Recently, the development of information and communication technology, number of hospitals using
electronically process and management of medical information have increased in order to improve the
quality of medical services. As electronic medical information is processed, the convenience and efficiency
of handling and processing of medical information by patients and medical staff has increased. Despite
these advantages, there is still a possibility that personal information such as patient or medical staff may
be infringed Accordingly, ISO published the technical specification ISO/TS 25238 in December 2008. This
technical specification covers basic definitions, non-identification, minimum requirements for re-identification
and policies, scenarios and risk analysis for the secondary use of personal medical information. Since then,
the revision of this standard has been in progress and will be published in 2017. Therefore, in this paper,
we compare the recent revision of ISO DIS 25237 and ISO / TS 25237, and discuss major changes and
additions. Finally, future research directions are presented.