Skip to content
Compliance centre

Certified, scoped and published in advance.

A certification logo means nothing without its scope, its certifying body and its review date. All three are on this page for every standard we hold — alongside the shared-responsibility boundary, so you know exactly which obligations remain yours.

Certifications held
6
Independent audits / yr
6
Data residency
Switzerland
Our legal role
Processor
A historic Swiss street leading toward a church clock tower.
Swiss legal tradition

The clock tower predates
the software by centuries.

Swiss data protection law didn't arrive with cloud computing — it sits inside a legal tradition older than any platform built on it. The revised FADP (nDSG) has governed every byte of patient data since it took force on 1 September 2023, and the EDÖB in Bern is the supervisory authority we answer to when it does not.

1 Sep 2023
FADP / nDSG in force
EDÖB
Supervisory authority
Art. 9
Our processor obligation
72 h
Breach notice to EDÖB
Read the privacy policy

Six standards.
Scopes and dates included.

Certifications are only meaningful within their stated scope. Ours cover the MediVault platform, our Swiss data centres and the operations that support them — not a narrow carve-out chosen to make the certificate easy.

ISO 27001

Information Security Management System

Certifying body
SQS Schweizerische Vereinigung für Qualitäts- und Management-Systeme
Scope
MediVault platform, Swiss data centres and supporting operations
Status
Recertified March 2026 · next surveillance March 2027
SOC 2 Type II

Service Organization Control, Trust Services Criteria

Certifying body
Independent AICPA-accredited auditor
Scope
Security, Availability and Confidentiality criteria
Status
12-month observation window · report available under NDA
FADP / nDSG

Bundesgesetz über den Datenschutz (SR 235.1)

Certifying body
Self-attested with external legal review
Scope
Art. 5, Art. 8, Art. 25 and Art. 30 obligations
Status
In force since 1 September 2023 · reviewed annually
HIPAA

Health Insurance Portability and Accountability Act

Certifying body
Business Associate Agreement offered on all plans
Scope
Administrative, physical and technical safeguards
Status
Independent readiness assessment, renewed annually
ISO 27701

Privacy Information Management System

Certifying body
SQS · extension to the ISO 27001 certificate
Scope
Processor obligations for personal health information
Status
Certified February 2026
HL7 FHIR R4

Fast Healthcare Interoperability Resources

Certifying body
Conformance statement published, Touchstone-tested
Scope
Patient, Observation, DocumentReference, Consent and 19 more
Status
R4 (4.0.1) · R5 conformance in progress
ISO 27001 recertifiedMar 2026
ISO 27701 certifiedFeb 2026
SOC 2 Type II window closedJan 2026
Independent pen testApr 2026
HIPAA readiness reviewFeb 2026
Next ISO surveillanceMar 2027
HIPAA
Health Insurance Portability & Accountability Act
United States · 1996
§164.312(a)(2)(iv)
Encryption & Decryption

All ePHI is encrypted using AES-256-GCM both at rest and in transit using TLS 1.3.

§164.312(b)
Audit Controls

Cryptographically signed, immutable audit logs for every record access event.

§164.312(c)(1)
Integrity

HMAC-SHA512 integrity verification on every data object. Any modification is detected immediately.

§164.312(e)(2)(ii)
Transmission Security

TLS 1.3 enforced for all API communications. HSTS with 2-year max-age.

FADP / nDSG
Bundesgesetz über den Datenschutz (revised)
Switzerland · Effective 1 Sep 2023
Art. 8 nDSG
Datensicherheit

Technical and organisational measures proportionate to the risk. MediVault implements a full ISO 27001-aligned security framework.

Art. 25 nDSG
Privacy by Design

Data minimisation and purpose limitation are enforced at the schema level. Consent gates are embedded in the data model.

Art. 29 nDSG
Meldepflicht

Automated breach detection with <72h notification SLA to the FDPIC and affected data subjects.

Art. 30 nDSG
Auftragsbearbeitung

Standard AVV (data processing agreement) available for all customers. No sub-processors outside Switzerland.

ISO 27001
Information Security Management System
International · 2022 Edition
Annex A.8.24
Use of Cryptography

Defined cryptographic policy covering key lengths, algorithms, and key lifecycle management.

Annex A.8.15
Logging

Centralised, append-only log infrastructure with automated alerting on anomalous access patterns.

Annex A.8.8
Vulnerability Management

Continuous vulnerability scanning, monthly penetration tests, and a responsible disclosure programme.

Annex A.5.23
Cloud Security

All cloud services audited against ISO 27017 and 27018. Swiss-only data centre footprint.

SOC 2 Type II
Service Organization Control
AICPA · Annual Audit
CC6.1
Logical Access Controls

MFA enforced for all administrative access. Principle of least privilege applied at every level.

CC7.2
Monitoring

24/7 SIEM with automated alerting. Mean time to detect (MTTD) < 4 minutes.

CC9.2
Risk Mitigation

Annual third-party risk assessment. Vendor due diligence programme for all sub-processors.

A1.2
Availability

99.99% SLA guaranteed contractually. RPO < 1 hour, RTO < 4 hours.

Audit documentation

We publish redacted versions of our audit reports annually. Full reports are available to enterprise customers under NDA.

MediVault SOC 2 Type II Report 2026
PDF
ISO 27001 Certificate of Conformity
PDF
FADP Data Processing Agreement (AVV)
PDF
HIPAA Business Associate Agreement (BAA)
PDF

What we own.
What stays yours.

The most common cause of a compliance failure on a well-built platform is an obligation both parties assumed the other was carrying. Here is the boundary, written down.

Encryption of data at rest and in transit
MediVault — implemented by the platform, not configurable away by the customer.
Key management and rotation
MediVault on managed plans. Customer on BYOK/HYOK, where key availability becomes a customer responsibility.
Physical and infrastructure security
MediVault, via ISO 27001-certified Swiss Tier IV facilities under our contracts.
Access policy definition
Customer. We ship defaults encoding Swiss clinical governance norms; deciding who should see what remains the provider's clinical decision.
User provisioning and deprovisioning
Customer, automated through SCIM. We revoke sessions within 60 seconds of a deactivation signal.
Lawful basis and patient consent
Customer. As data controller, the healthcare provider determines the lawful basis. MediVault enforces the consents recorded in it.
Audit review and investigation
Shared. We generate, sign and retain the evidence; the customer's DPO and governance function review it.
Breach notification to authorities
Shared. We notify the customer within 24 hours of confirmation; the customer notifies the EDÖB and affected data subjects as controller.
Retention schedule configuration
Customer sets retention classes against their cantonal and specialty obligations. MediVault enforces them and prevents deletion under legal hold.
Business continuity of the platform
MediVault — 99.99% contractual SLA, quarterly restore tests, annual DR exercise.

Processor obligations
under Swiss law.

Our role
MediVault AG acts as a data processor (Auftragsbearbeiter) under FADP Art. 9. The healthcare organisation is always the controller.
Governing agreement
A standard AVV (Auftragsverarbeitungsvertrag) is executed with every customer before any patient data is processed. Enterprise customers may negotiate a bespoke DPA.
Data location
All production patient data is processed and stored exclusively in Switzerland. There is no transfer to the EU, the US or any other jurisdiction, for any purpose including support.
Sub-processors
Published in a public register with 30 days' advance notice of any change and a contractual right for customers to object.
Breach notification
Customer notified within 24 hours of confirmation. EDÖB notification within 72 hours where the FADP threshold is met, supported with our evidence.
Audit rights
Customers may audit our processing annually, either directly or through an independent auditor, in addition to the certifications we already hold.
Deletion and return
On termination, a full FHIR R4 export plus original documents within 30 days, followed by cryptographic erasure of all copies including backups.
Supervisory authority
Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB), Feldeggweg 1, 3003 Bern
Compliance centre

Send us the
questionnaire.

We complete security and data protection questionnaires in full, in writing, with evidence references — before any commercial conversation. Most are returned within five working days.

Dr. Anne-Sophie Reber, Group Data Protection Officer · dpo@medivaultzurich.site