A new law that changes how healthcare data must be protected
The Health Information Act (HIA) is Singapore's legislative framework requiring all licensed healthcare providers to secure patient health information and contribute to the National Electronic Health Record (NEHR) — the national system that shares patient records across healthcare providers for better, safer care.
Because NEHR is national critical infrastructure, HIA imposes cybersecurity obligations on healthcare organisations that go well beyond general data protection requirements. Being PDPA-compliant is not enough — HIA imposes a separate, additional layer of obligations on top of PDPA.
HIA applies to all licensed healthcare providers in Singapore
If your organisation holds or accesses patient health information — or builds systems that do — you are likely within scope.
HIA obligations follow the data, not just the institution. If your vendors or cloud systems process NEHR-linked data, they fall within your compliance perimeter too.
End-to-end support — from gap assessment to ongoing governance
Our consultancy is pre-scoped to align directly to MOH's Cyber Security and Data Security Essentials under HIA, so you know exactly what's covered from day one.
Gap Assessment
We assess your current controls, policies and governance against MOH's guidelines — giving you a clear, prioritised list of what needs to be done and in what order.
Risk Remediation
We assist you to implement the required technical controls: access management, audit trails, system security, and data protection policies aligned to HIA requirements.
Documentation
Data protection policies, data inventory mapping, accounts inventory, and an incident response plan designed around the 2-hour MOH notification requirement.
Retainer & Governance
Optional ongoing advisory retainer for policy reviews, staff awareness training, and continuous governance support as HIA requirements evolve.
Service fees
Fees are based on the number of endpoints. Two tracks are available: one for licensed healthcare providers (HIA entities), and one for HIMS vendors and system operators.
| Endpoints | Service Fee | CSA Co-Funding Cap | What You Need to Pay | Retainer/hr | Retainer/month |
|---|---|---|---|---|---|
| 1 – 5 | S$6,500 | S$3,893.17 | S$2,606.83 | S$250 | S$1,600 |
| 6 – 10 | S$7,000 | S$4,310.83 | S$2,689.17 | S$250 | S$1,800 |
| 11 – 20 | S$9,500 | S$5,862.50 | S$3,637.50 | S$250 | S$2,400 |
| 21 – 50 | S$14,000 | S$9,339.17 | S$4,660.83 | S$250 | S$4,000 |
| 51 – 100 | S$20,000 | S$14,639.33 | S$5,360.67 | S$250 | S$6,800 |
| 101 – 200 | S$25,000 | S$21,597.92 | S$3,402.08 | S$250 | S$12,500 |
| 201 – 500 endpoints (in increments of 100): Co-funding available up to the first 200 endpoints only. Contact us for pricing. | |||||
| 501 and above (in increments of 100): No co-funding. Contact us for pricing. | |||||
Retainer fees are optional and not eligible for co-funding. Co-funding is fully passed on to your organisation.
| Endpoints | Service Fee | CSA Co-Funding Cap | What You Need to Pay | Retainer/hr | Retainer/month |
|---|---|---|---|---|---|
| 1 – 5 | S$7,000 | S$4,114.95 | S$2,885.05 | S$250 | S$2,000 |
| 6 – 10 | S$7,600 | S$4,462.15 | S$3,137.85 | S$250 | S$2,200 |
| 11 – 20 | S$10,500 | S$6,373.15 | S$4,126.85 | S$250 | S$3,000 |
| 21 – 50 | S$16,000 | S$9,931.48 | S$6,068.52 | S$250 | S$4,800 |
| 51 – 100 | S$22,000 | S$15,367.92 | S$6,632.08 | S$250 | S$7,800 |
| 101 – 200 | S$28,000 | S$22,512.00 | S$5,488.00 | S$250 | S$14,500 |
| 201 – 500 endpoints (in increments of 100): Co-funding available up to the first 200 endpoints only. Contact us for pricing. | |||||
| 501 and above (in increments of 100): No co-funding. Contact us for pricing. | |||||
Retainer fees are optional and not eligible for co-funding. Co-funding is fully passed on to your organisation.
Frequently asked
Is my clinic or practice affected by HIA?
If you are a licensed healthcare provider in Singapore — including private GP clinics, dental practices, specialist centres, allied health providers, and clinical laboratories — you are within scope. HIMS vendors that manage health information systems for healthcare providers are also covered. When in doubt, contact us for a quick check.
We're already PDPA-compliant. Does that cover HIA?
No. PDPA and HIA are separate frameworks. PDPA governs how you handle personal data you already hold. HIA additionally requires you to actively contribute data to NEHR, secure the systems through which NEHR is accessed, and meet MOH’s specific Cyber and Data Security Guidelines — none of which PDPA covers.
How do I access the 70% co-funding?
Sign up via the IMDA CTOaaS portal at smesgodigital.gov.sg — do not engage us directly first if you wish to claim co-funding. After your application is approved, contact us to begin the engagement. The co-funding is fully passed on to your organisation.
What does the service cover, and how long does it take?
Our service is pre-scoped to MOH’s HIA Cyber Security and Data Security Essentials. It covers a gap assessment, risk remediation, policy documentation (including an incident response plan), and staff awareness. Timelines vary by organisation size and complexity — contact us for an indicative timeline for your situation.
What if my vendors or cloud provider are not compliant?
HIA compliance follows the data. If a vendor processes or stores NEHR-connected data on your behalf, they fall within your regulatory perimeter. You remain accountable. Our engagement will include guidance on what to require from vendors and how to assess their compliance.