Skip to content
SWISS PATIENT DATA VAULT · ZÜRICH, CH

[DKR fmt07& FMTahw3@<BIPWdkr 5$[DKRYfm6%]EL Zgnu18!}GN

The complete secure data infrastructure platform for healthcare — storage, access control, audit, integration, deployment and intelligence. Built for Swiss FADP and HIPAA from the ground up, operated entirely inside Switzerland.

4,200+
Patient records secured
Across 127 healthcare sites
0
Data breaches since 2019
Independently attested annually
99.99%
Contractual uptime SLA
99.997% measured, trailing 12 mo
100%
Swiss data residency
No data leaves CH jurisdiction

Not an encrypted folder.
A complete data platform for healthcare.

Healthcare organisations do not have a storage problem. They have a storage, access, evidence, interoperability and deployment problem — usually solved by five vendors who do not speak to each other. MediVault is those five layers, built as one platform, operated entirely inside Switzerland.

The buyer is an organisation,
not an individual patient.

A hospital laboratory with rows of automated diagnostic analysers and a technician at work.
Diagnostics · LIS
Laboratory, imaging and pharmacy systems keep running as they are — MediVault becomes the record they write to.

MediVault is sold to and operated by healthcare organisations. Patients benefit from it — through faster access, provable consent and a real record of who has seen their file — but the customer, the contract and the accountability sit with the provider.

Private clinicsSpecialist practicesHospitalsMulti-site organisationsHospital networksCantonal health authoritiesHealthtech providers
Snow-covered Swiss peaks rising above a sea of cloud.
Swiss by jurisdiction

Everyone says Swiss.
Very few mean the jurisdiction.

Swiss-hosted is a marketing line. Swiss-resident is a legal position you can be held to — one company, one country, one supervisory authority, and no clause anywhere that lets your patients' records be read under another nation's law.

100%
Data resident in Switzerland
0
Foreign jurisdiction exposure
FADP
Swiss law, in force 2023
EDÖB
Supervisory authority, Bern
Compliance centre

The vault, explained
without the marketing.

Three questions decide whether a hospital executive trusts a data platform: what goes in it, who can get it out, and what happens the moment somebody tries. Here are the answers.

01

Medical records

Structured encounters, diagnoses, medications, allergies

02

Clinical documents

Discharge letters, consultation notes, operative reports

03

Diagnostic reports

Radiology, pathology and cardiology reporting

04

Imaging metadata

DICOM study index and pointers; pixel data stays in PACS

05

Laboratory information

Orders, results, reference ranges, LOINC-coded panels

06

Referral documents

Inbound and outbound referrals with routing history

07

Treatment records

Care plans, procedures, therapy and follow-up schedules

08

Patient forms

Consent, intake, questionnaires and signed declarations

09

Insurance documentation

Coverage confirmations, guarantees, claim attachments

10

Administrative records

Identifiers, contact data, correspondence, mandates

Imaging note: MediVault indexes DICOM study metadata and holds pointers into your PACS. Pixel data stays where your radiology workflow already expects it — we do not ask you to migrate your archive.

Vault architecture

Eight products.
One platform.

Each pillar is a product a healthcare organisation could buy on its own. Together they remove the seams — the gaps between vendors where compliance failures and integration projects usually live.

Two clinicians in white coats reviewing a patient record together on a tablet.
At the bedside

Security nobody uses
protects nobody.

A control that adds seconds to a ward round gets routed around, and a system clinicians resent becomes a shadow drive full of unencrypted PDFs. MediVault is built to disappear into the working day — 38 ms to an authorised record, on the device already in their hand.

38 ms
Median authorised read
4
Interface languages
WCAG 2.2 AA
Accessibility conformance
3 days
Typical clinic go-live
See the clinical portal

Certified to the
highest standard.

From Swiss FADP to HIPAA, our compliance posture is independently audited, continuously monitored, and fully documented. We publish our audit reports annually.

HIPAA
Health Insurance Portability & Accountability Act
United States
CERTIFIED
FADP
Bundesgesetz über den Datenschutz (nDSG)
Switzerland
CERTIFIED
ISO 27001
Information Security Management System
International
CERTIFIED
SOC 2
Service Organization Control Type II
AICPA Standard
CERTIFIED
HL7 FHIR
Fast Healthcare Interoperability Resources R4
Healthcare Standard
CERTIFIED
SWISS LAW
FADP
nDSG / 235.1

The revised Federal Act on Data Protection (Datenschutzgesetz) came into force on 1 September 2023. MediVault was re-architected ahead of this transition. Our implementation covers all requirements under Art. 8 (Data Security), Art. 25 (Privacy by Design), and Art. 30 (Data Processor Agreements).

Art. 8 DatensicherheitArt. 25 Privacy by DesignArt. 30 AuftragsbearbeitungArt. 5 Grundsätze

Two rooms decide
whether this works.

The front desk, where a record is created under time pressure by someone who is not a clinician. And the ward, where it is read by someone with four minutes and a patient waiting. Everything in the architecture is answerable to those two rooms.

A clinician completing a form on a clipboard across a desk from a patient.
Admissions · Record creation
Identity, insurance and consent captured once, correctly, by staff who should never need to think about encryption.
Two clinicians in white coats reviewing a patient record together on a tablet.
Ward · Record access
Read in 38 ms by whoever holds the care relationship — and by nobody who does not, whatever their seniority.

It has to work with
what you already run.

No hospital replaces its estate to adopt a vault. MediVault connects to the systems already in the building through HL7 FHIR R4, an HL7 v2 bridge, REST endpoints, signed webhooks and first-party SDKs.

Clinical
  • EHR / EMR
  • Hospital information systems
  • Patient portals
Diagnostics
  • Laboratory (LIS)
  • Imaging (RIS / PACS)
  • Pathology
Operations
  • Pharmacy
  • Billing & TARMED
  • Scheduling
Downstream
  • Healthcare apps
  • Analytics platforms
  • Research registries
18
Certified connectors
23
FHIR resources
38 ms
Median read (p50)
A fibre-optic patch panel with labelled single-mode cables terminating in green connectors.
Cross-connect · ZH-DC-01
Certified connectors terminate against your existing interfaces — we do not ask you to migrate the estate.
api.medivaultzurich.siteTLS 1.3 ✓
GET /fhir/r4/Patient?identifier=756.1234.5678.97
Host: api.medivaultzurich.site
Authorization: Bearer {access_token}
X-MV-Purpose-Of-Use: TREATMENT
Accept: application/fhir+json

200 OK
{
  "resourceType": "Bundle",
  "type": "searchset",
  "total": 1,
  "entry": [{
    "resource": {
      "resourceType": "Patient",
      "id": "pat_8f2c41ba",
      "meta": { "versionId": "14", "security": [
        { "code": "R", "display": "Restricted" }
      ]},
      "active": true
    }
  }]
}
Sandbox tenants provisioned in under 5 minutesSDKs: TypeScript · Python · Java
Rows of enclosed white server cabinets in a data centre hall, viewed from above.
Rümlang & Glattbrugg, Kanton Zürich

Data residency is a
legal position, not a claim.

Every byte of production patient data lives in Tier IV facilities we can name, in cantons we can point to, under Swiss law. No processing, no backup, no support access and no telemetry leaves Swiss jurisdiction — including ours.

3
Swiss facilities
Tier IV
Primary and replica
15 min
Disaster recovery RPO
0
Bytes leaving Switzerland
Deployment models

Swiss soil.
Swiss jurisdiction.

Data residency is a legal position, not a marketing claim. Every byte of production patient data lives in facilities we can name, in cantons we can point to, under Swiss law — with a documented deployment model for organisations that need it inside their own walls.

ZH-DC-01Tier IV

Rümlang, ZH

Primary production vault

Role
Active — read / write primary
Resilience
2N power · N+1 cooling
Latency
< 4 ms to Zürich metro
Attested
ISO 27001 · ISO 50001 · biometric multi-zone access
ZH-DC-02Tier IV

Glattbrugg, ZH

Synchronous replica

Role
Active — synchronous replication
Resilience
2N power · N+1 cooling
Latency
< 2 ms inter-site RTT
Attested
ISO 27001 · ISO 22301 business continuity
GE-DC-03Tier III+

Meyrin, GE

Disaster recovery vault

Role
Warm standby — 15 min RPO
Resilience
N+1 power and cooling
Latency
< 9 ms Zürich → Genève
Attested
ISO 27001 · Swiss data-residency attested

Swiss cloud

Multi-tenant, fully managed, hosted in our Zürich Tier IV facilities.

Best fit
Clinics and hospitals wanting zero infrastructure burden

Private cloud

Single-tenant instance with dedicated compute, storage and key hierarchy.

Best fit
Groups with isolation requirements from their CISO

On-premise

Deployed inside your own data centre, operated by your team or ours.

Best fit
Institutions with existing estate and sovereignty policy

Hybrid

Keys and sensitive shards on-premise, scale and DR in the Swiss cloud.

Best fit
Networks balancing control against operational cost

Air-gapped

No external network path. Updates delivered by signed, verified media.

Best fit
Classified, forensic and public-sector environments
127
Healthcare sites live
Clinics, hospitals and networks
38 ms
Median API response
FHIR R4 read, p50, Swiss edge
1.2 bn
Audit events written
Cryptographically signed, immutable
18
EHR systems connected
Certified production connectors
6
Independent audits / year
Pen-test, SOC 2, ISO surveillance
30 min
P1 incident response
24/7 Swiss-based on-call

Watch encryption
happen live.

Our portal encrypts data client-side before it ever leaves your browser. The terminal below simulates a single patient record write — exactly as it happens in production.

medivault-portal · secure-enclave v2.4.1
MediVault Secure Shell v2.4.1 · ZH-DC-02 · TLS 1.3 ✓
Initialized HSM session · Key slot #7 active
──────────────────────
$vault write --patient-record --encrypt=AES256-GCM
$
01Client-Side Keying

Keys never touch our servers. Derived from your identity token using PBKDF2 with 310,000 iterations.

02AES-256-GCM Encryption

Authenticated encryption ensures both confidentiality and integrity. Any tampering is detected.

03HSM Seal

The encrypted payload is sealed with a hardware security module. Physical tamper-evidence guaranteed.

04Shard Storage

Data is split across geographically separated Swiss data centres. No single point holds a complete record.

Explore the full portal

No surprises.
Swiss precision.

All plans billed in CHF. No currency risk, no hidden fees. Annual billing available at a 20% discount.

Klinik
CLINIC
CHF299/ Monat

For private clinics and specialist practices with up to 500 active patients.

Start with Klinik
  • Up to 500 patient records
  • AES-256 encryption at rest
  • TLS 1.3 in transit
  • FADP & HIPAA compliant
  • HL7 FHIR R4 API
  • Audit trail (90 days)
  • Email support (48h SLA)
MOST POPULAR
Spital
HOSPITAL
CHF1,299/ Monat

For hospitals and multi-site practices managing thousands of records.

Start with Spital
  • Up to 5,000 patient records
  • All Klinik features
  • HSM-backed key management
  • Granular RBAC permissions
  • Audit trail (365 days)
  • SIEM integration
  • Priority support (4h SLA)
  • Dedicated CSM
Unternehmen
ENTERPRISE
Custom

For large hospital networks and canton health systems with custom requirements.

Contact Sales
  • Unlimited patient records
  • All Spital features
  • On-premise deployment option
  • Custom data residency SLA
  • Air-gap vault mode
  • Zero-knowledge architecture
  • 24/7 dedicated support
  • Annual penetration test

All prices in Swiss Francs (CHF) · VAT (MWST) may apply · No credit card required

Trusted by 127 Swiss healthcare sites

Your patients deserve
better protection.

Request a demo, book a technical deep-dive with our Zürich engineering team, or send us your security questionnaire — we answer it in full before you sign anything.

Data hosted exclusively in Switzerland · No US data transfer · FADP compliant