Choosing a Healthcare Security and Data-Protection Partner, A Decision Guide

5 min readLast updated 15 Jun 2026By Dominic Staiger

Why partner selection in healthcare is its own discipline

Hospitals, medical practices, laboratories, care facilities and HealthTech providers face a regulatory mix that few other sectors share: the Swiss nFADP and, where there is an EU nexus, the GDPR, the Swiss ISG/BACS reporting regime, the EU NIS2 Directive for entities with an EU establishment, the planned total revision of the EPDG (Electronic Patient Record Act), and on the product side MDR/IVDR and the Cyber Resilience Act (CRA). On top of this comes the EU AI Act once clinical or administrative AI is involved. Choosing a security and data-protection partner therefore does not mean buying a single service, but buying the ability to think about these requirements in an integrated way.

This article is deliberately neutral. It names no specific providers and recommends no particular firm. The aim is to give you, as a decision-maker, a clean grid against which to compare offers, and to state honestly where a large, operations-oriented provider is the better fit and where a legally led, specialised partner plays to its strengths.

Criterion 1: integrated regulation rather than isolated topics

The most important question first: does the partner cover nFADP/GDPR, NIS2 or the Swiss ISG/BACS reporting regime, the EPDG, MDR/CRA and the EU AI Act within a coherent model, or does it treat each topic in isolation? In healthcare these regimes interlock: a vulnerability in a medical device is simultaneously a data-security matter, a reporting matter and potentially a product matter. If these strands are advised separately, gaps and duplicated work arise.

Watch for clean delineation here: NIS2 is an EU directive that Switzerland has not transposed. It binds primarily entities with an establishment or operations in the EU. A purely Swiss hospital does not fall under NIS2 but under the Swiss ISG/BACS reporting duties. A serious partner keeps these two worlds distinct and does not blur them into a vague "NIS2 applies to everyone". Equally important: MDR/IVDR cybersecurity requirements are already in force, while the CRA applies in stages across 2026/2027 (verify the dates in each case), and the EPDG total revision is planned or in preparation, without a fixed date.

Criterion 2: legal depth and professional secrecy

Health data are particularly sensitive personal data. Questions about data ownership, processing, cross-border data flows, consent and the protection of secrecy under Art. 321 of the Swiss Criminal Code are at their core legal questions, not primarily technical ones. Check therefore whether your partner brings genuine legal depth, or whether the legal assessment ends up back with you or your in-house counsel.

One special aspect that only a few constellations offer: where an adviser is also a lawyer and advises in that legal capacity, your statements may be subject to professional secrecy under Art. 321 of the Swiss Criminal Code. This is not blanket protection for every activity of the consultancy, but in sensitive situations, such as working through an incident or a legally exposed risk assessment, it is a real advantage. Ask specifically which parts of the mandate this protection covers and which it does not.

Criterion 3: multilingualism DE/FR/EN

Swiss healthcare is multilingual. An organisation with sites in German-speaking Switzerland, the Romandie and Ticino, working with EU partners or publishing internationally, needs documents, training and authority communication in several languages. Check whether the partner actually delivers policies, data-protection impact assessments, data-processing agreements and awareness training in German, French and English, and to a sound professional standard, not merely machine-translated.

Multilingualism is more than convenience: a consent declaration that staff in the Romandie do not understand in their working language is weaker both legally and in practice. Awareness training only works if it takes place in the language of the staff.

Criterion 4: board-ready governance rather than a mere findings report

A frequently underestimated difference: at the end, does the partner deliver only a technical findings report, a list of vulnerabilities with severity scores, or a board-ready governance template that genuinely enables the executive and the board (or foundation council) to decide? A hospital board needs risks expressed in business and liability language, prioritised measures, accountabilities and a traceable residual-risk decision.

Both outputs have their place. A pure findings report is valuable for the technical team. But when you have to discharge an oversight duty, build ISMS governance, or account to supervisory authorities, you need the translating layer on top. Ask for sample deliverables: do they look like a pentest log, or like a template you can carry straight into the committee?

Criterion 5: independence and conflicts of interest

Does the partner resell its own Security Operations Centre (SOC), its own software, or specific products? That is not bad in itself, but it creates a structural incentive: a firm with its own solution in the portfolio tends to recommend it even where a neutral view would reach a different conclusion. An independent partner with no own SOC and no sales tie can recommend what makes the most economic sense, including third-party solutions.

So clarify openly: does the partner have a financial interest in the tools it recommends? How does it separate advice from implementation? Independence is a hard quality marker, especially when selecting service providers and tools. It makes the recommendation credible.

Where the large managed-SOC provider fits, and where the legally led partner

Honesty belongs in a decision guide. If your primary need is ongoing 24/7 operation, continuous monitoring, alerting, real-time technical response to incidents, hands-on testing of medical devices, firmware or IoMT, then a large, operations-oriented provider with its own managed SOC and a specialised testing team is the right choice. A legally led, boutique partner does not replace that ongoing operation.

Conversely, the legally led partner plays to its strengths where integrated regulation, legal depth, board-ready governance and preparation matter: ISMS and ISO 27001 support, data-protection mandates, a vCISO function, penetration testing and vulnerability scanning, AI governance, and preparing interfaces and escalation paths for an emergency. Ransomware readiness here means: tabletop exercises, governance and preparing escalation paths, plus coordinating with named external incident-response providers and insurers, not the real-time operation itself. For hands-on device testing, a serious partner refers you to a specialised testing partner. In practice, many healthcare organisations combine both: the operator for ongoing operation, the legally led partner for governance, law and preparation.

Buyer's checklist and where SIDD fits

Use this checklist in the selection meeting:

  • Integration: Are nFADP/GDPR, ISG/BACS or NIS2, EPDG, MDR/CRA and the AI Act thought through in one model, and cleanly delineated?
  • Legal depth: Is there genuine legal competence, and in which parts of the mandate does professional secrecy under Art. 321 of the Swiss Criminal Code apply?
  • Languages: Does the partner deliver documents and training to a sound professional standard in DE/FR/EN?
  • Governance: Do you receive a board-ready output, or only a technical findings report?
  • Independence: Does the partner resell its own SOC, software or products?
  • Delineation: Is ongoing operation (SOC, real-time response, device testing) clearly separated from preparation and governance?
  • References: Is there demonstrable experience in healthcare?

SIDD positions itself clearly as a legally led, independent boutique partner: integrated advice across nFADP/GDPR, ISG/BACS, the EPDG context, MDR/CRA and the AI Act, with legal depth, multilingual in DE/FR/EN and with board-ready deliverables. We operate no SOC of our own and resell no products of our own; hands-on device testing we refer to a specialised testing partner. A reference from the healthcare field is Openmedical AG (nFADP data-flow analysis, thousands of data-processing agreements, pentests). More at data protection advisory, ISMS/ISO 27001 and penetration testing. For a selection meeting, reach us via the contact form; request a quote via our quote form.

Need help putting this into practice? SIDD operates the matching service.
See service →

Choosing a Healthcare Security and Data-Protection Partner, A Decision Guide

INSIGHT

InfoSec
15 June 2026
Dr. Dominic Staiger
A neutral decision guide for hospitals, practices and HealthTech: which criteria matter when choosing a security and data-protection partner, with a buyer's checklist.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.