A wish or some feedback about tunnl.? We would love to hear your echo.

Write an echo
New message
Settings
Appearance
Language
DEEN
Admin cockpit

In brief

Sending patient data and medical reports securely

Health data is especially sensitive – legally and in everyday practice.

Health data counts as especially sensitive personal data, and professional secrecy under article 321 of the Swiss criminal code applies on top. Between practices and hospitals, HIN is the Swiss standard and remains the right choice. For the route to people without HIN – patients, lawyers, insurers, relatives – you need something that works without an account on the other side.

What applies

Under the revised Swiss data protection act, health data is especially sensitive personal data. For doctors, dentists, therapists and practice staff, professional secrecy applies on top – a breach is prosecuted ex officio. An unencrypted medical report by mail is therefore not merely unwise.

This also covers the seemingly harmless: an appointment confirmation from an oncology department says something through its sender alone that is nobody else’s business.

HIN – and where it ends

Between healthcare providers, HIN is the Swiss standard: encrypted mail inside a closed, vetted circle. Anyone working with it should stay with it – for referrals, reports and exchange with hospitals that is the established route.

The gap lies outside that circle. The patient wants her report. The lawyer needs a file. The insurer requires a form. A daughter is organising care for her father. None of these people has HIN, and none will set it up for one errand.

What has to close that gap

Three things: the content must not sit readable at the provider. The other side must not need an account, or it will not be used. And it must expire by itself, so the report does not sit in a private mailbox for years.

And with tunnl.

tunnl. closes exactly that gap. The report is encrypted in the browser at the practice, the patient opens a link and reads – no account, no app. For sensitive cases add a password handed over at the desk or by phone. After the window the content is gone, for us too. Servers and company are in Switzerland, and a data processing agreement is ready to print at /avv.

What tunnl. cannot do here: tunnl. does not replace HIN between healthcare providers and is not a patient record. It is the route for the single errand going outwards. Whether it suffices for your practice is decided by your data protection concept – and in doubt, by your professional association.

How tunnl. encrypts · Data processing agreement · What we store

We cannot read your messages. We do not store IP addresses.

What for?Help & questionsEcho usPrivacyLegal notice

Beta

xoox ag · bluematic ag · cloud services ag