
IT security for hospitals, clinics and life sciences
A budget competing against medical equipment and staffing, devices that cannot be patched, and an operation with no maintenance window. Where we start in healthcare.
The situation
Swiss acute care hospitals reached an EBITDAR margin of 6.8 percent in 2025. That is better than in previous years, but still clearly below the roughly ten percent needed to self-finance investment. The net margin was back in positive territory for the first time in years, at 1.0 percent (PwC hospital study, July 2026, fiscal year 2025).
In plain terms: it is enough to operate, not enough to invest. A security budget in that situation competes directly with medical equipment and staffing, and it only wins that comparison when the benefit is expressed in downtime and operational risk rather than threat scenarios.
At the same time the technical starting point is harder than in almost any other industry. Medical devices run on vendor-approved software versions, the operation runs around the clock, and maintenance windows barely exist. Every change has to fit the clinical routine, not the other way round.
And there is a new topic on top: speech recognition and documentation assistants are in use in many institutions faster than the rules covering them, and they process patient data.
What we find in this industry
- Every franc has to be justified against equipment and staffSecurity only wins that comparison when the benefit is expressed in downtime and operational risk. A predictable amount beats an open-ended consulting mandate in this setting.
- Medical devices cannot simply be updatedSoftware versions are vendor-approved. An update on your own initiative can affect the device's certification. Securing them means segmenting and monitoring, not patching.
- The operation runs around the clockMaintenance windows barely exist. Every change has to be agreed with the clinical routine, and anyone who does not plan for that will not get their project past operations management.
- Many professions, shift work, high turnoverShared logins are not carelessness. They appear because the process at the bedside has to be faster than the login. Solutions therefore have to start at the workflow.
- Patient data with evidence duties, but no dedicated roleResponsibility ends up with the IT team that is already at its limit. It is formally assigned and practically vacant.
- AI tools arrive faster than the rulesDictation and documentation assistants are introduced by clinical departments, often without clarifying which data may go in and where it is processed.
Typical trigger
An incident at another institution, an audit finding, or a tender that demands security evidence. Or the question whether an AI tool may work with patient data.
The ODCUS difference
No selling of additional tools. The first step is always: what do you already have, what of it works, and what can we cut? Most mandates start by reducing cost and improving protection at the same time.
Why these services fit
A known amount instead of an open consulting bill
CHF 9,800 fixed price, and the result is a prioritised roadmap with measures that actually get implemented. We assess infrastructure, processes and data protection on site.
In an institution where every expense must be justified, predictability is an argument in itself.
Relief for IT, not another load on it
We take on security responsibility instead of leaving it with a stretched IT team, and align measures with clinical operations.
Senior experience on the days it is needed, without another full-time line in the staffing plan.
Protection requirements and evidence, without slowing care
We assess protection requirements and risks along the care processes and document them so the evidence holds up with regulators and partners.
Data protection under the revised Swiss FADP is built in, including a data protection impact assessment where one is needed.
Clear rules before patient data flows into AI tools
We clarify which tools are permitted, which data may go into them, and how that is documented so it can be evidenced.
On request as a management system to ISO/IEC 42001, when the owning body or partners expect formal proof.
Who it is for
- Hospitals, clinics and care homes with a thin IT team
- Institutions with medical devices that cannot be freely updated
- Organisations holding patient data with evidence duties under the Swiss FADP
- Operations where AI tools are already in use without rules for them
Related engagements
- Gap assessment against CIS Controls with an implementation roadmap
- Email migration for a university with 12,000 mailboxes
- Hardening a Microsoft 365 tenant including device management
Anonymised looks at real engagements. Not all of them come from this industry, but the task is the same.
FAQ
How do we secure medical devices we are not allowed to patch?
By segmenting them, monitoring them and controlling access to them. That is established practice and does not touch the device's certification. It does require an inventory that shows which devices are on the network in the first place.
May we use AI tools with patient data?
That depends on the tool, the place of processing and the legal basis, not on the technology as such. We clarify it per tool and record the outcome so it can be evidenced to regulators and patients.
We have no maintenance window. How is this supposed to work?
By planning measures so they do not interrupt clinical operations, and by rehearsing the incident case instead of improvising it. Anything that cannot be done without an interruption is scheduled and agreed with operations management.
What does it cost to start?
The security assessment costs CHF 9,800 at a fixed price, including implementation of the most urgent measures. The step before that, a criteria-based initial review in conversation, is free.
Let us talk about your situation
Thirty minutes, free and without obligation. We tell you honestly whether and where we can help.

