Getting Started with NEN 7510
NEN 7510 is the Dutch standard for information security in healthcare. It is based on ISO 27001 and ISO 27002 but adds healthcare-specific requirements for protecting patient data (persoonlijke gezondheidsinformatie). NEN 7510 compliance is effectively mandatory for all Dutch healthcare organizations under the Wbp (now superseded by GDPR/AVG) and is referenced by the Dutch Healthcare Inspectorate (IGJ) and the Dutch Data Protection Authority (AP). NEN 7510 consists of two parts:- NEN 7510-1 - Management system requirements (based on ISO 27001)
- NEN 7510-2 - Implementation guidance (based on ISO 27002, with healthcare-specific controls)
Activate NEN 7510 under Settings - Frameworks - NEN 7510. Controls are pre-populated based on NEN 7510-1 and the healthcare-specific extensions in NEN 7510-2.
Am I in Scope?
NEN 7510 applies to any organization that processes patient health information in the Netherlands:- Hospitals, clinics, and GP practices
- Mental healthcare institutions
- Pharmacies and laboratories
- Health insurers
- Municipal health services (GGD)
- IT service providers that process health data for healthcare organizations
- Home care and long-term care providers
NEN 7510 Structure
Since NEN 7510 is based on ISO 27001/27002, it follows a familiar structure with healthcare additions:Key Healthcare-Specific Extensions
NEN 7510-2 adds or strengthens controls in these areas compared to ISO 27002:- Access control for patient data - role-based access, break-glass procedures for emergencies, automatic session timeouts
- Logging and auditability - all access to patient records must be logged with who, when, what, and why (NEN 7513)
- Data exchange - electronic exchange of patient data must meet trust requirements (NEN 7512)
- Mobile devices - specific controls for tablets, smartphones, and portable media used in clinical settings
- Physical security - controls for clinical environments where patient data is visible on screens or printed
Recommended Implementation Plan
Relationship to Other Standards
Next Steps
- Controls - working through NEN 7510-2 healthcare controls
- Risk Management - healthcare-specific risk assessments
- Vendor Risk - managing processors handling patient data
- Audit Programs - internal audit and certification preparation