Data Protection in Swiss Medical Practices, DSG, Patient Records, EPR
Introduction
A Swiss medical practice processes several hundred categories of sensitive personal data per patient each year: diagnoses, laboratory results, imaging, medication, correspondence with insurers, family history. The processing has been part of daily practice for decades, but legal complexity has risen sharply with the revised Federal Act on Data Protection (DSG, in force since 1 September 2023), the expanding obligations under the Federal Act on the Electronic Patient Record (EPRA / EPDG) and the long-standing professional secrecy duty under Art. 321 of the Swiss Criminal Code (SCC). Practice owners or IT leads without a clean data-protection and security baseline in 2026 risk fines of up to CHF 250,000 under Art. 60 DSG, criminal complaints for breach of professional secrecy and material reputational and insurance damage.
This article covers:
- The interplay of legal sources (DSG, KVG/health insurance act, EPDG, Art. 321 SCC, cantonal health law)
- Obligations toward patients, insurers and authorities
- Requirements for practice IT systems, cloud hosting and EPR connection
- Pragmatic technical and organisational measures (TOMs)
- How a data-protection adviser concretely takes load off you
Legal framework
A medical practice sits at the intersection of several regulatory bodies that apply in parallel and do not displace each other:
- Professional secrecy (Art. 321 SCC): duty of secrecy for physicians, pharmacists, midwives and their auxiliaries. Breach is prosecuted on complaint with a penalty of up to three years imprisonment. The duty applies vis-à-vis every person outside the treatment relationship – including family members, lawyers, police – unless statute mandates disclosure or the patient releases the practitioner.
- Federal Act on Data Protection (DSG): applies subsidiarily. Health data is "sensitive personal data" under Art. 5(c) DSG, high-risk profiling triggers DPIA duties, and rights of access, rectification and erasure apply.
- Health Insurance Act (KVG/KVV): obligations toward health insurers (billing, economic-efficiency review), including data transfer under Art. 42 KVG.
- EPDG and implementing ordinances: obligations on connection to the electronic patient record; from 2026 mandatory connection for new inpatient providers, voluntary for outpatient care – political pressure to extend the duty is real.
- Cantonal health law: licensing and supervision rules, retention periods (typically 10-20 years after end of treatment).
Obligations toward patients
Patients have substantive rights against the practice that must be operationalised. Four areas shape daily work:
- Information (Art. 19 DSG): when collecting patient data – at reception, online or on admission – the practice must transparently inform about purposes, recipients, retention period and rights. A written privacy notice is standard and should be available at reception, in admission forms and on the practice website.
- Consent: for processing outside the treatment contract (marketing, research participation, transfer to third parties beyond statutory duties), explicit and documented consent is required.
- Right of access (Art. 25 DSG): patients may request a free copy of all processed data, including the full medical record. Deadline: 30 days. The practical challenge: correctly separating patient data from physician-internal notes ("personal notes" under the FMH code of conduct – which still fall within scope of access when stored on the shared system).
- Data portability on practice change: patients are entitled to a complete medical record – electronic or on paper.
EPR and practice IT systems
The Swiss electronic patient record (EPR / ePD) has been live since 2020; connection is rolling out in waves and is increasingly mandatory. In 2026 all inpatient providers are connected; outpatient connection remains voluntary, with active parliamentary debate to extend the duty. From a data-protection standpoint the key point is that the EPR is patient-managed – the patient decides which documents are uploaded and which providers can access them. The medical practice is a processor of EPR data, not its owner.
Practice IT systems (PIS) such as Vitomed, Aeskulap, Achillesmed, Elexis or TriaMed are the core of practice IT. When selecting, verify: Swiss data residency or at minimum EU/EEA hosting with a transparent sub-processor list, encryption at rest and in transit, role-based access (physician, MPA, accounting), tamper-evident audit logs with personal attribution, IHE-conformant EPR interfaces and a clean data-processing agreement under Art. 9 DSG. Cloud hosting is permitted provided the vendor preserves professional secrecy under Art. 321 SCC through suitable TOMs (above all encryption with key control at the provider) and is engaged as an auxiliary under Art. 321(1) SCC – a point that must be reflected precisely in the contract.
Interfaces with insurers and authorities
Data flows between practice and health insurers are statutorily regulated and politically charged. For billing under Tarmed/Tardoc and, from 2026 onwards under the new outpatient flat-rate tariffs, diagnosis and treatment data must be transmitted in limited form. Art. 42(3) and (4) KVG mandates a separation: the insurer receives detailed diagnosis data under tiers-payant (mandatory benefits, hospitalisation) but not under supplementary insurance and tiers-garant. In practice the trusted physician (Vertrauensarzt) is the interface entitled to see detailed information while the rest of the insurer organisation receives only aggregated data.
Statutory disclosure duties break the secrecy in targeted ways: notifiable diseases under the Epidemics Act (e.g. tuberculosis, HIV in pseudonymised form), suspicion of violence against children (Art. 364 SCC), fitness-to-drive concerns to road-traffic authorities in cases of acute self-/third-party endangerment, and statistical reporting under Federal Statistical Office ordinances. Each disclosure must be documented in the medical record. For requests from lawyers, employers, treating physicians outside the relationship or family members: without explicit release by the patient (or, for the incapable, by the authorised representative), disclosure is impermissible.
Technical and organisational measures
The GDK (Swiss Conference of Cantonal Health Ministers) and the FDPIC (EDÖB) have set out the expected level of protection for health data in several recommendations. The 2026 minimum standard for a Swiss medical practice is:
- Access control: personalised logins, two-factor authentication for remote access, automatic screen lock after 5 minutes, clear role profiles (physician, MPA, practice manager, accounting).
- Audit logging: complete logging of all access to patient records, retained for at least 12 months, periodic spot-checks by the practice lead.
- Encryption: encrypted server backups, full-disk encryption on mobile devices (laptop, tablet, smartphone), restrictively managed USB ports.
- Backup and recovery: daily backup, at least one copy off-site or in a geographically separate cloud region, quarterly restore tests.
- Awareness: mandatory annual training for the entire team on phishing, secure e-mail, telephone social engineering and professional secrecy.
- Incident plan: documented plan for ransomware, system outage, data breach; contact list with IT provider, cantonal data-protection officer, BACS, FDPIC.
- Processor management: written DPA under Art. 9 DSG with every PIS vendor, cloud provider, billing service, external lab, IT provider.
Data breaches and notification
Personal-data breaches – ransomware, mistaken e-mail with patient data sent to a third party, theft of a laptop – must be reported to the FDPIC (EDÖB) as quickly as possible under Art. 24 DSG where a high risk to the data subjects exists. For health data this threshold is in practice always met. The reporting deadline is not numerically fixed at 72 hours as under Art. 33 GDPR, but the FDPIC's understanding is comparable: the duty starts when the controller becomes aware of the incident; delays must be justified.
For a breach, the recommended sequence is: 1. immediate containment (isolate system, lock account, e-mail recall), 2. evidence preservation (logs, identify affected records), 3. risk assessment vis-à-vis patients with data-protection and legal counsel involvement, 4. notification to the FDPIC via the official portal, 5. notification of affected patients where risk demands, 6. reporting to BACS/NCSC for cyber incidents under Art. 74b ISG (usually not mandatory for individual practices but increasingly relevant for larger practice groups and hospitals), 7. evaluate criminal complaint, 8. lessons-learned and adjustment of TOMs documented. Practices that have not rehearsed this sequence lose valuable hours during which damage compounds.
How SIDD supports you
SIDD advises numerous Swiss medical practices, practice partnerships and smaller hospitals as external data-protection adviser. We deliver the record of processing activities under Art. 12 DSG, the patient privacy notice, staff training, DPA templates for PIS and cloud vendors, and a usable incident playbook for data breaches. Our data-protection adviser mandate is tailored to practice realities: monthly availability, annual compliance review, immediate response support. We complement this with data-protection workshops for your team, vulnerability scans of your infrastructure, and – for larger practice groups – penetration tests of your PIS and cloud integration. Speak with us via our contact form if you want an initial assessment, or request a quote for a tailored adviser mandate. We deliver a pragmatic proposal within two weeks that joins professional secrecy, DSG and EPR reality.
