Standard
NEN 7510. Healthcare requirements on top of what you already have.
NEN 7510 is the Dutch standard for information security in healthcare. The current edition, NEN 7510:2024, has two parts. Hospitals and care organizations ask their software and IT suppliers for it, especially when those suppliers process health data on their behalf. Because it builds on ISO 27001, most of the work is shared. Trustbird reuses that work and shows you what healthcare adds.
- Builds on your ISO 27001 management system
- Healthcare-specific controls clearly marked
- One Statement of Applicability for both standards
How Trustbird handles NEN 7510
Part 1 of NEN 7510 sets the same management system requirements as ISO 27001. Part 2 follows the ISO 27002 controls and adds eight healthcare-specific controls and healthcare guidance. Trustbird links both parts to the core you already maintain.
Shared management system
Context, leadership, risks, internal audit and management review are the same for both standards. You maintain them once and they count for NEN 7510 as well.
Controls linked across standards
Each control you already have for ISO 27001 is linked to the matching NEN 7510 requirement. Evidence you attached earlier counts there too.
What healthcare adds
The eight additional healthcare controls appear as a separate, clearly marked set. For each one you decide on applicability and record how you meet it.
Healthcare guidance, comply or explain
Where the healthcare guidance asks for a specific approach, you record whether you follow it and, if not, why. That reasoning sits next to the control.
Health data in view
Record which systems and suppliers process health data on behalf of your customers. Risks and controls around that data stay visible in one place.
One file for a combined audit
Export one Statement of Applicability with a column per standard, together with the evidence and audit trail, ready for a combined or separate audit.
Adding NEN 7510
-
01
Adopt the standard
Switch on NEN 7510 next to ISO 27001. Trustbird links the requirements to the controls and documents you already have.
-
02
Review the overlap
See per requirement what is already covered, and by which control and evidence.
-
03
Close the healthcare gaps
Decide on the healthcare-specific controls and guidance, assign owners and attach evidence where needed.
-
04
Update the audit file
Run the internal audit and management review for both standards together and export the combined file.
Frequently asked questions
- Do I need NEN 7510 if I already have ISO 27001?
- That depends on your customers. Healthcare organizations often ask for it, particularly from suppliers that process health data on their behalf. According to NEN, ISO 27001 counts as equivalent for suppliers that do not process health data. Check with your customers what they expect.
- How much of my ISO 27001 work carries over?
- Most of it. The management system requirements are the same and the controls largely overlap. The additional work lies in the healthcare-specific controls and guidance.
- Does Trustbird include the text of NEN 7510?
- No. Trustbird describes the requirements in its own words, linked to the official numbering. The standard itself is published by NEN, and through an agreement between the Dutch Ministry of Health and NEN you can view it free of charge via NEN Connect.
See what Trustbird does for your organization
Trustbird is being built with two certified design partners, and we are looking for more companies to join them at co-founder pricing. Apply as a design partner, or mail us with a question.