Healthcare · EPR & EPR Act revision · legally led

EPR & EPR Act revision: data-protection & security readiness, legally led

The electronic patient record connects practices, pharmacies, hospitals and communities, and places high demands on data protection, consent and identity security. We make you ready today and factor in the planned EPR Act revision: nFADP/EPRA alignment, consent logic, DPIA and Trusted-Third-Party stewardship.

legally led (Dr. iur., CIPP/E) DE · FR · EN Trusted Third Party for health data
Data protection and security around the electronic patient record

For EPR communities, practices, ambulatory groups, pharmacies, hospitals and cantonal e-health programmes

Legally led Dr. iur. · CIPP/E
EPR & EPRA nFADP alignment
Trusted Third Party data & key stewardship
Consent & access audit-ready records
CH · EU multilingual DE/FR/EN
Dr. Dominic Staiger

Responsible for this mandate

Dr. Dominic Staiger

LL.M., Dr. iur., CIPP/E · Attorney at Law (New York) · Solicitor (UK)

LinkedIn

The EPR today: what data protection and security require

The electronic patient record pools especially sensitive health data across organisational boundaries, and sets clear expectations for consent, identity and confidentiality.

The EPR rests on patients' voluntary, informed consent and on a differentiated access concept with confidentiality levels. Anyone who uploads or retrieves documents must be securely identified, able to demonstrate the legal basis for access and to document the processing.

For connected providers this means: nFADP-compliant processing of health data, clean data-processing agreements with IT and platform partners, a maintained record of processing activities, and technical and organisational measures that match the protection requirement.

We therefore treat the EPR not as a pure IT project but as a governance task: who may do what, on which legal basis, with which consent, and how you demonstrate it to patients, the community and supervisory bodies.

The planned EPR Act revision: act early instead of catching up later

A comprehensive revision of the EPR Act is planned, or in preparation. It aims at broader and more binding connection. Details and timing are still politically in motion.

Today many small and mid-sized practices and ambulatory providers are not yet connected to the EPR. The planned revision points towards broader, partly more binding participation and a modernisation of the technical and organisational foundations, which increases the preparation effort for organisations not yet connected.

We deliberately name no fixed entry-into-force date and no guaranteed deadline: legislative processes shift and detailed rules are still open. What we provide is dated, case-specific orientation, and a readiness foundation that holds regardless of the exact timing.

The advantage of acting early: those who have already cleanly set up data flows, consent logic, identity connection and contracts can meet a future connection duty calmly and without rush, instead of retrofitting under time pressure.

Our support: solid today, prepared for tomorrow

We combine current obligations with forward-looking design, legally led, technically robust and tailored to your size.

nFADP/EPRA alignment

We assess your processing of health data against the nFADP and the EPR framework: legal bases, confidentiality levels, retention, data-subject rights and the duties of a connected provider or community.

Consent logic & access

We design and document an audit-ready consent and access logic: voluntary, informed consent, confidentiality levels, withdrawal and logging, so you can evidence it to patients and supervisory bodies.

DPIA support

For EPR connection and new data flows we support your data-protection impact assessment: risk assessment, measures and documentation, as audit-ready evidence rather than a formality.

Trusted Third Party

As an independent Trusted Third Party we can act as steward for health data and cryptographic keys, for example to separate roles, escrow keys or serve as a neutral party between partners in a community.

Contracts & processing agreements

We draft and review data-processing agreements with platform, hosting and IT partners, clarify responsibilities within the community and ensure a clean contract chain around the EPR connection.

Training & awareness

In a data-protection and IT-security workshop we enable your team in handling the EPR: obtaining consent correctly, justifying access cleanly, recognising and reporting incidents, practical and tailored to your roles.

EPR Readiness Assessment, fixed-fee entry

EPR Readiness, compact for small practices

Fixed fee

Template-based and affordable for solo practices and small ambulatory providers preparing for connection.

  • Compact nFADP/EPRA alignment via a structured checklist
  • Templates for consent, access logic and the record of processing
  • Prioritised list of measures for connection
  • Short report with next steps

EPR Readiness, community & hospital

on request

For (root) communities, cantonal e-health programmes and hospitals with many connected providers.

  • Governance model for the community's roles, responsibilities and access
  • Trusted-Third-Party concept for data and key stewardship
  • Integration with ISO 27001 / ISMS and existing security measures
  • Preparation for future broader connection under the EPR Act revision

Matching SIDD services around the EPR

The EPR touches several compliance topics. We think them together:

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For your EPR readiness, concretely: LexCommand backs every statement in the nFADP/EPRA alignment and the DPIA with the primary source at its exact location, surfaces overlapping duties from the nFADP and the EPR framework side by side, and provides dated orientation on the version in force despite the still-moving EPR Act revision.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions on the EPR and the EPR Act revision

We are a small practice and not yet connected to the EPR. Is it worth preparing now?

Yes. Many practices are not yet connected. The planned EPR Act revision points to broader participation. With our template-based compact assessment you lay a clean foundation today, without much effort, and are prepared should connection become more binding.

Is there a fixed date for the EPR Act revision?

We deliberately name no guaranteed date. The total revision is planned, or in preparation, but content and timing are still politically in motion. We give you dated, case-specific orientation and build readiness that holds regardless of the exact timing.

What does Trusted Third Party mean in the EPR context?

As an independent Trusted Third Party we can act as a neutral steward for health data and cryptographic keys, for example to separate roles, escrow keys or mediate as a neutral party between partners in a community. We define the exact scope per mandate.

Do we need a DPIA for the EPR connection?

Processing health data is especially high-risk. New data flows from an EPR connection may trigger a data-protection impact assessment. Whether and to what extent we assess case by case, and support you in producing it as audit-ready evidence.

Do you work in French for French-speaking Switzerland?

Yes. We advise throughout in German, French and English, including cantonal specifics of the e-health programmes.

Get EPR-ready, solid today, prepared for the revision

We start with a fixed-fee EPR Readiness Assessment: nFADP/EPRA alignment, consent logic and prioritised measures, documented board-ready.