top of page

AI in the Medical Practice: What Already Applies Today.

  • Aug 1
  • 4 min read


The report was done in five minutes. That's where the problem begins.


Monday morning, a packed schedule. The medical assistant opens a free AI app on her phone and dictates the key points from the last patient. Thirty seconds later, a clean draft report is ready. What used to take twenty minutes is done before the next patient is even called in from the waiting room.


This scene is currently playing out in many Swiss practices — usually without practice management's knowledge. That's exactly where the problem lies: free and premium versions of common AI tools come with no data processing agreement, meaning no contractual assurance of how the provider handles the data entered. For patient data, such consumer versions are therefore unsuitable. The data leaves the practice, but no one can say where it goes.


The good news first: the problem is solvable. There are ways for your practice to achieve the same time savings without handing over patient data. More on that later. First, it's worth looking at what actually applies under the law.


There is no AI law — yet AI is already regulated.


A common misconception holds that as long as Switzerland has no AI law, you're operating in a gray area. The opposite is true.


The revised Federal Act on Data Protection (FADP/DSG) has been in force since 1 September 2023; the Federal Data Protection and Information Commissioner (FDPIC) has clarified that it applies directly to AI applications. Anyone using an AI tool with personal data today is therefore not operating in a gray area, but squarely within existing law.


For your practice, there's an added layer: health data counts as sensitive personal data. It's subject to heightened requirements for consent, security, and documentation. On top of that sits the physician's duty of confidentiality under Art. 321 of the Swiss Criminal Code, a violation of which is punishable independently of data protection law.


A dedicated Swiss AI law does not yet exist. A draft bill open for consultation is expected by the end of 2026. The federal government is pursuing a sector-specific approach, and healthcare is among the sectors likely to be addressed first.


What does this mean in practice? Anyone who structures their AI use today in line with the FADP is already meeting the foundation of what's coming. There's no need to retrofit under time pressure later. This isn't a legal box-ticking exercise — it's a plannable head start.


Fines up to CHF 250,000: against you personally, not the practice


When people think of data protection, they tend to think of corporate fines. But the FADP works differently. It provides for fines of up to CHF 250,000, directed at the individual at fault. That's not the practice as a company — it's the responsible person, typically you as the practice owner.

A second legal regime, often overlooked, adds to this: the EU AI Act. It applies extraterritorially and can also capture Swiss operations — for instance, when AI output is used within the EU. Its requirements take effect in stages, with general applicability beginning on 2 August 2026.

One obligation under the AI Act has already applied since 2 February 2025 and affects practically every organization that uses AI: Art. 4 requires deployers of AI systems to ensure their staff's AI literacy. Anyone who provides AI tools to staff, or tolerates their use, should therefore train them in a demonstrable way.


Here too: these obligations are no reason to freeze. They're concrete, well-defined, and achievable on a plannable timeline. A team training session fulfills the literacy obligation. An inventory creates the overview the FADP requires. Both are achievable in weeks, not years.


What a privacy-compliant AI practice actually does differently:


The path to compliant AI use follows three steps in practice. None of them require you to have prior technical knowledge.


First: take stock. Which AI tools does your team already use, officially or unofficially? Answering this question honestly is the single most important step. Experience shows that more is in use than practice management typically assumes. Only once you have that overview can you assess where action is needed.

Second: training. Your team needs to know which data may be used in which tool, and which may not. Structured training eases the common fear of the technology, demonstrates its concrete benefit in daily practice, and simultaneously fulfills the AI literacy obligation under Art. 4 of the AI Act. A legal requirement becomes a double win.

Third: the right architecture for each use case. Differentiation pays off here, not blanket judgments. Cloud AI is not generally prohibited for patient data. Under certain conditions, it's permitted — for example, with a data processing agreement, a verified server location, and clear purpose limitation. For administrative tasks with no patient connection, it's often the pragmatic route.


For sensitive applications, there's a second option: on-premises solutions — AI that runs on a device inside your practice rather than in the cloud. Patient data never leaves the building. These systems work more slowly than cloud services; for many tasks, though, that doesn't matter: a system that processes reports or document categorization overnight is working while you recover for the next working day.


Which route fits which task depends on your processes, not on ideology. That match is exactly what serious advisory work comes down to. If you want to know where your practice stands today and which steps are worth taking first, that's the content of a conversation — not a major project.


The legal situation is clear enough to act now — not only once the next regulatory stage takes effect. What it takes is not an IT department, but an honest inventory, a trained team, and the right solution for your specific workflows.


Ready for a first conversation?


Schedule a no-obligation initial consultation: felber-advisory.ch/en/kontakt. Together, we'll assess what AI use is already happening in your practice, where action is needed, and which next steps will make your daily practice not only privacy-compliant, but also more efficient.


This article provides general information and does not replace individual legal advice.


 
 
 

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
bottom of page