Switzerland's new Federal Act on Data Protection (nDSG) has reshaped what "compliant" means for any organization processing patient information. For healthcare providers evaluating cloud-based clinical tools — from scheduling platforms to ambient voice documentation — the question is no longer whether data is encrypted, but where it physically lives and who can access it.
What the Revised nDSG Actually Requires
The nDSG extends far beyond its predecessor, introducing stricter definitions of sensitive personal data that explicitly capture health information, and imposing accountability obligations similar in spirit to the EU's GDPR. For clinical software vendors, this means data processing agreements must specify exact storage locations, retention periods, and cross-border transfer safeguards. Crucially, the law treats any transfer of health data outside Switzerland — even to jurisdictions with "adequate" protection status — as a decision requiring explicit justification and documentation. Healthcare organizations can no longer treat cloud infrastructure as an implementation detail; it is now a compliance decision.
Public Cloud vs. Sovereign Infrastructure
Most mainstream **public cloud providers** operate global data center networks, and by default, workloads can be replicated or processed across regions for redundancy and performance. While these providers offer Swiss-region hosting options, the underlying account infrastructure, support access, and backup systems frequently retain ties to parent organizations outside Switzerland. This creates ambiguity precisely where the nDSG demands clarity. **Swiss-sovereign cloud hosting**, by contrast, guarantees that data, backups, and administrative access remain within Swiss jurisdiction end-to-end, operated under Swiss law by Swiss-based entities. For clinical documentation — arguably the most sensitive category of personal data an organization can hold — this distinction is not academic. It determines whether an organization can confidently answer a regulator's or patient's question about exactly where their health record sits.
HIN Identity Mapping and Zero-Local Persistence
Beyond storage location, compliant systems must also solve the identity and access problem. **Health Info Net (HIN)** provides Switzerland's established secure identity and communication backbone for healthcare professionals, and mapping application access to HIN credentials ensures that only verified clinical staff can retrieve patient records — a critical safeguard against credential sharing and unauthorized access common in less rigorous systems. Equally important is **zero-local-data persistence**: ambient voice and mobile clinical tools should process audio and transcripts in transit and discard them immediately after structured data is extracted, rather than storing recordings on the caregiver's device where they could be lost, stolen, or improperly backed up to a personal cloud account.
A genuinely compliant clinical data architecture rests on three pillars:
- Data storage and processing confined entirely to Swiss-sovereign infrastructure, with no default cross-border replication.
- Identity verification integrated with HIN mappings so access is tied to a verified clinical professional, not a shared login.
- Zero-local persistence on caregiver devices, ensuring transcripts and audio are never retained beyond the moment structured data is extracted.
As Swiss healthcare organizations digitize more of their clinical workflow, the choice between public and sovereign cloud infrastructure has become a defining compliance decision rather than a background technical preference. Providers that can demonstrate all three pillars — Swiss data residency, HIN-mapped identity, and zero local persistence — give healthcare organizations a defensible answer when regulators or patients ask the only question that matters: where does the data actually go?
LLM site index · Full site content