For a long time, the Dutch Health and Youth Care Inspectorate (IGJ) primarily addressed information security only after an incident had occurred, such as a major data breach or ransomware attack. With the implementation of the Cyber Security Act (Cbw), this reactive approach is definitively a thing of the past. Since August 15, 2026, the IGJ has held an explicit dual mandate. Alongside its traditional focus on patient safety, the inspectorate now proactively enforces digital resilience.
For healthcare executives, this represents a fundamental shift. The question is no longer whether the IGJ will conduct supervision on NEN 7510 compliance in healthcare, but whether your information security is factually and demonstrably in order when they do.
The Harsh Reality: 90% of Mental Healthcare Facilities are Non-Compliant
The urgent need for this proactive oversight is undeniable, as recent inspection reports clearly show. A report dated May 27, 2026, revealed a painful fact: no less than 90% of the larger mental healthcare (GGZ) institutions examined did not have their information security structurally in order. Outdated risk analyses and inadequate access monitoring are common, leaving these organizations continuously lagging behind because they still rely on manual or incident-driven processes.
Under the updated NEN 7510:2024 standards and the mandate provided by the Cbw, the regulator no longer accepts "paper tigers." Information security must be verifiably embedded throughout the organization.
From Incident-Driven to Continuous AI-Driven Audits
Manually verifying logs, access rights, and policy documentation in 2026 is simply an unsustainable task for compliance officers. As we demonstrated earlier regarding the enforcement of Wabvpz logging requirements, it is impossible to screen millions of log lines for unauthorized access without the use of scalable technology.
This is exactly where autonomous agent systems play an indispensable, strategic role. By deploying continuous, AI-driven audits, healthcare institutions can abandon fragmented spot checks and achieve 100% coverage. An intelligent agent like ZIA acts as a permanent digital auditor: the AI monitors configurations, tests policies against ground truth reality, and timely flags anomalies within the NEN 7510 framework.
In addition, automated auditing technology helps organizations effectively steer their NIS2 supply chain security. Under the new regulations, healthcare institutions are also obligated to guarantee security throughout their entire chain of suppliers.
Operational Certainty in the Boardroom
The IGJ's strengthened mandate forces the healthcare sector to safeguard digital security at the executive level just as rigorously as medical protocols. Waiting for the inspectorate to show up or a data breach to occur poses an unacceptable operational risk. Transitioning to intelligent, automated audits provides executives with the concrete control needed to keep healthcare delivery safe and future-proof.
Would you like to know how our autonomous AI agent Zia can support your healthcare organization in structurally automating your NEN 7510 audits and how you can prepare strategically for the proactive supervision of the IGJ? Contact us today for an introduction.
