Start a free trial
Menu

AMedP-5.3

AMedP-5.3 telemedicine for mission support

Nations building a national telemedicine capability, and the medical, technical and administrative staff who plan, resource and operate it

AMedP-5.3 is NATO's guidance and minimum requirements for nations building interoperable military telemedicine capabilities, agreed by nations under STANAG 2517.

Edition
B
Published
2025-04

What it is

AMedP-5.3 is the NATO Allied Medical Publication that sets out guidance and minimum requirements for nations building a national telemedicine capability that can interoperate with allies on NATO and multinational operations. Nations record their agreement to use it in STANAG 2517: "the agreement of nations to use this publication is recorded in STANAG 2517," which is how the publication itself acquires force. It does not bind a supplier or a national programme on its own; it reaches one through national implementation, a multinational tasking, or a procurement that invokes it.

The document's own aim is threefold: "to describe telemedicine - scope, benefits and challenges," "to set out guidance as well as standards (minimum requirements and processes) for nations developing national Telemedicine capabilities," and to support interoperability "between NATO forces or affiliates in multinational missions." It is edition B, version 1, promulgated April 2025, and it supersedes edition A, version 1, which nations were told to destroy under their own local procedure.

Telemedicine and telehealth, as the document defines them

The document fixes the vocabulary before anything else. Telemedicine is "the delivery and support of healthcare over a distance using information and communication technologies," spanning everything from "a simple telephone conversation to remote robotic surgery." Telehealth is the wider category: "the provision of all remote health services, including telemedicine, health education and preventive care, using information and communication technology (ICT)." Telemedicine is described as "a subdiscipline of telehealth" and, throughout, as "a supporting capability for the delivery of clinical care" rather than an end in itself - a distinction the document repeats more than once.

Who it speaks to, and how it binds

The document names its key stakeholders as the Nations, ACT, ACO, NCIA, the NATO COMEDS Health Information and Technologies Working Group (HIST WG) and the Federated Mission Networking Inter-FMN Working Group (IWG) Medical Syndicate. Its requirements chapter is written to a nation developing its own capability, and through that nation, to the people who build and run it: "each nation should analyze these requirements (particularly the procedural instructions and technical requirements) as a guide to developing its own desired deployable telemedicine capabilities, to enable interoperability." It also speaks to the clinicians who use the finished capability: "healthcare providers throughout the deployed NATO Medical Force structure should have access to a telemedicine capability which provides expert advice in all needed specialty areas."

Planning and organisation

Recruiting suitable medical, technical and administrative experts and choosing the right equipment and applications is treated as critical, and the document is explicit that user "buy-in" from deployed personnel and the experts they consult is essential to a successful rollout. Planning "components include medical, legal, economical, technical, data protection and quality management aspects," and the equipment itself "shall be easy to use and simple to maintain by the end user." Because operational electromagnetic security measures can restrict how and when a system transmits, planning has to allow for delayed transmission or an alternative means of data transfer, and telemedicine data has to be incorporated into the national Electronic Health Record system where one already exists. For the data itself, the document points a nation toward the standardisation recommendations in STANAG 2543, STANAG 2231, STANAG 2348 and STANAG 7149, plus AMedP-8.2 and APP-11, for data sets and message formats.

Functional and communication requirements

A telemedicine capability starts from organising medical expertise "on call/on request," whether the exchange is real-time video-conferencing or asynchronous store-and-forward of images and data. Automated recording of data is called for so that using capture devices such as body sensors does not slow a clinician down, and because training of every user cannot be guaranteed, the interface has to be simple and intuitive rather than depend on instruction. On the communications side, capabilities "shall be interoperable and shall utilize standardized communication protocols, a standardized medical vocabulary (and classification) and data sets," and they have to keep working as available bandwidth changes: the document notes that as combat intensity rises, bandwidth priority can shift to combat activity or be deliberately reduced to counter electronic warfare, so a design has to tolerate a low-bandwidth environment rather than assume a stable connection.

Confidentiality, data protection and legal compliance

Confidentiality, data integrity and the availability of patient information are named as "essential prerequisites for the successful and accepted use of information technology" in this field. Encryption and security measures for personal medical data "should meet the standard required by each participating nation's health records law" - the document defers to national law rather than setting a figure of its own - and it is explicit that "encryption and security measures do not prevent interoperability." A structured system for storing telemedicine records, with a mechanism to archive a summary into the patient record, is also required, and a secure legal framework is called "an important prerequisite for IT systems in the healthcare sector," pointing to "information security standards" such as the ISO/IEC 27000 series, ISO/IEC 27001 and the NIST 800 series as reference points - not as a certification a telemedicine system has to hold. Where an agreement between nations already covers the provision of health care, the document says a section addressing telemedicine specifically should be included.

Training, evaluation and risk

"Education, Training, Exercising and Evaluation (ETEE)" has to be carried out so the system is used correctly and its expected benefits are realised, and the document is explicit that a telemedicine service should be worked into existing workflows rather than disrupt them, with Standard Operating Procedures covering standard minimum data sets and the roles of users and the remote experts they consult. Before wider use, new systems are expected to go through "a pilot or concept phase that includes clinical validation," and ongoing "(scientific) evaluation and re-evaluation" is what the document says allows a capability's translation "into routine use." System owners are expected to run clinical risk assessments against known risks the document names outright: treatment delay, patient confidentiality, language friction, poor connectivity, image degradation, service interruption, and the loss of visual, auditory and other cues.

What it deliberately leaves open

The document says plainly that "it is not our aim to set out detailed technical specifications, but to identify general requirements." Bandwidth figures, network specifications and video interface standards are left to NATO's Federated Mission Networking work and to national implementation, and no numeric encryption standard is set: that is deferred to each nation's own health records law. A reader working from this document should not expect it to answer a procurement's technical questions on its own.

Getting the document

AMedP-5.3 is free of charge, published by the NATO Standardization Office. We do not sell it or host a copy. It can be retrieved from the NATO Standardization Document Database, where NATO should be credited on reproduction.

How we help

AMedP-5.3 is not a management system standard: it describes an operational capability that a nation's medical service designs, procures, trains people on and evaluates, and that work - selecting equipment, running consultations, encrypting patient data in transit, validating a pilot - happens in the telemedicine programme itself, not in software. ComplyTrain is not a telemedicine platform, and it does not provide, host or secure a telemedicine capability.

What a programme built to this document still has to hold and evidence is where ComplyTrain fits: the planning documentation covering the medical, legal, technical and data-protection considerations the document lists, the Standard Operating Procedures for users and remote experts it calls for, training records showing the Education, Training, Exercising and Evaluation it requires, and the record of a system's pilot validation and its ongoing re-evaluation. ComplyTrain gives a programme a controlled place to hold and version those procedures and records, assign and track training against them, and keep the evaluation history a reviewer would ask to see.

It does not assess whether a telemedicine system meets AMedP-5.3's functional, technical or interoperability requirements, and it has no part in the clinical judgement, network engineering or encryption implementation the document asks for - that stays with the programme's own medical, technical and legal teams. Which standards apply to a given national telemedicine programme, and at what tier, is set by the programme's own tasking and the agreements it sits under, not by us. If you want to see what else sits alongside AMedP-5.3, the standards explorer lists the related publications, or talk to us about how we support the documentation and evidence side of that work.

Standards it references

Questions

Is AMedP-5.3 mandatory for a nation or a supplier?

Not by itself. Nations record their agreement to use it in STANAG 2517, and it reaches a supplier or a specific programme only once a national implementation, tasking or contract invokes it. Whether it applies to a given programme is a question for that programme, not for the publication on its own.

Can an organisation be certified against AMedP-5.3?

No. The document names no accreditation or certification scheme, and no body is described as certifying a nation or a supplier against it. What it describes is validation aimed at the telemedicine system itself: a pilot or concept phase with clinical validation, followed by ongoing evaluation and re-evaluation once the capability is in use.

What is the difference between telemedicine and telehealth under AMedP-5.3?

The document treats telemedicine as a subdiscipline of the broader category telehealth. Telemedicine is the delivery and support of clinical care itself over a distance; telehealth also covers things that fall short of direct clinical care, such as provider education and preventive health information.

Does AMedP-5.3 require ISO/IEC 27001 certification for patient data?

No. It names ISO/IEC 27001, the wider ISO/IEC 27000 series and the NIST 800-series publications as information security standards a nation should have regard to when building the secure legal framework telemedicine needs, but it does not require certification against any of them, and encryption requirements are instead tied to each participating nation's own health records law.

What edition of AMedP-5.3 is current?

Edition B, Version 1, promulgated in April 2025. It is effective on receipt and supersedes Edition A, Version 1, which nations were instructed to destroy under their own local procedure for document destruction.