+31 (0)73 - 220 2000 | info@brandcompliance.com
English
  • Dutch
  • English
  • Français
  • België
  • Dutch
  • English
  • Français
  • België
Brand Compliance
  • Certify
    • ISO 9001
    • ISO 22301 (BCM)
    • ISO 19770-1 (IT-assets)
    • ISO 27001
    • ISO 27017 and ISO 27018
    • BIO
    • ISO 27701 (Privacy)
    • NEN 7510
  • IT Assurance
    • SOC 2
  • Vacancies
  • Knowledge base
  • BC Academy
Talk to an expert
  • Information security
    • ISO 27001
    • NEN 7510
    • ISO 27799
    • ISO 27017 and ISO 27018
    • BIO
    • ISO 19770-1
  • Privacy
    • BC 5701
    • ISO 27701
    • GDPR standard BC 5701:2024 EN
  • IT assurance
    • SOC 2
    • ISAE 3402
    • ISAE 3000
  • Quality & continuity
    • ISO 9001
    • ISO 14001
    • ISO 22301
  • Knowledge & news
    • Knowledge articles
    • News
  • Academy
    • All training courses
    • NIS2 & CyFun
    • ISO 27001
  • About us
    • Accreditations
    • Careers
    • Compliment, complaint or tip
    • Locations
    • Privacy Statement
    • Contact

Certification process

10
  • The ultimate checklist certification
  • Do you have your first audit soon?
  • How long does ISO certification take?
  • What is a certification cycle?
  • The certification process step by step
  • Initial audit Stage 1
  • Initial audit Stage 2
  • Nonconformities within the management system
  • What should you know about certificate suspension or revocation?
  • Transfer of certification

General

10
  • Whitepaper management system audits
  • Quality Management: best practices for success
  • The Traffic Light Protocol (TLP): what does it mean for you?
  • The Brand Compliance glossary
  • What is a management system?
  • Internal or external audit?
  • Find out more about internal audits
  • Tips to describe a proper scope
  • Accreditation versus certification
  • The use of certification logos

Audits information security

2
  • Excelling in information security: best practices
  • Operational Capabilities: The Backbone of Information Security

NEN 7510

4
  • Transition to NEN 7510-1:2024
  • NEN 7510 without healthcare institution?
  • How to expand with NEN 7510
  • The differences between ISO 27001 and NEN 7510

NIS2 Directive

5
  • Transition CyberFundamentals 2023 to 2025
  • ISO 27001 in a NIS2 context in Belgium
  • Self-assessment & CyFun verification: best chance of success
  • NIS2 liability for board members
  • CyberFundamentals Framework in Belgium: what is the relationship with NIS2?

Assurance audits

1
  • ISAE 3402 vs SOC 2: what is the difference?

Audits privacy

8
  • Checklist for your BC 5701 certification
  • Transition to ISO/IEC 27701:2025
  • Whitepaper GDPR Certification Standard and Criteria BC 5701
  • BC 5701 certification: where do you start?
  • Data breach: What is it and how do you prevent it?
  • Your record of processing activities and the GDPR
  • Your Data Protection Officer and the GDPR
View Categories

NEN 7510 without healthcare institution?

1 min read

The standard NEN 7510 focuses on the following target groups:

  • healthcare institutions;
  • other administrators of personal health information.

In this article, we highlight a situation concerning the certification of the latter target group, referred to as ‘administrator’. This target group has healthcare institution(s) as its client, referred to as ‘healthcare client’.

Healthcare institution

healthcare institutionWhereas it is obvious for healthcare institutions to process personal health information, this is not always the case for administrators. The situation may arise where an administrator is asked by a healthcare client to comply with NEN 7510, while the administrator has no other healthcare clients (yet).

Administrator

An administrator is eligible for a NEN 7510 certification if it can demonstrate that:

  • Personal health information is processed;
  • The Statement of Applicability contains healthcare-specific controls relevant to the processing of the personal health information, and which result from the information security risk assessment.

If your organization does not yet have a healthcare client, it is not yet processing personal health information. For this reason, your organization is not eligible for a NEN 7510 certificate.

Solution

There is a solution for the above situation. Your organization first chooses ISO 27001 certification. This already covers a large part of the NEN 7510 requirements. The service is then started and after a certain period the ISO 27001 certification is expanded with NEN 7510. You can read how to approach this extension in the article: How to expand with NEN 7510.

Do you have additional questions? Please contact one of our specialists. They will be happy to help you.

Share This Article :

  • Facebook
  • X
  • LinkedIn
Updated on 21 February 2024
Transition to NEN 7510-1:2024How to expand with NEN 7510

Accreditation

RvA C548Brand Compliance B.V. has accreditation (C548) to certify ISO 27001, ISO 27701 NEN 7510 and ISO 9001 technical area 33 information technology and 35 other services.

View our accreditations

Contact

Have a question about certification, verification or assurance?

info@brandcompliance.com
+31 (0)73 220 2000

Prefer local contact details?
View our locations

Our locations

‘s-Hertogenbosch, The Netherlands

Antwerp, Belgium

Ottignies-Louvain-la-Neuve, Belgium

Stockholm, Sweden

Luxembourg, coming soon

Practical information

Privacy statement

Terms and conditions

Company details

Feedback and complaints

 

© Copyright 2026 Brand Compliance