Governance / Healthcare (HIA)
CSAListed CISOaaS consultant for HIA · Up to 70% co-funding
Get HIA-ready before patient data becomes your liability.
The Act makes data security, cybersecurity and incident notification legal duties for healthcare providers and the vendors who process health information for them. CISO-as-a-Service gets you ready before it comes into force.
- Hospitals
- Clinics
- Labs & radiology
- Nursing homes
- Pharmacies
- HIMS vendors
What is HIA
One law for how Singapore’s health information is shared and secured.
The Health Information Act 2026 (No. 1 of 2026) sets up the national electronic records system (NEHR), governs data sharing for specified use cases, and imposes security and breach-notification duties on everyone in the chain.
PART 2
National records
Contribute to, and access, the national electronic records system.
PART 3
Data sharing
Share relevant information for specified use cases under data sharing agreements.
PARTS 4–5
Security & notification
Data security, cybersecurity, and notifying incidents and breaches.
PARTS 6–8
Response & enforcement
Emergency measures, data portability, codes of practice and inspections.
Implementation
- 3 Feb 2026Act enacted
- Sep 2027NEHR records from GPs, private hospitals, clinical labs and radiology
- Sep 2028Specialist outpatient clinics, nursing homes and dialysis centres
- Mar 2029Dental clinics, surgical centres and retail pharmacies
Phased timeline per MOH (healthinfo.gov.sg/hia). Each provision takes effect on a date the Minister appoints by notification in the Gazette.
Who it applies to
If you create, access or process health information, you’re in scope.
All licensed healthcare providers, regardless of size or digital maturity, plus anyone who accesses, requests, shares or processes health information for them.
Specified contributors to NEHR (First Schedule): HCSA licensees providing
- Acute hospital service
- Ambulatory surgical centre
- Assisted reproduction
- Clinical laboratory
- Community hospital
- Contingency care
- Nuclear medicine
- Nursing home
- Outpatient dental
- Outpatient medical
- Outpatient renal dialysis
- Radiological service
- Retail pharmacy licensees
Vendors too. A health data intermediary (HDI), such as a clinic or hospital management system (HIMS) provider or cloud host, must apply the same safeguards. Its client must make sure it does.
NEHR
One record, many doors.
The National Electronic Health Record (NEHR) consolidates a patient’s records from multiple providers into one longitudinal profile. Every connected provider becomes a door into a national asset — so one weak clinic is everyone’s risk.
- Visit events
- Diagnoses / reasons for visit
- Adverse drug event history
- Prescribed medications
- Dispensed medications
- Medication list
- Vaccines administered
- Laboratory test reports
- Surgical procedure notes
- Discharge summaries
- Referral memoranda
S.14 · S.22
Obligations
Contributors and users must meet the conditions and technical requirements set for NEHR.
S.29–31
Access restrictions
Class 1 and class 2 restrictions limit who may view a patient’s records.
Requirements
What the Act requires of you.
Accountability & data security
S.65
Designated individual
Name one or more people responsible for complying with Parts 4 and 5.
S.66
Secure processing
Reasonable controls, including classifying information by its nature and the impact of disclosure.
S.66
Safeguards & awareness
Protect against unauthorised access, use, copying, modification or loss, and make sure staff know their role.
S.67
Retention & disposal
Stop keeping information once it’s no longer needed, and dispose of it securely.
S.66(4)
Vendor oversight
Make sure your HDI implements the same controls and safeguards.
Cybersecurity
S.68(1)(a)
Confidentiality & integrity
Safeguard computer systems that process health information.
S.68(1)(b)
Availability
Keep information available for day-to-day care and operations.
S.68(1)(c)
Tamper protection
Protect systems, including servers and network equipment you use but don’t own, against unauthorised access, interference or tampering.
Policies & incidents
S.69
Policies & practices
Set them, make staff and HDIs follow them, and review them at the prescribed frequency.
S.70
Incident management framework
Detect and respond to incidents and breaches, find root causes, and prevent them happening again.
S.71
Minister’s directions
The Minister can direct you to fix a contravention.
Notification
S.74–75
Cybersecurity incidents
Assess suspected incidents promptly. Notify the Minister of notifiable ones within the prescribed period.
S.77–79
Data breaches
Assess breaches that cause, or are likely to cause, significant harm or reach the prescribed scale, then notify the Minister.
S.80
Affected individuals
Notify affected patients, unless an exception or waiver applies.
Non-compliance
The penalties are significant.
Maximum penalties on conviction under the Act. For organisations, security and notification failures carry fines of up to S$1 million.
S$1M
Organisation: breaching data security, retention, cybersecurity, policy or notification duties
S.66–69, S.82
S$500K
or up to 10 years’ jail
Failing to take emergency measures directed by the Minister
S.84
S$200K
or up to 2 years’ jail
Individual: breaching data security, retention, cybersecurity, policy or notification duties
S.66–69, S.82
S$100K
or up to 12 months’ jail
No incident management framework
S.70
S$50K
or up to 2 years’ jail
Improper NEHR access by a user (higher for repeat offences)
S.38
S$20K
or up to 12 months’ jail
Ignoring a direction on NEHR contribution
S.15
This is a summary only and is not legal advice. Refer to the Act for the full list of offences, including additional fines for continuing offences and higher penalties for repeat offences.
Where patient data lives
Protect every step it travels.
HIA readiness covers each system that stores or processes health information, and each hand-off between them.
Clinic
Front desk and consult rooms
Records system
Patient records
Lab & diagnostics
Results and imaging
Cloud & backup
Hosted services
How we help
Six areas, one accountable partner.
70%
Up to · co-funding
Eligible SME healthcare providers may qualify
For a cybersecurity health plan and VAPT under CSA’s SG Cyber Safe Programme.
Subject to CSA and IMDA eligibility and approval.
What you receive
Deliverables you can show.
Pricing
Pre-scoped, co-funded pricing.
CISOaaS scoped to align with the HIA Cyber Security and Data Security Essentials. Up to 70% co-funding on the first 200 end-points.
How many end-points?
What you pay
- Consultancy fee
- Funding (up to 70%)
- Out of pocket
- Optional retainer, per man-hour
- Optional retainer, per man-month
| End-points | Fee | Funding | You pay | Retainer / hr | Retainer / month |
|---|---|---|---|---|---|
| 1–5 | S$3,500 | S$2,450 | S$1,050 | S$150 | S$720 |
| 6–10 | S$3,700 | S$2,590 | S$1,110 | S$150 | S$880 |
| 11–20 | S$4,700 | S$3,290 | S$1,410 | S$150 | S$1,440 |
| 21–50 | S$7,100 | S$4,970 | S$2,130 | S$150 | S$2,160 |
| 51–100 | S$11,900 | S$8,330 | S$3,570 | S$150 | S$2,880 |
| 101–200 | S$17,900 | S$12,530 | S$5,370 | S$150 | S$4,320 |
| 201–500 (add-on, per 100) | + S$7,100 | — | — | S$150 | S$1,440 |
| 501+ (add-on, per 100) | + S$3,500 | — | — | S$150 | S$1,440 |
| End-points | Fee | Funding | You pay | Retainer / hr | Retainer / month |
|---|---|---|---|---|---|
| 1–5 | S$3,400 | S$2,380 | S$1,020 | S$150 | S$720 |
| 6–10 | S$3,600 | S$2,520 | S$1,080 | S$150 | S$880 |
| 11–20 | S$4,600 | S$3,220 | S$1,380 | S$150 | S$1,440 |
| 21–50 | S$7,000 | S$4,900 | S$2,100 | S$150 | S$2,160 |
| 51–100 | S$11,800 | S$8,260 | S$3,540 | S$150 | S$2,880 |
| 101–200 | S$17,800 | S$12,460 | S$5,340 | S$150 | S$4,320 |
| 201–500 (add-on, per 100) | + S$7,000 | — | — | S$150 | S$1,440 |
| 501+ (add-on, per 100) | + S$3,400 | — | — | S$150 | S$1,440 |
SGD. Funding covers the first 200 end-points only and is subject to CSA and IMDA eligibility and approval. Optional retainer services receive no funding support. Above 200 end-points, the 201–500 and 501+ fees are charged per additional 100 end-points, on top of the 101–200 tier fee.
Official source
Read the official Health Information Act on MOH’s portal.
Resources
Tools to check where you stand.
Start with a quick look at your exposure or readiness.
Stage 01 · Just starting
Domain scan
Understand your exposure.
Coming soon
Stage 02 · Getting compliant
Cyber Essentials readiness assessment
See how close you are to certification.
Coming soon
Stage 04 · Mature, want to improve
Attack surface assessment
Find and close gaps.
Coming soon

Where does your governance need to go next?
Tell us your target framework or challenge, and we’ll suggest a starting point.