Skip to main content

Getting Started with NEN 7510

NEN 7510 is the Dutch standard for information security in healthcare. It is based on ISO 27001 and ISO 27002 but adds healthcare-specific requirements for protecting patient data (persoonlijke gezondheidsinformatie). NEN 7510 compliance is effectively mandatory for all Dutch healthcare organizations under the Wbp (now superseded by GDPR/AVG) and is referenced by the Dutch Healthcare Inspectorate (IGJ) and the Dutch Data Protection Authority (AP). NEN 7510 consists of two parts:
  • NEN 7510-1 - Management system requirements (based on ISO 27001)
  • NEN 7510-2 - Implementation guidance (based on ISO 27002, with healthcare-specific controls)
Supplementary standards NEN 7512 (electronic communication) and NEN 7513 (logging of access to patient data) provide additional requirements that are commonly implemented alongside NEN 7510. Matproof maps NEN 7510 requirements to controls, policies, and evidence workflows so you can demonstrate compliance to the IGJ and AP.
Activate NEN 7510 under Settings - Frameworks - NEN 7510. Controls are pre-populated based on NEN 7510-1 and the healthcare-specific extensions in NEN 7510-2.

Am I in Scope?

NEN 7510 applies to any organization that processes patient health information in the Netherlands:
  • Hospitals, clinics, and GP practices
  • Mental healthcare institutions
  • Pharmacies and laboratories
  • Health insurers
  • Municipal health services (GGD)
  • IT service providers that process health data for healthcare organizations
  • Home care and long-term care providers
If you provide IT systems or services that process patient data for Dutch healthcare organizations, you are expected to comply with NEN 7510 even if you are not a healthcare provider yourself. This is typically enforced through contractual requirements and data processing agreements.

NEN 7510 Structure

Since NEN 7510 is based on ISO 27001/27002, it follows a familiar structure with healthcare additions:

Key Healthcare-Specific Extensions

NEN 7510-2 adds or strengthens controls in these areas compared to ISO 27002:
  • Access control for patient data - role-based access, break-glass procedures for emergencies, automatic session timeouts
  • Logging and auditability - all access to patient records must be logged with who, when, what, and why (NEN 7513)
  • Data exchange - electronic exchange of patient data must meet trust requirements (NEN 7512)
  • Mobile devices - specific controls for tablets, smartphones, and portable media used in clinical settings
  • Physical security - controls for clinical environments where patient data is visible on screens or printed


Relationship to Other Standards


Next Steps