AI blog ISMS software
Information security in healthcare - NEN 7510:2024 in healthcare
NEN 7510:2024: compliance, certification and a practical step-by-step plan
How does your healthcare organization become demonstrably compliant — without certification necessarily being necessary?
Introduction
Many organizations wonder whether NEN 7510 is mandatory and whether they also need to obtain a NEN 7510 certificate. The answer is nuanced. Healthcare providers who process personal health information in a healthcare information system must demonstrably meet the requirements of NEN 7510. A certificate is not always required by law, but it does provide powerful and independent confirmation that information security is structurally set up and periodically tested.
Summary
NEN 7510 is the standard for information security in Dutch healthcare. Organizations must not only take appropriate security measures, but also be able to demonstrate that they actually work. This can be done by means of a well-designed Information Security Management System (ISMS), internal audits, risk analyses and continuous improvements. NEN 7510 certification is a voluntary, but widely used way to have this demonstrability independently assessed.
NEN 7510 is mandatory for healthcare organizations that work digitally with patient data
Does your healthcare organisation process patient or client data in a digital healthcare information system? Then you must demonstrably work in accordance with NEN 7510. The standard describes how to manage information security, manage risks and implement appropriate organisational and technical measures. So it's not just about a secure electronic health record, strong passwords or multi-factor authentication. NEN 7510 requires a working Information Security Management System (ISMS): a coherent system of policy, responsibilities, risk analyses, control measures, controls, audits and improvement actions.
Important distinction: compliance with NEN 7510 is mandatory when the standard applies to your organization. Obtaining a formal NEN 7510 certificate is not required by law. However, you must be able to demonstrate with objective evidence that the ISMS and the chosen control measures actually work.
What is the difference between compliance and certification?
| Subject |
Comply with NEN 7510 |
NEN 7510 certification |
| Meaning |
Your organisation has entered the requirements of the standard appropriately and can demonstrate its effectiveness. |
An accredited certifying body has assessed the ISMS and issued a certificate. |
| Obligation |
For healthcare providers who process personal health information in a healthcare information system: yes. |
No, certification is a voluntary, formal way of demonstrating. |
| Proof |
For example, an expert independent assessment, audit reports, risk and control evidence, registrations and demonstrable improvement cycles. |
A valid certificate, periodic audits and follow-up of findings within the certification scheme. |
| Added value |
Focused on factual control and legal demonstrability. |
Gives patients, clients, chain partners and regulators extra confidence and can be requested in tenders. |
Certification is therefore not the same as compliance. A certificate is a powerful means of proof, but the daily operation remains decisive. Conversely, it is possible to comply without a certificate, provided that the organization can convincingly demonstrate through an independent and expert assessment that it applies both parts of the standard and that information security works in practice.
The current standard is NEN 7510:2024
Since December 16, 2024, NEN 7510:2024 has been the current version. The new edition is in line with the updated international standards ISO/IEC 27001:2022 and ISO/IEC 27002:2022 and incorporates the healthcare-specific context into an updated structure of requirements and control measures. Organizations that are still working with documentation, risk analyses and controls from NEN 7510:2017 must therefore carry out a targeted transition. Just renaming texts is not enough: the scope, risks, declaration of applicability, control measures, evidence and internal controls must be reassessed against the 2024 version.
Deadline for existing certificates: organisations with a certificate against the old standard must have converted this to a certificate against NEN 7510:2024 by 20 February 2027 at the latest. After that, an old certificate is no longer sufficient as current proof of certification.
A practical step-by-step plan to a demonstrable level of NEN 7510
The fastest route is not to start with separate documents, but with a manageable program: clear scope, ownership, risk-driven priorities, appropriate controls and central evidence.
Determine scope, context, and responsibilities
Determine which healthcare processes, locations, systems, suppliers, links and types of personal health information fall within the ISMS. Appoint management ownership, process owners, the information security function and control owners.
Perform a baseline measurement and gap analysis
Compare the current situation with NEN 7510:2024. Assess not only whether documents exist, but also whether employees follow the agreements and whether checks are demonstrably carried out. Record the status, owner, burden of proof and required improvement action for each requirement.
Update the risk analysis and treatment plan
Identify threats to confidentiality, integrity, and availability of health information. Assess opportunity and impact, choose measures, accept residual risks at the right level and link improvement actions to a realistic schedule.
Build a NEN 7510:2024 control framework
Translate standard requirements into concrete, verifiable controls. Link every control to risks, policies, processes, systems, owners, test frequencies and evidence. Also make the relationship visible with, for example, ISO 27001, GDPR, NIS2/Cybersecurity Act and contractual requirements.
Implement policies and controls
Work focused on topics such as access security, logging, vendor management, incident management, backup and recovery, continuity, secure system architecture, awareness, physical security, and asset management.
Collect demonstrable evidence of operation
Record not only what has been agreed, but also what has been carried out: assessments, log checks, test results, training registrations, supplier reviews, incidents, remediation tests, decisions, exceptions and corrective actions.
Conduct internal audits and management reviews
Have it independently tested whether the ISMS covers both parts of the standard and works effectively. Discuss performance, risks, deviations, and improvements in the management review. Turn findings into manageable actions with owner and deadline.
Choose the desired form of external demonstrability
Based on legislation, customer questions and organizational goals, choose an independent assessment or formal certification. For an existing certificate, plan to switch to NEN 7510:2024 well before 20 February 2027.
Which parts must be demonstrably set up?
The exact interpretation depends on size, context and risks. In practice, a mature ISMS contains at least up-to-date and managed information about:
- Scope and context of the ISMS
- Information security policy and objectives
- Roles, tasks, responsibilities and powers
- Risk analysis, risk treatment and residual risk acceptance
- Statement of applicability
- Management of documents and registrations
- Access and authorization policies
- Asset Management
- Supply and supply chain security
- Logging and monitoring
- Incident Management
- Backup, recovery and business continuity
- Awareness, training and competencies
- Internal audits and independent assessments
- Management reviews
- Deviations and corrective actions
An ISMS in spreadsheets, individual Word documents, e-mail and shared folders seems simple at first, but quickly becomes difficult to manage. Versions vary, responsibilities are unclear, evidence is scattered and preparing for an audit takes an unnecessary amount of time. Dedicated management system or GRC tooling brings together policies, risks, controls, actions, registrations, audits and evidence. This creates one manageable environment in which you can see who is responsible for what, when an audit must take place, which deviations are still open and whether the organization is demonstrably in control.
The combination with a control framework
Tooling is most powerful when it is set up around a control framework. The framework forms the substantive backbone; The software supports the execution and evidence. For each control you can record:
- which NEN 7510 requirement and which risk are covered;
- which policy, process, system or supplier is relevant;
- who owns the control;
- how and how often the operation is tested;
- what supporting documents are required;
- what findings, exceptions and actions are open;
- which other frameworks are supported with the same control.
This prevents duplication of work. One well-designed control can provide evidence for multiple obligations. Moreover, the approach makes communication between management, healthcare, IT, privacy, security and auditors much easier. The standard thus does not become a pile of documentation, but a continuously controllable part of the business operations.
From one-off project to continuous control
The goal is not to collect documents just before an audit. An organization only meets convincingly when it can continuously demonstrate that risks are assessed, controls work, incidents and deviations are followed up and management makes timely adjustments. A clear step-by-step plan, a practical control framework and appropriate dedicated tooling make that movement feasible. They provide overview, ownership, consistent evidence and a shorter preparation for independent assessments or certification.
Conclusion
For healthcare organizations, the question is therefore not so much about whether information security is mandatory, but mainly about how it can be demonstrated that the legal requirements are met. A well-implemented ISMS forms the basis for this. Those who also opt for NEN 7510 certification increase the confidence of patients, chain partners, clients and regulators by having it independently established that the organization meets the standard.