Applications

IGJ Alarm on NEN 7510: Why GGZ Institutions Are Shifting to AI Log Audits in 2026

Geert Haisma

A critical IGJ report from May 2026 reveals that almost no large GGZ institution can demonstrate NEN 7510 compliance. Discover why healthcare executives are moving away from manual spot checks and deploying autonomous AI for structural EHR log audits.

IGJ Alarm on NEN 7510: Why GGZ Institutions Are Shifting to AI Log Audits in 2026

On May 27, 2026, the Dutch Health and Youth Care Inspectorate (IGJ) published a sobering report. Their large-scale investigation revealed that 93 percent of larger mental healthcare (GGZ) organizations could not demonstrate compliance with legal information security requirements. Only 6 out of 87 investigated institutions demonstrably operated according to the NEN 7510 standard. The inspectorate's reaction was uncompromising: supervision will be heavily intensified.

For healthcare executives, this is a clear warning. In 2026, information security is no longer a paper tiger or a simple compliance checklist. Especially now that the Cyberbeveiligingswet (Cbw) is in effect, the risks regarding director liability are significantly higher. In practice, the focal point of this organizational challenge almost always lies in one specific operational area: auditing EHR access logs.

The Unsustainability of Manual Wabvpz Audits

Electronic health records (EHR) contain the most intimate client data. Both the updated NEN 7510-1:2024 standard and the Dutch act on the processing of personal data in healthcare (Wabvpz) demand that organizations not only register who accesses a record, but also structurally verify whether this access is legitimate.

In daily operations, this process falls apart completely. A medium-sized GGZ institution easily generates millions of log entries every day. It is physically impossible for an information security department to manually review these volumes. The inevitable result is that many organizations are forced to fall back on incidental spot checks. This means that structural anomalies, such as an employee unlawfully viewing the file of an acquaintance, are only discovered after the reputational damage has already been done. This glaring lack of operational control is exactly why the regulator is stepping in.

ZIA: From Spot Checks to Autonomous AI Audits

To bridge this capacity gap, an increasing number of GGZ institutions are transitioning to automated solutions powered by artificial intelligence. Our AI Services, including the specialized autonomous agent ZIA, are explicitly designed to execute these types of complex data audits safely and efficiently.

Instead of having compliance officers scroll through Excel sheets for hours, the AI model continuously analyzes 100 percent of the generated log files. ZIA rapidly recognizes abnormal patterns in access rights, immediately flags suspicious combinations of users and patient records, and clearly reports the findings to the responsible executive. The compliance professional retains full control at all times, but the intensive preparatory data analysis is completely automated. This guarantees that your organization complies with the stringent NEN 7510 security requirements not only in theory, but also demonstrably in practice.

The Necessity of Scalable Information Security

The rapid intensification of IGJ supervision regarding NEN 7510 in mental healthcare in 2026 marks a direct turning point for many organizations. Waiting for a severe data breach or a formal directive from the inspectorate is simply no longer an option in the current compliance climate. The necessary technology to monitor EHR logs completely, safely, and proactively is available today and can be integrated directly into your existing healthcare systems.

Would you like to know how our autonomous AI solutions can help your institution effortlessly, efficiently, and demonstrably comply with strict NEN 7510 and Wabvpz regulations? Contact us directly via our contact page and discover what AI can do for your information security in a no-obligation demonstration.

Data PrivacyAgentic AIAutomationPublic Sector

Geert Haisma

Director

Geert Haisma is the co-founder and director of PrudAI, an AI specialist that supports organizations in securely and custom-deploying generative AI for improved decision-making and process automation. With a background in public administration and years of experience in making organizations more successful, Haisma is the driving force behind PrudAI's strategic and substantive direction.