What is NEN 7510, and to whom does the standard apply?

Healthcare organizations process sensitive information on a daily basis. This includes patient records, treatment information, medication records, and other personal data. This information must be properly protected. At the same time, healthcare providers must be able to rely on the fact that data is accurate and available when they need it.

NEN 7510 helps healthcare organizations systematically organize their information security. The standard covers not only technical security, but also policies, responsibilities, risks, employees, and suppliers.

But what exactly does NEN 7510 entail? Who is subject to this standard? And is a NEN 7510 certificate required? We’ll explain it in simple terms.

On this page

What is NEN 7510?

NEN 7510 is the Dutch standard for information security in the healthcare sector. The standard describes how healthcare organizations and other controllers of personal health information must organize their information security.

The goal is for health information to:

  • is treated confidentially;

  • remains accurate and complete;

  • is available when needed.

NEN 7510 therefore goes beyond simply installing antivirus software, a firewall, or a backup system. The standard examines the entire process by which an organization manages, implements, and monitors information security.

These include, for example:

  • responsibilities within the organization;

  • information security policy;

  • risk analyses;

  • user accounts and access rights;

  • device and system security;

  • agreements with IT vendors;

  • reporting and handling of incidents;

  • backups and recovery procedures;

  • periodic audits;

  • continuous improvement.

The current standard consists of NEN 7510-1:2024 and NEN 7510-2:2024. In 2026, Part 2 was supplemented with an amendment. The updated standard aligns with current international standards for information security and includes additional requirements for the healthcare sector.

Why is NEN 7510 important?

Information security in healthcare is not just about privacy. A system failure, incorrect configuration, human error, or cyberattack can also affect the quality and continuity of care.

A healthcare provider must have access to the right information at the right time. A healthcare organization must be able to trust that data has not been altered without authorization. It must also be clear who is authorized to view certain information.

NEN 7510 therefore focuses on three key areas.

Confidentiality

Only authorized individuals may view and use the information.

An employee should only have access to data that is necessary for performing their own job duties. The same applies to external vendors who manage or support systems.

Integrity

Information must remain accurate and complete.

Inaccurate or unchecked changes to health information can affect diagnoses, treatments, and medication. Organizations must therefore be able to verify who added, viewed, or modified the information.

Availability

Information and systems must be available when healthcare providers need them.

Among other things, this requires reliable systems, effective backups, recovery procedures, and plans for unexpected outages.

Who is subject to NEN 7510?

NEN 7510 is intended for healthcare providers and organizations that manage or process personal health information.

The size of the organization does not automatically make a difference in this regard. A small practice can fall short of the standard just as easily as a large hospital. Of course, the risks, systems, and necessary measures may differ.

Healthcare Providers

Healthcare providers that process personal data in digital healthcare systems must demonstrably comply with NEN 7510.

Examples include:

  • hospitals;

  • primary care practices;

  • primary care clinics;

  • dental offices;

  • pharmacies;

  • physical therapy practices;

  • mental health institutions;

  • home care organizations;

  • nursing homes;

  • organizations providing care for people with disabilities;

  • clinics;

  • laboratories;

  • independent treatment centers;

  • occupational health and safety services.

Smaller healthcare providers also fall within the scope of the standard. Therefore, having a limited number of employees or a small IT environment does not mean that NEN 7510 does not apply.

The way a small practice applies the standard does not have to be the same as in a hospital. Measures must be appropriate for the organization’s size, risks, and activities.

IT vendors and other service providers

Even organizations that do not provide healthcare themselves may have to comply with NEN 7510.

This applies especially to entities that store, manage, process, or exchange personal health information. Examples include:

  • providers of electronic patient records;

  • providers of electronic client records;

  • healthcare software providers;

  • hosting and cloud providers;

  • IT administrators;

  • managed service providers;

  • data centers;

  • backup providers;

  • laboratory system providers;

  • entities that facilitate digital data exchange.

Not every vendor plays the same role. A vendor that only supplies equipment has different responsibilities than an IT partner with administrative privileges who manages accounts, backups, workstations, and networks.

The specific responsibilities depend on the services provided, access to data, and the agreements with the healthcare organization.

Is NEN 7510 mandatory?

Healthcare providers must demonstrate that they operate in accordance with NEN 7510. The Health and Youth Care Inspectorate oversees information security within healthcare organizations.

Demonstrating compliance with the standard means that an organization must not only implement measures but also be able to show that these measures work effectively in practice.

For example, a healthcare organization must be able to demonstrate that:

  • Information security risks have been assessed;

  • responsibilities have been defined;

  • employees have appropriate access rights;

  • security measures have been implemented;

  • incidents are recorded and followed up on;

  • backups and recovery procedures have been established;

  • audits and evaluations are conducted;

  • areas for improvement are actually addressed.

So simply saying that information security is well managed is not enough.

Is a NEN 7510 certificate required?

A common misconception is that every healthcare organization is required to have a NEN 7510 certificate.

That is not the case.

A healthcare organization must demonstrably operate in accordance with NEN 7510 and have its information security regularly assessed by an independent body. Certification is one specific way to demonstrate this, but it is not the only option.

During the certification process, an independent certification body verifies that the information security management system complies with the standard. Periodic audits are conducted throughout the certificate’s validity period.

A certificate can be important for:

  • regulatory authorities;

  • clients;

  • health insurers;

  • collaborating partners;

  • customers and clients;

  • purchasers;

  • auditors.

Clients, business partners, or public procurement processes may also require certification as a contractual condition.

The most important question, therefore, is not merely whether a certificate is formally required. Above all, an organization must be able to demonstrate that it operates in accordance with the standard and that the measures it has implemented are actually effective.

What topics does NEN 7510 cover?

NEN 7510 consists of two parts.

NEN 7510-1: The Management System

The first part sets out requirements for the information security management system. This is also known as an Information Security Management System (ISMS).

These include, among other things:

  • policy;

  • roles and responsibilities;

  • risk analyses;

  • objectives;

  • available personnel and resources;

  • internal controls;

  • management reviews;

  • improvement measures.

The management system ensures that information security does not become a collection of isolated technical solutions. Policy, implementation, monitoring, and improvement must be interconnected.

NEN 7510-2: Safety Measures

The second section discusses the measures organizations can take to manage their risks.

For example:

  • identity and access management;

  • secure workstations;

  • network security;

  • logging and monitoring;

  • backups;

  • incident management;

  • vendor management;

  • business continuity;

  • physical security;

  • protection of cloud environments;

  • vulnerability management.

Not every measure needs to be implemented in exactly the same way at every organization. The organization must determine which measures are necessary based on risks and be able to justify the choices it has made.

What does NEN 7510 require of management?

Information security is still often viewed as the responsibility of the IT department or an external IT vendor. That view is too narrow.

Senior management remains responsible for how the organization manages information security.

Among other things, this means that the executive board:

  • establishes policy;

  • allocates responsibilities;

  • makes sufficient personnel and resources available;

  • commissions risk assessments;

  • evaluates decisions regarding measures and risks;

  • periodically monitors progress;

  • ensures that improvements are implemented.

An IT provider can implement and manage technical measures. However, the healthcare organization’s administrative responsibility cannot be fully outsourced.

What role does an IT supplier play?

An IT provider can assist a healthcare organization with a significant portion of its technical information security.

For example:

  • Securing Microsoft 365;

  • setting up multi-factor authentication;

  • managing accounts and access rights;

  • securing and managing workstations;

  • installing security updates;

  • network and firewall management;

  • monitoring;

  • backups;

  • recovery procedures;

  • logging;

  • support during security incidents.

To that end, the healthcare organization and the IT provider must establish clear agreements.

For example, who verifies that backups are performed correctly? Who revokes the accounts and access rights of departing employees? How quickly is a security incident reported? And what information does management receive regarding risks, incidents, and areas for improvement?

Without clear lines of responsibility, important measures may end up falling between the healthcare organization and the supplier.

Does NEN 7510 make an organization completely safe?

No. No standard can guarantee that an organization will never experience a system failure, human error, data breach, or cyberattack.

NEN 7510 does help to manage risks in a systematic way. An organization identifies risks, takes appropriate measures, and regularly checks whether these measures are working effectively.

An organization that properly implements NEN 7510, for example, knows that:

  • what information and systems are important;

  • what risks exist;

  • who is responsible;

  • what measures have been taken;

  • what to do in the event of an incident;

  • how data and systems are restored;

  • which vendors have access;

  • what improvements are still needed.

NEN 7510 therefore focuses primarily on control, demonstrability, and continuous improvement.

How do you get started with NEN 7510?

Working in accordance with NEN 7510 does not begin with applying for a certificate. First, it must be clear how the organization handles information, systems, and risks.

  1. Determine the scope: Identify which locations, departments, systems, processes, and suppliers are included in the assessment.

  2. Identify information and systems: Determine what personal health information is processed, where this information is stored, and who has access to it.

  3. Conduct a risk analysis: Identify existing threats and vulnerabilities and assess the potential consequences of an incident.

  4. Review existing controls: Examine which organizational, technical, and physical controls have already been implemented.

  5. Develop an improvement plan: Determine which measures are still needed. Set priorities based on risk, urgency, and feasibility.

  6. Define responsibilities: Clarify who is responsible for policies, systems, incidents, suppliers, and improvement actions.

  7. Have the effectiveness assessed: Have an independent audit conducted to verify that the organization demonstrably operates in accordance with the standard and that the measures function effectively in practice.

  8. Continue to monitor and improve: Information security is never complete. Systems, employees, threats, suppliers, and legal requirements are constantly changing.

NEN 7510 and Encis

Encis not only manages IT, but also ensures that it is done securely. Information security and data protection are therefore key components of our services.

Encis is certified to ISO 27001 and NEN 7510. In 2025, the company successfully renewed both certifications for the seventh consecutive year following an audit by KIWA.

Learn more about our ISO 27001 and NEN 7510 certifications. You can also read the news article about Encis’s recertification for ISO 27001 and NEN 7510.

This does not mean that a client automatically complies fully with NEN 7510 simply by partnering with Encis. The healthcare organization remains responsible for its own policies, risk analysis, internal processes, and the ability to demonstrate that the necessary measures have been taken.

However, you do work with an IT partner that understands the information security requirements in the healthcare sector and can demonstrate that it operates in accordance with these standards.

Among other things, we help organizations manage and secure:

Need help with technical information security?

Would you like to know which technical measures in your IT environment require attention?

Our specialists will review the configuration of your workstations, Microsoft 365 environment, network, access management, and backups, among other things. This will give you insight into technical risks and potential improvements.

Please contact Encis

Frequently Asked Questions About NEN 7510

NEN 7510 is the Dutch standard for information security in the healthcare sector. The standard sets out requirements and measures for the secure management and processing of personal health information.

The standard applies to healthcare providers that use digital healthcare systems and handle personal data. IT vendors and other organizations that manage or process personal health information may also fall within its scope.

Yes. Small healthcare providers must also demonstrate that they operate in accordance with NEN 7510. However, the implementation of the measures may be tailored to the size, risks, and complexity of the organization.

No. A certificate is not mandatory for every healthcare provider. However, healthcare organizations must demonstrate that they operate in accordance with the standard and have their information security independently assessed.

No. A certified IT provider can assist with technical and operational measures, but the healthcare organization remains responsible for matters such as policy, risks, internal processes, and controls.

Need help?
Email
Email
Phone
Phone