Digitalization, Digital Maturity and Information Security of Processes: Standard ISO 15189, ISO 17025, and EUROLAB Guide
Marco PradellaTesting and medical laboratories have been undergoing a process of progressive, unstoppable digitalization. The digitalization of laboratories carries risks for information security. There are differences between medical laboratories according to International Organization for Standardization (ISO) 15189 and testing laboratories according to ISO 17025. ISO 15189 refers to information security based on ISO 27001, while ISO 17025 is limited to certain clauses. Medical laboratories can use the guidelines with sources from Clinical & Laboratory Standards Institute (CLSI) documents. The European Federation of National Associations of Measurement, Testing, and Analysis Laboratories (EUROLAB) provides a guide to digitalization security that combines ISO 17025 requirements with ISO 27001 controls. The Italian Society of Clinical Pathology and Laboratory Medicine (SIPMeL) Q18R1 Recommendations regarding requirements for medical laboratory information systems confirm that laboratories should obtain at least ISO/IEC 27001 certification.