Industries / Health · hospitals, clinics & practices
Patient secrecy is criminal law. Protect your staff when they use AI.
Art. 321 CP makes the unauthorized disclosure of entrusted patient information a criminal offense, for the physician, the psychologist, the nurse and every other staff member who sends the prompt. A prompt containing patient data counts as a disclosure, unless technical controls prevent it.
The AI governance framework for healthcare
Five obligations. Here's our part, honestly.
We mark what NativeAI Guard solves for the channels we protect, where it contributes, and what stays with your processes.
Seen in Swiss clinics
A psychologist pastes session notes into an LLM to draft a therapeutic summary. Faster, better written, and a potential unauthorized disclosure under Art. 321 CP.
A clinic administrator uploads a PDF of patient records to an LLM for summarization. The whole document is uploaded, with no consent covering this processing.
Clinicians install Claude Desktop, for example, and step around every browser-based control. An explicitly named go-live requirement in our clinic conversations.
Patient data is flowing to ChatGPT uncontrolled.
Policies, managed
The rulebook for healthcare is already written. You adapt it instead of inventing it.
A base rulebook is already written and active from day one: the rules from the Swiss DSG, GDPR and the EU AI Act, plus the requirements your industry is specifically subject to. It covers the standard cases without you writing a single line. Security and compliance practitioners review it, and we keep it current as the law changes. On top of it sit the rules that apply only to you: your own data structures, your internal requirements, your exceptions.
During onboarding we tune the pack to your own data structures and internal rules, working from the compliance documents you already have.
Common questions
Frequently asked questions
Content leaves our network to be inspected. What exactly happens to patient data in that moment?
It is processed transiently in volatile memory on our own servers in Switzerland and discarded immediately afterwards. It is not written to disk in the course of inspection and it is not retained for model training. This is the question a clinic and its external counsel put to us most rigorously, and the answer is written into the data processing agreement, where your own lawyers can hold us to it.
Does your team become an auxiliary person under Art. 321 CP, and does that also cover support work?
Yes to both, and the second half matters more than it looks. Medical secrecy obligations that apply during processing must also apply to support and maintenance work, otherwise the two documents cover different ground. We align the data processing agreement and the non-disclosure agreement so that support staff sit inside the same medical-secrecy scope. That alignment is part of our standard contracts today, shaped by a clinic's legal counsel who pressed us on exactly this point.
Do you need access to our clinical systems or patient records at any point?
No, at no stage, including during onboarding and support. Policy tuning is done from anonymized examples and your own compliance documents, not from real records.
Protect your staff from Art. 321 CP, with a pilot phase that we run for you.
A healthcare policy starter pack, plus a report for management on data leaks, shadow AI, AI usage and model costs. Prompt content is processed only transiently in volatile memory on our servers in Switzerland and never stored.