- Introduction
- Applicability and scope
- Clause 4: Context of the organization
- Clause 5: Leadership
- Clause 6: Planning
- Clause 7: Support
- Clause 8: Operation
- Clause 9: Performance evaluation
- Clause 10: Improvement
- Annex A: Healthcare-specific information security controls
- Challenges of implementing NEN 7510
- Benefits of implementing NEN 7510
- Best practices
- The ideal approach for companies in the Netherlands
Introduction
If your organization records, processes, or exchanges patient data in the Netherlands, NEN 7510 compliance is almost certainly a legal expectation rather than a voluntary nicety. NEN 7510-1 contains the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS). That system protects the availability, integrity, and confidentiality of personal health information through risk-based controls, and it is meant to be woven into the organization's wider procedures rather than bolted on as a separate IT exercise.
The standard exists because health data is uniquely sensitive and uniquely consequential. Inaccurate or unavailable records can affect a diagnosis or a treatment decision, so confidentiality alone is never enough. The December 2024 edition replaced NEN 7510-1:2017+A1:2020, folding in the structural changes from NEN-EN-ISO/IEC 27001:2023, the healthcare additions from ISO/DIS 27799:2024, and references to newer Dutch and European law. If you ran the older edition, the management system you built still largely applies; the clause numbering and a handful of requirements are what shifted.
Applicability and scope
The standard is written for organizations that deliver care or otherwise process personal health information, regardless of size or service model. Healthcare providers in scope range from large hospitals to solo practitioners, and the requirements extend to other controllers of health data as well as the processors acting on their behalf. If your firm hosts, exchanges, or reuses health data on a provider's instruction, you fall inside the scope even when you never see a patient.
Several entity types are subject to NEN 7510 compliance, including:
- Healthcare institutions such as hospitals, clinics, and long-term care providers
- Solo and independent care professionals operating as a practice
- Service providers for patients (DVPs) and for healthcare organizations (DVAs)
- Hosting providers, cloud vendors, and other suppliers to care organizations
- Municipalities, health insurers, and parties handling health data for secondary use
A few areas sit outside the standard's reach: The specific statistical methods for anonymizing data, the methods for pseudonymizing it, and the network quality-of-service measurement of healthcare networks. The topics themselves can still appear in the standard, but the underlying methodologies are not its concern.
Compliance levels and requirements
NEN 7510-1 carries the requirements from clauses 4 through 10 of NEN-EN-ISO/IEC 27001:2023, then supplements Annex A with healthcare-specific controls drawn from Part 2. This is because it follows the harmonized structure for management system standards, it integrates cleanly with other systems an organization may already run. You cannot pick and choose among clauses 4 through 10. Excluding any of them rules out a conformity claim. By working through them in order, the organization moves from understanding its context, to leadership, to planning, and on through operation, evaluation, and improvement.
The seven management clauses and the control annex cover:
- Clause 4 - Context of the organization: Define what the ISMS needs to achieve and where its boundaries lie.
- Clause 5 - Leadership: Secure top-management ownership, policy, and clear roles.
- Clause 6 - Planning: Run risk assessment and treatment, and set security objectives.
- Clause 7 - Support: Provide the resources, competence, and documentation the system needs.
- Clause 8 - Operation: Execute the plan and keep operational processes under control.
- Clause 9 - Performance evaluation: Monitor, audit, and review the system.
- Clause 10 - Improvement: Handle non-conformities and improve continually.
- Annex A - Controls: Apply organizational, people, physical, and technological controls, plus healthcare additions.
Clause 4: Context of the organization
This clause is where the organization works out what its information security management system actually has to do. It identifies the internal and external issues that bear on the ISMS, the interested parties whose requirements matter, and the legal and contractual obligations among them. The 2024 edition adds an explicit prompt to decide whether climate change is a relevant issue. The clause closes by fixing the ISMS scope as documented information, so everyone knows what the system covers.
Clause 5: Leadership
Leadership is not a delegated task under this standard. Top management has to demonstrate commitment by setting an information security policy aligned with the organization's strategic direction, integrating ISMS requirements into business processes, and making the necessary resources available. The same leadership assigns and communicates the roles, responsibilities, and authorities for information security, including who is accountable for the ISMS conforming to the standard and who reports its performance upward.
Clause 6: Planning
Planning is the analytical heart of healthcare information security management. The organization defines a repeatable risk assessment process that produces consistent, valid results, identifies risks to the confidentiality, integrity, and availability of information, names risk owners, and analyzes likelihood and impact. It then selects treatment options, compares the chosen controls against Annex A to confirm nothing necessary was missed, and produces a Statement of Applicability that justifies each inclusion and exclusion. Risk owners approve the treatment plan and accept any residual risk. The clause also requires measurable security objectives.
Clause 7: Support
Support is what keeps the management system running once it is designed. The organization has to provide the resources the ISMS needs, make sure the people working under its authority are competent through education, training, or experience, and ensure they are aware of the policy and the consequences of not following it. It also determines what internal and external communication is relevant, then decides what to communicate, when, to whom, and how. Documented information has to be created, controlled, and protected against loss of confidentiality or improper use.
Clause 8: Operation
Operation is where planning becomes practice. The organization plans, implements, and controls the processes needed to meet its requirements, sets criteria for those processes, and keeps documented evidence that they ran as intended. It carries out risk assessments at planned intervals or whenever significant changes are proposed, and it implements the risk treatment plan. You also have to control planned changes, assess the consequences of unintended ones, and make sure that processes, products, or services delivered by external parties stay under control.
Clause 9: Performance evaluation
A management system the organization never checks is one it cannot trust. This clause requires monitoring and measuring the right things at the right times using methods that yield comparable, reproducible results, then analyzing and evaluating both information security performance and ISMS effectiveness. Internal audits run at planned intervals to confirm the system meets the organization's own requirements and the standard's, and management review brings the results to top management along with risk status, audit findings, and improvement opportunities.
Clause 10: Improvement
Improvement closes the loop and feeds back into the next cycle. When a nonconformity occurs, the organization reacts to contain and correct it, deals with the consequences, and then evaluates whether action is needed to remove the root cause so it does not recur or surface elsewhere. Corrective actions have to be proportionate to the effects of the nonconformity, and the organization keeps records of both the issue and what was done about it. Alongside this, it improves the suitability, adequacy, and effectiveness of the ISMS continually.
Annex A: Healthcare-specific information security controls
Annex A is the normative reference list that organizations compare their chosen controls against. Its controls are drawn from Part 2 and grouped into four themes: organizational, people, physical, and technological. Controls whose titles carry the “HLT” marker are healthcare-specific and do not appear in Annex A of ISO/IEC 27001:2023; the rest supplement their ISO counterparts. This is where the standard turns generic security into care-sector practice.
A few of the healthcare-specific additions show what that means in concrete terms:
- Classify personal health information as confidential: Health data should be classified uniformly as confidential across the organization.
- Role-based access to health data: Access to personal health information should follow a role-based access policy.
- Two-factor authentication: Systems that process personal health information should require at least two-factor authentication.
- Encrypt health data on removable media and in backups: Personal health information should be encrypted on removable media and in backups.
- Uniquely identify care recipients: Processes should guarantee a single, unambiguous identity per care recipient and merge duplicate records.
- Emergency communication and external incident reporting: Plan fallback communication channels for ICT outages, and report incidents in line with legal obligations.
Challenges of implementing NEN 7510
Reaching NEN 7510 compliance can be demanding, especially for smaller practices and for organizations adapting a 2017-era management system to the 2024 structure.
Limited security resources in smaller practices
Many care professionals work solo or in small clinics that have no dedicated IT security staff. The standard acknowledges this reality, but the obligation to run a working management system does not shrink with headcount. You will often have to lean on external advisors or shared services to cover competencies your team does not hold in-house.
Balancing security against clinical access
Healthcare runs on fast, reliable access to the right record at the right moment. Controls that lock data down too tightly can slow clinicians or push them toward unsafe workarounds, which undermines both safety and effectiveness. Striking that balance, rather than maximizing security in isolation, is one of the harder judgment calls the standard forces.
Mapping a sprawling estate of data flows
The standard expects every information flow, inside and between organizations, plus the integration platforms that carry them, to appear in the asset inventory. In practice, health data is distributed across systems, devices, and jurisdictions, and many organizations discover how little of that estate was ever documented when they start.
Third-party and supply-chain exposure
Care organizations rely heavily on hosting providers, cloud services, and software vendors, each of which becomes a route into sensitive data. The organization has to assess the risks of external access, agree security requirements with every supplier, and monitor their practices over time, which is a continuous effort rather than a one-time contract clause.
Keeping pace with overlapping legislation
NEN 7510 sits inside a thickening web of Dutch and European law, from the GDPR and the Wkkgz to newer instruments like NIS 2 and the European Health Data Space. Tracking which obligations apply, and how they intersect with the standard, is a moving target that demands ongoing legal and compliance attention.
Benefits of implementing NEN 7510
The work of getting to NEN 7510 compliance pays back in ways that reach well beyond satisfying an inspector.
A demonstrable answer to legal obligations
Dutch law repeatedly points to the NEN 7510 series, and the Autoriteit Persoonsgegevens treats it as the reference for the GDPR's Article 32 security obligation in healthcare. Organizations that implement the standard's controls can credibly show they have taken the “appropriate technical and organizational measures” the law expects.
Accredited certification that travels
You can certify against NEN 7510-1 through the NCS 7510 scheme, which is approved under accreditation and overseen by the Dutch Accreditation Council. That certificate gives patients, partners, regulators, and insurers independent assurance rather than a self-declared claim.
Safer, more interoperable data exchange
Organizations that adopt it find it easier to exchange data securely with one another, both nationally and across borders, because the standard rests on the ISO 27001 family. Consistent security practice is what makes new forms of collaboration, from regional exchange to virtual care, workable rather than risky.
A real reduction in clinical risk
Protecting the integrity and availability of health information is not an abstract goal. When records are accurate and reachable when care is delivered, the controls directly help prevent the kind of errors that flow from corrupted or missing data, supporting both patient safety and continuity of care.
One system that satisfies many standards
The harmonized structure means the ISMS slots alongside other management systems an organization may already operate. Rather than maintaining parallel compliance programs, you can run a single integrated system that answers to two or more standards at once.
Best practices
If the goal is more than minimum compliance, a few practices pay off over the long run.
Governance and risk management
- Treat the asset and data-flow inventory as a living document, and revisit it whenever a new system or integration platform comes online so nothing stays unmapped.
- Keep the Statement of Applicability current, recording not just which controls apply but the justification for every inclusion and exclusion.
- Give information security risk the same standing in clinical governance as care planning and infection control, rather than parking it with the IT team.
Operational and technical implementation
- Apply role-based access and at least two-factor authentication to every system that touches personal health information.
- Encrypt personal health information wherever it is most exposed, including removable media and backups.
- Plan and test fallback communication channels in advance, so a continuity event does not leave clinical teams without a way to coordinate.
Auditability, training, and oversight
Run internal audits and management reviews on a fixed cadence, and feed their findings straight into the improvement loop.
Give management role-specific security training, since leadership accountability is an explicit requirement rather than an assumption.
Assess supplier and external-party access against the identified risk, and monitor those relationships rather than reviewing them only at renewal.
The ideal approach for companies in the Netherlands
NEN 7510 is the backbone of information security in Dutch healthcare. It protects data whose accuracy and availability can shape a diagnosis or a treatment, and Dutch law leans on it heavily enough that opting out is rarely a genuine option. Organizations that treat it as a one-off certification project tend to find the same gaps reopening at each audit, because the standard is built around a cycle of planning, operating, checking, and improving rather than a fixed end state.
The more useful way to approach it is as a capability you are building over time. Start from an honest reading of your context and your risks, secure real ownership from leadership, and let the management system mature through each review cycle. Done that way, NEN 7510 compliance stops being a hurdle in front of you and becomes part of how your organization earns and keeps the trust of the people whose health data it holds.

