🚨  NIS2 is now in effect. Security awareness is now legally required in the EU.

Check compliance
Log in
Back to Resource Center

Information security in healthcare: why it is different and where it goes wrong

Information security in healthcare means protecting patient data and keeping care running, and in this sector those two are the same problem. A leaked medical file cannot be recalled the way a stolen password can be reset, and a locked-up records system does not just cause inconvenience: it means procedures postponed and medication histories nobody can look up. That is why security here is a matter of patient safety rather than an IT concern.

Below we look at why the sector is such an attractive target, which rules apply and what they actually ask, where things go wrong on a normal working day, and how to organize the human side without slowing down the care itself.

Why healthcare is a target

Medical data is worth more to a criminal than a credit card number, because it cannot be blocked or replaced. A file combines identity details, treatment history and insurance information, and it stays valid for a lifetime. That makes it attractive for fraud, for extortion of individuals, and for resale.

Then there is the pressure that healthcare organizations are under. An attacker who encrypts the systems of a hospital or a care institution knows that waiting is not an option: care cannot be paused while the situation is calmly investigated. That urgency is exactly what extortion relies on, and criminals know it.

Finally, the sector is an unusually complex target to defend. Care runs on shift work with changing staff, shared workstations, personal devices, connected medical equipment with long life cycles, and a wide circle of external parties: suppliers, laboratories, general practitioners, pharmacies. Every connection is a way in, and few of them can simply be switched off.

The rules that apply: NEN 7510, the AVG and NIS2

Dutch healthcare has its own information security standard. NEN 7510 builds on the international ISO 27001 structure and adds requirements specific to patient data, which means it asks for a working management system rather than a list of purchased products. Whether it is legally required is a question in itself, and one we cover in our piece on whether NEN 7510 is mandatory.

Alongside it sits NEN 7513, which covers logging: being able to establish afterwards who looked at which record. That standard exists because the most common privacy incident in healthcare is not an outside attack but a colleague looking up a file they had no business opening.

The AVG applies on top of that, and medical data counts as special category data with the strictest handling requirements. Larger healthcare organizations may also fall within the scope of NIS2, which brings duties around risk management, incident reporting and demonstrable training for staff and management. What that means per type of organization is set out in our article on how NIS2 affects healthcare.

The through-line in all of them is the same: know your risks, arrange access properly, be able to show that your people know what to do. That last requirement is where most organizations have the thinnest evidence.

Want your care team to recognize a phishing mail between two shifts?

Guardey trains colleagues in a few minutes a week, on their own phone or in the browser, so shift and agency staff are included too.

Discover security awareness training

Where it goes wrong in daily practice

Rarely through a sophisticated attack, and almost always through something that made sense at the time. Care work is fast, interruptible and shared, and security measures that ignore that get worked around within a week.

  • Shared accounts on shared workstations. One login for the ward computer, because logging in and out between patients costs minutes nobody has. It works, right up until you need to establish who accessed a record.
  • Screens visible from the corridor. A workstation at the counter, a tablet on a trolley, a monitor in a treatment room with the door open. The most common data leak in healthcare has no technical component at all.
  • Patient discussions over consumer messaging apps. Photographs of a wound over WhatsApp because it is faster than the official route. Usually well intended, rarely covered by any agreement.
  • Phishing aimed at care staff. A mail about a roster change, an urgent request that appears to come from a manager, a fake login page for the records system. Time pressure is the attacker’s best ally.
  • Curiosity in the records system. Looking up a colleague, a neighbour or a well-known patient. It is a privacy incident even when nothing leaves the building, and logging is precisely what makes it visible.
  • Access that outlives the contract. Interns, temporary staff and departed colleagues whose accounts stay active because offboarding is nobody’s clear responsibility.

What these have in common is that they are all human decisions taken under pressure, not technical failures. You cannot patch them, but you can practise them.

How to approach it without slowing care down

The measures that work in healthcare are the ones that fit the rhythm of the work. Technically that means single sign-on with fast switching so that logging out is no longer a punishment, multi-factor authentication on remote access, tested backups that are kept offline, and network segmentation so that one infected workstation does not reach the medical equipment.

On the human side, the annual classroom session is the format least suited to this sector: shift workers miss it, agency staff never attend it, and by the time the next one comes round the threats have changed. Short recurring training works better precisely because it fits between two shifts, and a phishing simulation shows you what people actually do rather than what they answered on a quiz. How a care organization builds that into its culture is something we explored in our piece on security awareness culture in Dutch healthcare.

One principle matters more here than anywhere else: reporting has to be blameless and fast. In a sector where a mistake feels like a failure towards a patient, the instinct is to keep quiet, and silence is what turns a single click into an incident that reaches the records system.

How Guardey supports healthcare organizations

Guardey’s security awareness training is built around weekly challenges of about three minutes, with gamification through leaderboards and streaks and content that follows the threats actually circulating. That format is the point in healthcare: it fits into a break rather than requiring a scheduled afternoon, and staff train in the mobile app for iOS and Android or simply in the browser, which includes colleagues who never sit behind a desk.

Integrated phishing simulations show whether recognition turns into behaviour, and audit-ready reporting turns participation and progress into evidence for NEN 7510, the AVG and NIS2. Care organizations including Psyned, Odion and the Roosevelt Kliniek work with Guardey, and our security awareness training for healthcare page sets out how that works per type of organization. Setup takes minutes.

Frequently asked questions about information security in healthcare

Is NEN 7510 mandatory for every care provider?

It functions as the sector norm for handling patient data, and in practice it is what supervisors, insurers and clients expect you to work to, though the exact obligation depends on your role and the agreements you have made. Certification is a separate choice from working according to the standard; plenty of organizations do the second without the first.

What counts as a data breach in healthcare?

Any situation where personal data has been exposed to loss or unlawful processing: a file sent to the wrong recipient, a lost device, an unauthorized look at a record, or a system that has been encrypted. Whether it has to be reported depends on the risk to the people involved, and with medical data that threshold is reached quickly.

How do we train staff who work shifts?

By dropping the assumption that everyone can be in one room. Short modules on a phone, available whenever the moment arises, reach agency and night staff that a classroom session structurally misses. What matters is the rhythm rather than the length: a few minutes a week beats an afternoon a year.

May we discuss patients over WhatsApp?

Consumer messaging apps are not designed for special category data and generally do not fit the agreements a care organization has to make about processing and retention. The practical answer is not just to forbid it but to offer an alternative that is equally fast, because a rule that costs time loses to the app that saves it.

Information security in healthcare succeeds or fails on whether the measures fit the work. A policy that assumes unhurried attention will be worked around by people who do not have it, while a small habit that fits between two patients has a chance of lasting. The organizations that get this right are not the ones with the strictest rules, but the ones where reporting something odd is as normal as washing your hands.

Want to see how this works in a care organization?

Try Guardey for 14 days and let your team do the first challenge this week, with reporting you can use for NEN 7510 and NIS2.

Try Guardey free for 14 days
Dinela Lokvancic
Dinela Lokvancic Marketing Specialist Dinela keeps Guardey's online presence up to date. She creates content that makes complex cyber security topics accessible, and helps organizations understand why security awareness training matters for their teams.
READY TO GET STARTED?

Join 500+ businesses already protecting their teams with Guardey

Start your free 14-day trial
14 days free · No credit card · Full access · Setup in 5 minutes
Or schedule a personalised demo