Secure Portal· ~90 days

UwDossierPortaal.nl

From "just send it by post" to encrypted digital dossiers

The story

Before

A healthcare organisation sends sensitive documents via email and WhatsApp. Audits fail. GDPR risks everywhere. They've been looking for a safe solution for years.

Obstacle

Existing portals are too expensive or too complex. They need NEN 7510 compliance, but budgets are tight. Every solution feels like overkill or undershoots.

Insight

They don't need an enterprise suite, but trust. A system that feels simple but is forensically secure.

After

Dossiers fully encrypted. Audit-proof logging. Compliance arranged. The team dares to communicate again.

The first 14 days

From concept to working prototype.

1
Day 1

Security requirements and compliance scan

We map NEN 7510, GDPR and their internal security policies. What needs to be encrypted? Which logs? Which access rights? Security-first from minute one.

2
Day 2

Threat modeling and architecture

We map attack vectors. What can go wrong? How do we prevent it? End-to-end encryption, zero-knowledge design.

3
Day 3

Database design with encryption at rest

PostgreSQL with field-level encryption. Keys are separated from data. Even we cannot read their content.

4
Day 4

Auth system with 2FA

Multi-factor authentication. Magic links plus TOTP. Session management with strict timeouts. Brute-force protection.

5
Day 5

Dossier structure and access management

Role-based access control. Who can see what? Per dossier, per document, per action. Granular permissions without chaos.

6
Day 6

Document upload with client-side encryption

Files are encrypted before they reach our server. Only the recipient can decrypt them. True zero-knowledge.

7
Day 7

Mid-week security audit

We have an external security expert review. Penetration testing. Vulnerability scanning. We fix everything that's vulnerable.

8
Day 8

Audit logging and compliance tracking

Every action is logged. Who, what, when, from which IP. Tamper-proof logs. GDPR-ready reports with one click.

9
Day 9

Secure messaging system

Messages between caregiver and client. Encrypted in transit and at rest. Notifications without leaking content.

10
Day 10

Admin dashboard and user management

Administrators can now safely add users, adjust rights, and view logs. Everything logged, everything traceable.

11
Day 11

Mobile-first responsive design

Caregivers work on the go. Mobile must be as secure as desktop. Progressive Web App for offline support.

12
Day 12

Backup and disaster recovery

Automated encrypted backups. Offsite storage. Restore procedures tested. Business continuity plan documented.

13
Day 13

Compliance documentation and NEN 7510

We document everything for the auditor. Security measures, policies, incident response plan. NEN 7510 checklist completed.

14
Day 14

Penetration test and go-live

Final security test. No more vulnerabilities. We go live with the first dossiers. Everything encrypted, everything compliant.

1-3 months later

From MVP to trusted platform

After the first 14 days it went live with a pilot group. In the months that followed, hundreds of dossiers were uploaded. Zero security incidents. Zero data leaks. We added extra features: e-signature, version control and automated retention policies. The organisation successfully passed their first GDPR audit.

200+ dossiers safely migrated
Zero security incidents
NEN 7510 audit with no findings
100% encrypted communication
Team dares to work digitally again

1 year later

From compliance to competitive advantage

UwDossierPortaal is now the standard within the organisation. They've expanded it to 5 departments. Other healthcare institutions ask about it. They consider a white-label version. What started as a compliance need is now a sales argument. "We work fully encrypted." That trust wins deals.

1000+ active dossiers
5 departments use it
White-label interest from 3 organisations
99.95% uptime
Saves 6 FTE of admin work

"We slept badly because of GDPR risks. Now we have a system that's safer than what we could buy. And it cost a fraction of enterprise solutions."

Dr. A. Janssen, Privacy Officer Healthcare Institution

Technology

Vue.jsTypeScriptLaravelPostgreSQLAES-256 EncryptionTOTPDockerLet's Encrypt

Ready for your story?

Let's discuss what we can build for you.

Call 085 083 5775

No-obligation intake