Secure Dutch Health Data
NEN 7510 Healthcare Information Security Certification
NEN 7510 is the Dutch standard for information security in healthcare. We help organisations that handle Dutch health data build and certify a compliant management system.
See the engagement path, 6 phasesSee the full Compliance service index
Overview
NEN 7510 is the Netherlands standard for managing information security when you handle health data. It builds on ISO 27001 and adds sector-specific controls from NEN 7512 and NEN 7513, covering trust in data exchange and logging of access to patient records. It matters because Dutch healthcare providers and their suppliers are expected to meet it, and it aligns your security with both national rules and the GDPR. We help you extend an ISO 27001 base into a NEN 7510 programme and certify it.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the NEN 7510 engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Gap Assessment. We set the scope for handling Dutch health data and measure you against NEN 7510 and its companion standards. Activities: Define the scope covering Dutch health data flows; Assess controls against NEN 7510 requirements; Compare against the existing ISO 27001 baseline; Rank healthcare-specific gaps by risk. Hands over NEN 7510 Gap Assessment Report. Phase 2, Healthcare Risk Assessment. We assess the risks specific to patient data, including access logging and secure exchange. Activities: Identify risks to patient record confidentiality; Assess access paths to health data; Review secure exchange with care partners; Score risks and agree treatment priorities. Hands over Healthcare Risk Assessment Report. Phase 3, Control Design. We design the sector controls from NEN 7512 for trusted exchange and NEN 7513 for access logging. Activities: Design NEN 7513 access logging for patient records; Specify NEN 7512 trusted exchange controls; Extend ISMS policies with healthcare requirements; Define log review roles and retention. Hands over Sector Control Design and Policy Updates. Phase 4, Implementation Support. We help you roll out the controls and start collecting the evidence auditors expect. Activities: Implement access logging on patient record systems; Roll out exchange controls with care partners; Train staff on health data handling rules; Start collecting audit evidence. Hands over Operating Controls and Evidence Trail. Phase 5, Internal Audit. We audit the management system against NEN 7510 and log findings for management review. Activities: Audit the management system against NEN 7510; Sample access logs and exchange records; Log nonconformities and corrective actions; Prepare management review inputs. Hands over Internal Audit Report. Phase 6, Certification Support. We support you through the certification audit, often alongside ISO 27001. Activities: Prepare the evidence pack for the certification body; Coordinate the audit with ISO 27001 where combined; Support auditor interviews with control owners; Close findings raised during the audit. Hands over NEN 7510 Certificate. Each phase begins from the artefact the phase before it produced.
Phase 01 Scoping and Gap Assessment
We set the scope for handling Dutch health data and measure you against NEN 7510 and its companion standards.
What Happens In This Phase
- Define the scope covering Dutch health data flows
- Assess controls against NEN 7510 requirements
- Compare against the existing ISO 27001 baseline
- Rank healthcare-specific gaps by risk
The Handover
NEN 7510 Gap Assessment Report
The next phase starts from this.
Phase 01 Scoping and Gap Assessment
We set the scope for handling Dutch health data and measure you against NEN 7510 and its companion standards.
What Happens In This Phase
- Define the scope covering Dutch health data flows
- Assess controls against NEN 7510 requirements
- Compare against the existing ISO 27001 baseline
- Rank healthcare-specific gaps by risk
The Handover
NEN 7510 Gap Assessment Report
The next phase starts from this.
- 01
Scoping and Gap Assessment
We set the scope for handling Dutch health data and measure you against NEN 7510 and its companion standards.
OutputNEN 7510 Gap Assessment ReportActivities
- Define the scope covering Dutch health data flows
- Assess controls against NEN 7510 requirements
- Compare against the existing ISO 27001 baseline
- Rank healthcare-specific gaps by risk
- 02
Healthcare Risk Assessment
We assess the risks specific to patient data, including access logging and secure exchange.
OutputHealthcare Risk Assessment ReportActivities
- Identify risks to patient record confidentiality
- Assess access paths to health data
- Review secure exchange with care partners
- Score risks and agree treatment priorities
- 03
Control Design
We design the sector controls from NEN 7512 for trusted exchange and NEN 7513 for access logging.
OutputSector Control Design and Policy UpdatesActivities
- Design NEN 7513 access logging for patient records
- Specify NEN 7512 trusted exchange controls
- Extend ISMS policies with healthcare requirements
- Define log review roles and retention
- 04
Implementation Support
We help you roll out the controls and start collecting the evidence auditors expect.
OutputOperating Controls and Evidence TrailActivities
- Implement access logging on patient record systems
- Roll out exchange controls with care partners
- Train staff on health data handling rules
- Start collecting audit evidence
- 05
Internal Audit
We audit the management system against NEN 7510 and log findings for management review.
OutputInternal Audit ReportActivities
- Audit the management system against NEN 7510
- Sample access logs and exchange records
- Log nonconformities and corrective actions
- Prepare management review inputs
- 06
Certification Support
We support you through the certification audit, often alongside ISO 27001.
OutputNEN 7510 CertificateActivities
- Prepare the evidence pack for the certification body
- Coordinate the audit with ISO 27001 where combined
- Support auditor interviews with control owners
- Close findings raised during the audit
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
Built by SecureRoot
TrustGrid
Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.
Built by SecureRoot
DPDPA Compass
Our own privacy platform. Consent, notices, data principal requests and records of processing under the DPDP Act.
What Is Examined, and What it Is Measured Against
Map
Map of the NEN 7510 scope, running left to right in three stages. Stage one, what we run, 7 tools and techniques: Vanta, Sprinto, Scrut, Microsoft Purview, Splunk, Jira, Confluence. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: NEN 7510:2017, NEN 7512, NEN 7513, ISO/IEC 27001:2022, GDPR.
What We Run
7 tools
- Sprinto
- Microsoft Purview
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
5 standards
- NEN2017
- NEN
- NEN
Deliverables
What You Receive
- Gap assessment report
- Healthcare risk assessment
- Access logging control design
- NEN 7510 policy set
- Certification audit support
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
How does NEN 7510 relate to ISO 27001?
NEN 7510 is based on ISO 27001 and adds healthcare-specific controls. If you already run an ISMS, we extend it rather than start over.
Who needs NEN 7510?
Dutch healthcare providers and any supplier that processes Dutch health data on their behalf. Buyers in that sector increasingly require it.
What do NEN 7512 and NEN 7513 cover?
NEN 7512 covers trust in the electronic exchange of health data, and NEN 7513 covers logging access to patient records. Both sit within a NEN 7510 programme.
Keep Moving Through Compliance
Service 11 of 13 in this practice area
Practice Area
More in Compliance
- ISO 27001Build and certify your information security management system.
- ISO 27701Extend your ISMS into a privacy information management system.
- ISO 22301Certify how your business keeps running through disruption.
- ISO 42001Govern your AI systems with the first AI management standard.
- DPDP ActGet ready for India's Digital Personal Data Protection Act.
- PCI DSSProtect cardholder data and pass your PCI assessment.
- HIPAAProtect health information and meet HIPAA requirements.
- SOC 2Earn a SOC 2 report your customers can trust.
- CCPAMeet California's consumer privacy requirements.
- GDPRMeet Europe's data protection standard with confidence.
- EU AI ActPrepare for Europe's risk-based AI regulation.
- Third Party Risk Assessment (TPRM)Understand and manage the risk your vendors bring.