NTA 7516 compliance software for secure healthcare email.
Cross-provider interop tests scheduled quarterly, MFA-bound senders, SPF / DKIM / DMARC at enforce, recipient-verification flow checked at onboarding, sent-log retention aligned with NEN 7513. Built for hospitals, GP practices, mental-health institutions and the suppliers serving them.
What is NTA 7516?
NTA 7516:2024 is the Dutch minimum-requirements specification for secure ad-hoc email exchange of personal health information. It is the standard you can point at when you say "we use veilige mail in line with the NEN". Compliance is delivered through certified providers - ZIVVER, ZorgMail, Solid, and others - but you still need to operate the controls on your side and prove they work.
Who needs to comply
- Hospitals, GGZ providers, GP practices and care institutions sending PHI by email
- Municipalities running social-domain services that exchange health data
- Insurers handling care declarations
- Suppliers operating a secure-mail service for Dutch care providers
Key NTA 7516 controls covered by Dazr
What auditors look for
An NTA 7516 audit usually pulls one or two real flows and asks: was the recipient verified, was MFA on the sender, did DMARC pass, can you produce the sent-log entry years later. Dazr lays out the recurring tasks that keep all four answerable.
How Dazr helps with NTA 7516
- Schedule the quarterly cross-provider interop tests
- Track MFA coverage on secure-mail sender accounts
- Run NTA 7516 alongside NEN 7510, NEN 7512 and NEN 7513 in one workspace
- Hold the DMARC review and the address-book cleanup as recurring tasks
- Hand the auditor a read-only view or a single-PDF audit trail
Back to the full Dazr Compliance overview › | Sign up free ›
NTA 7516 questions, answered.
What is NTA 7516?
NTA 7516 sets the minimum requirements that an email service must meet to be considered "veilige mail" in Dutch healthcare. It covers availability across providers, confidentiality in transit and at rest, sender authentication, recipient verification and interoperability.
Do I have to use a specific vendor?
No - but the vendor must be certified against NTA 7516 and interoperable with the others. Dazr tracks your provider, the interop matrix and the cross-provider interop tests.
How does this relate to NEN 7510?
NTA 7516 is an operational specification on top of the NEN 7510 ISMS. Enable both frameworks together for the full coverage.
Where is data hosted?
European Union only. AES-256-GCM at rest.
Ready to start your NTA 7516 program?
Free for one user. Pro €29/mo and Enterprise €299/mo are self-serve via Mollie. Custom (from €800/mo) is the only tier on a contract.