Data protection: The prerequisite for innovation

In an industry where protecting sensitive data is a top priority, Swisscoding Technologies is committed to the highest standards of IT security, exceeding current regulations.

While the benefits of innovation, particularly with the advancement of AI, are significant across all levels of the coding chain, they can only be realized under one condition: data security must be ensured. After all, protecting patient data is a top priority for hospitals.

To develop its own medical coding technology, Swisscoding Technologies had to face the great challenge of meeting the requirements for a powerful AI while respecting the security standards of hospitals.

The needs of a high-performance AI
To realize its full potential, artificial intelligence requires an environment and resources that often go beyond current requirements or the safety regulations of hospitals. This includes, for example, access to large amounts of data in real time, a flexible technological infrastructure, and powerful processing systems:

  1. To become efficient, AI needs large amounts of data that are as comprehensive as possible in order to learn medical coding and be able to train with specific treatment protocols and practice of individual hospitals or clinics.
  2. It also requires a robust technological infrastructure with specialized graphics processors capable of handling large volumes of data efficiently and are constantly evolving to meet the increasing demands of models and applications.
«With these new technologies based on LLMs, the required GPUs are highly specialized, expensive, and rapidly evolving. Keeping a local infrastructure up to date has become impossible. Therefore, we have decided to use Microsoft data centers in Switzerland, which offer the latest technological advancements while ensuring that the models operate in a secure, solated, and reliable environment, compliant with all certifications. In summary, it is like having your own computer, but with capabilities that are always up to date.»

Christophe Rosso, CIO of Swisscoding Technologies

The solutions found are innovative
1. Swisscoding Technologies has developed a powerful data nonymization software Data anonymization: that is installed locally on a small computer directly in hospitals. This ensures that the data is fully anonymized before being transferred to the coding servers.

2. Data processing: By using the cloud, particularly Microsoft servers in Switzerland, Swisscoding Technologies guarantees maximum security. The data does not leave this controlled and internet-disconnected environment, which complies with the strictest certifications. This choice combines performance, security, and scalability,
in contrast to data processing on hospital servers, which would be
expensive, not powerful enough, and not as quickly scalable.

«Our IT security measures are stricter than
the applicable regulations. We apply maximum
security requirements that also comply with
the rules of the IT parks of Swiss hospitals.»

Colin Chaleon, Swisscoding DPO & ISMS Manager

Data valuable only for coding
Since its inception in 2018, Swisscoding has developed a solution for anonymizing patient data to ensure secure processing that meets the requirements of the medical sector. This advanced software, installed directly in hospitals, allows for the control of various criteria such as names, dates, locations, and other information that is not relevant to the medical coding process. The data is anonymized directly on the institution’s servers, so it leaves the hospital infrastructure completely free of identifiable elements. As it is impossible to compare the data with the original patients, this technology ensures absolute confidentiality. Even if the data were to be compromised, it would be unusable.

«The ISO 27001 certification ensures that our processes comply with international best practices.»
Colin Chaleon, Swisscoding DPO & ISMS Manager

Swisscoding has been ISO 27001 certified for almost three years. Why is this certification important?
The ISO 27001 certification is one of the highest standards for information security. It encompasses a variety of requirements, from personnel security to the security of applications used,
and the security of subcontractors. For us, it means that our processes comply with the best international practices, and it builds trust with our partners and customers. This is particularly crucial in an industry like ours, where we handle sensitive data and where security is our top priority.

How do you, as an information security expert, assess Swisscoding’s commitment in this area?
At Swisscoding, security has always been a high priority since the company’s founding. This culture has been built around ISO 27001. Everything we do, from technical measures to internal policies, is designed to meet these requirements. Additionally, management plays a key role by actively participating in these
processes and leading by example, which is very stimulating.

What are the biggest challenges related to the development of
AI and legislation?
The introduction of a new European legislation, the AI Act, raises some questions for us as a Swiss company. So far, we are not directly affected by this law, as we operate exclusively in Switzerland. However, since Swisscoding Technologies plans
to expand into Europe, we should comply with these regulations. Therefore, we are working proactively to ensure that our solutions meet the highest standards beyond our borders. Currently, we are in the process of additionally obtaining ISO 27701 certification for Swisscoding Technologies, a standard specifically focused on handling personal data (PII).

The Highest Security Standard
The ISO 27001 certification is an international standard that ensures the implementation of a strict system for managing information security. It covers all processes that enable the effective protection of sensitive data from internal or external threats. This standard requires the continuous improvement of practices and andates that organizations stay up to date with the latest technologies and regulations by undergoing two external audits per year. Obtaining this certification demonstrates a continuous investment in data protection and fulfils the strictest security expectations.

Share this article:

Related Posts

Meet the team Anna

We are delighted to welcome Anna Waxweiler, who joins Swisscoding in March 2025 to strengthen our Medizincontrolling team in German-speaking Switzerland.

Read More »