ISO 27001 / ISMS in Healthcare, certification-ready and legally led
A certification-ready information-security management system for health networks, EPR communities, labs, pharmacies and MedTech, built along your healthcare data flows and bundled with an outsourced data-protection function and AI governance. We advise and lead the mandate juristically; you are certified by an accredited certification body.
certification-ready (gap → certification body)bundled: ISMS + DPO + AI governanceA vCISO keeps the ISMS alive
For health networks, EPR communities, labs, pharmacies and MedTech
ISO 27001
certification-ready ISMS
Legally led
Dr. iur. · CIPP/E
vCISO
ISMS stays alive
Supplier controls
A.5.19–A.5.23
CH · EU
multilingual DE/FR/EN
Responsible for this mandate
Philipp Staiger
M.Sc., MIT Sloan Fellow · Lead Auditor ISO 27001 (BSI)
Leads ISO 27001 and ISMS projects in healthcare from the scope workshop to stage-2 audit support, the interface to management, IT, data protection and the external certification body.
Why an ISMS in healthcare is more than a certificate
Health data is among the most sensitive personal data there is. Anyone processing it needs a system that makes security demonstrable and repeatable, not just a collection of one-off measures.
ISO 27001 is a management system: it embeds responsibilities, risk assessment, controls and continual improvement into the organisation. In healthcare this is more than good practice. Tenders from hospitals, insurers and cantons increasingly require it, and contractual partners expect demonstrable security across the entire supply chain.
An ISMS tailored to your healthcare data flows also bridges to your legal duties: it delivers the technical and organisational measures the revised FADP requires, and the audit-ready evidence that regulators and auditors want to see.
Important: we advise you and lead the build. The certification itself is issued by an accredited certification body. This separation is part of the system and strengthens the credibility of your certificate.
The road to ISO 27001, in clear stages
1 · Gap analysis & scope
We define the scope along your healthcare data flows, assess the current state against ISO 27001 and Annex A, and prioritise the gaps with a board-ready report.
2 · Risk assessment & SoA
We produce the risk assessment, the risk-treatment plan and the Statement of Applicability, aligned to clinical and administrative operations.
3 · Controls & documentation
We design policies, processes and the Annex A controls, including the supplier controls A.5.19–A.5.23, as one consistent documentation that also carries your data protection.
4 · Implementation & effectiveness
We support rolling out the controls, train the responsible staff and let the ISMS run an operating cycle so evidence of effectiveness accumulates.
5 · Internal audit & management review
We run the internal audit, prepare the management review and close open items before the certification body arrives.
6 · Certification by an accredited body
An independent, accredited certification body audits the ISMS (stage 1 and 2) and issues the certificate. We accompany you through the audit. You are certified, not us.
Why ISO 27001 with us, bundled, not isolated
Security, data protection and AI governance share the same risks and the same evidence. Leading them together avoids duplicated work and contradictions between systems.
ISMS + outsourced data protection
We bundle your ISMS with the external data-protection adviser role under the revised FADP and, where needed, the external data-protection officer under Art. 37 GDPR. One function leads security and data protection, legally anchored.
One consistent documentation
Policies, risk assessment, records of processing and controls live in one maintained system instead of separate folders. That makes audits and regulator requests faster and free of contradictions.
A vCISO keeps the ISMS alive
A certificate is not an endpoint: ISO 27001 requires ongoing operation, internal audits and surveillance audits. Our vCISO carries the management cycle forward so your ISMS stays effective between audits, rather than decaying into a paper exercise.
Supplier controls A.5.19–A.5.23
The Annex A supplier-security controls (A.5.19 to A.5.23) cover many of the supply-chain expectations that also arise under NIS2 for entities with an EU footprint. We design them so your ISMS and your contractual supplier duties fit together.
AI governance integrated
Where you use medical or administrative AI, we connect AI governance to your ISMS, from the AI Governance Check to ISO 42001. The result is a management system that steers security, data protection and AI together.
Backed by technical work
Our technical team backs the controls with penetration tests and vulnerability scans, so documented measures become verified effectiveness. Standalone tests run on demand, while the ISMS stays the leading system.
Clear roles: we advise, an accredited body certifies
A consultancy cannot, and should not, certify an ISMS itself. This independence is built into the system.
Accreditation bodies accredit certification bodies, not consultancies. SIDD builds and leads your ISMS to certification readiness; the certification itself you arrange with an independent, accredited certification body. We accompany you through the audits but never act as the issuer of the certificate.
This separation is not a drawback but the core of a credible certificate: whoever builds and whoever audits must not be the same party. That is precisely why our role stays that of an independent, legally led adviser.
We lead the full build from risk assessment to a passed internal audit, ready for the accredited certification body.
Risk assessment, risk-treatment plan and Statement of Applicability
Policies, processes and controls as one consistent documentation
Internal audit and preparation of the management review
Support through the certification body's stage 1 and stage 2 audit
vCISO, ISMS operation
Fixed fee on request
Ongoing operation of the ISMS between audits: management cycle, internal audits and surveillance audits, so the certificate holds.
Continuous management cycle and documentation upkeep
Preparation and support of the annual surveillance audits
Interlock with data protection, AI governance and technical testing
LexCMD
Our tool: LexCommand
Why we work with LexCommand, our own Swiss legal AI
LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.
01
Sovereign in Switzerland
The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.
02
No citation, no claim
Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.
03
From effort to judgement
LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.
04
Three disciplines, one picture
We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.
For your ISMS, concretely: LexCommand drafts the Statement of Applicability and the Annex A policies as sourced Word drafts with citations in the footnotes, and maps the supplier controls A.5.19 to A.5.23 against your revised FADP and NIS2 duties, so overlapping requirements surface in one documentation.
Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.
Frequently asked questions
Does SIDD issue the ISO 27001 certificate?
No. We advise and lead the build to certification readiness. The certificate is issued by an independent, accredited certification body. This separation of advice and certification is part of a credible ISMS.
Can you lead the ISMS and data protection together?
Yes, that is our preferred approach. We bundle the ISMS with the external data-protection adviser role under the revised FADP and, where needed, the external data-protection officer under Art. 37 GDPR, in one consistent documentation.
Does ISO 27001 cover the NIS2 supply-chain requirements?
The Annex A supplier-security controls A.5.19 to A.5.23 cover many of the expectations that arise under NIS2 for entities with an EU footprint. NIS2 is an EU directive Switzerland has not transposed; it binds only entities with an EU establishment or EU operations. We verify your scope case by case.
What happens after certification?
ISO 27001 requires ongoing operation with internal audits and annual surveillance audits. Our vCISO carries the management cycle forward so the ISMS stays effective and the certificate holds.
Do you work in French for French-speaking Switzerland?
Yes. We run the ISMS mandate throughout in German, French and English, including documentation and audit support for multilingual networks and EU parent companies.
Ready for a certification-ready ISMS?
We start with the ISO 27001 readiness gap assessment, fixed scope, fixed timeline, a board-ready report and a clear path to the accredited certification body.