples of delivery methods include documents, web portals, online knowledge bases, training
programmes, instructional videos, interactive tutorials, in-application guidance, automated notifications
and other suitable communication mechanisms.
4.2.11 Unique identification and authentication
4.2.11.1 General
The controls for cybersecurity aspects are found in ISO 27799:2025, 5.39. 4.2.11.2 to 4.2.11.4 in this
document provide additional telehealth considerations beyond the controls listed in ISO 27799.
4.2.11.2 Control
Subjects of care, as well as their devices and software applications used for telehealth services, should be
uniquely identified and authenticated when interacting with other telehealth service participants, devices
and software applications.
4.2.11.3 Purpose
To prevent unauthorized access and the incorrect association or misattribution of data among telehealth
service participants, devices and software applications.
4.2.11.4 Guidance
Telehealth service participants should identify the sources of telehealth service data and information to
support appropriate access control, traceability and secure telehealth services.
Identification and authentication should be established among telehealth service participants, devices and
software applications, including associations between the subject of care and devices, and among interacting
devices and software applications.
Where identities of subjects of care are shared or jointly used, telehealth service participants should
implement measures to identify the entity using the identity and to trace telehealth service data and
information to their originating source. Such measures can include additional authentication mechanisms,
user selection or confirmation processes, records of caregiver or delegated roles, records distinguishing
the individual performing an activity from the identity owner, user attestations associated with telehealth
activities, and records of delegated or linked identity relationships.

4.3 People controls
4.3.1 Identification of participating persons
4.3.1.1 General
The controls for cybersecurity aspects are found in ISO 27799:2025, 6.7. 4.3.1.2 to 4.3.1.4 in this document
provide additional telehealth considerations beyond the controls listed in ISO 27799.
4.3.1.2 Control
Persons participating in telehealth services should be identified, authenticated and approved.
4.3.1.3 Purpose
To ensure the identification and verification of telehealth service participants who are not physically present
in the same location during telehealth services.
4.3.1.4 Guidance
Procedures should be established to identify, verify and approve persons participating in or present during
telehealth services.
Telehealth services can have limitations in directly assessing remote environments and persons present
during telehealth services when telehealth service participants are not physically present in the same
location. Telehealth service participants should therefore consider methods to identify and verify persons
participating in telehealth services, including persons outside the camera view or otherwise not directly
observable.
Telehealth service participants should consider risks associated with unauthorized participation,
impersonation, undisclosed companions or observers, and the presence of unverified persons during
telehealth services.
Particular consideration should be given to telehealth services conducted in public, shared or semi-
controlled environments where unrelated persons can be present or have access to telehealth-related
information. Such environments can include shared hospital rooms, long-term care facilities, nursing home
rooms with multiple beds, public spaces or other environments where telehealth service participants cannot
fully control the surrounding environment.
Measures should be established to identify and verify persons participating in or present during telehealth
services. Consideration should be given to ISO 13131 for guidance on telehealth operational procedures
related to participant identification and verification.
4.3.2 Awareness, education and training for persons participating in telehealth services
4.3.2.1 General
The controls for cybersecurity aspects are found in ISO 27799:2025, 6.3 and 6.7. 4.3.2.2 to 4.3.2.4 in this
document provide additional telehealth considerations beyond the controls listed in ISO 27799.
4.3.2.2 Control
Persons participating in telehealth services should be provided with appropriate cybersecurity awareness,
education and training opportunities.

4.3.2.3 Purpose
To ensure awareness of cybersecurity risks and responsibilities related to telehealth services, and the
secure use of telehealth systems, services and devices.
4.3.2.4 Guidance
Persons participating in telehealth services who operate in isolated, remote or otherwise uncontrolled
environments without established cybersecurity policies, procedures or access to technical support are
particularly vulnerable to cybersecurity risks during telehealth services. Limited cybersecurity awareness,
technical knowledge or inadvertent actions can increase risks to telehealth services.
Telehealth service participants should ensure that appropriate and understandable cybersecurity
awareness, education and training resources are provided to persons participating in telehealth services.
Awareness, education, and training activities should address risks related to:
a) connecting telehealth devices or systems to rogue or untrusted wireless networks in public or shared
environments;
b) accessing untrusted websites or services using telehealth devices or systems;
c) install
...