Governance / Healthcare (HIA)

CSAListed CISOaaS consultant for HIA · Up to 70% co-funding

Get HIA-ready before patient data becomes your liability.

The Act makes data security, cybersecurity and incident notification legal duties for healthcare providers and the vendors who process health information for them. CISO-as-a-Service gets you ready before it comes into force.

  • Hospitals
  • Clinics
  • Labs & radiology
  • Nursing homes
  • Pharmacies
  • HIMS vendors
Isometric illustration: Contribute, Access, Secure and Notify layers stacked under a shield

Not in healthcare?

Eligible SMEs can receive up to 70% co-funding for CISO-as-a-Service and VAPT under CSA’s SG Cyber Safe Programme as well.

What is HIA

One law for how Singapore’s health information is shared and secured.

The Health Information Act 2026 (No. 1 of 2026) sets up the national electronic records system (NEHR), governs data sharing for specified use cases, and imposes security and breach-notification duties on everyone in the chain.

PART 2

National records

Contribute to, and access, the national electronic records system.

PART 3

Data sharing

Share relevant information for specified use cases under data sharing agreements.

PARTS 4–5

Security & notification

Data security, cybersecurity, and notifying incidents and breaches.

PARTS 6–8

Response & enforcement

Emergency measures, data portability, codes of practice and inspections.

Implementation

  • 3 Feb 2026Act enacted
  • Sep 2027NEHR records from GPs, private hospitals, clinical labs and radiology
  • Sep 2028Specialist outpatient clinics, nursing homes and dialysis centres
  • Mar 2029Dental clinics, surgical centres and retail pharmacies

Phased timeline per MOH (healthinfo.gov.sg/hia). Each provision takes effect on a date the Minister appoints by notification in the Gazette.

Who it applies to

If you create, access or process health information, you’re in scope.

All licensed healthcare providers, regardless of size or digital maturity, plus anyone who accesses, requests, shares or processes health information for them.

Specified contributors to NEHR (First Schedule): HCSA licensees providing

  • Acute hospital service
  • Ambulatory surgical centre
  • Assisted reproduction
  • Clinical laboratory
  • Community hospital
  • Contingency care
  • Nuclear medicine
  • Nursing home
  • Outpatient dental
  • Outpatient medical
  • Outpatient renal dialysis
  • Radiological service
  • Retail pharmacy licensees

Vendors too. A health data intermediary (HDI), such as a clinic or hospital management system (HIMS) provider or cloud host, must apply the same safeguards. Its client must make sure it does.

Isometric illustration: a grid of blocks around a tall glass block under a shield

NEHR

One record, many doors.

The National Electronic Health Record (NEHR) consolidates a patient’s records from multiple providers into one longitudinal profile. Every connected provider becomes a door into a national asset — so one weak clinic is everyone’s risk.

  • Visit events
  • Diagnoses / reasons for visit
  • Adverse drug event history
  • Prescribed medications
  • Dispensed medications
  • Medication list
  • Vaccines administered
  • Laboratory test reports
  • Surgical procedure notes
  • Discharge summaries
  • Referral memoranda

S.14 · S.22

Obligations

Contributors and users must meet the conditions and technical requirements set for NEHR.

S.29–31

Access restrictions

Class 1 and class 2 restrictions limit who may view a patient’s records.

Requirements

What the Act requires of you.

Accountability & data security

S.65

Designated individual

Name one or more people responsible for complying with Parts 4 and 5.

S.66

Secure processing

Reasonable controls, including classifying information by its nature and the impact of disclosure.

S.66

Safeguards & awareness

Protect against unauthorised access, use, copying, modification or loss, and make sure staff know their role.

S.67

Retention & disposal

Stop keeping information once it’s no longer needed, and dispose of it securely.

S.66(4)

Vendor oversight

Make sure your HDI implements the same controls and safeguards.

Cybersecurity

S.68(1)(a)

Confidentiality & integrity

Safeguard computer systems that process health information.

S.68(1)(b)

Availability

Keep information available for day-to-day care and operations.

S.68(1)(c)

Tamper protection

Protect systems, including servers and network equipment you use but don’t own, against unauthorised access, interference or tampering.

Policies & incidents

S.69

Policies & practices

Set them, make staff and HDIs follow them, and review them at the prescribed frequency.

S.70

Incident management framework

Detect and respond to incidents and breaches, find root causes, and prevent them happening again.

S.71

Minister’s directions

The Minister can direct you to fix a contravention.

Notification

S.74–75

Cybersecurity incidents

Assess suspected incidents promptly. Notify the Minister of notifiable ones within the prescribed period.

S.77–79

Data breaches

Assess breaches that cause, or are likely to cause, significant harm or reach the prescribed scale, then notify the Minister.

S.80

Affected individuals

Notify affected patients, unless an exception or waiver applies.

Non-compliance

The penalties are significant.

Maximum penalties on conviction under the Act. For organisations, security and notification failures carry fines of up to S$1 million.

S$1M

Organisation: breaching data security, retention, cybersecurity, policy or notification duties

S.66–69, S.82

S$500K

or up to 10 years’ jail

Failing to take emergency measures directed by the Minister

S.84

S$200K

or up to 2 years’ jail

Individual: breaching data security, retention, cybersecurity, policy or notification duties

S.66–69, S.82

S$100K

or up to 12 months’ jail

No incident management framework

S.70

S$50K

or up to 2 years’ jail

Improper NEHR access by a user (higher for repeat offences)

S.38

S$20K

or up to 12 months’ jail

Ignoring a direction on NEHR contribution

S.15

This is a summary only and is not legal advice. Refer to the Act for the full list of offences, including additional fines for continuing offences and higher penalties for repeat offences.

Where patient data lives

Protect every step it travels.

HIA readiness covers each system that stores or processes health information, and each hand-off between them.

Isometric illustration: a clinic building under a medical cross

Clinic

Front desk and consult rooms

Isometric illustration: two record servers under a shield

Records system

Patient records

Isometric illustration: stacked glass blocks under a lab flask

Lab & diagnostics

Results and imaging

Isometric illustration: a storage block under a cloud

Cloud & backup

Hosted services

How we help

Six areas, one accountable partner.

Governance & accountability

Clear ownership of cybersecurity and data security.

Readiness assessment

A risk-based view of where you stand against HIA.

Remediation planning

A prioritised roadmap to close gaps.

Implementation guidance

Practical help putting controls in place.

Incident preparedness

Ready to capture, respond to and report incidents.

Assurance & reporting

Documentation that shows your readiness.

70%

Up to · co-funding

Eligible SME healthcare providers may qualify

For a cybersecurity health plan and VAPT under CSA’s SG Cyber Safe Programme.

Subject to CSA and IMDA eligibility and approval.

What you receive

Deliverables you can show.

Risk assessment

Compliance roadmap

Control recommendations

Incident response capability

Audit documentation

Pricing

Pre-scoped, co-funded pricing.

CISOaaS scoped to align with the HIA Cyber Security and Data Security Essentials. Up to 70% co-funding on the first 200 end-points.

How many end-points?

What you pay

  • Consultancy fee
  • Funding (up to 70%)
  • Out of pocket
  • Optional retainer, per man-hour
  • Optional retainer, per man-month
End-pointsFeeFundingYou payRetainer / hrRetainer / month
1–5S$3,500S$2,450S$1,050S$150S$720
6–10S$3,700S$2,590S$1,110S$150S$880
11–20S$4,700S$3,290S$1,410S$150S$1,440
21–50S$7,100S$4,970S$2,130S$150S$2,160
51–100S$11,900S$8,330S$3,570S$150S$2,880
101–200S$17,900S$12,530S$5,370S$150S$4,320
201–500 (add-on, per 100)+ S$7,100——S$150S$1,440
501+ (add-on, per 100)+ S$3,500——S$150S$1,440
HIA entity
End-pointsFeeFundingYou payRetainer / hrRetainer / month
1–5S$3,400S$2,380S$1,020S$150S$720
6–10S$3,600S$2,520S$1,080S$150S$880
11–20S$4,600S$3,220S$1,380S$150S$1,440
21–50S$7,000S$4,900S$2,100S$150S$2,160
51–100S$11,800S$8,260S$3,540S$150S$2,880
101–200S$17,800S$12,460S$5,340S$150S$4,320
201–500 (add-on, per 100)+ S$7,000——S$150S$1,440
501+ (add-on, per 100)+ S$3,400——S$150S$1,440
HIMS vendor

SGD. Funding covers the first 200 end-points only and is subject to CSA and IMDA eligibility and approval. Optional retainer services receive no funding support. Above 200 end-points, the 201–500 and 501+ fees are charged per additional 100 end-points, on top of the 101–200 tier fee.

Official source

Read the official Health Information Act on MOH’s portal.

Resources

Tools to check where you stand.

Start with a quick look at your exposure or readiness.

Isometric illustration: blocks on a platform under a magnifier

Stage 01 · Just starting

Domain scan

Understand your exposure.

Coming soon

Isometric illustration: a checklist with three ticked items under a shield

Stage 02 · Getting compliant

Cyber Essentials readiness assessment

See how close you are to certification.

Coming soon

Isometric illustration: buildings on a platform scanned by a radar

Stage 04 · Mature, want to improve

Attack surface assessment

Find and close gaps.

Coming soon

Flowing cyan and blue ribbon artwork

Where does your governance need to go next?

Tell us your target framework or challenge, and we’ll suggest a starting point.

Enquiry