Information security in Dutch healthcare — technische maatregelen.
See your NEN 7510 readiness in 60 seconds. Free, no signup.
NEN 7510 is the mandatory information security standard for organisations processing patient data in the Netherlands. It builds on ISO 27001 with healthcare-specific controls. Inspectie Gezondheidszorg en Jeugd (IGJ) and Autoriteit Persoonsgegevens (AP) actively audit against it.
All Dutch healthcare providers, healthcare insurers and parties that process patient information on their behalf.
AP fines up to €20M / 4% of turnover (via AVG/GDPR linkage) + IGJ enforcement.
Each row links a NEN 7510 clause to the external check we perform and the evidence it produces. Mappings are reviewed by our compliance team and updated when standards change.
| NEN 7510 clause | What it requires | How we evidence it |
|---|---|---|
TLS-1 10.1 Cryptografische beheersmaatregelen | Versleuteling moet worden toegepast om de vertrouwelijkheid en integriteit van patiëntgegevens in transit te beschermen. | Encrypted transport (TLS 1.2+) We verify the certificate chain, expiry, supported TLS versions and cipher suites on every public hostname. |
EMAIL-1 13.2 Informatietransport | Beleid en procedures voor veilig elektronisch berichtenverkeer, inclusief authenticiteit van e-mail. | Email authentication (SPF / DKIM / DMARC) We resolve and validate SPF, DKIM and DMARC records, including DMARC enforcement policy and reporting addresses. |
WEB-1 13.1 Beheer van netwerkbeveiliging | Netwerken die patiëntgegevens dragen worden beveiligd; publieke webservices moeten gehard zijn. | Secure HTTP response headers We test for HSTS, Content-Security-Policy, X-Frame-Options, Referrer-Policy, Permissions-Policy and X-Content-Type-Options on the live site. |
DNS-1 13.1.2 Beveiliging van netwerkdiensten | Beveiligingsmechanismen, dienstverleningsniveaus en beheereisen van netwerkdiensten worden vastgesteld. | DNS hygiene & DNSSEC We resolve A, AAAA, MX, NS, CAA and DNSSEC records and flag anomalies, dangling records and missing controls. |
REP-1 12.6 Beheer van technische kwetsbaarheden | Informatie over technische kwetsbaarheden van gebruikte systemen wordt tijdig verkregen en beoordeeld. | Reputation & threat intelligence We cross-check the domain and its IPs against VirusTotal, Shodan, Spamhaus, URLhaus and Google Safe Browsing. |
BREACH-1 16.1 Beheer van informatiebeveiligingsincidenten | Detectie van datalekken (waaronder gelekte inloggegevens) en formele meldprocedure aan AP en betrokkenen. | Credential exposure monitoring We query Have I Been Pwned for breaches involving the monitored domain and surface affected accounts. |
EXP-1 9.4 Toegangsbeveiliging tot systemen en toepassingen | Voorkom onbedoelde openbare toegankelijkheid van systeembestanden en beheerinterfaces. | Exposed files & admin panels We probe for publicly accessible .env, .git, backups, admin panels and other sensitive paths that should never be reachable. |
SUB-1 8.1 / 15.1 Bedrijfsmiddelen & leveranciersrelaties | Een actueel overzicht van informatiemiddelen en externe verwerkers — inclusief derde-partij diensten die op publieke domeinen worden geladen (third-party data flow map). | Third-party data flow map (subdomains & external services) We enumerate subdomains via Certificate Transparency logs, fingerprint every third-party service they load (analytics, payments, chat, CDNs, tag managers, ad networks, fonts) and map where browser-side data flows. This is the externally-observable evidence regulators ask for under supplier, supply-chain and processor-inventory clauses. |
External monitoring is one part of compliance. These areas need other evidence — typically from your GRC platform, HR system, or internal logging:
One scan. Every clause on this page evaluated against your live domain. Auditor-ready PDF in your inbox.
Annex A controls auto-evidenced from the public attack surface.
Article 21 cybersecurity measures + Article 23 incident reporting.
Continuous evidence for CC6 (logical access) and CC7 (system operations).
Article 32 security of processing + Article 33 breach notification.
Digital Operational Resilience Act for financial entities.
External requirements for any business handling cardholder data.
We use strictly necessary cookies to run the site, and — only with your consent — analytics and marketing cookies (Google Analytics, Google Tag Manager) to improve the product. You can change your choice anytime via "Cookie preferences" in the footer. Privacy Policy · Sub-processors