Tag: Swiss Data Protection Act

Covid-19

Covid-19 mini-series | Legal advice for Switzerland Privacy, Health & Technologies

With Covid-19, the world is facing a huge crisis and the economy will be massively impacted.

New coronavirus, known as “Covid-19“, spreads itself from China (Wuhan province) to Europe, and then to the world leading to unprecedented measures from authorities in various countries, including Switzerland. Public health issues combine health law, protection of personal data & Privacy and the use of new technologies to fight and help during this tough historical time. Remote work and the use of online conferencing tools has flourished and turned from B2B to B2C with down sides of using online tools in an urgency mode without proper diligence.

To support as much as we can on providing useful information, we have started a legal mini-series, including tips and downloadable documents for business and organizations. This series of guidance and materials aim at providing simple and practical information to better understand and tackle legal issues and economic repercussions due to the coronavirus.

Both public and private organisations are suffering. We intend to publish regular posts on our LinkedIn page and our dedicated Covid-19 website on datalex, our new digital legal platform for organizations seeking legal advice and services.

_______________________________

ABOUT OUR MINI LEGAL SERIES 

We are committed to providing legal advice and guidance to individuals and companies in connection with Covid-19.  As usual, this series is bilingual (FR/EN) with some episodes in Italian!  The first episode provides information on the application of the law on epidemics and its federal ordinance. For the other ones, here is the list of our episodes:

Episode 1Federal Act on Epidemics

Episode 2: Telemedicine & Law

Episode 3: Criminal sanctions: what are the risks?

Episode 4: Ethics guidelines: rules for triage of patients in intensive care units

_______________________________

DATA PRIVACY PERSPECTIVE FOR SWITZERLAND / GERMANY / BELGIUM

To provide further legal guidance on technology and data protection to businesses, we regularly participate webinars with law firms around the world that are part of the PrivacyRules network on data privacy matters. We have started with the following webinar in 4 parts, in collaboration with German and Belgian experts for comparative data protection considerations between these three countries.

Part 1What Data Protection Authorities are saying

Part 2Challenges and possible solutions

Part 3Top tips and advice for organizations

Part 4 What may happen post-Covid-19

Note that the episodes of this webinar are in English only.

_______________________________

IMPACT ON THE ECONOMY

While Switzerland’s historic decision to limit events to a maximum of 1,000 people intends to reduce the risk of the virus spreading, it has a major impact on event organisers and other sectors of industry. Employers have to deal with teleworking solutions and implement health and remote work policies and deal with travel and distance restrictions. Employers also need to ensure that they do not interrupt the supply of goods, and have to potentially deal with contract termination or damages for non-performance. This includes, where necessary, to invoke force majeure or reject force majeure arguments from suppliers who are under the impossibility to deliver their services.

The economic repercussions in Switzerland and around the world are enormous. The Watches and Wonders exhibition decied to cancel the event on 27 February 2020. After this, the lucrative Geneva International Motor Show (GIMS), took the same path on 28 February 2020. After this, the famous Cully Jazz Festival had to accounce cancellation of its 2020 Edition on March 10, 2020. The organisers of this festival declared that, except with donation and external financial support and given the considerable losses, this cancellation may jeopardise future editions.

When it came to Italy deciding on 9 March 2020 to quarantine the country, the EU population was in shock, realizing the seriousness of the facts. France decided to limit the events to a maximum of 1000 people. In Spain, the World Mobile Exhibition in Barcelona cancelled the event, which was expecting more than 110k visitors. Such event would generate around 492 million euros in local economic spin-offs, as well as more than 14,000 jobs. The same happened to the Formula 1 Chinese Grand Prix. Originally scheduled for April 19 2020 in Shanghai, they decided to postpone it.

A list of all the episodes in this series can be found on the publications page of this blog or on the dedicated page on datalex.ch.

_______________________________

FEDERAL vs CANTONAL COMPETENCES

On 28 February 2020, the Federal Council decided by means of a federal ordinance to ban large scale events involving more than 1,000 people. This decision resulted from the outbreak of the “Covid-19”. This is a measure that is normally under the responsibility of the cantons. However, in special emergency situations, the government must protect the population against communicable diseases.  In those case, the Swiss Confederation may enact measures by means of a federal ordinance. It has used such power to limit the gathering of people. Furthermore, the Federal Office of Public Health (‘FOPH’) explained, in a press release dated 28 February 2020, the different situations that can arise when dealing with a contagious disease that endangers public health.

(1) In normal situations

The cantons are competent to put in place the necessary measures to protect the population. These consist of quarantine and isolation measures.

(2) In special situations

The Federal Council may encroach on the autonomy of the cantons. This may be the case where: (a) the cantons can no longer exercise their prerogatives or take appropriate measures, should there be a (i) high risk of infection and spread to the population, a (ii) risk to public health or (iii) to the economy. This may also be the case if (b) the World Health Organization (WHO) declares an international health emergency threatening Switzerland.

(3) Extraordinary situations

They arise in the event of an “extraordinary threat to public health“. In such circumstances, the Federal Council may issue federal ordinances without the need for a legal basis in order to take rapid and targeted actions applicable to all Switzerland. The cantons may still have some room to implement them or to issue stricter rules. Pandemic situations may be considered as extraordinary situations, which the Federal Council may invoke to use its overriding powers.

By Gabriel Avigdor | NTIC.ch

Revision of the Swiss Data Protection Act: Conference for HCPs

This Thursday 24 October 2019, I will have the pleasure to present the current state of the revision of the Swiss Federal Data Protection Act (DPA), as currently discussed at the Federal Parliament. I will be discussing the consequences for doctors in private practice in a conference organised by FMH Services, at the Hotel Aquatis in Lausanne.

Since the GDPR become enforceable on May 25, 2018, data protection has become a hot topic and an area concern for many sectors, particularly in the healthcare sector. The various actors, whether healthcare institutions or organizations (HCOs), hospitals, clinics or doctors (HCPs), are particularly sensitive to the changes of the legal framework given the sensitivity of the data processed on a daily basis.

The objective of this conference is to review the updates that will likely pass and be introduced by the total revision of the Swiss Data Protection Act. We will discuss the challenges that doctors will face and the recommendations they will need to receive for preparing to the changes. This will be the opportunity to discuss how the GDPR applies to physicians and HCPs, as well as best practices for the use of technologies by doctors as data controllers of health-related personal data.

The revision of the Swiss DPA aims at strengthening the rights of the individuals, in this case patients, and at aligning on the European data privacy standards. We will examine to what extent the revision fulfils this objective.

________________________________

CONSEQUENCES ON THE DAILY PRACTICE OF HCPS

Generally, the daily practice of HCPs will not change drastically with the new Swiss Data Protection Act and the guidance will remain similar for a physician’s practice to the ones already issued by the Commissioner in the past.

In my previous article on outsourcing medical billing, I mentioned what guidance the Federal Commissioner issued in the context of healthcare, which contains exhaustive recommandations, examples and cases studies on security measures at the medical office, outsourcing, guidance on the use of cloud computing and how to respond to patients exercising their access right to medical records. The Federal Commissioner also issued a guidance on how to deal with data privacy generally at the office.

This being said, the major changes for processing of medical information is relating to the use of new technologies, where the risk for medical secrecy and data protection is the highest. This is also true because a very low number of HCPs are prepared to face digital transformation and have little measures in place or best practices for the use of ICTs. This requires an increased vigilance and diligence from health professionals and physicians to avoid being held liable from a civil or a criminal perspective.

Therefore, security and the application of data privacy principles of patient data at the medical office remains essential because of the increased risks associated with the use of information systems, social media, cloud computing, telemedicine and other similar technologies. In this context, all previous recommendations of the Federal Commissioner remain valid (see below) and must be followed, as must those issued by the Code of Ethics of the Swiss Federation of Physicians.

It should be noted that risks increase with the use of telemedicine systems and unsecured means of communication, as well as in the case of outsourcing (subcontracting) of services, such as invoicing or secretarial services.

________________________________

FINES IMPOSED ON HOSPITALS AND DOCTORS UNDER THE GDPR

In Europe, we have already seen hospitals sentenced by data protection authorities to administrative penalties of several hundred thousand euros.

Since the implementation of the GDPR, most breaches have consisted of deficiencies in appropriate security measures to protect patient data. Similarly, the violation of the duty to set up controls for the rights of access to the same data in patient files has often been the cause of sanctions and breaches by health institutions.

In this respect, the following European decisions are worth mentioning:

  • Portugal: my previous article and comments on the € 400,000.- fine imposed to a Portuguese hospital. Note that in this article, I also discuss other major fines under the GDPR (equifax, Cambridge Analytica) and the very first fine (ICANN) under the GDPR, as well the situation of Swiss hospitals with regard to privacy and data protection and some elements of the current revision of the Swiss Data Protection Act;
  • Pays-Bas: € 460,000 fine imposed to Haga Hospital (Netherlands) for allowing non-authorized access to employees and third parties to the medical record of a local celebrity. The fine was imposed as a result of inapropriate security measures, especially a weak access control mechanisms (art. 32 GDPR) with no double-factor authentication, which was considered the “ABC” of security;
  • Cyprus: € 14,000 imposed to a doctor for publishing health-related information of a patient on Instagram, mentioning the name of the patient without her consent. After investigations, the Data Protection Commissioner of Cyprus also imposed a €5,000 fine to the hospital for not being able to recover the medical record of the patient following an access request.

These examples demonstrate the importance of privacy and security compliance and data protection principles. Those basic principles have to be applied in medical offices and hospitals. Also to guarantee a good control over personal data, it is crucial to apply the principle of privacy-by-design, implement a complete data protection and management program for all types of health actors.

This should include training, rules of conduct for employees and managers, access controls, as well as appropriate organizational and technical measures to avoid data breaches, unauthorized access to personal data, data losses, alteration, and other violations protection. It also remains key, even for micro enterprise and medical offices to have an action plan in the event of a data breach in order to notify the authorities or the patient if necessary. Given those challenges, a light version of an data protection officer (external) would be welcome.

Even if the legal regime of the Swiss DPA will differ from the European sanctions under the GDPR (2% – 4% of the global turnover or €10 – €20 million), these basic rules and principles are essential and must be respected in order. This is key to avoid civil or criminal liability for violation of the Data Protection Act. Also, where applicable, such behavior may infringe the Criminal Code (Art. 321) for violation of medical secrecy.

Now, the Swiss sanctions system only offers the possibility for individuals to initiate a civiel or a criminal proceedings for violation of the Federal Data Protection Act. The maximum penalties amount to CHF 10k. However, the plan with the revision is to increase the level of criminal fine up to CHF 250,000 maximum. This still remains a criminal fine, based on a criminal trial initiated by a plaintiff or a data subject, where the individual will be held liable, excepting the data controller that cannot receive any direct administrative sanction from the Swiss authority.

Find my other articles relating to healthcare:

  • Article on the outsourcing of medical data
  • Non-economic physicians and the consequences of overbilling (in French: “polypragmasie”, in German “Überarztung”)
  • Videoconference: software and medical devices regulation
  • Conference on telemedicine