NTA 7516 readiness for secure health communication
Asteron helps healthcare organisations and healthtech suppliers implement NTA 7516 for the secure, usable and interoperable exchange of personal health information by email and chat. We assess communication flows, supplier capabilities, organisational controls and user behaviour, then turn the findings into a practical implementation and evidence plan. The service is designed for organisations operating in the Netherlands and European healthtech vendors-including German companies entering the Dutch market-that must support local healthcare communication practices.
- Email and chat use cases mapped
- Organisational and supplier controls aligned
- Interoperability and usability assessed
- Evidence and rollout plan prepared
What is NTA 7516?
NTA 7516:2019 defines functional requirements for securely exchanging personal health information through ad-hoc communication between people. This includes email and chat or messenger functionality, whether provided directly or through a messaging portal.
The standard addresses five connected outcomes: availability, integrity, confidentiality, interoperability and usability. Security must work in everyday communication between professionals, patients, clients and other authorised participants—not only in a technical test environment.
NTA 7516 is different from standards governing structured system-to-system healthcare exchange. It is relevant when people compose and exchange individual messages containing personal health information.
Who needs NTA 7516?
An organisation does not become compliant merely by purchasing a secure-mail product. The healthcare organisation remains responsible for configuration, policies, user access, working practices, supplier management and ongoing review.
Is NTA 7516 mandatory?
NTA 7516 is not currently a generally mandatory certification requirement. An organisation may choose not to use email or chat for personal health information.
When health information is exchanged through these channels, applicable GDPR and Dutch healthcare-security duties still require appropriate technical and organisational protection. NTA 7516 provides a recognised and practical reference for demonstrating how secure ad-hoc communication has been designed and controlled.
What secure communication requires
Confidentiality
Only intended and authorised recipients should be able to access the information. Authentication, access management, secure transmission, storage and protection against addressing errors must reflect the sensitivity of health data.
Integrity
Messages, attachments, sender information and delivery status must remain reliable. The organisation should be able to identify unauthorised changes and preserve relevant communication evidence.
Availability
Authorised users need dependable access when communication supports care or operational decisions. Availability, continuity, recovery and supplier dependencies must be understood.
Interoperability
Secure communication should work across relevant organisations and solutions without forcing recipients into unsafe workarounds. Product and supplier claims must be tested against actual communication scenarios.
Usability
Security controls must be understandable and practical for professionals and patients. If the secure route is difficult to recognise or use, people may return to ordinary email, consumer messaging or other uncontrolled channels.
Organisation and supplier responsibilities
Healthcare organisation or healthtech operator
- – Define which communication flows may contain health information
- – Establish approved channels and prohibited workarounds
- – Configure identities, roles, access and retention
- – Train users and maintain clear operating procedures
- – Manage incidents, suppliers and periodic reviews
- – Preserve evidence that controls operate as intended
Communication product or service provider
- – Explain which NTA 7516 requirements the product supports
- – Provide transparent security and interoperability information
- – Maintain appropriate product and service controls
- – Support secure configuration and customer responsibilities
- – Supply relevant assurance, incident and continuity evidence
- – Clearly disclose requirements that remain with the customer
Responsibility must be allocated explicitly in contracts and implementation documentation. It should never be inferred from marketing claims alone, and residual customer duties should be visible on the record.
Current certification status
This service therefore provides NTA 7516 assessment and implementation readiness, not certification. Certification badges should not be displayed and no provider should be described as currently NTA 7516 certified without separate, current evidence.
Relationship with other Dutch healthcare standards
Existing NEN 7510 or ISO 27001 controls can be reused, but they do not automatically demonstrate that specific email and chat workflows satisfy NTA 7516. Communication flows must be assessed on their own merits.
How Asteron delivers the project
Communication-flow discovery
Identify senders, recipients, data types, channels, systems and recurring workarounds. Distinguish professional-to-professional, professional-to-patient and cross-organisation flows.
Requirement and responsibility mapping
Allocate NTA 7516 controls between the organisation, product and external providers so that no requirement is left ambiguous.
Product and supplier assessment
Review functionality, contracts, evidence, interoperability with common Dutch solutions and service dependencies.
Organisational implementation
Prepare policies, approved-use rules, access, procedures, training and incident handling that make secure communication the default option.
Scenario validation
Test representative professional-to-professional and professional-to-patient workflows end to end, including addressing, delivery, response and error handling.
Evidence and rollout plan
Document residual gaps, owners, priorities and readiness evidence. Prepare a phased rollout aligned with change and training capacity.
Deliverables
Assessment and design
- – Defined NTA 7516 scope and communication inventory
- – Requirement-to-control mapping
- – Product and supplier evidence review
- – Responsibility and contract matrix
- – Gap and risk assessment
Implementation and evidence
- – Secure communication policy and approved-use rules
- – Configuration and operating-control requirements
- – User guidance and training content
- – Scenario-based validation record
- – Prioritised remediation and rollout plan
- – Management readiness summary
NTA 7516 readiness pricing
Covers a scoped NTA 7516 readiness and implementation project for one principal organisation, agreed communication environment and representative set of email or chat workflows.
Final pricing depends on the number of products and suppliers, communication channels, user groups, legal entities, integrations, patient-facing workflows and the quality of existing documentation.
An existing Asteron Compliance Core may reduce discovery and evidence work, but it does not create an automatic fixed discount.
- – 40% at signing
- – 40% after delivery of the assessment and control map
- – 20% after the contracted readiness deliverables
Prices exclude VAT where applicable.
What remains separate
External providers are selected, contracted and paid separately unless explicitly included in the proposal.
- – Purchase or licensing of secure email, chat or portal products
- – Product development and integration work
- – Migration of users, mailboxes or historical messages
- – Penetration testing and technical remediation
- – Formal external legal opinions
- – Supplier fees and third-party assurance activities
- – Certification, because no current NTA 7516 certification engagement is offered
Frequently asked questions
What is NTA 7516?
NTA 7516:2019 is the Dutch technical agreement that defines functional requirements for the secure ad-hoc exchange of personal health information between people, by email and chat or messenger. It covers confidentiality, integrity, availability, interoperability and usability.
Does NTA 7516 apply to both email and chat?
Yes. It applies to ad-hoc communication between people that contains personal health information, whether delivered by email, by chat or through a messaging portal. It does not govern structured system-to-system healthcare exchange.
Is NTA 7516 legally mandatory?
NTA 7516 is not a generally mandatory certification requirement. However, when personal health information is exchanged by email or chat, applicable GDPR and Dutch healthcare-security duties still require appropriate technical and organisational protection, and NTA 7516 provides a recognised reference for how to meet them.
Can health information be sent by ordinary email?
Ordinary consumer email generally does not provide the confidentiality, integrity, addressing controls and evidence expected for personal health information. Organisations should define approved channels and prohibit ad-hoc workarounds, using NTA 7516 as the design reference.
Does buying secure-email software make us compliant?
No. The healthcare organisation remains responsible for configuration, policies, user access, working practices, supplier management and ongoing review. A secure product is a component of NTA 7516 readiness, not a substitute for organisational controls.
Can an organisation currently obtain NTA 7516 certification?
No. The former NCS 7516-1 certification scheme was withdrawn and previously issued supplier certificates were withdrawn from 15 May 2022. Asteron therefore delivers assessment and implementation readiness, not certification.
What happened to the previous supplier certificates?
Certificates issued under the NCS 7516-1 scheme were withdrawn from 15 May 2022 when the scheme was discontinued. Any current claim of NTA 7516 certification should be verified against separate, current evidence.
How does NTA 7516 relate to NEN 7510?
NEN 7510 governs organisation-wide information security in Dutch healthcare. NTA 7516 addresses a specific communication use case within that scope. NEN 7510 or ISO 27001 controls can be reused, but they do not automatically demonstrate that specific email and chat workflows satisfy NTA 7516.
Does NTA 7516 apply to patient communication?
Yes. It applies to ad-hoc communication with patients or clients as well as with other authorised participants. Patient-facing workflows must remain usable so that people are not pushed to unsafe alternatives.
What should a healthtech vendor entering the Netherlands prepare?
Existing communication features should be assessed against Dutch healthcare workflows and NTA 7516 requirements. Vendors should be able to explain which requirements the product supports, which remain with the customer, and how interoperability with common Dutch solutions has been validated.
How much does an NTA 7516 readiness project cost?
A scoped NTA 7516 readiness and implementation project starts from €6,900. Final pricing depends on the number of products and suppliers, communication channels, user groups, legal entities, integrations and existing documentation.
Official references
- – NEN — NTA 7516:2019 secure ad-hoc communication of personal health information
- – NEN — NEN 7516 revision and standardisation programme
- – NEN — status of the NCS 7516-1 certification scheme and withdrawal notice
- – NEN 7510 information-security-in-healthcare portal
Last reviewed: July 2026
Asteron is not endorsed by or partnered with NEN, ISO, any supervisory authority or communication product provider.
Make secure healthcare communication work in practice
Understand where personal health information is exchanged, establish which controls belong to your organisation and suppliers, and prepare a usable NTA 7516 implementation for the Dutch healthcare market.
