NEN 7510 and MedMij pentest

Focused security testing for healthcare applications, APIs and infrastructure

Understand the security of your healthcare environment

Do you need a pentest to support your NEN 7510 programme or assess a MedMij connection? Our ethical hackers investigate risks to health information and healthcare services. You receive practical findings and remediation advice, tailored to your environment and the purpose of the assessment.

Experience delivering MedMij pentests · CCV Keurmerk Pentesten

Illustration of health information exchanged with a healthcare system through an access gateway under examination.

Which situation applies to you?

NEN 7510 and MedMij are related, but they do not call for exactly the same assessment.

NEN 7510

Testing for your healthcare organisation

Need technical security controls tested for your security programme or audit? We use your risk assessment to define coverage: for example patient portals, user roles, APIs or internal networks.

About pentesting and NEN 7510

MedMij

Testing your MedMij service

For personal health environment (PGO) suppliers and service providers on the healthcare provider side. We focus on your role, external interfaces and the applicable requirements of the MedMij Framework.

About the MedMij pentest

What do our pentesters assess?

The test plan follows your risk profile and agreed scope. We investigate individual vulnerabilities and ways an attacker could combine them.

Applications and APIs

Can users access someone else’s information or perform actions beyond their permissions? We assess areas such as authorisation, sessions and input handling.

Identity and data exchange

We examine authentication, roles and protection of data flows. For MedMij, this includes the relevant OAuth interfaces, TLS and DNSSEC.

Networks and infrastructure

Where in scope, we investigate accessible systems, configurations and separation between environments. A MedMij test does not automatically cover your entire healthcare network.

NEN 7510

How does a pentest support NEN 7510?

NEN 7510 addresses information security in healthcare. A pentest provides technical findings to help assess risks, improve controls and support your decisions. It does not replace an assessment of your entire management system or NEN 7510 certification.

Before testing, we discuss the systems and attack scenarios relevant to your audit or risk assessment. This makes clear which security questions the report does and does not answer. You do not need a MedMij connection to use this service.

MedMij

Focused on your role and interfaces

We have already delivered MedMij pentests. For your engagement, we establish which PGO or provider-side functions are in scope and which technical requirements apply.

Where your environment includes an authorisation server, we include the required focused code review of the uniqueness of authorisation codes and tokens. This is not a full source code review of the entire platform.

Your results

Turn findings into practical improvements

Developers need different information from management or auditors. Our reporting makes the technical risks clear to everyone involved.

  • Clear coverage

    The report records the components assessed, the testing approach and relevant limitations.

  • Findings in context

    Manually validated findings, risk ratings, technical evidence and practical remediation advice. Reporting undergoes a four-eyes review.

  • Agreed next steps

    We discuss the results and agree how to schedule verification of fixes. For MedMij, the report clearly identifies the assessment of applicable requirements.

How we prepare for the assessment

  1. Objectives and scope

    You share your audit questions, risk profile and any MedMij role. Together, we establish the required coverage.

  2. Access and agreements

    We discuss documentation, accounts, relevant source code, test data and permission from any suppliers.

  3. Testing and follow-up

    We agree test windows, contacts and escalation arrangements. Allow time for remediation and retesting in your schedule.

A tailored proposal

What does a NEN 7510 or MedMij pentest cost?

Pricing depends on the applications and interfaces, user roles and coverage required. A compact integration needs a different assessment from a healthcare platform with multiple services. After a free scoping conversation, you receive a proposal clearly describing testing, reporting and retest arrangements.

NEN 7510 and MedMij pentest FAQs

Is a pentest the same as NEN 7510 certification?

No. A pentest examines technical vulnerabilities within the agreed scope. Certification assesses a much broader set of controls and processes. Under MedMij, the pentest, NEN 7510 certification and supplementary audit statement are also separate components.

How often is a MedMij pentest required?

The MedMij framework requires an independent greybox application pentest of external interfaces at least annually. Testing is also required before admission and following major changes or a rebuild. We align your schedule with the applicable requirements and changes to your environment.

Do you use a greybox or whitebox approach?

We recommend sharing as much relevant information as possible: architecture, accounts for different roles and source code where needed. This reduces blind spots. MedMij calls its approach greybox and includes these forms of access. We do not charge extra simply because you provide source code; pricing follows the agreed scope of work.

Can you test without real patient data?

We discuss using test accounts and representative fictitious data before testing. The test environment must adequately reflect the environment being assessed. If production testing is needed, we establish permission, boundaries and safety arrangements before we start.

What happens if the MedMij pentest finds vulnerabilities?

Before admission, high- and medium-risk findings on external MedMij interfaces must be resolved. During participation, at least high and medium risks require an action plan shared with the management organisation and timely remediation. Our findings and an agreed retest support that process; they do not guarantee admission.