Data protection: what the nFADP really expects from an SME

Published on February 23, 20267 min read
A medical-practice secretary files sensitive patient folders into a lockable cabinet, one marked with a padlock

A patient asks to see their entire file. At the reception desk, Lucie F. realises she couldn't actually say where all of that information lives: some in the practice software, some in emails, a few scans on a USB stick. Dr Anne P., for her part, is asking a simpler and more unsettling question: are we even allowed to run things this way?

Data protection: what the nFADP really expects

Since 1 September 2023, Switzerland has applied the nFADP — the new Federal Act on Data Protection. It is not aimed only at large groups: any organisation that holds personal data is concerned, including a neighbourhood medical practice. In the eyes of the law, that practice is a "controller": the party that decides why and how personal data is used. It carries the responsibility — not its software, not its IT provider.

Two words change everything for a practice. First, "sensitive data": health information is part of it, alongside religious opinions, trade-union membership or biometric data. The law protects it more strictly than your supplier list. Second, "appropriate" security: nowhere does the nFADP demand flawless protection or a digital vault worthy of a major bank. It requires measures proportionate to the risk — the more sensitive and voluminous the data, the higher the expected level. For a practice, the bar therefore sits a notch higher than for a corner shop, but it remains well within reach.

Put plainly, as Camille, our adviser, would say: the nFADP doesn't ask you to be perfect, it asks you to be serious and to be able to show it. For concrete steps, the National Cyber Security Centre (NCSC) publishes practical recommendations designed for SMEs — a good compass when you don't know where to start.

In practice, "processing data" isn't limited to storing it in software. It also means viewing it, printing it, sending it, copying it onto a stick, archiving it or deleting it. Each of these everyday gestures falls within the scope of the law. That's why "appropriate" security isn't only about firewalls: it also relies on very human things, such as knowing who opened which file. A reception desk where everyone shares a single account cannot answer that question — and that is exactly the kind of detail the law looks at, because it determines traceability if something goes wrong.

And the GDPR, the European regulation everyone talks about? It only concerns you if you process the data of people located in the European Union — for example cross-border patients living in France. For the vast majority of Swiss SMEs, the nFADP takes precedence, and that is where you should start. No need to drown in European law if your patients are Swiss.

Key takeaways

Three ideas are enough to frame the subject.

First: the nFADP thinks in terms of responsibility, not certificates. No one will come and hand you a "compliant" stamp. You are expected to be able to explain, if a patient or an authority asks, what data you hold and how you protect it. It is a posture to maintain over time, not an exam you pass once and for all.

Second: "appropriate" means proportionate. You don't have to encrypt and lock everything down by tomorrow morning. You first need to know what, in your organisation, would deserve the most attention — and it is almost always health data and the access routes that lead to it. One named account per person, a retention period that is decided rather than endured, a former employee whose access has indeed been cut off: these are modest measures, but they are exactly what "appropriate" covers for a care setting.

Third: in the event of a leak, the law provides for a notification. If a breach of data security is likely to result in a high risk to the persons concerned, the controller must notify the FDPIC — the Federal Data Protection and Information Commissioner, the Swiss supervisory authority — as soon as possible. It is not the GDPR's fixed 72-hour deadline, but the spirit is identical: you don't hide an incident, you report it.

Steps to put in place this week

1. Map your sensitive data

Take a sheet of paper — really — and list what you hold: patient files, test results, insurance invoices, staff data. For each category, note where it is stored, who has access and how long you keep it. This list has a name in the law: the register of processing activities, that is, the simple description of what you do with data. Small businesses are in principle exempt, but as soon as sensitive data is processed — the case of a practice — the register becomes the norm again. It is also, incidentally, what will let you answer within ten minutes a patient who asks for their file, instead of searching everywhere like Lucie F.

2. Reserve a safe channel for health data

Ordinary email is a postcard: readable by more people than one thinks, and rarely hosted in Switzerland. Sending a test result this way is the most common and the riskiest gesture in a practice. Most practice software offers secure messaging or a patient portal: make it the default channel for anything health-related. And set a simple rule for the team: no sensitive data leaves by standard email or on an unencrypted USB stick (a stick whose contents aren't made unreadable without a password).

3. Prepare the "breach" reflex

No one wants to think about it, and that is precisely why it should be done in cold blood. Write half a page: what do we do if a laptop goes missing, if a file is sent to the wrong recipient, or if the practice is hit by ransomware (software that blocks your files until a ransom is paid)? Who is alerted internally, who decides, and in which cases do we contact the FDPIC? Having these answers written down before the incident saves you the hours that really count on the day.

Where do you really stand?

The good news is that none of these steps requires a big budget or an in-house IT specialist. The less good news is that, on your own, it is hard to know whether you are doing enough — or whether you are exhausting yourself on a detail while leaving a door wide open.

That is exactly where a structured self-assessment against the requirements of the nFADP comes in. Cyber Passport certifies nothing and issues no label: it walks you through, question by question, what the law expects and what you have actually put in place, then shows you in black and white where you are solid and where you still rely on goodwill alone. And to turn that snapshot into a data-protection action plan — from the register to patients' rights — our dedicated blueprint lays out the way forward, step by step.

Topics

  • nFADP
  • data protection
  • SME
  • Switzerland
  • healthcare

Read next