Evaluating information security in reimbursement decisions for digital health technologies in Germany and Switzerland – stretching the fourth hurdle too far?
Benjamin Wyss, Carl Rudolf BlankartAbstract
Digital health technologies (DHTs) can improve healthcare delivery but also raise concerns about data protection and cybersecurity. Germany and Switzerland take contrasting approaches to these issues in reimbursement decision-making: in Germany, the Fast-Track procedure assigns explicit responsibility to the Federal Institute for Drugs and Medical Devices (BfArM) for evaluating data protection and cybersecurity, whereas in Switzerland no dedicated procedure exists at the reimbursement level, and these issues are treated as having been addressed at the market access stage. This study compares how data protection and cybersecurity are handled in relation to reimbursement decision-making for DHTs in both countries. We conducted a document analysis and semi-structured interviews with experts from industry and public authorities and used reflexive thematic analysis to examine the material. Interviewees in both countries reported uncertainty among stakeholders about the role of reimbursement authorities and identified limited resources and a lack of relevant expertise as important constraints. Our findings suggest that greater reliance on international standards may reduce overlap between market access and reimbursement, support clearer allocation of responsibilities, enable more predictable pathways, and help balance security with innovation. In smaller markets, additional country-specific requirements may discourage market entry and limit patient access to DHTs.