ISO 27799 certification for healthcare organizations

ISO 27799:2025 is an international standard containing information security controls and implementation guidance for health organizations. It supports the protection of the confidentiality, integrity and availability of personal health information. On this page, you can read about ISO 27799, its relationship with NEN 7510 and the independent certification process offered by Brand Compliance.

Important: Following a positive independent assessment, Brand Compliance issues an ISO 27799 certificate. This certification is not performed under accreditation.

What is ISO 27799?

ISO 27799:2025 is officially titled “Health informatics — Information security controls in health based on ISO/IEC 27002”.

The standard provides healthcare-specific information security controls and implementation guidance. It is based on ISO/IEC 27002:2022 and addresses systems and technologies used in healthcare, including electronic health records and medical devices containing health software.

Why is ISO 27799 important in healthcare?

The digital health environment is developing rapidly. Healthcare information must therefore be protected against threats such as data breaches, cyberattacks and unauthorized access.

ISO 27799 provides healthcare-specific controls for protecting health information. Applying these controls can contribute to meeting applicable legal, regulatory and contractual information security requirements. Compliance must always be assessed against the specific requirements that apply to the organization.

How does ISO 27799 relate to NEN 7510?

ISO 27799 provides international information security controls and implementation guidance for health organizations. NEN 7510-1 contains certifiable requirements for information security management systems in Dutch healthcare.

NEN 7510-2 provides healthcare-specific guidance for implementing information security controls and is aligned with ISO 27799.

Implementation of ISO 27799

Implementing ISO 27799 can include:

  • conducting a risk analysis;
  • selecting and implementing relevant controls;
  • developing and maintaining an information security policy;
  • evaluating the implementation and effectiveness of the controls.

ISO 27799 can be applied in a variety of healthcare settings, including hospitals, clinics and other healthcare facilities. By selecting and implementing controls based on their specific risks and healthcare environment, organizations can reduce information security risks and contribute to meeting industry-specific requirements.

What are the benefits of ISO 27799 certification?

ISO 27799 certification by Brand Compliance provides independent confirmation that the organization has implemented the applicable healthcare information security controls in accordance with the certification criteria.

This can strengthen confidence among patients, clients, partners and other stakeholders. Implementing the applicable ISO 27799 controls can also contribute to maintaining the confidentiality, integrity and availability of personal health information and reducing the risk of security incidents.

This certification is not performed under accreditation.

How can your organization obtain ISO 27799 certification?

To obtain an ISO 27799 certificate from Brand Compliance, your organization must implement the applicable healthcare information security controls and meet the criteria of the Brand Compliance certification scheme.

Brand Compliance then conducts an independent assessment of the implementation and effectiveness of these controls. Following a positive assessment and certification decision, Brand Compliance issues an ISO 27799 certificate.

ISO 27799 certification checklist

The following steps form the basis of the ISO 27799 certification process:

  1. Purchase ISO 27799:2025 or its European and Dutch adoption, NEN-EN-ISO 27799:2026, through an authorized standards provider such as ISO, NEN or NBN.
  2. Schedule an introductory meeting with Brand Compliance to discuss the scope and certification criteria.
  3. Develop the knowledge needed to interpret and implement the healthcare-specific information security controls.
  4. Select and implement the controls relevant to the organization’s risks and healthcare environment.
  5. Evaluate the implementation and effectiveness of the controls through an internal assessment.
  6. Have management review the results and implement necessary corrective actions.
  7. Undergo the independent assessment by Brand Compliance.
  8. Following a positive assessment and certification decision, receive the ISO 27799 certificate issued by Brand Compliance.

What does ISO 27799 certification cost?

The costs relate to the ISO 27799 certification provided by Brand Compliance. This certification is not performed under accreditation.

The total costs depend on factors such as the complexity of the processes, shift work, the maturity of the implemented controls, the number of full-time equivalents and the number of locations.

The certification costs are based on the time required for preparation, the independent assessment, reporting and the certification decision. Additional costs may include administration, the certificate and travel expenses.

The quickest way to obtain an indication of the costs is to schedule an introductory meeting.

Conclusion

ISO 27799 provides healthcare-specific information security controls and implementation guidance for protecting personal health information. An independent assessment by Brand Compliance can provide additional confidence that the applicable controls have been implemented effectively.

Following a positive assessment and certification decision, Brand Compliance issues an ISO 27799 certificate. This certification is not performed under accreditation.

Would you like to know what ISO 27799 certification means for your organization? Request an introductory meeting to discuss the scope, certification criteria and assessment process.

FAQ

What is ISO 27799?

ISO 27799:2025 contains information security controls and implementation guidance for health organizations. It is based on ISO/IEC 27002:2022 and addresses healthcare-specific systems, technologies and risks.

What is the difference between ISO 27799 and the NEN 7510 standard?

ISO 27799 provides international information security controls and implementation guidance for health organizations. NEN 7510-1 contains certifiable requirements for information security management systems in Dutch healthcare. NEN 7510-2 provides healthcare-specific implementation guidance and is aligned with ISO 27799.

Is ISO 27799 certification by Brand Compliance accredited?

No. Brand Compliance can issue an ISO 27799 certificate following a positive independent assessment, but this certification is not performed under accreditation.

Which version of ISO 27799 is current?

ISO 27799:2025 is the current international version. It replaced ISO 27799:2016.

Why does ISO refer to ISO 27799:2025 while NEN refers to NEN-EN-ISO 27799:2026?

ISO published the international standard as ISO 27799:2025 in December 2025. The standard was subsequently adopted as a European standard and published in the Netherlands by NEN in 2026 as NEN-EN-ISO 27799:2026. These are not different technical versions. The different year reflects the later European and Dutch publication date.