Standards
The standards and frameworks CHORUS is built to meet.
CHORUS is built around the standards institutions already expect - which is what makes it straightforward for ethics boards and data governance committees to approve.
The frameworks
| Framework | What it is | Where CHORUS stands |
|---|---|---|
| Five Safes | The reference model for governing access to sensitive data, from the UK Office for National Statistics. | The organising structure of the CHORUS security documentation. |
| SATRE | The reference architecture for Trusted Research Environments - the technical detail behind the governance vocabulary. | Tracked as the technical specification CHORUS is assessed against. |
| ISO/IEC 27001 | The international standard for managing information security, and the control catalogue institutions already use. | The security principles CHORUS is designed around. |
| EU/EHDS | Regulation (EU) 2025/327, establishing the European Health Data Space. In force since March 2025, applying in phases to 2029. | CHORUS is designed as a Secure Processing Environment for its secondary-use regime. |
| TEHDAS2 | The EU Joint Action writing the technical specification for Secure Processing Environments under EHDS. | Tracked as that specification is published. |
| GDPR | The European data protection regulation. | Designed for its requirements from the outset. |
How they relate
They are layers, not alternatives:
- Five Safes gives the governance vocabulary - the five questions any secure environment has to answer.
- SATRE gives the technical detail for each of those answers.
- ISO/IEC 27001 supplies the underlying control catalogue that the technical layer draws on.
- EHDS is the law for health data in Europe, and TEHDAS2 is writing the specification that says what an environment must do to satisfy it.
Primary and secondary use
EHDS separates two things, and CHORUS sits firmly in one of them.
Primary use is the direct provision of care - a clinician opening a patient record. CHORUS is not a medical record system and plays no part in it.
Secondary use is the reuse of health data for research, innovation, policy and regulatory work. This is what CHORUS is built for, and what the Secure Processing Environment requirements in the regulation govern.
Why it matters
Meeting standards institutions already require means an assessment does not start from scratch. Ethics boards, data protection officers, and governance committees can evaluate CHORUS in the language they already use - and the same vocabulary carries across the partners CHORUS works with.