Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of Compliance13 services in this practice area

Secure Dutch Health Data

NEN 7510 Healthcare Information Security Certification

NEN 7510 is the Dutch standard for information security in healthcare. We help organisations that handle Dutch health data build and certify a compliant management system.

See the engagement path, 6 phasesSee the full Compliance service index

Overview

NEN 7510 is the Netherlands standard for managing information security when you handle health data. It builds on ISO 27001 and adds sector-specific controls from NEN 7512 and NEN 7513, covering trust in data exchange and logging of access to patient records. It matters because Dutch healthcare providers and their suppliers are expected to meet it, and it aligns your security with both national rules and the GDPR. We help you extend an ISO 27001 base into a NEN 7510 programme and certify it.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the NEN 7510 engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Gap Assessment. We set the scope for handling Dutch health data and measure you against NEN 7510 and its companion standards. Activities: Define the scope covering Dutch health data flows; Assess controls against NEN 7510 requirements; Compare against the existing ISO 27001 baseline; Rank healthcare-specific gaps by risk. Hands over NEN 7510 Gap Assessment Report. Phase 2, Healthcare Risk Assessment. We assess the risks specific to patient data, including access logging and secure exchange. Activities: Identify risks to patient record confidentiality; Assess access paths to health data; Review secure exchange with care partners; Score risks and agree treatment priorities. Hands over Healthcare Risk Assessment Report. Phase 3, Control Design. We design the sector controls from NEN 7512 for trusted exchange and NEN 7513 for access logging. Activities: Design NEN 7513 access logging for patient records; Specify NEN 7512 trusted exchange controls; Extend ISMS policies with healthcare requirements; Define log review roles and retention. Hands over Sector Control Design and Policy Updates. Phase 4, Implementation Support. We help you roll out the controls and start collecting the evidence auditors expect. Activities: Implement access logging on patient record systems; Roll out exchange controls with care partners; Train staff on health data handling rules; Start collecting audit evidence. Hands over Operating Controls and Evidence Trail. Phase 5, Internal Audit. We audit the management system against NEN 7510 and log findings for management review. Activities: Audit the management system against NEN 7510; Sample access logs and exchange records; Log nonconformities and corrective actions; Prepare management review inputs. Hands over Internal Audit Report. Phase 6, Certification Support. We support you through the certification audit, often alongside ISO 27001. Activities: Prepare the evidence pack for the certification body; Coordinate the audit with ISO 27001 where combined; Support auditor interviews with control owners; Close findings raised during the audit. Hands over NEN 7510 Certificate. Each phase begins from the artefact the phase before it produced.

Phase 01 Scoping and Gap Assessment

We set the scope for handling Dutch health data and measure you against NEN 7510 and its companion standards.

What Happens In This Phase

  • Define the scope covering Dutch health data flows
  • Assess controls against NEN 7510 requirements
  • Compare against the existing ISO 27001 baseline
  • Rank healthcare-specific gaps by risk

The Handover

NEN 7510 Gap Assessment Report

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Scoping and Gap Assessment

    We set the scope for handling Dutch health data and measure you against NEN 7510 and its companion standards.

    OutputNEN 7510 Gap Assessment Report

    Activities

    • Define the scope covering Dutch health data flows
    • Assess controls against NEN 7510 requirements
    • Compare against the existing ISO 27001 baseline
    • Rank healthcare-specific gaps by risk
  2. 02

    Healthcare Risk Assessment

    We assess the risks specific to patient data, including access logging and secure exchange.

    OutputHealthcare Risk Assessment Report

    Activities

    • Identify risks to patient record confidentiality
    • Assess access paths to health data
    • Review secure exchange with care partners
    • Score risks and agree treatment priorities
  3. 03

    Control Design

    We design the sector controls from NEN 7512 for trusted exchange and NEN 7513 for access logging.

    OutputSector Control Design and Policy Updates

    Activities

    • Design NEN 7513 access logging for patient records
    • Specify NEN 7512 trusted exchange controls
    • Extend ISMS policies with healthcare requirements
    • Define log review roles and retention
  4. 04

    Implementation Support

    We help you roll out the controls and start collecting the evidence auditors expect.

    OutputOperating Controls and Evidence Trail

    Activities

    • Implement access logging on patient record systems
    • Roll out exchange controls with care partners
    • Train staff on health data handling rules
    • Start collecting audit evidence
  5. 05

    Internal Audit

    We audit the management system against NEN 7510 and log findings for management review.

    OutputInternal Audit Report

    Activities

    • Audit the management system against NEN 7510
    • Sample access logs and exchange records
    • Log nonconformities and corrective actions
    • Prepare management review inputs
  6. 06

    Certification Support

    We support you through the certification audit, often alongside ISO 27001.

    OutputNEN 7510 Certificate

    Activities

    • Prepare the evidence pack for the certification body
    • Coordinate the audit with ISO 27001 where combined
    • Support auditor interviews with control owners
    • Close findings raised during the audit

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Built by SecureRoot

TrustGrid

Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.

Built by SecureRoot

DPDPA Compass

Our own privacy platform. Consent, notices, data principal requests and records of processing under the DPDP Act.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the NEN 7510 scope, running left to right in three stages. Stage one, what we run, 7 tools and techniques: Vanta, Sprinto, Scrut, Microsoft Purview, Splunk, Jira, Confluence. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: NEN 7510:2017, NEN 7512, NEN 7513, ISO/IEC 27001:2022, GDPR.

What We Run

7 tools

  • Vanta
  • Sprinto
  • Scrut
  • Microsoft Purview
  • Splunk
  • Jira
  • Confluence

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

5 standards

  • NEN75102017
  • NEN7512
  • NEN7513
  • ISO/IEC 27001:2022
  • GDPR
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Gap assessment report
  • Healthcare risk assessment
  • Access logging control design
  • NEN 7510 policy set
  • Certification audit support

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

How does NEN 7510 relate to ISO 27001?

NEN 7510 is based on ISO 27001 and adds healthcare-specific controls. If you already run an ISMS, we extend it rather than start over.

Who needs NEN 7510?

Dutch healthcare providers and any supplier that processes Dutch health data on their behalf. Buyers in that sector increasingly require it.

What do NEN 7512 and NEN 7513 cover?

NEN 7512 covers trust in the electronic exchange of health data, and NEN 7513 covers logging access to patient records. Both sit within a NEN 7510 programme.

Keep Moving Through Compliance

Service 11 of 13 in this practice area