Debated in Parliament on 3 Jul 2017.
Mr Pritam Singh asked the Minister for Defence what measures have been undertaken to ensure the security of the medical records of SAF personnel in view of the integration via the Internet of the SAF's electronic medical records system (the Patient Care Enhancement System (PACES)) with the National Electronic Health Record system.
Two main aspects to ensure security of medical records of Servicemen were taken into account in the design and implementation of the Singapore Armed Forces' (SAF's) electronic medical records system. They relate primarily to (a) the confidentiality of records, and (b) measures to guard against unauthorised access and cyber intrusions. Stringent processes for these two aspects have been put in place, which are aligned with international standards.
First, to ensure confidentiality of records, access to the SAF's electronic medical records system is limited only to medical personnel and selected human resource (HR) practitioners on a need-to basis and the list of authorised users is regularly reviewed. Even then, the level of access is also tiered-based, that is, medical officers as primary caregivers need to and can access detailed medical information, but medics and HR practitioners can access less information that is relevant to fulfil their functions. Regular audits are conducted to ensure that access and the confidentiality of the medical information have complied with existing policies and regulations and benchmarked to the Ministry of Health's practices and standards.
The SAF's electronic medical records system is regularly tested for vulnerabilities to update the system's software. In addition, the system is constantly being monitored for any attempted cyber intrusions.