Vertical

SOC for healthcare: patient data, EPR and operational safety

Hospitals, clinics and practices lose more than data during an incident; they lose the ability to treat patients. A SOC for Swiss healthcare monitors clinical IT (HIS, RIS, PACS), administrative IT and medical device networks together. It reports incidents promptly to the FDPIC and, for critical infrastructures, to the National Cyber Security Centre (NCSC). The core risk is loss of patient care. See [SOC as a Service Switzerland](/en/soc/soc-as-a-service-switzerland) for details of the framework and operating model.

All

Scope: SOC vs medical device approval vs EPR certification

This page covers ongoing detection and response. Medical device approval (Swissmedic, MDR) and EPR certification under EPDG are upstream requirements for products and communities. These requirements remain separate from the SOC, which uses their outputs (inventories, responsibilities, contacts) for monitoring. Standard IT security products fall short in a clinical environment. Clinical operations cannot tolerate an active agent on an MRI or a block on an operating theatre workstation.

Short version

Approval says what a device may do. The SOC sees what happens and what has to be reported.

What needs monitoring in a hospital

  • Clinical core systems: HIS, RIS, PACS, laboratory information systems, medication systems.
  • Medical device networks: imaging, monitoring, infusion, operating theatre technology, often on long-lived Windows or Linux systems.
  • Administrative and communication infrastructure: email, portals, HR, finance and procurement systems.
  • Identity and access layer: physicians, nursing, referring doctors, external service providers with temporary access.
  • EPR connections to reference communities and the associated certificate and signing processes.

Swiss healthcare regulation

  • revFADP (revised Federal Act on Data Protection): health data is sensitive personal data. Organisations must notify the FDPIC as soon as possible following a high-risk incident and inform affected people. See revFADP and SOC.
  • ISG: healthcare entities classified as critical infrastructure report cyber incidents to the National Cyber Security Centre (NCSC) within 24 hours. Loss of patient care is the classic trigger. See SOC and ISG reporting.
  • EPDG: reference and derived communities have certification obligations. The responsible bodies communicate incidents affecting the EPR, and the SOC incorporates these incidents into its response.
  • Professional secrecy (SCC Art. 321): unauthorised data disclosure has criminal law implications, independently of data protection law.
  • Supervisors and auditors increasingly expect ISO 27001 and industry standards (including eHealth Suisse recommendations) as a baseline. See ISO 27001 and SOC.

Effective detection and response in clinical operations

  1. Ransomware focus with fallback: use EDR, network segmentation and rapid isolation to keep the emergency department operational. Develop a backup and recovery strategy specifically for clinical systems. See Ransomware backup strategy.
  2. Passive monitoring for medical devices: NDR reads traffic from SPAN/TAP without an agent on certified devices. See NDR.
  3. Identity monitoring for physicians and external referrers: MFA, session anomalies, token theft. See Token theft and session hijacking.
  4. Codify reporting duties in playbooks: revFADP (revised Federal Act on Data Protection) to the FDPIC, ISG to the NCSC within 24 hours, EPDG channels. Record deadlines and escalation points in the incident response plan.
  5. Supply-chain view: many healthcare incidents originate through software vendors and remote maintenance. Monitor the attack surface and vendors. See Supply-chain attacks and Attack Surface Management.
What clinics often underestimate

The surgical robot, the MRI and the insulin pump are rarely the primary target. Attackers land via phishing, VPN remote maintenance or a compromised service provider inside the HIS and encrypt file shares. The clinical consequence is the same: treatments stop. That is why the SOC has to see the path there, not only the end target.

Legal basis and sources

  • ISG (SR 128), Art. 74a-74f: Fedlex
  • Cybersecurity Ordinance (CSV, SR 128.51): Fedlex
  • ISG reporting duty at the National Cyber Security Centre (NCSC) including routing: bacs.admin.ch
  • Reporting data security breaches to the FDPIC: edoeb.admin.ch

Frequently asked questions

May a SOC agent be installed on medical devices?

A SOC agent requires manufacturer approval for the specific configuration. We generally use passive monitoring (NDR) and monitor the upstream and downstream IT. We take active measures outside the certified devices.

How fast does a hospital incident have to be reported?

Critical infrastructure operators must report incidents to the National Cyber Security Centre (NCSC) within 24 hours under ISG. Under revFADP (revised Federal Act on Data Protection), organisations must notify the FDPIC as soon as possible once they anticipate a high risk to affected people. They must submit both notifications in parallel and document them clearly.

How does the SOC handle external referrers and practices?

The SOC uses identity federation and Conditional Access; all external access runs through monitored brokers with MFA. The SIEM correlates session anomalies and OAuth grants.

How does the SOC fit into the EPR landscape?

The communities bring their own reporting channels and certificate processes. The SOC monitors the technical connectors, signing flows and access from its own organisation and alerts community bodies as agreed.

What does a SOC typically cost for a Swiss hospital?

Costs depend on site count, endpoint numbers and OT share. See [SOC cost Switzerland](/en/soc/soc-cost-switzerland) for ranges and models.

Continue reading in this cluster
SOC as a Service in Switzerland: The Complete Guide
SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.
Ransomware backup strategy: immutable, tested, recoverable
Backups are the last reliable lifeline against ransomware. They must be immutable, tested regularly and segregated from the production network. Cyber insurers list 'segregated backups' among the five core controls; missing evidence in a claim eliminates cover. A ransomware recovery layer such as [Halcyon Anti-Ransomware](/en/services/halcyon-anti-ransomware) complements backups. It addresses the encryption attempt itself and shortens recovery time.
SOC & ISG: The 24-hour cyber-incident reporting duty in Switzerland
Since 1 April 2025, the Swiss Information Security Act (ISG, SR 128, Art. 74a-74f) imposes a cyberattack reporting duty on critical infrastructure operators. Operators must report cyberattacks to the National Cyber Security Centre (NCSC) within 24 hours of detection. Operators need 24/7 detection and documented response processes to meet this deadline reliably. A SOC delivers these two building blocks.
ITDR: Identity Threat Detection and Response for Switzerland
ITDR (Identity Threat Detection and Response) detects attacks on the identity itself, not just endpoints or networks. Targets are accounts, tokens, sessions, permissions and identity providers such as Entra ID or Okta. ITDR extends EDR and SIEM with signals only visible in the identity layer. These include impossible travel, consent phishing, refresh-token abuse, role abuse and attacks on federation and directory objects. For Swiss organisations running M365, Entra ID and regulated processes, ITDR today is as important as EDR was five years ago.
Exeon NDR Managed: network visibility without sensor sprawl
ANOMAL runs Exeon NDR as a managed service for Swiss environments. It centrally analyses network metadata from existing sources (firewalls, switch flows, proxies) without additional inline sensors. The service focuses on threats invisible to endpoints, particularly in OT, IoT and BYOD zones. The ANOMAL SOC handles detections 24/7 with clear response playbooks and Swiss data sovereignty.