Industries / Health · hospitals, clinics & practices

Patient secrecy is criminal law. Protect your staff.

Art. 321 CP makes disclosing entrusted patient information a crime for whoever sends the prompt. A prompt with patient data is a disclosure unless technical controls prevent it.

See it in action

Omnichannel protection, across all devices.

ChatGPT, Claude, Gemini, Copilot, DeepL and whatever your employees try next week: the same policies, anonymization and audit trail on the work laptop and the work phone.

See scenarios →

Summarize the session notes for Anna Keller, born 02.07.1979, diagnosis moderate depressive episode (F32.1), for the referral letter.

Summarize the session notes for <PATIENT>, born <DATE>, diagnosis <DIAGNOSIS>, for the referral letter.

Here is the customer list:

Q3_Kundenliste.xlsx (2,400 rows)

NativeAI Guard, BLOCKED: Blocked attachment: Q3_Kundenliste.xlsx. Blocked by policy: Customer Data Leakage Prevention.

DEADLINESNOW · Art. 321 CP · DSG in forceOCT 2024 · NIS2 covers healthcareAUG 2026 · EU AI ACT HIGH-RISK (clinical, patient-facing & mental-health AI)

The AI governance framework for healthcare

Five obligations. Here's our part, honestly.

We mark what NativeAI Guard solves for the channels we protect, where it contributes, and what stays with your processes.

Art. 321 CPCriminal professional secrecy, covers physicians, psychologists, pharmacists and their auxiliaries, including IT.✓ We solve · block/anonymize patient data
Swiss DSG / GDPRData minimization, records of processing, cross-border limits, with personal liability up to CHF 250,000.✓ We solve · anonymization + RoPA
EU AI ActAI for clinical assessment, patient-facing AI and mental-health AI are high-risk from Aug 2026, logging, oversight, governance.◐ We contribute · logging + oversight
NIS2Healthcare is an essential sector, supply-chain security and incident reporting for AI channels.◐ We contribute · monitoring + reports
HIPAAOnly if you bill US insurers or have US operations, minimum-necessary standard and §164.312 safeguards.◐ We contribute · minimum necessary + audit logs

Seen in Swiss clinics

The session summary

A psychologist pastes session notes into an LLM to draft a therapeutic summary. Faster, better written, and a potential unauthorized disclosure under Art. 321 CP.

NativeAI Guard: patient identifiers become [PATIENT], [DIAGNOSIS] before the prompt is sent, the summary still gets written.
The uploaded patient file

A clinic administrator uploads a PDF of patient records to an LLM for summarization. The whole document is uploaded, with no consent covering this processing.

NativeAI Guard: documents are inspected inside the upload, patient records detected, the file blocked before it is sent.
The desktop app gap

Clinicians install Claude Desktop, for example, and step around every browser-based control. An explicitly named go-live requirement in our clinic conversations.

NativeAI Guard: the desktop agent, currently in development, extends the same policies beyond the browser: one policy, every channel.
"

Patient data is flowing to ChatGPT uncontrolled.

DPO & HEAD OF CLINICAL OPERATIONS · SWISS CLINIC

Policies, managed

The rulebook for healthcare is already written. You adapt it.

Swiss DSG, GDPR and EU AI Act, plus your industry's specific duties. Security and compliance practitioners review it; we keep it current as the law changes.

Healthcare packArt. 321 CP · medical secrecyPatient data · PHISwiss DSG · GDPREU AI Act, clinical AINIS2

During onboarding we tune the pack to your own data structures and internal rules, working from the compliance documents you already have.

Common questions

Frequently asked questions

Content leaves our network to be inspected. What exactly happens to patient data in that moment?

It is processed transiently in volatile memory on our own servers in Switzerland and discarded immediately afterwards. It is not written to disk in the course of inspection and it is not retained for model training. This is the question a clinic and its external counsel put to us most rigorously, and the answer is written into the data processing agreement, where your own lawyers can hold us to it.

Does your team become an auxiliary person under Art. 321 CP, and does that also cover support work?

Yes to both, and the second half matters more than it looks. Medical secrecy obligations that apply during processing must also apply to support and maintenance work, otherwise the two documents cover different ground. We align the data processing agreement and the non-disclosure agreement so that support staff sit inside the same medical-secrecy scope. That alignment is part of our standard contracts today, shaped by a clinic's legal counsel who pressed us on exactly this point.

Do you need access to our clinical systems or patient records at any point?

No, at no stage, including during onboarding and support. Policy tuning is done from anonymized examples and your own compliance documents, not from real records.

Protect your staff from Art. 321 CP.

A pilot phase, run by us: a healthcare policy starter pack plus a report on data leaks, shadow AI, usage and costs. Prompts are processed transiently in Switzerland, never stored.