✓ OSCP · OSWE · OSEP certified | Joost performs every test himself — no juniors | Response within 1 business day | Based in Haarlem

Pentest for the Healthcare Sector

Healthcare institutions process special categories of personal data and are exposed to targeted cyberattacks. The NEN 7510 standard and the GDPR set specific requirements for information security in healthcare — including technical vulnerability testing.

Why is cybersecurity extra critical in healthcare?

  • Patient data is the number one target of ransomware groups
  • System outages directly impact patient safety
  • The GDPR sets strict requirements for protecting special categories of personal data
  • NEN 7510 requires demonstrable technical security management
  • Regulators NZa and IGJ expect a demonstrable level of security

What do we test for healthcare institutions?

  • Electronic health record (EHR) systems and patient portals
  • Interfaces with external systems (VIPP, LSP, ZorgMail)
  • Medical devices and IoMT environments
  • VPN and remote access for healthcare staff
  • Microsoft 365 and cloud environments
  • Network segmentation between care applications

NEN 7510 and our reporting

Our report includes a mapping to NEN 7510 controls, so findings can be used directly as input for your ISMS audit. We also provide recommendations that fit the operational reality of a healthcare environment — no measures that disrupt care delivery.

FAQ

Is NEN 7510 mandatory for healthcare institutions?

NEN 7510 is the Dutch standard for information security in healthcare and is widely required by health insurers, regulators and chain partners. Conformity with NEN 7510 is mandatory for connecting to the LSP or VIPP.

How do you handle patient data during a pentest?

We always test in a test environment or with anonymised data. Test account and scope are documented in writing. We sign a GDPR-compliant data processing agreement before the test.

Can you also test medical devices?

We test the network connectivity and communication protocols of medical devices (IoMT). Direct testing of the device itself requires coordination with the manufacturer and falls outside standard scope.

Also see: DigiD pentest | ISO 27001 | vulnerability scan | request a quote

Scroll to Top