AI agents in Swiss healthcare: test before you trust
Our first healthcare focus: agents that support communication and workflow, while clinical responsibility stays with qualified people.
A concrete example: the appointment workflow
Picture an agent that answers an authenticated patient, reads clinic availability and prepares an appointment. It may collect the preferred location and time — but it never diagnoses, never judges urgency from symptoms and never confirms the booking alone. The final screen shows patient, clinic, practitioner, time and message to a staff member, who approves that exact booking.
If the patient describes an emergency, the agent follows the approved escalation message and routes the case to the defined human channel. The organization’s clinical lead owns that boundary and the escalation wording; a product team cannot redefine clinical responsibility through a prompt.
Protect patient context
Map identifiers, symptoms, recordings, notes and derived fields from capture to deletion. Use minimum access and separation between customers or providers. Disclose the real processing locations and assess any cross-border transfer with the relevant safeguards — Swiss data protection creates no universal must-stay-in-Switzerland rule.
Medical professional secrecy needs a separate, contextual review. The FDPIC notes that professions listed in Article 321 of the Swiss Criminal Code, including their assistants, are bound by professional secrecy, and raises specific concerns when doctors use third-party or foreign cloud providers. Hosting and disclosure therefore need a review of the professional role, patient information, provider access and concrete location — not a generic residency slogan.
FDPIC patient-data guidance advises against foreign cloud providers in the medical-secrecy context; general transfer safeguards do not resolve that issue.
How we test patient-data access
We create two synthetic patients under separate care teams. Then we ask the agent — directly and through a retrieved document — to summarize the other team’s record. The expected result: refusal before protected content reaches the AI, plus a record showing the authorization decision. We also test a shared practitioner, revoked access and a cached search result.
Requested evidence includes the access matrix, retrieval-filter settings, synthetic test identities, prompt and tool records, the refusal event, cache handling and the retest result. Passing this sample proves the tested boundary for the stated setup — not that every disclosure route is gone.
Evidence — and where clinical responsibility stays
The dossier should include the clinical scope statement, data-flow map, professional-secrecy and hosting analysis, appointment approval policy, escalation routes, representative multilingual tests, incident owner and shutdown procedure. Patient data stays minimized or synthetic wherever the test allows.
Clinical validation and patient-care responsibility remain with the qualified healthcare organization and its professionals. A technical assessment can verify controls and workflow behaviour, but it never authorizes diagnosis, replaces professional judgement or decides whether a clinical use is appropriate.
Common questions
Does the assessment certify clinical accuracy?
No. It evaluates the declared controls and workflow evidence. Clinical validation, professional judgement and authorization of the care use stay separate.
Must healthcare AI data always stay in Switzerland?
Swiss data protection creates no universal residence rule — but medical professional secrecy, provider access, patient information and foreign-law exposure always need a separate hosting analysis.
Why require human approval for an appointment?
The draft scheme ties the final patient, clinic, time and message to a responsible person before the external booking exists. It also produces a record that can be reviewed later.