NEN 7510 is the Dutch standard for information security in healthcare, and every Dutch care provider must be able to show that it complies. A certificate is not mandatory, but a regular independent assessment is, and that is what the Dutch Health and Youth Care Inspectorate (IGJ) asks to see. If you use AI with client data, that application falls under the same system of risk assessment, access control, logging and supplier agreements.
Key points
- NEN 7510 is mandatory through the Wabvpz, the Dutch act that adds healthcare-specific rules to the GDPR, and the Begz decree based on it. Since 1 June 2026 the legal reference has been NEN 7510-1:2024 and NEN 7510-2:2024+A1:2026.
- Certification is optional. You must show that your management system works, with an independent assessment at least once every three years.
- When the IGJ examined 87 larger mental healthcare organisations, only 6 could show that they work to the standard (May 2026).
- If the Cyberbeveiligingswet (the Dutch NIS2 act, in force since 15 August 2026) applies to you, you meet its duty of care with NEN 7510, with ISO 27001 and 27002, or with an equivalent level. For your care information systems, NEN 7510 remains mandatory through the Wabvpz. The IGJ supervises the Cbw too.
- AI does not change the standard, but it adds homework: a DPIA, a data processing agreement, traceable access, as little data as possible going to the language model, and a care worker who checks.

Diagram: how NEN 7510, NEN 7512, NEN 7513, ISO 27001, the Wabvpz, the Begz decree and the Cbw fit together, with the AP and IGJ as supervisors, Z-CERT as the healthcare cyber-incident expertise centre, and four AI points of attention
What is NEN 7510?
NEN 7510 describes how a healthcare organisation sets up and keeps improving its information security. At its core is an information security management system (ISMS). That is not a binder of policies but a cycle: you assess risks, choose measures, check whether they work and adjust.
The standard has two parts. NEN 7510-1 sets the requirements for the management system and is the Dutch counterpart of ISO/IEC 27001. NEN 7510-2 describes the controls, such as access management, backups and logging. It combines ISO/IEC 27002 with ISO 27799, the international guideline for information security in health.
NEN 7510 applies to organisations, not to products. According to NEN, an app cannot be "NEN 7510 compliant" on its own: the care organisation makes sure its systems are used securely. Thanks to an agreement between the Dutch health ministry (VWS) and NEN, you can read NEN 7510, 7512 and 7513 free of charge on NEN Connect. They exist in Dutch only.
Which version of NEN 7510 applies now?
The current version is NEN 7510:2024. NEN published both parts in December 2024, replacing the 2017 versions. The revision aligns with ISO/IEC 27001:2022 and ISO/IEC 27002:2022.
On 1 March 2026 an amendment to part 2 followed: NEN 7510-2:2024+A1:2026. It aligns the standard with the final version of ISO 27799 and tightens several healthcare-specific controls. Annex E now maps NEN 7510-2 to the Cyberbeveiligingswet instead of to NIS2.
Legally, a new edition only counts once the minister announces it. The minister decided this on 7 May 2026; the decision was published in the Staatscourant on 18 May 2026. Since 1 June 2026, NEN 7510-1:2024 and NEN 7510-2:2024+A1:2026 have been the legal standard. Do you hold a certificate against the old version? According to NEN, it must be converted to NEN 7510:2024 by 20 February 2027.
Is NEN 7510 mandatory for care providers?
Yes. Every care provider that processes client data electronically must work to NEN 7510. This follows from the Wabvpz (Wet aanvullende bepalingen verwerking persoonsgegevens in de zorg). Article 15j of that act allows rules on the security of care information systems. Those rules are in the Begz (Besluit elektronische gegevensverwerking door zorgaanbieders).
Article 3 of the Begz requires care providers to use their information system "in accordance with NEN 7510 and NEN 7512". Article 5 requires logging that meets NEN 7513. The Dutch rules on using the citizen service number (BSN) in healthcare also refer to NEN 7510.
The obligation applies to large and small alike. According to the IGJ, it covers "smaller care providers and sole traders" too. Only youth care providers follow ISO 27001 instead, a standard closely resembling NEN 7510, through the Youth Act.
Three misunderstandings come up often:
- "We comply with the GDPR, so we comply with NEN 7510." No. The GDPR asks for appropriate measures. NEN 7510 spells them out for healthcare and goes further.
- "Our IT supplier complies, so we do too." No. According to the IGJ you remain responsible yourself. You put security requirements in your contracts and assess your suppliers' services.
- "We need a certificate." No again. What the IGJ does ask for is set out below.
What is the difference between NEN 7510 and ISO 27001?
ISO/IEC 27001 is the international standard for an information security management system in any sector. NEN 7510-1 follows that structure and NEN 7510-2 adds the healthcare controls from ISO 27799. So if you meet NEN 7510, you have covered most of ISO 27001. The reverse is not true.
For suppliers, the type of information decides: NEN 7510 for health information, ISO 27001 for other information. If you want both certificates, NEN says the certification scheme avoids a double audit burden.
| ISO/IEC 27001 | NEN 7510 | NEN 7512 | NEN 7513 | |
|---|---|---|---|---|
| Subject | Management system, any sector | Information security in healthcare | Basis of trust for data exchange | Logging of actions on health information |
| Current edition | 2022 | 2024, part 2 with A1:2026 | 2022 | 2024 |
| Mandatory in Dutch healthcare | No, except for youth care | Yes, Begz article 3 | Yes, Begz article 3 | Yes, Begz article 5 |
| Certifiable | Yes | Yes, against NEN 7510-1 | No | No |
| Key question | Do you manage your information risks? | Does that fit health data? | Do you know who you exchange data with? | Can you show who viewed which record and when? |
What do NEN 7512 and NEN 7513 cover?
NEN 7512 covers the assurances parties give each other before exchanging data: between care providers, with clients, with health insurers and with other parties involved in care. Under the Begz, NEN 7512:2022 has applied since 1 March 2024.
NEN 7513 covers logging: the automatic recording of what happens to health information. The 2024 edition records three types of events: access to data, searches in data and exchange with third parties. The last one is new. The standard builds on the international standard ISO 27789:2021 and adds Dutch fields, such as the treatment relationship protocol and the consent profile. That lets you see afterwards on what basis someone was given access.
Two points are often missed. First, you keep the logs for at least five years from the moment a log entry is written (Staatscourant 2019, 38007). Second, logging alone is not enough. NEN 7513 elaborates a control in NEN 7510-2 stating that logs should be "produced, stored, protected and analysed". The aim is that you can check whether access was lawful.
What does the Wabvpz require of your organisation?
The Wabvpz supplements the GDPR for healthcare. Four articles matter here:
- Article 15a: consent. You only make data available through an electronic exchange system if the client has given explicit consent.
- Article 15d: electronic access and copy. If a client asks, you provide access or a copy electronically and free of charge. This has applied since 1 July 2020.
- Article 15e: who looked? At the client's request, that copy also states who viewed or requested information, and on what date. This too has applied since 1 July 2020. Without proper logging you cannot deliver it.
- Article 15j: the legal basis for the Begz, and therefore for the duty to follow NEN 7510, 7512 and 7513.
How strict is this? The IGJ supervises the Wabvpz, but cannot impose punitive sanctions under that act. It said so itself in May 2026, after investigating a laboratory that had been hacked. The Dutch Data Protection Authority (AP) can, under the GDPR.
What does the IGJ check for NEN 7510?
The IGJ checks whether your information security demonstrably works, not whether a certificate hangs on the wall. Policy on paper is not enough: you show that you check whether the measures work, and that you adjust them.
The key piece of evidence is the independent assessment: a review by an expert who is not involved in your information security. That can be an internal auditor, an external specialist or someone from another care organisation. A certificate is one way to demonstrate compliance, but not the only one. The IGJ expects at least one assessment every three years.
According to the IGJ, the assessment report must show, among other things:
- the status of each part of the management system and of the applicable controls;
- evidence of how things work in practice, not just plans;
- who assessed, why that person is independent and competent, and who was interviewed;
- for each part of the standard, which evidence was used;
- a distinction between critical deviations, non-critical deviations and points for improvement.
The IGJ's Digital Care Assessment Framework (Toetsingskader Digitale Zorg, August 2026) adds what else it checks. The board has adopted the policy, assigned roles, had an objective audit carried out and acted on deviations. And there is a continuity plan that has been implemented and tested.
The IGJ's own investigations show why it is pushing:
| IGJ investigation | Outcome |
|---|---|
| Hospitals (2022, follow-up 2023) | In 2022, 54 of the 77 hospitals did not comply. In November 2023 the IGJ expected 70 to comply that year. |
| Out-of-hours GP services (October 2025) | 43 of the 49 organisations did not yet (fully) comply. |
| Larger mental healthcare organisations (May 2026) | 6 of the 87 could show that they work to the standard. 14 did not respond; the IGJ assumes they do not work to the standard. |
The IGJ expects mental healthcare organisations that do not yet comply to have at least an independent assessment carried out this year. Investigations into youth care, laboratories and primary care have been announced. And after the hacked laboratory case, the IGJ added: if you use a third party, actively check that its information security demonstrably complies.
Does the Cyberbeveiligingswet apply to your care organisation?
That depends on your size. The Cyberbeveiligingswet (Cbw) is the Dutch implementation of the EU NIS2 Directive and has applied since 15 August 2026. In healthcare it covers care providers, EU reference laboratories, research into medicinal products, pharmaceutical companies and manufacturers of medical devices. For care providers:
- Large care providers (250 FTE or more, or more than €50 million in turnover and more than €43 million in balance sheet total) are essential entities. The IGJ can open an investigation at any time.
- Medium-sized care providers (50 FTE or more, or more than €10 million turnover and balance sheet total) are important entities. The IGJ only investigates if there is an indication that something is wrong.
If you are in scope, you have five duties:
- Register with the National Cyber Security Centre (NCSC) through MijnNCSC.
- Meet the duty of care. Under the Cybersecurity Regulation for Healthcare (Cyberbeveiligingsregeling voor de zorg), your measures must demonstrably meet NEN 7510, ISO 27001 and 27002, or an equivalent level. Note the scope: the Wabvpz covers care information systems, the Cbw covers all your network and information systems, including your HR system.
- Report significant incidents: an early warning within 24 hours, a notification within 72 hours and a final report no later than one month after that. In healthcare, an incident is significant if, among other things, a critical business process is down for more than four hours.
- Board responsibility. The board approves the measures. Each board member must have sufficient knowledge within two years and complete training with a certificate.
- Inform the recipients of your services. If a significant incident may affect your services, you inform the recipients of those services without undue delay (Cbw article 30).
You report through MijnNCSC; the NCSC forwards reports from healthcare to the IGJ and to Z-CERT, the cybersecurity expertise centre for Dutch healthcare. For the full picture of the act, read our pillar NIS2 in the Netherlands: does the Cyberbeveiligingswet apply to you. If you are not in scope, NEN 7510 remains mandatory through the Wabvpz.
What does AI change for NEN 7510?
The standard stays the same. For NEN 7510, an AI application is an information system that processes health data, just like your electronic client record. Health data is also a special category of personal data (Article 9 GDPR). Five topics need extra attention.
1. The DPIA. A data protection impact assessment (DPIA) analyses the privacy risks before you start (Article 35 GDPR). The AP put large-scale processing of health data on its list of processing operations that always require a DPIA; individual care professionals are exempt. Describe what the AI does with client data, where that happens and how you limit the risk.
2. The data processing agreement. If a supplier processes client data for you, you sign a data processing agreement (Article 28 GDPR). Record which sub-processors run the language model, where, and whether data is retained or used for training. Include your security requirements: according to NEN, you set the requirements and the supplier shows that the software meets them.
3. Traceable access. NEN 7513 requires that you can see who viewed which record. In that standard a "user" can also be a process. If an AI assistant looks on everyone's behalf under one system account, the log only shows that account. You can then no longer check whether access was lawful, nor honour Article 15e of the Wabvpz. So ask your supplier: whose name appears in the log when the AI retrieves data?
4. Data minimisation. You process no more data than necessary (Article 5(1)(c) GDPR). So no full record to the language model when last week's reports will do, and no citizen service number when the question does not need it.
5. A human decides. Have a care worker check what the AI suggests before it goes into the record. That is not literally in NEN 7510, but it protects the accuracy of the record, and integrity is a core value of the standard.
The AI Act (Regulation (EU) 2024/1689) applies as well. Article 4 on AI literacy has applied since 2 February 2025. An amending regulation of 8 July 2026 (Regulation (EU) 2026/1744) adjusted that duty: you take measures to support your staff's AI literacy, but you do not have to guarantee a specific level. The same regulation postponed the high-risk rules: for the uses in Annex III to 2 December 2027, and for AI in products under Annex I, including medical devices, to 2 August 2028.
NEN 7510 checklist: where does your organisation stand?
| Area | What you must be able to show | Basis |
|---|---|---|
| Governance | Adopted policy, assigned roles, approved measures | NEN 7510-1; IGJ framework 5.1; Cbw article 24 (if in scope) |
| Risk assessment | An owner and a treatment choice per risk, kept up to date | NEN 7510-1 |
| Statement of Applicability | Per control: applied or not, and why | NEN 7510-1 and -2 |
| Access | Rights matching the care relationship, reviewed periodically | NEN 7510-2 |
| Logging | Access, searches and exchange logged, kept for five years, checked for unlawful access | Begz article 5; NEN 7513 |
| Client rights | Electronic access and copy, on request with who viewed the data | Wabvpz articles 15d and 15e |
| Data exchange | Consent, established identity of parties, secure transport | Wabvpz article 15a; NEN 7512 |
| Suppliers | Requirements in the contract, processing agreement, review of their services | NEN 7510-2; GDPR article 28 |
| Incidents | A procedure, breach notification to the AP within 72 hours, Cbw deadlines and informing recipients | GDPR article 33; Cbw articles 25 to 30 |
| Continuity | A continuity plan that has been implemented and tested | IGJ framework 5.2 |
| AI applications | DPIA, processing agreement, traceable access, minimal data, human review, training | GDPR articles 5, 28 and 35; NEN 7513; AI Act article 4 |
| Independent assessment | At least every three years, with a report that meets the IGJ requirements | NEN 7510; IGJ |
How it works at Prudai
ZIA is our AI assistant for care organisations, IRMA our platform for risk management and information security. Here is how they work, limits included.
ZIA and Nedap ONS: read, and write back one thing. The ZIA integration with Nedap ONS (in Dutch) reads the client overview from the care organisation's own ONS environment. It can write back exactly one thing: a daily report. ZIA always shows the care worker the draft first and asks for explicit confirmation. Other report types, edits and deletions are not possible. Write-back is off by default and requires a separate write permission from Nedap.
Three design choices connect to this article:
- Traceable access. With every request to ONS, ZIA sends the identity of the signed-in care worker. That identity comes from the login, not from the question. Without a traceable care worker, the integration refuses the request. ZIA only requests clients within the scope that ONS sets for that care worker.
- Less data to the model. By default, the citizen service number does not reach the language model. Free text from reports and notes is capped at 4,000 characters per item and 32,000 in total. Reports come from the last seven days by default.
- The care worker decides. ZIA always asks for confirmation of the daily report first. The care worker can approve the draft, edit the text or reject it.
How a care organisation approaches such a project is described in the use case From pilot to practice with AI in care (in Dutch).
IRMA and NEN 7510. IRMA contains NEN 7510 as a framework, in its 2024 edition. The library holds 101 requirements: 93 map one-to-one to the controls in Annex A of ISO/IEC 27001:2022, and 8 are healthcare-specific additions. Link a measure to the ISO control and IRMA also counts it towards the NEN requirement. That saves double work if you carry both standards; see the use case crosswalk for ISO 27001, BIO2 and NEN 7510 (in Dutch). NEN 7512 and 7513 are not in the library. And a framework in a tool does not make you compliant: it helps you keep requirements, measures and evidence in one place.
Prudai itself. For ISO/IEC 27001:2022 and NEN 7510, our certification audit was completed in August 2026; we expect the certificate in the fourth quarter of 2026. Customer data is stored on our own servers in EU data centres. The AI processing itself runs through external model providers. That distinction belongs in every DPIA, including yours.
For the specialist
How a new edition becomes law. Article 7 of the Begz refers to the latest edition of the standard. The minister announces it in the Staatscourant, with a date from which it applies. For NEN 7510 that date is 1 June 2026 (Staatscourant 2026, 17743), for NEN 7512:2022 it is 1 March 2024 (Staatscourant 2023, 9608). For NEN 7513 the latest announcement concerns the 2018 edition (Staatscourant 2018, 46644); we found no announcement by the minister under Article 7 of the Begz for NEN 7513:2024 as of 2 October 2026 (the standard does appear in NEN's list of new standards, Staatscourant 2025, 2145). Agree with your auditor which edition you are assessed against. The differences are listed in Annex B of NEN 7513:2024.
Comply or explain. In an audit, nonconformities are only raised against chapters 4 to 10 of NEN 7510-1 and the controls in Annex A. If you deviate from guidance in NEN 7510-2, justify it in the Statement of Applicability. The explanatory notes to the Cybersecurity Regulation for Healthcare put it this way: although NEN 7510-2 contains recommendations, these "cannot simply be ignored".
Equivalent level under the Cbw. The regulation allows an alternative to NEN 7510 or ISO 27001 and 27002, but the burden of proof lies with the organisation. Certification is not required here either.
Medical device manufacturers are listed in Annex 2 of the Cbw and are therefore important entities, even when large. Large manufacturers of devices placed on the list of critical devices during a public health emergency (Article 22 of Regulation (EU) 2022/123) fall under Annex 1 and are then essential entities.
CSIRT. Z-CERT performs the tasks of the computer security incident response team (CSIRT) for healthcare. When the regulation was adopted on 12 August 2026, Z-CERT had not yet been formally designated and the NCSC was acting in the interim.
Frequently asked questions
Is a NEN 7510 certificate mandatory?
No. The law does not require one, the Cyberbeveiligingswet does not, and NEN 7510 itself does not either. You must show that you work to the standard, with regular independent assessments. A certificate is one way to show it.
How often must an independent assessment take place?
The IGJ expects at least once every three years, alongside your own internal audits. How often exactly depends, according to the IGJ, on how quickly your organisation changes, for example through a new client record system or a merger.
Does NEN 7510 apply to a small practice?
Yes, also to small care providers and sole traders. The standard is risk-based, so the measures fit your size. The IGJ advises starting with the most important information flows, such as the client record and exchange with partners in the care chain.
Can I use AI with client data?
Yes, if you set up the AI like any other system that holds client data. Think of a DPIA, a processing agreement, access control, logging per care worker and as little data as possible going to the model. Have a care worker check what the AI suggests.
What goes into a NEN 7513 log entry?
A log entry describes the event (access, search or exchange, with a timestamp), who performed the action, through which access point and source system, and which client and data were involved. NEN 7513:2024 adds Dutch fields, such as the authorisation protocol, the treatment relationship protocol, the consent profile and the checks performed at the event.
Sources
- Besluit elektronische gegevensverwerking door zorgaanbieders (Begz), wetten.overheid.nl, in force since 1 October 2020, consulted 2 October 2026
- Wet aanvullende bepalingen verwerking persoonsgegevens in de zorg (Wabvpz), wetten.overheid.nl, consulted 2 October 2026
- Decision of 7 May 2026: new edition of NEN 7510 applies from 1 June 2026, Staatscourant 2026, 17743, 18 May 2026
- Cyberbeveiligingsregeling voor de zorg, Staatscourant 2026, 28763, 14 August 2026
- IGJ, Questions about NEN 7510 (in Dutch), consulted 2 October 2026
- IGJ, Inspectorate concerned about information security in mental healthcare (in Dutch), 27 May 2026
- NEN, Information security in healthcare (NEN 7510, in Dutch), consulted 2 October 2026
- Regulation (EU) 2026/1744 amending the AI Act, EUR-Lex, 8 July 2026
Would you like to know how ZIA uses client information from Nedap ONS while the care worker stays in control? See ZIA for healthcare and social care or read how the Nedap ONS integration works (in Dutch).
Updated on 2 October 2026