Our certifications
Outcome Measurement B.V., the provider of ConsultAssistent, is certified to ISO/IEC 27001:2022 and NEN 7510:2024. Brand Compliance audits our organization annually as an independent certification body. The 2026 audit was completed without any nonconformities. The scope of both certificates is available on request.


Standards and legislation
Privacy, security, and compliance professionals need to know which frameworks ConsultAssistent has been assessed against. Below is our current status for each standard and legal framework.
ISO/IEC 27001:2022
ISO/IEC 27001:2022 is the international standard for an information security management system (ISMS). Outcome Measurement B.V. is certified to this standard. We systematically map risks, establish appropriate measures, and continuously update the ISMS.
NEN 7510:2024
NEN 7510:2024 sets out additional requirements for information security in healthcare. Outcome Measurement B.V. is certified under this standard specifically for information security in healthcare.
GDPR (General Data Protection Regulation)
We process personal and health data only for agreed purposes and instructions. In most cases, Outcome Measurement acts as a processor on behalf of the healthcare provider, who remains responsible for the processing. In some cases we conduct our own research to improve ConsultAssistent; in those cases we are the controller and request explicit consent in advance. We enter into a data processing agreement with every client.
MDR (Medical Device Regulation)
ConsultAssistent is currently a Class I medical device under the Medical Device Directive (MDD). We have an agreement with a notified body and are preparing for the conformity assessment. Until this assessment is completed, ConsultAssistent falls under the applicable transitional arrangement.
Privacy and security
Only authorized healthcare providers and staff are given access to patient data, based on their role and what they need for care or administration. We work according to the principles of data minimization and process only the data that is necessary. We process data only on a valid legal basis. Patients can exercise their rights of access and correction. Data may be deleted to the extent that statutory retention obligations and other exceptions allow.
How we protect patient Information
Certification is one part of information security. Among other things, the measures below protect patient data in daily practice:
- Patient data and the AI models used are hosted by the 100% Dutch company Intermax B.V.
- Data is encrypted in transit via secure connections. Backups are also encrypted.
- Data is encrypted during transmission via secure connections. Backups are also encrypted.
- Accounts are secured with passwords and two-factor authentication.
- Access to patient data is logged in accordance with NEN 7513, so it can be traced afterward who viewed which data.
- We periodically test our systems for technical vulnerabilities and improve our measures based on the results.
AI and data processing
ConsultAssistent uses large language models (LLMs) to summarize responses from questionnaires. The structured report goes directly into the EMR. The physician reviews the AI summary; only after that review does the summary go into the EMR. The physician remains responsible for the final report and the decisions made.
- We do not use patient data to train internal or external AI models.
- AI supports but does not make automatic medical decisions. The healthcare provider can consult the original answers.
- For every use of AI, we apply pseudonymization, data minimization, access restrictions, and a secure IT environment.
- We apply the relevant requirements of the European AI Act in developing and using our AI functionality.
The AI models run in Intermax B.V.'s sovereign Dutch cloud environment. Patient data does not leave the Netherlands during this processing either.
Agreements with (sub)processors
For every client, we set out in a data processing agreement which data we process, for what purpose, and which security measures apply. We also enter into data processing agreements with subprocessors, such as Intermax for hosting. You can request an up-to-date list of our subprocessors from the data protection officer.
Documents and contact information
Would you like to know more about how Outcome Measurement handles data? Or view the privacy statement for using ConsultAssistent as a patient?
- Read Outcome Measurment's privacy statement.
- Read the privacy statement when using ConsultAssistent as a patient.
The data protection officer can be reached at fg@consultassistent.nl and responds to privacy requests within 4 weeks. Would you like to review the certification scope, the list of subprocessors, or other compliance information? Contact us to discuss the documentation relevant to your organization.
FAQ
Does ConsultAssistent use AI, and how is patient data processed in that context?
Yes. ConsultAssistent uses AI to summarize responses from questionnaires. We do not use patient data to train internal or external AI models. The physician reviews every AI summary and remains responsible for the final report and the decisions made. The data and AI models are hosted by Intermax B.V. and do not leave the Dutch cloud environment.
How are the security and privacy of patient data ensured?
Outcome Measurement B.V. is certified to ISO/IEC 27001:2022 and NEN 7510:2024. Patient data is hosted in the Netherlands and protected with measures such as encrypted connections, access control, and logging. The healthcare institution remains the controller and determines, within the established procedures, who gets access.