AsteronAsteron

    NTA 7516 readiness for secure health communication

    Asteron helps healthcare organisations and healthtech suppliers implement NTA 7516 for the secure, usable and interoperable exchange of personal health information by email and chat. We assess communication flows, supplier capabilities, organisational controls and user behaviour, then turn the findings into a practical implementation and evidence plan. The service is designed for organisations operating in the Netherlands and European healthtech vendors-including German companies entering the Dutch market-that must support local healthcare communication practices.

    View NTA 7516 pricing
    • Email and chat use cases mapped
    • Organisational and supplier controls aligned
    • Interoperability and usability assessed
    • Evidence and rollout plan prepared

    What is NTA 7516?

    NTA 7516:2019 defines functional requirements for securely exchanging personal health information through ad-hoc communication between people. This includes email and chat or messenger functionality, whether provided directly or through a messaging portal.

    The standard addresses five connected outcomes: availability, integrity, confidentiality, interoperability and usability. Security must work in everyday communication between professionals, patients, clients and other authorised participants—not only in a technical test environment.

    NTA 7516 is different from standards governing structured system-to-system healthcare exchange. It is relevant when people compose and exchange individual messages containing personal health information.

    Who needs NTA 7516?

    Healthcare providers
    Staff exchange personal health information with patients, other providers and external parties.
    Healthtech platforms
    Products include messaging, inbox, notification, email or chat functionality used in healthcare workflows.
    Secure communication providers
    Customers expect the service to support NTA 7516 requirements and transparent evidence.
    European vendors entering the Netherlands
    Existing communication features must be assessed against Dutch healthcare expectations and workflows.
    Procurement and compliance teams
    Supplier claims, contracts, responsibilities and residual controls need to be verified before deployment.

    An organisation does not become compliant merely by purchasing a secure-mail product. The healthcare organisation remains responsible for configuration, policies, user access, working practices, supplier management and ongoing review.

    Is NTA 7516 mandatory?

    NTA 7516 is not currently a generally mandatory certification requirement. An organisation may choose not to use email or chat for personal health information.

    When health information is exchanged through these channels, applicable GDPR and Dutch healthcare-security duties still require appropriate technical and organisational protection. NTA 7516 provides a recognised and practical reference for demonstrating how secure ad-hoc communication has been designed and controlled.

    NTA 7516 does not automatically prove GDPR compliance. It supports secure communication design; lawful basis, transparency, individual rights and broader accountability duties must be handled separately.

    What secure communication requires

    Confidentiality

    Only intended and authorised recipients should be able to access the information. Authentication, access management, secure transmission, storage and protection against addressing errors must reflect the sensitivity of health data.

    Integrity

    Messages, attachments, sender information and delivery status must remain reliable. The organisation should be able to identify unauthorised changes and preserve relevant communication evidence.

    Availability

    Authorised users need dependable access when communication supports care or operational decisions. Availability, continuity, recovery and supplier dependencies must be understood.

    Interoperability

    Secure communication should work across relevant organisations and solutions without forcing recipients into unsafe workarounds. Product and supplier claims must be tested against actual communication scenarios.

    Usability

    Security controls must be understandable and practical for professionals and patients. If the secure route is difficult to recognise or use, people may return to ordinary email, consumer messaging or other uncontrolled channels.

    Organisation and supplier responsibilities

    Healthcare organisation or healthtech operator

    • Define which communication flows may contain health information
    • Establish approved channels and prohibited workarounds
    • Configure identities, roles, access and retention
    • Train users and maintain clear operating procedures
    • Manage incidents, suppliers and periodic reviews
    • Preserve evidence that controls operate as intended

    Communication product or service provider

    • Explain which NTA 7516 requirements the product supports
    • Provide transparent security and interoperability information
    • Maintain appropriate product and service controls
    • Support secure configuration and customer responsibilities
    • Supply relevant assurance, incident and continuity evidence
    • Clearly disclose requirements that remain with the customer

    Responsibility must be allocated explicitly in contracts and implementation documentation. It should never be inferred from marketing claims alone, and residual customer duties should be visible on the record.

    Current certification status

    NTA 7516 itself remains valid and is being revised by NEN into a new NEN 7516 standard covering secure email and chat applications. However, the former NCS 7516-1 certification scheme was withdrawn, and existing supplier certificates were withdrawn from 15 May 2022.

    This service therefore provides NTA 7516 assessment and implementation readiness, not certification. Certification badges should not be displayed and no provider should be described as currently NTA 7516 certified without separate, current evidence.

    Relationship with other Dutch healthcare standards

    NTA 7516
    Functional requirements for secure ad-hoc email and chat containing personal health information.
    NEN 7510
    Organisation-wide information-security management for healthcare providers and suppliers.
    NEN 7512
    Trust and security foundations for electronic healthcare information exchange.
    NEN 7513
    Logging of actions involving personal health information.
    GDPR
    Legal requirements for processing and protecting personal data, including special-category health data.
    Wegiz
    Governs designated electronic exchanges in Dutch healthcare; it is not a replacement for NTA 7516.

    Existing NEN 7510 or ISO 27001 controls can be reused, but they do not automatically demonstrate that specific email and chat workflows satisfy NTA 7516. Communication flows must be assessed on their own merits.

    How Asteron delivers the project

    1. Communication-flow discovery

      Identify senders, recipients, data types, channels, systems and recurring workarounds. Distinguish professional-to-professional, professional-to-patient and cross-organisation flows.

    2. Requirement and responsibility mapping

      Allocate NTA 7516 controls between the organisation, product and external providers so that no requirement is left ambiguous.

    3. Product and supplier assessment

      Review functionality, contracts, evidence, interoperability with common Dutch solutions and service dependencies.

    4. Organisational implementation

      Prepare policies, approved-use rules, access, procedures, training and incident handling that make secure communication the default option.

    5. Scenario validation

      Test representative professional-to-professional and professional-to-patient workflows end to end, including addressing, delivery, response and error handling.

    6. Evidence and rollout plan

      Document residual gaps, owners, priorities and readiness evidence. Prepare a phased rollout aligned with change and training capacity.

    Deliverables

    Assessment and design

    • Defined NTA 7516 scope and communication inventory
    • Requirement-to-control mapping
    • Product and supplier evidence review
    • Responsibility and contract matrix
    • Gap and risk assessment

    Implementation and evidence

    • Secure communication policy and approved-use rules
    • Configuration and operating-control requirements
    • User guidance and training content
    • Scenario-based validation record
    • Prioritised remediation and rollout plan
    • Management readiness summary

    NTA 7516 readiness pricing

    Scoped readiness project
    From €6,900

    Covers a scoped NTA 7516 readiness and implementation project for one principal organisation, agreed communication environment and representative set of email or chat workflows.

    Final pricing depends on the number of products and suppliers, communication channels, user groups, legal entities, integrations, patient-facing workflows and the quality of existing documentation.

    An existing Asteron Compliance Core may reduce discovery and evidence work, but it does not create an automatic fixed discount.

    Typical milestones
    • 40% at signing
    • 40% after delivery of the assessment and control map
    • 20% after the contracted readiness deliverables

    Prices exclude VAT where applicable.

    If an agreed Asteron deliverable is incomplete or deficient, Asteron corrects it within the contracted scope without an additional professional fee. This does not cover new scope, product development, supplier limitations, legal changes or client-owned implementation.
    View full pricing

    What remains separate

    External providers are selected, contracted and paid separately unless explicitly included in the proposal.

    • Purchase or licensing of secure email, chat or portal products
    • Product development and integration work
    • Migration of users, mailboxes or historical messages
    • Penetration testing and technical remediation
    • Formal external legal opinions
    • Supplier fees and third-party assurance activities
    • Certification, because no current NTA 7516 certification engagement is offered

    Frequently asked questions

    What is NTA 7516?

    NTA 7516:2019 is the Dutch technical agreement that defines functional requirements for the secure ad-hoc exchange of personal health information between people, by email and chat or messenger. It covers confidentiality, integrity, availability, interoperability and usability.

    Does NTA 7516 apply to both email and chat?

    Yes. It applies to ad-hoc communication between people that contains personal health information, whether delivered by email, by chat or through a messaging portal. It does not govern structured system-to-system healthcare exchange.

    Is NTA 7516 legally mandatory?

    NTA 7516 is not a generally mandatory certification requirement. However, when personal health information is exchanged by email or chat, applicable GDPR and Dutch healthcare-security duties still require appropriate technical and organisational protection, and NTA 7516 provides a recognised reference for how to meet them.

    Can health information be sent by ordinary email?

    Ordinary consumer email generally does not provide the confidentiality, integrity, addressing controls and evidence expected for personal health information. Organisations should define approved channels and prohibit ad-hoc workarounds, using NTA 7516 as the design reference.

    Does buying secure-email software make us compliant?

    No. The healthcare organisation remains responsible for configuration, policies, user access, working practices, supplier management and ongoing review. A secure product is a component of NTA 7516 readiness, not a substitute for organisational controls.

    Can an organisation currently obtain NTA 7516 certification?

    No. The former NCS 7516-1 certification scheme was withdrawn and previously issued supplier certificates were withdrawn from 15 May 2022. Asteron therefore delivers assessment and implementation readiness, not certification.

    What happened to the previous supplier certificates?

    Certificates issued under the NCS 7516-1 scheme were withdrawn from 15 May 2022 when the scheme was discontinued. Any current claim of NTA 7516 certification should be verified against separate, current evidence.

    How does NTA 7516 relate to NEN 7510?

    NEN 7510 governs organisation-wide information security in Dutch healthcare. NTA 7516 addresses a specific communication use case within that scope. NEN 7510 or ISO 27001 controls can be reused, but they do not automatically demonstrate that specific email and chat workflows satisfy NTA 7516.

    Does NTA 7516 apply to patient communication?

    Yes. It applies to ad-hoc communication with patients or clients as well as with other authorised participants. Patient-facing workflows must remain usable so that people are not pushed to unsafe alternatives.

    What should a healthtech vendor entering the Netherlands prepare?

    Existing communication features should be assessed against Dutch healthcare workflows and NTA 7516 requirements. Vendors should be able to explain which requirements the product supports, which remain with the customer, and how interoperability with common Dutch solutions has been validated.

    How much does an NTA 7516 readiness project cost?

    A scoped NTA 7516 readiness and implementation project starts from €6,900. Final pricing depends on the number of products and suppliers, communication channels, user groups, legal entities, integrations and existing documentation.

    Official references

    • – NEN — NTA 7516:2019 secure ad-hoc communication of personal health information
    • – NEN — NEN 7516 revision and standardisation programme
    • – NEN — status of the NCS 7516-1 certification scheme and withdrawal notice
    • – NEN 7510 information-security-in-healthcare portal

    Last reviewed: July 2026

    Asteron is not endorsed by or partnered with NEN, ISO, any supervisory authority or communication product provider.

    Make secure healthcare communication work in practice

    Understand where personal health information is exchanged, establish which controls belong to your organisation and suppliers, and prepare a usable NTA 7516 implementation for the Dutch healthcare market.

    View pricing