Care & care related

Information security in healthcare

Kynexis Information Security supports healthcare organisations and organisations around information security, NIS2 and the Dutch Cybersecurity Act. The approach connects health and customer data, critical care processes, NEN 7510, suppliers and board-level responsibility to demonstrable execution.

Caregivers in conversation with an older client in a wheelchair
Sectoral approachDigital resilience supports safe and continuous care.

Your context

Information security for reliable and continuous care

Care, customer support, advocacy, well-being and healthcare providers are heavily dependent on digital information. Availability, confidentiality and reliable data exchange directly affect people, professionals and continuity.

The broad name care and care-related includes organisations that process health data, support healthcare processes or work closely with healthcare providers. The relevant frameworks and research progress follow from their own roles and risks.

Care is one of the sectors that is given particular attention within NIS2 and the Dutch Cybersecurity Act. Whether an organisation is directly governed by the law depends, inter alia, on the legal entity, scope and actual service provision. In addition, health care-related organisations may receive additional security and evidence requirements through contracts, municipalities, healthcare providers or other chain partners.

Digital patient monitor in a modern treatment room

Digital dependency in practice

Bedside care is becoming increasingly digital

Medical equipment, client files, communications and suppliers are part of one digital care chain. Information security therefore follows the organisation's daily care practice and recovery capabilities.

Focus areas

Reducing digital risks to manageable choices

The scope is tailored to the organisation, its societal mission, critical processes and digital dependencies.

Health and customer data

Access, exchange, logging, retention periods and careful processing.

Digital continuity

Critical processes, relapse procedures, backup, recovery and crisis communication.

Suppliers and chains

agreements, assurance, incident reports, management rights, links and exit.

Governance, NIS2 and oversight

Connecting entity status, knowledge, risk appetite, duty of care, reporting obligation, ownership and reporting with quality and continuity.

Governance and digital resilience

Appropriate frameworks for care and organisations around care

For healthcare providers, Kynexis Information Security connects the Dutch Cybersecurity Act with the Governance Code Healthcare 2022, NEN 7510, information security, continuity, data and suppliers. Existing NEN 7510 or ISO 27001 control may be a strong basis; NIS2 specific topics such as entity status, registration, reporting obligation and board-level obligations are added in a targeted manner.

For care-related organisations, the legal entity, actual service, data flows, size and chain arrangements shall determine the appropriate framework. The scope clause distinguishes between direct legal obligations and contractual chain requirements and translates them into a proportionate approach.

Read about the Governance Code Healthcare 2022 and information securityStart with a Cyber Security Baseline assessmentIdentify health risks with a risk analysis information securityOrganize structural direction with CISO as a ServiceView the central chapter on NIS2 and the Dutch Cybersecurity ActDo the NIS2 QuickscanView the NIS2 GAP analysis for healthcare organisationsAllow for detectable operation tests with an NIS2 auditRead what a data breach shows with a supplierNIS2 Boardroom Training for governance and oversightRead the customer case about board-level grip on AI and digital resilience

Your result

Clear priorities and demonstrable progress

Kynexis Information Security translates research into decision-making information for the board and executive management and into concrete actions for those responsible in the organisation.

  • Overview of critical processes, data and chain dependencies
  • Board-level interpretation of risks for people, quality and continuity
  • Clear choice of appropriate standards and research progress
  • Roadmap with priorities, ownership and demonstrable follow-up
KYNEXISInsight and direction
  1. Investigations
  2. Prioritize
  3. Run
  4. Embed
View the governance GAP analysis →

Insight and execution

Research and support related to this

The appropriate route follows from your steering question, desired security and the current maturity of the organisation.

Governance and assurance

Governance gap analysis

Key the translation of governance principles into ownership, digital risks, reporting and demonstrable follow-up.

View Governance gap analysis
Actual operation

Cyber Security Audit

Review technique, processes, suppliers and operational control with independent evidence.

View Cyber Security Audit
Structural support

CISO as a Service

Organize direction, reporting, supplier control and a fixed improvement cycle with experienced guidance.

View CISO as a Service
Preparing to act

Incident management

Work out roles, decision-making, communication and recovery before speed and overview make the difference.

View Incident management

Frequently Asked Questions

Practical answers for care & care related

Which organisations are covered by care-related organisations?

This could include client organisations, stakeholders, health support organisations, civil society initiatives and healthcare providers. The scope is determined by the actual service and data.

Is NEN 7510 always applicable?

The applicability and desired depth depend on the role, service, contractual requirements and processing of healthcare information. Kynexis Information Security carefully reflects this in the scope assessment.

Does every care organisation fall under NIS2 and the Dutch Cybersecurity Act?

The healthcare sector falls within its scope, but the assessment is made by legal entity and depends, inter alia, on the size and actual service provision. A targeted scope clause clarifies the obligations of the organisation.

Is NIS2 replacing NEN 7510?

No. NIS2 and the Dutch Cybersecurity Act contain legal obligations, while NEN 7510 is a sector-specific standard for information security in healthcare. A working NEN 7510 facility can provide important building blocks for the implementation of the duty of care.

Can management or oversight get a separate session?

Yes. Risks, responsibilities and findings can be translated into an board-level session with concrete questions, choices and priorities.

Wouter Parent

A technical incident can have immediate consequences for care provision. Therefore, make clear in advance which processes should not stop and how safe recovery is organised.

Current
WebinarFree webinars on NIS2, cyber risk management and oversight

Choose a live session for the board, executive team, supervisory board or board of trustees and register directly.

View webinars and dates