Debated in Parliament on 12 Jan 2026.
Order for Second Reading read.
Senior Minister of State Tan Kiat How.
Mr Deputy Speaker, on behalf of the Minister for Health, I move that, "The Bill be now read a Second time."
I will first set out the context of the Health Information Bill (HIB) and its role in supporting the transformation of our healthcare delivery model. I will then outline how the HIB will help Ministry of Health (MOH) achieve the goal of "One Patient, One Health Summary, One Care Journey", and bring Members of the House through the key provisions of the Bill, before finally covering our plans to commence the Bill from early 2027.
Sir, Singapore is rapidly ageing. By 2030, one in four Singaporeans will be aged 65 and above. This substantial demographic shift brings with it a higher burden of chronic diseases and a higher proportion of patients with multiple co-morbidities. These patients will need well-coordinated, sustained care.
This is why we are transforming our healthcare delivery, from being hospital-centric to delivering care in the community. We are implementing national programmes like Healthier SG and Age Well SG, as well as initiatives, such as the Home Personal Care and Mobile Inpatient Care @ Home.
Sir, this effort will enable patients to benefit from timely and more holistic care. Patients will receive care from a wider range of healthcare providers, not just at public hospitals and polyclinics, but also at home or in the community, including at general practitioner (GP) clinics, dialysis centres and via home medical or rehabilitation services.
The sharing of a patient's key health information across settings and service providers is therefore essential. Such sharing of health information will also benefit younger patients who visit new healthcare providers or encounter medical emergencies.
Today's situation is not ideal. Currently, when patients move between healthcare providers, such as from private specialist clinics to their GPs, their key health records are often not accessible across providers. Such gaps can risk medication errors, delayed treatment and duplicate tests and procedures.
This is why many jurisdictions, such as Australia, Estonia, Finland and Norway, have developed robust governance frameworks to govern the sharing of health information across healthcare providers. This sharing regime has led to better patient outcomes, reduced costs and more effective and efficient healthcare delivery. We have studied these jurisdictions carefully and adopted key features suited to our local context.
But, Sir, in practice, we are not starting from scratch. Singapore started sharing health information across providers since 2011, with the implementation of the National Electronic Health Record system (NEHR). Today, all public hospitals and polyclinics are already contributing key health information to NEHR. Public hospitals contribute about 80% of total beds in Singapore and account for approximately 90% of hospital stays. And with Healthier SG, most GP clinics are already onboarded to NEHR. This has been of tremendous benefit for GPs and their patients. Most private hospitals have also onboarded to NEHR, while the remaining are in the process of doing so.
Hence, the vast bulk of key healthcare services are already on NEHR, or coming onboard soon, leaving a small group that have not done so, such as specialist clinics, clinical and radiological laboratories and dental clinics.
Sir, with your permission, may I ask the Clerks to distribute a handout on the key elements of the HIB.
Please proceed.
Thank you, Sir. Members may also access the handout through the MP@SGPARL App. [A handout was distributed to hon Members.]
Sir, the HIB will help us realise the vision of "One Patient, One Health Summary, One Care Journey" in two important ways.
First, the HIB will close the remaining gap by requiring all licensed healthcare providers to contribute to the NEHR and providing for their NEHR access. This will allow patients' key health information to be accessible by their healthcare providers when they move across healthcare settings. Patients will benefit from better coordinated care, enhanced quality of care and lower costs.
Let me illustrate with a hypothetical example of 50-year-old Ms Kamala, as covered in the infographic. Ms Kamala regularly visits her nearby GP to manage her chronic health conditions. She recently moved to a new estate. When she visits a different GP near her new home, the doctor there can make informed care decisions based on Ms Kamala's health information in NEHR.
Her new doctor can see which tests have been done and the medications that have been prescribed. He need not repeat the tests, saving Ms Kamala time and money.
Appropriate tests and medications can also be ordered to better manage Ms Kamala's health requirements. Patients moving between private and public healthcare providers, or acute and community settings will similarly benefit.
Actually, I think many Members in the House can relate to these examples. We often see our residents, especially our seniors, sitting in front of a GP clinic, carrying a big plastic bag of medicine. I once joked with an Ah Gong, saying, "Most people go and see doctor to collect medicine. How come you see doctor, bring medicine to see doctor?" So, he laughed and said, "Doctor asked me what medicine do I take. How can I remember? So, I brought everything there." And I am pretty sure, if I looked into his plastic bag, there would be medicine that has been issued by another doctor many months or even some time ago, and probably had expired. So, this situation is not ideal.
Second, the HIB will enable the sharing of non-NEHR health information to facilitate community-based care. Today, the Agency for Integrated Care (AIC) under MOH shares data with community health partners to enable them to engage and provide befriending services or care to seniors. The HIB will provide an additional channel for the sharing of non-NEHR health information to better support national health programmes and initiatives.
Let me illustrate this using another hypothetical example also covered in the infographic: 72-year-old Mr Lim has Type 2 diabetes and has rarely left home since his wife passed away. Mr Lim has been skipping his polyclinic appointments and struggles to manage his diabetes.
Without the opportunity to see Mr Lim, the polyclinic cannot seek his consent to share his contact and relevant health information with community health partners for follow-up. However, if our community healthcare providers and their partners are aware of Mr Lim's conditions, they can better support him.
With the HIB, when Mr Lim's polyclinic assesses that he would benefit from community support, the polyclinic can potentially share his contact information and an indicator of his level of health risk, such as whether he has a chronic condition, with AIC. AIC can then prioritise engaging Mr Lim, encourage him to check on his well-being and link him up with necessary support if needed.
AIC's early engagement of seniors like Mr Lim allows them to benefit from healthcare providers and community-based services before their isolation sets in, leading to more serious health consequences. And again, this is a scenario that I am sure many Members in the House see when we do our house visits, meeting our seniors in the community, especially seniors living alone, isolated. And these provisions under the HIB will help to enable better care for our seniors.
To ensure that the Bill addresses Singapore's healthcare needs as well as considers stakeholders' views, MOH has been engaging the public and stakeholders since 2022.
I would like to take this opportunity to thank members of the public and patient advocacy groups for their support for the Bill and their invaluable inputs, such as providing patients with greater control over their access to NEHR. I would also like to thank the professional bodies and healthcare professionals for their feedback, particularly regarding the cyber and data security requirements and the support that their members and colleagues may require as part of the transition. MOH has taken these viewpoints onboard.
Sir, now allow me to go through the Bill's key provisions and safeguards for the sharing of health information under the Bill.
In the example of Ms Kamala shared earlier, NEHR would only be able to support her new doctor if key health information from her previous healthcare providers were contributed to NEHR.
The HIB will require all healthcare providers licensed under the Healthcare Services Act 2020 and retail pharmacies licensed under the Health Products Act 2007 to contribute key health information about patients into NEHR. The key health information are those crucial for continuity of care such as allergies, vaccinations, diagnoses, medications, laboratory test results, radiological images and discharge summaries.
As certain public agencies such as the Singapore Armed Forces (SAF) and the Singapore Civil Defence Force (SCDF) also provide patient care, the Bill enables these agencies to be gazetted under the Act to contribute key health information to NEHR.
Key health information of Singapore Citizens, permanent residents and patients with long-term immigration passes will need to be contributed as these groups are more likely to seek care in Singapore over time. Health information of transient visitors such as tourists need not be contributed.
Clauses 10 to 15 set out the provisions relating to the contribution of key health information to NEHR. The First Schedule lists the key health information that each licensee category needs to contribute, based on the patient care functions they provide.
NEHR access will be provided to the healthcare providers that are contributing key health information to NEHR. The Bill will also enable NEHR access for community health partners providing clinical or care planning services. This is in recognition of their increasingly important role in supporting patients' continuity of care.
To enable the provision of timely and effective care, there will not be a need for every healthcare professional to seek consent each time they access their patients' NEHR.
At the same time, we are mindful that patients expect their NEHR information to be kept confidential. The Bill provides for robust legislative safeguards to address these concerns. We also have in place technical controls to ensure that access to NEHR is tightly regulated.
Let me first speak about the legislative safeguards.
NEHR access for patient care purposes will be limited to licensed healthcare providers and their authorised individuals.
Healthcare providers must also implement appropriate practices to ensure their healthcare professionals access NEHR appropriately. This will include regular training on the appropriate use of NEHR and conducting audits on NEHR access.
In short, access to NEHR is restricted to healthcare professionals for the purpose of providing care to their patients. Accessing NEHR for purposes relating to employment or insurance will be strictly prohibited. This means healthcare professionals will not be allowed to access NEHR for purposes such as filling out medical reports required for insurance claims or pre-employment medical screening forms. This will address the concerns expressed during the public consultation that health information could be used in a discriminatory manner by employers or insurance companies.
However, there are medical examinations set out in statutes which serve to protect the public and safeguard the health of the individual and those around him. Examples include examinations of persons who are at risk of an infectious disease and the medical examinations to assess fitness for service in the SAF, SCDF and Singapore Police Force as required under the Enlistment Act. NEHR access will therefore be allowed for these statutory medical examinations.
Clauses 16 to 23 set out the provisions relating to NEHR access, including the legislative safeguards. The Second Schedule sets out the categories of authorised individuals who may access NEHR for different categories of healthcare providers. The specified statutory medical examinations for which NEHR may be accessed is listed in the Third Schedule.
That is the set of legislative safeguards. Let me turn to the technical controls that MOH will put in place to tightly regulate access to NEHR.
First, authorised individuals will only be granted access to the data types required for their patient care duties. For example, nurses in general will not have access to radiological images as they do not require this information for their patient care duties.
Patients themselves can monitor access of their NEHR information through their HealthHub account and can report suspicious activities to MOH for investigations.
Sir, by default, patients' key health information will be contributed to NEHR and will be accessible by healthcare providers to support the continuity of care across healthcare settings. For those who continue to have privacy concerns, they may restrict access to their NEHR information so that only select healthcare providers may have this access. This Access Restriction feature is like the approach adopted by countries like Australia, Estonia and Hong Kong.
Today, such an Access Restriction regime is already in place. Patients can submit their request to place an Access Restriction at public healthcare institutions (PHIs). From the second half of this year, patients can do so through the HealthHub app.
For patient safety, when patients visit their healthcare providers, the provider will still be able to view a subset of records in the patients' NEHR even if there is an Access Restriction in place. This subset of records comprises critical allergies and vaccination information that helps reduce the risk of inappropriate prescriptions or immunisations when patients visit new healthcare providers.
Further, a patient's NEHR information may be accessed during medical emergencies despite an Access Restriction. This feature, known as "break-glass", is like Australia's approach. Access in such extenuating situations will be subject to strict controls.
First, only doctors will be allowed to "break glass". Second, before "breaking glass", the doctor must re-verify their credentials and declare a medical emergency has happened. Third, every instance where a doctor "breaks glass" will be subject to audits. Confirmed cases of inappropriate "break-glass" will be investigated as potential breaches under the HIB and may also be referred to the Singapore Medical Council for disciplinary action.
To ensure there are no gaps in patients' records even during emergencies, health information will continue to be contributed to NEHR even when an Access Restriction is placed.
While Access Restriction is an option, we do not encourage its use as it would adversely affect the quality of care we receive as patients. It is only when healthcare providers – our doctors and our frontline healthcare staff – have access to our key health information that they can deliver holistic and effective care in a timely manner.
Next, let me turn to clauses 29 to 33, which deal with Access Restrictions. Details relating to these Access Restrictions will be set out in subsidiary legislation.
As the national repository of key health information, NEHR information can be used to inform national policies and research to improve population health outcomes for Singaporeans. The HIB will provide for the sharing of identifiable NEHR information for public health purposes and anonymised NEHR information for broader public interest purposes.
Let me give a few examples. For example, in the event of a major drug contamination incident, MOH may share necessary information from NEHR, such as the identity of patients prescribed with the drug, with relevant healthcare institutions and direct them to promptly contact the affected individuals and advise them to stop taking the drug and seek medical care. The HIB will not impede the sharing of NEHR information as required or permitted under other laws.
For example, NEHR information may be required under the Criminal Procedure Code 2010 to facilitate criminal investigations by the Police or by the Communicable Diseases Agency under the Infectious Diseases Act 1976 for outbreak investigations and contact tracing of potentially exposed individuals.
But for all requests, MOH will assess whether the NEHR information is appropriate and necessary for the purpose of the request, taking into consideration factors such as whether alternative information is suitable and whether anonymised or aggregated data would suffice.
The sharing of NEHR information under other laws, as well as for public health and public interest purposes, are provided for in clause 5 and clauses 20 to 28 respectively.
Sir, let me now turn to the provisions for the sharing of non-NEHR health information to facilitate community-based care.
As mentioned earlier, the HIB will provide an additional channel for data sharing to support the goal of "One Patient, One Health Summary, One Care Journey". We will enable the scoped sharing of non-NEHR health information without an individual's consent only if three key criteria are met.
First, data sharing must be between specified entities. For a start, this will cover key public healthcare stakeholders such as PHIs, AIC and public agencies.
Second, information must only be shared for specified use cases to support continuity of care and population health outreach under national programmes such as Healthier SG and Age Well SG. For example, PHIs may share contact information and the addresses of seniors with AIC for AIC to contact and engage these seniors to connect them to relevant community-based care services and activities based on their needs.
Third, we will restrict the data types that can be shared to those relevant to each use case. The data shared will generally be limited to basic identification and contact information and if necessary, broad health risk indicators, such as the presence of frailty or chronic conditions, but not the actual medical conditions.
The scope and key requirements for the sharing of non-NEHR health information are provided for under clauses 45 to 60 while the use cases and specified entities are set out in the Fourth Schedule. The list of data types allowed for each use case will be set out in subsidiary legislation.
Let me now turn to the measures in the HIB to secure and protect health information.
Healthcare providers that contribute to and access NEHR as well as entities allowed to share and receive non-NEHR health information will need to meet cybersecurity and data security requirements. They will also be responsible for assessing whether a notifiable cybersecurity incident or data breach has occurred. Once confirmed, MOH will need to be notified. Where a data breach has resulted in, or is likely to result in, significant harm to individuals, the affected individuals will also need to be notified. These security requirements are covered in clauses 61 to 82.
To be clear, today, licensed healthcare providers and practitioners already have obligations to safeguard the personal data of their patients under existing laws. The security requirements under the HIB are based on existing standards and legal requirements. What the HIB does is to consolidate these requirements in relation to health information.
Additionally, the Bill will empower the Minister for Health to take emergency measures in critical events where the threat to health information or relevant health information systems could result in health information being lost or compromised. Such powers are not unique to this Bill and can be found in the Infectious Diseases Act 1976 and the Cybersecurity Act 2018.
These powers are necessary. We have seen how incidents, whether cyber or physical in nature, can lead to major and prolonged disruptions of essential services around the world, including healthcare services. Physical incidents, such as fires, can take out information systems and result in data loss, just as faulty information technology (IT) updates or cyberattacks can lead to the same outcome. Hence, these powers are scoped towards enabling responses to protect health information regardless of the form of the threat.
Should an outage involving health information or the systems that host or process such information occur in Singapore and threaten a major disruption of healthcare services, clauses 83 to 85 will allow the Minister to direct relevant healthcare providers to take mitigating or recovery measures.
Sir, as I have earlier mentioned, we intend for the Bill to take effect from early 2027. This would give healthcare providers sufficient time to familiarise themselves with the Bill’s requirements and strengthen their cybersecurity and data security postures. MOH is working closely with healthcare providers on the implementation timelines and will announce further details soon.
Sir, during our consultations, some healthcare providers shared concerns about the burden of implementing the HIB’s security requirements. MOH has been engaging the associations and providers. I wish to reassure them that MOH is committed to supporting them through this transition.
We will inform healthcare providers of NEHR-compatible systems that meet the Bill’s cybersecurity requirements and automate the contribution of key health information. With the use of such NEHR-compatible systems, healthcare providers will then only need to ensure their data security measures are in place, such as training staff involved in patient care to access and use NEHR appropriately. Training resources and programmes, as well as funding support, will be made available to support healthcare providers and healthcare professionals.
We are aware that some healthcare professionals are concerned about increased liability from accessing and using NEHR. MOH is working towards publishing guidelines on the appropriate access and use of NEHR information that healthcare professionals, including nurses and allied health professionals, may use as a resource.
I will now touch on the key offences and the penalties. Under the HIB, non-compliance with contribution requirements is not an offence in the first instance, as we recognise that there could be genuine challenges onboarding to NEHR. If non-contribution arises from technical difficulties, for instance, we will work with healthcare providers to rectify the underlying issue. However, in the event of deliberate or reckless non-compliance or breaches, directions may then be issued to the healthcare provider to comply. It is only when the healthcare provider fails to comply with a direction that the provider could be liable for an offence punishable by up to $20,000, one year’s imprisonment or both, upon conviction. And I reinforce, it is really in the event of deliberate or reckless non-compliance or breaches.
For breaches that are likely to have a greater impact on patients, maximum penalties are higher. For instance, a person convicted of an offence relating to unauthorised access of NEHR information under clause 38 faces a fine of up to $50,000, two years’ imprisonment or both, for a first offence. This maximum penalty is doubled for a repeat offence or if the unauthorised access was for employment or insurance purposes. The penalty for this offence is comparable to other relevant laws. For instance, the maximum fine of $50,000 is aligned with serious breaches involving unauthorised access to computer material in the Computer Misuse Act 1993.
Breaches involving systemic failures are dealt with most severely. For instance, healthcare providers that fail to put in place the cybersecurity or data security measures required under the HIB may face a fine of up to $1 million, as the health information of many patients could be compromised. A failure would likely be committed by a healthcare provider or other organisation. Hence, the maximum fine must be high enough to serve as an effective deterrent to such organisations.
Nevertheless, these are maximum penalties, which are aimed at addressing the most egregious of breaches. We would like to reassure healthcare providers and healthcare professionals as well as Singaporeans that should potential breaches occur, MOH will look at the facts of each case carefully. The Bill also allows for a range of enforcement actions besides prosecution, including composition of offences, directions to rectify breaches and letters of warning.
Sir, the HIB will play a critical role in supporting the transformation of our healthcare delivery services and model. Through “One Patient, One Health Summary, One Care Journey”, Singaporeans will benefit from better coordinated care, enhanced quality of care and lower costs. I urge Members of the House to support the Bill. Deputy Speaker, Sir, I beg to move.
*Question proposed.*
Ms Mariam Jaafar.
Sir, I first declare my interest as managing director and senior partner of a management consulting firm that does work in the healthcare space.
Over the last several years, healthcare in Singapore has been on a profound journey of transformation – from hospital to community, from treating sickness to preventing it. This Bill marks a decisive step on that journey. At its heart, the HIB is not about technology. It is about enabling a healthcare system that is more connected, more proactive and more centred on the patients, not on institutions. As MOH puts it: “One Patient, One Health Summary, One Care Journey”.
This Bill establishes a statutory framework governing how selected health information is collected, accessed, used and shared – not just for medical treatment but also for community health, preventive care and population well-being.
The Health Government Parliamentary Committee (GPC) supports this Bill. Over the course of this debate, my colleagues will examine it from the perspectives of patients, general practitioners (GPs), allied health professionals, workers, legal safeguards and cybersecurity. We are united by one conviction – this Bill must deliver safer, more continuous and more trusted care. I will focus on what the Health GPC regards as most critical – continuity of care, especially as care shifts into the community.
Mr Deputy Speaker, our residents do not experience healthcare as a single episode or a single institution. They experience it as a journey – often a long one – across GP clinics, polyclinics, hospitals, community hospitals, community health posts, home care teams and social services. Yet, too often, our systems still treats each encounter as if it were disconnected. For many of them, especially seniors and those managing chronic conditions, the biggest challenge is not access to care but continuity of care.
My Woodlands residents tell me: “I have to repeat my story every time”; or “My GP didn’t know what the hospital had done or that my medication had changed”; or “My mother was discharged, but no one seems to have the full picture.” One of my “Ah Mas" in Woodlands carried a plastic bag stuffed with her medical records – and yes, medications, just like the Senior Minister of State’s resident “Ah Gong” – wherever she went, just in case. That is not integrated care.
And this is not only about the very old. Woodlands Hospital is already seeing residents in their 40s and 50s at the Accident and Emergency Department (A&E), presenting with diabetes and complications. They bounce between providers, miss follow-ups, have poor disease control and ultimately, fall out of the system. That is exactly why longitudinal, joined up information matters. If we wait until people are frail, we have already failed them.
Continuity of care is directly linked to public health and early intervention. When middle-aged residents presenting with advanced diabetes, it tells us we did not see them early enough, support them consistently enough or connect the dots across years of care. A health information system that allows us to identify patterns – not to police individuals, but to detect communities at risk – gives us the ability to intervene before preventable diseases derail lives. This is responsible public health planning.
Continuity of care is not an abstract principle. It is about whether a doctor sees the whole patient, not just the part that walks into their clinic that day. It is the difference between safe medicine and risky medicine, between early prevention and avoidable deterioration. It is foundational to patient safety, quality of care, system efficiency and dignity.
The HIB strengthens this foundation by ensuring that essential health information – medications, allergies, diagnoses – can follow the patient, not remain trapped in institutions. It enables care teams across settings to work from a shared understanding and make better clinical decisions. It also enables the sharing of health information outside the NEHR to support critical programmes, such as Healthier SG and Age Well SG. This is particularly important in the community setting, where healthcare and social care must operate in close coordination.
In Woodlands, the Health Promotion Board and the National Healthcare Group have embarked on the Improving Health in Woodlands Town Project, and it has my full support. It integrates health, social and community services using shared data dashboards to guide proactive care, from identifying at-risk residents or residents with chronic diseases and connecting them to health and social services to smoothening transitions from hospital to community and home care, to promoting healthy living and to partnering with grassroots organisations and communities to curate health-related activities and link up residents to relevant interventions, supported by Community Health Dashboards for local planning and progress monitoring. This Woodlands project could show what becomes possible when care is joined up, data works for the people and communities lead the way – a model that could inspire the rest of Singapore.
But none of this works if information does not move. If the GP does not know what medications were changed, if the community nurse does not see the discharge summary, if the social worker is unaware of the medical risks at home, care becomes fragmented. Residents repeat their histories, tests and procedures may be duplicated, caregivers are left uncertain and opportunities for early intervention are missed. Conversely, when information is shared, care becomes coordinated and outcomes improve. Residents feel assured, caregivers feel supported and the system functions more effectively.
The Bill also enables a learning healthcare system. With longitudinal data, we can anticipate disease, manage chronic illness better, support public health planning and evidence-based policy-making and accelerate medical research breakthroughs, from early cancer detection to precision or personalised medicine. For public health planners, this data allows us to understand which neighbourhoods are ageing faster, where chronic disease is poorly controlled and where caregivers are under strain, so we can deploy resources where they are needed most, not where the voices are loudest.
But none of this can succeed without public trust. And trust, Sir, is not built by aspiration. It is built by rules, limits and accountability. And that is why the Health GPC will be watching five critical issues closely.
First, access controls. The Bill allows broad categories of “authorised users” to access NEHR data for healthcare and care coordination. My residents’ greatest anxieties relate to sensitive data including mental health, reproductive health and social vulnerabilities.
This fear is real, but the solution to fear is not fragmented care. The solution is stronger rules on who can see what.
Access must be purposeful, proportionate and auditable. Sensitive information, for instance, mental health records should require higher-level authorisation or additional justification. Member Alex Yeo, a lawyer, will address this from a legal and governance standpoint while Member David Hoe will bring his characteristic moral framing and empathy for the most vulnerable in our community, that I have come to admire so much in a short time in this House.
And earlier, in the PSGA debate, Member Cai Yinzhou made the case that when Government agencies and external parties want to use health data for non-healthcare purposes, there must be clear use cases, justifications and safeguards.
Second, employment and insurance use. The Bill rightly prohibits the use of NEHR data for employment and insurance eligibility. This is crucial. But prohibition on paper is not enough. Indirect access or inference – for example, where doctors are asked for medical reports or insurers rely on clinical documentation – must be tightly controlled. We must have clear guidelines for clinicians. Doctors must not be placed in ambiguous positions of having to decide what can or cannot be disclosed, and patients must not be pressured to consent to disclosures that undermine the spirit of the law.
Our labour Member Dr Wan Rizal will speak from the National Trades Union Congress (NTUC) perspective on safeguarding workers' rights – particularly for those with mental health conditions, this is his passion.
Third, support for smaller providers. Mr Deputy Speaker, I have heard people say that older GPs might be a problem when it comes to implementing this Bill. Let me be clear: in the transformation our healthcare journey is on, GPs are not the problem; they are the solution.
Many Woodlands residents have seen the same GP for decades. Some of these GPs cared for my residents when they were young and are now caring for their children. That is longitudinal data in action.
Smaller providers often have limited manpower and IT resources. If onboarding, cybersecurity and reporting requirements are too costly or complex, smaller GPs could struggle. Older GPs could decide to close shop. We then risk widening the gap between large institutions and community care – exactly the opposite of what this Bill intends.
Financial support, shared services models and practical implementation timelines must be clearly set out. MPs Yip Hon Weng, Joan Pereira and Choo Pei Ling will speak on how to support these GP clinics and community partners.
Fourth, protection for doctors and allied health professionals. NEHR must support, not replace, professional judgement. Clinical protocols, medico-legal guidance and professional standards must be clear so that healthcare workers are not unfairly exposed.
A doctor himself, Member Dr Hamid Razak, will speak on medico-legal clarity for doctors, while Member Choo Pei Ling together and Member Dr Wan Rizal will speak up for allied healthcare professionals – community nurses, therapists, social workers – who play a critical role in community care and must also have clarity and protection when using NEHR data.
Fifth, cybersecurity and accountability. Public trust requires resilience. Audit logs, breach detection, structured response and transparent communication to citizens are essential. Past breaches have left long shadows. Member Yip Hon Weng will address resilience and cybersecurity measures, drawing on perspectives of the Defence GPC. Members Choo Pei Ling and David Hoe will speak on breach response, transparency and recourse.
Mr Deputy Speaker, some have asked: "Why not make this system opt in? Why can't I opt out fully?" We should be honest. There are many things in life one can opt out of, but you cannot opt out of safe care. In an emergency, your doctor must know your allergies. That makes safeguards even more important, not less. Access to sensitive data must be carefully designed. Prohibitions on employment and insurance use must be real in practice, not just in statute. Smaller clinics and community partners must be properly supported, not overwhelmed. And the rate of people opting to activate access restrictions should be tracked, as a barometer of public trust.
Sir, the Health GPC supports the direction of this Bill because the status quo – fragmented information and disjointed care – is not good enough for our citizens. But our support comes with a. responsibility to ensure continuity of care is delivered in practice, that safeguards are real, professional guidance is clear and that community-based providers are not left behind. If we get this right, my Woodlands Ah Ma would no longer need to carry her medical history in her plastic bag. Her integrated care team will already have it, working together across settings to give her the best possible care and ensure she enjoys a good quality of life well into her old age. This is the system this Bill must deliver. With these expectations clearly in mind, I support the Bill.
Mr Dennis Tan.
Mr Deputy Speaker, the HIB is transformative in a way. It will set the legal framework for the mandatory contribution, collection, storage and disclosure of health information across the entire healthcare ecosystem of Singapore. When passed, fragmented and often paper-based health records held by individual healthcare providers will be a thing of the past, morphing into a unified interoperable NEHR.
This is not merely a technological upgrade. The Bill promises smoother, safer, more efficient healthcare for all patients under our country's health system. Given Singapore's rapidly ageing population, successful implementation of NEHR is critical to ensuring seamless care and continuity across different healthcare institutions.
Trade-offs may test people's trust. However, these benefits come with trade-offs, which, if not properly addressed, will affect the people's trust in this national Smart Nation effort. After all, nothing could be more sensitive and personal than one's health information records over the years. The thought of such intimate human data being viewed by viewed by nameless, faceless persons, other than your own doctors, or even worse, falling to the hands of hackers, must be very real to some of us when we contemplate the HIB.
Thus, while I support the Bill, I wish to raise a few concerns posed by the HIB, and I will be speaking on the challenges for smaller healthcare operators, such as single or dual-doctor practitioner clinics that many of my residents rely on for their daily medical needs.
Sir, we must recognise that the centralisation of health data across all healthcare providers, from the very small to the very large, introduces significant privacy and cybersecurity risks across the entire ecosystem. Even with strict regulations and legal governance frameworks, there has been cases of unauthorised access as well as outright hacks. It is public knowledge that some of the most egregious data breaches in the past 10 years have happened within healthcare. Chief among them was the 2018 hack of the SingHealth system that led to a Committee of Inquiry, and also the delay of the NEHR roll-out by more than five years. The personal particulars of 1.5 million SingHealth patients, including the then Prime Minister Mr Lee Hsien Loong and the records of outpatient dispensed medicines belonging to 160,000 patients were stolen. Till today, the identified hostile state actors behind the attack remain unaccounted for.
More recently, there have been at least two reported cases of unauthorised access by healthcare professionals. For instance, a neurosurgeon at SingHealth was dismissed in 2022 for inappropriately assessing the medical records of over 70 patients not under his care. More recently, in 2025, a customer service associate at the NUH was found to have unlawfully accessed the records of 11 individuals, including family members and former colleagues via NUHS' internal Epic system, reportedly driven by personal motives to reconnect with one of them.
While the overwhelming majority of healthcare professionals uphold ethical and legal standards, the ease of access to such records will severely undermine public trust.
Many of us may be asking how can I be sure that the GP clinic at the next block to mine with only one and half doctors, and one to two doctors and two clinic staff on shifts be able to comply with the HIB and also be self-protected against cyber and data risk created by either human or system errors.
The NEHR is only as secure as the smallest operators are. While the HIB's stringent requirements are essential for safeguarding patient data and access, they place a significant burden on smaller healthcare providers who may no longer opt out of contribution to NEHR. Under Part 2, Division 2, failing to comply will lead to a fine not exceeding $20,000, or to imprisonment for a term not exceeding 12 months, or to both. In the case of continuing offence after conviction, a daily fine of $1,000 applies.
Large institutions like SingHealth and National Health Group may mobilise their dedicated IT teams. Small practices, however, will find themselves in unfamiliar territory and will have to rely on costly external consultants to comply, creating a significant operational burden.
On an ongoing basis, the challenge is particularly acute when it comes to warding off attacks and data breaches. Under the law, healthcare providers of all sizes share legal liability for data breaches caused by health data intermediary failure, placing a disproportionate burden on clinics that lack control over these risks.
Although the GP IT Enablement Grant offers one-time subsidies for adopting NEHR compatible system, as I understand, they do not cover the ongoing cost of maintaining cyber security compliance. Small healthcare operators may be out pocket for purposes of upgrading and maintaining their clinic management systems to meet strict security standards, audit trails and data portability. Even with this grant, GPs are simply not trained to assess whether their providers use genuine end-to-end encryption, secure server configurations, or follow basic cyber security best practices.
How can we help clinics to use appropriately secure yet affordable compliance systems? How can we ensure the essential cyber hygiene practices like staff training and regular software updates are undertaken without imposing disproportionate cost burden and/or adding to the existing pressures of running their small practices?
We should also be concerned whether this leads to GPs passing the cost down to patients and reducing affordability in primary care. How will MOH ensure that such cost will not be passed down to patients? How will it affect our mom-and-pop clinics and family doctors?
Mr Deputy Speaker, many family doctors are people who are located near to our homes convenient for us to visit when trouble hits and who have known us and our family members for years, if not decades. They are an important part of keeping us safe and healthy. With the Community Health Assist Scheme (CHAS) and Healthier SG schemes, they have become more integrated into the overall health delivery infrastructure nationwide – at least some of them. However, they are often by nature very small, akin to mom-and-pop clinics, often fronted by one doctor with, say, possibly another on a locum basis, or not even without another locum, they open only part of the day. Some may not even have air conditioning and some may still use paper records. Furthermore, the doctors are older, serving their patients past their official retirement age, which makes them well loved and trusted.
I do wonder whether the passing of the HIB with punitive costs for non-participation and compliance may be the straw that breaks this group and push them to give up their practices for good. I certainly hope not, even if they are in a minority. We should be concerned about conveniently located medical services disappearing from our neighbourhoods at exactly the point when Singapore is becoming a super-aged society that needs more care, not less.
A volunteer shared with me recently her worries for her 87-year-old mother who lives in her own flat and is under the trusted care of her family doctor a few blocks away. This doctor runs a solo practice in a void deck shop without air-conditioning. He only opens a few hours a day, but this suits the elderly patients that he mostly serves.
If this doctor is forced to close due to implementation of the HIB, my volunteer is worried that her mother will no longer have convenient access to care. It will be stressful for this volunteer as a daughter living away from her mother whenever her mother falls ill, needs to top up her medicines or take a vaccination, whereas currently, she trusts her mom to visit this doctor and her troubles will usually be sorted.
Mr Deputy Speaker, I hope MOH will provide the necessary assistance to all small clinics and practises, so that the burden of the HIB and NEHR may not be so overwhelming for these doctors, such that they will prefer to close their practices instead.
Next, extend financial support beyond GP IT Enablement Grant and set up an IT Shared Services Office. Given the challenges I have highlighted above, will the Minister consider giving a grant for small clinics or practices with say, fewer than three full-time practitioners to assist the clinic or doctors in their ongoing compliance, with the HIB's cyber and data standards and practices?
This may be an extension of the GP IT Enablement Grant, but targeted towards the smaller operators rather than the chain clinics. Going beyond financial support is also important. They need Institute of Technical Education technicians to help them directly when issues arise. They also need a dedicated help desk.
To address this, could the Minister consider setting up an IT Shared Services Office within the Ministry that may provide small clinics with not a one-off, but a continuing out-sourced, cost effective and compliant IT support, acting in lieu of the dedicated IT department of large healthcare institutions?
Besides my suggestion above, I would also urge MOH to consider setting up a similar initiative to support all clinics and practices, like the shared services initiative for charities. The Commissioner of Charities has partnered with various organisations to set up shared services to strengthen charities, regulatory compliance and efficiency of their backend operations, especially helpful to smaller charities. These are not nice to have. They are imperative.
This Bill changes the rules of the game. It mandates that every private clinic from the specialist in Orchard Road to the void deck GP in the heartlands must contribute their data. They have no choice if they wish to stay open. But if MOH were to demand institution-grade security against risk and breaches on a solo operator's budget, it may not just be unfair, it may even be unsustainable for some.
Compliance with the HIB cannot be a one-size-fits-all assignment. More must be done to help onboard small clinics and family doctors at the same level of standards and readiness as large institutions. Let us not make the small clinics the weakest link of the system. They should also be the trusted mission-critical partners, worthy of a Smart Nation.
Next, Mr Deputy Speaker, in the final part of my speech, I will touch on the penalty regime under the HIB. I have spoken about the SingHealth data breach of 2018. The Personal Data Protection Commission fined SingHealth $250,000 and its IT vendor, Integrated Health Information System (IHiS), $750,000, totalling $1 million for failing to protect 1.5 million patients' data.
Section 66 of the HIB states a fine not exceeding $1 million for organisations that fail in data security in handling of health and relevant information. While the figure of $1,000,000 appears substantial in isolation, it pales when contextualised against the scale of modern healthcare data breaches, such as the SingHealth one in 2018. Let us do the math: 1.5 million SingHealth records were leaked in 2018. A total fine of $1 million – $750,000 plus $250,000 – equates to an effective fine per record of 66 Singapore cents.
Mr Deputy Speaker, we may wish to review whether this is the value we wish to place on the privacy of our citizens, as such. Furthermore, for a large healthcare conglomerate with annual revenues in the hundreds of million, a $1 million fine is a relatively lesser or even trivial operating expenses. Relatively speaking, it is roughly equivalent to the cost of a few high-end medical devices. It is hardly a pain point to some, even less of a serious business risk to the large hospital groups. Instead, the $1 million cap effectively puts a ceiling on the value of the collective privacy of the nation, regardless of the number of persons attached or affected.
Let us compare this with global standards that have successfully shifted corporate behaviour. First, the European Union's (EU's) General Data Protection regulation imposes administrative fines of up to $20 million euros, or 4% of total worldwide annual turnover, whichever is higher. The 4% turnover clause is the main deterrent. For a tech giant or a global hospital chain, this could amount to hundreds of millions or billions of dollars. This scales the penalty to the size of the entity, ensuring that the fine is never just a cost of doing business.
Another is the California Consumer Privacy Act, which allows for a private right of class action lawsuits with statutory damages between US$100 and US$750 per consumer per incident. This directly monetises the harm to the individual. It creates a mathematical certainty of catastrophe for negligence. If this is applied to the SingHealth case of 1.5 million victims, we will be looking at a payout of between $200 million and $1.5 billion. The penalty, in a sense, may better match the pain of the victims. More importantly, it will make organisations take the message much more seriously.
Mr Deputy Speaker, I would surely understand, on one hand, some of us may think that the penalty regimes in EU and California may be a bit too high, and some will argue that they will be eventual cost impact on consumers. On the other hand, some may argue that they can better match the pain of the victims. We can, and perhaps we should, review and decide where the balance may better lie for Singapore.
But it is important that our regime must ultimately make all organisations take the message more seriously. By way of example, if you were to introduce say, a per person fine, similar to the approach in California – and of course, we must discuss this robustly before any decision is reached, how much this fine should be and the premises for arriving at the quantum – say, for illustrative purposes, we peg the fine per person's records to what we have to pay to acquire people's personal information from, say, the Accounting and Corporate Regulatory Authority's BizFile, where per report or certificate is charged at $33 or $50. This is purely for illustration. This method would scale automatically a small clinic losing 50 records pay $ 1,650 to $2,500, painful but survivable. This shaves the calculus. It forces senior management and boards director to view cybersecurity not as an IT cost, but as an existential business risk.
It signals that the state values each individual's privacy. It moves away from the abstract notion of system security to the concrete value of personal data. This is how we can build a system that is robust at the outset. There is the trust of every contributor. We can start looking numerically at what would be a good balance for Singapore, or at least a better balance than what we have now, and which pertinently will make all organisations take the message more seriously, while being fair and equitable for bigger medical organisations, as well as smaller clinics and practices. Mr Deputy Speaker, in closing, notwithstanding my concerns, I support this Bill.
Dr Wan Rizal.
Mr Deputy Speaker, when Singaporeans hear about greater use and sharing of health data, their first reaction is rarely about system architecture or data flows. Their concern is much simpler, it is much more human, and they ask: can this information be used against me? Will it affect my job? Will it affect how I am treated? I hear this from workers, from our seniors and from caregivers alike.
Many residents, especially older residents managing long-term conditions, worry about who can see their information, whether consent is meaningful and what happens if something goes wrong. These are legitimate concerns and I know that other Members will raise them in detail, particularly on system safeguards and patient protections.
As a labour Member, I rise today to focus on a pillar of this Bill that is essential to public confidence: worker trust, and in particular, the safeguard that disallows health data from being accessed or used for employment purposes.
Sir, for workers, health data does not exist in isolation. It intersects very directly with their livelihoods, with hiring decisions, job retention, access to work opportunities and sometimes, continued participation in the workforce. This applies not only to traditional employees, but also to self-employed persons and platform workers, whose access to work can be more fragile and more easily withdrawn.
In these contexts, the imbalance of power is real. When income and job security are at stake, workers often feel they have little room to refuse disclosure, even when they are uncomfortable. And that is why legal safeguards matter, not just in theory, but in how workers experience the system.
This is why I want to state clearly and on record that I strongly support the safeguard in this Bill that disallows health data from being accessed or used for employment purposes. This safeguard is not peripheral. It is central to whether workers trust the system at all.
So, why is this system so important? Some may ask why this needs emphasis, since the safeguard is already existing in the Bill. The reason is not legal, it is behavioural. Even the perception that health data could affect employment decisions can discourage workers from seeking timely care, disclosing relevant information to healthcare professionals or participating fully in national health initiatives like Healthier SG. This would undermine the very objectives of this Bill.
Workers should never have to weigh their health against their livelihood. If this Bill is to succeed in improving continuity of care and public health outcomes, workers must feel safe engaging with the healthcare system, without fear of downstream consequences at work.
This concern is especially relevant for protected characteristics and disabilities, including mental health conditions. I want to be clear: I am not suggesting that any one type of health condition is more important than another, but from a workplace fairness perspective, some types of information are more likely to be misunderstood, stigmatised or misinterpreted in employment contexts.
Mental health conditions, for example, are often less visible, episodic and poorly understood in workplaces, despite progress over the years. The issue is not the data itself. It is the risk of unfair treatment if such information is misused or even informally taken into account. This is precisely why the employment-use safeguard is so important.
The Labour Movement has long stood for the principle that workers should not be discriminated against, on the basis of protected characteristics, including disabilities and mental health conditions. The safeguards in this Bill include specific prohibitions on NEHR access for insurance and employment purposes. It reinforces, in the context of health data, the same values we have already affirmed as a society: that personal characteristics and health conditions should not become barriers to fair treatment at work. Seen in this light, this safeguard is not an additional demand. It is a logical extension of principles that Parliament has already endorsed.
Workers are also concerned about indirect or "backdoor" use of health information. Not necessarily through access to records, but through fitness-for-work assessments, third-party requirements or other channels that could influence employment outcomes.
I note that the Bill identifies specific Statutory Medical Examinations where NEHR access is permitted, such as pre-enlistment checkups or assessments for vocational driving licenses. These are strictly defined to prevent harm to the individual or to public interest. I seek the Minister's assurance that this list of exceptions will remain tightly scoped and will not be expanded to general pre-employment screenings without rigorous oversight.
Furthermore, while healthcare providers can override an individual's "Access Restriction" during a medical emergency, the law must remain clear, that data can still never be used for employment purposes.
Mr Deputy Speaker, I also want to speak briefly about healthcare workers, including members represented by the Healthcare Services Employees' Union. Healthcare workers occupy a unique position in this Bill. They are entrusted to access and handle sensitive health data, they are required to do so as part of patient care, and often times, under pressure and subject to, of course, significant penalties if things go wrong.
From a labour perspective, safeguards must protect not only patients, but also the workers tasked with implementing the system. I hear you. Accountability is important and wilful misuse of data must be dealt with firmly. But accountability must be fair and also proportionate.
We must distinguish clearly between intentional wrongdoing, and inadvertent errors arising from system design, workflow complexity, or even operational constraints. And this means we need to have clear role-based access, proper training and guidance, and supportive implementation, especially during transition periods. Protecting patient data and treating our healthcare workers fairly are not competing objectives. They must go hand in hand if the system is to function well.
Sir, if I may briefly return to the concerns of my residents, especially those who are seniors and caregivers. Many seniors manage multiple conditions and interact frequently within the healthcare system. They worry about privacy, they worry about consent and they worry about whether their personal information is respected.
While I have focused today on worker trust, I want to assure residents that their concerns are also heard. Trust is the common thread, whether one is a worker, a patient, or a caregiver or a senior managing long-term care.
When Singaporeans trust that their health information is handled with care, strong safeguards and clear boundaries, they are more willing to seek care, share information honestly, and participate fully in our healthcare system. Sir, please allow me to continue in Malay.
(In Malay): [Please refer to Vernacular Speech.] This Bill must be able to establish public trust. Health data is intended to safeguard health, not to jeopardise livelihoods. Therefore, safeguards that prohibit the use of health data for employment purposes are extremely important, for workers, the self-employed, and platform workers.
No worker should fear that seeking medical care could be held against them at work.
These safeguards align with principles of fairness and dignity in the workplace, including for individuals with disabilities or mental health conditions. When trust is maintained, workers and senior citizens will feel more confident in seeking treatment and sharing health information honestly.
A robust healthcare system begins with trust, and trust only exists when clear boundaries and robust safeguards are implemented.
(In English): Mr Deputy Speaker, with the right safeguards in place, this Bill can strengthen healthcare delivery and public health outcomes. The safeguard disallowing the use of health data for employment purposes is a critical part of our trust framework. It reassures our workers that seeking care will not put their livelihoods at risk. It aligns with long-standing principles against discrimination and it supports, rather than undermines the objectives of this Bill.
At the end of the day, a healthcare system can only be as strong as the confidence people. When workers, patients and seniors trust that their health data will not be misused, at work or elsewhere, they are more likely to engage, participate and benefit. For these reasons, I support this Bill and the safeguards it contains.
Mr Louis Chua.
Mr Deputy Speaker, one's medical information is more than just a set of datapoints on a server. It is the deeply personal and sensitive, and a digital diary of our physical and mental lives.
Therefore, the public's trust is sacrosanct to the implementation of the NEHR. We must ensure that the Government and healthcare stakeholders do their utmost to safeguard the privacy of this data.
While I broadly agree with the principles of the HIB, which delineates the responsibilities of our healthcare ecosystem and mandates data contribution, I believe it is also important that we continue to strengthen areas of data privacy, transparency and individual agency.
As we move towards Smart Nation, we must ensure that our progress does not leave Singaporeans feeling as to the power asymmetry between themselves and the state is growing, and that they are losing control of their own data and privacy, and that public education measures would be stepped up to foster a deeper understanding of the NEHR's and one's rights as patients.
One crucial aspect of this Bill is that patients of opt in or out of the NEHR by way of an Access Restriction, which blocks medical practitioners from viewing all of the patient's NEHR's records, save important details, such as one's critical allergies and personal information. Patients may also select the medical institutions to the impose and access restriction on.
Notably, clause 30(7) reveals that even if a restriction is in place, a patient's information continues to be uploaded to the NEHR in the background. This, according to MOH, is in the interest of ensuring the expeditious provision of care should the patient wish to opt-in to the NEHR in the future or during an emergency situation. But Mr Deputy Speaker, if a citizen says "no" to the NEHR today, should the state then be allowed to say, "Okay, but trust me" and collect their data anyway?
In a 2017 letter to MOH, the then President of the Singapore Medical Association highlighted that this might compromise the patients' right to privacy. This is because patients might not wish for their medical records to be uploaded to the NEHR at all.
I urge the Government to reconsider this continuous background uploading and if other additional options can also be considered. For example, we should consider offering a total opt out or a so-called "no means no" option, provided the patient is thoroughly briefed on the dangers and risks of doing so and is counselled on the implications of such an option.
Second, patients might prefer to block access to certain documents and records only, instead of imposing a wholesale access restriction on their records. I understand that one sensitive health information that could potentially lead to stigmatisation and discrimination will be secured by additional measures, such as double lock-in feature.
Nevertheless, what is sensitive to one might not be sensitive to another. Hence, patients might wish for additional flexibility when protecting their health records rather than just give a blanket nod.
Part 3 of the Bill also allows for the sharing of both administrative and clinical information, to facilitate the continuity of care and outreach efforts for national health programmes through data sharing arrangements. Notably, patient consent is also not required for the sharing of such data between healthcare providers and public agencies as established under clause 50.
Therefore, I hope that patients will be recorded some flexibility and control over the types of health information they wish to disclose and how they would like that information to be used.
While I appreciate that we can already check out any NEHR access history in HealthHub, patient consent should also be sought for data sharing between healthcare providers and public agencies. On that note, Part 2, Division 4 of the Bill also sets out the requirements for the usage of any NEHR data for secondary purposes or derived information. After all, a national health record database provides a valuable snapshot of our population's health condition, which could then be used by researchers for developing solutions to public health issues faced by our society.
The Bill separates such derived information into two categories. Type 1, which is information that is individually identifiable, as well as Type 2, data that is aggregated and anonymised.
And it is worth noting that clause 30(5) paragraph (a) states that "The imposition of an access restriction does not preclude one's NEHR records, be it individually identifiable or anonymised from being disclosed as derived information, if an approval is granted by the Minister.
I agree with clause 25(2) that the Minister may approve an application to obtain Type 2 derived information, if the Minister is satisfied, having regard to the purpose for which the application is made. That is in the public interest to do so.
However, what are the instances in which subsection (1) will apply where individually identifiable health information is required in the name of promoting public Health?
This is another case where even if an individual exercises his right to impose an access restriction, it can be again overruled with a Ministerial approval for his individually identifiable information to be shared on public healthcare grounds.
Although the cost to the patient's privacy may be outweighed by the benefits such research brings to society at large, that should not preclude the Government from giving patients more agency over secondary usage of the health information, especially for research purposes. This is a principle that is adopted by other healthcare systems worldwide as well. For instance, both Taiwan and the EU have enacted regulations empowering patients to restrict the use of their identifiable health data for secondary purposes. Therefore, I hope that the Government would consider allowing patients to exercise greater control over the secondary usage of their health data.
To follow on the Ministerial approval requirement under clause 25, according to MOH's Trusted Research and Real World-Data Utilisation and Sharing Tech (TRUST) platform, which provides anonymised healthcare-related data for secondary usage, the Data Access Committee reviews the social value and public interests of each data request.
I agree that access to any NEHR data unlocks research and development (R&D) potential and supports long-term public health outcomes. When it comes to commercial-linked entities, however, while such parties might use the data for generating public health reasons and research, it raises ethical concerns surrounding transparency and privacy, especially if access to data is excessive, insufficiently justified or beyond stated that be used.
Back in 2015, in the United Kingdom, the Royal Free and HS Foundation Trust in London signed an agreement with Google DeepMind. This allowed the British AI firm to analyse sensitive information on 1.6 million patients who uses the TRUST hospitals each year. The access was used for monitoring software for mobile devices called Streams which promises to improve clinicians' ability to support patients with acute kidney injury. But according to the study's authors, the publicist dated in the agreement were far less specific and made more open-ended references to using data to improve services.
In the last few years, there has been a significant drive and race across providers to train AI models using the largest and most diverse datasets available in order to achieve better performance. However, this trend also raises important concerns about data privacy, particularly, in regard to sensitive records, such as medical information – NEHR data.
For this reason, we should exercise caution before granting third parties, especially if they are commercially-linked organisations, with excessive or unconstrained access to NEHR data, especially when longitudinal studies examining individuals' health records over prolonged periods are involved and be mindful of scope creep, given commercial incentives.
Besides R&D applications, I do believe that Government should capitalise on the NEHR's capabilities to boost the efficiency of healthcare delivery and financial assistance to all Singaporeans.
With allied health professionals, such as medical social workers having access to the patient's NEHR record, I hope that the possibility of financial assistance being further streamlined via enhanced data sharing procedures with the likes of the Social Services Office can be explored – with the patient's approval, of course. This would be most helpful in cases, such as long-term assistance to those permanently unable to work due to illness or disability. And in turn, this could also help to alleviate the workload of our medical social workers while easing the experience of those seeking financial and social support.
Finally, an extensive public education effort on the NEHR should also be implemented, should this Bill be passed. A 2018 Singapore Medical Association survey revealed that only 50% of respondents heard about the NEHR and 14.9% fully understood what the NEHR was back then. As shared in the Feedback Report on the Public Consultation for the Health Information Bill, during the public consultation exercise, MOH received feedback requesting for a greater clarity and clearer communication of the policy positions under the Bill. Will the MOH be conducting and updated public awareness survey upon implementation of the Bill to measure how public understanding of the NEHR has evolved, particularly regarding access restrictions and the use of individually identifiable data?
It is nonetheless critical that the Government ramp up its patient's education efforts regarding the purposes of the NEHR and how it might benefit them as well as to explain the rights of each patient pertaining to their medical data.
In conclusion, Mr Deputy Speaker, the NEHR represents a significant milestone in our Smart Nation journey but its success rests entirely on the foundation of trust. Medical information is among the most intimate forms of data one can share and the success of the NEHR ultimately depends, not on compulsion, but on trust.
To ensure this trust is not eroded by a perceived power asymmetry between the state and the individual, we must move beyond a "collect first, tell later" approach. And throughout my speech, I have highlighted three recurring themes: agency, transparency and proportionality.
I hope Singaporeans can be granted more meaningful control and disclosure over how their health information is accessed, shared and used. More importantly, we cannot have a well-functioning healthcare system if only 15% of people fully understood what the NEHR is. We must ramp up public education to ensure every Singaporean knows their rights and how their data is used to serve the common good, in order to foster the trust that turns our national database into a national asset. Notwithstanding these clarifications, I support the Bill.
Mr Yip Hon Weng.
Mr Deputy Speaker, Sir, we are becoming a super-aged society. Despite Healthier SG, care is not yet delivered in one place or coordinated by one healthcare team. It moves across clinics, hospitals and community settings. In such a system, information is not just paperwork. It is safety. It is continuity. It is dignity.
Because health information accompanies us through our most vulnerable moments, the success of this Bill will not be judged only by how efficiently data flows. It will be judged by something far more human – whether residents continue to trust the system enough to seek care early, speak honestly and return when they need help. That trust is fragile and once lost, it is hard to restore.
Today, I would like to focus my clarifications on three areas which residents have consistently raised with me: access control, support for smaller GP clinics and cybersecurity.
Mr Deputy Speaker, Sir, I begin with access control. The Bill introduces Access Restrictions under clause 29, with exceptions in clause 30, and the process for managing them in clause 31. These are important safeguards. But residents ask a practical question – will this protect me in real life?
My first question relates to the default setting. If Access Restrictions require residents to take proactive steps, does this mean their information is broadly accessible by default? How will seniors, especially those who are not digitally confident, know what to do? If privacy depends on digital literacy, then privacy is no longer equal.
My second question concerns granularity and role-based access. Clause 29 allows Class 2 Access Restrictions to be prescribed by information type, user class, purpose and time period. This is a powerful provision, but power lies in how it is used. Will this flexibility translate into true "need-to-know" access or will residents experience it as broad visibility once someone is authorised? Access should follow purpose and visibility should follow necessity.
My third question concerns sensitive health information. Yio Chu Kang residents tell me plainly that they want help, but fear being labelled. They worry not only about what is written, but about who might see it. This concern extends beyond mental health to other sensitive data such as human immunodeficiency virus (HIV) status, sexually transmitted infections, reproductive health history, genetic conditions and substance use treatments. These are conditions where fear of exposure can deter people from seeking care altogether.
Residents also raise a related fear that goes beyond stigma. They worry about where boundaries are drawn beyond direct care, such as access by insurers, employers, ancillary service providers or the downstream use of data for research, analytics or artificial intelligence (AI) training. Even where data is described as de-identified, residents worry about re-identification risks and inference. If these boundaries are not clear and credible, residents may hold back information or delay care.
How will MOH use the flexibility in clause 29 to ensure such sensitive categories are treated with particular care? Furthermore, under clause 30, where exceptions allow information to remain accessible, how will MOH ensure these exceptions are narrow and clearly defined rather than quietly eroding the intent of the restriction?
Sensitive care must feel safe or people will stay away. Healthcare for stigmatised conditions must be a sanctuary, not a spotlight.
My fourth question concerns privacy signals. Even when information is restricted, residents worry that the very presence of a "sealed" marker invites speculation. How will MOH prevent the fact of restriction itself from becoming a source of stigma or inference?
Finally, on transparency. Residents can view access logs on HealthHub, which is a good start. But do they merely see that an organisation has accessed their data or do they understand why? Will logs be presented in plain language?
Beyond investigation timelines, what happens if misuse occurs? Will residents be notified promptly, given a clear explanation and told what corrective or remedial actions have been taken? Transparency without recourse does not build trust. It only documents its absence.
Mr Deputy Speaker, Sir, I turn to the second area – support for smaller GP clinics. In estates like Yio Chu Kang, the neighbourhood GP clinic is not just a provider, it is a relationship where trust has been built over years. While the Bill places necessary obligations on institutions, the compliance costs land hardest on these small practices. Has MOH assessed the full financial and operational impact on solo GPs, from onboarding to ongoing cybersecurity obligations?
We hear feedback that NEHR can be cluttered and time consuming for less digitally savvy, elderly GPs. If clinicians spend more time searching and less time caring, have we truly improved care? Will MOH commit to measurable usability improvements, such as time-to-find critical information, structured clinical summaries and clinician user experience testing so that "less clutter" becomes a performance obligation rather than an aspiration?
There is a real last-mile reality. Cybersecurity and data requirements designed for large institutions can overwhelm small practices where the doctor is also the administrator and IT troubleshooter. Some GPs have shared a quiet concern that if requirements become too complex or costly, retirement may be the only option. When small clinics close, residents, especially seniors, lose convenient access and familiar doctors.
Has MOH weighed this risk against the Bill's policy objectives? If we ask neighbourhood clinics to operate like large corporations, we should not be surprised if they struggle. Residents will feel this quickly through higher fees and longer waits.
In that context, I ask whether support will be predictable and sustained. Will there be grace periods, phased onboarding and a genuine "no wrong door" approach so small clinics are guided rather than penalised as they come on board?
How will MOH prevent digital medical records vendors from engaging in fearmongering and profiteering, pushing small clinics into expensive contracts out of fear of non-compliance? Will responsibility for implementation be clear rather than fragmented? Where alternative contribution pathways are provided for pen-and-paper clinics, how will MOH ensure these are feasible and not a second-class solution? Compliance should not become a hidden healthcare tax on the heartlands.
Mr Deputy Speaker, Sir, I turn to the third area – cybersecurity. For residents, a breach is not a statistic, it is personal. The 2018 SingHealth cyberattack was a stark reminder that even well-resourced systems are vulnerable.
As the Chair of the GPC for Defence, I approach this with particular care. In defence, we learn that systems rarely fail at the centre. They fail at the edges, where resources are thin and the smallest gap becomes the point of entry. Healthcare systems are no different.
The Bill rightly imposes duties under clause 68 for reasonable safeguards and clause 70 for incident management. But residents ask two fundamental questions: will it be secure and will it be doable?
How will reasonable safeguards under clause 68 be defined in a tiered, risk-based way? Will small clinics have a clear, achievable baseline while larger institutions shoulder proportionately greater responsibility? How will MOH support small clinics in meeting incident management requirements under clause 70 without turning doctors into cybersecurity managers? Will there be shared services, templates, guided exercises and clear escalation pathways so bureaucratic demands do not take doctors away from patients?
Residents also care deeply about what happens when things go wrong. If a breach occurs, when will residents be notified, what information will they receive and what practical support will be provided to help them protect themselves and restore trust? Where cybersecurity failures arise from vendors or intermediaries, how will accountability follow control so that small clinics are not unfairly blamed or penalised for failures beyond their technical reach?
Availability also matters. When systems are down, patients are at risk. What resilience standards will apply to NEHR access? A system is only as strong as its weakest link and in healthcare, patients bear the cost of weakness.
In conclusion, Mr Deputy Speaker, Sir, we began with a simple reality. In a super-aged society, care no longer sits in one place, with one doctor, at one time. It moves across settings. Where care moves, trust must move with it. This Bill is about data, but more importantly, it is about people. It is about whether access controls feel like protection or complexity. It is about whether neighbourhood clinics are strengthened or quietly strained. It is about whether cybersecurity inspires confidence or quiet fear.
At its heart, this Bill asks a deeper question of us as a society. Can we build a system that is effective without being intrusive, secure without being crushing and connected without losing compassion? Trust is not a technical feature. Trust is the infrastructure that makes every other system work.
I call on the Government to ensure that as this Bill moves forward, implementation is anchored in three clear commitments: access controls that residents can understand and use; support that keeps heartland clinics viable and affordable; and cybersecurity that is strong, proportionate and shared across the system.
If we get this right, we will not only improve care, we will preserve dignity, we will strengthen trust, and we will send a clear message to every resident – seeking care will never mean surrendering control.
That is the healthcare system Singaporeans deserve. That is the standard we should hold ourselves to. I support the Bill.
Mr Fadli Fawzi.
Mr Deputy Speaker, the Bill advances necessary and timely updates to our healthcare ecosystem and I am supportive of the Bill's intentions.
The Bill establishes a statutory framework to consolidate key medical data into an integrated, longitudinal view of an individual's health record. This is in line with the vision of "One Patient, One Health Record", when the NEHR commenced a decade ago.
I understand that patient records from our public healthcare institutions are already in the NEHR. Let us say that you sought treatment in the Singapore General Hospital (SGH), information about your visit, such as your admission and discharge records, your laboratory test results, the procedures you did, the medication you were prescribed, are already in the NEHR. Following that, if you were to visit the Changi General Hospital (CGH), perhaps to see a specialist for a different medical issue, the CGH doctor will be able to use the NEHR to view the medical summary information of your SGH visit.
However, with this Bill, private healthcare providers will now also be mandated to contribute to the NEHR. This is significant since one of the reasons why patients opt for private healthcare is so that their health information is not included in the NEHR. This is especially concerning for patients dealing with sensitive medical issues, including those related to mental health, sexual health or addiction.
Sir, it is a given that a national electronic healthcare database will clearly help to optimise patient care and continuity of care. However, the success of the NEHR hinges on fostering trust that the Government can collect and consolidate our health information safely and responsibly. The trust can only exist if we keep patient privacy and patient autonomy at the forefront.
By patient privacy, I mean that patients must have the assurance that their confidential health data remains private and secure, with access granted only to particular persons for what is medically necessary or for public health purposes. Patient autonomy, on the other hand, means that patients should be able to meaningfully determine who has access to their data and how their data is used. In general, patients should be able to know when and why their data is accessed and by whom.
I believe the Government can agree with me that the NEHR must leave patients feeling empowered, not exposed. For that to happen, we cannot compromise on either patient privacy or patient autonomy.
Mr Deputy Speaker, the Bill defines a person's clinical information to include both the physical and mental health of the individual, and the diagnosis, treatment or care of the individual, while part one of the first schedule outlines the different types of health information to be contributed by specific healthcare providers. Altogether, there are 13 different types of health information, though only the providers of acute hospital service need to contribute to all 13.
However, I want to focus on the category of visit diagnosis, reasons for visit, or patient problem list, which many healthcare providers are mandated to contribute. I would like to ask the Minister about this category of health information. How lengthy or extensive should the contribution pertaining to diagnosis, reasons for visit or patient problem list be for the purposes of the NEHR?
I also want to note that, as of 8 January, the "Frequently Asked Questions" (FAQ) on Synapxe's website – Synapxe being our national HealthTech agency responsible for running the NEHR – states that the NEHR is meant to receive and consolidate key health summary information, but "not doctor's notes".
Here is a hypothetical example. Let us say a person were to meet a private psychiatrist and discuss their recent psychological difficulties, due to a recent breakdown in his or her marriage. The psychiatrist then records these details in their own doctor's notes. My first question: when contributing health information to the NEHR about the visit, is the psychiatrist mandated to include those personal and private details of the patient's life under the category of "visit diagnoses, reasons for visit or patient problem list"? My second question: if the private psychiatrist was not mandated to share their doctor's notes, can such information still be contributed to the NEHR, including without the patient's knowledge?
I believe that the public will benefit from an assurance from the Ministry that the scope of health information contained in the NEHR will only relate to key health summary data and will not include "doctor’s notes", especially intimate and confidential details about a patient's personal life, even if that information were in some way medically relevant to the provision of care.
Mr Deputy Speaker, the Bill also explicitly identifies certain "excluded purposes". I am sure that all patients appreciate the assurance that their healthcare information cannot be used for employment and insurance purposes.
However, I want to ask the Minister whether the Police and other law enforcement agencies will be similarly barred from using information from the NEHR? For instance, if a substance abuser sought treatment on his own to battle his addiction, would law enforcement be able to use the NEHR records to arrest and charge him? I ask this because patients seek treatment and care with some expectation of confidentiality, that their sensitive health information will be kept private. We need to ensure that patients continue to feel comfortable to seek treatment.
Mr Deputy Speaker, other than safeguarding their privacy, we need to ensure that patients are able to retain autonomy over their health information. Clauses 29 and 30 allow for access restrictions, which patients can use either to restrict all access to their information in the NEHR or to restrict access for specific users or purposes.
And if I understand clause 30(7) correctly, these Class 1 and Class 2 access restrictions do not prevent or restrict the contribution of healthcare information by a medical provider. In other words, healthcare information about every medical visit and treatment in Singapore will be recorded in the NEHR, but patients can block other healthcare providers from having access to that information.
Sir, these access restrictions will only work if these options can be exercised easily and in a patient-friendly manner. Currently, there is an option to opt out of the NEHR, but this involves a slightly elaborate and tedious process of making an appointment at one of the polyclinics and restructured hospitals to obtain and submit an opt-out form. Patients wishing to opt out will also be – and here I quote directly from the Synapse FAQ – they will be "counselled, to ensure that they fully understand the implications of this decision to their care as their providers will not have access to their records."
Even then, opting out does not mean your healthcare information gets deleted from the NEHR. What happens is that healthcare providers do not get to view them. Moreover, these Access Restrictions can be, understandably, overridden in a medical emergency.
I thus want to ask how the Ministry intends to implement the Access Restriction mechanisms under the Bill. Firstly, will the Ministry continue to counsel those who wish to invoke access restrictions and can we have further details about the content and duration of that counselling process? Secondly, is the Ministry considering the possibility of allowing patients to invoke or revoke these access restrictions online through HealthHub? Thirdly, is the Ministry planning to conduct regular public campaigns to educate patients about their access restriction rights?
Mr Deputy Speaker, another important dimension to patient autonomy is being transparent about the who, when and why of access to our healthcare information. I understand that patients can view which healthcare providers have accessed their health records through the NEHR Access History section in HealthHub. I want to clarify with the Minister about how granular this data would be. Would the patient only be able to see which healthcare institutions have accessed their records or will it also list out the specific healthcare professionals who were accessing their records? Moreover, at GP clinics, how can patients be sure that only their doctor is able to view the health information on the NEHR and not their non-clinical staff?
This relates to another question about unauthorised access to the NEHR. Clause 77 identifies what is a "notifiable data breach", namely, a breach which "(a) results in, or is likely to result in, significant harm to an affected individual; or (b) is, or is likely to be, of a significant scale".
Can I then ask the Minister to clarify how the Ministry intends to define "significant harm" and "significant scale” and why it has settled on such a standard? Would it not be more reasonable, not to mention the right thing to do, to notify affected individuals in any and all cases of unauthorised access to their health information?
Looking ahead, the national electronic healthcare system, once it is fully up and running, our citizen's pooled health data will be a valuable goldmine for clinical researchers and pharmaceutical companies. While this can accelerate drug development and spur medical innovation, the public needs assurance that their personal health data will not be monetised for profit.
Here, my question is whether the Government intends to make healthcare information in the NEHR available to the private, academic or any other sectors and whether the current Bill makes provisions to regulate such a possibility? While I am in principle not opposed to such collaborations, I hope that it can be explicitly legislated that any dataset from the NEHR must be anonymised, if this has not been done already.
Moreover, if the data is used for commercial research, the Government should consider a "Social Dividend" which ensures that the benefits return to the people. Any revenue or benefits derived should be reinvested directly into patient subsidies or national health funds, ensuring that the value generated by the people's health data is returned back to the people.
I would also suggest exploring the model of data cooperatives. One example of this model is non-profit Swiss cooperative MIDATA where citizens control their data and can choose to contribute it to specific research projects that they believe in. This has enabled research and tailored care plans for diseases, such as multiple sclerosis.
Mr Deputy Speaker, my foregoing questions and suggestions are intended to safeguard the integrity of the NEHR to strengthen public confidence in the system. To this end, we continue to emphasise patients' privacy and patients' autonomy to ensure Singaporeans are empowered, not exposed.
Mr Alex Yeo.
Mr Deputy Speaker, I rise in support of the Bill. Before I start, I wish to declare that as a legal practitioner in private practice, I have and do act for insurers and insureds in a variety of disputes. I make this declaration, as I will be addressing certain points relating to the "excluded purposes" contained in clause 6 of the Bill.
This Bill will govern the framework of our NEHR to: one, enable more effective clinical care; two, improve coordination; and three, consolidate care across different healthcare settings. In many urgent and emergency medical situations, this could certainly save lives.
On the other hand, the Bill also incorporates safeguards, a reflection that in this tech pervasive information age, personal healthcare information, in the wrong hands, used for inappropriate and insidious purposes, can potentially destroy lives. I would like to cover three areas of the Bill briefly: access, consent and excluded purposes.
Let us start with access. As we expand the NEHR to include all healthcare providers in Singapore, invariably, the number of access points to the NEHR will increase significantly. Any digital online system with many access points is particularly vulnerable to unauthorised access, inappropriate use and/or a cyber threat.
The Bill incorporates stringent access rules and restrictions, with deterrent penalties for breaches. Individuals are also at liberty to place access restrictions and view instances of NEHR access to their medical records via the HealthHub App. The Bill therefore provides safeguards while giving individuals with privacy concerns to decide on who should have access rights.
I am therefore glad to hear from the Senior Minister of State that MOH will conduct regular audits to flag inappropriate access to the NEHR. This is vital as it will provide healthcare providers regular and crucial information and feedback on the strength of their protocols and processes and allow them to act in a timely manner to adjust and tighten as required.
Given the large number of healthcare providers in Singapore, I would like to invite the Senior Minister of State to share with the House, the Ministry's plans on how these audits would be conducted, including the frequency and parameters of what would be studied, to ensure that the safeguards remain robust and amply protect the personal healthcare information of Singaporeans.
I now move on to the point on consent. The notion of patient consent is fundamental in medical practice – serving as a cornerstone in both legal and ethical obligations. Doctors regularly seek patient agreement in instances, such as treatment/interventions or to share medical information with a third party, including family members and so on. Even in the case where a patient has lost mental capacity, legal documents, such as a Lasting Power of Attorney or the legal appointment of a deputy, authorises another to, in effect, "consent" on the patient’s behalf.
In the context of healthcare, patient involvement in decisions about their care is an intuitive concept. Set against this background, the Bill however, does not require patient agreement to upload the key health information onto the NEHR. In fact, it makes it compulsory for healthcare providers to do so.
This can be a cause for concern for Singaporeans who may legitimately have privacy concerns with uploading their personal healthcare records onto the NEHR. One may ask, why can I not choose not to upload my healthcare information onto the NEHR? This is especially so since the harm or detriment suffered would likely be largely to the individual in the event of a leak or misuse.
We have also appeared to have taken a slightly different approach from jurisdictions, such as Australia, which allows patients to choose whether or what medical records to upload onto their system which is called "My Health Record" or to even have a record at all. As I believe, this would be an issue of interest to many Singaporeans, I invite the Senior Minister of State to share the policy and practical considerations behind why the framework governing the NEHR has been set up in this manner.
Finally, I would like to share some thoughts about the excluded purposes set out in the Bill. Clause 6 of the Bill sets out excluded purposes. In other words, these are purposes for which healthcare providers are not allowed to access the NEHR.
As things stand, these are when accessing the NEHR for: one, employment; or two, insurance purposes which include when an employer decides to employ, promote or terminate an employee and when an insurer decides whether to insure, continue or renew a policy and during the processing of claims.
This is a welcomed clause. Speaking from professional experience, it is important to have a clear demarcation of what relevant medical information of individuals should be provided in the context of these employer/employee and insurer/insured relationships, and what is sensitive confidential medical information that could be misinterpreted or inappropriately applied.
The Bill also goes one step further. The excluded clauses are, in fact, what I would describe as blanket exclusions, in that, even if an individual consents or agrees to allow access for these excluded purposes, healthcare providers are not permitted to do so. I appreciate the intent. Individuals should not be compelled to allow access for such purposes. For example, if all insurers in Singapore require NEHR access consent before agreeing to cover an individual under a health-related policy, then the individual is left with no real choice but to agree if he or she wants to be covered by the insurance.
However, I believe that there is a case to be made to allow for some relevant healthcare information to be accessed. Let us take the example of a health-related insurance policy. Generally, an insurer decides on whether to extend cover and if so, set the premium payable based on actuarial calculations. These calculations take into account a number of factors, including pre-existing medical conditions and medical history. If individuals can consent to a limited scope of relevant information that is agreed between the patient and in this instance, the insurer, then access can be permitted for that limited scope of relevant information via the healthcare provider. For example, this could be for medical histories of heart conditions or cancers.
However, as the Bill currently stands, there is no such option. Even if an individual wishes to consent, the healthcare provider is not permitted to access NEHR for the excluded purposes. It may be useful to understand whether this would impact insurance premium setting and/or insurance cover in the future, if and when the Bill comes into effect.
There is also, an instance in which the blanket exclusion can be lifted. If a legal dispute arises in the Courts between an insurer and insured, say, on issues relating to the non-declaration of relevant medical history, the Court can order access to a party’s NEHR records as part of the discovery of evidence process.
Before I conclude, I just want to make one observation of Mr Dennis Tan’s suggestion to increase the penalties for a breach. I can appreciate the intent. The balance, however, in such matters is between taking a punitive approach or supportive approach, where we work with healthcare providers to strengthen their protocols and processes in order to prevent breaches to re-occur. Mr Tan makes the point that large organisations may take financial penalties as a cost of business. In some cases, this may very well be true.
However, in the case of a healthcare provider, the people within – clinicians, nurses, administrators and so on – are well intentioned and want to build a system that better serves patients. When such a breach incident happens, I believe, it impacts not only the organisation but also the personal professional reputations of the people involved. Viewed from this context, a punitive approach may not be the best option. Perhaps we could start with the current approach and review this as the ecosystem takes shape after implementation.
Mr Deputy Speaker, notwithstanding the clarifications I have sought, I support the Bill.
Mr Kenneth Tiong.
Mr Deputy Speaker, I support the principles underlying this Bill. A population-scale set of longitudinal medical records is the "means of production" for more timely interventions, accurate diagnoses and preventive health at large. The contribution of data to the NEHR will create a valuable dataset and that value should flow to all Singaporeans.
But before I move on to the question of value, my belief is that a Bill that compels contribution must also come with robust ecosystem safeguards. From my conversations with practitioners and from my reading of the Bill, I have three sets of concerns: (a) the disproportionate cybersecurity burden on small providers; (b) the uploading of sensitive medical information despite patient objections; and (c) possible insurance loopholes that may render our privacy protections ineffective.
I will then speak to a broader question: if we are building a national health asset, who benefits and how do we continue to ensure it catalyses a dynamic ecosystem rather than becoming captured by a single monopoly provider?
First, to the cybersecurity obligations imposed on healthcare providers. The Bill designates all Healthcare Services Act licensees – from tertiary hospitals employing thousands to single-doctor GP clinics in HDB heartlands – as "relevant persons" under section 64. All face the same statutory obligations: to implement reasonable controls for secure processing, reasonable safeguards against unauthorised access and cybersecurity protections under sections 66 and 68. The penalties for non-compliance are severe; fines up to $200,000 or two years' imprisonment for individuals, and up to $1 million for other entities.
The Bill does use the word "reasonable", which implies proportionality. But I have spoken with doctors who run small operations. They worry that when a breach occurs – and breaches are a matter of "when" and not "if" – the enforcement spotlight will fall on them. Did they have sufficient firewalls? Was their anti-virus updated? Were their staff trained adequately? They fear being "hung out to dry”.
[Mr Speaker in the Chair]
I also wish to speak for some of my constituents who are senior GPs still practising in the heartlands. Many are approaching retirement and are not tech-savvy. They will struggle with the digitalisation requirements that this Bill will impose. If the transition is too abrupt, many of these senior GPs may feel forced to retire early or sell their independent clinics to large corporate chains, accelerating consolidation in the primary care sector. The end state of a modern, integrated health information system is desirable. But the transition must be managed carefully.
So, I ask: one, would the Ministry issue clear, tiered guidance on what constitutes "reasonable" safeguards for practices of different sizes? A safe harbour framework, if you will.
Two, will the Ministry consider providing or subsidising cybersecurity insurance for small providers so that they need not fear shouldering the entire financial risk of a breach?
Three, will there be a transition period with educational enforcement, rather than immediate punitive action, to allow smaller providers to build up cybersecurity capabilities?
Four, could the Ministry offer transitional support for senior practitioners nearing retirement, perhaps something as simple as sending personnel to help digitalise their records monthly?
Second, to the question of sensitive medical conditions that patients wish to keep private. There is a group of patients today who pay cash, wanting to keep their records, perhaps with sexually transmitted infections, mental health conditions or abortion records, off the system. Many foreigners also do not want to be on NEHR.
Under this Bill, that option will no longer exist. The Bill provides for "access restrictions" – Class 1 that prevents all access and Class 2 that restricts access for specific purposes or persons. But as section 30(7) states: "To avoid doubt, an access restriction does not prevent or restrict the contribution of health information." So, the data is uploaded and stored centrally. Any access restriction is a viewing control. It masks who can see the data. It does not exclude the data from NEHR.
If the burden of proof is on the custodian of NEHR to have a robust privacy model, let us examine the custodian.
Synapxe, the custodian of NEHR, was rebranded from IHIS, which was responsible for allowing the 2018 compromise of 1.5 million SingHealth patient records. The Committee of Inquiry found that IHiS staff lacked adequate cybersecurity awareness, that key staff failed to take appropriate action even when there were clear signs of an ongoing attack, and that the Chief Information Security Officer's response was, and I quote, "clearly lacking and displayed an alarming lack of concern”. This has led many doctors to mistrust Synapxe in these matters. Given the history here, I believe our health authorities also need to take steps towards rebuilding that trust.
So, I ask: one, how is MOH going to police unjustified access of NEHR, where rogue elements read medical histories of unrelated people? What assurance can MOH give us that our health data is safe with Synapxe?
Three, what is the technical architecture for access-restricted data? Is it encrypted separately? Is it stored in a segregated environment? Or is it simply flagged in the same database, such that a breach would expose it alongside unrestricted records?
Four, what is the access model for NEHR data? In Taiwan, the National Health Insurance system uses a dual-card approach – the patient must present their Health IC smart card, the doctor uses their professional IC card, and both are required for access, with written patient consent. This dual authorisation prevents rogue access because no single party can retrieve records alone. Will Singapore's NEHR access model include such safeguards?
And five, what is MOH’s position on specific carve-outs for defined sensitive conditions, where patients can opt out of contribution entirely?
Moving on to insurance. Mr Speaker, I commend the drafters of this Bill for their attention to the concern regarding the use of medical information for insurance underwriting.
Section 6 defines "excluded purposes" to include deciding whether to insure an individual, continuing or renewing insurance, or processing insurance claims. So, section 19(2) prohibits specified users from accessing NEHR for any excluded purpose and section 38(5) imposes enhanced penalties for accessing records for excluded purposes.
Insurers cannot access NEHR directly. Healthcare providers cannot access NEHR on behalf of insurers, and a patient's consent cannot be used to circumvent these protections. Is it watertight? Let me offer two possible scenarios.
Scenario one. According to section 3.1.2.2 of the Draft Guidelines on Appropriate Use and Access to NEHR, released by MOH in 2023: "In the event that such information was previously transcribed from NEHR into the patient's clinical notes, it would be treated as part and parcel of the medical record belonging to the healthcare institution."
Meanwhile, Integrated Plan insurers are increasingly requiring doctors to sign contracts containing "Inspection and Right to Audit" clauses. These clauses grant insurers the right to inspect full medical records to verify claims. The result is that doctors check NEHR for relevant history – past abortions, in-vitro fertilisation (IVF) treatment, mental health conditions, sexually transmitted infections – and note it in their files for clinical safety. Because of these audit clauses, insurers then gain access to this sensitive, transcribed NEHR data, even if it is irrelevant to the current claim. A patient going in for gallbladder surgery may find their insurer reviewing their psychiatric history.
Scenario two. Section 17(1) provides that an individual may access and collect their own accessible health information. A Singaporean applies for insurance. The insurer's application form may include a new requirement: "Please attach a complete printout of your National Electronic Health Record." No printout, no policy. Once the data leaves the system through legitimate patient access, it seems beyond the Bill's reach.
Even if insurers do not require a NEHR printout directly, they already have a right to refuse payouts if a pre-existing condition was not previously disclosed. If an applicant fails to disclose a condition, one that now sits permanently in NEHR, the insurers can void the policy at claim time when they discover the non-disclosure through other means.
The existence of NEHR with its comprehensive longitudinal record makes non-disclosure almost impossible to sustain.
So, I ask: one, does MOH agree that a transcription pathway where NEHR-derived information entering clinical notes and becomes accessible to insurers through audit clauses defeats the legislative intent of section 6?
Two, what if there is a data breach? Can insurers use the now public information?
Three, will the Government work with the Monetary Authority of Singapore (MAS) to prohibit insurers from requiring NEHR payouts or NEHR-derived information as a condition of coverage, claim processing or policy renewal?
Four, will the Government review the inspection and right to audit clauses in Integrated Plan contracts to ensure that they did not circumvent the excluded purposes provisions?
And five, if an insurer is found to utilise either pathway, what enforcement mechanisms will exist? Will this be a matter for MAS, MOH or both?
Deputy Speaker, I now wish to speak to a broader question. This Bill will create, for the first time, a comprehensive national database. Social determinants, such as postal code, education, marital status; clinical outcomes, such as blood pressure readings over decades, medications prescribed; and soon, perhaps, genomic data from the SG100K project.
It is a formidable dataset. It is a "means of production"; not just of population health outcomes, but of significant economic value. So, how do we ensure that value from this national health data infrastructure, and its possible monetisation of any form, flows to citizens?
Globally, startups are experimenting with patient-centric data models, where individuals can choose to share their data for research and receive compensation. I believe a monopoly, such as Synapxe, may not experiment with such models. But a contestable market will. Some players may try patient-centric approaches and the best models will emerge.
To create the conditions for competition to discover it, that requires open APIs, interoperability standards like the opt-in mechanisms of the sort that my hon colleague Mr Fadli Fawzi mentioned, and a contestable application layer.
Mr Speaker, let me turn to the system operator. Section 8 provides that the Minister may designate a system operator to operate, administer and maintain the national electronic record system. In practice, that will be Synapxe.
Synapxe, formerly known as IHiS, today employs about 3,500 people. It serves as a technology backbone for our entire public healthcare system.
When IHiS was set up in 2008, I believe the original vision was that it will operate on contestable principles. MOH will issue tenders, IHiS will compete, win some, lose some, it would have enough work to survive, but will need to compete elsewhere to thrive. In doing so, it will face enough competition to stay efficient.
This model was the original plan for the Ministry of Defence and ST Engineering. Dr Goh Keng Swee, speaking in 1977, said, "We do not own or run enterprises on ideological grounds. We expect Government-owned enterprises to be efficient, to make money and to expand whenever feasible. If a Government-owned enterprise loses money, it is allowed to go bankrupt, and this has happened, fortunately, in very few instances."
This was and is the discipline of contestability. Government-owned enterprises were to be subject to market forces.
But the current model for Synapxe has drifted from this vision. Today, MOH relies almost exclusively on Synapxe to implement its technology integrations. There is capture and cost inflation. An engineer is hired at $5,000 a month. That engineer's services are sold to public healthcare clusters at significantly higher rates. If the mark-ups are excessive – and they can become excessive in the absence of competition – it can crowd out innovation and make the ecosystem weaker than it should be.
I believe a different model is possible and necessary. My vision for Synapxe is different. It would return to the original contestable principles surrounding IHiS' creation.
First, I would seek to separate Synapxe into two entities.
The first entity would be a core infrastructure company. It would handle standard setting, data exchange protocols, security baselines and the NEHR plumbing. This stays Government-owned and lean – perhaps a few hundred people. It runs the pipes and sets the protocols but does not compete at the application layer.
The second entity would be a commercial services company. It would handle system integration, consulting and vendor management. This gets spun off – maybe privatised, maybe converted to a Government-linked company that must compete commercially, both domestically and internationally.
Second, MOH must reacquire the in-house capacity to be an intelligent buyer of technology services. Before or concurrent with any Synapxe structuring, MOH needs a technical unit of about 50 to 100 people – not administrators but engineers, data architects, security specialists – people who can evaluate bids, write specifications and challenge cost claims. Without this capacity, the Ministry will find it hard to escape capture.
Third, we should legislate interoperability standards and open API requirements for all health data intermediaries, including any entity that emerges from Synapxe. The goal is to ensure that the application layer – the layer where innovation happens – is open and contestable.
I happen to think all this can be done within four to five years.
Mr Speaker, with such contestability and with an opening for opt-in mechanisms where citizens can choose to share their data for specific purposes and receive compensation, I believe the NEHR can be a means of production for three outcomes: (a) better population scale outcomes. This is the primary purpose and I support it fully; (b) a fair stake in data monetisation for every citizen. If value is going to be extracted from the data, we should create conditions where citizens can likely share in it, not just bear the risk; and (c) an ecosystem catalyst for health-based startups.
With open APIs and interoperability, Singapore can become a place for health tech innovation. Startups can build on the NEHR platform, small and medium enterprises (SMEs) can compete for contracts. We can export health tech capabilities regionally. The NEHR can become a flywheel for a more dynamic health tech ecosystem, one that benefits the Government, citizens and entrepreneurs alike, not merely a Government-only benefit and asset.
Mr Speaker, in conclusion, I support this principle of a unified national health record. It can improve care, reduce waste and enable the precision medicine of tomorrow.
But a Bill that compels contribution must also come with robust ecosystem safeguards. Those compelled to contribute must be protected from disproportionate burden or liability.
Privacy controls must be real. Since access controls do not exclude data from NEHR, a breach potentially exposes everything, regardless of restrictions. Possible loopholes must be closed.
Today, insurers cannot access NEHR, but perhaps through transcription and audit clauses, they can access NEHR-derived information sitting in clinical notes. In locking the front door, we must also lock the back door. If we are to build a national data asset, we must ensure that it is governed by contestable principles, not captured by a monopoly provider. The original vision for IHiS was discipline through competition. We should return to it.
I look forward to the Ministry's reply. Thank you, Speaker.
Ms Joan Pereira.
Mr Speaker, the HIB is necessary for Singapore to transition to an integrated, community-based healthcare ecosystem. There are two aspects which I find essential for successful implementation that I wish to spotlight.
First, there is to be comprehensive onboarding support for GPs, including innovative shared staffing arrangements for small clinics; and second, I would like to call for strengthened support for community partners to ensure seamless continuity of care across our healthcare ecosystem.
To achieve "One Patient, One Health Summary, One Care Journey", our GPs, particularly those operating small, independent practices, need adequate support to participate sustainably. While most primary care clinics are already contributing to the NEHR, this figure masks significant challenges faced by small practitioners.
Stakeholder feedback had indicated that GP clinics and smaller healthcare organisations are worried about meeting cybersecurity and data security requirements as they have limited resources and administrative capacity. This is a valid concern as the burden falls on them to maintain cyber and data security. This is an ongoing challenge, even for well-resourced organisations globally.
Unlike large hospital groups with dedicated IT departments and compliance teams, small GP clinics often operate with minimal administrative staff, tight margins and practitioners who are clinicians first, not IT specialists. The clinics' concerns are understandable. Hence, I would like to seek three clarifications from the Minister.
First, would the Ministry elaborate on the scope and quantum of funding support? It would be helpful for the GPs to have more details. What is the maximum funding quantum per clinic? Does it cover hardware, software, training and ongoing maintenance? Will funding be provided upfront or reimbursed retrospectively? Small practices operate on tight cash flow and cannot afford to frontload substantial IT investments without certainty of reimbursement. Would MOH publish clear funding guidelines, eligibility criteria and the application timeline before the Bill takes effect from early 2027?
Second, would MOH extend implementation support beyond technology to operational capacity? While NEHR-compatible systems address the technical dimension, the administrative burden of data entry, staff training and compliance monitoring remains substantial. Small GP clinics often lack administrative staff dedicated solely to data management. I propose that MOH explore small clinics jointly hiring and sharing data entry staff through collaborative arrangements or tapping on some form of shared resources.
For example, MOH could facilitate or fund shared service models where three to five GP clinics in the same geographical cluster jointly employ a trained data coordinator who rotates between clinics, ensuring accurate and timely NEHR contribution, conducting staff training and maintaining compliance with cybersecurity protocols.
Third, would MOH consider a calibrated enforcement framework that accounts for clinic size and capacity? The Bill appropriately provides that MOH work with healthcare providers to resolve non-compliance, such as technical challenges leading to non-contribution, before issuing formal directions or penalties. However, enforcement must be differentiated. I hope that there could be special considerations given, for example, cases where it is a single-doctor clinic with two nurses should not be held to the same compliance timeline as a multi-site group practice with dedicated IT infrastructure.
The second aspect for a successful implementation calls for strengthened support for community partners to ensure seamless continuity of care across our healthcare ecosystem. We must ensure that data sharing between healthcare providers and community partners supports smooth continuity of care, particularly as patients transition from acute hospital settings to community care options.
Implementation requires operational readiness and active Ministry support for community partners. Community care organisations – Active Ageing Centres, voluntary welfare organisations, befriending services – often lack the IT infrastructure and data governance expertise to receive, safely store and use health information securely. Would MOH extend support packages beyond healthcare providers to include community partners, funding secure data systems, staff training and compliance with data security requirements? Sir, in Mandarin.
(In Mandarin): [Please refer to Vernacular Speech.] Community care organisations – Active Ageing Centres, volunteer welfare organisations, befriending services – often lack the IT infrastructure and data governance expertise to receive, safely store and use health information securely. Would MOH extend support packages beyond healthcare providers to include community partners, funding secure data systems, staff training and compliance with data security requirements?
(In English): Next, I would like to ask if MOH has a timeline for the sharing of non-NEHR health information with the private and community healthcare partners. This is necessary for seamless care continuity.
The Bill currently limits data sharing to public sector entities – AIC, healthcare clusters and public agencies. Over time, private community healthcare partners, nursing homes and home care providers should be included, subject to governance and data protection safeguards.
Sir, to meet the objectives of this Bill – "One Patient, One Health Summary, One Care Journey" and "A Community of Health” – small practices need support to participate meaningfully. Equally, community partners need active Ministry support to fulfil their role in continuity of care.
I look forward to the Minister's response. I support the Bill.
Deputy Leader, Zaqy Mohamad.