"For an individual practice it is not feasible: we are talking about no fewer than 117 controls." That is what the security officer of the Amsterdam regional GP organisation (ROHA) said in 2023 in De Dokter, the magazine of the Dutch GP association LHV, about the old NEN 7510. The 2024 version has 101 (93 general and 8 healthcare-specific), but the point still stands: as a small practice you need to choose wisely, collaborate where you can and leave the rest to your suppliers. This page shows what is really required, what it costs and how to get it done in a year.
Is NEN 7510 mandatory for a GP practice?
Complying: yes. Certifying: no. Article 3(2) of the Besluit elektronische gegevensverwerking door zorgaanbieders (the Dutch decree on electronic data processing by healthcare providers) says that a healthcare provider ensures safe and careful use of the healthcare information system (for you: the HIS) and of the exchange system it is connected to "in accordance with NEN 7510 and NEN 7512". Article 5 adds that the logging of those systems must meet NEN 7513. Under Article 7 the latest edition of the standard always applies; the minister announces a new edition and its effective date in the Staatscourant.
The explanatory notes to the Cyberbeveiligingsregeling voor de zorg (August 2026) confirm this for small providers: they fall outside the Cbw, but "Small-scale healthcare providers, however, are already required under the Wabvpz to comply with NEN 7510". A certificate is therefore one way to show that you comply, not a legal requirement.
So why do some practices choose certification anyway? Because a regional GP organisation offers it as a joint programme (like the ROHA with a number of front-runner practices), because a care partner or client asks for it, or because it makes accountability towards the IGJ (the Health and Youth Care Inspectorate) and patients easier. Check what your own contracts say; requirements differ per party.
And the Cyberbeveiligingswet?
Healthcare is listed in Annex 1 of the Cbw, the Dutch law implementing NIS2, but the law only applies from 50 FTEs, or with fewer than 50 FTEs if both annual turnover and balance sheet total exceed €10 million. Partner and linked enterprises count too. A solo or two-GP practice is well below that. An out-of-hours GP service (the organisation that covers evenings, nights and weekends) or an organisation with several health centres can be above it; then the Cbw applies, with the IGJ as supervisor and Z-CERT as CSIRT. If in doubt, run the NIS2 scope checker.
What a small practice really needs
NEN 7510 is risk-based: you decide which controls are needed and record that in a Statement of Applicability. For a typical practice with a cloud-based HIS, a few workstations and data exchange via the national switch point (LSP), we arrive at this core:
| Topic | What you arrange | Who does it |
|---|---|---|
| Responsibility | One person who coordinates information security (often the practice manager) and a short policy note, adopted by the practice owners | Practice |
| Risk analysis | Yearly: what can go wrong with the HIS, email, telephony, workstations and paper? What do you do about it? | Practice, possibly with the regional organisation |
| Suppliers | Overview of the HIS supplier, IT managed service provider, telephony and email; data processing agreements; their certificate or statement (NEN 7510 or ISO 27001) | Practice asks, supplier provides |
| Access | Personal accounts, two-factor authentication, rights per role, revoke accounts immediately when someone leaves, periodic review | Practice and IT provider |
| Logging | Who accessed which record (NEN 7513); periodic spot checks | HIS supplier provides, practice checks |
| Workstations | Automatic updates, antivirus, screen lock, no patient data on personal devices, clear desk and clear screen at the front desk | IT provider |
| Backup and continuity | Know what the HIS supplier backs up; make a plan for when the HIS or telephony goes down; test it once a year | Supplier and practice |
| Awareness | Short annual training on phishing, pretext phone calls and misaddressed email | Practice |
| Incidents and data breaches | Procedure and register; knowing when to notify the Autoriteit Persoonsgegevens within 72 hours | Practice |
| Physical | A locked room for network equipment, no unsupervised visitors near workstations | Practice |
In 2023 the LHV, together with InEen and the Dutch College of General Practitioners (NHG), released three easy-to-use scans, for privacy, integrity and availability, that give a first impression of where your practice stands. That is a good starting point for your risk analysis.
Two pitfalls we often see: a risk analysis that only covers the HIS (while the biggest risks are in email and telephony), and suppliers who say they are "NEN 7510-proof" without you knowing the scope of their certificate.
What does it cost?
Amounts vary widely per practice, region and supplier, so we don't give indicative prices. These are the cost items:
- Your own time: the biggest item. Count on a fixed morning per month for the practice manager in the first year, and less after that.
- Technical measures: two-factor authentication, a password manager, backup, patch management. Much of this is often already in your IT contract.
- Training: online awareness training for the team.
- External support (optional): an adviser for the baseline assessment and setting up documents.
- Certification (optional): an initial audit and annual surveillance audits by a certification body. The price depends on scope and size; ask for quotes.
Subsidy: under the Dutch Mijn Cyberweerbare Zaak scheme, small businesses with up to 50 employees and up to €10 million in turnover can get back 50% of the cost of certain measures, up to €1,250. The categories include MFA, password managers, setting up and testing backups, patch management, antivirus and awareness training. According to the NCSC, applications can be submitted from 7 September to 30 November 2026, first come, first served. Check with RVO (the Netherlands Enterprise Agency) whether your practice qualifies.
Do it yourself or hire an adviser?
| Yourself (with your region) | With an adviser | |
|---|---|---|
| Suits | Practices with a practice manager who is given time for it, and a regional organisation that provides templates and a joint risk analysis | Practices that want to certify, have little time or need to change course quickly after an incident |
| Advantage | Knowledge stays in the practice; cheaper | Faster, less chance of missing something; audit experience |
| Risk | Stalling after the first months; a paper policy nobody knows | Generic documents that don't fit your practice; dependency |
| Tip | Block fixed moments in the diary and use a tool with recurring tasks | Ask for a handover: you need to be able to keep it up yourself afterwards |
A middle way often works best: do it yourself, with a few half-days of external advice for the baseline assessment and an internal audit at the end of the year. In the Amsterdam example from De Dokter, the cooperative arranged things like the risk analysis, supplier management and the record of processing centrally, and the practices did the rest themselves.
A practical 12-month plan
- Month 1, get started: appoint a coordinator, have the practice owners adopt a short policy note, run the LHV scans. Apply for the subsidy if you qualify.
- Month 2, take stock: a list of systems (HIS, email, telephony, website, workstations), suppliers and data processing agreements.
- Month 3, risk analysis: per system: what goes wrong, how bad is it, what do you do about it. Record the choices in a first Statement of Applicability.
- Month 4, access: two-factor authentication wherever possible, personal accounts, a leavers procedure.
- Month 5, suppliers: request certificates or statements and check the scope; agree on incident notification.
- Month 6, data breaches and incidents: procedure, register and an exercise with a misdirected referral letter.
- Month 7, continuity: what do you do if the HIS is down for a day? Make an emergency procedure (paper workflow, availability) and test it.
- Month 8, workstations: updates, screen lock, laptop encryption, clear desk and clear screen.
- Month 9, awareness: training for the whole team, including locums and temporary staff.
- Month 10, logging: first spot check of the NEN 7513 logging in the HIS; record the findings.
- Month 11, internal review: go through everything (yourself, with a peer practice or an adviser) and make an improvement list.
- Month 12, review: discuss the outcome with the practice owners, adopt the risk analysis and the plans for next year. Decide whether you want to certify.
Sources
- Besluit elektronische gegevensverwerking door zorgaanbieders, Staatsblad 2017, 446
- Cyberbeveiligingsregeling voor de zorg, Staatscourant 2026, 28763
- LHV, De Dokter 7/2023: Informatiebeveiliging, houd de aandacht vast (pdf, in Dutch)
- Kiwa, Herziene NEN 7510 gepubliceerd (in Dutch)
- Kiwa, Wat betekent de nieuwe NEN 7510:2024 voor certificaathouders? (in Dutch)
- NCSC, Subsidie Mijn Cyberweerbare Zaak (in Dutch)
- NCSC, Valt mijn organisatie onder de Cyberbeveiligingswet? (in Dutch)
- Regulation (EU) 2016/679 (GDPR), EUR-Lex
- Autoriteit Persoonsgegevens (data breach reporting desk)
As of 1 October 2026. This page is general information, not legal advice. Laws, regulations and sector rules can change; always check the current source.