NEN 7510 Internal Audit
The final rehearsal for your certificate.
The NEN 7510 standard makes it mandatory: before you can be certified, you must carry out an internal audit. Many organizations have an internal employee tick off the checkboxes. The risk? Organizational blind spots.
Schedule your NEN Internal AuditThe NEN 7510 internal audit is an independent review of your healthcare information security, performed by a senior auditor. Within 72 hours you receive a report with findings, recommendations and the improvements to make before the external audit or an inspection. Fixed price: 1,600 euros for a small healthcare organization.
The risk? Organizational blind spots.
We see it in every healthcare organization that checks its own work: whoever built the system inevitably looks at it with biased eyes. Exactly the findings the external auditor or the inspectorate will see remain hidden, until the moment fixing them is most expensive.
If you work in the processes every day, you no longer see the risks. Our consultants carry out this audit independently. We play 'devil's advocate', but on your side, identifying deviations an external auditor would also find, so you can still resolve them.
Strict on the content, gentle on the relationship.
An independent pair of eyes removes those blind spots while you can still adjust course. The external audit loses its surprises, your accountability toward the inspectorate and chain partners stands, and your team puts its energy back into care instead of the file.
-
A critical look at your paperwork
Our approach is thorough and starts at the foundation: your documentation.
-
Practical testing in the workplace
We speak with your employees, from the caregiver at the bedside to the system administrator.
-
Targeted samples
Finally, we put things to the test with targeted samples.
-
Within 3 working days: report and explanation
So you are audit-ready, without stress.
A relaxed atmosphere, a thorough audit.
An audit may sound daunting, but we create a relaxed atmosphere. We do not come to point fingers, but to improve processes.
Fully prepared: we make sure you are prepared for the audit. Our knowledge of audit standards means you can focus on continuous improvement, not on paperwork perfection.
Full insight, no panic: you know exactly where you stand, with a focused action list to take care of the final details.
Crystal-clear priorities: teams stop wasting time on noise and unimportant side issues.
Sources
The standard texts and supervisory guidance this page is based on.
- NEN 7510: information security in healthcare NEN
- NEN 7510-1:2024, the standard text NEN
- Questions about NEN 7510 and its supervision Dutch Health and Youth Care Inspectorate (IGJ)
Schedule your NEN 7510 Internal Audit before the external auditor or inspectorate does.
- 01
Response within one business day
You hear from us personally, never from an autoresponder.
- 02
A call with a senior specialist
45 minutes with a consultant who knows your standard and sector. Free and without obligations.
- 03
A concrete proposal
You decide at your own pace. The engagement is concluded directly with the consultant.
Prefer direct contact? rob@auditdirect.nl +31 6 300 24 200
Frequently Asked Questions about the NEN 7510 Internal Audit by AuditDirect
Why is an internal audit required for NEN 7510?
The standard requires independent testing of the security of patient data. AuditDirect provides the mandatory objectivity that is often difficult to organize internally.
What do you specifically look at in NEN 7510?
We focus on healthcare-specific requirements such as logging (access to records), strong authentication (MFA/UZI), and physical security of archives and servers.
What does an internal audit cost?
For SME healthcare organizations, we charge a fixed price of €1,600 (excl. VAT). This includes the audit day, reporting, and travel costs.
Does this replace the external audit?
No. The internal audit is the preparation to identify and fix errors. The external audit by a certification body is the official exam.
What about confidentiality during the audit?
Our auditors always sign a confidentiality agreement. Patient data is never included in our reports; we only assess the process.