A US digital-health company that has finished its HIPAA analysis knows where it stands. It is a covered entity, a business associate, or neither, and for the consumer app that is neither, the Federal Trade Commission's Health Breach Notification Rule and a growing set of state statutes fill the gap. That map is drawn around who holds the data. Swiss law draws its map around what the data is. Under the DSG, Switzerland's federal data-protection statute, data about a person's health is sensitive personal data whoever processes it.1Datenschutzgesetz (DSG), SR 235.1, in force 1 September 2023; Art. 3(1) (effects in Switzerland) and Art. 5(c) (data about health as sensitive personal data). A wellness app with a few thousand Swiss users, a hospital-facing platform hosted in Virginia, and a prescription digital therapeutic newly listed for reimbursement on 1 July 2026 all inherit the same statutory category from the first Swiss user. What differs among them is not whether the DSG applies. It is which of its duties attach, in which role, alongside which other Swiss law, and who is personally exposed when one of them is missed.
1. A Category, Not a Covered Entity: How the DSG Reaches a Health App
The reach question comes first, and the DSG answers it with a formula the GDPR's vocabulary does not contain. Art. 3(1) DSG applies the statute to matters that have an effect in Switzerland, even where they are initiated abroad. Art. 3(2) GDPR asks whether a controller outside the Union offers goods or services to people in the Union or monitors their behavior. A US company that has concluded it does not target Europe in that sense has built its analysis around intent.2Regulation (EU) 2016/679 (GDPR), Art. 3(2) (targeting test), Art. 27 (representative), Art. 28 (processor), Art. 33 (notification within 72 hours). The Swiss test is built around effect. A German-language onboarding flow, a subscription priced in Swiss francs, or a hospital customer in Bern all produce effects in Switzerland without anyone having decided to target the country. The DSG's personal scope in Art. 2 DSG then asks only whether whoever processes the data is a private person or a federal body. It does not ask whether the company is large, whether it has an establishment in Switzerland, or whether health data is its business.
The category does the rest of the work. Art. 5(c) DSG lists data about health among the categories of sensitive personal data, next to genetic data and biometric data that uniquely identify a person, and it attaches the label to the data rather than to the entity holding them. That is the structural inversion of the HIPAA model. Under 45 C.F.R. Parts 160 and 164, protected health information is defined by its passage through a covered entity or a business associate. The same blood-pressure reading in a consumer app is not protected health information at all, which is why the FTC's rule, amended with effect from 29 July 2024, and Washington's My Health My Data Act, in force since 31 March 2024, exist to cover what HIPAA leaves out.345 C.F.R. Parts 160 and 164 (HIPAA rules); 16 C.F.R. Part 318 (FTC Health Breach Notification Rule, as amended effective 29 July 2024); Wash. Rev. Code ch. 19.373 (My Health My Data Act). The DSG has no sector to leave out. A step count, a mood diary, a medication reminder and a hospital's discharge summary are sensitive personal data on the same footing, and the consequences follow the label. Where consent is the ground relied on, Art. 6(7)(a) DSG requires that it be express. Disclosing sensitive data to a third party is, under Art. 30(2)(c) DSG, a violation of personality that needs a justification under Art. 31 DSG. And extensive processing of sensitive data is, by the terms of Art. 22(2)(a) DSG, high-risk processing that requires a data protection impact assessment before it begins, followed by a consultation of the EDÖB, the federal data-protection authority, under Art. 23 DSG where a high residual risk remains, unless a data protection advisor appointed under Art. 10 DSG has been consulted instead.
The ordinance adds duties a US vendor rarely sees coming, because they are keyed to the same category. The DSV requires a private controller and its private processor that process sensitive personal data on a large scale to maintain a processing regulation, a Bearbeitungsreglement, covering internal organization, processing and control procedures and the security measures in place, and to keep it updated.4Datenschutzverordnung (DSV), SR 235.11; Art. 4 (logging), Art. 5 (processing regulation), Art. 7 (sub-processors), Art. 24 (record exemption unavailable for large-scale sensitive data). Where preventive measures cannot guarantee data protection, Art. 4 DSV requires logging of at least the storage, modification, disclosure, deletion and destruction of the data and of access to them, with the logs retained for at least one year, separately from the system that processed the data, and accessible only to those charged with verifying compliance or with safeguarding the data's confidentiality, integrity, availability and traceability. The record of processing activities under Art. 12 DSG, which Art. 24 DSV waives for companies with fewer than 250 employees, is not waived for them where sensitive data are processed on a large scale, so a forty-person digital-therapeutics company does not have the small-company exemption its headcount suggests. None of these duties is triggered by being a covered entity, a device manufacturer or a Swiss company. They are triggered by the data.
Reach and category together produce a further obligation that has no counterpart in the US framework and a misleading counterpart in the European one. Art. 14 DSG requires a private controller with its seat abroad to designate a representative in Switzerland where it processes data of persons in Switzerland in connection with offering goods or services or observing their behavior, and the processing is extensive, regular, and carries a high risk to the personality of the data subjects. The four conditions are cumulative.5EDÖB, guidance on the duty to designate a representative under Art. 14 DSG: four cumulative conditions; high risk assessed as gross risk, with sensitive personal data among the factors. The EDÖB's published reading assesses the high-risk condition as a gross risk across all existing and planned processing, before mitigating measures are counted, and names sensitive personal data among the factors that establish it. A consumer health application with a regular Swiss user base therefore tends to satisfy the fourth condition by its subject matter and the first three by its business model, on the day it has enough Swiss users to be called extensive, a threshold to which neither the statute nor the guidance attaches a number. The representative keeps the record of processing activities under Art. 15 DSG, answers the EDÖB, and tells data subjects how to exercise their rights. Its name and address must be published. A company that appointed a representative in the Union under Art. 27 GDPR has not appointed a Swiss one. The two are different offices under different statutes, and the EDÖB can order the appointment by decision under Art. 51(4) DSG.
The DSG attaches to the data category, not to the entity holding it, so a health app that HIPAA never reaches is sensitive-data processing under Swiss law from its first Swiss user.
The practical effect of the inversion is that a US vendor's compliance inventory is usually organized in the wrong order. HIPAA compliance is a question of contracts and roles. GDPR compliance is a question of legal bases and records. The DSG asks, before either, what the data are, and then follows that answer into duties the vendor may have assigned, in its own documentation, to a customer, to a downstream processor, or to nobody.
2. Processor, Controller, or Auxiliary: The Role Question a Hospital Contract Does Not Settle
The same platform is a controller, a Verantwortlicher under Art. 5(j) DSG, when it sells to consumers and a processor, an Auftragsbearbeiter under Art. 5(k) DSG, when it hosts a hospital's patient data. A US vendor that has drafted one data processing addendum on the Art. 28 GDPR model will find the Swiss processor provision shorter and, in one respect, sharper. Art. 9(1) DSG permits processing to be entrusted to a processor only where the data are processed as the controller itself would be permitted to process them and where no statutory or contractual duty of confidentiality prohibits the transfer. Art. 9(2) DSG requires the controller to satisfy itself that the processor can guarantee data security. Art. 9(3) DSG permits the processor to pass processing to a third party only with the controller's prior approval, which Art. 7 DSV allows to be general, provided the processor gives notice of every intended change in its sub-processors and the controller may object. There is no catalog of mandatory contract terms of the kind Art. 28(3) GDPR sets out, which US counsel tend to read as a lighter regime. The reading is incomplete. The confidentiality bar in Art. 9(1)(b) DSG is a statutory precondition rather than a contract term. Art. 61(b) DSG makes it a criminal offense, punishable by a fine of up to CHF 250,000 on complaint, for a private person intentionally to hand processing to a processor without the conditions of Art. 9(1) and (2) DSG being met. That exposure sits with the hospital, which is why a Swiss hospital's procurement questionnaire asks a US SaaS vendor questions that a HIPAA business associate agreement never anticipated.
The duty of confidentiality that matters is criminal, not contractual. Art. 321 StGB makes it an offense for physicians, pharmacists, psychologists, nurses, physiotherapists and the other listed professions, and for their auxiliary persons, to disclose a secret entrusted to them in the exercise of their profession, punishable by imprisonment of up to three years or a monetary penalty, unless the person entitled has consented or the supervisory authority has authorized the disclosure in writing.6Strafgesetzbuch (StGB), SR 311.0, Art. 321 (professional secrecy of health professions and their auxiliary persons); privatim plenary of 17 May 2017 on outsourcing and the auxiliary-person question. Whether a cloud or SaaS provider can be an auxiliary person, a Hilfsperson, of the hospital is the question on which the lawfulness of the entire outsourcing turns, and no published decision of the Federal Supreme Court has answered it. Prevailing practice treats a provider bound by contract and instruction as an auxiliary person. The conference of Swiss data-protection commissioners, privatim, has rejected the view that every outsourcing contractor qualifies and in 2017 saw only two lawful routes, the patient's prior express consent or an encryption that leaves the provider no access to the data. Art. 62 DSG then adds a second, parallel offense. Anyone who intentionally discloses secret personal data learned in the exercise of a profession that requires knowledge of such data, or while working for a person bound by such a duty, faces a fine of up to CHF 250,000. Whether a vendor's own engineers with production access fall within that provision is not a question its US counsel has ever had to ask, and Swiss law has not answered it cleanly for them.
The fork widens when the customer is a public hospital. Art. 2 DSG confines the federal statute to private persons and federal bodies. A university hospital in Basel or Zurich is a cantonal public body, and its data processing answers to cantonal law. In Basel-Stadt that law is the Gesetz über die Information und den Datenschutz of 9 June 2010, in Zurich the Gesetz über die Information und den Datenschutz of 12 February 2007, each supervised by a cantonal data-protection commissioner rather than by the EDÖB.7IDG Basel-Stadt (SG 153.260) and IDG Zürich (LS 170.4); privatim, resolution on outsourcing data processing to the cloud (18 November 2025). Healthcare is cantonal in Switzerland. The twenty-six cantons retain primary jurisdiction over hospitals, and the closest US analogue, a state-by-state patchwork, understates the autonomy. On 18 November 2025 privatim adopted a resolution on outsourcing to the cloud that treats international SaaS providers as unsuitable for sensitive or secrecy-protected data unless the public body itself encrypts the data and the provider has no access to the key. The resolution cites the absence of true end-to-end encryption in most SaaS products, the limits of what a Swiss authority can verify about a global provider's staff and measures, and the reach of the US CLOUD Act into data held in Swiss data centers. It binds nobody by itself. It describes the posture the supervisors of Switzerland's largest hospitals bring to a US vendor's security annex, and a private hospital group across the street is, on the prevailing view, a private person under the DSG and subject to none of it. One master services agreement, presented to two Swiss hospitals, can be governed by two different statutes, two different regulators and two different views of whether the vendor may exist in the data flow at all.
3. Prescribed, Reimbursed, Self-Administered: The July 2026 Listing and the Duties It Pulls In
Switzerland has no equivalent of Germany's DiGA fast track, and a US developer that has read the German pathway as the European template, a reading examined in Insight 50, will look for a Swiss listing procedure that does not exist. Reimbursement by the mandatory health insurance, the OKP, runs through the general architecture of the KVG. A service must be effective, appropriate and economical under Art. 32 KVG, and aids and devices applied by the patient are reimbursed only if listed in the Mittel- und Gegenständeliste, the MiGeL, which the EDI issues under Art. 52(1)(a)(3) KVG as Annex 2 to the KLV, on prescription by a physician under Art. 20 KLV and up to a maximum reimbursement amount under Art. 24 KLV.8KVG, SR 832.10, Art. 32, 42(3)-(3bis), 52(1)(a)(3); KLV, SR 832.112.31, Art. 20, 20a, 24 and Annex 2 (MiGeL); BAG media release of 4 December 2025 on reimbursement of digital therapy applications from 1 July 2026. On 4 December 2025 the BAG announced the first use of that route for software. With effect from 1 July 2026 the OKP reimburses a digital application delivering cognitive behavioral therapy for mild to moderate depressive episodes and recurrent depressive disorders, prescribed by a physician holding the specialist qualification the listing names, as a supplement to psychotherapy or as a bridge until it begins. The position was written around a single application already established in the German DiGA register, but the list names no product. The entry is generic, under evaluation until 31 December 2026, and the prescribing physician must name the product on the prescription. What the announcement created is a market. What it did not create is a data regime, and the one that applies was not designed with a self-administered therapy in mind.
The listing pulls in three layers that the developer's US model keeps apart. The first is product regulation. A therapeutic application is a medical device, and a manufacturer without a seat in Switzerland may place it on the market only through an authorized representative in Switzerland under Art. 51 MepV, an appointment whose liability profile Insights 05 and 07 examine.9Medizinprodukteverordnung (MepV), SR 812.213, Art. 51 (authorized representative for manufacturers without a seat in Switzerland). The second is the billing chain. Under Art. 42(3) and (3bis) KVG the provider must give the debtor a detailed invoice with the information needed to verify the calculation and the economic efficiency of the service, coded diagnoses and procedures included, and under the tiers payant system that debtor is the insurer. A reimbursed therapeutic therefore sits inside a flow in which a prescribing physician, a dispensing point, an insurer with its own statutory basis for processing, and the vendor each hold a fragment of the same episode of care. The vendor, whose application the physician does not enter, holds the only complete record of the therapy itself. The third layer is the DSG's treatment of what the application does with that record. A program that evaluates a user's responses to adapt the next session is evaluating aspects of that person's health, which is profiling within Art. 5(f) DSG. Whether it is profiling with high risk under Art. 5(g) DSG, permitting an assessment of essential aspects of the personality, is a question the definition invites and the vendor's documentation must answer, because Art. 6(7)(b) DSG requires express consent for high-risk profiling by a private person wherever consent is the ground relied on. A program that escalates, restricts or discharges a user on the strength of an automated assessment may be taking an automated individual decision within Art. 21 DSG, with the notice and human-review rights that follow, unless the decision is taken in direct connection with a contract with the user and grants the user's own request, or the user has expressly consented to its being automated. The impact assessment under Art. 22 DSG is owed before processing begins. For a product listed on 1 July 2026, the question is whether it exists, and whether it describes the reimbursed configuration rather than the consumer one.
Two further features of Swiss law press on the design. Art. 25(3) DSG allows health data to be communicated to the data subject, with the data subject's consent, through a health professional the data subject designates, a mechanism drafted for a physician's file that a self-administered application has to reproduce without a physician in the loop. Art. 28 DSG gives a right to receive the data one has disclosed to the controller in a common electronic format, or to have them transferred to another controller where that needs no disproportionate effort, where processing is automated and rests on consent or on a contract with the data subject, which describes the consumer subscription exactly. Beyond the statute sits the national infrastructure. On 5 November 2025 the Federal Council submitted to Parliament the Bundesgesetz über das elektronische Gesundheitsdossier, the EGDG, which would replace the electronic patient record established under the EPDG with an opt-out dossier for every resident, operated by the Confederation with the data stored in Switzerland, that every provider billing the OKP must connect to and populate with treatment-relevant data.10EPDG, SR 816.1; Federal Council message of 5 November 2025 on the EGDG (opt-out dossier, mandatory participation of providers billing the OKP, earliest operation around 2030). The National Council's health committee voted to enter into the bill in February 2026 and began its detailed deliberation in April. The Federal Council's own estimate places the earliest operation around 2030. Whether a reimbursed digital therapeutic is a provider that must feed the dossier, whether its outputs are treatment-relevant data the prescribing physician must document, and how a vendor's US-hosted record meets a statutory requirement that dossier data remain in Switzerland are questions the message does not address, because its definitions were written around professions and institutions rather than software. A product architecture chosen in 2026 will meet that infrastructure with whatever answers the 2026 architecture happened to embed.
4. A Clock Without a Number and a Fine With a Name: Transfers, Breaches and Personal Exposure
Every path in the preceding sections ends at a server, and for most US vendors that server is in the United States. Art. 16(1) DSG permits disclosure abroad where the Federal Council has found the destination's legislation adequate, and the list in Annex 1 to the DSV names the United States only for organizations certified under the Swiss-US Data Privacy Framework, with effect from 15 September 2024.11Annex 1 DSV, entry for the United States (organizations certified under the Swiss-US Data Privacy Framework, effective 15 September 2024); EDÖB recognition of the EU standard contractual clauses (27 August 2021). For an uncertified recipient, Art. 16(2) DSG requires a treaty, contractual data-protection clauses notified in advance to the EDÖB, standard clauses the EDÖB has approved, issued or recognized, or binding corporate rules. The EDÖB's recognition, on 27 August 2021, of the European Commission's standard contractual clauses carries Swiss-specific adaptations that a US-drafted clause set often omits, and Art. 9 and 10 DSV then specify what such clauses must contain and require the exporter to take measures to ensure the importer honors them. The exceptions in Art. 17 DSG, express consent and a direct connection with a contract among them, are available but narrow, and Art. 61(a) DSG makes an intentional disclosure abroad without an adequacy finding, an Art. 16(2) DSG safeguard or an Art. 17 DSG exception a criminal offense. The Swiss framework runs on the same American architecture as the European one. The Federal Council's finding rests on Executive Order 14086 and the Data Protection Review Court, and the US Supreme Court's ruling of 29 June 2026 on the President's power to remove Federal Trade Commission members, examined in Insight 64, raises for the Swiss list the same question it raises for the EU adequacy decision. A vendor whose only transfer mechanism is its framework certification has a single point of failure on both sides of the Rhine.
The breach provision is where a US incident-response playbook fails quietly. HIPAA gives sixty days, the FTC rule gives sixty days, the GDPR gives seventy-two hours. Art. 24(1) DSG requires the controller to notify the EDÖB as quickly as possible, so rasch als möglich, of a breach that is likely to lead to a high risk to the personality or the fundamental rights of the data subject, and Art. 24(3) DSG requires the processor to notify the controller as quickly as possible, with no risk threshold at all. A clock without a number is not a clock without a deadline. It is a deadline that will be measured after the fact against what the company knew and when. Art. 15 DSV prescribes the content of the notification and requires the controller to document the breach, its effects and the measures taken and to keep that record for at least two years from the notification, while leaving open whether breaches below the notification threshold must be documented too, and Art. 24(5bis) DSG, in force since 1 April 2025, allows the EDÖB, with the controller's consent, to forward the notification to the BACS for analysis. The security floor beneath the notification duty is set by Art. 8 DSG and Art. 1 to 3 DSV, which require measures appropriate to the risk across confidentiality, availability, integrity and traceability. An intentional failure to meet the minimum requirements the Federal Council has laid down is, under Art. 61(c) DSG, itself an offense.
That criminal thread runs through the entire statute, and it is the divergence US counsel most consistently underestimate. HIPAA's civil money penalties and the FTC's orders bind the company, and the GDPR's administrative fines are levied on the undertaking. Art. 60 to 63 DSG impose fines of up to CHF 250,000 on private persons, prosecuted by the cantonal criminal authorities and, for most of the offenses, only on complaint, for intentionally providing false or incomplete information, intentionally failing to inform data subjects, unlawful disclosure abroad, unlawful engagement of a processor, failure to meet the minimum security standards, breach of professional confidentiality, and disregard of a decision of the EDÖB issued under reference to that penalty. Art. 64 DSG allows the fine to be imposed on the business instead of the individual only where the fine would not exceed CHF 50,000 and identifying the responsible person would require disproportionate investigative effort. The statute names a person, and which person is a question of who decided, not of who signed. The EDÖB itself has no power to fine. Its instruments are the investigation under Art. 49 DSG, the administrative measures under Art. 51 DSG, which the Federal Administrative Court upheld in a judgment of 6 October 2025 that confirmed the authority's practice under the revised statute, and the criminal complaint.12EDÖB, 33. Tätigkeitsbericht 2025/2026 (30 June 2026); Urteil BVGer A-2941/2024 vom 6. Oktober 2025, confirming the EDÖB's administrative measures. The authority's activity report published on 30 June 2026 records more than two thousand reports of suspected violations in the year, 156 interventions, nine formal investigations, and one criminal complaint against a private company that refused the cooperation Art. 49(3) DSG requires. For a US officer, a fine under a foreign criminal statute, imposed by name, is the kind of exposure that a standard directors' and officers' policy was rarely drafted to describe, and the disclosure question it raises in the United States does not wait for the Swiss proceeding to end.
5. Strategic Considerations
The questions that follow are not answerable from the outside, and most of them turn on facts the vendor's own records may not hold. In which of the four configurations does the application actually run in Switzerland today, and does the role the vendor assigned itself in each, controller here, processor there, survive the observation that the same production system serves all of them? When did the fourth condition of Art. 14 DSG trip, if it has, and was the Swiss user count that made the processing extensive noticed by anyone whose job it was to notice?
A hospital contract raises a different order of question. Was the data processing addendum drafted to Art. 28 GDPR, and if so, where in it is the customer's confidentiality bar under Art. 9(1)(b) DSG satisfied, by what characterization of the vendor as an auxiliary person, and on whose legal analysis? If the customer is a cantonal hospital, has the vendor's security annex been read against the privatim resolution of November 2025, and is the encryption architecture it describes one in which the vendor could not read the data if asked to, or one in which it merely does not? And for the reimbursed therapeutic, does the impact assessment under Art. 22 DSG that stands behind the July 2026 listing describe the profiling the product performs in the terms Art. 5(f) and (g) DSG use, or in the terms the product team uses?
The transfer and incident questions have the shortest fuse. What does the vendor rely on for Swiss data if its framework certification ceases to carry an adequacy finding, is that fallback already in the contracts, and does it carry the Swiss adaptations the EDÖB's recognition requires? What does an incident-response plan built around sixty days do with a Swiss obligation to notify as quickly as possible, and who, by name, is the natural person a cantonal prosecutor would identify as having decided the timing? Beneath all of these sits the question with the longest horizon. Will a product architecture fixed in 2026 meet the electronic health dossier that was still before Parliament in the summer of 2026 with the data in the right place, in the right hands, and under a role the vendor chose rather than one it discovered? These questions require analysis tailored to specific facts and commercial context.