Healthcare providers in Switzerland operate at the intersection of Switzerland's Federal Act on Data Protection (FADP), the Federal Act on Patient Data (KADG), cantonal health laws, and in some contexts, GDPR. Health data is treated as sensitive personal data under FADP — the highest protection category — and the personal liability framework means the wrong decisions can expose individual practitioners and administrators.
Why Healthcare Is High-Sensitivity Under FADP
FADP classifies health data as sensitive personal data. Processing sensitive personal data triggers heightened requirements:
- Specific justification required — you must have a recognised ground for processing (explicit consent, vital interests, legal obligation, public interest, or professional confidentiality)
- DPIA obligation — large-scale processing of health data requires a Data Protection Impact Assessment
- Heightened security measures — appropriate to the sensitivity of the data
- Disclosure requirements — must be disclosed prominently in your privacy notice
Health data includes: medical records, diagnoses, treatment information, prescriptions, clinical notes, test results, health insurance data, disability status, and any data that reveals or could reveal a person's physical or mental health.
Lawful Grounds for Processing Health Data
Processing of sensitive personal data under FADP requires a justification beyond the general processing grounds. Applicable justifications for healthcare contexts:
| Ground | Application in healthcare |
|---|---|
| Explicit consent | Patient consents specifically to processing of their health data for a defined purpose |
| Vital interests | Processing necessary to protect the life of the patient or a third party — emergency situations |
| Legal obligation | Processing required by Swiss law (e.g., mandatory reporting obligations, public health law) |
| Public interest | Processing for public health purposes established by law |
| Professional confidentiality | Healthcare professionals bound by professional secrecy — but this defines the obligation, not always the ground for processing |
Consent in healthcare: Patient consent must be freely given, specific, and informed. In a healthcare context, patients are often in a vulnerable position relative to their provider — this means genuine free choice must be ensured. Pre-consent embedded in standard patient admission forms must be reviewed carefully.
Professional Secrecy and Data Protection
Medical professionals in Switzerland are bound by professional secrecy under the Criminal Code (Article 321 StGB). This obligation prohibits disclosure of health information confided in the professional capacity.
Professional secrecy interacts with FADP as follows:
- The secrecy obligation is not a data protection ground per se — it describes the obligation of confidence
- Disclosures that breach Article 321 StGB are also likely to violate FADP
- Where a patient consents to disclosure (e.g., sharing records with another treating physician), this lifts the secrecy obligation and provides a lawful basis under FADP
Professional secrecy applies to: physicians, dentists, pharmacists, midwives, psychologists, and their support staff.
Key Compliance Requirements for Healthcare Providers
Privacy Notice
- Publish a healthcare-specific privacy notice explaining: what health data is processed, why, who receives it (treating teams, laboratories, insurers, health authorities), retention periods, and patient rights
- Ensure consent to data processing is documented separately from consent to treatment
- Address electronic health record (EHR) processing specifically
Data Processing Register
- Maintain a register of processing activities for all health data processing
- Include: processing of clinical records, insurance billing data, employee health data, research activities, CCTV in clinical settings
Data Protection Impact Assessment
- Complete a DPIA for:
- Any large-scale processing of patient health records
- New clinical IT systems handling patient data
- Research projects involving patient data
- Digital health platforms processing health data of multiple patients
- Document DPIAs and retain them
Security
- Implement security measures appropriate to health data:
- Access controls — only treating team members access specific patient records
- Audit logging — log who accessed which patient's record when
- Encryption at rest and in transit
- Physical security of paper records and clinical systems
- Clear desk policy for areas where health records are present
- Implement a process for detecting and responding to security incidents
Breach Notification
- Implement a breach detection process specific to clinical systems
- A breach of health data is very likely to meet the "high risk" threshold for FDPIC notification
- Notify the FDPIC as soon as possible when a health data breach meets the threshold
- Notify affected patients where the breach puts them at risk (e.g., sensitive psychiatric or sexual health data exposed)
Data Subject Rights for Patients
- Implement a process for patients requesting access to their health records
- Respond within 30 days
- Note: some health data access requests may intersect with cantonal health law patient rights — review the applicable cantonal rules
- Implement a process for requests for deletion or restriction — note that retention requirements under health law may conflict with erasure requests; document the legal basis for retention
Digital Health and Healthtech SaaS
Swiss and EU-based healthtech SaaS companies selling to Swiss healthcare providers have both controller and processor obligations.
As a processor for healthcare providers:
- Execute DPAs with all healthcare customers
- Implement security appropriate to health data
- Support customer obligations — enable data export, deletion, and audit log access
- Sub-processor chains must be disclosed and controlled
As a controller for your own purposes:
- Apply FADP requirements to any health data you collect directly (app users, wellness platforms)
- Conduct DPIAs for health data processing features before launch
- Ensure lawful grounds for processing health data
The EU AI Act intersection: If your healthtech product uses AI to assist clinical decisions or assess patient risk, it may be classified as high-risk under EU AI Act Annex III — triggering separate compliance requirements for any EU deployments.