Category: Liability

Revision of the Swiss Data Protection Act: Conference for HCPs

This Thursday 24 October 2019, I will have the pleasure to present the current state of the revision of the Swiss Federal Data Protection Act (DPA), as currently discussed at the Federal Parliament. I will be discussing the consequences for doctors in private practice in a conference organised by FMH Services, at the Hotel Aquatis in Lausanne.

Since the GDPR become enforceable on May 25, 2018, data protection has become a hot topic and an area concern for many sectors, particularly in the healthcare sector. The various actors, whether healthcare institutions or organizations (HCOs), hospitals, clinics or doctors (HCPs), are particularly sensitive to the changes of the legal framework given the sensitivity of the data processed on a daily basis.

The objective of this conference is to review the updates that will likely pass and be introduced by the total revision of the Swiss Data Protection Act. We will discuss the challenges that doctors will face and the recommendations they will need to receive for preparing to the changes. This will be the opportunity to discuss how the GDPR applies to physicians and HCPs, as well as best practices for the use of technologies by doctors as data controllers of health-related personal data.

The revision of the Swiss DPA aims at strengthening the rights of the individuals, in this case patients, and at aligning on the European data privacy standards. We will examine to what extent the revision fulfils this objective.

________________________________

CONSEQUENCES ON THE DAILY PRACTICE OF HCPS

Generally, the daily practice of HCPs will not change drastically with the new Swiss Data Protection Act and the guidance will remain similar for a physician’s practice to the ones already issued by the Commissioner in the past.

In my previous article on outsourcing medical billing, I mentioned what guidance the Federal Commissioner issued in the context of healthcare, which contains exhaustive recommandations, examples and cases studies on security measures at the medical office, outsourcing, guidance on the use of cloud computing and how to respond to patients exercising their access right to medical records. The Federal Commissioner also issued a guidance on how to deal with data privacy generally at the office.

This being said, the major changes for processing of medical information is relating to the use of new technologies, where the risk for medical secrecy and data protection is the highest. This is also true because a very low number of HCPs are prepared to face digital transformation and have little measures in place or best practices for the use of ICTs. This requires an increased vigilance and diligence from health professionals and physicians to avoid being held liable from a civil or a criminal perspective.

Therefore, security and the application of data privacy principles of patient data at the medical office remains essential because of the increased risks associated with the use of information systems, social media, cloud computing, telemedicine and other similar technologies. In this context, all previous recommendations of the Federal Commissioner remain valid (see below) and must be followed, as must those issued by the Code of Ethics of the Swiss Federation of Physicians.

It should be noted that risks increase with the use of telemedicine systems and unsecured means of communication, as well as in the case of outsourcing (subcontracting) of services, such as invoicing or secretarial services.

________________________________

FINES IMPOSED ON HOSPITALS AND DOCTORS UNDER THE GDPR

In Europe, we have already seen hospitals sentenced by data protection authorities to administrative penalties of several hundred thousand euros.

Since the implementation of the GDPR, most breaches have consisted of deficiencies in appropriate security measures to protect patient data. Similarly, the violation of the duty to set up controls for the rights of access to the same data in patient files has often been the cause of sanctions and breaches by health institutions.

In this respect, the following European decisions are worth mentioning:

  • Portugal: my previous article and comments on the € 400,000.- fine imposed to a Portuguese hospital. Note that in this article, I also discuss other major fines under the GDPR (equifax, Cambridge Analytica) and the very first fine (ICANN) under the GDPR, as well the situation of Swiss hospitals with regard to privacy and data protection and some elements of the current revision of the Swiss Data Protection Act;
  • Pays-Bas: € 460,000 fine imposed to Haga Hospital (Netherlands) for allowing non-authorized access to employees and third parties to the medical record of a local celebrity. The fine was imposed as a result of inapropriate security measures, especially a weak access control mechanisms (art. 32 GDPR) with no double-factor authentication, which was considered the “ABC” of security;
  • Cyprus: € 14,000 imposed to a doctor for publishing health-related information of a patient on Instagram, mentioning the name of the patient without her consent. After investigations, the Data Protection Commissioner of Cyprus also imposed a €5,000 fine to the hospital for not being able to recover the medical record of the patient following an access request.

These examples demonstrate the importance of privacy and security compliance and data protection principles. Those basic principles have to be applied in medical offices and hospitals. Also to guarantee a good control over personal data, it is crucial to apply the principle of privacy-by-design, implement a complete data protection and management program for all types of health actors.

This should include training, rules of conduct for employees and managers, access controls, as well as appropriate organizational and technical measures to avoid data breaches, unauthorized access to personal data, data losses, alteration, and other violations protection. It also remains key, even for micro enterprise and medical offices to have an action plan in the event of a data breach in order to notify the authorities or the patient if necessary. Given those challenges, a light version of an data protection officer (external) would be welcome.

Even if the legal regime of the Swiss DPA will differ from the European sanctions under the GDPR (2% – 4% of the global turnover or €10 – €20 million), these basic rules and principles are essential and must be respected in order. This is key to avoid civil or criminal liability for violation of the Data Protection Act. Also, where applicable, such behavior may infringe the Criminal Code (Art. 321) for violation of medical secrecy.

Now, the Swiss sanctions system only offers the possibility for individuals to initiate a civiel or a criminal proceedings for violation of the Federal Data Protection Act. The maximum penalties amount to CHF 10k. However, the plan with the revision is to increase the level of criminal fine up to CHF 250,000 maximum. This still remains a criminal fine, based on a criminal trial initiated by a plaintiff or a data subject, where the individual will be held liable, excepting the data controller that cannot receive any direct administrative sanction from the Swiss authority.

Find my other articles relating to healthcare:

  • Article on the outsourcing of medical data
  • Non-economic physicians and the consequences of overbilling (in French: “polypragmasie”, in German “Überarztung”)
  • Videoconference: software and medical devices regulation
  • Conference on telemedicine

Google fined €50M by the CNIL under the GDPR

This 21 January 2019, the French data protection supervisory authority (Commission Nationale de l’Informatique et des Libertés – the “CNIL“) fined Google LLC 50 million Euros for breach of the General Data Protection Regulation (the “GDPR“).

In today’s communication (in French), the French authority issued the highest fine against Google LLC since 25 May 2018 considering severe infringements of the GDPR by Google for failing to inform properly the users and collecting valid consent for targeted advertising services.

SCOPE OF THIS DECISION. It is worth noting that this decision is solely based on investigations of the CNIL related to configuration of new Android device for the first time by a user. This particular infringement of the GDPR only relates to the privacy notice displayed to users when they create an account and when logging into their new Android phone. However, the full complaint has not yet been examined by the CNIL and goes far beyond that. The complete case is much broader and related to targeted advertising on Youtube, Gmail and Google Search platforms. The CNIL will have to examine how Google may have or not “forced” users to consent to sharing their personal data via Google targeted ads services. So we can expect to hear more from the CNIL in the upcoming months in this case. This is probably only the beginning of a long series for 2019. The two organizations also filed (as explained below) similar complaints against other GAFAM in several jurisdictions.

________________________________

FINDINGS OF THE CNIL

The CNIL considered that Google did not comply with the GDPR for three main reasons: (1) lack of transparency (art. 5 GDPR); (2) insufficient information (art. 12 and 13 GDPR); and (3) invalid consent collection (art. 7 GDPR).  The two complaints were brought by Max Schrems’ non-profit organization called “None Of Your Business” (NOYB) and the association La Quadrature du Net, a French association that regrouped complaints from 9’974 individuals. Those two organizations claimed that Google’ services, including the targeted advertising services on Android OS, did not comply with its obligation to process personal data with the proper legal basis (art. 6 GDPR), forcing users to share massive amount of personal data and therefore compromising their privacy without their consent.

Those complaints have just been confirmed by the CNIL in today’s findings. After that, it is interesting to read on the blog of NOYB, that Google will move its EU headquarters to Ireland with effect to 22 January 2019, with the Irish DPA (Data Protection Authority) as the lead authority.

The French authority adds some interesting considerations to its findings. The CNIL explains that with Google current services, due to the way the data are collected, the volume that can be processed and the type of data collected through those services, it can result in revealing entire parts of someone’s life, which becomes very intrusive. The CNIL also considered the fact that Google’s business model is partially based on those intrusive services.

Finally, the CNIL explains that, essentially, despite Google’s efforts to change its processes, Google is still not compliant. This also means that as long as Google remains non compliant, it may face other complaints and, potentially other fines unless the way Google processes data about individuals changes drastically.

________________________________

HISTORY OF THE CASE

Two massive complaints on 25 and 28 May 2018 for € 7,6 bn

25 May 2018. Max Schrems – the Austrian privacy advocate who provoked the cancellation of the Safe Harbor framework by the European Court of Justice (see judgement here) – founded a not profit organization called “None Of Your Business” (NOYB) to support consumers and data subjects in filing complaints against companies and to authorities to enforce and protect their privacy. Just the day the GDPR became enforceable on 25 May 2018,  Max Schrems sued Instagram (Belgium), WhatsApp (Hamburg, Facebook (Austria) and Android (France) with a massive complaint amounting to € 7,6 bn via its NGO for infringement of the GDPR. Find more details on NOYB’s website here.

28 May 2018. The French Digital Rights Group “La Quadrature du Net” lodged a complaint on 28 May 2018 against Google, Apple, Facebook, Amazon and LinkedIn in front of the CNIL on the behalf of 12,000 individuals for illegal processing of personal data.

The CNIL’s sanction of € 50 millions issued today is only one sanction against one company – Google LLC – and in one juridiction. There is most likely other sanctions to come if other authorities follow the CNIL’s argumentations and considerations.

In terms of procedure, Google can appeal to this sanction and contest the fine (edit 24-janv-2019), which the company announced publicly. Even if the fine remains low compared to the €4bn it can incur in the event of a maximum fine, the amount is high for this case. In its public statement, Google said:

We´ve worked hard to create a GDPR consent process for personalised ads that is as transparent and straightforward as possible, based on regulatory guidance and user experience testing

By appealing against this decision, Google wants initiates the process of a precedent in interpreting the GDPR’s requirements on information, transparency and how to validly obtain consent, particularly in the area of targeted advertising.

Google’s appeal is therefore highly strategic. Not contesting this fine would create room for potential more severe sanctions, especially as the scope of the case is limited. In addition, it could be seen as an indirect acknowledgment of responsibility for using non-compliant practices.

Finally, Google defends itself by arguing that it has worked hard to set up data collection in order to respect transparency, but also said:

We´re also concerned about the impact of this ruling on publishers, original content creators and tech companies in Europe and beyond

We will see if his work has been sufficient or not and how strong this EU Regulation can effectively be in practice.

________________________________

THE CASE IN MORE DETAILS

To get into more details, the CNIL provides the following explanations to justify the sanction against Google:

  • Breach of transparency: the transparency principle refers to how you inform individuals about the processing activities. This usually takes the form of privacy notices. This information is supposed to remain concise, clear, accessible, unambiguous and intelligible by any person.

This was not really the case. Google spread all that information in many separate places through links and buttons which made it very difficult to access, understand and takes ages. At the end, all that information was only accessible after 5 or 6 actions, in any case after several steps to know what data are collected about the individual. The information was not clear enough, vague and described in a too generic way. That means that if nobody takes the time to read that information (why would Google collect your data for what purpose, for how long, what categories of data are used for the targeted advertising, etc.), the obligation of having a clear and easily accessible notice is not achieved. Also, Google failed to inform about the retention period of certain personal data (for how long will Google keep that data).

  • Invalid consent: Google requested the consent of the users to collect the personal data. However, the CNIL considered that this legal basis was not valid for the options of customized advertising for the two following main reasons:

The consent was not informed. This means that users do not understand the scope of use of the data. For example, in the “customized publicity” section, it is not possible to see how many services, sites and applications are related to the processing and there is no information about the volume of personal data that those services will process and combine.

The consent was not specific, nor unambiguous despite the fact that users may have the ability to select several parameters. According to article 7 of the GDPR:

request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language

With Google targeted advertising services and options, the users could only access those parameters by clicking “more options”. Also, the option to use “targeted advertising” was already pre-ticked, which forces the user to turn it off. So the option will remain active, if the user does nothing, unless there is an active action from the user to disable the option. Therefore, using pre-ticked boxes is contrary to the principle of privacy by default (art. 25 GDPR), which requires to turn off any settings or parameters by default to apply a maximum protection of privacy to the user. It is only up to the user to decide whether he or she wishes to increase the level of intrusiveness to his or her privacy and agree to share any personal data. Finally, Google only provided one box for the users to click which appeared like this:

“I accept Google’s terms and conditions” and “I accept that my data are used as described above and as detailed in the privacy policy”

Such bundled consent, which is not specific and do not provide any details for each purpose is not compliant with the requirements as set out in the GDPR.  Where several purposes for processing personal data exist, users must have the ability to only consent to those purposes that they wish. Having all the purposes all-in-one, does not work under the GDPR.

________________________________

ARE THOSE REQUIREMENTS NEW UNDER THE GDPR?

Yes and no.

Yes, the requirements to collect a valid consent has been extensively strengthened. It not as easy as before to collect a valid consent and as this case demonstrates, there are individuals and authorities out there that can have a word and ultimately impose fines to your organization.

No,  the principles of consent, collecting personal data with a valid legal basis and informing the individuals via privacy notice, are not new from an EU data protection legislation. The obligation to process personal data with a lawful ground already existed under Directive 95/46/EC and also applies under the Swiss Federal Data Protection Act (DPA), as probably in most of the jurisdiction that have adopted comprehensive data protection framework. A company responsible for collecting and processing personal data has to justify a valid legal reason. As a reminder, the GDPR offers 6 different legal bases to justify the processing of personal data (article 6 GDPR), which are:

  • consent;
  • performance of a contract;
  • compliance with a legal obligation;
  • protect the vital interests of natural persons;
  • performance of a task carried out in the public interest or in the exercise of official authority; and
  • legitimate interest.

Each of those legal bases have their pros and cons, but where you use the consent, you should remain careful to collect it lawfully, unless the processing becomes illegal. With the GDPR, the consent has become much more difficult to obtain. In particular, you need to inform and explain who shall consent, what you will do with that data, for what reasons and based on what legal basis you process the data, with whom you will share them. And this shall apply for each purpose. If those conditions are not, the consent is not valid illicit and you cannot process the personal data.

And this is what happened to Google LLC in the case of targeted advertising, for this first part of the story.

________________________________

By Gabriel Avigdor | ICT.ch 

Digital Lawyer

GDPR: Portuguese hospital fined €400k for bad access controls to patient data | ICT

Portugal initiates fines under the GDPR in the EU. The data protection supervisory authority (Comissão Nacional de Proteção de Dados) issued a €400k fine against a hospital for three infringements of the GDPR. This article is the opportunity to analyse two elements:

  • looking back at a few important decisions and ruling that we have seen since 25 May 2018; and
  • understand what is the current situation with Swiss hospitals from a privacy perspective.

_____________________

BAD MANAGEMENT OF ACCESS CONTROLS TO PATIENT DATABASE 

According to the press, the “Hospitalar Barreiro-Montijo” in Portugal received a €400,000 fine from the Portuguese supervisory authority for three different violations of the EU General Data Protection Regulation:

  1. Infringement of integrity and confidentiality of the data: €150,000.- ;
  2. Infringement of access limitation (access rights management): €150,000 ; and
  3. Unable to ensure integrity of the data by the hospital (data controller): €100,000

After an investigation, the CNPD assessed that the hospital’s staff, as well as psychologists, dietitians and other professionals had access to patient data via false profiles. Those accesses included members of the administrative personnel of the hospital, which were normally to be used by physicians only. In the news, we can read that

while 985 doctors had clearance for accessing patient files although the hospital only hired 296 doctors, non healthcare professionals could also access patient data.

This case started after an association of doctors reported the facts to the CNPD in June 2018. The decision from the CNPD has not been made public yet, and references can be found in this local article and here (in Portuguese).

As detailed in my last article on GDPR readiness in EU countries, Portugal has not implemented the GDPR yet. However, the fine was calculated and assessed pursuant to Regulation (EU) 2016/679 that is now applicable and enforceable. The hospital has contested the decision.

_____________________

REMINDER: NOT EVERY DECISION ISSUED AFTER 25 MAY 2018 ARE ANALYZED UNDER THE GDPR

After 25 May 2018, we have already seen a few important decisions from supervisory authorities and courts. The vast majority of them related to facts that data controllers or processors did before Regulation (EU) 2016/679 (GDPR) became enforceable.

As a reminder, it is worth noting that the GDPR applies worldwide, but only as of 25 May 2018. It applies to processing by processors of personal data (private and public), wherever they are located, to the extent it relates to individuals that are located within the EU. Citizenship is not relevant to assess the extraterritorial reach of this EU Privacy law. The principle of non-retroactivity of the laws applies and facts that are older than 25 May 2018 would trigger the local data protection legislation for any investigation. The famous 2% -€10M / 4% – €20M shall therefore not apply. In Europe, Directive EU 95/46/CEE on the protection of individuals with regard to the processing of personal data and on the free movement of such data governed data protection as a framework, which the 28 EU countries have implemented into their local laws.

Beware, many articles on the Internet explain that fines were imposed in 2018 according to the GDPR, which is probably not exact. So verify when the facts are dated.

_____________________

 

TWO IMPORTANT DECISIONS AFTER 25 MAY 2018, BUT NOT PURSUANT TO THE GDPR

Two important decisions are worth noting in the context of the previous legal regime (Directive 95/46/CE) even though it was published after the GDPR:

The Equifax case

2017 was a bad year with 23 cyberattacks reported. But it became worse with the Equifax scandal.

In September 2017, the Equifax scandal became public with cybercriminals who stole Equifax Inc. credit card data. While the cyberattack happened in the USA, the case impacted over 145 millions customers’ credit card data, and around 15 millions citizens in the UK. The UK Information Commissioner’s Office (ICO) imposed the maximum fine of £500,00 to Equifax Ltd, for breach of the UK data protection legislation. While the ICO issued this decision in September 2018, the facts dated back 2017. The bad thing is that Equifax knew about the hack more than a month before they reported it.

In this case, Equifax failed to implement and maintain appropriate organizational and technical measures to prevent unauthorized access to the data (equivalent to article 32 of the GDPR). The ICO considered the infringement as particularly high due to the sensitive aspects of credit card data and the fact that it has impacted so many individuals. In this decision, the ICO considered that the retention period of the credit card data was too long.

Under the GDPR, failing to comply with article 32 (appropriate technical and organizational measures – ATOM) may lead to a 2% fine according to article 83 §4 (a) GDPR. This is the same for not complying with the privacy by design obligation, which includes the obligation to only keep the data for as long as necessary for the purpose of the processing (art. 25 and 83 §4 (a)). Therefore, and to the extent the sanction by the ICO may have been assessed under the same criteria as under the GDPR, the fine may have been around £20.87 millions, instead of £500,000.

Cambridge Analytica case

On 24 October 2018, Facebook Ireland Ltd was fined the highest possible fine under UK privacy law by the British Information Commissioner’s Office. This decision, although taken in October 2018, related to facts prior to 25 May 2018.

In this decision, Facebook was fined £500,000 for failing to ensure the security of its users’ data. In this scandal, Cambridge Analytica misled Facebook users by collecting survey data to analyze user behavior and influence their voting intentions, which may have been used for the US elections during the Donald Trump campaign. It is also likely that such methods have been used in previous campaigns in the United States, such as the election of Barack Obama.

Facebook had failed to protect its users by not putting in place appropriate security measures. Cambridge Analitica, through its surveys, had been able to obtain access to the user profiles, but also to the profiles of the “Facebook friends” of the people participating in the survey, although these people did not know this and could not consent to or be informed of this.

If the sanction had been imposed under the GDPR, and provided that the same application criteria had been used, the maximum fine of 4% would have been of a different magnitude. Indeed, if we take the Facebook group’s net annual turnover in 2017 (2018 not yet known), i.e. excluding taxes, and compare the exchange rate on 31 December 2017 between EUR and GBP, the fine could have amounted to some £471.64 million. This would represent an increase of +943% over the fine imposed by the ICO in the United Kingdom

* * *

Uber data breach in 2016

One last case for those who still doubt that supervisory authorities will fine companies for breach of data protection or if data protection is not important at least for keeping a good reputation.

A press release dated 27 November 2018 from the Dutch supervisory authority showed that Uber was fined € 600k for breach of the Dutch data protection legislation after the famous cyber attack, in which Uber failed to report the breach within the deadline of 72 hours. The data breach affected 57 million Uber users worldwide, and concerned 174,000 Dutch citizens. Amongst the data were names, e-mail addresses and telephone numbers of customers and drivers.

Not only Uber failed to report the breach, but Uber also paid off hackers to hide the massive data breach for a period of one year. According to CNBC and the NY Times, Uber agreed to pay $158 million to settle claims related the data breach in the United States of America, but was also fined in the UK for £385,000.

Finally it is worth noting that, while there may be one authority issuing a fine in one country, each supervisory may be competent to issue a fine separately for each jurisdiction in which data subjects may be affected and suffered from the data breach. This may become a nightmare for companies that will have to deal with lawsuits in many jurisdictions and appealing in potentially all 28 (27?) EU countries.

_____________________

WHAT IS THE FIRST DECISION UNDER THE GDPR?


On 29 May 2018, an important German decision opposed ICANN vs EPAG. This case was about “Whois data”, i.e. the personal data of domain name holders, where such data was collected and made publicly available. The company “Registrar EPAG Domainservices GmbH”, a German company accredited by the ICANN for domain name registrations (Registrars) was in dispute against the ICANN. In this case, the question was about whether contact data – that were published online by the registrar when registering domain names (Admin-C and Technical-C) – should necessarily be collected.

Analyzing the situation under art. 5 (1) letter c) of the GDPR, the German court considered that it was not mandatory to collect that data. Therefore, the EPAG did not have any obligation to collect this data so that no one could force EPAG to do so.

The consequence of this decision is quite significant. For years, many online providers have asked clients to pay for not appearing as the owner of the website (such as “whois guard service“), in order to remain anonymous. Now that there is no obligation to collect this data, paid services would no longer be necessary, making them obsolete or even illegal. We now see agencies offering “free” anonymisation of contact data from the site owner to their customers. Some agencies even use this as a marketing argument, while there is no legal obligation to publish that data.


WHAT ABOUT SWISS HOSPITALS?

The vast majority of – if not all – Swiss public hospitals and private clinics are not subject to the GDPR.

Why?

The reason is that those healthcare institutions generally do not have any establishments in the EU or EU presence. In addition, they usually do not offer goods and services to patients located in the EU, nor do they monitor the behaviour of data subjects in the EU, where the processing is happening in the EU.

There is still a need to remain cautious. This is not because European fines under the GDPR cannot affect Swiss hospitals that the risks are low. On the contrary.

In my article where I analyzed the cyber attack and theft of data of 800,000 customers from Swisscom, the absence of serious data protection legislation (with sanctions that have a preventive and dissuasive effect) does not encourage data controllers to protect the data of Swiss citizens and patients. Many recent cases have shown that hospitals have become a prime target for cyber attacks, particularly due to the high value of health data which are highly sensitive and the fact that adequate security measures are expensive and time-consuming to implement.

This report show that medical data provides access to a wide range of information for various fraudulent uses:

  • American Hospital Association document on hospital attacks;
  • Anthem – historical record of data theft involving more than 80 million patients and employees.

Ransomware have become commonplace, and human errors are the biggest cause of security breaches. In an environment with so many transitions, staff changes, 24-hour activities, access to patient and confidential data, it requires strict control over access and constant training of employees at all hierarchical levels. It is not surprising that many hospitals are subject to investigations and sanctions by data protection authorities.

________

WHAT ABOUT SWISS PRIVACY?

The draft revision of the Swiss Data Protection Act (DPA) is still pending in the federal Parliament. The law will sooner or later be finalized and will enter into force with very broad alignment with the GDPR.

Talking about the fines, the status of the draft bill still doesn’t address the same mechanism for the sanction regime as there is no plan to give the Commissioner with powers to impose administrative fines. The fines may be imposed through criminal proceedings, where an individual may be held liable instead of the company. As compared to the actual fines for violation of the Swiss DPA that are ridiculously low, the amount of criminal fines will still get higher than today with a maximum of CHF 250k.

In addition, incidents will have to be reported (which is not the case today), DPIA (data protection impact assessments) will become compulsory for processing that are at risk, in certain cases the controller shall record the processing and document it, consent requirements will become stronger, and so on.

With this in mind and the upcoming changes in the Swiss privacy framework, which will probably not become in force before 2021, it remains essential for Swiss healthcare professionals and institutions – as well as any Swiss companies, to prepare for the revision of the Swiss DPA. Swiss companies are highly advised to learn from what is happening with he European framework (GDPR) and prepare for the next years to come.

By Gabriel Avigdor | NTIC.ch

If you are looking for legal advice relating to privacy whether related to the GDPR or the current or upcoming Swiss DPA, we offer services to support you towards compliance. You can contact me directly or visit our new online platform datalex.ch for more information.

Outsourcing medical billing: a matter of transparency

What is required when outsourcing medical invoices to a third party?

_______________________________________________

In healthcare, it is frequent for medical professionals and health institutions to outsource medical billing to a third party. There are many financial and practical advantages to subcontract such service. First, outsourcing can increase efficiency, by reducing the cost of performing these kinds of tasks by the employees. Therefore, it saves work spaces and it is cost-effective, as the service is provided by experts within a company specialized in this area. Second, the responsibility and the costs for investing in this service, the employees’ management, staff training and keeping these skills up to date, are borne by the third party. Finally, one can expect regular reporting services and cooperation from the third party as part of the deal.

Where outsourcing contains many advantages, medical billing must comply with legal obligations, in particular with medical secrecy and data protection regulations, especially if the third party wishes to use the data for another purpose than medical billing. This would be the case if the personal health-related data are used for the supplier’s benefit (such as creating its own creditors and debtors database), or for the benefit of third parties (e.g.: selling the data to insurance companies).

Transferring health data of patients to a third party can infringe medical secrecy and data protection regulations. If the data are not used for the same purpose as for medical invoicing, the Swiss Criminal code (art. 321), the Swiss Federal Data Protection Act (DPA), and cantonal laws protect the medical secrecy by prohibiting undue disclosure without express consent of the patient.

Infringements observed by the Swiss Federal Commissioner

_______________________________________________

The Federal Data Protection and Information Commissioner (FDPIC) recently osbserved that third parties specialized in medical billing are using health data of patients to:

  • create their own database with individual’s solvency to categorize them; and
  • sell the data to third parties (such as health insurances).

According the FDPIC, healthcare professionals must reinforce their obligation to comply with transparency, which he states as follows:

Where healthcare professionals outsource medical billing services to third parties, they shall remain precise and draw attention of the individuals in a clear manner to where and to whom the data would be transferred, and for what purpose the supplier may process such data. This includes in particular using such health-related data to create unrelated databases and potential sales to third parties. In order to comply with this obligation, the healthcare professionals must get the individuals’ express consent“.

Medical secrecy and explicit consent

From a legal perspective, medical personal data – meaning health-related data from an identified or an identifiable individual – are sensitive data. This special category of personal data requires to get the patient’s explicit consent before the processing (art. 4 § 5 DPA), in writing , and before a transfer to a third party for another purpose than for medical invoicing. Therefore, it would be illegal to transfer and use of such data for another purpose without a valid written consent.

This practice complies with both art. 321 of the Swiss Criminal code and art. 10a § 1 let. b of the DPA to the extent the owner of the secret has released the health professional from the medical secrecy.

How do I draft my privacy clause in an outsourcing contract?

_______________________________________________

Among the other contract clauses which are specific to the outsourcing agreement, the contract should at least contain the following:

For outsourcing in Switzerland:

  • a reference to the relevant DPA provisions;
  • a warranty from the billing company to comply with the DPA provisions;
  • a warranty of fulfilment of data protection claims of data subjects;
  • the prior consent of the data controller (health professionals) if the data processor decides to subcontract the service;
  • describe the purpose for the processing of the data;
  • an obligation for the employees, auxiliary personnel, freelancers etc. of the processor to comply with the DPA provisions;
  • an obligation for the data processor to comply with data security obligations;

For cross-border transfers to the third party:

  • If permitted by national law to transfer to a third party based in another country, include a provision to regulate cross-border transfers. If personal data are processed (accessed or transferred) in a country without a sufficient protection level for the processing, the data protection clause shall at least include:
    • an obligation to enter into standard contractual clauses, such as the C2P EU model clauses (or privacy shield, or Swiss transborder data flow agreement);
    • an obligation for the data processor to enter into such standard model clauses with its affiliates located in countries without an adequate protection level;
    • an obligation or the data processor to inform the data controller prior the transfer if the data are being subcontracted, including a right to object, and provide information to the controller about the subprocessors (identity, location) and engage the subprocessor with a contract containing the same level of contractual obligations.
  • For the Swiss Federal commissioner, Swiss Doctor should not allow a third party outside Switzerland to access medical records. If so, the Doctor may infringe medical secrecy which is protected by the Swiss Criminal code and by the DPA.

Practical recommendations

_______________________________________________

According to the FDPIC, it is not sufficient to inform the patient of such processing somewhere in the medical office, or a waiting room. Nor would it be sufficient to add a clause in small letters in a medical consent form. To comply with transparency, the patient shall receive a proper information to allow – or not – the processing on the basis of a written consent. The patient shall do this without any pressure of any kind.

This short note of the FDPIC reinforces the principle of transparency of the processing.

For the patients

This memo is a call for reinforcement of transparency in the healthcare sector. It explains that more supervision will occur in the future in that particular area to protect the individuals’ right to privacy, and from an undue processing when third parties wish to use the data for their own benefit.

As consent is required, the patient may withdraw its consent at any time. In such event, healthcare professionals and any third party using the data will have to stop using them and potentially delete them to comply with the patient’s request.

For healthcare professionals and hospitals

The principle of transparency, which comes from privacy regulations is not new. It is protected by the non-disclosure obligation for healthcare professionals relating to medical secrecy. But even with the consent to disclose medical information, privacy regulations do not allow anyone to use any personal data for whatever purpose. It would be a breach of the DPA and the processing would become illegal.

In practice, doctors and hospitals shall duly inform the patient to allow him/her to validly consent to sharing medical information for other purposes than for medical billing.

The service provider being a data processor, it has to comply with all the data controller (doctors and healthcare professionals) instructions and requirements, and is responsible for the processing, and to comply with the DPA.

To remain cautious, heathcare professionals should ensure that:

with regard to the service provider:

  • it does not use the data for other purposes than for medical billing;
  • it will comply with privacy regulations, as well as medical secrecy, as the service provider is not bound by medical secrecy;
  • include a paragraph for get the data back at any time, at no costs;
  • for cloud computing purposes, use only service providers based in Switzerland, and draft a contractual clause to prohibit any transfer of such data to a subcontractor or a third party outside Switzerland

with regard to the patient:

  • update the consent forms and add a clear clause – separated from medical related acts – to draw the patient’s attention that the processing may be done for other purposes than medical being (and explain which ones);
  • if the data may be used for other purposes than for medical billing:
    • get the consent after having duly informed the patient and before to process the data; or
    • inform the patient of such transfer in order for the patient to give or withdraw its consent on the processing.

For service providers

The Commissioner has not given its opinion on the supplier’s civil responsibility towards the patient for undue processing, or medical secrecy infringement, or both.

In order to protect the service provider for using the data for other purposes than medical billing, it may perform the following:

  • anonymize the data, whichever it will use the data for its own use or to sell the data to third parties. In this case, medical secrecy and privacy laws will not apply;
  • clarify with healthcare professionals for what other purposes it wishes to use the data;
  • request healthcare professionals to ensure, in the outsourcing agreement, that the patient has been informed of the processing validly given its consent to the processing;
  • include a specific exclusion of liability in case of a third party claim (for medical secrecy of privacy infringement);
  • add an indemnification clause for losses it may incur as a result of the breach of privacy laws or medical secrecy.

To go further, see the following notes on the website of the Swiss Federal Commissioner:

  • This note in French, German or Italian on outsourcing in the context of healthcare
  • This note in French, German or Italian on the use of service providers for keeping medical records in the cloud
  • This note in French, German or Italian on security in medical offices
  • Guide on processing of personal data in the context of healthcare

Gabriel Avigdor | NTIC.ch

Drone

Drone regulation : compared case study under US and Swiss laws !

INTRODUCTION

What is a drone and what does it do? Drones are those little guided quadcopters (also called FPV drones for ‘First Person View’) that we can find in the FNAC or in Xtreme sport videos on Youtube. They can be used for civil (private, commercial or humanitarian) or military purposes. We do not realize that they will invade our low sky and replace lots of current tools. As examples, drones can be used for:

  • Delivery services for food or commercial and private mail: With its Prime Air program, Amazon announced an estimated time of delivery of max 30 minutes. The Swiss e-commerce company Qoqa has taken the lead on Swiss market of delivery by drones with a test phase for the first time in Switzerland called FlypaQ.
  • Mapping and modelling like the Swiss company Pix4D with its mapping software that is able to create 3D modelling from 2D pictures.
  • Fun and hobbies, like personal video recording, sport even and cinema. Autonomous drones used during sport activities are very popular as shown by the French start-up Hexo+. In Hollywood, the FAA authorized film producers to use drones for film shooting. Cameramen are being replaced by these drones to record scenes in the air or for car chase, which offers original angles of view. Skyfall, the Wolf of Wall Street or Harry Potter and the secret chamber contain scenes that have been shot via such drones.
  • Observation, surveillance private or public, like locating or tracking people being pursued or surveillance of events by the police for Euro2016.
  • For humanitarian or rescue purposes especially in area difficult to access or for sending food, medics, give logistics support when a natural disaster happens, etc.
  • For military purposes, to attack specific targets, to defend, track or identify, spy or watch civil zones …

 

Ideas are not missing. From an economical point of view, there is a huge market growing up for the manufacturing, repair industry and for a bigger part software companies providing specialized software and mobile applications.

Disadvantages and risks. Potential often rhymes with risks. One can argue that not everyone owns a beautiful villa with a garden and a playground where the drone can land easily to deliver a new pair of shoes like in the sympathetic, but naive trailer of Prime Air drones of Amazon…How to deal with the lambda citizens living in buildings in the cities? Will there be landing points in the city to avoid a delivered package to be stolen? In addition, with 4K UHD cameras, video surveillance will cause problems related to privacy for individuals. The Swiss Federal Data Protection Commissioner (the Swiss Commissioner), published a note on this particular matter. Furthermore, as drones are either guided or autonomous flying vehicles with a certain weight, they may collide with flying objects (or animal) or with people on the ground. Liability issues will then occur as incident risks are real. This has already been demonstrated by the recent crash of a drone with a passenger aeroplane from the company British Airways just before landing at London Heathrow airport on April 18th, 2016. From a noice perspective, it would be easy to imagine that a sky overloaded with drones would cause damage to the environment as well as to the residents. Animal welfare organizations will likely mobilize for the cause. Even worse, one can imagine drones to be hijacked, hacked, but also used for terrorist purposes. Maybe there is here a threat that shall not be underestimated…

Future will tell us.

____________________________

PART I

DRONE REGULATION IN THE USA – CASE STUDY

Producers of TV series are very creative to elaborate original and fun scenarios related to new technologies, especially when interpretation of the law remains uncertain. One of the latest episodes (S07e18) of the excellent TV show The Good Wife, created by Ridley Scott, is a story about a surveillance drone flying above a neighbourhood recording the area for potential crime that may be committed, which disturbs one of the residents. The litigation is divided in three acts like a case study for law students or cases for bar admission exam.

ACTE 1. The owner of the drone is a private organism that seeks to record acts of crime in the neighbourhood. The drone prototype flies several times a day and randomly over the houses, recording the streets and the houses, which means people that may be inside or outside their house. The fact is that on resident isn’t happy because, as a therapist, he practices at home and his patients are filmed from the air when they come for an appointment. The therapist takes legal action against the owner of the drone for violation of his private life, especially because the drone can film people that even appear through the windows of the house that have not given their consent. He also considers the drone responsible for a loss of patients and claim for compensation damages in an amount of USD 300,000 with a prohibition for the drone to fly again.

Arguments: The therapist alleges a violation of his private life based on the common law principle of “intrusion upon seclusion“, but loses the trial. Under first amendment of the US constitution, the right for the owner of the drone and the interest of all other neighbours to prevent acts of crimes by air surveillance wins against the privacy rights and the drone can fly!

______________________________________

FLY AGAIN OVER MY PROPERTY AND I WILL SHOOT YOUR DRONE !

ACTE 2. The drone continues to fly over the houses and the drone camera record the therapist taking his shotgun and destroys the drone while flying over his property. This time, the owner of the drone takes legal action against the therapist and asks for compensatory damages to get reimbursed of the value of the drone, which is an USD 80,000 prototype. In addition, the owner claims for USD 10,000 punitive damages as well as a prohibition for the therapist to shoot any drone that would fly over the houses.

Arguments: The therapist alleges that he shot the drone because he felt threatened. He argues that the drone was shot to repel a potential attack. His counsellors plead the “Castle doctrine“, created in 1628, which is a common law principle for legitimate defence specific to the property. Under this doctrine, a landlord can repel an imminent attack when there is a legitimate threat of an intrusion in his property or the house. As the judge considers that this situation does not constitute a reasonable fear/threat, he requires the lawyers to prove it. Therefore, the counsellors call a drone expert, who presents to the Court a video with civil and military drones showing that it is almost impossible to make the difference between civil drones and combat drones. We can also see that drone technology allows to capture infrared or heat detection images and that some other drones can feature connected technologies that can hack a computer from the air and can steal the landlord’s personal data. In reference to the castle doctrine, the expert concludes that a drone can be an intruder in the house without physically penetrating it resulting in a violation of the therapist’s property and privacy.

Despite those efforts, the drone owner wins this second act. The recording shows that, at the moment the therapist shot the drone, it was not flying in a stationary mode, but rather flying away the propertym which means he was “retreating”. In such case, the castle doctrine is not applicable to retreating because it is strictly prohibited to shoot in the back…

____________________________

THE SKY IS ALSO MY PROPERTY, RIGHT?

ACTE 3. The final act intend to solve altitude issues related to unmanned aircraft systems. Basically, the question is to know whether the drone was still flying in the jurisdiction of the FAA (Federal Aviation Administration) when flying over the property of the therapist or not. As the drone was shot at a 200 feet altitude (60m), the Court must determine whether the federal rules of FAA still apply or if the case is governed by the rules of private property.

Arguments: The chief legal counsel of the FAA (from the enforcement and compliance division) is called to inform the Court whether it is legal or not to shoot an unmanned aircraft in this area of space. The legal counsel explains that between 0 and 500 feet (150m), there is a zone  called “Classe G” that does not fall under the FAA’s jurisdiction.  According to the therapist’s lawyers, it would be illegal to shoot a drone over 500 feet, but totally legal under.

The attorney of the owner of the drone, plead the US vs Causby case. In this case, military planes from the military airport where making a lot of noise in addition to flies over Mr Causby’s property. This situation caused a severe damage to Mr Causby’s, which forced him to abandon his business. Actually, the planes were flying at an altitude of 83 feet (25m) above the farm which led the chicken to jump over the wall killing themselves. This case refers to an old Roman law principle “Usque ad sideras et usque ad inferos”  which inspired the common law principle of “from the depths to the heavens” related to vertical property. In Causby’s case, which he won, the limit of the vertical property was set at 83 feet. Thus, 200 feet (60m) is above 83 feet, which means the therapist was not entitled to shoot the drone that wasn’t flying over the space of his property. On that question, the lawyer of the FAA considers that between 83 and 500 feet, the regulation never said anything. The judge then considers that, in this case, the law is not adapted to technologies and rules in favour of the owner of the drone confirming Causby’s case.

This funny episode proves that, at least in the USA, one can play with the law and imagine scenarios that may be solved in such manner. The solution of such litigation may be based on very old case law related to airplanes frightening chicken, which may be inappropriate, but applicable to drones…

This first part only offers a summary of a TV show for further discussions. In no event shall this constitute a legal opinion under US law. For further information under US Law related to drones, this legal blog provides very detailed information and is only dedicated to the applicable regulation and rules of drones in the USA.

____________________________

PART II

DRONE REGULATION IN SWITZERLAND

What is the regulation in Switzerland and how would a Swiss Court rule this case ?

In Switzerland, unmanned aircrafts systems are regulated by the Federal Office of civil aviation (FOCA). It is governed by the Swiss Federal Act related to Aviation (LA) and the Federal Ordinance about special category aircrafts (OACS). “Air rules” also supplements this regulation with EU law related to the maximum flying altitude. Because of the developments of the civil drones market, FOCA recently amended its Ordinance and gave some guidance. From a legal perspective, drones are mostly remotely piloted aerial vehicles. They are de jure aircraft models, which corresponds to Small Unmanned aircraft Systems (sUAS) in the USA. Up to a weight of 30 kg these aerial vehicles can basically be operated without a special permission under the condition that the pilot keeps a permanent eye contact with the flying object (art. 17 OACS). Under those rules, drones are not allowed to fly above gatherings of people. Any exception to these principles requires an authorization from the FOCA, that can be required through this page, especially for drones that are operated without any eye contact.

For further information, visit the website of the FOCA or AirShoot suisse.

____________________________

HOW TO APPLY US CASES UNDER SWISS LAW ? 

It seems interesting to wonder, from a theoretical point of view, how the fictive litigation of Ridley Scott would have turned if it had happened in Switzerland. Of course, US trials are extremely different from EU countries and are based on common law principles (Anglo-saxon influence) that differ a lot from civil law principles (Roman law influence) .

ACTE 1 – Private surveillance  from the air. The first act basically raises two questions: how can a citizen use a drone for private surveillance and to what extend can the landlord claim for damages to the owner of the drone for loss of customers.

Arguments : Drone surveillance is related to both aviation rules and right to privacy or right to publicity (art. 28 of the Swiss civil Code and Data protection Act). With autonomous unmanned aircraft flying without constant visual eye contact from the pilot, the owner needs a permit from the FOCA. It is likely that for privacy rules or publicity rules, as well as security of the residents and noise pollution, no permit would be delivered for an autonomous, frequent and random fly over a residential neighbourhood.  It would be a case by case question that may only be decided by the FOCA. A surveillance drone records images from the air on the private and public domain. Video surveillance on the public domain is not allowed by private individuals or companies without concluding an agreement with the local authorities. According to the Swiss Commissioner, such surveillance on the public domain is generally considered as disproportionate and prohibited, unless the area filmed on the public domain is very small. Because the rights to privacy of passers-by would be violated, such surveillance would probably be illegal as it is the role of the police to prevent acts of crimes and to have jurisdiction in this field.

____________________________

CONSENT THAT HITS THE  NAIL ON THE HEAD

Regarding drone videosurveillance on the private domain, the Swiss Commissioner published a memento related to surveillance by private individuals. In summary, if a person cannot be identified, especially if faces or licence plates are blurred, the Data protection Act will not apply. Other questions would raise such as neighbourhood law in relation to excessive noise imissions (art. 684 al. 2 of the Swiss Civil Code). As the purpose of the surveillance is to know the author of the crime, the faces would not be blurred, and this images would be stored, used, published or even sent to the police. To be legal, every filmed person should consent to this recording (art. 13 Privacy Act) after having been informed (art. 4 al. 5 privacy Act) of the surveillance. It could be done through warning signs with detail information of the owner. In a recent decision 4A_576/2015 of March 29th, 2016, the Swiss Supreme Court considers that even inside a building, one single tenant can refuse to be filmed and can require the landlord to withdraw all the cameras of the building. In the Ridley Scott case, there may be other less invasive ways for the owner of the drone to prevent acts of crimes. The answer would certainly be different for surveillance of a commercial property with no passers-by and with high security risks.

Except neighbourhood issues, the liability of the owner of the drone for loss of customers is interesting. This is a case of civil liability in the form of an economical damage caused by a third party to the customers of a resident with a decline in turnover. There is no contract between the parties, which means that basic rules of tortious liability. Such trial would not be easy for the neighbour to win especially if the drone is entitled to fly. If it is not, the therapist must prove that civil liability rules have been violated according to article 41 of the Swiss Obligation Code. He would need to prove that (1) he has suffered a prejudice (decline of turnover), (2) in “natural and adequate causal relation” with the fly of the drone over the houses, (3) that the owner of the drone violated a specific article of the law (legal principles or articles such as violation of the Data Privacy Act) and (4) that the owner of the drone committed a fault (wisful misconduct or negligence). If these four conditions are met and if the therapist can quantify the amount to claim, he would be entitled to claim for damages…

____________________________

GIVE ME MY GUN SO THAT I CAN SHOOT THIS GODDAMN DRONE ! 

ACTE 2 – Shooting the drone. Weapons regulation is very different in Switzerland compared to the USA. Very far from the second Amendment of the US Constitution that give to every US citizen the right to wear a gun, Switzerland prohibits any acquisition, possession or use of automatic weapons (art. 5 al. 1 to 3 of the Swiss Federal Act related to weapons). The fact that one can buy a gun if he holds a licence (art. 8 LArm), does not mean that he would be allowed to have free use of it. If someone shot from his garden like the therapist did, the neighbours would very likely report such act by calling the police or to criminal authorities for fraud to the Swiss weapons Act, or to have taken a risk for the neighbours life or physical integrity in case the drone crashes. The issue would be similar if the therapist destroys the drone without any weapons resulting in a risky zone. It would depend on the weight, the height and the place where the drone could land or crash in case of an accident. If nobody is hurt and no risk was created, the owner of the drone could only claim for reimbursement of the drone if the drone was flying illegally over the therapist’s property.

____________________________

I SAY: THERE IS A DRONE FLYING OVER MY GRASS !

ACTE 3 – From the depths to the heavens. Switzerland abandoned since a long time the Roman Law principle under which a landlord can repel any threat or disturbance to one’s property from the hell to the heaven, which meant regardless of the depths or the height. Jurisprudence related to article 667 al. 1 CC explains that a landlord can master aerial space and prevent or stop any misconduct from a third party in this space if it undermines peaceful use of the property. However, the Swiss Supreme Court declares, in a first case, that property right shall continue at least up to a height of 10m to 40m corresponding to a cable car passing over a constructed house or building. The Court also declared that it is illegal to fly at a low altitude in the nearings of a private airport without consent of the landlord who may be entitled to oppose. Therefore, a landlord is entitled to protect and defend himself against damages to his property from third parties, for example against noise disturbance at an altitude of 108m, but not  600m…

Argumentation : Given the mentioned jurisprudence, it is certain that property rules apply up to 40m, likely up to 108m, and unlikely with a doubts between 108m and 600m. In the Ridley Scot story, the drone was flying at 60m (200 feet) above the property of the therapist. Therefore, the drone would still be in its property and, to the extend that the fly caused a prejudice to the therapist, who must have a legal interest to exercice its rights against the owner of the drone.

____________________________

SEE YOU IN A CRIMINAL COURT !  BUT REALLY, BASED ON WHAT ?

From a criminal point of view, one can advice to file a complaint to the Prosecutor (district attorney) or the police based on a violation of domicile (unlawful entry). In Switzerland, this offence (art. 186 of the Swiss Penal Code) would be difficult to apply as it related to humans, entering a garden  closed with a fence. Thus, it is hard to fence off the sky…To know if an unmanned aircraft can imply to hold its owner as liable for for unlawful entry is questionable. Unmanned aircraft may cause injuries, but in this case no accident has occured. If someone is placed in a life-threatening position by the drone another offence could be questionable, but hardly applicable (art. 129 CP). Legitimate self-defence related to unlawful entry can apply. Under Article 15 CP, imminent attacks can be legally repelled, for example, against its property or if one’s individual freedom is violated. The therapist could also try to file a complaint for violation of the Swiss Data Protection Act (art. 34 et 35 LPD)…

CONCLUSION

If shooting a drone is forbidden in your country, well you may be forced to use on of these techniques :

Cells

Celine case: Bayer not liable for Yasmin contraceptive pills

WHAT THE CASE IS ABOUT

On Wednesday, 21 January 2015, the Swiss-German press reported the verdict handed down by the Swiss Federal Court in the Celine Case, better known to the media as the Yasmin Pills Case. This is a case that created a scandal in the canton of Zurich, as well as at the national level, concerning the use of the latest generation of contraceptive pills in Switzerland. In this case, the Swiss Supreme Court found that Bayer AG did not breach the Swiss Product Liability Act for lack of information in the medication leaflet.

This article outlines the key legal issues relating to drug liability under the Swiss framework and compares the situation between Switzerland and the US in particular from lawsuits perspective involving 4th generation contraceptive pills.

* * *

In 2008, a 16-year-old girl was hospitalized in an emergency and found herself paralyzed following a pulmonary embolism. The consequence was a lack of oxygen leading to severe head injury. Yet it had only been two months since this young woman started taking the contraceptive “Yasmin”, a prescription-based “4th generation” contraceptive pill that many women around the world use. As a result of this serious disability, the young woman represented by her mother, as well as her health insurer, CSS Assurances, brought the case before the courts claiming CHF 5.3 million for tort and CHF 400,000 for moral damage. In the end, the Swiss Supreme Court upheld the previous decisions and dismissed the appeal of the girl and her health insurance, declaring that the drug manufacturer, Bayer AG, could not be held liable. However, Bayer waived its right to claim reimbursement of the appellant’s costs and expenses to Celine, which amounted to CHF 120,000 as a result of the duration of the proceedings, including attorney and courts fees. CSS Insurance did not get this chance.

_____________________

LIMITED INFORMATION DUTY OF THE PHARMACEUTICAL COMPANY

In this case, Bayer was accused of not mentioning in the patient package insert that the risk of undergoing pulmonary embolism was twice as high with the “Yasmin” pill as with other similar contraceptives. In essence, the Federal Court considered, in its judgment of 5 January 2015 (4A_365/2014 and 4A_371/2014 (in German)), that the German pharmaceutical company was not liable for this lack of information for patients, the mere fact that doctors had access to this information being sufficient. The Federal Court pointed out that the placing of a medicinal product on the market and the standards for obtaining the necessary authorisations from Swissmedic for their marketing do not oblige a pharmaceutical company to inform patients of a higher risk than other equivalent products. With regard to prescription drugs, the patient is not in a position to judge the risks involved, so it is up to doctors to evaluate the benefits and risks of the various products on the market to redirect the patient to the appropriate medical treatment.

Thus, the Federal Court acknowledged that the drug was not defective and that the company could not be held liable under the Swiss Federal Product Liability Act (PLA). The “causal liability” mechanism of this law allows the victim of a defective product to claim damages from the manufacturer, without any fault (art. 1 § 1 PLA). However, the product must be considered defective for the manufacturer to be liable for the damage caused.

In particular, the distinctions between manufacturing defects, design defects and presentation defects can be found in the famous “coffee maker case“, where the Supreme court clarifies the causes of a defect for products that have been validly placed on the market.

_____________________

INEQUALITIES IN LOCAL LEGISLATION: COMPARISON BETWEEN SWISS AND US LITIGATION

Market access authorisation framework and liability for defective drugs:

The case of Switzerland

The authority shall grant a market access authorisation for a drug for a renewable period of 5 years and must comply with the legal requirements of the Swiss Federal Therapeutic Products Act (TPA), in particular requiring the approval of Swissmedic.

Market access shall only be granted where a pharmaceutical company:

How the pharmaceutical company decides to label its product and the way in which the information is highlighted in the leaflet are also essential conditions for obtaining such authorisation (Art. 11 § 1 let. f TPA). However, to the extent those conditions are met, the manufacturer cannot be held liable for a defective product, unless its market access
authorisation was not granted properly. The responsibility for defective drug usually extends to suppliers, i.e. distributors and importers, but this excludes the medical liability of doctors or pharmacists.

1) provides evidence that the drug or a manufacturing process is of high quality, safe and effective;

2) holds an authorisation as a manufacturer, importer or wholesaler issued by the competent authority; and

3) has its domicile or its registered office in Switzerland, or has established a subsidiary in Switzerland (Art. 10 TPA).

In summary, the manufacturer’s liability for defective product it is a rather difficult to obtain, especially when a consumer has to pay very large amounts of legal fees and expenses in advance. Therefore, as a result of this case Bayer was not convicted in Switzerland by the Federal Court, which sets a precedent for pharmaceutical companies active in selling 4th generation contraceptive pills.

Situation in the USA

Mass compensation

Since 2013, the German pharmaceutical company has already paid out around USD 1.4 billion in the United States to compensate victims of similar cases by way of settlement in legal proceedings involving a total of more than 6,760 plaintiffs (the figures are not uniform, see the following reports here). These US trials are more broadly related to 3 contraceptive pills “Yaz”, “Yasmin” and “Ocella”. In the USA, the U.S. Food and Drug Administration (FDA), the authority responsible for approving and marketing consumer products, including medicines (which is the equivalent to Swissmedic in Switzerland), must ensure that a drug meets two requirements:

  • Manufacture of safe drugs with precise statements of any potential risks; and
  • Precisely warns under what circumstances the drug may or may not be used.

Le Monde.fr recently mentioned the impressive figure of 15,000 legal actions filed against the pharmaceutical group. The American judicial system allows, thanks to class actions and specific ethical rules on the legal profession (pactum de quota litis), to have a different means of pressure on large companies than in Switzerland where each individual must find their way alone to a long and costly trial.

Position of patient advocates

Pharmaceutical trials in the United States are particularly fascinating for civil law lawyers. For example, the drugwatch website provides information on lawsuits related to pills sold by Bayer and arguments that the attorneys may raise in court against the German manufacturer. The challenges and costs of those trials as well as the risks for manufacturers are so hihg, that some law firms become specialists defending clients in trials for those pills. They do not hesitate to document their willingness to defend the victims with explanatory videos motivating patients to consult and hire them free of charge as long as the pharmaceutical company do not pay anything to compensate any damage caused to them. You can also find links to a free medical assessment form intended for assessing the medical situation of a relative or read sentences such as: “If your loved one has died as a result of using these contraceptives, you may be able to file a wrongful death lawsuit“. There is also an American website specific to the Yaz & Yasmin trials.

On another level related to conspiracy, press articles try to establish a link between FDA members and the German manufacturer. Also from the the FDA we can find reporting risks associated with Beyaz, Safyral, Yasmin and Yaz in highly technical reports.

It’s hard to find your way around in this American romantic universe…!

_____________________

CONCLUSIONS AND LESSONS LEARNED FROM THE SWISS DECISION

The Federal Court’s decision highlights several elements:

  1. A pharmaceutical company is not required to inform patients that its drug presents a higher risk compared to other competing therapeutic products.
  2. The Swiss Supreme Court implicitly confirms the principle that a physician has an obligation to inform the patient of the nature of the risks and the degree of danger associated with taking such a drug. Indeed, the consumer does not have access to the same information as his doctor and is not in a position to make a decision without consulting him and having a free and informed opinion.
  3. Prescription drugs are not treated in the same way as those that do not require them to obtain them. Indeed, when a prescription is mandatory, the doctor must intervene to prescribe the drug in question to his patient, who has the knowledge to refer the patient, supported by a medical record. It is therefore up to the doctor to assess the risk and appropriateness of the patient taking a medicinal product on the basis of information intended for health professionals. The assessment of a pharmaceutical company’s liability for a non-prescription drug would probably be different if the risks are not sufficiently indicated.
  4. Obtaining compensation from the manufacturer of a drug for lack of information is not easy. Where appropriate, and under certain conditions, the civil and/or criminal medical liability of a doctor, or even a pharmacist or other health professionals may be incurred where, as a result of insufficient information, a damage to health occurs which could have been avoided if adequate information had been provided.

The information in the Yasmin pill package insert and contraindications are available on the website of the Swiss Compendium of Medicines.

By Gabriel Avigdor | NTIC.ch

Electronic appeal in Switzerland – attorneys remain liable

In a recent decision (6B_691/2012 of February 21th, 2013), the Swiss Supreme Court confirmed that Swiss attorneys remain liable for the submission of electronic appeals. In this case, the attorney who has not verified that the appeal was properly received by the authority or the Court is liable. On the contrary, as technical service providers cannot guarantee a 100% available service, the submission of an electronic appeal is considered as a risk that shall be borne by the attorney if the provider gets down and cannot deliver the data to the court. The Swiss Supreme Court, reminds that the use of technologies contains risks. Therefore, the attorney remain liable :

  • even when there is no fault on the attorney;
  • even if the server gets down the last day of the deadline for submitting the documents to the Court
  • even if the software installed on the attorney’s computer contains bugs, an older or even an incompatible version that prevent the attorney to connect properly to the provided services.

To avoid any liability in case of any doubt, the attorney shall submit a separate documentation to the authority or the Court … by mail ! If the attorney does not comply with this obligation, he could face the consequence of this negligence which means that the appeal would be considered as a belated action with no possibility to require from the Court a new deadline.

With such opinion, the Swiss Supreme Court does not encourage Swiss lawyers to resort to new technologies. In consequence, this will delay the birth of 100% digital lawyers…

For further details, you can read the full analysis of this decision in French  here.