HIA Readiness Checklist for Singapore GP Clinics: All 13 CS/DS Essentials Measures

The Health Information Act (HIA), MOH's upcoming law on the safe handling of health information, isn't in force yet. General practitioner (GP) clinics fall in Batch 1, due September 2027, alongside five other service types listed in the table below. The Personal Data Protection Act (PDPA), Singapore's existing data protection law, applies today. Keep the two clocks separate.

The measures come from MOH's Cybersecurity and Data Security Essentials (first edition, 2026), developed by MOH in consultation with the Cyber Security Agency of Singapore (CSA), the Infocomm Media Development Authority (IMDA) and the Personal Data Protection Commission (PDPC). They set the security measures expected of "HIA entities": every Healthcare Services Act (HCSA) licensee, which puts a licensed GP clinic in scope, plus National Electronic Health Record (NEHR) contributors and users, and prescribed entities.

HIA deadlines by clinic type

MOH batches the deadline by service type. The date below is not only a security deadline: it is the date a provider starts contributing to the NEHR and has the cybersecurity and data security measures in place.

  1. Batch 1 by September 2027 Your batch

    • Outpatient Medical Service (GP)
    • Acute Hospital
    • Community Hospital
    • Clinical Laboratory
    • Radiology Laboratory
    • Nuclear Medicine Service
  2. Batch 2 by September 2028

    • Outpatient Medical Service (Specialist)
    • Nursing Home
    • Contingency Care Service
    • Outpatient Renal Dialysis
  3. Batch 3 by March 2030

    • Outpatient Dental
    • Ambulatory Surgical Centre
    • Assisted Reproduction
    • Retail Pharmacy

MOH, Implementation Timelines, last updated 27 July 2026.

If you provide more than one service type, you have more than one deadline. MOH's rule is that "NEHR contribution and CS/DS requirements apply according to each service's respective implementation timeline". A GP practice that also runs a dental chair keeps September 2027 for the GP service and March 2030 for the dental one. The earlier date is the one that governs your planning.

What matters is the evidence. You need to be able to show that you have done what the measures ask, in the moment someone asks for it: after an incident, or if MOH follows up on a breach. So read each box below as a record you could produce, dated before anyone came looking. For each item the question is not "have we done this?" but "could we show it?"

The 13 measures fall into three groups: cybersecurity, your machines and network, including updates, anti-malware, firewalls, backups and passwords; data security, the health information itself, being who may see it and how it leaves the clinic; and common practices, how the clinic runs around the technology, from staff training to having a plan for the day something goes wrong.

Start by knowing what health information your clinic holds and can access, such as medical records and laboratory test results. Everything below is how you protect it.

Where to start

MOH doesn't rank or sequence the 13 measures set out below, so treat this order as our practical suggestion rather than the regulator's.

  • First, the protections that install once and then largely run themselves. Anti-malware on every device, and malicious-link blocking at the network layer. They close the most common attack routes for the least work. Automatic updates belong in this group too, with one difference: switching them on takes a minute, and confirming they actually ran stays a job someone in the clinic has to do.
  • Next, the measures that take real time to finish. Account and password hygiene is the hardest: unique logins for everyone, removing shared and dormant accounts, two-factor authentication and a password manager all sit in measure 2, and they are the fiddliest part to roll out. None of it can be rushed at the end.
  • Start collecting evidence now. Training records and periodic reviews cannot be backdated, and the ones you begin this month are the ones you will have. Nothing else on this list is made harder by starting late in quite the same way.
  • Write the policy documents last. A policy is easier to write once the practice it describes already exists.

If you want the certificate, the route is published. CSA's Cyber Essentials mark for HIA entities sets out what an assessor looks for, and as things stand our understanding is that earning it is not mandatory. It covers hardcopy records as well as systems, so the locked-cabinet and disposal measures are in scope too, and it separates what is required from what is merely recommended.

You will not be doing all of this unaided. MOH is issuing a guidebook and templates over 2026, which it says should cover most of the measures, and a clinic management system vendor that is CE certified builds several Section A controls in for you. Beyond that, some clinics work through it themselves, some use a self-serve platform, and some engage CISO-as-a-service.

How to work through this list

Each of the 13 measures below sets out what MOH asks for, then names the record that shows you have done it. That second line is the one that matters when someone asks you to evidence readiness, and it is the part most clinics leave until last. Work down the list and mark each measure as done, partly done, or not started. to tick it off on paper. Nothing here is submitted anywhere; it is for your own record. Unsure how the HIA relates to the PDPA? Our guide to clinic cybersecurity myths untangles that.

Where StrongKeep does some of the work, the measure is marked:

StrongKeep covers this

StrongKeep covers part of this

Unmarked measures are the clinic's own. The obligation stays yours either way: the mark is only about who does the work.

Section A: Cybersecurity (IT and software measures)

MOH applies these to computers and systems interconnected with the NEHR or containing health information.

1. Updates

  • Operating system and application updates from legitimate sources are installed promptly, critical or important ones first.

Record to keep. Nothing to buy here: switch automatic updates on, and let them run when they ask to. Keep a note of the date you last confirmed every device was current, and who checked.

2. Secure/Protect

  • Anti-malware runs on every endpoint (laptops, desktops, servers), auto-updates its signatures, scans files on access, including downloads and USB drives, and runs regular scans.
  • Firewalls are configured and deployed: built-in operating system and router firewalls in a simple setup; a perimeter firewall accepting only authorised traffic in a network setup.
  • Staff policies require authorised software from trusted sources only, trusted networks (not public Wi-Fi) for clinic data and email, and immediate reporting of suspicious emails. Staff are also told why public networks are risky, not just that they are barred.
  • You keep an inventory of all user, administrator, third-party and service accounts: name, username, department, role, date created, last log-on.
  • Each person has a unique account; shared, dormant or inactive accounts (for example, unused for over 60 days) are removed; the administrator account is used only for administrator tasks, with senior management approval.
  • Access is granted and revoked through documented approvals, reviewed on staff changes, so people reach only what their role needs.
  • For each person granted access, you record six things: name, the system they can reach, department, role or account type, the date access started, and the date it ends where there is one.
  • Default passwords are replaced with strong passphrases (MOH's benchmark: at least 12 characters, mixing upper case, lower case and/or special characters), changed on any suspected compromise. Two-factor authentication (2FA) is used for administrative access, including remote access, to important systems, such as an internet-facing system holding sensitive or business-critical data. Accounts lock after multiple failed logins (for example, after 10).
  • Third parties and contractors reach only what their work requires, lose access when done, and sign a non-disclosure agreement (NDA) if handling health information.
  • Physical access to IT assets is restricted to authorised people; log-ins are tracked and security logs are viewable only by authorised individuals.
  • Desktops, servers and routers use secure settings: weak protocols replaced before use, unused features disabled, auto-connection to open networks and auto-run of non-essential programmes switched off.

Record to keep. The largest measure, and mostly account work rather than software. The account inventory is itself the record: every user, administrator, third-party and service account, with who approved it and when it was last used. Expect to go device by device and through your Microsoft 365 or Google Workspace admin centre.

3. Backup

  • Business-critical systems and essential data are backed up regularly, at a frequency matched to recovery needs; backups are restricted to authorised personnel and stored separately from the operating environment.
  • For cloud services, know who is responsible for backup, you or the provider, and keep an alternative backup.

Record to keep. The record is your backup schedule, where the copies are kept, and who can reach them. MOH does not ask you to test a restore. It is still the only way to find out whether the backup works, so do it anyway, and date it when you do.

4. Asset

  • New hardware and software are authorised before use, approval dates recorded in an up-to-date asset inventory; anything unapproved is removed.
  • Assets past End-of-Support (EOS), when the maker stops updates and servicing, are replaced; any continued use is risk-assessed, approved by senior management and monitored until replaced.

Record to keep. The asset list is the record, and the End-of-Support line is the one with a budget attached: anything you keep running past it needs the assessment and the sign-off above, in writing.

Section B: Data security (data-related practices)

These apply to electronic data and hardcopy documents alike.

5. Secure

  • Policies identify and protect your health information, with clauses in employment and vendor contracts prohibiting unauthorised disclosure.
  • Hardcopy records live in access-controlled spots such as locked cabinets, or offsite only with storage providers whose security you have checked (with deposit records and periodic stock-takes); laptops and portable media holding health information are cable-locked when not in use.
  • Retention periods have a documented rationale, considering the PDPA, HCSA licence conditions, contracts and national guidelines.
  • Copies of health information are made only by authorised people, for an official need-to-know purpose, and staff keep possession of copies made externally.
  • Transfers are controlled: only necessary information leaves the clinic, materials stay in staff possession, screens are shielded from view, and files sent electronically are password-protected, the password sent by a different channel and recipients checked.

Record to keep. Most of this is written down rather than configured. The records are your signed policy and a retention schedule that says how long you keep each kind of record and why, with the reason traceable to the PDPA, your HCSA licence conditions or a national guideline.

6. Identify

  • Health information is marked so staff recognise it, for example headers or footers added at creation; where impractical, policy specifies which data counts as health information and staff apply the matching safeguards.
  • In deciding whether and how to mark it, you weigh four things MOH names: the format, hardcopy or electronic; how practical marking is, including the cost of changing an IT system; who handles the information, your own staff or a third-party vendor; and what the marking is meant to achieve.

Record to keep. The smallest measure on the list. The record is the policy line stating what counts as health information in your clinic, so a new staff member can tell without asking.

7. Access

  • Access to health information goes only to people with a legitimate need to know for their work, third parties included.
  • Someone with the authority to do so decides who has that need, and everyone given access acknowledges in writing that they have read your security measures, your policies, and the laws that apply such as the PDPA.

Record to keep. Someone has to decide who needs access, and that decision has to be someone's job. The record is each person's written acknowledgement that they have read your policies and the rules that apply.

Section C: Common practices (personnel training, vendor management, organisation protocols)

8. Training and education

  • Staff attend cybersecurity and data security awareness training periodically, ideally at least once a year in MOH's words, in-house, external or via self-help resources.
  • Day-to-day hygiene policies tell staff the security behaviour expected of them.

Record to keep. Only your staff can generate this one. The record is the completion register, with dates. MOH asks for training periodically, and ideally at least once a year in its own words, so what you want is a register that keeps going rather than one push before the deadline.

9. Outsourcing and vendor management

  • Any IT provider managing your network, systems or medical devices has clearly understood services, and sends regular vulnerability reports and security updates.
  • For third-party software and devices, you know where health information is stored (Singapore or overseas), what safeguards and certifications the vendor holds, and who bears what responsibility in an incident.
  • For cloud services, you understand your own responsibility for security configurations.

Record to keep. This needs someone willing to ask a supplier an awkward question. The record is the vendor's written answers: where your data sits, what certifications they hold, and who is responsible for what when something goes wrong.

10. Security reviews and internal audit

  • You periodically review your safeguards, check that policies are being followed (self-assessments or external audits, at your discretion), and fix any lapse promptly, retraining where needed.

Record to keep. Keeping evidence is not the same as reviewing it. The record is a dated review note saying what you checked, what had slipped, and what you did about it.

11. Disposal

  • Health information is securely destroyed before any hardware or data is disposed of: shred documents, encrypt a hard disk before reformatting, overwrite stored data completely.

Record to keep. The record is a disposal log: what was destroyed, when, by whom, and how. This applies to paper as much as to hard disks.

12. Emergency planning for contingency

  • A business continuity plan identifies critical assets needing high availability and their redundancies, covers disruptions including cyber incidents and data breaches, and is ready to execute.

Record to keep. The record is the plan itself, dated, plus evidence someone has actually read it. The useful test is whether your practice manager could run it on a Tuesday morning without calling you, because that is the scenario it exists for.

13. Incident response

  • An up-to-date incident response plan assigns roles, sets procedures to detect, respond to and recover from common threats such as phishing and ransomware, and includes a communication plan with escalation timelines for internal and external stakeholders.
  • Everyone with access to your IT environment knows the plan and how to report suspicious activity.

Record to keep. The record is the plan plus evidence your staff have seen it. Under the HIA the first notification to MOH is due within two hours of assessing that a threshold is met, which is not enough time to work out who to call.

Incident reporting under the HIA: thresholds and timelines

Once the HIA applies to your clinic, these are the reporting rules in the Essentials; until then, PDPA breach notification to the PDPC remains the live duty.

What is reportable Threshold
Cybersecurity incident Involves a computer or system that contains health information, or is interconnected with one, and that is under the clinic's control
Data breach Aligned to the PDPA threshold: the breach results in, or is likely to result in, significant harm to an affected individual, or is, or is likely to be, of significant scale (500 or more affected individuals)

For both categories:

  • Initial notification to MOH within 2 hours after the clinic assesses that the incident meets a reporting threshold.
  • An incident report within 14 days of the initial notification.
  • The clinic must notify affected individuals at the same time as notifying MOH, or as soon as practicable after, if the incident causes or is likely to cause significant harm.

MOH's examples of notifiable cybersecurity incidents include unauthorised hacking, malicious software, denial-of-service and man-in-the-middle attacks. What counts as "significant harm" will be detailed in subsidiary legislation, and the specific reporting process will be shared in due course.

September 2027 sounds far away, and thirteen measures do not embed in a quarter. The useful question is not which ones you could tick today, but which ones you could evidence today, because those are different lists and only the second one counts.

If the gap is people rather than intent, meeting the Essentials without an IT team walks the sequence a practice manager can run.

Frequently asked questions about the HIA

Is the HIA in force yet?

No, not yet. GP clinics sit in Batch 1 of the implementation timeline, due September 2027. The clock already running is the PDPA's: Singapore's existing data protection law applies to your clinic today, HIA or not.

Which batch are GP clinics in?

Batch 1, by September 2027. Five other service types share that date: acute hospitals, community hospitals, clinical laboratories, radiology laboratories and nuclear medicine services. Batch 2 (specialist outpatient, nursing homes, contingency care, outpatient renal dialysis) follows by September 2028, and Batch 3 (dental, ambulatory surgical centres, assisted reproduction, retail pharmacy) by March 2030. That date is when NEHR contribution starts as well as when the cybersecurity and data security measures have to be in place. The full table of service types is on this page.

What happens if my clinic misses its deadline?

Not settled yet, and worth being straight about that. The Health Information Act gives MOH enforcement powers, which the Minister of State set out at the Bill's Second Reading, but the specifics, including what counts as significant harm and how penalties are set, come in subsidiary legislation that has not been published. What is already true is that the PDPA applies to your clinic today, with its own enforcement regime, so a clinic with weak data security is exposed now rather than only from 2027.

Do the CS/DS Essentials apply to my clinic?

Yes, if your clinic is an HIA entity, and a licensed GP clinic is one. The Essentials apply to every Healthcare Services Act (HCSA) licensee, to National Electronic Health Record (NEHR) contributors and users, and to prescribed entities. Hold an HCSA licence? That's you.

Sources

This article is general information for clinic owners, not legal advice. For guidance on your clinic's specific obligations, consult a qualified professional or contact MOH's HIA enquiries channel.