Updated 2 min read

Who owns your health data?

Legally, your health data is treated as the most sensitive category of personal information that exists. In Europe, the General Data Protection Regulation (GDPR) places it among the “special categories” whose processing is prohibited except under narrow, explicitly justified conditions. In the United States, protected health information is governed by a dedicated federal regime, HIPAA. Switzerland protects it under the revised Federal Act on Data Protection (nLPD).

Yet “most protected” does not mean “yours in practice”. Your records are scattered across the institutions that created them: hospitals, laboratories, insurers, apps. Each holds a fragment, and none of them answers to you first.

Who actually controls the data: the Data Controller

The pivotal legal role is the Data Controller: the entity that determines why and how personal data is processed. Under GDPR, HIPAA and the Swiss nLPD alike, being a Data Controller means accepting full legal accountability for data governance. In today’s system, that role belongs to the institution holding your record, not to you.

This is also why health data is best understood as a liability for the institutions that hold it. Healthcare has been the most expensive sector for data breaches for fourteen consecutive years. A record only becomes an asset when its processing creates value for the person it describes.

What patient ownership looks like

Ownership becomes real when three things hold at once:

  1. You hold the record. Your data from different sources lives in one place that belongs to you, not a fragment in each institution’s silo.
  2. Access runs on your consent. Every access is explicit, traceable, and revocable at any time, not buried in terms of service.
  3. An accountable steward carries the legal weight. Someone must still be the Data Controller. The question is who that entity answers to.

This is the structure Health Data Safe was created for: a Swiss non-profit foundation acting as Data Controller, holding patient data under explicit, revocable consent on open-source infrastructure. The Foundation’s statutes put patients’ fundamental rights and their control over their own data at the centre, treat health data as a common good that is neither bought nor sold, limit its use to clinical care and approved research, and give the Foundation no profit-making purpose. Swiss foundation law makes that mission permanent.

Why it matters beyond you

When patients hold their own records and share them on their own terms, research gains something the current system cannot produce: consented, research-grade data from the moment of collection.

Want to see the mechanics? How it works walks through the five steps, from creating an account to sharing and revoking access.