HIPAA
HIPAA is a US law protecting health data that can also affect Swiss firms with US clients.
The Health Insurance Portability and Accountability Act (HIPAA) is a US law for protecting health information. It applies to healthcare providers, health insurers, and clearinghouses in the USA, as well as their service providers, including those abroad.
How it works
HIPAA contains several rules. The Privacy Rule governs who can use and share protected health information. The Security Rule requires administrative, physical, and technical safeguards for electronic health data. The Breach Notification Rule regulates the reporting of data breaches. Service providers who process health data on behalf of others must sign a Business Associate Agreement. As a Business Associate, they are also directly subject to parts of the Security Rule.
A Swiss medtech company offers software to US clinics for analysing patient data. The clinics require a Business Associate Agreement. The company must therefore meet the Security Rule's requirements. It must log access, encrypt data, and be able to report incidents.
What to look out for
- Check if you process health data from US patients on behalf of another company.
- Read Business Associate Agreements carefully, especially the reporting deadlines.
- Conduct a risk analysis as required by the Security Rule.
- Log and analyse access to protected health information.
When it is relevant for Swiss firms
HIPAA does not apply directly in Switzerland. It becomes relevant for Swiss medtech, pharma, and software firms working for US clinics, insurers or their service providers. The obligation then arises from the contract with the US customer.
Switzerland and regulation
In Switzerland, health data is governed by the revFADP (revised Federal Act on Data Protection). The revFADP classifies it as sensitive personal data, and cantonal laws may also apply. There are separate regulations for the electronic patient record. These rules exist independently of HIPAA.
Relevance for the SOC
The Security Rule requires monitoring of access and handling of security incidents. A SOC can provide the necessary detection, investigation, and evidence for this purpose.
Typical mistakes
Health data is often copied to test or support environments without the same safeguards. Another common mistake is using subcontractors without their own Business Associate Agreement.
How we implement it
We monitor systems containing health data and provide evidence for incident detection and response. Compliance with HIPAA remains your responsibility.