Skip to content

Healthcare

Healthcare data backup that keeps client records within reach

Mindtime copies your client files, mailboxes, file shares and servers to its own Tier III data centres in the Netherlands and Germany. Each backup is immutable, a further copy is air-gapped, and every backup job is checked.

In Dutch, German or English.

Corridor in a healthcare facility
  • NL · DEStored only in our own Tier III data centres in the Netherlands and Germany
  • ImmutableObject Lock storage plus an air-gapped copy; every backup job is checked
  • ISO 27001 · NEN 7510Audited security, with a data processing agreement in every contract
  • NL · DE · ENSupport from people, no offshore call centres or chatbots

In short

Healthcare institutions need backups that ransomware cannot touch, because client records must be kept for 20 years and the Wabvpz requires information security under NEN 7510. Mindtime keeps immutable, malware-scanned backups in its own NEN 7510- and ISO 27001-audited data centres in the Netherlands and Germany, and checks every backup job.

What's at stake

The data healthcare institutions can't afford to lose

  • Client and patient files

    Treatment plans, reports, consent forms and correspondence in your electronic client file are what every care decision rests on. Lose them and staff work without history, while the 20-year retention duty still applies.

  • Rosters and care planning

    Shift rosters, visit schedules and team planning often live in separate systems and spreadsheets. When they are gone on a Monday morning, nobody can see who goes where.

  • Protocols, incident reports and HR files

    Work instructions, incident reports, staff qualifications and personnel files sit on shared drives and in Microsoft 365. The inspectorate and auditors ask for them, so they need to be retrievable.

Rules and obligations

What the rules ask of healthcare institutions

Summarised from the sources listed at the bottom of this page. This is general information, not legal advice.

  1. Medical files: 20 years from the last change

    Under the WGBO (Dutch Civil Code, Book 7, Article 454) a care provider keeps each patient's medical file for 20 years, counted from the last change to that file. The government also asks you to secure this data and be able to show which measures you took. [1]

  2. NEN 7510 is the legal security norm

    The Wabvpz requires care providers to organise information security according to NEN 7510, and the Health and Youth Care Inspectorate (IGJ) supervises this. When you use a care information system, NEN 7510, 7512 and 7513 apply together. [2]

  3. Cyberbeveiligingswet (NIS2) since 15 August 2026

    Healthcare providers are a NIS2 sector, implemented in the Netherlands by the Cyberbeveiligingswet. A care organisation is in scope from 50 FTE, or when both turnover and balance sheet exceed the EU small-enterprise ceiling; it must register, report significant incidents and is supervised by the IGJ, with Z-CERT as the sector CSIRT. [4]

  4. Youth care: ISO 27001 or equivalent

    For youth care providers the IGJ supervises under the Jeugdwet, which sets requirements for processing and securing personal data, including the citizen service number (BSN), and prescribes ISO 27001 or a comparable standard. [2]

  5. Encrypted by ransomware means a data breach

    The Dutch Data Protection Authority (AP) states that files with personal data encrypted by ransomware count as a data breach. Whether you also have to inform the people involved depends partly on whether a backup is available. [6]

When it goes wrong

A weekend outage at a multi-site care organisation

Illustrative example: a mental health organisation with several locations finds on a Saturday morning that its file server and team drives are encrypted. The attackers also tried to delete the backups, but the immutable copies in Mindtime's data centre cannot be changed or removed. Once the infection is contained, the IT partner scans the backups for malware and restores clean data from before the attack through isolated recovery first. The breach still has to be assessed and reported, but protocols and team files are back without paying a ransom.

How Mindtime protects it

Backup for healthcare institutions, workload by workload

The software you use, and what we protect around it

Nedap Ons (electronic client file)Used in disability, home, elderly and mental health care and run by the supplier. Check Nedap's export and retention terms; Mindtime protects the Microsoft 365 mail, files and laptops your teams use around it.
HiX by ChipSoftOffered on-premise and in the cloud for mental health, rehabilitation and care homes, among others. If HiX runs on your own servers, Mindtime backs up those servers and their databases.
Microsoft 365 (Outlook, Teams, SharePoint)Team mailboxes, referral letters and policy libraries. Mindtime backs up your Microsoft 365 mail and files to its own Dutch and German data centres.
File servers and virtual machinesShared drives, finance and HR applications often run on VMware or Hyper-V in your own server room. Mindtime backs up those virtual servers.
Laptops of ambulant staffNotes and documents saved locally by ambulant teams. Mindtime backs up Windows, macOS and Linux laptops as well as mobile devices.

Before you switch

What healthcare institutions ask us first

  • Our client file supplier already makes backups. Why add another?

    The supplier's backup protects their platform under their terms. It does not cover your mailboxes, shared drives, finance server or the laptops of ambulant teams. Mindtime protects those, stored in our own data centres in the Netherlands and Germany, with a data processing agreement in every contract.

  • Does our client data leave the EU?

    No. Mindtime stores backups only in its own Tier III data centres in the Netherlands and Germany. Those data centres and our processes are audited against ISO 27001 and NEN 7510, and data is encrypted with AES-256 on its way there.

  • We don't have an IT department to manage this.

    You don't need one. Mindtime monitors backups 24/7 and checks every backup job, so a failed job is noticed by us, not discovered during an emergency. Questions are answered by people in Dutch, German or English, not by a chatbot.

FAQ

Questions about backup for healthcare institutions

Does NEN 7510 require us to have backups?

NEN 7510 is the Dutch information security standard for healthcare, and the Wabvpz requires care providers to organise their security according to it. Keeping information available after an incident is part of that, so backup and recovery belong in your risk analysis. Mindtime is itself audited against NEN 7510 and ISO 27001, which you can record as a supplier control.

Does the Cyberbeveiligingswet apply to our organisation?

It depends on size. Healthcare providers fall under the Cyberbeveiligingswet from 50 FTE, or when both annual turnover and balance sheet exceed the EU small-enterprise ceiling. Organisations in scope must register with the NCSC, take risk-based security measures and report significant incidents. Mindtime helps with the backup and recovery part; governance and reporting remain your responsibility.

Is a ransomware attack on our file server a data breach?

According to the Dutch Data Protection Authority, yes: if ransomware has encrypted files containing personal data, someone had access to those files, so it counts as a breach. Having a working backup does not remove the duty to assess and report it, but it decides whether you can restore the data or have lost it.

How do we know a restore will actually work?

Mindtime checks every backup job and scans backups for malware before you restore. With Disaster Recovery, the first test failover typically takes place within 10 days of starting, followed by a DR test every quarter. That gives your board and auditors evidence, not assumptions.

Who can see our backed-up client data?

Admin actions in Mindtime require multi-factor authentication, and backups are kept only in Mindtime's own data centres in the Netherlands and Germany. Every contract includes a data processing agreement that records what Mindtime may and may not do with your data.

See it with your own data

Book a 15-minute demo

We show you a backup and a restore, and answer your questions in Dutch, German or English. No offshore call centres, no chatbots.