Data Residency & Cloud in Hospitals: Microsoft 365, US Access Risk and Swiss Hosting, Legally Clarified
The cloud question stalls entire procurements in hospitals: may patient data sit in Microsoft 365 or with a US hyperscaler? We answer it legally and technically in one mandate, with data-flow analysis, a transfer-impact assessment, encryption and hosting options, and the Swiss Priverion platform as sovereign tooling.
legally led (Dr. iur., CIPP/E)DE · FR · ENPriverion Platform
Few topics delay hospital IT projects as reliably as the question of whether and how patient data may sit in the cloud.
Microsoft 365, Teams, Exchange Online and Azure have long been standard in daily hospital work. But the moment particularly sensitive health data flows into these services, the core question arises: where is the data processed, who can access it, and on what legal basis? This is exactly where projects tip into months-long stalemates between IT, data protection, legal and procurement.
At the centre sits the US CLOUD Act: a provider with a US nexus can be legally compelled to hand over data, even if it physically resides in a European or Swiss data centre. For a hospital this means a theoretical government access risk to patient data that must be cleanly addressed in data-protection law and risk assessment, rather than ignored in the procurement process.
On top of this come the ECJ's Schrems case law and the requirements for transfers of data abroad: is the EU-US Data Privacy Framework or an adequacy decision sufficient, are standard contractual clauses needed, and are additional safeguards required in the individual case? These questions cannot be answered with a checkbox in a procurement form; they call for a documented legal assessment that withstands scrutiny by the FDPIC or an EU supervisory authority.
What makes it harder is that IT architecture and the legal position are rarely assessed by the same people. IT knows the technical configuration, legal knows the transfer scenarios, and neither side alone has the complete picture. We close this gap by bringing both perspectives together in one mandate.
From blocker to a documented decision
There is no single correct cloud answer, but a reasoned, documented decision per data category and use case. These are the paths we walk with you.
We start with a data-flow analysis: which data of which sensitivity flows into which services, into which regions, to which sub-processors? Only once the real data flows are visible can we judge where a transfer or access risk actually exists and where it does not. Often it turns out that only a portion of the data is critical and can be handled in a targeted way.
This is followed by the transfer-impact assessment (TIA): for each transfer we examine the legal basis, the recipient country, the government-access situation and the effectiveness of safeguards. The result is a traceable assessment with clear conditions, which we underpin with standard contractual clauses and supplementary technical and organisational measures.
On the technical side we assess encryption and key sovereignty: client-side encryption, bring your own key and hold your own key, double key encryption, and the question of whether the provider can access plaintext at all without your key. Where key sovereignty sits with the hospital, the legal access risk changes noticeably. We assess what your architecture actually delivers; we do not configure a solution ourselves, we evaluate it.
Where the risk demands it, we review Swiss and EU hosting options as an alternative or complement: Swiss data centres, the EU Data Boundary, sovereign-cloud offerings and hybrid models in which the most sensitive data categories stay in Switzerland. We assess these options soberly along law, risk and operational fitness, without selling a hosting product of our own. This keeps our recommendation independent.
We do not capture the results in a one-off PDF but in our Swiss Priverion Platform: the records of processing, data flows, TIA and measures are maintained there and stay current. Because the platform is itself a Swiss solution, you avoid the paradox of keeping data-protection evidence in, of all things, a US cloud tool. That is a sovereign tooling differentiator that purely technical or purely legal providers do not offer in this form.
Why SIDD for data residency & cloud
The cloud question is both a legal and an architecture question. We assess both sides in one mandate and in the same language.
Law and technology under one roof
Doctorate-level lawyers with CIPP/E assess the transfer scenarios, an in-house technical team evaluates architecture, encryption and key sovereignty. The result is an assessment that holds up both legally and technically.
Transfer law nFADP and GDPR vetted
We assess transfers under the revised FADP and under the GDPR, including the EU-US Data Privacy Framework, adequacy, standard contractual clauses and Schrems requirements. For hospitals with an EU parent or EU patients, we think both legal regimes together.
Key sovereignty assessed concretely
We examine whether BYOK, HYOK or double key encryption actually reduces the access risk in your concrete setup, or whether the configuration only creates the appearance of protection. This distinction drives the legal assessment of the transfer.
Independent, no in-house hosting
We sell neither cloud capacity nor a data centre of our own. Our recommendation between Microsoft 365, Swiss hosting and hybrid models follows your risk alone, not a sales interest.
Sovereign Swiss tooling
We maintain data flows, TIA and measures in the Swiss Priverion Platform, instead of keeping data-protection evidence in a US cloud tool. In case of a request from the FDPIC or an EU authority, the evidence is available as maintained, current tooling.
Multilingual for CH and EU
We advise in German, French and English, relevant for French-speaking Switzerland, for international providers and for EU parent companies. Procurement boards, IT and data protection receive the same result in the respective language.
Cloud, data-flow and transfer assessment
Cloud baseline assessment
Fixed fee
The fast entry when a specific procurement or a single cloud service is blocked.
Capture of the affected services and data categories
Initial legal classification of the transfer situation
Traffic-light rating of the US access risk
Prioritised immediate measures for the procurement
Data-flow & transfer assessment
Fixed fee
The in-depth assessment for Microsoft 365 and further cloud services, documented in an audit-ready way.
Complete data-flow analysis across services, regions and sub-processors
Transfer-impact assessment per transfer under nFADP and GDPR
Assessment of encryption, BYOK, HYOK and key sovereignty
Comparison of Microsoft 365, EU and Swiss hosting options
Standard contractual clauses and supplementary measures recommended
Why we work with LexCommand, our own Swiss legal AI
LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.
01
Sovereign in Switzerland
The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.
02
No citation, no claim
Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.
03
From effort to judgement
LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.
04
Three disciplines, one picture
We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.
For your transfer-impact assessment, concretely: LexCommand backs every statement on the CLOUD Act, Schrems, adequacy and standard contractual clauses with the exact primary source, lays the revised FADP and GDPR transfer duties side by side, and reads the law as valid on your reference date, so the TIA holds up under FDPIC scrutiny.
Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.
Frequently asked questions on data residency & cloud
May patient data sit in Microsoft 365 at all?
There is no blanket answer. It depends on the data category, configuration, encryption, key sovereignty and the documented transfer situation. We assess your concrete case and deliver a reasoned, audit-ready decision rather than a gut feeling.
Is it enough if the data sits in a Swiss or EU data centre?
The physical storage location alone is often not enough. Under the US CLOUD Act a provider with a US nexus can be compelled to hand over data even if it sits in Switzerland or the EU. What matters is the combination of storage location, provider structure, access possibilities and key sovereignty, which we assess together.
What is a transfer-impact assessment?
A transfer-impact assessment is the documented examination of a transfer of data abroad: legal basis, recipient country, government-access situation and the effectiveness of safeguards. It is the basis for choosing standard contractual clauses and supplementary measures with legal certainty and justifying them to supervisory authorities.
Does encryption with your own keys really reduce the risk?
Often yes, but not automatically. What matters is whether the provider can access plaintext without your key. Models such as BYOK, HYOK or double key encryption differ considerably. We examine what your concrete configuration actually delivers and translate that into the legal assessment of the transfer.
Do you sell cloud or hosting yourselves?
No. We run no data centre of our own and sell no cloud capacity. Our recommendation between Microsoft 365, Swiss hosting and hybrid models follows your risk alone. Our Priverion Platform is a tool for keeping evidence, not a hosting offering for your patient data.
Do you work in French for French-speaking Switzerland?
Yes. We advise throughout in German, French and English, including cantonal specifics and international providers and EU parent companies.
A cloud decision instead of a cloud stalemate
We clarify data residency, US access risk and hosting options legally and technically, with a board-ready report and a clear recommendation.