In brief
Sending patient data and medical reports securely
Health data is especially sensitive – legally and in everyday practice.
Health data counts as especially sensitive personal data, and professional secrecy under article 321 of the Swiss criminal code applies on top. Between practices and hospitals, HIN is the Swiss standard and remains the right choice. For the route to people without HIN – patients, lawyers, insurers, relatives – you need something that works without an account on the other side.
What applies
Under the revised Swiss data protection act, health data is especially sensitive personal data. For doctors, dentists, therapists and practice staff, professional secrecy applies on top – a breach is prosecuted ex officio. An unencrypted medical report by mail is therefore not merely unwise.
This also covers the seemingly harmless: an appointment confirmation from an oncology department says something through its sender alone that is nobody else’s business.
HIN – and where it ends
Between healthcare providers, HIN is the Swiss standard: encrypted mail inside a closed, vetted circle. Anyone working with it should stay with it – for referrals, reports and exchange with hospitals that is the established route.
The gap lies outside that circle. The patient wants her report. The lawyer needs a file. The insurer requires a form. A daughter is organising care for her father. None of these people has HIN, and none will set it up for one errand.
What has to close that gap
Three things: the content must not sit readable at the provider. The other side must not need an account, or it will not be used. And it must expire by itself, so the report does not sit in a private mailbox for years.
And with tunnl.
tunnl. closes exactly that gap. The report is encrypted in the browser at the practice, the patient opens a link and reads – no account, no app. For sensitive cases add a password handed over at the desk or by phone. After the window the content is gone, for us too. Servers and company are in Switzerland, and a data processing agreement is ready to print at /avv.
What tunnl. cannot do here: tunnl. does not replace HIN between healthcare providers and is not a patient record. It is the route for the single errand going outwards. Whether it suffices for your practice is decided by your data protection concept – and in doubt, by your professional association.
How tunnl. encrypts · Data processing agreement · What we store

