National Electronic Health Record (NEHR) for Healthcare Providers
The NEHR is a secure, nationwide health record that enables authorised healthcare professionals to access key health information, supporting safer, more connected care across Singapore. Synapxe manages and operates the NEHR.
Contributing Health Information to NEHR
Healthcare providers are responsible for contributing the required data generated during a patient visit in Singapore, to the NEHR.
What to Contribute: Healthcare providers must upload key "health information" such as patient demographics, prescriptions, diagnostic test results, medical procedures, and discharge summaries. The exact datasets required are tailored to the specific healthcare provider category, as set out in the First Schedule of the HIA.
What is Excluded:
Records of Foreign Patients: Only key health information relating to Singapore citizens, permanent residents, and holders of a foreign identification number (FIN) is required to be contributed. Records pertaining to all other foreign patients are out of scope.
Raw Clinical Notes: Unstructured, highly granular clinical narratives are excluded. Excluding these keeps the NEHR streamlined, high-yield, and easy for other providers to navigate.
Data that is Not Generated: If the data is not generated during the healthcare service provision, there is no need to contribute the data. For instance, if a healthcare provider did not prescribe medications, there is no need to contribute medication data.
Retrospective Records: Contribution requirements only apply prospectively. Historical records should not be uploaded.
Accessing the NEHR
The HIA regulates who can access and view patient records in the NEHR. Healthcare providers must ensure that NEHR access is granted only to healthcare professionals (doctors, nurses, pharmacists, and allied health professionals) who require it for direct patient care. Administrative and corporate staff should not have NEHR access. Healthcare providers may refer to the Second Schedule of the HIA for guidance on NEHR access eligibility based on healthcare service type.
Healthcare providers must also ensure that authorised staff manage NEHR information properly by providing regular training on appropriate access and use, cyber and data security, and by conducting regular audits to monitor how their staff accesses the system. Authorised individuals must access NEHR information only for patients to whom they are actively providing care.
Appropriate Use of the NEHR
Permitted Uses | Strictly Prohibited Uses | ||
|---|---|---|---|
Delivering direct patient care | Checking on patients not registered under their care | ||
Whitelisted statutory medical examinations (e.g. SAF/SCDF/SPF enlistment, infectious disease control) (Refer to Third Schedule of the HIA) | Filling out medical reports for insurance claims | ||
Compliance with a court order or written law | Pre-employment medical screenings, or any other HR or employment-related assessments |
Important Clinical Guidance: Accessing the NEHR is not mandatory for every consultation. It should be viewed as an adjunctive source of information. It does not replace professional judgement, history-taking, or physical examination.
Note: All access and use must align with the relevant professional standards such as those under the Ethical Code and Ethical Guidelines (e.g. SMC ECEG), as well as MOH's published Guidelines on Appropriate Contribution, Use and Access to NEHR. Unauthorised access to NEHR, such as for for employment or insurance purposes is an offence under the HIA.
Technical Safeguards (System Controls)
Technical restrictions are implemented in NEHR to control who can access health information.
Role-Based Access Control: Professionals only see data fields matching their specific medical role.
Volumetric Rate Limits: Safeguards prevent bulk extraction by limiting the number of patient records accessed in a timeframe.
Automated Threat Detection and Regular Compliance Audits: Synapxe runs continuous monitoring to detect and alert on suspicious access patterns and runs independent system audits monitoring access logs to spot anomalous behaviour.
Progressive Security Scaling: Infrastructure undergoes continuous, progressive rollouts of advanced security patches.
Patient Access History and Access Restrictions
Patients can view their key health information through HealthHub and review which healthcare institutions have accessed their National Electronic Health Record (NEHR). The "NEHR access history" feature displays access at the institution level for the past 12 months. For public healthcare institutions, access is presented at the cluster level.
Healthcare providers should be aware that patients may review their NEHR access history through HealthHub. Accordingly, all access to patient records should be appropriate, for legitimate clinical or operational purposes, and in accordance with the Health Information Act (HIA). Patients who have concerns about unauthorised access may report the matter to Synapxe for investigation, and healthcare institutions may be required to support such investigations where necessary.
Managing Patients with Access Restrictions
From 2027, we will allow patients greater control regarding who can access their information on National Electronic Health Record (NEHR). Those who chose to place access restrictions may restrict their NEHR access to entities that they select.
For information on how patients may apply for or manage Access Restrictions, please refer patients to the Synapxe website or HealthHub.
When access restrictions are in place, healthcare providers will continue to have access to a limited set of information required to support safe care, namely the patient's name, NRIC or FIN, date of birth, race, sex, allergies, and vaccination records.
What Healthcare Providers Should Note
Healthcare providers should be aware of the following operational considerations:
Contribution continues: Under the HIA, required health information must continue to be contributed to the NEHR regardless of whether a patient has placed Access Restrictions.
Application channels: Patients can currently submit a request to place Access Restrictions at selected public healthcare institutions. From 2027, they will be able to do this via the HealthHub app.
Institution Level, Not Individual Level Restrictions: Access Restrictions apply at the institution level. This means Access Restrictions cannot be placed on specific healthcare professionals within the same institution.
Healthier SG Condition: Access Restrictions cannot be placed on the primary care provider (PCP) of a Healthier SG (HSG) enrollee.
Healthcare providers should exercise clinical judgment when caring for patients with Access Restrictions, recognising that incomplete health information may affect clinical decision-making and continuity of care. Where appropriate, providers should counsel patients on the potential implications of restricting access to their health information so they can make informed decisions.
Emergency (Break-Glass) Access
From 2027, in life-threatening medical emergencies (e.g., severe allergic reaction, stroke, heart attack), doctors may override a patient's Access Restriction to deliver timely, life saving care. This emergency access feature is also found in national health repositories in jurisdictions such as Finland, Australia, and Hong Kong.
Re-verify Credentials
The doctor must securely log in and re-authenticate their identity before proceeding with the override.Declare Medical Emergency
The doctor must formally declare in the system that the patient faces an immediate, life-threatening condition. This feature must never be used for non emergencies or simply at the patient's request.Access Records & Provide Care
The Access Restriction is bypassed, allowing the doctor to view the necessary health information to make rapid, life-saving clinical decisions.Automatic Logging and Audits
All instances of overridden Access Restrictions are automatically logged by Synapxe. Inappropriate use of the break-glass feature is a breach of the HIA.
Health Information Management Systems (HIMS)
In a digitised healthcare ecosystem, electronic documentation is the foundational baseline for clinical operations. A Health Information Management System (HIMS) serves as the central hub for collecting, storing, managing, and securely exchanging patient health information.
Under the Health Information Act (HIA), healthcare providers must utilise a HIA compliant HIMS to seamlessly and securely connect to and contribute core health information to the National Electronic Health Record (NEHR).
Healthcare providers may browse options for HIA-compliant HIMS on the certified HIMS provider directory on Synapxe, and find one that fits their organisational needs.
⚖️ Legal Accountability
As HIMS vendors are interconnected to NEHR and process health information on behalf of healthcare providers, they are required to meet requisite CS/DS requirements under the HIA.
Technical Framework for HIMS Compliance under the HIA
To achieve formal HIA-compliance certification, HIMS must satisfy NEHR Connectivity requirements alongside mandatory third-party governance certifications.
NEHR Connectivity
System Integration Requirements
Data Integration Requirements
National Coding Standards
Governance & Compliance: Technical functionality must be backed by security governance frameworks to safeguard data at rest and during provider transitions:
Cyber Essentials (CE) for HIMS: HIMS vendors are required to achieve the Cyber Essentials for HIMS Vendors Certification. Administered by the Cybersecurity Agency of Singapore (CSA), this certification verifies that the provider's product and internal operational infrastructure align with the HIA’s CS/DS Essentials.
Code of Practice for Data Portability (CODE): When healthcare providers switch from one HIMS to another, accurate and complete porting of patient records between systems is essential to ensure safety and for continuity of care. HIMS vendors are required to self-declare their adherence to the CODE, which sets out MOH’s minimum expectations for data migration to ensure data portability.
Alternate Contribution Channel (ACC)
To support healthcare providers requiring additional time to complete their digitalisation journey and adopt a fully compliant HIMS, MOH will provide the Alternate Contribution Channel (ACC). The ACC is a secure, web-based portal that allows clinics to manually upload and submit required data to the NEHR. This ensures providers can meet their statutory contribution requirements even if their internal systems are not yet fully integrated.
Further operational details, including eligibility criteria, onboarding application methods, and pricing structures, will be announced by MOH at a later date.
⚠️ Important Transition Notice
The ACC is intended as a temporary transition measure during the initial implementation of the HIA. As the web-portal data entry requires manual administrative effort, automated data transmission via an integrated, HIA-compliant HIMS remains the standard and preferred long-term approach to ensure efficient, seamless, and safe care delivery.
