Updated 3 min read

Who owns your health data?

Legally, your health data belongs to the most protected class of personal information. In Europe, the General Data Protection Regulation (GDPR) places it among the “special categories” whose processing is prohibited except under narrow, explicitly justified conditions. In the United States, protected health information is governed by a dedicated federal regime, HIPAA. Switzerland protects it as “sensitive personal data” under the revised Federal Act on Data Protection (nLPD).

Yet “most protected” does not mean “yours in practice”. Your records are scattered across the institutions that created them: hospitals, laboratories, insurers, apps. Each holds a fragment, and none of them answers to you first.

Who actually controls the data: the Data Controller

The pivotal legal role is the Data Controller: the entity that determines why and how personal data is processed. Under GDPR and the Swiss nLPD, the controller carries the legal responsibility for how data is processed; HIPAA reaches a similar result through its “covered entities” (providers, health plans, clearinghouses) and their business associates. In today’s system, that role belongs to the institution holding your record, not to you.

This is also why health data is best understood as a liability for the institutions that hold it. According to IBM’s Cost of a Data Breach Report 2026, healthcare has been the costliest sector for data breaches for the thirteenth year running. A record only becomes an asset when its processing creates value for the person it describes.

What patient ownership looks like

Ownership becomes real when three things hold at once:

  1. You hold the record. Your data from different sources lives in one place that belongs to you, not a fragment in each institution’s silo.
  2. Access runs on your consent. Every access is explicit, traceable, and revocable at any time, not buried in terms of service.
  3. An accountable steward carries the legal weight. Someone must still be the Data Controller. The question is who that entity answers to.

This is the structure Health Data Safe was created for: a Swiss non-profit foundation acting as Data Controller, holding patient data under explicit, revocable consent on open-source infrastructure. The Foundation’s statutes put patients’ fundamental rights and their control over their own data at the centre, treat health data as a common good that is neither bought nor sold, limit its use to clinical care and approved research, and give the Foundation no profit-making purpose. Under Swiss foundation law, that purpose is fixed in the Foundation’s charter and can only be changed by the supervisory authority in narrowly defined cases (Swiss Civil Code, Art. 86).

Why it matters beyond you

When patients hold their own records and share them on their own terms, research gains something the current system cannot produce: consented, research-grade data from the moment of collection.

Want to see the mechanics? How it works walks through the five steps, from creating an account to sharing and revoking access.

Sources