Can a medical practice put patient data into ChatGPT? A checklist for practices and clinics
End of a long consultation day. A doctor pastes her notes into ChatGPT to turn them into a referral letter: two minutes instead of fifteen. The notes hold a name, a diagnosis and a list of medication. Where are they now, and who else can read them?
The short answer: not through an account someone opened on their own, and not without a solid basis. Health data is sensitive data under the Data Protection Act, and medical secrecy is a duty under criminal law. Whatever leaves the practice needs the patient's consent, or a provider you can hold to your secrecy the way you hold your own staff, in a country the law accepts.
Checked against the law on 30 September 2026
Who answers for it?
- 3 years
The maximum custodial sentence for doctors, dentists, psychologists, nurses, physiotherapists and their staff who reveal a secret learned in their work (art. 321 SCC). Prosecuted on complaint; the patient's consent removes the offence.
- Sensitive data
Health data is sensitive personal data under the law (art. 5 FADP). Where the patient's consent is what allows processing it, that consent must be explicit (art. 6 FADP).
- US law
US providers can be required to hand data they control to US authorities, even when it is stored in Switzerland (CLOUD Act).
The checklist
0 of 11 checked
Processing health data on a large scale normally needs a data protection impact assessment beforehand, unless an exemption applies; if a high risk remains, the FDPIC is consulted first (arts. 22 and 23 FADP).
Dictation and transcription apps included, on phones too. Ask the whole team, and look at expense claims: the tool you don't know about is the one that breaches secrecy.
Consultation notes, reports, lab results, images, appointment lists. Even an appointment list tells who is a patient.
A free or personal account runs on consumer terms. A business plan comes with a different contract. Which one is each person really using?
Some consumer plans may use conversations to train their models, and keep them for a while, unless a setting is off. Read the terms of the plan in use, not the homepage.
A company that handles patient data for you is what the law calls a processor. That's allowed with a contract, if it only does what you could do yourself and keeps the data secure, and if no duty of secrecy forbids it (art. 9 FADP).
Many AI tools process data in the United States. Sending patient data there needs a legal basis, for example Swiss-US Data Privacy Framework certification or standard data protection clauses (arts. 16 and 17 FADP).
If you rely on the patient's consent, it must be explicit for health data (art. 6 FADP) and it only covers what the patient was told. Write down what they agreed to, and when.
Names, dates of birth, insurance numbers. A rare diagnosis can identify a patient on its own, so removing the name isn't always enough.
Which tools, for which tasks, with which data, and what never goes in. A page people can find is a page they can follow.
Secrecy binds medical assistants and reception staff too. Go through the rules with everyone, repeat them for every newcomer, and give them a tool they're allowed to use.
Ticked them all? Rules that exist only in your head don't stop anyone. The next step is to write them down for your team: the kit has a one-page policy and a consent text to adapt. Get the kit
Which tasks can go where?
The kit sorts six everyday tasks in a practice. Two of them:
- Writing a patient leaflet on a common condition
- A public tool is fine, then check it medically.
- Rewording a practice letter with no patient details
- A public tool is fine.
- Turning consultation notes into a referral letter
- In the kit
- Summarising a patient's history
- In the kit
- Transcribing a dictated report
- In the kit
- Answering a patient's email
- In the kit
Secrecy covers the whole team
The Criminal Code's professional secrecy names doctors, dentists, chiropractors, pharmacists, midwives, psychologists, nurses, physiotherapists, occupational therapists, dieticians, optometrists and osteopaths, together with their auxiliaries. It lasts after they stop practising (art. 321 SCC). Cantonal health laws add their own rules on patient records.
Data protection applies as well
Handing patient data to a provider without the conditions of article 9 paragraphs 1 and 2, or sending it abroad without the protection of article 16 and outside the exceptions of article 17, can be fined up to CHF 250,000. The fine targets the person responsible, for intentional breaches, on complaint (art. 61 FADP).
What works in practice
A common setup has three tiers: public AI tools for general texts with no patient details, nothing about a patient in any tool your contracts don't cover, and a private AI run in Switzerland for letters, summaries and transcriptions.
Where does your firm stand?
The self-check takes two minutes and says which first step fits. Or talk it through in a free 15-minute call.
Book a free 15‑minute call
Pick a time that suits you and confirm it from your inbox. If the time no longer works on our side, you hear from us the same working day.
What happens in 15 minutes
- 0–5 min
Your situation
What AI should do for you, and what it must never see.
- 5–10 min
What's possible
Which tasks can run privately, roughly what it costs, and what should stay human.
- 10–15 min
The next step
A test on your own documents, an assessment, or nothing yet.
Prefer to write? Send a message
Tell us what you'd like AI to do, and what it must never see. We'll tell you honestly what's possible, what it costs and what should stay human. No details yet? A hello is enough.
