In healthcare, security is first a legal and governance question. We lead it juristically, not just technically: revised FADP, EPR law, EU AI Act, NIS2/critical-infrastructure reporting, ISO 27001/42001, one partner for hospitals, clinics, practices, EPR communities and MedTech.
For hospitals, clinics, practices, EPR communities and MedTech
Health data is especially sensitive. Healthcare organisations face a dense wave of regulatory obligations across 2026–2028.
Cyberattacks on healthcare providers have risen worldwide and in Switzerland, hitting operations, patient safety and reputation. At the same time, legal requirements for data protection, reporting duties and AI are tightening.
We bundle these topics into one legally led mandate, instead of isolated, one-off technical measures.
Orientation, not legal advice. We verify dates and scope case by case. Some timelines are still politically in motion.
| Regulation | What it requires | Timing | Status |
|---|---|---|---|
| Revised FADP | DPIA for health data, breach notification to the FDPIC, technical and organisational measures | since 1 Sep 2023 | in force |
| Critical-infrastructure reporting (ISG/BACS) | Reporting relevant cyber incidents to the BACS within a short deadline | since 2025 | in force (verify detailed deadlines) |
| EU AI Act (medical AI) | High-risk obligations for diagnosis, triage and decision-support AI | deadlines 2026/2027, under revision | verify dates (Digital Omnibus) |
| EU NIS2 | Risk management and reporting duties for healthcare entities with an EU footprint | depending on national transposition | only with an EU establishment |
| EPR Act revision | Modernisation of the electronic patient record, broader connection | in preparation | planned |
| EU Cyber Resilience Act | Security and vulnerability duties for connected products | staggered 2026–2027 | verify dates |
Dive into the topic relevant to you:
High-risk compliance for diagnosis, triage and decision support.
Reporting duties, board responsibility and readiness.
Certification-ready ISMS tailored to healthcare data flows.
Data-protection and security readiness for connection and the future.
Tabletop exercises, playbooks and governance, before the incident.
Microsoft 365, US access risk and Swiss hosting in hospitals.
In healthcare, law and governance drive the risk. That is exactly where our focus lies.
Your mandate is led by doctorate-level lawyers with CIPP/E, backed by an in-house technical team. So we assess processing, data-processing agreements and DPIAs on solid legal and technical ground.
Where a SIDD lawyer advises in a legal capacity, your information may be covered by professional secrecy under Art. 321 of the Swiss Criminal Code, in addition to contractual confidentiality. We clarify the exact scope per mandate.
With three dedicated AI services (AI Officer, AI Governance Check, AI Security) we cover the EU AI Act for medical AI, a field that purely technical security providers barely serve.
We advise in German, French and English, relevant for French-speaking Switzerland and EU parent companies. Because we do not sell an in-house SOC, our recommendations stay independent.
We maintain records of processing, DPIAs and measures in our Swiss Priverion Platform. In case of a regulator request, the evidence is available as maintained tooling.
You start with a fixed-fee Healthcare Compliance baseline assessment with a board-ready report and then decide on an ongoing mandate.
For a Swiss healthcare platform (Openmedical AG) we aligned data protection with the revised FADP: a platform data-flow analysis, new data-processing agreements with the extensive customer base, plus penetration tests and vulnerability scans to assess technical risk.
Our tool: LexCommand
LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.
The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.
Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.
LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.
We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.
For the Healthcare Compliance baseline assessment, concretely: LexCommand maps your overlapping duties from the revised FADP, EPR law, EU AI Act, NIS2/critical-infrastructure reporting and ISO 27001/42001 into one crosswalk, in the version valid at each deadline, so every statement in the board-ready report traces to a retrievable primary source.
Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.
No. We are a legally led governance, compliance, assessment and readiness partner. We coordinate 24/7 monitoring with specialised providers, which keeps our advice independent.
With a fixed-fee Healthcare Compliance baseline assessment: a multi-regulatory gap analysis with prioritised measures and a board-ready report.
Yes. We advise throughout in German, French and English, including cantonal specifics and EU parent companies.
We assess your compliance and security posture, with a board-ready report and prioritised measures.