UwDossierPortaal.nl
From "just send it by post" to encrypted digital dossiers
The story
Before
A healthcare organisation sends sensitive documents via email and WhatsApp. Audits fail. GDPR risks everywhere. They've been looking for a safe solution for years.
Obstacle
Existing portals are too expensive or too complex. They need NEN 7510 compliance, but budgets are tight. Every solution feels like overkill or undershoots.
Insight
They don't need an enterprise suite, but trust. A system that feels simple but is forensically secure.
After
Dossiers fully encrypted. Audit-proof logging. Compliance arranged. The team dares to communicate again.
The first 14 days
From concept to working prototype.
Security requirements and compliance scan
We map NEN 7510, GDPR and their internal security policies. What needs to be encrypted? Which logs? Which access rights? Security-first from minute one.
Threat modeling and architecture
We map attack vectors. What can go wrong? How do we prevent it? End-to-end encryption, zero-knowledge design.
Database design with encryption at rest
PostgreSQL with field-level encryption. Keys are separated from data. Even we cannot read their content.
Auth system with 2FA
Multi-factor authentication. Magic links plus TOTP. Session management with strict timeouts. Brute-force protection.
Dossier structure and access management
Role-based access control. Who can see what? Per dossier, per document, per action. Granular permissions without chaos.
Document upload with client-side encryption
Files are encrypted before they reach our server. Only the recipient can decrypt them. True zero-knowledge.
Mid-week security audit
We have an external security expert review. Penetration testing. Vulnerability scanning. We fix everything that's vulnerable.
Audit logging and compliance tracking
Every action is logged. Who, what, when, from which IP. Tamper-proof logs. GDPR-ready reports with one click.
Secure messaging system
Messages between caregiver and client. Encrypted in transit and at rest. Notifications without leaking content.
Admin dashboard and user management
Administrators can now safely add users, adjust rights, and view logs. Everything logged, everything traceable.
Mobile-first responsive design
Caregivers work on the go. Mobile must be as secure as desktop. Progressive Web App for offline support.
Backup and disaster recovery
Automated encrypted backups. Offsite storage. Restore procedures tested. Business continuity plan documented.
Compliance documentation and NEN 7510
We document everything for the auditor. Security measures, policies, incident response plan. NEN 7510 checklist completed.
Penetration test and go-live
Final security test. No more vulnerabilities. We go live with the first dossiers. Everything encrypted, everything compliant.
1-3 months later
From MVP to trusted platform
After the first 14 days it went live with a pilot group. In the months that followed, hundreds of dossiers were uploaded. Zero security incidents. Zero data leaks. We added extra features: e-signature, version control and automated retention policies. The organisation successfully passed their first GDPR audit.
1 year later
From compliance to competitive advantage
UwDossierPortaal is now the standard within the organisation. They've expanded it to 5 departments. Other healthcare institutions ask about it. They consider a white-label version. What started as a compliance need is now a sales argument. "We work fully encrypted." That trust wins deals.
"We slept badly because of GDPR risks. Now we have a system that's safer than what we could buy. And it cost a fraction of enterprise solutions."