About Cybersecurity and Data Security (CS/DS)
The HIA includes various protective measures at multiple levels, ensuring patients' health information is kept safe and secure at every step.
Cybersecurity & Data Security Essentials
Healthcare providers are already required to protect health information under the Personal Data Protection Act 2012 (PDPA) and sectoral requirements like the Healthcare Services Act 2020 (HCSA). The HIA builds upon these existing frameworks by consolidating and enhancing security standards specifically for health information.
To ensure safe and secure handling of health information:
Healthcare Providers: Must meet mandatory cybersecurity and data security standards to contribute to, access, or share data under the HIA framework.
HIMS Vendors: That support healthcare operations and facilitate connection with the NEHR are required to meet requisite security standards and certification.
MOH Oversight: The Ministry of Health (MOH) may conduct thematic audits to ensure compliance to these security measures.
All HIA-regulated entities must comply with the security controls set out in the Cybersecurity and Data Security Essentials. These controls were developed by MOH in consultation with the Cybersecurity Agency of Singapore (CSA), the Infocomm Media Development Authority (IMDA), and the Personal Data Protection Commission (PDPC). The CS/DS Essentials provide guidance on the security measures to be put in place for the proper storage, access, use, and sharing of health information.
Incident Assessment and Reporting
When a cybersecurity incident (“incident”) or data breach (“breach”) occurs, the healthcare provider must assess it to determine if it is a notifiable cybersecurity incident or notifiable data breach under the HIA. This assessment must be conducted in a reasonable and expeditious manner. If the incident / breach is assessed to be notifiable, the healthcare provider must notify MOH within the prescribed timeframe.
Mandatory incident / breach reporting enables MOH to understand the nature and impact of the incident, monitor sector-wide risks, and provide support or guidance where appropriate.
As the HIA requirements have yet to take effect, further communications will be provided in due course on when mandatory reporting will begin.

Incident Reporting Timeline
If the incident / breach is assessed as notifiable, an initial notification must be submitted to MOH within 2 hours of the assessment.
For notifiable data breaches involving health information that are assessed to be likely to result in significant harm, healthcare providers must also notify the affected individuals.
A detailed report must be submitted to MOH within 14 days of the initial notification. The report should provide a more comprehensive account of the incident / breach, including its impact, investigation findings, remediation measures taken, and any planned actions to prevent recurrence. Where appropriate, MOH may provide guidance and resources to support the healthcare provider’s response. For more information on managing an incident / breach, please refer to the Implementation Guide.
Compliance, Liability, and Enforcement
Our Calibrated Enforcement Approach
We are cognisant that healthcare providers, retail pharmacies and approved users of the NEHR are concerned about the enforcement approaches that may be taken against them, should potential breaches occur. For any breaches, MOH will look at the facts of each case carefully. The HIA allows for a range of enforcement actions to be taken. Besides prosecution, other enforcement actions include the issuance of directions to rectify breaches, letters of warning or issuance of notices of composition.
In relation to contribution, non-compliance with contribution requirements is not an offence in the first instance, as MOH recognises that there may be genuine challenges onboarding to NEHR. If non-contribution arises from technical difficulties, MOH will support healthcare providers and retail pharmacies to resolve the underlying issue. However, in the event of deliberate or reckless non-compliance or breaches of the HIA, directions may then be issued to the healthcare provider or retail pharmacy to ensure compliance or to rectify the breach. Failure to comply with such a direction could then result in enforcement action being taken.
