Kiteworks earns Dutch healthcare data security certification
Kiteworks said Tuesday it has received NEN 7510-1:2024 certification, the Dutch healthcare information security standard required for care organizations, for its Kiteworks Control Plane and Zivver Secure Communications Services. The move matters as Dutch regulators tighten scrutiny after major breaches and as healthcare vendors face pressure to prove compliance, not just claim it.
Why it matters: - The certification gives Dutch healthcare customers an independently verified security standard at a time when regulators are demanding proof, not promises. - NEN 7510 compliance is legally required for healthcare organizations in the Netherlands, and the standard now aligns more closely with broader European cyber rules tied to NIS2. - The certification also covers AI-related access controls and auditing, a growing gap for organizations handling patient data.
What happened: - Kiteworks announced it has earned NEN 7510-1:2024 certification for information security management in Dutch healthcare. - Brand Compliance B.V., an independent accredited third party, issued certificate NL 3069.1.1. - The certificate applies to Kiteworks USA LLC and affiliated companies including Kiteworks Europe AG, Kiteworks PTE LTD, Kiteworks BG Ltd, Dracoon GmbH, 123formbuilder S.R.L. and Zivver B.V. - The certification covers two products under one scope: the Kiteworks Control Plane and Zivver Secure Communications Services.
The details: - NEN 7510-1:2024 is the updated Dutch healthcare information security standard, published in December 2024. - The standard follows the same controls as ISO 27001:2022, with additional requirements tailored to healthcare organizations. - Dutch healthcare providers have been legally required to comply with NEN 7510 since 2008. - Since 2023, organizations must demonstrate compliance rather than simply declare it. - The standard overlaps with Dutch cyber legislation implementing the EU NIS2 directive, so NEN 7510 compliance also helps meet part of those requirements. - Kiteworks said the certified platform provides one audit trail across email, file sharing, file transfer, forms, APIs and agents. - The company said the platform uses one report an auditor can follow instead of multiple logs assembled from separate tools. - Kiteworks said the same access controls and audit trail now extend to AI agents handling patient data. - The company said the certification helps customers avoid relying on a patchwork of point solutions. - The company also pointed to industry gaps in audit readiness, including a finding that half of organizations cannot produce a full audit record of AI data access within one business day and only 17% can do so within an hour.
Between the lines: - The certification lands after a 2025 ransomware attack on Clinical Diagnostics, a Dutch lab supporting national cervical cancer screening, exposed the data of about 850,000 people. - Exposed information included citizen service numbers and other sensitive data. - In May 2026, the Dutch Health and Youth Care Inspectorate concluded Clinical Diagnostics had not met the required NEN 7510 standard at the time of the attack. - The inspectorate cited gaps including the lack of an independent information security audit and inadequate periodic risk reviews. - The regulator said complying with NEN 7510 could have reduced both the likelihood and the impact of the incident. - Dutch data breach reporting remains elevated: the Dutch Data Protection Authority logged 39,407 breach reports across sectors in 2025, up from 37,839 in 2024. - Kiteworks Field CTO Rick Goud said healthcare CISOs increasingly want independent verification, not vendor assurances. - Goud said Zivver already held NEN 7510 certification before the Kiteworks platform did. - Goud said many European organizations have stronger general security than AI governance, and only 26% have implemented purpose binding, which limits AI agents to approved tasks and data.
What's next: - Kiteworks said readers can learn more about the certification in its Compliance Brief. - The certification is likely to strengthen Kiteworks' pitch to Dutch healthcare buyers that need vendor proof aligned with their own regulatory obligations. - Healthcare organizations will still need to show their own compliance, but certified suppliers may reduce audit friction and security risk across the data chain.
The bottom line: - Kiteworks is using third-party certification to turn a compliance requirement into a sales advantage for healthcare data exchange and secure communications.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
Today in Healthcare
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.