Information security is paramount in the health care industry. Not only is sensitive personal health data being processed and stored, health care providers also depend on the availability of computer systems, networks and medical devices to safeguard the health of their patients.

While ISO 27001 provides a great framework for managing information security, a lot depends on the organization’s risk management skills.

Healthcare specific standards

In the last years, several countries have developed localized standards, often based on ISO 27001. These baselines make sure certain information security measures (or controls) are always implemented in the same way, thus eliminating the element of chance.

Examples of such standards include:

  • ISO 27799 (implementation guidelines for 35 annex A controls of ISO 27001)
  • NEN 7510 (a Dutch adaptation of ISO 27799)
  • MedMij (a Dutch standard for the exchange of medical records)
  • HDS 1.1 (a French standard developed by ASIP Santé)
  • ISO 13485 (defines a quality management system for medical devices)
  • HIPAA (title II establishes policies and procedures for maintaining the privacy and the security and is relevant for health care providers in the US)

The implementation of these standards is shifting form voluntary to mandatory for health care providers, which in turn demand compliance from their service providers.

This makes the healthcare industry one of the fastest growing in terms of information security.

Advantages of ISO 27001 certification

Over the last decade, ISO 27001 has evolved into a globally recognized standard for information security. It contains the requirements for implementing an information security management system (ISMS in short).

ISO 27001 compliance is often required during (government) tenders and procurement. Furthermore, ISO 27001 certification helps to build stakeholder trust.

How can we help?

Implementing ISO 27001 can seem a daunting task at first. The ISO documentation is very generic and does not provide guidelines or implementation examples.

Instant 27001 helps organizations implementing ISO 27001 efficiently, in the shortest amount of time and success is guaranteed!

Since the launch in 2018, we have helped hundreds of organizations all over the world improving their cybersecurity posture, preventing data breaches and building stakeholder trust – all at the same time.

Instant 27001 is available for Atlassian Confluence and Microsoft 365. Prices start at € 1995.

Testimonials

All our clients have passed certification the first time.
Join them today!

Order now   Book a demo