Skip to main content

NEN 7510 and GDPR for healthcare organisations

One platform for NEN 7510, ISO 27001 and your GDPR accountability. Healthcare templates, evidence that collects itself and one file for your auditor and the regulator.

  • NEN 7510 and ISO 27001 on one set of controls
  • Suppliers and chain partners in view
  • Built and hosted in the EU
The Tidal Control dashboard showing progress on NEN 7510

What healthcare organisations achieve with Tidal

50+
Audits passed by our customers, a 100% pass rate
0-2
Findings on average at the certification audit
35+
Frameworks on one set of controls, including NEN 7510 and ISO 27001

Why NEN 7510 stalls in healthcare

The standard is clear. Healthcare organisations get stuck on execution: a long supply chain, policies that do not keep up and evidence only gathered at audit time.

  • Many parties touch patient data

    From EHR vendor to lab links, the overview sits in separate contracts. A missing data processing agreement only surfaces at the audit.

  • Policies on the shelf

    Written for the first certification and not updated since. The auditor checks whether they match how you work today.

  • Evidence spread across folders

    Access rights, logging and backups are only gathered when the auditor asks. That takes weeks and shows a single moment.

  • Quiet after the certificate

    Without a steady rhythm of checks and reviews, the organisation nearly starts over at recertification.

How healthcare organisations use Tidal

From the controls to the file the regulator asks for, always from the same source.

Every healthcare-specific control in one place

NEN 7510 builds on ISO 27001 and adds requirements on patient data, access and logging. In Tidal those controls are pre-mapped, each with an owner and a status, so you never start from a blank page.

More on NEN 7510
The controls overview in Tidal Control, with status, progress and framework per control

Evidence for your controls collects itself

Connect Azure and Entra ID, Google Workspace and the rest of your tooling. Tidal collects the evidence automatically and attaches it to the right control. Where there is no integration, as with many EHR systems, you record evidence with an expiry date.

See all integrations
Connected integrations in Tidal Control, including Azure, Google Workspace and Google Cloud

Chain partners in view, including their risk

From your EHR vendor to scheduling tools and lab links, you remain responsible for every party that touches patient data. Tidal tracks the risk per supplier and whether the data processing agreement is in place.

More on vendor management
Vendors in Tidal Control with risk rating and assessment status

One file for your auditor and the regulator

Your Statement of Applicability, risk assessment and management review build themselves from live data. When the regulator asks how you control access to records, the answer is ready, including who changed what and when.

More on controls and reporting

NEN 7510 audit dossier

PDF

  • Statement of ApplicabilityCurrent
  • Care process risk analysisCurrent
  • Management reviewCurrent
  • Internal audit reportCurrent

Manual or with Tidal

  • Suppliers and chain partners

    Manual

    A list in a spreadsheet

    With Tidal

    Risk and data processing agreement per party

  • NEN 7510 controls

    Manual

    An empty template

    With Tidal

    Pre-mapped with owner and status

  • Collecting evidence

    Manual

    Manually per control

    With Tidal

    Automatic where an integration exists

  • Evidence current between audits

    Manual

    Not included

    With Tidal

    An expiry date per piece of evidence

  • Combining with ISO 27001

    Manual

    A separate project

    With Tidal

    One set of controls

The journey: a median of 13 weeks from kickoff to certificate

A realistic path, not a promise of compliance in a few days. You always see what is expected of your team.

  1. Day 1

    Setup

    Connect your tooling and see straight away which NEN 7510 controls are already in place.

  2. Week 1-2

    Plan

    We map your care processes, systems and chain partners and set the scope for NEN 7510.

  3. Week 3-11

    Implement

    Policies, risk assessment and controls go into Tidal, with templates written for healthcare.

  4. Week 12-13

    Certify

    An independent, accredited certification body carries out the audit. Your evidence is ready in one file.

  5. After

    Maintain

    Annual audits, new chain partners and changes to the standard run in the same system.

Connect the systems you already use

  • Azure
  • Entra ID
  • Google Workspace
  • TOPdesk
  • Microsoft Sentinel
  • Jira
  • AWS
  • Google Cloud
  • OVHcloud
  • Scaleway
  • Hetzner
  • All integrations

“The pace genuinely surprised me. I hear from others that it usually takes six months to a year in an implementation like this.”

Ties Verberne

Co-founder, Aivory

In healthcare this is not a board decision

Four places where information security in healthcare is already written down.

GDPR art. 32
Appropriate technical and organisational measures
Begz
Dutch healthcare providers must meet NEN 7510 when processing data electronically
Health inspectorate
Supervision of information security as part of good care
NIS2
Larger healthcare providers fall under the duty of care of the Dutch Cybersecurity Act

Frequently asked questions

Certification is not a legal requirement, but meeting NEN 7510 is. The Dutch decree on electronic data processing by healthcare providers (Begz) prescribes the standard for processing patient data. In practice insurers, chain partners and tenders increasingly ask for the certificate.

NEN 7510 is the Dutch healthcare-specific reading of ISO 27001. The structure is the same; NEN 7510 adds requirements around patient data, access to records and logging of who viewed what. If you already have ISO 27001, you are not starting over.

Across our customers the median is 13 weeks from kickoff to certificate. How long it takes for you depends on your size, the number of chain partners and what is already in place.

Tidal connects to the systems your evidence comes from, such as Azure and Entra ID and Google Workspace. Most EHR systems have no direct integration. There you record evidence manually with an expiry date, so it does not go stale unnoticed.

The certificate is valid for three years, with annual surveillance audits. Tidal keeps your evidence current in between, so every audit starts with a file that is already in order.