NEN 7510 Penetration Testing: Evidence for Healthcare Information Security
A NEN 7510 penetration test tests the systems that hold patient data: access, authentication, logging and data exchange; a retest within 90 days is included.
What is tested and why it matters
Validating the technical controls of NEN 7510 where patient data is processed.
Healthcare providers in the Netherlands must apply NEN 7510, NEN 7512 and NEN 7513 under the Besluit elektronische gegevensverwerking door zorgaanbieders; the Inspectie Gezondheidszorg en Jeugd (IGJ) uses these standards as its assessment framework, and ICT suppliers to healthcare receive them through their contracts. The standard requires that technical vulnerabilities are managed, that security is tested during development and acceptance and that the effectiveness of controls is evaluated. A penetration test provides that evidence and shows, before an auditor or an incident does, whether a user can reach records outside their own care relationship, whether access is logged as NEN 7513 requires and whether the systems around the electronic patient record hold.
Who needs this assessment
Organisations that benefit most.
This assessment is designed for healthcare providers and their ICT suppliers that must demonstrate to auditors, the IGJ and their customers that the technical controls of NEN 7510 work in practice.
Hospitals, mental health institutions, nursing and care organisations and general practice groups preparing for a NEN 7510 certification audit or an IGJ visit
Vendors of electronic patient record systems, patient portals and care applications that must show NEN 7510 compliance to their healthcare customers
Healthcare hosting and managed service providers processing patient data on behalf of care providers
Organisations connecting a patient portal to DigiD, where the yearly DigiD assessment and NEN 7510 overlap
Healthcare organisations in scope of NIS2 that use NEN 7510 as the framework for the measures of Article 21
Care organisations after a data breach or an access incident involving patient records
Where these assessments are relevant
- Financial services: customer portals, payment processing, and cloud-hosted transaction infrastructure.
- SaaS and technology: application validation before production deployment or enterprise procurement.
- Healthcare: digital systems handling patient data, clinical records, and connected medical devices.
- Retail and e-commerce: web applications processing transactions, customer accounts, and payment data.
What the assessment produces
The insight and evidence delivered at the conclusion of the assessment.
Every assessment concludes with a structured report covering technical findings, severity ratings, evidence and remediation guidance, written for the certification auditor and the IGJ. Reports are delivered through the Pentrox Portal and are available for download at any time.
- Independent validation that the technical controls of NEN 7510 work on the systems that hold patient data
- Verified access control on patient records: whether users can reach records outside their own care relationship
- Verified logging of record access as required by NEN 7513, including whether the log can be bypassed
- Reporting structured for the certification auditor, the IGJ and the board
- Portal access with real-time findings, retest workflow and report downloads for the lifetime of the client account
How an assessment runs
- Scope and Intake
- Planning
- Assessment
- Reporting
- Findings & Retest
Retesting of remediated findings is included as standard with every assessment.
Assessment methodology
Five phases from scope definition through verified remediation.
Each phase builds on the previous one. Scoping defines the systems that process patient data, application and infrastructure testing validates the controls, and the access and logging checks confirm the healthcare-specific requirements.
Scope and patient data flows
The systems that process patient data are mapped: electronic patient record, patient portal, care applications, APIs and supporting infrastructure. The scope is aligned with the ISMS boundary, so the test covers the systems the audit covers.
NEN 7510-1, NEN 7510-2, ISO 27001 clause 4.3Application and API testing
Patient portals, care applications and their APIs are tested manually for authentication, authorisation, session handling, injection and business logic flaws, following the OWASP Web Security Testing Guide.
OWASP WSTG, OWASP ASVS, NEN 7510-2 secure development controlsAccess control on patient data
Role and relationship checks are tested: can a user reach records of patients outside their own care relationship, and does the break-the-glass procedure leave a trace? Horizontal and vertical privilege escalation are documented with evidence.
NEN 7510-2 access control, NEN 7513Logging and infrastructure
Logging of record access is verified against NEN 7513: completeness, integrity and whether access paths exist that bypass the log. The supporting infrastructure, identity platform and data exchange with other care providers are tested for the controls of NEN 7512.
NEN 7513, NEN 7512, NIST SP 800-115Reporting for the auditor and the IGJ
Findings are documented with evidence, reproduction steps and a CVSS score, in a form an auditor can verify. Critical findings are communicated immediately during testing.
NEN 7510-2, ISO 27001 clause 9.1Scope and deliverables
What is included, what is excluded, and what is delivered.
The statement of work defines the exact systems, environments and testing approach before the assessment begins. The lists below reflect the standard scope for a NEN 7510 penetration test.
In scope
- Electronic patient record (EPD/ECD) and its interfaces
- Patient portals and care applications, including the DigiD login where present
- APIs and data exchange with other care providers, laboratories and pharmacies
- Authentication, authorisation and the care relationship checks on patient records
- Logging of record access (NEN 7513): completeness, integrity and bypass paths
- Identity platform, remote access and the supporting infrastructure
- Security of workstations and shared devices where the ISMS scope includes them
Out of scope
- Organisational controls and policy review (the ISMS audit itself)
- Physical security of care locations (available as a separate mystery guest assessment)
- Medical devices and their networks unless explicitly agreed
- Denial-of-service testing against production systems unless explicitly agreed
What you receive
- Executive summary Security posture of the systems that hold patient data, severity distribution and remediation priorities written for the board, the certification auditor and the IGJ.
- Detailed findings Each vulnerability documented with evidence, reproduction steps, CVSS severity rating and remediation advice.
- Access and logging verification The result of the care relationship checks and the NEN 7513 logging verification, including any bypass paths found.
- Remediation plan Prioritised by exploitability and impact on patient data for efficient resolution.
- Portal access Real-time findings, report downloads, retest workflow and team management through a dedicated platform.
- Findings meeting A scheduled session to align on risks, priorities and the remediation approach.
- Retest report Verification results after remediation, documenting each finding with its updated status.
Read more
What a penetration test costs
Indicative prices by service, what moves the number, and what the price includes.
Why the report is the real deliverable
What a report must contain to be useful to your team and to an auditor.
Retesting: how a fix is proven
What a retest checks, the three outcomes, and why the record matters in an audit.
When independent assessment is the right step
An independent assessment is required ahead of an audit, a product launch, or a funding round, and the organisation needs documented evidence from a third party.
Digital platforms handle revenue, customer data, or service delivery, and the security of those platforms has not been validated by an external party.
Existing security controls have been implemented but have not been tested from an attacker perspective to confirm they work as intended.
Timeline
Illustrative durations to support planning. Confirmed in the statement of work.
The duration of a NEN 7510 penetration test depends on the number of applications that process patient data, the complexity of roles and care relationships, and whether data exchange and infrastructure are included. The calibration bands below are indicative. Exact duration is confirmed in the statement of work.
What determines duration
- Number of applications and APIs that process patient data
- Number of roles and the complexity of care relationship rules
- Whether data exchange with other care providers (NEN 7512) is included
- Whether the identity platform and infrastructure are included
- Availability of test accounts per role and a test environment with realistic data
Actual duration is confirmed during scoping and depends on the number of systems and the depth of the access control checks. A statement of work confirms the exact scope and timeline before the assessment begins. The final report is delivered within five business days after completion of testing.
Why Pentrox
The operational standards behind every NEN 7510 assessment.
These operational standards apply to every NEN 7510 assessment Pentrox delivers, regardless of the size of the organisation or the number of systems in scope.
Tested against OWASP checklists
A recognised method, not a bespoke checklist.
Applications, portals and APIs are tested against the OWASP Web Security Testing Guide and the OWASP Top 10; infrastructure follows PTES and NIST SP 800-115. Each finding carries evidence, reproduction steps and a CVSS score, in the form an auditor and the IGJ can verify.
Patient data handled with care
Test accounts and masked evidence.
Testing uses test accounts and a test environment wherever possible. Evidence in the report is masked; no patient data is exported. Findings and reports are stored in the Pentrox Portal on a dedicated server in a datacenter in the European Union.
Access and logging verified, not assumed
Care relationship checks and NEN 7513 logging tested in practice.
The assessment proves whether a user can reach records outside their care relationship and whether that access appears in the log. These are the two questions an auditor and the IGJ ask first.
Portal-delivered results
Findings visible in real time, not buried in a PDF delivered weeks later.
The Pentrox Portal provides remediation tracking, retest requests, report downloads and team access management. Role-based access control is enforced on every account.
Retest included
Verification that fixes are effective, at no additional cost.
Remediated findings are flagged through the Portal and scheduled for verification. Each finding is re-evaluated individually. Retest cycles repeat until all findings are resolved.
Frequently asked questions
Practical answers for information security officers, CISOs and procurement in healthcare.
Is a penetration test mandatory under NEN 7510?
The standard does not use the words penetration test. It does require that technical vulnerabilities are managed, that security is tested during development and acceptance and that the effectiveness of controls is evaluated, in line with ISO 27001 controls 8.8 and 8.29 and clause 9.1. Certification auditors accept a penetration test as the most direct evidence for those requirements. Most certified healthcare organisations and their suppliers therefore test at least once a year and after major changes.
What is the difference between NEN 7510, NEN 7512 and NEN 7513?
NEN 7510 is the management system and the set of controls for information security in healthcare. NEN 7512 sets the requirements for secure electronic data exchange between care parties. NEN 7513 sets the requirements for logging access to patient records. A NEN 7510 penetration test covers the technical side of all three: the applications and infrastructure, the exchange interfaces and the logging.
Do we need NEN 7510 certification, or is compliance enough?
The Besluit elektronische gegevensverwerking door zorgaanbieders requires healthcare providers to apply the standard; it does not require a certificate. In practice, hospitals and health insurers increasingly demand certification from their ICT suppliers, and tenders ask for it. Whether you certify or not, the auditor or the customer will ask for evidence that the technical controls work; that is what this assessment provides.
How does this relate to the DigiD assessment?
A patient portal connected to DigiD needs the yearly DigiD assessment against the Norm ICT-beveiligingsassessments DigiD. Many of those requirements overlap with the NEN 7510 controls for web applications. Pentrox can combine both in one assessment, so the same test evidence serves the Register EDP-auditor for DigiD and the certification auditor for NEN 7510.
Is retesting included, and at what cost?
Retesting of remediated findings is included as standard with every assessment, within 90 days after report delivery. There are no additional charges for verifying that fixes have been implemented correctly. The retest is managed through the Pentrox Portal, where you flag remediated findings and request the retest.
How is patient data handled during the test?
Testing uses test accounts and, wherever possible, a test environment with realistic but non-identifying data. Where production is unavoidable, the statement of work defines the testing window, excluded operations and escalation contacts. Evidence in the report is masked and no patient data is exported. Findings and reports are stored in the Pentrox Portal on a dedicated server in a datacenter in the European Union, with mandatory two-factor authentication and role-based access.
Is the report delivered in Dutch or English?
Reports are delivered in English by default. Dutch-language reporting can be arranged when required. The statement of work confirms the reporting language before the assessment begins.
What happens when a critical vulnerability is found during testing?
Critical or blocking vulnerabilities are communicated immediately through the channel agreed at kickoff. Findings are published in the Pentrox Portal as they are confirmed, so remediation can begin before the final report is delivered. The escalation path is documented in the statement of work.
Which NEN 7510 controls does a penetration test provide evidence for?
Mainly the technological controls: management of technical vulnerabilities, secure development and security testing, access control, secure authentication, logging and monitoring, network security and cryptography. In the 2024 edition these follow the numbering of ISO 27002:2022 (controls 8.x), with the healthcare additions of NEN 7510-2.
Can this assessment also serve NIS2?
Yes. Healthcare is a sector under NIS2 and the Dutch Cyberbeveiligingswet. Article 21 requires, among other measures, policies to assess the effectiveness of measures. A NEN 7510 penetration test report with findings, reproduction steps and retest results is that evidence.