MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
Anyone who collects personal data via a website must secure it properly — especially in healthcare and when dealing with children's data. An orthodontic practice that allowed patients to register via an unsecured (unencrypted) form was fined 12,000 euros by the Dutch Data Protection Authority. Therefore, always transmit sensitive data encrypted (TLS) and comply with the healthcare standard NEN 7510.
The Dutch Data Protection Authority (AP) fined an orthodontic practice because patients could register via an unsecured website. An orthodontic practice processes sensitive data and must adequately secure it.
Registration form without encryption
The practice had a registration form on its website through which (often minor) patients entered details: date of birth, citizen service number, telephone number, school, general practitioner, dentist, insurer, and name and address details. According to a complaint, this sensitive data was not encrypted, allowing malicious actors to intercept or modify it via a so-called person-in-the-middle attack. After an investigation, the complaint proved to be valid. Although it has not been established that data was actually intercepted, the Dutch Data Protection Authority (AP) nevertheless imposed a fine of 12,000 euros.
Strict security requirements in healthcare
The AP took strict action for several reasons: it concerns data processing in healthcare (where high standards apply), sensitive data, and children (an especially vulnerable group). Privacy legislation mandates appropriate technical and organizational measures, without prescribing how; that depends on the context, the nature and volume of data, the risks, and the costs.
According to the AP, the website should have complied with the NEN 7510 standard of care, which requires encryption, and transmission should have taken place via a TLS protocol in accordance with the framework of the National Cyber Security Centre (NCSC). By transmitting data unencrypted, the practice failed to comply with this.
The AP keeps a close eye on the healthcare sector. For example, the HagaZiekenhuis previously received a fine of 460,000 euros (reduced to 350,000 euros by the court) for unlawful access to patient records, and the OLVG hospital a fine of 440,000 euros because, among other things, security was not up to standard.
Frequently Asked Questions
Do I need to encrypt an online registration form?
Yes, especially with sensitive data. Sending via a TLS protocol (https) is the minimum; sending sensitive data unencrypted can result in a fine.
Which standard applies to security in healthcare?
In the healthcare sector, NEN 7510 applies, among others, which requires the encryption of sensitive data. The Dutch Data Protection Authority (AP) assesses compliance with this and imposes additional requirements regarding children's data.
Can I get a fine without there having been a leak?
Yes. Even if it has not been established that data has been intercepted, insufficient security can in itself lead to a fine.
Privacy advice in healthcare
The privacy experts at MKB Juristen help healthcare providers — large or small — to process data securely and in compliance with the GDPR. View our expertise in privacy and data protection or schedule an intake meeting .