Health and customer data
Access, exchange, logging, retention periods and careful processing.

Care & care related
Kynexis Information Security supports healthcare organisations and organisations around information security, NIS2 and the Dutch Cybersecurity Act. The approach connects health and customer data, critical care processes, NEN 7510, suppliers and board-level responsibility to demonstrable execution.

Your context
Care, customer support, advocacy, well-being and healthcare providers are heavily dependent on digital information. Availability, confidentiality and reliable data exchange directly affect people, professionals and continuity.
The broad name care and care-related includes organisations that process health data, support healthcare processes or work closely with healthcare providers. The relevant frameworks and research progress follow from their own roles and risks.
Care is one of the sectors that is given particular attention within NIS2 and the Dutch Cybersecurity Act. Whether an organisation is directly governed by the law depends, inter alia, on the legal entity, scope and actual service provision. In addition, health care-related organisations may receive additional security and evidence requirements through contracts, municipalities, healthcare providers or other chain partners.

Digital dependency in practice
Medical equipment, client files, communications and suppliers are part of one digital care chain. Information security therefore follows the organisation's daily care practice and recovery capabilities.
Focus areas
The scope is tailored to the organisation, its societal mission, critical processes and digital dependencies.
Access, exchange, logging, retention periods and careful processing.
Critical processes, relapse procedures, backup, recovery and crisis communication.
agreements, assurance, incident reports, management rights, links and exit.
Connecting entity status, knowledge, risk appetite, duty of care, reporting obligation, ownership and reporting with quality and continuity.
Governance and digital resilience
For healthcare providers, Kynexis Information Security connects the Dutch Cybersecurity Act with the Governance Code Healthcare 2022, NEN 7510, information security, continuity, data and suppliers. Existing NEN 7510 or ISO 27001 control may be a strong basis; NIS2 specific topics such as entity status, registration, reporting obligation and board-level obligations are added in a targeted manner.
For care-related organisations, the legal entity, actual service, data flows, size and chain arrangements shall determine the appropriate framework. The scope clause distinguishes between direct legal obligations and contractual chain requirements and translates them into a proportionate approach.
Read about the Governance Code Healthcare 2022 and information security →Start with a Cyber Security Baseline assessment →Identify health risks with a risk analysis information security →Organize structural direction with CISO as a Service →View the central chapter on NIS2 and the Dutch Cybersecurity Act →Do the NIS2 Quickscan →View the NIS2 GAP analysis for healthcare organisations →Allow for detectable operation tests with an NIS2 audit →Read what a data breach shows with a supplier →NIS2 Boardroom Training for governance and oversight →Read the customer case about board-level grip on AI and digital resilience →Your result
Kynexis Information Security translates research into decision-making information for the board and executive management and into concrete actions for those responsible in the organisation.
Insight and execution
The appropriate route follows from your steering question, desired security and the current maturity of the organisation.
Key the translation of governance principles into ownership, digital risks, reporting and demonstrable follow-up.
View Governance gap analysis →Review technique, processes, suppliers and operational control with independent evidence.
View Cyber Security Audit →Put digital threats, vulnerabilities, impact and appropriate measures structured in the picture.
View Information security risk assessment →Organize direction, reporting, supplier control and a fixed improvement cycle with experienced guidance.
View CISO as a Service →Work out roles, decision-making, communication and recovery before speed and overview make the difference.
View Incident management →Frequently Asked Questions
This could include client organisations, stakeholders, health support organisations, civil society initiatives and healthcare providers. The scope is determined by the actual service and data.
The applicability and desired depth depend on the role, service, contractual requirements and processing of healthcare information. Kynexis Information Security carefully reflects this in the scope assessment.
The healthcare sector falls within its scope, but the assessment is made by legal entity and depends, inter alia, on the size and actual service provision. A targeted scope clause clarifies the obligations of the organisation.
No. NIS2 and the Dutch Cybersecurity Act contain legal obligations, while NEN 7510 is a sector-specific standard for information security in healthcare. A working NEN 7510 facility can provide important building blocks for the implementation of the duty of care.
Yes. Risks, responsibilities and findings can be translated into an board-level session with concrete questions, choices and priorities.

A technical incident can have immediate consequences for care provision. Therefore, make clear in advance which processes should not stop and how safe recovery is organised.