Whoever runs information security in Dutch healthcare has two calendars side by side. One belongs to NEN 7510: the revised standard from December 2024, with a certification window closing in February 2027. The other belongs to the Cyberbeveiligingswet, which takes effect on 15 August 2026 and reaches healthcare too. Two movements, one underlying question: can you show that the protection of patient data actually works?
#What NEN 7510 is, and why there is no way around it
NEN 7510 is the Dutch standard for information security in healthcare, based on ISO 27001 and extended with healthcare-specific controls. Unlike most standards, it is not optional: for providers processing patient data electronically, NEN 7510 is anchored in law, among others through the decree on electronic data processing by healthcare providers.
The healthcare inspectorate IGJ supervises and expects you to demonstrably work on a management system that meets the standard. Note the distinction: certification is not mandatory, demonstrability is. A certificate is one way to organise that demonstrability, not a goal in itself. In practice, chain partners and buyers do ask for it more and more.
#What changed in NEN 7510:2024
On 16 December 2024, the revised standard appeared, aligned with ISO 27001:2022. The structure was cleaned up considerably: fourteen chapters became four themes (organisational, people, physical, and technological), and the controls were consolidated into 93 general controls plus eight healthcare-specific ones. New are controls around cloud, threat intelligence, and data leakage prevention, themes that barely existed in the old 2017 version.
For organisations already on ISO 27001:2022, the switch is manageable. For those still on the old structure, it is more than a textual update: the risk analysis, the statement of applicability, and the internal audits all move with it.
#The Cyberbeveiligingswet joins in
Healthcare is one of the eighteen sectors under the Cyberbeveiligingswet, the Dutch transposition of NIS2 that takes effect on 15 August 2026. Mid-sized and large providers get a duty of care, a reporting duty for significant incidents, and a registration duty with the NCSC.
Good news for anyone who took NEN 7510 seriously: the law's duty of care and the standard's management system overlap heavily. If you demonstrably work to NEN 7510, most of the foundation for the Cyberbeveiligingswet is already in place. The full picture of that law is in the Netherlands has its NIS2 law.
#The blind spot: AI on the work floor
The standard governs systems, processes, and roles. But the biggest day-to-day risk sits in an action no process description covers: a clinician letting a public chatbot summarise a referral letter, or pasting patient details into a prompt to speed up a report. Patient data is special category data, and NEN 7510 demands strict control of exactly this kind of processing.
A policy that says "no patient data in AI" is a start, not control. You want to see which AI tools are actually used, and you want a measure at the moment it goes wrong: while typing, before sending. How the standard and AI use come together is covered in more depth in BIO and NEN 7510: AI and privacy in government and healthcare.
#What to arrange now
- Map the transition to NEN 7510:2024. New structure, updated risk analysis, statement of applicability, and audits. Certified? Then you want to be over well before 20 February 2027.
- Check whether the Cyberbeveiligingswet reaches you and register through mijn.ncsc.nl.
- Include AI use in your risk analysis. Which tools are used, with which data, and what has been agreed about them?
- Make awareness concrete. Not a yearly e-learning, but a signal at the moment someone types sensitive data somewhere.
- Organise the demonstrability. The IGJ, the auditor, and soon the supervisor under the Cyberbeveiligingswet all ask the same thing: show that it works.
Getting sight of AI use does not have to be manual work. The AI Tools module shows which AI tools are in use, checked against a catalog of more than 700 assessed tools, without ever putting an individual employee on screen.
#From observing to substantiating
Demonstrability is the hardest requirement in healthcare, because collecting evidence costs time nobody has. BeeSensible turns it around: what happens on the work floor becomes the substantiation. Sensitive data gets a highlight while someone types, in AI tools, email, and chat, and the aggregated figures show that the measure works. Always as counts, never the text, never one person, and with no per-employee breakdown anywhere.