New: ISO 42001 and NIS2 Supply Chain are available in the Compliance Tool.Explore standards and requirements →Careers
Healthcare & social care

Privacy and information security that fit day-to-day care.

Health information needs to be available for work and carefully protected. Connect arrangements for systems, staff and supply chain partners to the processes in which that information is used.

Which situations call for support?

A healthcare or social care organisation may have many arrangements in place yet still lack coordination or resources. Reasons to reorganise the work include:

  • A new system or partnership: for an electronic patient record, electronic client record, client portal or data exchange, use, access, supplier arrangements and privacy questions need to be considered together.
  • Insufficient capacity or an unfilled role: day-to-day privacy questions remain unresolved, security actions lack an owner or independent Data Protection Officer oversight needs to be established.
  • An assessment or incident: policies exist, but it is difficult to demonstrate how arrangements are implemented and improvements followed up.

Bring the actual issue and the processes involved. This helps us determine whether you mainly need specialist support, a defined implementation project or independent assessment.

Which questions does DCA help answer?

Existing care practices are the starting point. DCA helps translate privacy and information security into arrangements that the staff involved can put into practice:

  • Who may use which information? Connect the roles of employees and external parties to access arrangements and checks when people join, change roles or leave.
  • What should we agree with suppliers? Bring dependencies, available evidence and follow-up of supplier questions together.
  • Who follows up reports and improvements? Clarify who assesses incidents, who makes decisions and who checks that agreed actions have been carried out.
  • Which expertise is missing? Distinguish practical privacy support, information security and independent oversight. Record the role and reporting arrangements for each assignment.

A Privacy Officer or Information Security Officer can support implementation and provide advice. The position of an independent Data Protection Officer is established separately, as described in the RST customer story.

What does a workable approach look like?

  1. Define processes and information flows. Discuss the care or support process, systems used, locations and supply chain partners. Involve frontline staff alongside management, IT and those responsible for privacy.
  2. Assess existing arrangements and risks. Compare policies and supplier arrangements with day-to-day implementation. Identify decisions, controls or evidence that are still missing.
  3. Agree a workable plan. Assign owners to actions, agree DCA’s involvement and allocate staff time. Where appropriate, use the Compliance Tool; software is not a prerequisite for consultancy.
  4. Check effectiveness and adjust. Discuss checks, incidents and improvement actions regularly. Prepare an internal audit or independent assessment with a clear scope and follow-up.

Illustrative example: if a client portal becomes unavailable, the work plan may describe who contacts the supplier, how employees obtain essential information and who checks recovery. The team assesses whether those arrangements are workable in its own care process. This example does not describe an incident at a customer.

What remains with the care organisation?

Support only works if the people who know the process remain involved. We agree in advance which activities DCA carries out and who within your organisation provides information, decides and follows up.

  • Board and management: set priorities, provide resources and make formal decisions on risks and improvements.
  • Process owners and care teams: provide practical knowledge, assess whether arrangements are workable and carry out the agreed activities.
  • IT and supplier relationship owners: organise access, technical controls and follow-up of arrangements with system suppliers.
  • DCA: provides the agreed expertise, helps develop plans and documents, and supports implementation, assessment and reporting. Independent oversight and operational tasks have separate responsibilities.

Outsourcing activities does not remove your own responsibility for the care process and information security. A supplier certificate also does not replace an assessment of your own processes.

What healthcare experience is available?

At RST Zorgverleners DCA provides dedicated consultants for the roles of Privacy Officer, Information Security Officer and independent Data Protection Officer. The existing customer story describes the division of roles, collaboration with staff and the separation between implementation, advice and oversight.

RST does not use the Compliance Tool for this collaboration. The story therefore illustrates a consultancy model that can also operate without our software. The right allocation of roles for you depends on existing expertise and responsibilities.

How do you determine which requirements apply?

According to the IGJ explanation of NEN 7510 healthcare providers processing personal data in a healthcare information system must demonstrably work to NEN 7510. The inspectorate distinguishes between an effective management system, independent assessment and certification: a certificate is not a general legal requirement. For youth care, the IGJ refers to ISO 27001. First determine the nature of your services; the label “healthcare and social care” alone is not enough to establish the applicable requirements.

Explore the NEN 7510 approach and audit preparation and the article on the current NEN 7510 publications. The standard is also explained by NEN itself. Privacy questions and client arrangements are assessed separately for their applicability.

An assessment considers not only documentation but also what happens in practice. The article on preparing for an internal audit helps organise discussions, evidence and follow-up.

What is a useful next step?

  • You are missing a role or capacity: discuss the support needed, the current division of responsibilities and the independence required by the assignment.
  • The applicable requirements are still unclear: start with the Compliance Scan and bring details of your services and the systems used.
  • You want to manage tasks and evidence centrally: see the Compliance Tool in a demo using your own way of working as the starting point.

For an initial discussion, bring the key process, existing policies and the unresolved question. This allows us to discuss the resources required and cost breakdown without assuming a fixed lead time in advance.