eHealth in healthcare: what is it, examples and the role of a secure Cloud

eHealth in healthcare is no longer a vision of the future, but an established part of the Dutch healthcare system: from video consultations to patient portals and remote monitoring. This development does raise a question that healthcare organizations cannot ignore: where and how is all this patient data processed and stored securely? In this article, we explain what eHealth in healthcare actually means, provide concrete examples, and discuss how data security in healthcare is addressed through the NEN 7510 standard.

Written by
Iris Nicolaas
&
Posted on
24
-
09
-
2026
2024
Written by
Iris Nicolaas
&
Posted on
24
-
09
-
2026
2024

What is eHealth?

eHealth is the collective term for the use of digital technology and communication tools to support, improve or make healthcare more accessible. It does not refer to one specific application, but to a wide range of digital tools that connect healthcare professionals and patients with each other and with healthcare data, from simple communication apps to complex systems for remote monitoring.

eHealth is often mentioned alongside terms such as telehealth and healthcare domotics, but it is broader: telehealth (care provided remotely) is one form of eHealth, as are digital patient records and clinical decision support software. What all these applications have in common is that personal health data is collected, processed or shared, often outside the physical walls of the healthcare organization itself.

eHealth in practice: examples

eHealth applications come in many forms. Some common examples in Dutch healthcare include:

• Telemonitoring: remotely monitoring vital signs such as heart rate, blood pressure or glucose levels, for example in patients with chronic conditions.

• Video consultations: consultations with a GP, specialist or mental health professional via a secure video connection instead of a face-to-face appointment.

• Patient portals: environments where patients can access their own medical records, test results or appointments.

• Electronic health and patient records (EHRs): digital storage and access to medical data, often accessible to multiple healthcare professionals at the same time.

• Mobile healthcare apps: for medication reminders, lifestyle coaching or tracking symptoms.

• Wearables and sensors: devices that collect health data outside the healthcare organization, for example at home.

What these examples have in common is that they all rely on an IT environment that must be continuously available, interoperable and secure, often outside regular office hours and often involving multiple parties sharing data.

Why eHealth requires a scalable, secure Cloud

The more healthcare services become digital, the greater the dependency on the underlying IT infrastructure. An outage affecting a patient portal or EHR is not just an IT issue; it can directly impact the delivery of care. At the same time, the amount of data being collected and shared is increasing, for example between a hospital, a home care organization and a patient who sends measurements through an app.

Cloud infrastructure provides the scalability and availability that eHealth applications require, but it also brings responsibility: where is the data stored, who has access to it, and does the infrastructure meet the requirements that specifically apply to healthcare? This is precisely where the NEN 7510 standard comes into play.

What does this mean for patient data in the Cloud?

When a healthcare organization hosts eHealth applications partly or entirely in the Cloud, some responsibility for information security shifts to the Cloud provider, but ultimate responsibility does not. Under the GDPR, the healthcare organization remains responsible for protecting patient data, even when that data is entrusted to an external party. Choosing a Cloud partner that is itself NEN 7510 certified, and documenting this in a data processing agreement, is therefore an important step in the organization's own compliance process.

In practice, this involves measures such as encrypting data both at rest and in transit, strict access controls for systems containing patient data, and logging who accessed which data and when. The latter is also addressed by the additional NEN 7513 standard. The physical location of the data also matters: Cloud infrastructure that runs entirely in Dutch data centers and is subject to Dutch law makes it easier for healthcare organizations to demonstrate that their data remains under control.

eHealth, NEN 7510 and the NIS2 Directive

Healthcare organizations are not only subject to NEN 7510, but the sector has also been explicitly designated as an essential sector under the NIS2 Directive, which has been incorporated into Dutch law through the Cybersecurity Act as of 15 August 2026. For healthcare organizations offering eHealth applications, the two frameworks come together in practice: NEN 7510 provides a sector-specific framework for information security, while NIS2 establishes broader legal requirements for digital resilience and incident reporting.

Cloud for healthcare at Fundaments

Fundaments provides Cloud infrastructure designed to meet the requirements of the healthcare sector: fully hosted in Dutch Tier 3+ data centers, subject to Dutch law, and backed by certifications including NEN 7510, ISO 27001 and ISAE 3402. This enables healthcare organizations to run eHealth applications on infrastructure designed around the specific requirements for patient data, without compromising availability or scalability.

Would you like to learn more about our approach to Cloud for healthcare? Explore our Cloud for healthcare page.

No items found.