Protecting Health Information, Strengthening Member Trust: iCare Achieves ISO/IEC 27001:2022 Certification 

The certification issued by TÜV Rheinland marks an important step in iCare’s continuing effort to strengthen information security governance across its healthcare operations. 

In healthcare, protecting people also requires protecting the information they entrust to the organizations responsible for their care. Member profiles, medical information, identification records, authorization requests, claims documents, and payment details may pass through multiple systems before a consultation, diagnostic procedure, or hospital admission is completed. 

iCare has achieved ISO/IEC 27001:2022 certification issued by TÜV Rheinland. The certification recognizes the information security management system covered by the scope stated in iCare’s official certificate and confirms that it was assessed against the requirements of the international standard. 

“Healthcare organizations are entrusted not only with the well-being of their members, but also with highly sensitive information about their health, identity, and financial transactions. Achieving ISO/IEC 27001:2022 certification reflects our commitment to managing that responsibility through stronger governance, disciplined processes, and continuous improvement. For iCare, information security is essential to earning member trust and delivering healthcare services with confidence,” said Geronimo V. FransciscoPresident and CEO of iCare. 

ISO/IEC 27001:2022 specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system, commonly known as an ISMS. It requires organizations to identify information security risks, assign responsibilities, apply appropriate controls, monitor performance, and continually improve their systems. The standard is designed to support the confidentiality, integrity, and availability of information. 

TÜV Rheinland describes ISO/IEC 27001 certification as a structured process involving an initial review of documentation and organizational readiness, followed by an assessment of the implementation and effectiveness of the ISMS. Certification is followed by surveillance audits and eventual recertification, reinforcing the principle that information security must be continuously maintained rather than treated as a one-time project. 

The certification does not mean that security incidents are impossible, nor does it replace compliance with Philippine laws and regulatory requirements. Its significance lies in providing independent assurance that a defined management system has been assessed against internationally recognized requirements. 

For regulatory bodies, this is particularly relevant because HMOs handle information involving health, identity, employment, and financial transactions. Under the Data Privacy Act of 2012, information relating to an individual’s health is classified as sensitive personal information and is subject to heightened protection. 

The Insurance Commission also recognizes data privacy and protection as a fundamental right of HMO consumers. Its guidelines governing HMOs identify the right to data privacy and protection alongside equitable treatment, transparency, protection against fraud and misuse, and timely handling of complaints. 

For CEOs, CFOs, CHROs, HR leaders, and business owners, information security should form part of HMO due diligence. Employers entrust healthcare partners with data belonging to their employees and dependents. The governance of that information should therefore be evaluated alongside medical benefits, provider network access, operational reliability, customer service, and financial capability. 

The certification also carries wider importance for the Philippine HMO industry. Digital authorizations, electronic claims, telemedicine, online member services, and other technology-enabled healthcare processes can improve convenience and access. Their usefulness, however, depends on systems that manage information consistently, securely, and reliably.  

iCare previously completed a SOC2 Type II certification last September 2025 conducted by Reyes Tacandong & Co.  

For iCare, the certification is not the end of an information security journey. It is a stronger foundation for the work ahead. In healthcare, protecting information is part of protecting people. When members can trust both the care they receive and the systems that make that care possible, better health becomes more dependable, accessible, and human.  

For members, that framework supports a simple but essential principle: information entrusted in the pursuit of better health must be handled with care.  

In healthcare, information security is not separate from member care. It is part of the trust that allows care to be delivered with confidence. 

 

Sources and References 

  • iCare. ISO/IEC 27001:2022 Certificate Issued by TÜV Rheinland. Internal certification record. 
  • iCare. SOC 2 Type II Independent Attestation Report Conducted by Reyes Tacandong & Co. Internal assurance record. 

 

Anne Rosales
mdrosales@icare.com.ph


Share This