NEN 7510:2011

Organizations in the Netherlands must demonstrate control over patient health data in accordance with the NEN 7510 standard.

Microsoft and NEN 7510:2011

Microsoft has analyzed our current certifications and assurance statements and created a NEN 7510 coverage report (available on the Service Trust Platform), which maps those certifications and assurance statements against the NEN 7510 controls for which Microsoft is responsible as a cloud service provider. This document can help customers determine which additional controls they must implement to ensure that their use of Microsoft cloud services in connection with the storage or processing of patient health information complies with NEN 7510.

Learn how to accelerate your NEN 7510 deployment with our Azure Security and Compliance Blueprints.

Download the Microsoft Cloud - Azure and Office 365 NEN7510-2011 Standard Coverage User Guide

Microsoft in-scope cloud services

NEN 7510 Overview

Organizations in the Netherlands that process patient health information must demonstrate control over that data and their organization consistent with the requirements set out in the NEN 7510 standard. Microsoft is not itself subject to NEN 7510, but its cloud customers in the healthcare sector need to establish that they comply with NEN 7510 with respect to solutions built on the Microsoft Cloud. Microsoft cloud services undergo various periodic certifications and audits, some of which include elements closely related to requirements specified in NEN 7510.

female working on laptop with male colleague looking at her screen
female working on laptop with male colleague looking at her screen

Assess your GDPR compliance

Find out if your organization meets personal data protection requirements. Take our quick, interactive 10-question evaluation to assess your readiness to comply with the GDPR today.

Take the assessment

Frequently asked questions

Expand all

Demonstrating NEN compliance is the responsibility of the healthcare organization (the “customer”). When using a cloud services vendor, customers typically demand assurances from the vendor, and add their own (additional) technology and organizational decisions, choices, and processes. This results in an overall assessment by the customer on its NEN 7510 compliance, which can be submitted for review or certification to a third-party auditor. The NEN 7510 coverage report provides insight into which NEN 7510 controls are covered by Microsoft Online Services, but, as such, does not cover end-to-end compliance.

The responsibility for NEN 7510 compliance is applicable to Dutch Healthcare organizations. It requires the organization to implement an information security management system and to address risk with appropriate technical and organizational measures. For Microsoft in its role as cloud service provider, NEN 7510 compliance is not the objective, nor is it technically feasible. When a customer implements or uses Microsoft Online Services, those services may be in scope of a NEN 7510 evaluation. However, the organization must add its own (additional) controls, choices, and processes that are part of the overall NEN 7510 evaluation. The objective of the report is to demonstrate that a Healthcare entity can adopt the Microsoft Online Services in a manner that is compliant with NEN 7510.

Microsoft Online Services provides many controls that help organizations within Dutch Healthcare with their NEN 7510 compliance needs. However, an organization needs to complement those vendor assurances with their own implementation choices, additional technology controls, and administrative processes. The report shows already over 94% direct coverage of the full list of applicable controls. For the remaining controls, Microsoft provides guidance in the report on how compliance with those controls can be demonstrated.

Note: Implementing the full list of controls is not the primary purpose of NEN 7510 (although the large coverage of Microsoft Online Services does help). NEN 7510 mandates the implementation of a risk-based information security system that can be used by an organization to determine which controls are applicable to them.

No. It is a supporting tool for the customer’s internal NEN 7510 assurance process and helps to establish confidence and trust that NEN 7510 compliance is feasible. The report (created by independent auditor, KPMG) has a descriptive status and includes a legal disclaimer.

Microsoft created a mapping between its global assurances to the controls in the NEN 7510 standard. Microsoft then hired KPMG (an independent auditor) to perform an independent review on the control mapping to NEN 7510, which resulted in the report.

The report is provided with you under a non-disclosure agreement (NDA), on the basis that it is for customer information only and that it will not be copied or disclosed via other channels than the Microsoft Service Trust Platform.

Customers can share the report with their own internal or external auditor as part of their compliance or assurance processes.