Controversy over security in the digital health record

Controversy over security in the digital health record

Today, the National Chamber is about to vote on the Electronic Patient Record Act. The Federal Office of Public Health is refusing to engage in a fundamental technical debate. The digital civic society might push for a referendum.

(note: Original article is written in German. Translation via Deepl Pro).

If one were to create a separate patient record for the electronic patient record project itself, the list of problems would be long: a complex web of different stakeholders, pseudo-competition, a chronic lack of demand due to the medical profession’s failure to make it mandatory, certification hurdles for providers, a graveyard of PDFs.

Of over 9 million residents, only just over 140,000 people have so far had a digital medical record created on a voluntary basis. Years ago, the then Minister for Health, Alain Berset, had to admit that, unfortunately, progress had not been as far as hoped.

It was regarded as a failed IT project.

That is why the government pressed the reset button in 2025 with the new Minister for Health, Elisabeth Baume-Schneider. Now the rebranding is done: the patient dossier is to become the health dossier.

Paradigm shift causes resistance

This is accompanied by a paradigm shift: from a voluntary to a transition that is mandatory for everyone (unless a citizen objects within the specified time limit), and from a decentralised to a centralised infrastructure (the Confederation alone is responsible for the operational infrastructure for the health dossier in its own data centres, rather than various local authorities being responsible).

The electronic health record is also intended to be mandatory not only for hospitals, but equally for doctors, physiotherapists and pharmacists. Patients’ data should be provided in a structured format rather than as PDFs, which are difficult to process automatically. And citizens themselves should continue to have full control over their data and determine with whom, if anyone, they share it.

In theory the project promises major improvements in many respects.

However, this fresh start following the long-running debacle is also facing fierce criticism. For instance, from the Digital Society, which has been examining the health record for months.

Firstly, the organisation is frustrated by the new opt-out mechanism. Anyone who fails to object in time will simply be assigned a compulsory health record – without active consent. And from that point onwards, pharmacies and doctors will then start populating this record.

Secondly, it is frustrated by the Federal Office of Public Health’s (FOPH) stance on encryption.

The background to this is a paper by the ‘Centre for Digital Trust’ at the Swiss Federal Institute of Technology in Lausanne, which was commissioned by the FOPH. In it, cryptographers Linus Gasser and Imad Aad examined various options for the encryption architecture. Each option gives the federal government and the citizen a different degree of control and sovereignty.

And opinions on the ‘right architecture’ could not be more divided.

Several options for encryption

The first option: the key is stored in a hardware security module (HSM) that is entirely controlled by the federal government. Sovereignty therefore effectively lies with the Federal Office of Public Health – one relies on the federal administration to abide by the law, as technically the federal government could view the health data in plain text.

The second option would be somewhat more complicated. The keys would also be stored in an HSM module, but this would be managed not by the federal government, but by a number of independent organisations.

This is how it works: when a patient logs in to access her medical record using her e-ID, a minimum number – for example, 9 – out of 12 organisations or their servers confirm the patient’s identity (a minimum number is defined because a few servers might not be working at that moment). According to the Federal Office of Public Health, it is still to be decided whether the government-issued e-ID or another means of identification will be used to verify the patient’s name.

For example, the patient grants a specific psychologist access to the medical record. The psychologist also logs in to the HSM module. As soon as her identity and access are authorised by the organisations, the psychologist receives the key to the patient’s file and can decrypt the data.

Under this scenario, the nine independent organisations could, in theory, collude with one another and thus read all patients’ files. However, this would require a great deal of criminal intent and a high degree of corruption.

The third option, on the other hand, is easy to understand: this involves classic end-to-end encryption, as we know it from Signal, Threema or WhatsApp. Here, the key is stored directly on the citizen’s device (for example, on their mobile phone or in their digital wallet) – the federal government can never view the data in unencrypted form. Control clearly lies with the individual.

Digitale Gesellschaft has a clear favourite: Option 3.

The debate over security

Citizens should be in possession of the key and thus protected against all forms of misuse: both from access by the FOPH and from cybercriminals. “That is why it does not matter that the data is stored on federal servers. The public retains control through the key, and this also fosters trust,” says Digitale Gesellschaft.

The FOPH takes a completely different view, as no country has yet implemented such a decentralised key system. And the agency does not wish to engage in any pioneering experiments. In a 7-page paper, the FOPH argues primarily against Option 3, albeit in a somewhat contradictory manner.

The FOPH emphasises the importance of the principles of zero trust and security by design. Zero trust means, roughly speaking, that no one and nothing on the network is automatically trusted – every request must be repeatedly checked and confirmed. Security by design means that security is built into the development of a system from the outset – not added as an afterthought.

Both principles would actually be best implemented with end-to-end encryption, as confirmed by numerous IT experts I spoke to. And both principles contradict Option 1, under which one must entrust everything – namely the data and the corresponding key – to the FOPH alone.

However, the FOPH interprets these principles completely differently, as it states in response to an enquiry: “ In particular, strong identity, authentication and authorisation mechanisms, continuous logging of accesses (…), and end-to-end encryption of data transmission (…) are crucial.”

Furthermore, the costs of end-to-end encryption are said to be too high and its implementation too complicated, which would result in significant compromises in user-friendliness. In short: citizens would bear too much responsibility, particularly if they lost their mobile phone or their login details.

Linus Gasser, author of the EPFL study, can certainly understand the FOPH’s reasoning: “Option 3 would be my cryptographic dream. But the system has not been tested, and no one anywhere in the world has implemented it yet.”

Gasser also highlights another problem: the emergency scenario and key recovery.

Specifically, the question is how to access a file if the person concerned is in a coma or unconscious, but the emergency doctor may need information that is vital to their survival. And there is the question: what happens if a citizen loses their mobile phone?

However, Erik Schönenberger from Digitale Gesellschaft already has potential solutions ready for both scenarios: “In an emergency, a network of independent bodies can grant access to the relevant health data via distributed partial keys, with every instance of access being logged.” Patients retain control over their access rights.

Regarding the loss of a mobile phone, the co-managing director of Digitale Gesellschaft says: “If the personal key is lost, Option 3 provides for a decentralised recovery service in which several independent bodies each hold only one part of the recovery key.” Only when a specified number of these bodies cooperate can the key be restored (though it must remain with the record holder themselves).

FOPH postpones discussion about fundamental technical issues to the ordinance level

In addition to the significant disagreement amongst experts on the issue of encryption, there is also a democratic problem: after years of deadlock, the FOPH finally wants to push the health dossier through and comprehensively digitise the healthcare system. It is hoped that this will provide data and information to improve the quality of treatment, as well as offering potential savings on healthcare costs.

That is why the FOPH wants to rush the federal bill through Parliament – without wasting too much time on discussions of technical details. Even though the FOPH’s statement sometimes reads as though only Option 1 actually corresponds to the ‘state of the art’: an FOPH spokesperson emphasises that they do not wish to commit to any option at present. The details would be negotiated in the implementing legislation.

At that stage, however, they would no longer be subject to a referendum.

You can read the full article here: https://www.republik.ch/2026/09/14/streit-um-sicherheit-bei-digitalem-gesundheitsdossier

On my blog, I publish all the posts that I share across my various channels, either in full (original blog posts) or in abridged form (republik.ch). As I’m only employed part-time, I’m grateful for any support.

Anyone wishing to support my blogging activities is welcome to donate to the Techjournalismus.ch association’s bank account.

The aim is to continue expanding the editorial content of this blog in the future. With sufficient financial support, I will also be able to commission other journalists to carry out smaller research projects. I am grateful for every donation!

Verein Techjournalismus.ch 4053 Basel

CH36 0077 0255 9452 2200 1

Weitere Beiträge

Streit um Sicherheit bei digitalem Gesundheits­dossier

Heute entscheidet der Nationalrat über das Gesetz zur elektronischen Krankenakte. Das BAG verweigert eine technische Grundsatz­diskussion. Deshalb droht nun ein Referendum. Würde man für das Projekt des elektronischen Patienten­dossiers ein eigenes Patienten­dossier anlegen, wäre die Liste der Pathologien lang: ein komplexes Geflecht von verschiedenen Akteuren, Pseudo­wettbewerb, chronisch mangelnde Nachfrage aufgrund fehlender Pflichten

Weiterlesen

Welche Sprachmodelle stecken hinter der neuen «KI» für das Bundesparlament?

Endlich, dachte ich letzte Woche… endlich kriegen die Bundesparlamentarier:innen in Bern eine eigene KI als neues Arbeitstool. Denn dies war überfällig…was hörte ich alles an Geschichten von Nationalrät:innen, die ihre Kommissionsunterlagen auf ChatGPT oder Claude.ai hinaufladen, ihre Texte auf deutsch und französisch übersetzen lassen etc. Alles Kommissionsgeheimnisse, die Medienschaffende auf

Weiterlesen

The creepy comeback of smart glasses

NOTE: Original article was written in german. Translation via Deepl Pro. Smart glasses and facial recognition were already a reality ten years ago. Back then there was a big opposition against those gadgets, politically and socially.. That has changed – which is why these gadgets must be banned. Just a

Weiterlesen

Das gruselige Comeback der smarten Brillen

Smart Glasses und Gesichts­erkennung funktionierten bereits vor zehn Jahren. Doch sie waren politisch und gesellschaftlich verpönt. Das hat sich geändert – weshalb diese Anwendungen verboten werden müssen. Noch vor wenigen Jahren war für viele die Vorstellung gruselig, sich eine Brille aufzusetzen, mit der man Zusatz­informationen über Objekte und Menschen bekommt. Die im

Weiterlesen

Palantir co-founder funds space research in Switzerland

Note: Original article is written in german. Translation via Deepl Pro. The discreet co-founder of Palantir Nathan Gettings has settled down in Switzerland and supports academic projects at universities in Zurich and Lausanne. There isn’t much information available on the website: “The founder, an entrepreneur, has achieved considerable success in

Weiterlesen

Co-Gründer von Palantir finanziert Weltraum­forschung in der Schweiz

Der verschwiegene Nathan Gettings hat sich in der Schweiz nieder­gelassen und fördert unter anderem Projekte an Hoch­schulen in Zürich und Lausanne. Viele Informationen findet man nicht auf der Website: «Der Gründer, ein Unter­nehmer, hat in seiner Karriere beachtliche Erfolge erzielt. Jetzt, da er von den Zwängen wirtschaftlicher Rentabilität befreit ist, kann

Weiterlesen