Benefits NEN 7510 for your organization
- You get to know your security risks to which you can then respond.
- You get a practical framework for setting up your information security according to the legal requirements around the Electronic Patient File (EDP).
- You will show health insurers and patients that patient data is in good hands with you.
- The NEN 7510 helps you reduce the number of security incidents.
NEN 7510 approach 2-Control
2-Control's IT auditors can perform an IT audit against the NEN 7510. We go through the following phases with you:
- Pre-audit
By first checking the extent to which your systems comply, you will gain insight into the measures that you must take in any case. We can perform this pre-audit for you. Our IT auditors map out the extent to which your organization meets certain standards. The outcome of the pre-audit gives a clear picture of the measures you need to take to comply with the NEN 7510 standards. - Taking measures
Following our pre-audit, you implement the necessary measures to better protect your systems against external misuse. - Final audit
Once the previous stages have been completed, the final audit will be conducted. - Report
We provide a clear and concise assurance report with our findings and recommendations. The report is a prescribed standardized report. This format has been developed in consultation with the professional group of auditors (NOREA).
Differences between NEN 7510 and ISO 27001
- NEN 7510 and ISO 27001 are both information security standards. Only NEN 7510 is specifically intended for healthcare institutions and other managers of personal health information, while ISO 27001 is the general and internationally applicable standard for information security, regardless of the industry in which one operates.
- NEN 7510 is based on this international standard and in terms of content they are very similar. The NEN 7510 standard is in fact an extension of the requirements from the ISO 27001 standard. The NEN 7510 can be seen as a set of additional requirements that organizations working in the healthcare sector must meet.
- Within the NEN 7510 and ISO 27001 standard there is a lot of room for organizations to set up how they meet the requirements in the standard themselves.
NEN 7510 and IT service organizations
If you are a supplier of IT services to healthcare organizations, you may also have access to patient privacy-sensitive information. Your customers, the healthcare organizations, will therefore demand that you also comply with NEN 7510 standards. After all, in the "chain," the healthcare organizations also depend on your people, resources and processes. Together with your assurance statement, the healthcare institution can demonstrate that they comply with NEN 7510.
For IT service organizations, we also achieve an assurance statement, but use NOREA's guidance on Service Organization Control (SOC2) reports. The SOC2 standard is a form of assurance specifically aimed at IT service organizations and provides guidelines and principles for determining, instituting and enforcing measures they should normatively take to secure information provision. To align with the NEN 7510, a mapping with the NEN 7510/ISO 27001 standards is used.
Our support for you
2-Control consists of an enthusiastic team of registered IT auditors (RE) who can assess your compliance with NEN 7510 at short notice through an IT audit. An IT audit is a way to show that you handle information securely by means of measures.
We specialize in assessing risks and selecting appropriate security measures and then demonstrating the operation of these measures. Our IT auditors have extensive experience and expertise with healthcare institutions.
2-Control
Neem contact met ons op
Heeft u vragen of opmerkingen over onze IT-auditdiensten? Wij horen graag van u. Vul uw gegevens in het onderstaande formulier in en wij nemen zo snel mogelijk contact met u op. U kunt ook rechtstreeks contact met ons opnemen via het telefoonnummer aan de linkerkant.
Ons toegewijde team staat klaar om u te helpen met eventuele vragen of problemen. Wij streven ernaar om u de best mogelijke service te bieden.