Health insurers & payers · legally led data-protection and AI governance

Data Protection & AI Governance for Health Insurers and Payers, legally led

Health insurers and payers process especially sensitive health and claims data every day, in dense data flows between mandatory and supplementary insurance, providers and reinsurers. Where you use AI in claims adjudication, underwriting or fraud detection, the revised FADP and the EU AI Act meet. We lead these topics juristically, as one partner for your data-protection and compliance leads.

legally led (Dr. iur., CIPP/E) AI governance depth, EU AI Act independent, no in-house SOC business
Data protection and AI governance for health insurers and payers

For health insurers, supplementary insurers, payers and their data-protection and security leads

Legally led Dr. iur. · CIPP/E
EU AI Act high-risk payer AI
Health data especially sensitive
DPO & vCISO as an external function
CH · EU multilingual DE/FR/EN
Dr. Dominic Staiger

Responsible for this mandate

Dr. Dominic Staiger

LL.M., Dr. iur., CIPP/E · Attorney at Law (New York) · Solicitor (UK)

LinkedIn

Complex data flows, especially sensitive data

No other healthcare player concentrates as much health and claims data on as many people as a health insurer. Exactly this data is especially sensitive under the revised Data Protection Act.

Health insurers and payers move data along a long chain: claims billing and diagnosis codes from providers, medical records from the medical-officer service, application and health questions from the supplementary-insurance business, reimbursement and tariff data, plus exchange with reinsurers and service providers. These flows span the mandatory-insurance business under the Health Insurance Act and the supplementary-insurance business under the Insurance Contract Act, two worlds with different legal bases, purpose limitations and separation requirements.

From the revised Data Protection Act this gives rise to concrete duties: a robust record of processing activities across all lines, a data-protection impact assessment for high-risk processing such as extensive profiling over health data, clean data-processing agreements with IT, print and collection providers, and notification of data-security breaches to the Federal Data Protection and Information Commissioner. The criminal fines of up to CHF 250,000 target the responsible natural person. This makes data protection a leadership task.

A particular sharpness arises at the interface of mandatory and supplementary insurance: data collected for claims handling under the Health Insurance Act must not flow unfiltered into the supplementary business or into underwriting. We review these separations legally, document the purpose limitation and bring your data flows into an audit-ready form that is defensible vis-à-vis the Commissioner.

AI in claims adjudication, underwriting and fraud detection

Where you apply AI to health and claims data, a strong high-risk link to the EU AI Act arises, and in parallel the duty to carry out a data-protection impact assessment. Both belong in one shared governance.

Algorithms today support claims review, the detection of billing fraud, risk classification in underwriting, and the steering of case management and customer contact. As soon as such systems help decide on access to insurance benefits or on the pricing of individuals, they typically fall into the high-risk category within the scope of the EU AI Act. The high-risk obligations apply from 2026/2027, but the deadlines are under revision (Digital Omnibus) and must be checked case by case. It also matters whether you have an establishment or activity with an EU nexus.

A central requirement for high-risk AI is appropriate human oversight: an automated recommendation to deny a benefit must not become the decision unchecked. This connects with the data subject's right under the revised Data Protection Act to be informed of an automated individual decision with significant effect and to request a human review. We translate these legal lines into concrete processes, roles and documentation.

Our AI governance brings both worlds into one approach: we inventory your AI use cases, classify them by risk level, run a data-protection impact assessment and an AI-Act-oriented evaluation for the relevant cases, check data quality, bias risks and transparency, and define the human oversight. For language models, RAG and agent setups, our AI security review adds the specific technical risks. The result is governance that holds up before authorities, the board and supervisors.

Why SIDD for health insurers and payers

For payers, law and governance drive the risk, from separating insurance lines to oversight of AI decisions. That is exactly where our focus lies.

Legally led

Your mandate is led by doctorate-level lawyers with CIPP/E, backed by an in-house technical team. So we assess data flows between mandatory and supplementary insurance, purpose limitations, data processing and impact assessments on solid legal and technical ground.

AI governance depth

With three dedicated AI services (AI Officer, AI Governance Check, AI Security) we cover the EU AI Act for claims adjudication, underwriting and fraud detection, including the data-protection impact assessment and human oversight. A field that purely technical or purely legal providers rarely serve together.

Swiss professional secrecy

Where a SIDD lawyer advises in a legal capacity, your information may be covered by professional secrecy under Art. 321 of the Swiss Criminal Code, in addition to contractual confidentiality. We clarify the exact scope per mandate.

DPO and vCISO as a function

We provide the data-protection adviser under the revised Data Protection Act, the data protection officer under Article 37 GDPR where there is an EU nexus, and on request a vCISO, as external functions without a new hire, closely interlocked with your internal data-protection and security leads.

Audit-ready evidence

We maintain records of processing, impact assessments, the AI inventory and measures in our Swiss Priverion Platform. For a Commissioner request or in the board, the evidence is available as maintained tooling.

Multilingual & independent

We advise in German, French and English, relevant for French-speaking Switzerland and EU parent companies or reinsurers. Because we do not sell an in-house SOC, our recommendations stay independent and risk-oriented, not geared to selling a platform.

Payer data and AI governance, packages

AI Governance Check

from CHF 3'900

Where AI is in use in claims adjudication, underwriting or fraud detection: the focused governance review of one AI use case under the EU AI Act, with a data-protection impact assessment.

  • Risk classification of the use case and derivation of obligations
  • Data-protection impact assessment and review of human oversight
  • Assessment of data quality, bias risks and transparency towards insured persons
  • Concrete recommendations and documentation for supervisors and the board

AI Officer

from CHF 500/month

Ongoing AI governance as an external function: your named contact keeps the AI inventory, risk classification and impact assessments current while the legal situation keeps evolving.

  • A named contact for your organisation's AI governance
  • Ongoing upkeep of AI inventory, risk classification and documentation
  • Support for new AI initiatives in claims, underwriting and fraud detection
  • Monitoring of the evolving EU AI Act deadlines case by case

External Data-Protection Adviser & DPO

on request

The ongoing data-protection function: data-protection adviser under the revised Data Protection Act and, where there is an EU nexus, data protection officer under Article 37 GDPR, as an external function alongside your internal leads.

  • A named contact for data-protection questions across all lines
  • Ongoing upkeep of record, impact assessments and data processing
  • Support with access requests and the rights of insured persons
  • Escalation path and first response in a data-protection incident

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For your data-protection and AI governance, concretely: LexCommand sets the parallel duties from the Swiss health-insurance, insurance-contract and revised data-protection laws and the EU AI Act side by side, so separation and purpose limitation between mandatory and supplementary insurance surface together, and drafts the record and impact assessment with a citation to the exact norm.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions from health insurers

Is our AI in claims review really high-risk under the EU AI Act?

Often yes, but not across the board. Systems that help decide on access to insurance benefits or the pricing of individuals typically fall into the high-risk category within the scope of the EU AI Act. The high-risk deadlines apply from 2026/2027 but are under revision through the Digital Omnibus and must be checked case by case, as must whether you have an EU nexus at all. This is exactly the classification we carry out in the AI Governance Check.

May we use data from mandatory insurance in the supplementary business?

Not unfiltered. Data collected for claims handling under the Health Insurance Act is subject to purpose limitation and must not simply flow into the supplementary business or into underwriting. We review this separation legally, document the permitted purposes and bring your data flows into an audit-ready form. We clarify the specific case per mandate.

Can you provide our external data-protection adviser or DPO?

Yes. We take on the data-protection adviser under the revised Data Protection Act and, if you have an establishment or processing with an EU nexus, the data protection officer under Article 37 GDPR, as an external function without a new hire. On request we add a vCISO for information security. We work closely with your internal data-protection and security leads.

Are you a managed-SOC provider?

No. We are a legally led governance, compliance, assessment and readiness partner. We do not run our own 24/7 monitoring; where technical monitoring is needed, we coordinate it with specialised providers. This keeps our advice independent and risk-oriented.

How does a mandate start?

With the fixed-fee Payer Data and AI Governance Assessment: a gap analysis of your data flows and AI use cases across mandatory and supplementary insurance, with prioritised measures and a board-ready report. You then decide on an ongoing mandate with an AI Officer, data-protection adviser or vCISO.

Ready for a legally led payer baseline assessment?

We assess your data flows and AI use cases across mandatory and supplementary insurance, with a board-ready report and prioritised measures.