Häs­sig postu­la­te (25.3155): Streng­thening the pro­tec­tion of Swiss hos­pi­tals against cyberattacks

Sub­mit­ted text

The Fede­ral Coun­cil is ins­truc­ted to work with the can­tons to exami­ne how well pro­tec­ted Swiss hos­pi­tals are against cyber­at­tacks. It should also ana­ly­ze the spe­ci­fic chal­lenges faced by hos­pi­tals in the area of cyber secu­ri­ty and cla­ri­fy what pre­ven­ti­ve mea­su­res would be effec­ti­ve in ensu­ring that hos­pi­tals are pro­tec­ted against cyber attacks.

Justi­fi­ca­ti­on

Swiss hos­pi­tals mana­ge lar­ge amounts of high­ly sen­si­ti­ve per­so­nal data and ope­ra­te vital systems. A suc­cessful cyber­at­tack could the­r­e­fo­re not only result in serious data pro­tec­tion brea­ches, but also acu­te­ly jeo­par­di­ze medi­cal care. At the same time, hos­pi­tals face par­ti­cu­lar chal­lenges in the area of cyber secu­ri­ty. The­se include the decen­tra­li­zed struc­tu­re of the heal­th­ca­re system, a lar­ge num­ber of inter­faces bet­ween ser­vice pro­vi­ders, health insu­rance com­pa­nies and pati­ents, and an incon­si­stent level of digitalization.

As the Fede­ral Coun­cil sta­ted in its respon­se to the Inter­pel­la­ti­on 24.4014 noted that in recent years, “in other count­ries (e.g. France, Eng­land) the­re have been various suc­cessful cyber­at­tacks with a direct impact on the ope­ra­ti­on of lar­ge hos­pi­tals”. Alt­hough Switz­er­land has so far lar­ge­ly escaped major cyber­at­tacks on hos­pi­tals, the­re are indi­ca­ti­ons that this is due more to coin­ci­dence than to effec­ti­ve pro­tec­ti­ve mea­su­res. For exam­p­le, a Report published by the Natio­nal Cyber­se­cu­ri­ty Test Insti­tu­te (NTC) at the end of Janu­ary 2025 show­ed that three hos­pi­tal infor­ma­ti­on systems that are essen­ti­al for Swiss hos­pi­tals had “serious vul­nerabi­li­ties” at the time of the test. The NTC wri­tes that “cyber­se­cu­ri­ty reviews are urgen­tly nee­ded”. It con­clu­des that the­se appear to be “com­mon pro­blems in the indu­stry”, which indi­ca­te “a lack of awa­re­ness of cyber secu­ri­ty among manu­fac­tu­r­ers as well as insuf­fi­ci­ent con­trols by hospitals”.

In view of this appar­ent­ly wide­spread defi­ci­en­ci­es in the cyber secu­ri­ty of hos­pi­tals it is urgen­tly neces­sa­ry for the Fede­ral Coun­cil, tog­e­ther with the can­tons, to exami­ne which mea­su­res would be sui­ta­ble for impro­ving the secu­ri­ty situa­ti­on. This is the only way to ensu­re the pro­tec­tion of pati­ents and the main­ten­an­ce of medi­cal care