Skip to content
Back to overview
Data privacyMarch 202612 min read

Privacy-First AI: Why patient data must not end up on US servers

Clinics can gain a lot of operating room from AI. Without control over hosting and data paths, that same gain turns into a privacy and trust problem.

In short

Health data is a legal category of its own, and three developments are tightening the picture right now. Europe's data protection authorities hold that a model trained on personal data cannot simply be treated as anonymous.[3] The AI Act's transparency obligations have applied since August 2026.[6] And the European Health Data Space takes effect from March 2027.[5] Putting an AI into clinic operations today also decides how expensive the correction will be in two years.

The problem with public APIs

Running a generic chatbot through a standard API often means moving sensitive content into a legal and operational environment outside your own organisation. That is a very different risk profile for medical or personal data than for ordinary website copy.

In clinic settings, convenience and compliance clash quickly. Even where providers talk about low retention, the questions around access, responsibility and traceability often remain unresolved.

What the law singles out

Health data is no ordinary personal data. The GDPR lists it as a special category whose processing is prohibited in principle and allowed only through narrow exceptions.[1] Swiss data protection law likewise counts health data among the specially protected categories, with a higher bar for consent and care.[2]

For clinic operations that means: even the question of which chat thread a diagnosis appears in is a data protection question. Whoever routes such content through a generic API carries the burden of showing the path is clean, and the provider does not carry it for them. This text replaces no legal advice; mapping which data classes appear in your own funnel still belongs at the start of every AI project.

A trained model is not automatically anonymous

The most common misconception in AI projects runs like this: whatever went into training has dissolved in there and is therefore anonymous. The European Data Protection Board published an opinion in 2024 that denies exactly this. AI models trained on personal data cannot in all cases be considered anonymous; anonymity requires that both direct extraction and obtaining personal data through queries are insignificantly unlikely.[3]

For a clinic this carries an uncomfortable second half. The same opinion holds that an organisation deploying such a model must, under its own accountability, assess whether the model was not developed through unlawful processing of personal data.[3] Responsibility does not end with the provider. It begins with the selection, and it cannot be delegated to a contract that only describes what the provider promises to do.

The transfer path to the US

Where a model runs is no matter of IT taste. In 2020 the Court of Justice of the European Union invalidated the adequacy decision behind the EU-US Privacy Shield and required a third country to offer protection essentially equivalent to the EU standard, including scrutiny of government access there.[4] Its predecessor had already fallen before that.

Today's successor, the EU-US Data Privacy Framework, holds: in 2025 the General Court dismissed an action against the adequacy decision.[7] Sending patient data to the US therefore rests on a viable legal basis that remains subject to periodic review, and whose two predecessors both fell in court. That is no reason to panic. It is a reason to know the way back before you need it.

The Health Data Space from 2027

The regulation on the European Health Data Space has been in force since March 2025 and applies from 26 March 2027, with staggered deadlines for the individual data categories through 2031.[5] It governs both patient and clinician access to health data and its secondary use, and it gives patients explicit rights to restrict access and to opt out of secondary use.

For a clinic selecting systems today this is less a deadline than a direction: regulatory pressure on health data keeps growing over the coming years. An architecture in which nobody can say where which data sits becomes more expensive under it, not cheaper.

What the law requires, and when

Since / fromWhat appliesWho it affects
OngoingHealth data as a special category (GDPR Art. 9, Swiss FADP)Every processing step, including chat
2 August 2026AI Act transparency obligations: AI must be recognisable as AIThe provider of the system; the clinic checks when selecting
26 March 2027European Health Data Space, staggered through 2031Health data and its secondary use

The table orders dates, not obligations in an individual case. Which of them apply to your organisation is a question for your own legal counsel.

The two major downstream effects

Legal and operating risk

Unclear data paths can create liability exposure, internal approval problems and costly rebuilds later. The core issue usually sits in the operating model rather than in the contract wording.

Loss of trust in the market

If you collect sensitive information, you need to signal control in first contact. Fuzzy infrastructure or cloud dependence directly works against brand and conversion.

What the RakenAI approach looks like

Privacy-first does not mean giving up modern models. It means placing model execution and data handling on an inspectable architecture.

Swiss or EU infrastructure

Models and sensitive workloads can run in clearly defined legal environments on dedicated infrastructure.

Permissions and auditability

Access, escalation and write rights are designed so later it remains understandable who was allowed to see or trigger what.

No open training path

Patient messages and internal information are not silently fed into external product models.

The Swiss view

The Swiss Federal Data Protection and Information Commissioner makes clear that the data protection act is written technology-neutrally and therefore applies directly to AI-supported data processing as well.[8] The transparency expectation goes beyond the usual privacy-notice level: the purpose, the way it works and the data sources of AI-supported processing belong in the open, and explicitly also whether entered data is reused to improve self-learning systems.

That makes the third point of our architecture, the missing training path, no marketing promise in Switzerland. A supervisory authority wants that question answered.

Three questions before any AI project

Where do prompts and uploads go, and in which jurisdiction do the servers stand? The answer has to be a place, and no diagram with question marks.

Who can access, and how is deletion handled? Whether an incident becomes a manageable process or a reputation problem is decided by roles, logs and deletion periods.

What flows into someone else's training? A no has to be secured technically, and a contract clause alone secures nothing.

These three answers take an hour when the architecture is clean, and they are found in no contract when it is not. Our general position is on the data sovereignty page; the entry point is a question for the audit.

When the effort is not warranted

Not every AI initiative in a clinic needs dedicated infrastructure. Running a model purely on public text, meaning website copy, general preparation guidance or internal drafts without personal references, solves a problem with dedicated servers that does not exist at that point.

The data class decides how much effort is warranted. As soon as a patient names their name, their appointment or their complaint in a channel, the processing is a different one. That is exactly why classifying the data comes at the start of a project, not at the end.

Why this matters commercially as well

In sensitive markets, privacy is not a legal appendix. It is part of the sales experience and the brand promise. Teams that can make control visible tend to build trust faster in discovery, first response and implementation.

That is why privacy-first is not an isolated page for RakenAI. It is a visible component of product, design and architecture.

The effect shows up in real conversations: after price, the most frequent question from international patients is often how their data is handled. A clear answer at that moment sells, and no answer does too.

Frequently asked questions

May patient data be processed on US servers?

A transfer to the US is not banned outright, but it needs a viable legal basis. In 2020 the Court of Justice struck down the adequacy decision of the time and required protection essentially equivalent to the EU standard;[4] the current successor was upheld in court in 2025.[7] For health data the stricter requirements for special categories apply on top.[1] The assessment for your specific case belongs to legal counsel.

Are AI models anonymous once they are trained?

Not automatically. According to an opinion of the European Data Protection Board, models trained on personal data cannot in all cases be considered anonymous.[3] Anyone deploying a model must also assess for themselves whether it was developed lawfully.

What is the European Health Data Space?

An EU regulation governing access to health data and its secondary use. It has been in force since March 2025 and applies from 26 March 2027, with staggered deadlines through 2031.[5] Patients receive explicit rights to restrict access and to opt out of secondary use.

Is a contract that rules out training enough?

A contract is necessary and not sufficient. The Swiss data protection commissioner expects disclosure of whether entered data is reused to improve self-learning systems;[8] a no is technically secured only when the data path does not permit it in the first place.

Which data does a clinic chatbot actually need?

For appointment questions, preparation and logistics, the appointment, the language and the contact channel are enough. Diagnoses and treatment details do not belong in a dialogue channel that does not need them. What that looks like for appointments is in the piece on AI and no-shows.

Does an AI system have to identify itself as AI?

In the EU the AI Act's transparency obligations have applied since 2 August 2026: anyone interacting with an AI system must be able to recognise it.[6] The duty addresses the provider of the system first; the clinic checks it when selecting.

Does privacy-first mean giving up good models?

No. It means controlling where the model runs and how the data travels. What model quality is achievable depends on the setup, not on the principle.

Sources

  1. 1.GDPR: Art. 9 — Processing of special categories of personal data gdpr-info.eu/art-9-gdpr/
  2. 2.Swiss Federal Act on Data Protection (FADP), SR 235.1 www.fedlex.admin.ch/eli/cc/2022/491/de
  3. 3.European Data Protection Board: Opinion 28/2024 on data protection aspects of AI models (adopted 17 December 2024) www.edpb.europa.eu/system/files/2024-12/edpb_opinion_202428_ai-models_en.pdf
  4. 4.Court of Justice of the European Union, judgment of 16 July 2020, C-311/18 (Schrems II) eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A62018CJ0311
  5. 5.Regulation (EU) 2025/327 on the European Health Data Space eur-lex.europa.eu/eli/reg/2025/327/oj
  6. 6.Regulation (EU) 2024/1689 (AI Act), Art. 50 eur-lex.europa.eu/eli/reg/2024/1689/oj
  7. 7.General Court of the European Union, judgment of 3 September 2025, T-553/23 (Latombe) eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A62023TJ0553
  8. 8.Swiss Federal Data Protection and Information Commissioner: AI and data protection www.edoeb.admin.ch/de/ki-und-datenschutz
Next step

Clarify data sovereignty early, before the system has to be corrected later at high cost.

We can design the right infrastructure and audit model for your setup.