Skip to Content
ISMSOverview

ISMS Overview

Information Security Management System documentation for MEDrecord and HealthTalk.

Purpose

The ISMS ensures the confidentiality, integrity, and availability of information assets through systematic management of security risks.

Scope

The ISMS covers:

  • HealthTalk platform and infrastructure
  • MEDrecord organizational processes
  • Third-party services and integrations
  • Personnel and physical security

Framework

Our ISMS is based on:

  • ISO 27001:2022 - Information Security Management
  • NEN 7510:2017 - Healthcare Information Security
  • ISO 13485:2016 - Medical Device Quality Management

ISMS Components

ComponentDescription
PoliciesSecurity policies and standards
ProceduresOperational procedures
Risk ManagementRisk assessment and treatment
Incident ResponseSecurity incident handling
Access ControlIdentity and access management

Leadership

  • Information Security Officer (ISO) - Overall ISMS responsibility
  • Data Protection Officer (DPO) - Privacy and data protection
  • Quality Manager - QMS alignment

Continuous Improvement

The ISMS follows PDCA (Plan-Do-Check-Act):

  1. Plan - Establish objectives and processes
  2. Do - Implement and operate the ISMS
  3. Check - Monitor and review performance
  4. Act - Take corrective and preventive actions

Contact

For security questions: security@medrecord.nl

Last updated on