The Norm for informasjonssikkerhet og personvern i helse- og omsorgssektoren (Code of Conduct for Information Security and Data Protection in the Health and Care Sector), commonly referred to as Normen, is the leading information security and data protection framework for Norway's health and care sector.
Normen is not direct legislation; it is a sector-wide code of conduct that translates legal and regulatory requirements into practical security measures. It helps organizations establish a consistent approach to protecting health and personal data while supporting compliance with Norwegian legislation and the General Data Protection Regulation (GDPR).
This blog explains what Normen is, who it applies to, how it works in practice and why it plays such an important role in the Norwegian healthcare sector.
Who should comply with Normen?
Note that Normen does not replace the General Data Protection Regulation (GDPR). It instead provides healthcare-specific guidance to help Norwegian organizations apply the GDPR's information security and privacy requirements in practice.
Normen applies to organizations that process health and personal data within the Norwegian health and care sector. It covers both patient care and supporting administrative activities where information security could affect patient safety, service delivery or public trust.
Affected organizations include:
- Hospitals and health trusts
- Municipal health and care services
- General practitioners (fastleger)
- Private healthcare providers
- Pharmacies and laboratories
- Emergency healthcare services
- Radiology providers
- National e-health services
- IT vendors, cloud providers and other suppliers processing health data
Normen follows the same controller and processor roles defined by the GDPR.
Data controllers, such as hospitals, municipalities and GP practices, are responsible for determining how health data is processed, performing risk assessments, protecting patient rights and selecting trustworthy suppliers.
Data processors, including software vendors, hosting providers and telecom operators, process health data only on documented instructions from the controller. They are expected to implement appropriate security measures, support audits, assist with incident handling and protect data throughout the service lifecycle.
Normen does not replace the GDPR. It instead explains how these responsibilities should be applied in the Norwegian healthcare sector.
What does Normen do?
The framework provides a structured approach to managing information security and privacy. Organizations are expected to build security into their everyday operations instead of treating it as a one-time compliance project.
It begins by helping organizations understand their legal obligations, information assets, risks and responsibilities. Management is expected to establish clear security policies, assign responsibilities and provide sufficient resources for information security.
Like ISO/IEC 27001, Normen promotes a risk-based management system. Organizations should regularly:
- Identify information security risks
- Assess their potential impact
- Implement appropriate safeguards
- Review and improve their controls over time
This approach recognizes that security requirements differ between organizations. A small general practice and a university hospital face different risks and require different levels of complexity. Both, however maintain documented risk assessments, clear responsibilities and proportionate security measures, however.
Normen also provides practical guidance, templates and implementation examples covering topics such as risk assessments, access management, supplier agreements and incident handling. These resources help organizations translate security requirements into daily practice.
Information security requirements in practice
Normen combines organizational, technical and physical security measures to protect sensitive health information throughout its lifecycle.
From an organizational perspective, the framework expects documented policies, clearly defined responsibilities, regular staff training and established procedures for onboarding, offboarding and change management. Information security should be integrated into governance and clinical workflows rather than managed separately.
Technical safeguards focus on protecting systems and health data through measures such as:
- Access control based on job responsibilities
- Strong authentication
- Encryption of sensitive information
- Secure logging and monitoring
- Network segmentation
- Vulnerability management
- Secure system development
Logging receives particular attention because it supports both security monitoring and patient privacy. Organizations should be able to identify who accessed patient records, when access occurred and whether that access was appropriate.
Normen also provides guidance for cloud services, mobile devices and medical technology. Before introducing new technologies or suppliers, organizations are expected to assess risks, define responsibilities and ensure appropriate contractual safeguards are in place.

Bridging GDPR and everyday healthcare
While the GDPR establishes overarching privacy principles, Normen serves as the practical bridge that translates high-level legal mandates into concrete healthcare security controls.

Incident Management & Business Continuity
This bridge directly shapes how healthcare providers prepare for and respond to operational disruptions.
- Incident Response: Because no organization can eliminate every security threat, Normen requires clear procedures to detect, report, investigate, and resolve incidents. Staff are trained to spot anomalies, system logging helps detect unauthorized access, and root-cause analyses ensure long-term prevention.
- Business Continuity: Even during cyberattacks or system outages, critical care cannot stop. Normen enforces proactive continuity planning—requiring organizations to identify core systems, maintain actionable recovery protocols, and routinely test resilience.
By translating EU-level law into daily operational blueprints, Normen helps healthcare organizations move seamlessly from legal compliance to active protection.
Why Normen matters
Normen has become the common information security framework for the Norwegian health and care sector because it gives organizations a shared approach to protecting sensitive health information.
Instead of thousands of independent clinics interpreting complex data legislation on their own, Normen offers the Norwegian healthcare sector a standardized framework to support compliance with the GDPR and national legislation.
Tip: Many organizations also combine Normen with ISO/IEC 27001. The two frameworks share many management system principles, while Normen adds healthcare-specific guidance for areas such as patient data, logging, national e-health services and clinical workflows. In Cyberday, you can confidently work on multi-compliance with ISO 27001, GDPR and Normen without duplicating compliance efforts.
By following Normen, organizations can strengthen information security, improve risk management and build trust among patients, regulators and healthcare partners. Most importantly, the framework helps ensure confidential health information remains secure, available and accurate so healthcare professionals can continue delivering safe and reliable patient care.

%201.jpg)















