Certified, scoped and published in advance.
A certification logo means nothing without its scope, its certifying body and its review date. All three are on this page for every standard we hold — alongside the shared-responsibility boundary, so you know exactly which obligations remain yours.
- Certifications held
- 6
- Independent audits / yr
- 6
- Data residency
- Switzerland
- Our legal role
- Processor

The clock tower predates
the software by centuries.
Swiss data protection law didn't arrive with cloud computing — it sits inside a legal tradition older than any platform built on it. The revised FADP (nDSG) has governed every byte of patient data since it took force on 1 September 2023, and the EDÖB in Bern is the supervisory authority we answer to when it does not.
- 1 Sep 2023
- FADP / nDSG in force
- EDÖB
- Supervisory authority
- Art. 9
- Our processor obligation
- 72 h
- Breach notice to EDÖB
Six standards.
Scopes and dates included.
Certifications are only meaningful within their stated scope. Ours cover the MediVault platform, our Swiss data centres and the operations that support them — not a narrow carve-out chosen to make the certificate easy.
Information Security Management System
- Certifying body
- SQS Schweizerische Vereinigung für Qualitäts- und Management-Systeme
- Scope
- MediVault platform, Swiss data centres and supporting operations
- Status
- Recertified March 2026 · next surveillance March 2027
Service Organization Control, Trust Services Criteria
- Certifying body
- Independent AICPA-accredited auditor
- Scope
- Security, Availability and Confidentiality criteria
- Status
- 12-month observation window · report available under NDA
Bundesgesetz über den Datenschutz (SR 235.1)
- Certifying body
- Self-attested with external legal review
- Scope
- Art. 5, Art. 8, Art. 25 and Art. 30 obligations
- Status
- In force since 1 September 2023 · reviewed annually
Health Insurance Portability and Accountability Act
- Certifying body
- Business Associate Agreement offered on all plans
- Scope
- Administrative, physical and technical safeguards
- Status
- Independent readiness assessment, renewed annually
Privacy Information Management System
- Certifying body
- SQS · extension to the ISO 27001 certificate
- Scope
- Processor obligations for personal health information
- Status
- Certified February 2026
Fast Healthcare Interoperability Resources
- Certifying body
- Conformance statement published, Touchstone-tested
- Scope
- Patient, Observation, DocumentReference, Consent and 19 more
- Status
- R4 (4.0.1) · R5 conformance in progress
All ePHI is encrypted using AES-256-GCM both at rest and in transit using TLS 1.3.
Cryptographically signed, immutable audit logs for every record access event.
HMAC-SHA512 integrity verification on every data object. Any modification is detected immediately.
TLS 1.3 enforced for all API communications. HSTS with 2-year max-age.
Technical and organisational measures proportionate to the risk. MediVault implements a full ISO 27001-aligned security framework.
Data minimisation and purpose limitation are enforced at the schema level. Consent gates are embedded in the data model.
Automated breach detection with <72h notification SLA to the FDPIC and affected data subjects.
Standard AVV (data processing agreement) available for all customers. No sub-processors outside Switzerland.
Defined cryptographic policy covering key lengths, algorithms, and key lifecycle management.
Centralised, append-only log infrastructure with automated alerting on anomalous access patterns.
Continuous vulnerability scanning, monthly penetration tests, and a responsible disclosure programme.
All cloud services audited against ISO 27017 and 27018. Swiss-only data centre footprint.
MFA enforced for all administrative access. Principle of least privilege applied at every level.
24/7 SIEM with automated alerting. Mean time to detect (MTTD) < 4 minutes.
Annual third-party risk assessment. Vendor due diligence programme for all sub-processors.
99.99% SLA guaranteed contractually. RPO < 1 hour, RTO < 4 hours.
Audit documentation
We publish redacted versions of our audit reports annually. Full reports are available to enterprise customers under NDA.
What we own.
What stays yours.
The most common cause of a compliance failure on a well-built platform is an obligation both parties assumed the other was carrying. Here is the boundary, written down.
- Encryption of data at rest and in transit
- MediVault — implemented by the platform, not configurable away by the customer.
- Key management and rotation
- MediVault on managed plans. Customer on BYOK/HYOK, where key availability becomes a customer responsibility.
- Physical and infrastructure security
- MediVault, via ISO 27001-certified Swiss Tier IV facilities under our contracts.
- Access policy definition
- Customer. We ship defaults encoding Swiss clinical governance norms; deciding who should see what remains the provider's clinical decision.
- User provisioning and deprovisioning
- Customer, automated through SCIM. We revoke sessions within 60 seconds of a deactivation signal.
- Lawful basis and patient consent
- Customer. As data controller, the healthcare provider determines the lawful basis. MediVault enforces the consents recorded in it.
- Audit review and investigation
- Shared. We generate, sign and retain the evidence; the customer's DPO and governance function review it.
- Breach notification to authorities
- Shared. We notify the customer within 24 hours of confirmation; the customer notifies the EDÖB and affected data subjects as controller.
- Retention schedule configuration
- Customer sets retention classes against their cantonal and specialty obligations. MediVault enforces them and prevents deletion under legal hold.
- Business continuity of the platform
- MediVault — 99.99% contractual SLA, quarterly restore tests, annual DR exercise.
Processor obligations
under Swiss law.
- Our role
- MediVault AG acts as a data processor (Auftragsbearbeiter) under FADP Art. 9. The healthcare organisation is always the controller.
- Governing agreement
- A standard AVV (Auftragsverarbeitungsvertrag) is executed with every customer before any patient data is processed. Enterprise customers may negotiate a bespoke DPA.
- Data location
- All production patient data is processed and stored exclusively in Switzerland. There is no transfer to the EU, the US or any other jurisdiction, for any purpose including support.
- Sub-processors
- Published in a public register with 30 days' advance notice of any change and a contractual right for customers to object.
- Breach notification
- Customer notified within 24 hours of confirmation. EDÖB notification within 72 hours where the FADP threshold is met, supported with our evidence.
- Audit rights
- Customers may audit our processing annually, either directly or through an independent auditor, in addition to the certifications we already hold.
- Deletion and return
- On termination, a full FHIR R4 export plus original documents within 30 days, followed by cryptographic erasure of all copies including backups.
- Supervisory authority
- Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB), Feldeggweg 1, 3003 Bern
Send us the
questionnaire.
We complete security and data protection questionnaires in full, in writing, with evidence references — before any commercial conversation. Most are returned within five working days.
Dr. Anne-Sophie Reber, Group Data Protection Officer · dpo@medivaultzurich.site