SOC for healthcare: patient data, EPR and operational safety
Hospitals, clinics and practices lose more than data during an incident; they lose the ability to treat patients. A SOC for Swiss healthcare monitors clinical IT (HIS, RIS, PACS), administrative IT and medical device networks together. It reports incidents promptly to the FDPIC and, for critical infrastructures, to the National Cyber Security Centre (NCSC). The core risk is loss of patient care. See [SOC as a Service Switzerland](/en/soc/soc-as-a-service-switzerland) for details of the framework and operating model.
Scope: SOC vs medical device approval vs EPR certification
This page covers ongoing detection and response. Medical device approval (Swissmedic, MDR) and EPR certification under EPDG are upstream requirements for products and communities. These requirements remain separate from the SOC, which uses their outputs (inventories, responsibilities, contacts) for monitoring. Standard IT security products fall short in a clinical environment. Clinical operations cannot tolerate an active agent on an MRI or a block on an operating theatre workstation.
Approval says what a device may do. The SOC sees what happens and what has to be reported.
What needs monitoring in a hospital
- Clinical core systems: HIS, RIS, PACS, laboratory information systems, medication systems.
- Medical device networks: imaging, monitoring, infusion, operating theatre technology, often on long-lived Windows or Linux systems.
- Administrative and communication infrastructure: email, portals, HR, finance and procurement systems.
- Identity and access layer: physicians, nursing, referring doctors, external service providers with temporary access.
- EPR connections to reference communities and the associated certificate and signing processes.
Swiss healthcare regulation
- revFADP (revised Federal Act on Data Protection): health data is sensitive personal data. Organisations must notify the FDPIC as soon as possible following a high-risk incident and inform affected people. See revFADP and SOC.
- ISG: healthcare entities classified as critical infrastructure report cyber incidents to the National Cyber Security Centre (NCSC) within 24 hours. Loss of patient care is the classic trigger. See SOC and ISG reporting.
- EPDG: reference and derived communities have certification obligations. The responsible bodies communicate incidents affecting the EPR, and the SOC incorporates these incidents into its response.
- Professional secrecy (SCC Art. 321): unauthorised data disclosure has criminal law implications, independently of data protection law.
- Supervisors and auditors increasingly expect ISO 27001 and industry standards (including eHealth Suisse recommendations) as a baseline. See ISO 27001 and SOC.
Effective detection and response in clinical operations
- Ransomware focus with fallback: use EDR, network segmentation and rapid isolation to keep the emergency department operational. Develop a backup and recovery strategy specifically for clinical systems. See Ransomware backup strategy.
- Passive monitoring for medical devices: NDR reads traffic from SPAN/TAP without an agent on certified devices. See NDR.
- Identity monitoring for physicians and external referrers: MFA, session anomalies, token theft. See Token theft and session hijacking.
- Codify reporting duties in playbooks: revFADP (revised Federal Act on Data Protection) to the FDPIC, ISG to the NCSC within 24 hours, EPDG channels. Record deadlines and escalation points in the incident response plan.
- Supply-chain view: many healthcare incidents originate through software vendors and remote maintenance. Monitor the attack surface and vendors. See Supply-chain attacks and Attack Surface Management.
The surgical robot, the MRI and the insulin pump are rarely the primary target. Attackers land via phishing, VPN remote maintenance or a compromised service provider inside the HIS and encrypt file shares. The clinical consequence is the same: treatments stop. That is why the SOC has to see the path there, not only the end target.
Legal basis and sources
- ISG (SR 128), Art. 74a-74f: Fedlex
- Cybersecurity Ordinance (CSV, SR 128.51): Fedlex
- ISG reporting duty at the National Cyber Security Centre (NCSC) including routing: bacs.admin.ch
- Reporting data security breaches to the FDPIC: edoeb.admin.ch
Frequently asked questions
May a SOC agent be installed on medical devices?
A SOC agent requires manufacturer approval for the specific configuration. We generally use passive monitoring (NDR) and monitor the upstream and downstream IT. We take active measures outside the certified devices.
How fast does a hospital incident have to be reported?
Critical infrastructure operators must report incidents to the National Cyber Security Centre (NCSC) within 24 hours under ISG. Under revFADP (revised Federal Act on Data Protection), organisations must notify the FDPIC as soon as possible once they anticipate a high risk to affected people. They must submit both notifications in parallel and document them clearly.
How does the SOC handle external referrers and practices?
The SOC uses identity federation and Conditional Access; all external access runs through monitored brokers with MFA. The SIEM correlates session anomalies and OAuth grants.
How does the SOC fit into the EPR landscape?
The communities bring their own reporting channels and certificate processes. The SOC monitors the technical connectors, signing flows and access from its own organisation and alerts community bodies as agreed.
What does a SOC typically cost for a Swiss hospital?
Costs depend on site count, endpoint numbers and OT share. See [SOC cost Switzerland](/en/soc/soc-cost-switzerland) for ranges and models.
Related terms
- GDPR The EU's General Data Protection Regulation governs how organisations process the personal data of individuals inside the EU.
- revFADP The revFADP is the revised Swiss Federal Act on Data Protection, which governs personal data processing.
- Ransomware Ransomware is malicious software that encrypts data and demands a ransom for decryption.
- SOCaaS SOC as a Service (SOCaaS) is a SOC operated by an external provider and delivered as an ongoing service.
- ISO 27001 ISO 27001 is the international standard for information security management systems. Certification confirms that risks are managed systematically.