
Short answer: ISO 27799 is the health informatics standard that applies ISO/IEC 27002 security controls to personal health information. As of October 2026 the current edition is ISO 27799:2025, based on ISO/IEC 27002:2022. It is control guidance, not a certificate: you certify an ISMS to ISO/IEC 27001 and use ISO 27799 to shape its health-specific controls.
Related guides:
- ISO 27001 for healthcare companies: benefits and implementation steps
- After SOC 2: the compliance roadmap for HealthTech companies
- HIPAA vs HITRUST
Key takeaways
- ISO 27799:2025 is the third edition. It replaced ISO 27799:2016 and ISO/TS 14441:2013, which ISO lists as withdrawn.
- It is based on ISO/IEC 27002:2022, so it follows the same control structure and adds health-specific guidance on top.
- You do not get "ISO 27799 certified" in the way buyers usually mean. The certificate is for your ISO/IEC 27001 ISMS, and ISO 27799 feeds your risk assessment and Statement of Applicability.
- ISO 27799 is not a substitute for HIPAA. US companies handling ePHI still need a HIPAA risk analysis, business associate agreements and Security Rule safeguards. Treat the two as a mapping exercise.
- For a SaaS team already running ISO 27001, adopting ISO 27799 is mostly a gap review of health risks such as patient safety, emergency access and record access logging.
What is ISO 27799?
ISO 27799 is an ISO health informatics standard that gives information security controls, with implementation guidance, to organizations that provide healthcare or hold personal health information.

It is published by ISO's health informatics committee, ISO/TC 215. According to ISO's catalogue entry for ISO 27799:2025, the current edition is titled "Health informatics: Information security controls in health based on ISO/IEC 27002", and its scope is broad:
- Systems: generic ICT plus health-specific systems, such as electronic health record systems and medical devices that include health software.
- Other equipment: digital equipment on healthcare premises, such as environmental, infection control, building management and physical security systems.
- Information: personal health information in any form or medium.
- Organizations and settings: organizations of all types and sizes, across hospitals, clinics, ambulances and care at home, including remote or virtual care.
In plain terms, ISO/IEC 27002 describes good security controls in general. ISO 27799 extends them for patient information, where a security failure can also become a care or safety failure.
Which edition of ISO 27799 is current in 2026?
As of October 2026, the current edition is ISO 27799:2025, the third edition, published in December 2025.
ISO's page for the 2016 edition shows it as withdrawn and replaced by the 2025 edition. The 2016 edition was a companion to the older ISO/IEC 27002, so many templates still reference a control structure that no longer exists. The new edition is based on ISO/IEC 27002:2022, and ISO also lists ISO/TS 14441:2013 as a withdrawn predecessor.
| ISO 27799:2016 | ISO 27799:2025 | |
|---|---|---|
| Status (as of October 2026) | Withdrawn | Current |
| Edition | Second | Third |
| Based on | Earlier ISO/IEC 27002 | ISO/IEC 27002:2022 |
| Title focus | Information security management in health | Information security controls in health |
If your ISMS already follows ISO/IEC 27001:2022 and ISO/IEC 27002:2022, the 2025 edition lines up with your existing control list. If your policies cite ISO 27799:2016, update the references and recheck your health-specific controls. Our ISO 27001 vs ISO 27002 guide explains how the two parent standards relate.
ISO 27799 vs ISO 27001: can you get certified?
ISO/IEC 27001 is the certifiable requirements standard for an information security management system, while ISO 27799 is sector guidance on which controls to run and how.

ISO itself does not perform certification or issue certificates. External certification bodies do, and the certificate HealthTech buyers ask for is ISO/IEC 27001 for your ISMS. Ask your certification body whether it can reference ISO 27799 in your audit, but plan around ISO/IEC 27001 as the target.
| ISO/IEC 27001 | ISO 27799 | |
|---|---|---|
| Purpose | Requirements for an ISMS | Health-specific security controls and guidance |
| Content | Management system clauses plus an Annex A control list | Controls and implementation guidance based on ISO/IEC 27002:2022 |
| Certification | Certifiable by an external certification body | Used as guidance inside your ISMS |
| How you use it | Run the ISMS, get audited, keep the certificate | Inform risk treatment and control choices for health information |
So "ISO 27799 vs ISO 27001" is not really a choice. ISO 27001 is the management system. ISO 27799 makes that system fit healthcare.
Who uses ISO 27799?
Anyone who holds personal health information and wants a recognized, international reference for health-specific security controls.
- Health providers such as hospitals, clinics, ambulance services and home care providers, who are directly in the standard's scope.
- HealthTech and digital health vendors such as EHR, telehealth, remote monitoring and health data platforms that act as custodians of personal health information for their customers.
- Buyers outside the US. In our experience, international health buyers and public sector procurement teams are more likely to recognize ISO terminology than US-specific frameworks. Our ISO 27001 in Australia guide covers one such market.
- Security and compliance teams who want to show a health customer that their controls were tailored to health data.
If you sell mainly to US health systems and payers, HIPAA and often HITRUST will drive more of your questionnaires. ISO 27799 is most useful when ISO 27001 is already on your roadmap.
How do you use ISO 27799 inside an ISO 27001 ISMS?
Use it as an additional control source during risk assessment and risk treatment, and record the result in your Statement of Applicability.
ISO/IEC 27001 already expects you to justify your controls against Annex A in a Statement of Applicability (see our Statement of Applicability guide). ISO 27799 slots into that workflow:
- Scope. Confirm that the systems, people and locations handling personal health information are inside your ISMS scope.
- Risk assessment. Add health-specific threats and consequences to your risk register. Rate impact on patients, not only on confidentiality, integrity and availability of data.
- Control selection. When treating each risk, check the ISO 27799 guidance for the matching ISO/IEC 27002:2022 control, plus any health-specific controls it adds.
- Statement of Applicability. Note where you follow ISO 27799 guidance, or why you do not.
- Internal audit and management review. Include the health-specific controls in your audit program like any other control.
Health-specific considerations we suggest every HealthTech ISMS covers, whatever framework you map them to:
- Patient safety. Treat wrong, missing or unavailable health data as a safety risk, not only a privacy risk.
- Emergency access. Define "break glass" access during an emergency, who approves it, and how it is reviewed afterwards.
- Logging of record access. Log who viewed or changed a patient record and when, and review those logs.
- Patient identity. Tie records to the correct individual, since misidentification can harm care.
- Devices and suppliers. Include device software, hosting and subprocessors in asset, vulnerability and vendor management.
How does ISO 27799 relate to HIPAA?
They overlap heavily in subject matter but are not equivalent: HIPAA is US law, and ISO 27799 is voluntary international guidance.
HIPAA's Security Rule applies to covered entities and their business associates. HHS lists failure to comply with the Security Rule as one of the ways a business associate is directly liable. HHS also describes the rule as flexible, scalable and technology neutral, requiring an accurate and thorough assessment of risks to ePHI rather than one specific control set.
So an ISO 27001 ISMS informed by ISO 27799 is a strong foundation, but not proof of HIPAA compliance. Two health themes map naturally to Security Rule text:
| Health consideration | HIPAA Security Rule text (45 CFR 164.312) |
|---|---|
| Emergency access | Emergency access procedure: procedures for obtaining necessary ePHI during an emergency |
| Logging of record access | Audit controls: mechanisms that record and examine activity in systems containing ePHI |
What ISO 27799 does not cover for you: business associate agreements, HIPAA's documentation and breach notification obligations, and the US-specific definitions of PHI and ePHI. HHS has also proposed changes to the Security Rule, so track the final rule separately. Build one control set and map it to both HIPAA and your Statement of Applicability. If HITRUST is also on the table, our HIPAA vs HITRUST guide linked above explains how it differs.
What does a practical ISO 27799 adoption plan look like?
For a SaaS team, it is a five-step gap review of an existing ISMS, done as part of normal ISMS work.

- Get the 2025 edition. Buy ISO 27799:2025 and retire references to the 2016 edition in policies and customer-facing documents.
- Map it to your controls. Both build on ISO/IEC 27002:2022, so map each ISO 27799 control to the control you already run and mark gaps.
- Add health risks. Add patient safety, emergency access, record access logging and identity risks to the register, with owners and treatment plans.
- Update the Statement of Applicability. Record where ISO 27799 guidance shaped each control, and justify exclusions.
- Audit and review. Cover the new controls in your next internal audit and management review, and tell your certification body you use ISO 27799 as guidance.
Example starting point for step 3 (example values, not a template):
| Example risk | Example treatment |
|---|---|
| Support engineer reads patient records without a ticket | Just-in-time access with a linked ticket, plus monthly review of access logs |
| Clinician locked out during an outage | Documented break-glass account, alerting on use, after-the-fact review |
| Wrong patient record shown after a data import | Validation checks on imports and identity matching, with rollback |
Not started ISO 27001 yet? Begin there with our ISO 27001 for healthcare companies guide, linked at the top.
How SecureSlate helps
SecureSlate gives HealthTech teams one place to run ISO 27001 and HIPAA together. ISO 27001 and HIPAA are built in, and multi-framework control mapping lets one control satisfy both. ISO 27799 does not have a built-in page, so you set it up as a custom framework or add its health-specific guidance as custom controls, mapped to your existing ISO 27001 controls. Risk management holds your health-specific risks, access reviews and agentless read-only cloud integrations help evidence who can reach patient data, and audit management keeps evidence ready for your certification body. Vendor risk management tracks subprocessors, and the trust center and security questionnaire automation help you answer health buyers.
Start your free SecureSlate trial
FAQ
Is ISO 27799 mandatory?
No. ISO standards are voluntary unless a law, regulator or contract requires them. Check your customer contracts and tenders.
Can my company be ISO 27799 certified?
Plan on certifying your ISMS to ISO/IEC 27001 and using ISO 27799 as guidance within it. ISO does not issue certificates itself, so ask your certification body whether and how it can reference ISO 27799 in your audit.
Is ISO 27799:2016 still valid?
ISO lists the 2016 edition as withdrawn and replaced by ISO 27799:2025. New policies and mappings should reference the 2025 edition.
Does ISO 27799 make us HIPAA compliant?
No. It can strengthen the controls you use for HIPAA, but HIPAA has its own legal requirements, including a risk analysis, business associate agreements and breach notification. Map the two rather than treating one as the other.
Disclaimer (legal note)
This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds