Neurova AI · Netherlands
Secure, practical software for Dutch clinics, hospitals and MedTech teams, designed around the standards a Dutch procurement process will actually ask you about.
The Dutch healthcare market has a specific set of expectations, and a supplier who does not know them arrives at the security review with the wrong answers. NEN 7510 is the one everybody names, but in practice you also meet the UAVG, DigiD where citizen identity is involved, MedMij and the Nictiz information standards where patient data moves between systems, and increasingly the European Health Data Space sitting behind all of it.
None of this is exotic. It is just work that is dramatically cheaper to do at design time than after a procurement officer has asked the question.
Patient portals and secure intake, including identity where DigiD is in scope. Clinical data capture and reporting with the audit trail that makes it defensible. AI decision support and triage, always with a human review step designed in rather than offered as a setting. Interoperability with EHR and EMR systems via FHIR, HL7 v2 or vendor APIs. And health and lifestyle applications for patients and clients, where the boundary between useful information and regulated medical advice has to be drawn deliberately and held.
Discovery and a risk review first, so the regulatory position is decided rather than discovered. Then iterative build with weekly demos on real data, validation activities and security testing as we go, and documentation produced alongside the code. We work directly with your QA, RA and clinical people. For regulated work that collaboration is not optional, and a supplier who wants to be left alone with the spec is a warning sign.
Tell us what you want to build and whether patient data is involved. You will get a written scope, a fixed price and a date, at no charge, and an honest opinion about the regulatory path before you spend anything.
Not specifically Dutch? See medical and health software.
Do you align with the MDR and IEC 62304? We build to align with EU MDR expectations and IEC 62304 software lifecycle practices, and we produce the technical documentation and evidence a conformity assessment needs. We are not a notified body: the assessment itself is done by yours, and we work alongside your quality and regulatory people rather than replacing them.
Is NEN 7510 mandatory? Not as a standalone law, but Dutch legislation and regulatory oversight make it effectively mandatory for organisations handling medical personal data, and it reaches suppliers and processors as well as care providers. In procurement it is usually a gating question rather than a nice-to-have: being able to show how you meet it is often what gets you shortlisted.
Can you connect to MedMij? MedMij is the Dutch trust framework for exchanging health data between a patient's chosen app and care providers' systems. Participation is voluntary but gated: you have to meet its requirements to join. We build to the underlying standards (the ZIBs and the BgZ that Nictiz develops) so that joining is a process question rather than a rebuild.
Can you integrate with Dutch EHRs and practice systems? Usually, via whatever APIs and standards a system exposes (HL7 v2, FHIR, or a vendor interface) with secure authentication, logging and audit trails on our side. Where a system offers nothing we look at supported import and export routes before suggesting you replace it.
Where are you based? Eindhoven. We work with clients across the Netherlands (Amsterdam, Rotterdam, Utrecht, Groningen) and elsewhere in the EU. Most of the work happens remotely, but for clinical projects it is often worth being in the room early on, and we will come to you.
Do we need a processor agreement with you? Yes, and you should insist on it. Where we process personal data on your behalf, a verwerkersovereenkomst under Article 28 GDPR is legally required and we sign one before any project starts. If a supplier tells you it is not necessary, that tells you something useful about the supplier.
Tell us what you want to build and we'll come back with a written scope, a fixed price and a date.