Find out what NEN 7510 means for secure email and file sharing in the healthcare sector, with a practical checklist and an overview of FileCap’s role.

Healthcare organizations process confidential patient information on a daily basis: medical records, referral letters, lab results, and clients’ personal data. The NEN 7510 standard describes how to secure that information in practice and is not merely non-binding guidance within the Dutch healthcare sector. On this page, you’ll learn exactly what NEN 7510 entails, how the standard relates to the GDPR and NTA 7516, and what this means in concrete terms for secure emailing and file sharing in healthcare. You’ll also find a practical NEN 7510 checklist that lets you quickly assess your organization’s current status, and we’ll explain how FileCap supports healthcare institutions in communicating more securely. Whether you’re just getting started with information security or want to strengthen your existing policies, this page provides a concrete starting point.
NEN 7510 is the leading Dutch standard for information security in the healthcare sector. The standard is largely based on the international standards ISO 27001 and ISO 27002, but is specifically tailored to the Dutch healthcare context. NEN 7510 outlines the measures a healthcare organization must take to ensure the availability, integrity, and confidentiality of patient information, ranging from risk assessment to access control and incident response.
The standard consists of two parts. The first part follows the structure of ISO 27001 and describes the required framework for an information security management system: how to identify risks, select controls, and continuously improve the system as a whole. The second part is the Dutch adaptation of ISO 27002 and ISO 27799 and provides practical, healthcare-specific guidelines for those measures.
Under the regulations governing the use of the Citizen Service Number (BSN) in healthcare, healthcare providers are required to comply with the requirements of NEN 7510. A formal NEN 7510 certificate is not legally required in and of itself, but is often used in practice to demonstrate that an organization complies with the standard, for example, to regulators, clients, or patients. The Health and Youth Care Inspectorate uses NEN 7510 as a guideline when assessing whether healthcare institutions have their information security in order, even if no certificate is present. Furthermore, the standard applies not only to healthcare institutions themselves but also to their suppliers, such as software developers and hosting providers, as soon as they process patient data within the meaning of the GDPR.
The GDPR is the European privacy law that applies to all sectors and requires organizations to implement appropriate technical and organizational measures to protect personal data. The GDPR largely leaves open what “appropriate” means exactly. NEN 7510 elaborates on this for the healthcare sector, developing it into a concrete, risk-based management system and thereby providing guidance on what appropriate security means in practice when it comes to medical and personal data.
While NEN 7510 outlines a broad framework for information security, the Dutch Technical Agreement (NTA) 7516 specifically addresses secure email communication in the healthcare sector: it specifies the requirements for encryption, recipient identification, and logging when sending patient data via email. NTA 7516 is, in fact, a concrete implementation of part of what NEN 7510 outlines in general terms. If you’d like to learn more about what NTA 7516 means for your organization and how FileCap aligns with these requirements, please read our page about NTA 7516 and FileCap.
Do you work with third parties, such as an IT administrator, a SaaS provider, or an administrative office that sends patient data on your behalf? If so, those parties also fall within the scope of NEN 7510 as soon as they have access to or process patient data. This is something you should explicitly address in data processing agreements and supplier assessments.
NEN 7510 is a framework, not a ready-made technical solution. The exact measures required depend on your organization’s risk assessment. However, there are a number of topics that recur in virtually every risk assessment when it comes to email and file transfers involving patient data:
In practice, the greatest risks often arise not from sophisticated attacks, but from simple human errors: an email with an attachment sent to the wrong address, a large file sent via a free, consumer-oriented file-sharing service because the regular email system cannot handle it, or an employee logging into an unsecured network. NEN 7510 therefore requires not only technical measures but also clear operational guidelines and employee awareness regarding how they handle patient data on a daily basis.
Because NEN 7510 is risk-based, it is not a one-time assessment. Measures that are sufficient today may no longer be adequate a year from now, for example, due to new threats or changes within the organization. The standard therefore requires periodic evaluation and adjustment of your security measures regarding email and file transfers.
Use the checklist below as an initial, practical assessment for the “secure email and file sharing” component of NEN 7510. The checklist is not a substitute for a formal risk assessment or audit, but it immediately highlights the most important areas of concern. When completing the checklist, it is best to involve both someone responsible for information security or quality and someone familiar with the day-to-day practice of email and file sharing.
Do you recognize some of the items on the checklist as outstanding issues? If so, that’s not a problem in itself: it’s exactly what a risk-based standard like NEN 7510 calls for. Start with the items that address the greatest risks, such as encryption and access control, and work from there.
FileCap is designed for encrypted email and secure file transfer, with features such as access control, recipient verification, and logging of sent and received messages and files. Contec B.V., the provider of FileCap, has been ISO 27001-certified for its information security management system (ISMS) since April 1, 2021, and will be certified to the ISO 27001:2022 standard starting in 2025. Since NEN 7510 is largely based on those same ISO 27001/27002 standards, the control measures from this certified ISMS align with a large portion of the corresponding NEN 7510 measures. A detailed mapping for your supplier assessment is available from FileCap upon request. More details and the certificate itself can be found on our security page.
Data storage is also a relevant factor in a risk assessment conducted in accordance with NEN 7510. The FileCap SaaS environments operate entirely within the European Union, hosted by the European cloud provider Scaleway and in EU regions of Amazon Web Services. Data does not leave Europe and is not used for AI training or marketing purposes, and backups of the SaaS platforms are stored in the Netherlands.
FileCap does not automatically make an organization NEN 7510-compliant. The standard applies to the entire organization: from policy and risk management to physical security and employee awareness. FileCap is a building block within that broader policy, specifically focused on the encrypted and auditable transmission of emails and files containing patient data.
Curious about how healthcare organizations use FileCap in practice? Check out our page on FileCap for the healthcare sector.
Would you like to know how FileCap fits into your organization’s NEN 7510 process? Request a quote or contact us for a demo.
The FileCap add-in makes sending a secure email or sensitive files child's play. Check out how it works below:
Invite someone to send you large files or a message securely with FileCap. Fast and simple!
Choose one of four available authentication methods: password, code via email, code via SMS or a company password. Sending extra sensitive information? Simply use a second verification.
Customize your FileCap portal with a large background, your company logo and, of course, matching colors. The emails that you send with FileCap will also automatically receive your house style. Very familiar for your customers.

By taking advantage of the additional security options, business rules to monitor the content of emails and messages and the ability to retract sent messages, you reduce the likelihood of data breaches.




























































Discover how FileCap helps healthcare organizations with encrypted email and file transfers as a building block within a broader NEN 7510 approach.
Request a quote