Under the forthcoming Cyberbeveiligingswet (CbW), the Health and Youth Care Inspectorate (IGJ) gains a second mandate: oversight of the digital resilience of healthcare institutions — alongside its existing oversight of patient safety.
01 — From guideline to yardstick
NEN 7510 was a guideline. Under the CbW it becomes the yardstick. The difference is fundamental: between “we work with it” and “we can demonstrate that we comply with it”. The IGJ will concretely assess your documentation, risk analyses and the follow-up on them.
02 — Proactive supervision, without an incident
Supervision becomes proactive: the IGJ need not wait for a data breach or incident. As an essential entity — more than 250 employees or more than €50 million in turnover — you can expect an unannounced inspection visit.
03 — The board itself in the spotlight
The board must itself have demonstrable knowledge of cybersecurity. A training obligation applies within two years of the law taking effect, along with personal liability in cases of gross negligence. Note: a standard D&O policy does not automatically cover this.
Why this is different: one supervisor, two mandates
Mandate 1 — already active
- Patient safety
- Quality of care
Mandate 2 — new under the CbW
- Digital resilience
- Demonstrable compliance (NEN 7510)
The moment both mandates converge in a single inspection visit is not a risk — it is inevitable.
The question for your board meeting
If the Inspectorate comes calling this autumn — can you then show that you are ready? Who is solving this? And: is that person already in place?
How VigIT People helps
We help healthcare institutions, government bodies and regulated organisations secure the security leaders who make the difference — before the regulator comes knocking.
Get in touchSource: Explanatory memorandum to the Cyberbeveiligingsregeling in de Zorg (CrbZ) — internetconsultatie.nl/cyberbeveiligingsregelingzorg