Debated in Parliament on 12 Jan 2026.
Debate resumed.
Ms Kuah Boon Theng.
Mr Speaker, within the healthcare industry, the HIB has been much discussed and long anticipated. This vision of achieving nationwide contribution of health information into a central repository is a truly ambitious and challenging goal. But as with all things new, it has not come without its fair share of fear and trepidation from the ground.
For years, our public sector healthcare institutions have been contributing to the NEHR. However, there are still private clinics and other healthcare establishments that have yet to modernise and digitise their patient records. And I agree with Members who have spoken so far that for those who struggle with new technology, it is particularly daunting to navigate the journey of digital transformation.
In this respect, I know that Ministry officers have been making the necessary preparations for a long time. Through various stakeholder consultations, the Ministry came to realise that many medical practitioners had concerns about the potential increase in medico-legal liabilities arising from the mandatory contribution of health information and the wider accessibility of that information to other healthcare providers.
And so, in late 2022/early 2023, the Ministry appointed the National Electronic Health Record Guidelines Workgroup and tasked the Workgroup to come up with a set of guidelines that would provide clarity on the professional responsibilities and obligations of healthcare professionals in terms of their contribution to, access and use of our national health records. The Workgroup, which I co-chaired, has since completed its work and issued a set of guidelines setting out the core ethical principles relating to our national health records, and proposing reasonable professional standards to be observed by all contributors and users. The draft guidelines have been made available, and I understand it will be published at such time when the HIB makes its successful passage through this House.
To formulate these guidelines, there were numerous engagement sessions arranged by the Ministry involving various stakeholders, for example, the Academy of Medicine, the Singapore Medical Association and the Singapore Dental Association, as well as nurses, pharmacists and allied health professionals. As co-chair of the Workgroup, I was present at most, if not all, of these engagement sessions to hear and address the concerns from the ground and to obtain constructive feedback.
We also took into account the interests of patients, the need to respect their autonomy in terms of who they would grant access to their national health records and the sensitivities associated with certain types of health information, for example, conditions that are stigmatising or affect employment opportunities or one's insurability. I am heartened to see that these issues have been specifically addressed in the Bill, which provides for access restrictions and makes it clear that access to our national health records should not be for employment or insurance purposes.
Some have mentioned that patients do not like to be asked repeatedly about their medical histories. But there is a need to emphasise that the primary source of health information remains with the patient. National health records can provide a back-up source of essential health data when patients are poor historians or are otherwise unable to provide information to their doctors, but it is not a replacement for the traditional way in which doctors interact with their patients through direct communication, which is so important if we are to build a strong doctor-patient partnership, one that is based on trust.
Integrated care also does not mean that we should expect doctors to routinely have to trawl through and read NEHR records before they even exchanged the first word with the patient. We do need to ensure that the healthcare professionals who are users of the system see it as an asset, rather than a potential quagmire where missteps will engender swift punishment and legal liability. As for patients, they need to have trust in the National Health Records System and believe that it is there to serve their needs and safeguard their interests, and not at the expense of their privacy or autonomy.
Many concerns from the ground remain, for example, that time is needed for their practices to be compliance-ready, that they need technical support to deal with cybersecurity threats or simply to familiarise themselves with recommended practice guidelines and the statutory obligations that will be put in place once the Health Information Act comes into force.
I can attest to the fact that senior Ministry officers who were present to hear these concerns from the ground have been extremely understanding and reassuring. They have signalled that flexibility will be exercised and allowances given in the event of non-compliance due to teething problems during the initial stages, and these problems could include delays in implementing adequate systemic safeguards. I would like to ask the Senior Minister of State if he can confirm that, indeed, contributors and users of the National Electronic Records System will be given some latitude, especially in the initial period, as they adapt to the new changes and expectations?
In addition, I would like to ask the Senior Minister of State if the Ministry intends to continue focusing on patient education efforts that will, in my view, be essential if we want patients to feel secure and have faith in how their sensitive health information will be handled. We are unlikely to gain all the benefits from this ambitious initiative if too many of our patients resort to setting controls on access due to fear or misconceptions. Patient education, therefore, needs to continue to be a priority and we must continue to listen to and address their concerns and build their trust.
Dr Choo Pei Ling.
Mr Speaker, I would like to declare that I am a registered member of the Allied Health Professions Council, and my work involves accessing, treating and educating on disability.
The HIB before us is a landmark piece of legislation. It establishes a robust legal framework for secure health information sharing across our healthcare ecosystem and this will shape the way Singapore delivers care for decades to come.
This Bill is not just about technology or compliance. It is about trust – trust between patients and providers, between Government and citizens, and between institutions and the professionals who serve in them. It is essential for our transition from hospital-centric care to community-based care, particularly as we confront the twin challenges of an ageing population and the rising burden of chronic disease.
Today, I would like to focus on these four areas: one, supporting community healthcare practitioners and GPs in onboarding to the NEHR system; two, improving data transition between Government hospitals and the community sector; three, strengthening support for allied health professionals (AHPs); and four, addressing patients' concerns about data protection thresholds and breach safeguards.
The vision of "One Patient, One Health Record, One Care Journey" is compelling. But to realise it, we must ensure that practitioners outside hospital settings, especially GPs in smaller, independent practices, have adequate support to participate meaningfully.
Today, most primary care clinics already contribute to NEHR. This is commendable progress. This is driven by Healthier SG's integration requirements. Yet we must acknowledge the realities. Many GPs operate with lean teams, limited administrative bandwidth and modest technical capacity. For them, NEHR integration can feel like a burden, even if its clinical value is clear.
The Bill rightly provides support mechanisms: whitelisted NEHR-compatible systems and funding packages to defray onboarding and cybersecurity costs. These are welcome. However, as we move towards mandatory participation, we must ensure that implementation timelines are realistic. The Bill takes effect from 2027, providing healthcare providers time to adopt support measures and comply with requirements. But for some GPs and smaller practices, this may still be a tight timeline for them.
I urge MOH to adopt a calibrated enforcement approach, working collaboratively with GPs to resolve technical challenges rather than defaulting to penalties. This is crucial for building a genuine partnership with community practitioners. May I ask how MOH will ensure it has sufficient technical professionals and resources on the ground to assist clinics in implementing these changes on time?
The Bill rightly seeks to enable seamless data transition between Government hospitals and community healthcare partners. This is vital for the continuity of care as patients move from acute to community settings.
This framework is sound. However, we must ensure that the data transition process is not merely technically compliant, but genuinely supportive of community-based practitioners. When a patient is discharged from a Government hospital, the community GP or AHP taking over care should receive comprehensive, timely, clinically relevant information.
Further, as private community healthcare organisations mature in governance and systems, they should be progressively included in the Fourth Schedule of the Bill. This would extend data sharing arrangements beyond public institutions, strengthening care continuity across the entire healthcare ecosystem.
AHPs – physiotherapists, radiographers, occupational therapists, speech and language therapists and radiation therapists – play indispensable roles in patient care and should have access to relevant NEHR information. In particular, AHPs are crucial in managing chronic conditions, rehabilitation and preventive care in the community and outpatient settings. They need access to medication histories, adverse drug reactions, recent investigations and relevant diagnoses to deliver safe and effective care.
For them, access to relevant NEHR information is not optional. It is essential. Yet, the stakeholder feedback indicates concerns about whether all AHPs will have equal access rights and whether sufficient safeguards exist to ensure they access only clinically relevant information for their specific roles.
The Bill provides role-based access controls, ensuring AHPs can only access data relevant to their duties. This is appropriate. But I urge MOH to go further.
First, establish clear practice guidelines for each AHP profession, specifying what NEHR data is relevant and when access is clinically justified. This removes ambiguity and supports professional judgement. Second, ensure that AHP associations are active partners in training and upskilling of their members on NEHR use, medico-legal responsibilities and safeguards. The MOH will publish guidelines on appropriate use of NEHR to address medico-legal concerns, but professional bodies should help manage implementation through their own continuing education programmes. If we want integrated care, we must empower every professional who contributes to it.
Finally, Mr Speaker, let me turn to the issue of data protection. Trust is the currency of healthcare. Patients must feel confident that their most sensitive information is safeguarded. Healthcare providers must report data breaches to MOH and affected individuals if the breaches result in significant harm. This is sensible for large-scale incidents. But what of smaller breaches, affecting 50, 100 or 200 people?
May I seek the Minister's assurance on four points.
First, all breaches, regardless of scale, must be assessed and remedied. The MOH's enforcement will take seriously even breaches affecting small numbers of people. Two, patients should be notified of significant breaches affecting any number of individuals. Three, repeated smaller breaches that reveal systemic vulnerabilities must trigger decisive corrective action. Four, patients should be able to view access logs for their records and flag suspicious activity to MOH. Citizen monitoring can be a powerful supplement to regulatory oversight.
Mr Speaker, the HIB is a decisive step towards integrated, secure, patient-centric digital healthcare. With targeted support for community practitioners, robust data transition frameworks, enhanced support for AHPs and clear safeguards for smaller data breaches, this Bill can deliver genuine benefits while protecting patient privacy and maintaining trust.
If we succeed, this Bill will not only strengthen our healthcare system but also deepen the confidence of Singaporeans in it. I support this Bill.
Dr Haresh Singaraju.
Mr Speaker, I wish to declare that I am a family physician with the National University Polyclinics. I am a father of young children. Growing up in the heartland and now serving in public healthcare, I have lived and worked among Singaporeans across generations, across every walk of life.
Every day, I sit across the table from patients: the uncle in his 60s managing six chronic conditions; the young mother bringing her newborn for a jaundice review, hoping the hospital's records have already reached me; the elderly auntie who cannot remember which medicines to take; and the caregivers, trying to make sense of it all for loved ones who cannot.
They come because they trust we will help them make sense of a system that can feel overwhelming. And I work alongside nurses, care coordinators, allied health staff, administrators and fellow doctors. People who entered healthcare to help, doing their best under difficult conditions. I speak today for both: for patients and families who depend on the system and for healthcare workers who make it work.
Mr Speaker, the vision behind this Bill is right. One patient, one health summary, one care journey. Information that follows the patient. Fewer duplicated tests. Fewer medication errors. Better patient safety. Better clinical decisions.
The Bill sets clear boundaries. Clause 6 – excluded purposes: employment and insurance related matters. Clause 38 makes it an offence to access the NEHR, for these purposes. Penalties are serious.
Patients must trust that their health information will not be used against them. These protections matter. But the Bill is only as good as the trust it builds, from patients and from providers. I have three observations.
First, the boundaries are clear, the grey zone is not. The Bill tells us what we must not do, but not what we must do, or how much is enough. A patient comes to see me. Cough for two weeks. No clinical red flag features. I take a history, examine her and I am satisfied. Likely a viral or post-viral cough. I treat her symptomatically. I do not access the NEHR. Three months later, it turns out she had early lung cancer. A CT scan done elsewhere six months ago showed a lung nodule. It was in NEHR. I did not see it. Was I wrong? I had no reason to suspect cancer. My clinical assessment was adequate. But the information was there.
Consider the reverse. I access NEHR. Years of records. Hundreds of entries. How deep must I go? How wide? If I click "Result A" but not the adjacent "Result B" because it seems unrelated to the current consult, is that reasonable? Or will I be asked, later, why I did not check?
Clause 99 protects those who act in good faith and with reasonable care, but it does not define what reasonable care looks like. In practice, clinicians exercise professional judgement every day. But what does reasonable care and professional judgement look like with 10 minutes of consultation time and 10 years of records?
I am not asking for immunity from accountability. I am asking for clarity. Clarity on what reasonable access looks like. What constitutes adequate review. How we should document the choices we make, against the ever-increasing complexity and demands of clinical care.
And this guidance must be sustained. Not a one-time circular, but updated as systems and practice evolve. Without this, clinicians will practise hesitantly. Some will over-access, lost in screens. Others will under-access, afraid of what they might find. Neither serves patients.
I ask the Minister: will the Ministry commit to facilitating and supporting the development of clear, practical guidance, in consultation with the profession, on what constitutes reasonable access and review?
Next, governance is central, enablement must be central too. NEHR is centrally governed. Standards are set by the Ministry, but implementation is local and the burden falls unevenly.
Public institutions have the resources to maintain systems, keep them updated and respond when things go wrong. We cannot say the same for private practice. I still speak to friends from medical school, former colleagues now in private practice. The solo GP in Bedok, the small group practice in Jurong: they face the same data security and breach reporting standards under Parts 4 and 5, with far fewer resources. I know senior doctors, still sharp, still caring, who are thinking of hanging up their white coats early. Not because they cannot practise medicine, but because they cannot keep up with the infrastructural demands.
Clinicians should be caring for patients, not managing systems. I do not argue for lower standards. Patient data must be protected, but enablement must match governance. Central standards require central support and this support must be sustained, not just during roll-out. If we expect doctor-patient relationships to last decades, the support must last too.
I ask the Minister: will there be dedicated, sustained support for smaller practices? This could take many forms: shared IT services, pooled cybersecurity monitoring, simplified compliance pathways. Existing structures like Primary Care Networks could be leveraged. These need not be free, but they must be accessible and sustained; not tapering off after implementation, but continuing for as long as the obligations continue.
Third, portability must align with continuity. Part 7 provides for portability of health information. Patients can request their records be transferred. This is right. Patients should control their own information. But there is a tension. Healthier SG encourages patients to build long-term relationships with one family doctor. Continuity improves outcomes. Trust takes time and NEHR supports this, giving access to specialist and hospital records, enabling coordinated care. Yet, seamless portability makes it easier to move between private providers. If records follow effortlessly, why stay with one doctor?
I am not suggesting we restrict portability. There are valid reasons to change primary providers: relocation, a breakdown in relationship perhaps. But if portability inadvertently undermines continuity, NEHR risks enabling fragmentation. Episodic care from whichever provider is nearest, cheapest or most convenient, leading to wasted resources.
The technology is neutral. The outcomes depend on policy coherence. I ask the Minister: what measures will ensure that portability reinforces, rather than weakens, the care relationships Healthier SG seeks to build?
In closing, Mr Speaker, this Bill matters. It matters to the patient hoping the next doctor knows what the last one did. It matters to the clinician wanting to do the right thing but uncertain of the rules. It matters to the small practice owner worried about compliance. Legislation alone does not build trust. Trust is built through clarity, through support, through coherence between policies meant to work together. While I support this Bill, I urge the Minister to address these concerns, please.
Mr David Hoe.
Mr Speaker, Sir, I am speaking in support of the HIB. At the very core, the Bill addresses a very real and familiar problem in the healthcare today: information does not follow the patient always. You see, as care becomes more complex, with more providers, more settings and more chronic conditions, patients often carry their own medical history across the system.
For many Singaporeans, the most stressful part of a health episode is not just the illness alone, but it is the friction that comes along with it. They have to repeat their story with every medical visit. They struggle to recall the medication names – sometimes I do – past dosages, or test results that sit in different institutions. For those caring for ageing parents, they become our human bridge as they juggle between appointment letters, WhatsApp photos of prescriptions and fragmented notes of different providers.
Therefore, having a well-governed national health record reduces this burden. It supports safer handover between stakeholders in the healthcare systems, such as our GPs, specialists, hospitals and community partners. It also lowers the risk of missed allergies, drug interactions and also unnecessary repeated tests that cost time, money and anxiety.
This Bill puts the NEHR system on a clearer legal footing, including governance of access, use and safeguards. For these reasons, I support the intent and direction of this Bill.
That said, Mr Speaker, I would like to raise three broad points which I hope will be used to strengthen trust and confidence in implementation.
My first point pertains to individual regarding sensitive health data and access restrictions. Mr Speaker, not all health information feels the same to all citizens. Sharing information about a cough, a vaccination, a fracture, is usually straightforward.
But many Singaporeans will understandably feel unease when information relates to areas where stigma still exists, such as mental health conditions, sexually transmitted diseases, HIV status, substance abuse, self-harm or records that may expose abuse. The fear is not only about embarrassment, but it is about the consequences that will come along too. Specifically, how would such information affect their employability.
This is why the Bill's safeguards matters, because access is purpose-limited, it is role-based, logged, restrictions are auditable and misuse attracts serious consequences. It gives individuals the ability to impose access restrictions. The ability to impose access restrictions provides individuals with the peace of mind. In essence, it gives that reassurance to say that, "Hey, I can see my records. I can understand my records, and if I wish, I can limit the information the other party can see", which is important because this is how we build trust.
In addition, it is important to reassure Singaporeans clearly by proactively communicating the following, that MOH has stated that NEHR's information is for clinical care and is not accessible by employers or insurers. The message should remain consistent and prominent as the Bill is being implemented.
And against this backdrop, I have two clarifications on this. Firstly, let us agree that not all Singaporeans are digitally competent or confident. As we have seen in the recent Community Development Council (CDC) January vouchers, where even after multiple rounds of education, some seniors still do not feel confident in claiming their vouchers digitally. They still come to our Community Centres to collect hardcopy vouchers.
Against this backdrop, I wonder what assisted pathways will be available for residents who wish to understand and also know how they can manage their access restrictions? Could this include in-person support at polyclinics, hospitals or even trusted community touchpoints, so that the right to impose, to understand access restrictions, it is not only for those who are digitally confident, but for every single Singaporean?
Second, I wonder, will citizens also be able to view their access history in a way that is simple and meaningful; and will MOH also clearly explain what the access history does and does not capture? For example, a resident showed me that if you go to our HealthHub's FAQ page, it says: "Your healthcare professionals may be accessing your records from their own Electronic Medical Records (EMR) systems. Accesses made to your records in their own EMR systems are not included in the National Electronic Health Record Access History." In plain English, what it means is that sometimes doctors and nurses, they see your records through their own systems rather than the NEHR. And what this means is that it would not be captured in the access history, because they are looking for information through their own system. If we want to build trust, then we must be clear what the access history can capture and cannot capture.
Beyond these two questions, that got me thinking about the issue of data completeness. As clinicians document care in their own clinic and hospital systems, the NEHR depends on what is contributed through integration. Other systems abroad also show that governance alone is not enough. Some jurisdictions mandate provider contributions through law, while others rely on technical readiness or voluntary participation.
Regardless, the NEHR will only reach its fullest potential if data contributions are consistent and timely. In our case, beyond reporting required by law, how would MOH encourage strong compliance in the everyday operations, that is required in the core data that is reflected in our Bill, such as medication list, vaccinations administered and also dental notes, and so on.
We need to ensure that this contribution is consistent, prompt, with good quality, across providers. Would there be positive levers such as integration support, performance feedback, recognition of good practices and contributors to be considered for the rest to learn from.
Mr Speaker, my second point pertains to smaller providers, reflecting the unevenness in readiness to implement. Cybersecurity audit and reporting obligations are necessary, but they are operationally demanding. Smaller clinics and some community providers may need more time and practical support to meet new requirements properly.
From my own experience in procuring cyber security services in different roles, significant time and effort goes into spelling out the requirements, finding the right provider, implementing and ensuring user adoption, all that to say, it requires time.
I therefore hope that the implementation of this Bill will be accompanied by the reassurance that: one, transition timelines will take into account of capacity of smaller providers; two, implementation support will be sustained and ongoing beyond simply the launch period. In practical terms, what this could look like means standard templates, shared tools, training resources, a clear helpdesk and escalation pathway and where necessary, support to uplift baseline cyber security since the system is only as strong as its weakest link.
Finally, Mr Speaker, I would like to raise a practical continuity of care issues brought up by some Singaporeans that I have had conversations with. In these interactions, a Singaporean shared with me, and I also understand so, because I have experienced that through my friends who are young parents as well. They shared that some of them would prefer to go overseas for screenings or procedures, because they perceive it to be cheaper and/or faster. For instance, with the initiative such as the Johor-Singapore Special Economic Zone and the MOU on Corporation in Health signed in December 2025, I think we are likely to see closer health linkages and maybe more Singaporeans might go up north for medical screening and treatments in the near future.
However, information generated overseas will not automatically be captured in our national health record system, so I would like to seek the Ministry's view on information generated overseas. In particular, would the Ministry consider capturing reliable and credible health information data from abroad in our system? Because in my experience when I spoke with some parents, when they have newly-born, they are quite excited to search for and know the gender of the child. They would go overseas to do a quick test so that they will know whether it is a boy or a girl.
Is there even a possibility for Singapore residents to share the clinically relevant overseas finding with Singapore providers in a way that clinicians can validate and incorporate safely? Of course, this should be considered with the intent that any integration of overseas health information should be done to strengthen our continuity of care and not compromise data quality and clinical safety.
Mr Speaker, in sum, the HIB is a necessary step for our modern healthcare system. If implemented with clear communication, assisted access pathways, and credible transparency, this Bill can help Singapore build a health data ecosystem that is both enabling and trusted. With this point, Mr Speaker, I support the Bill.
Dr Hamid Razak.
Mr Speaker, Sir, I rise in support of the HIB. Before that, I declare my interest as an orthopaedic surgeon currently in private practice.
Drawing from both my clinical experience and ground feedback that I have gathered, I will focus my remarks on two areas that have surfaced repeatedly: one, the practical realities faced by clinicians, particularly in smaller healthcare settings; and two, the importance of patient trust, supported by robust access and privacy safeguards.
Mr Speaker, as clinicians, we do see every day how fragmented information can compromise care: duplicated tests; missed drug allergies or interactions; incomplete histories, especially for seniors with multiple medical problems. At the same time, many doctors, particularly those in smaller GP practices, specialist clinics and dental clinics, have raised practical questions about how this Bill affects their medico-legal responsibilities. I think this was alluded to earlier by Dr Haresh as well.
First, I would like to seek clarification from the Minister on the intended role of the NEHR in daily clinical practice. Can the Minister confirm that the NEHR is positioned as a supplementary clinical tool, and not a mandatory step that must be accessed in every single consultation?
Such clarity is important. Good medicine still begins with history-taking, physical examination, and the doctor's professional judgment, based on the presentation of the patient at that material point in time. Digital tools should enhance clinical decision-making, not replace it. Clear articulation of this principle will help address concerns that clinicians could be exposed to liability simply for not accessing NEHR in every encounter.
Second, clarity in guidance will be essential. As clinicians are required to contribute to and access NEHR responsibly, clear, practical guidelines on appropriate use will help healthcare professionals act with confidence: firstly, knowing when access is appropriate; next, how to document decisions made on the access of NEHR data; and then, how to meet their obligations without fear of inadvertent non-compliance. I therefore welcome the Ministry's intention to provide guidance and training to all healthcare professionals.
Third, I wish to speak for smaller providers who are concerned about cybersecurity and data protection requirements. Unlike large institutions, many smaller clinics operate with limited manpower and resources, as already alluded to by previous speakers. In this regard, I do welcome the funding support and the use of whitelisted systems to help smaller providers comply safely and securely. A calibrated enforcement posture, coupled with practical assistance, will be key to ensuring that compliance strengthens care rather than becoming an administrative burden.
Ultimately, Mr Speaker, clinicians want to do the right thing for their patients and for the healthcare system. This Bill works best when it enables clinicians, rather than paralyse them.
Mr Speaker, the second area I wish to address is patient trust. Trust is the bedrock of healthcare. Patients share deeply personal information because they trust it will be used solely for their care and not to disadvantage them in any way.
Unfortunately, on the ground, I personally have seen instances that undermine this trust. There have been cases where insurers have written to multiple clinics in the vicinity of a patient's residence, seeking information about the patient's medical history in the context of an insurance claim. These broad and often non-specific requests are deeply troubling because they go back in years. They ask about someone presenting with a particular symptom, 10 to 15 years before the current claim is being made. This places our clinicians in a very difficult position and risk compromising confidentiality between providers who may actually have no direct care relationship with the patient. These practices underscore why clear legal boundaries around access and use of health information are essential.
In this regard, I strongly support the safeguards embedded in this Bill. I understand that access to the NEHR will be both role based and purpose specific. Healthcare professionals may only access records for patients under their own care and only for direct patient care purposes. Crucially, the Bill explicitly prohibits access for employment and insurance purposes, except in narrowly defined statutory medical examinations. This clarity sends a strong and necessary signal and directly addresses public concerns about misuse.
I also welcome the transparency features enabled through HealthHub. Patients will be able to see who has accessed their records, restrict access where appropriate, and flag potential misuse. These features reinforce accountability and uphold public confidence.
Importantly, this Bill maintains a careful balance. Even when patients apply restrictions, a core set of critical health information, and full access in genuine medical emergencies, will remain available. This ensures that patient autonomy does not inadvertently compromise patient safety.
I was glad to hear fellow Member Mr Fadli prioritise patient autonomy in his speech earlier. This is why I believe a restricted access approach, rather than a complete opt-out approach would be more beneficial to patients, clearly demonstrating that in medical emergencies in the case of an opt-out system, critical information more not be available to the attending physicians.
Mr Speaker,
As we aspire to have inmates eventually transition back into the community or require care in our public healthcare institutions, timely access to critical medical information can be important for their safety and continuity of care. I seek the Minister's clarification on how such health information is treated within the broader framework of the NEHR and how safeguards are applied in these contexts.
Finally, I would like to seek the Minister's clarification on how the Bill safeguards particularly sensitive health information, including mental health data, and the penalties in place to deter misuse. Such safeguards are critical in protecting dignity and sustaining trust, especially for patients who already feel vulnerable at the point of care.
Mr Speaker, this Bill is not ultimately about data or systems. It is about ensuring that clinicians have the right information at the right time, that patients retain dignity, privacy and autonomy, and that trust remains the foundation of our healthcare system. When trust is preserved, seamless care becomes possible. For any healthcare system to function well, healthcare providers must trust the system, patients must trust the system and the healthcare system must be worthy of that trust.
With the safeguards for patients, clarity for providers, and support for implementation, I support this Bill.
Order. I propose to take a break now. I suspend the Sitting and will take the Chair at 7.25 pm.
Sitting accordingly suspended
at 7.13 pm until 7.25 pm.
Sitting resumed at 7.25 pm.
[Speaker in the Chair]
Debate resumed.
Senior Minister of State Tan Kiat How.
Mr Speaker, I thank all the Members who have spoken, for supporting the Bill, especially our new Nominated Members, Ms Kuah and Dr Haresh, contributing to the debate on the first day they are sworn in.
Sir, only by enabling data sharing and a unified health summary for each patient, can we support continuity of care when patients move between different healthcare settings and receive care from multiple healthcare providers.
The Members have raised a number of thoughtful views and constructive comments which I will address in four broad themes.
But before I do that, I would like to address the points made by the Member Mr Kenneth Tiong around the organisation of and his views on Synapxe, the health tech agency that implements many of the IT projects in MOH. As that topic does not pertain to the specifics of the HIB, I encourage Mr Tiong to raise a separate Parliamentary Question or raise the issue separately from today's debate. But suffice to say that Synapxe is not a commercial entity. Its fundamental role is to support MOH in delivering digital health and IT services to benefit the healthcare clusters to deliver better healthcare services to our Singaporeans.
Let me now turn to the substance of the Bill. There are four broad themes of comments that came in. First, it is around the safeguards for patients. Second, the obligations and support measures for healthcare providers. Third, the support measures for healthcare professionals. And fourthly, the sharing of non-NEHR health information. Let me start with the safeguards for patients.
Mr Yip Hon Weng, Mr David Hoe, Dr Wan Rizal, Dr Hamid Razak and Mr Fadili Fawzi highlighted the importance of safeguarding access to and the use of patients' NEHR information. And this has been a focus for us when we carried out the public consultation and prepared this Bill. There are broadly two sets of concerns that we hear from individuals.
The first is how a patient's NEHR information will be adequately safeguarded and accessed only as needed by healthcare professionals and providers. Of special concern is the access to health information that may be deemed more sensitive. There were also related questions about the Access Restriction feature. So, that is the first set of concerns. The second is around whether their NEHR information would be used beyond healthcare, such as for employment and insurance purposes.
Let me touch on the first set of concerns. Sir, we are not starting from scratch. We have been operating the NEHR for 15 years. Importantly, the vast majority of healthcare providers are already onboard – all public healthcare institutions, most private hospitals and the bulk of the GP clinics. So, this is a system that has been operating for many years. And we have built in various ex-ante safeguards into the design of the NEHR. This includes role-based access, such that authorised healthcare professionals can only access the types of health information required for their specific patient care roles. We also have technical controls and regular ex-post audits to flag unauthorised accesses to the NEHR.
With the HIB, we are enhancing the legislative safeguards and stiffening penalties for unauthorised access.
Mr Dennis Tan spoke about offences and whether the $1 million maximum fine was sufficient. Sir, the regimes he compared with as well as PDPA that he referred to, do not have criminal prosecution. The breaches to the HIB are serious and we take this seriously. For example, a conviction involves not just fines, it is imprisonment as well. But more basically, we take an approach that is more supportive, working together with our healthcare providers, the healthcare professionals. These are people – nurses, clinicians and administrators, who want to do well, who want to serve the patients, who want to take care of the patients. And we want to take a supportive role and approach to uplift data security and cybersecurity postures, not a punitive approach.
Mr Alex Yeo asked about audits on unauthorised accesses of the NEHR and Mr Tiong asked if Synapxe would proactively monitor against unauthorised access. Synapxe, the NEHR system operator, conducts regular audits and ongoing monitoring to detect suspicious behaviour or atypical patterns, including in response to patient alerts. For example, accessing the NEHR information of a patient who has not recently visited any healthcare provider is a flag. Synapxe will conduct investigations to determine whether an unauthorised access has occurred. Synapxe will regularly review its audit plans, including frequency, best practices and the use of new tools like artificial intelligence to ensure that the regime is robust.
In addition, instances when a patient's NEHR information is accessed over the preceding 12 months will be made known to him through the "NEHR Access History" feature in the HealthHub application. This provides an additional layer of transparency. Patients can monitor which healthcare providers have accessed their NEHR information and flag any unauthorised access to the authorities for investigation.
The logs will show access at the healthcare institution level to keep the function simple, useable and practical. In a multi-disciplinary team, healthcare professionals across different roles may access the patient's NEHR information at different times of the patient's care journey. Depending on the patient's condition, it is also not uncommon for nurses, pharmacists or allied health professionals to need access. In our healthcare system, the institution is ultimately responsible for care to its patient.
I would like to take the opportunity to clarify the comment made by Mr David Hoe. HealthHub access logs will show all accesses to NEHR, regardless of whether the access is through EMR or the portal. So, just to clarify on his point earlier.
Sir, I would like to assure Mr Hoe, Mr Fadli and Mr Yip that we will seek users' feedback when reviewing the interface to ensure it is simple and user-friendly.
Mr Speaker, we understand that some patients are particularly concerned about access to health information that may be deemed more sensitive. Mr Louis Chua, Mr Yip, Dr Hamid, Mr Hoe and Mr Tiong have commented on the need for safeguards for such information. Such health information includes sexually transmitted infections, delusional disorders and schizophrenia. The diagnoses and test results that confirm the condition are subject to additional safeguards.
First, there are restrictions on who can access this information. Only a select group of healthcare professionals are allowed to access this information, based on their role in caring for the patient diagnosed with the health condition. For example, a nurse who is working in a psychiatric ward will have access to the psychiatric condition of the patient he or she is caring for. So, that is the first control.
Sir, we appreciate that despite all these safeguards, some patients may still have privacy concerns. To assuage the concerns of these patients, the HIB will allow patients to restrict healthcare providers from accessing their NEHR information or we call this "Access Restrictions" in the Bill. As I mentioned earlier in my opening speech, we do not encourage this, as it could lead to adverse impact on care delivery for the patient.
To address the queries raised by Members, the Access Restrictions have been designed to balance the impact to patient care; considering the welfare and interest of the patient, while taking into consideration their concerns around privacy.
So, patients may restrict access to their NEHR information at the healthcare institution level, but not at an individual healthcare professional level. As I have mentioned earlier, care delivery is team-based and increasingly multi-disciplinary. It is not operationally feasible to restrict access to specific healthcare professionals but not others, when they all work in a team, in the same healthcare institution. This is aligned with good practices we observed elsewhere, like in Australia.
Health information will be contributed to NEHR even if Access Restrictions are in place. As pointed out by Dr Hamid, who brings in a practitioner's perspective, an incomplete record, including if individuals opt not to contribute select healthcare information deemed to be more sensitive, will significantly reduce the utility of NEHR in supporting healthcare professionals to provide quality care and could pose a safety risk.
In certain situations, access to such records in a timely manner could save lives, as I mentioned earlier in my opening speech. One example would be when a doctor or pharmacist needs to have the ability to access drug interactions and his job is hindered due to incomplete medication information, the patient could suffer unintended consequences, especially in emergency situations when the patient may not be able to respond.
It also ensures that if patients change their mind in future, for instance, when they are older and remove such Access Restrictions, there would be no gap in NEHR information and this was a valuable learning point when MOH colleagues engaged other jurisdictions. The approach we are adopting aims to achieve a balance between patient choice and ensuring that patients receive better and more coordinated patient care.
Sir, in summary, healthcare providers would be granted access to NEHR to support patients' continuity of care across healthcare settings by default. Patients may, however, restrict access to all healthcare providers, or from the second half of 2026, limit access so that only select healthcare providers, such as their own Healthier SG clinic, may access their NEHR information. Whilst in place, restricted healthcare providers will not be able to, unless required by other written law, access the patient's NEHR information, except for the essential subset of records that cover allergies and vaccination records.
Next, I would like to also thank Members like Mr Yip, Mr Hoe, Mr Chua, Mr Fadli and Ms Kuah Boon Theng for highlighting the importance of educating the public on the implications of placing Access Restrictions and supporting patients who are less digitally savvy. We are likewise mindful of this point.
MOH will work with the healthcare institutions to set-up physical touchpoints for those who require help with placing Access Restrictions and help them understand the implications of doing so. Alternatively, patients may seek the help of trusted individuals, like their family members and caregivers to place Access Restrictions on their behalf.
Mr Yip raised the concern that the act of placing an Access Restriction may itself become a source of stigma or adverse inference. This Access Restriction will be known only to the healthcare providers managing the patient and all healthcare professionals are bound by their respective professional bodies' ethical codes and ethical guidelines to treat all patients fairly and without prejudice.
Let me now move to queries around NEHR access by insurers and employers. We understand Singaporeans' concerns about the potential discrimination or stigmatisation they may face if their health information is revealed to their employer or insurer. On this, I would like to reiterate three points that I have made earlier in my opening speech.
First, insurers and employers do not and will not have access to NEHR. Second, healthcare professionals are also prohibited from accessing NEHR for employment or insurance purposes, except for prescribed statutory medical examinations, which I will talk on later, or where authorised by other written law or Order of the Court. Third, the HIB imposes strict penalties for any unauthorised access to NEHR, with higher penalties for prohibited employment or insurance purposes.
Dr Wan Rizal asked whether statutory medical examinations may provide a backdoor for employers to gain access to NEHR information. The list of statutory medical examinations that is in the Bill is tightly scoped to those where NEHR access is necessary to protect the public and safeguard the health of the individual. This is the key principle.
We have no plans to expand this list to include employment-related screenings that are not necessary to protect the public and the individual. The current practice for employment-related screenings will remain – where doctors rely on their history-taking, clinical assessment and their own existing medical records for the individual, if any, without access to NEHR.
On Mr Yeo's query, on whether MOH would consider allowing individuals to give consent for their NEHR information to be accessed for insurance purposes for some situations, I would like to reiterate that NEHR is primarily for patient care purposes. When insurers request for health information, the current practice is for healthcare providers and professionals to rely on their medical records and patient interactions, which include history-taking, as well as physical examinations, to prepare the necessary reports for the insurer. This will continue to be the case after the HIB is enacted. NEHR must not be accessed for such insurance- and employment-related checks.
To Mr Tiong's query, healthcare providers and professionals should prepare separate medical reports, memos or clinical summaries for the insurer, instead of providing their raw medical records, such as printouts from their clinical medical records. This is because raw medical records contain extensive information, including potentially irrelevant information.
Where NEHR information is referred to during a medical examination, information relevant to the episode would be validated or confirmed with the patient during history taking and may be captured in the provider's own medical records, together with the doctor's clinical assessment. Such information would then be treated as part of the provider's own medical records. Healthcare providers and professionals will need to carefully assess what information in their own medical records is relevant and necessary to include in the report provided to an insurer.
MOH has issued a circular to healthcare providers and a guidance note to insurers to clearly state these positions. Healthcare providers may inform MOH if there are any inappropriate requests for NEHR information for insurance purposes.
Sir, let me now address questions about the contribution requirements in the Bill. Dr Haresh asked if mandatory contributions, coupled with access will encourage episodic care affecting initiatives, such as Healthier SG, which encourages building a trusted relationship between patients and their family doctors. Mr Hoe asked about the requirement to contribute information in a timely and accurate manner and the treatment of overseas medical records. Mr Fadli Fawzi asked about the level of details of key health information to be contributed to NEHR.
The Bill requires healthcare providers to contribute accurate and complete health information in a timely manner. This ultimately benefits patients by enabling their healthcare providers to access all relevant health information to provide the best care. Take a Healthier SG family doctor as an example. The bill will allow the doctor to deliver better patient care, taking account of the patient's medical history across different settings, including private specialist clinics.
This enables the doctor to build a trusted, and hopefully lifelong relationship towards better health outcomes. And to help healthcare providers comply with the contribution requirements in the Bill, we have whitelisted health information management systems (HIMS) that have the requisite technical features and encourage all healthcare providers to subscribe to these HIMS.
On overseas medical records, the HIB only applies within Singapore. Nevertheless, patients can bring their overseas health records to their local healthcare providers, who may then incorporate relevant information into their own medical records and once incorporated, these records will be contributed to NEHR.
To Dr Hamid's query on whether populations who receive care outside the conventional system, such as prison inmates, would benefit from the Bill, I would like to assure the Member that all Singaporeans key health information, including those under the care of the Singapore Prison Service, will be contributed to NEHR.
To Mr Fadli's query, NEHR is designed to be a "One Health Summary". We will only require the contribution of health information prescribed in the First Schedule of the Bill and not the doctor's detailed clinical notes. The design of the system and the data pipes take in only the prescribed data types.
For example, if a patient has diabetes and is prescribed with insulin, the doctor will only contribute "diabetes" as a diagnosis and "insulin" as the medication. So, only information that is needed for continuity of care.
Sir, let me now turn to Dr Choo Pei Ling's suggestion to extend NEHR access to other users, such as allied health professionals working outside of licensed institutions. I would like to thank Dr Choo for her suggestion to extend the access to other users. However, I would like to reiterate that the primary purpose of the NEHR is to support and enhance the continuity of care for patients. Hence, the HIB provides for NEHR access for licensed healthcare institutions. Within these institutions, NEHR access is only provided for healthcare professionals with clinical or care planning roles. This is the core principle governing NEHR access.
However, we recognise that as care models develop and evolve, we may need to grant new providers or services access to NEHR. In doing so, we will consider factors such as whether NEHR information is required for that role and whether the provider or service is able to comply with the HIB's requirements. Prior to changing the scope of providers that may access NEHR, we will consult relevant stakeholders and publicly communicate the changes through the MOH website.
Sir, Mr Louis Chua, Mr Yip and Mr Fadli Fawzi also asked about the sharing of NEHR information for non-patient care purposes under the HIB or other written laws such as the Criminal Procedure Code 2010.
NEHR was set up to facilitate patient care and the information within NEHR is primarily intended to be shared across healthcare providers for that purpose. This is a consistent principle adopted by other jurisdictions that we have studied.
MOH is of the view that identifiable health information should generally be interpreted and managed by qualified healthcare professionals. Parties from outside the healthcare sector generally do not require identifiable health information for non-healthcare-related purposes. Therefore, when parties seek MOH's views on this, MOH will suggest that such parties consider alternative data sources or ways of achieving its policy intent instead of using NEHR information or involve qualified healthcare professionals to partner parties in meeting the intent.
For public health purposes under the HIB, NEHR information may be needed in certain situations, for example, to quickly identify and enable healthcare providers to contact affected patients in the event of a major drug contamination incident. Another example is in the event of an outbreak of a serious infectious disease, there may not be sufficient time nor would it be feasible to seek consent from individuals to use their NEHR information to contain the outbreak. De-identified NEHR information may also be needed for public policy analysis and planning purposes, such as to review healthcare utilisation trends or to analyse the cost effectiveness of medicines.
I have given some examples to the queries raised by Members on the scenarios in which those clauses apply.
As a general rule, MOH will ensure requests for NEHR information have sound basis before supporting it. For all supported requests, whether from private entities such as academic institutions and health-related organisations or from public agencies under other written laws, MOH will share only the necessary data required to fulfil the intent.
Let me give another example to illustrate my point. For example, for requests from the Police to locate missing persons, we only provide administrative information about visits to healthcare providers without details of the patient's medical condition. This enables the Police to confirm if missing persons have been warded in an emergency and in turn alert worried family members. Requesting parties will also be required to protect the data against loss and against unauthorised access, use, modification, disclosure or other misuse.
Mr Chua and Mr Fadli asked specifically about the use of NEHR for research. De-identified NEHR health information may be shared through established platforms such as TRUST under the National Research Foundation for research purposes. This could include training for artificial intelligence models.
Where requests are received from commercial parties, possibly for commercial purposes, we are extremely cautious in assessing such requests, including whether the sharing of such data is helpful in contributing to better healthcare and better health outcomes. Primarily, NEHR is for continuity of care and for public health purposes, not for commercial purposes.
Mr Chua suggested allowing Access Restrictions to be applied to the sharing of NEHR information for broader public health interest purposes such as policy planning and analysis. This is not advisable as it could lead to incomplete analysis and would undermine the utility of NEHR informing national policies and planning.
Sir, now, let me turn to the third topic on resilience and security of the system.
A number of Members, including Mr Yip and Mr Dennis Tan asked about the resilience and security standards for NEHR, particularly in light of the SingHealth data breach in 2018. I would like to reassure Members that MOH has taken in the recommendations under the Public Sector Data Security Review Committee conducted in 2019. And NEHR is complying with the relevant resilience and security requirements for Government systems recommended by this committee. NEHR is subject to security and resilience audits, with vulnerability scans, penetration tests and exercises carried out regularly to ensure that systems are secure and backup systems are operational in the event of a downtime.
I must add that, really, the lesson from the SingHealth data breach is that we were open and transparent about the issue, convened a Committee of Inquiry, learned our lessons, applied them and made sure we work very hard to prevent such breaches from recurring. We took those lessons to heart as we built up our cybersecurity and data security standards. We have done so over the years.
Additionally, there are several lines of defence before the NEHR database, with intrusion detection at various parts of the network. Timely hardware, software and application upgrades are implemented, which include security patches as well as security controls to detect and block suspicious traffic from external sources.
MOH and Synapxe will continue to work with the Cyber Security Agency of Singapore, GovTech and independent auditing firms to conduct regular cybersecurity reviews and security assessments.
I would also like to thank Mr Yip for his feedback on the need to make NEHR more user-friendly. I assure him we will continue to invest in the improvement of NEHR's technology and features to help healthcare providers quickly identify the most relevant information for their patients.
Relatedly, Mr Yip, Dr Choo, Mr Hoe, Ms Joan Pereira and a number of Members like Mr Fadli Fawzi, Mr Tiong and Mr Dennis Tan asked for further details on the cybersecurity and incident management requirements, including their feasibility and the availability of MOH support.
Sir, I would like to clarify that today, healthcare providers are already required to make reasonable security arrangements to protect personal health information. This is an existing requirement in laws such as the Personal Data Protection Act and Healthcare Services Act 2020.
The Bill's cybersecurity and data security requirements are based on these existing standards and legal requirements, but contextualised for the healthcare sector. These include frameworks such as the Cyber Security Agency of Singapore's Cyber Essentials Mark and the Infocomm Media Development Authority's Data Protection Essentials, which were designed to be accessible and implementable by smaller organisations.
Examples of these requirements include the use of anti-malware solutions and firewalls in computers, the backing up of essential business information and data storage practices. Healthcare providers will also need to train their staff on cyber-hygiene and data governance practices to ensure safe and secure access to health information.
On the incident management framework, healthcare providers and their HIMS providers must put in place a framework to identify, resolve and mitigate cybersecurity and data breaches. This includes notifying MOH of prescribed security incidents and implementing mechanisms and processes to detect and respond to incidents such as ransomware attacks or unauthorised access to NEHR.
But even with the best preventive measures, a data breach may still occur. Healthcare providers will be required to notify MOH and affected individuals of significant data breaches. Once notified, MOH will work with the healthcare providers to understand the root cause of the breach, the extent of the data exposed, the potential harm to patients, and the containment and mitigation measures that need to be implemented.
In the event of any data breach, healthcare providers are expected to take necessary measures to remediate the situation and prevent such incidents from occurring again. Where MOH is of the view that the mitigation or preventive measures are inadequate, we will work with the healthcare providers on implementing the appropriate measures.
To Mr Fadli Fawzi's query on how significant harm will be defined, if a data breach causes or is likely to cause significant harm to an individual, for example, if it involves disclosure of health information that may be deemed more sensitive, healthcare providers must notify the affected individuals on or after notifying MOH.
Additionally, MOH will only require significant breaches to be notified in alignment with the approach under existing legal frameworks such as the PDPA. These details will be set out in subsidiary legislation.
Let me now turn to the support measures for healthcare providers. I appreciate the concerns that Members have raised about the support needed for smaller providers, especially smaller GP clinics. I mentioned earlier that with Healthier SG, most GP clinics have already onboarded to NEHR, with the support of MOH.
MOH recognises the importance of providing healthcare providers with reasonable time to comply with the HIB requirements and will offer the necessary support for healthcare providers to prepare and adapt their systems and processes. We see them as a valuable partner in supporting the continuity of care in the community.
Our support package will include measures to defray costs of subscription to whitelisted HIB-compliant HIMS to digitalise their clinical records and to contribute data to NEHR more seamlessly. There are also other support packages to engage professional services from whitelisted service providers to implement cyber and data security requirements.
Additionally, resources, guidance materials and training programmes will be available to help healthcare providers, including our community health partners, to meet the HIB cybersecurity and data protection requirements on an ongoing basis.
We would like to reassure providers that with this support in place, healthcare providers will be better enabled and supported to implement the relevant requirements.
We acknowledge the concerns raised by Mr Yip about potential fear-mongering tactics by some vendors. To address this, MOH is developing basic service packages specifically tailored to the needs of solo practitioners and small and medium enterprises so that they can self-help and prevent overselling of unnecessary services. We are also establishing clear guidelines for whitelisted service providers on appropriate engagement practices and transparent pricing. Healthcare providers that encounter unethical practices by whitelisted service providers can report them to MOH.
Additionally, we recognise that there is a small group of what Members call the pen-and-paper clinics that may face challenges in digitalising their clinics and meeting the Bill's requirements. As Members highlighted, these clinics may require additional implementation support.
Sir, digitalisation is becoming key to the provision of healthcare. It is critical for clinical documentation, transmission of information between providers and laboratories, and supports timely coordination with other providers.
Today, most clinics already have some form of IT system for clinic management, accounting and billing. Going forward, digital tools will increasingly become important, enabling clinics to rely on clinical decision support systems to close care gaps and deliver safer care. Therefore, in recent years, we have strengthened the digitalisation in the private primary care sector to support Healthier SG and other national initiatives.
Today, about 1,100 Healthier SG clinics are onboard suitable Clinic Management Systems and contribute to NEHR. Across the GP sector, more than 80% of them are on Clinic Management Systems. So, there are a large number of clinics, a vast number of them, already embarking on the digitalisation efforts. And we are supporting the remaining clinics to digitalise and onboard suitable systems to enable better delivery of care.
To Ms Joan Pereira's query if smaller clinics could collaborate on shared resources, this is a good idea for smaller clinics to explore. Currently, clinics can already join the Primary Care Networks (PCNs). PCNs not only provide peer leadership and support to small or solo GP practices, they also offer administrative assistance through the PCN headquarters. The PCNs will continue to offer advice and support to member clinics, share resources to smoothen the clinics' journey in digitalisation and fulfilling NEHR contribution. We will further consider Mr Dennis Tan's and Ms Pereira's suggestions on shared IT support services as part of the roll-out.
I would like to assure Members that MOH is mindful of the administrative effort required to contribute information to NEHR. And this is why we encourage all healthcare providers to adopt a whitelisted HIMS, which automates the process of contributing relevant health information to NEHR. That said, for smaller clinics that may require more time to digitalise, we will make available an alternative contribution channel so that these clinics will be able to start contributing data when required, while MOH continues to work with them on their digitalisation plans.
Ms Kuah reflected concerns from the ground about time and effort needed for compliance, and if MOH will take these considerations in event of non-compliance, especially in the initial period. MOH has worked closely with healthcare providers and professionals and have been engaging them over the last few years. We have taken their feedback on board.
First, the Bill will commence in early 2027 to allow sufficient time for healthcare providers and professionals to familiarise themselves with the Bill's requirements. Second, to support their transition, guidance materials and dedicated support channels will be made available from the second quarter of this year to help providers and professionals understand their options and navigate the process. Third, should there be challenges complying with the Bill by the required timelines, MOH will consider the facts of each case carefully and assist where appropriate.
Sir, now let me turn to the comments and suggestions for support for healthcare professionals.
Dr Hamid Razak and Dr Choo Pei Ling enquired about how MOH intends to support healthcare professionals, noting that they have concerns about increased liability arising from the HIB. I think Dr Haresh also pointed out concerns from healthcare professionals on medical and legal liabilities and how they should think about it.
We have been engaging the professional bodies and speaking to them over a period of time, and have taken their suggestions, ideas and feedback on board. MOH will publish a set of guidelines to support healthcare professionals' appropriate access and use of NEHR information. These guidelines will apply not only to doctors but also to other healthcare professionals accessing NEHR, such as dentists, nurses and allied health professionals. Let me share some examples of the guidance that will be provided.
Sir, healthcare professionals have asked whether they will be required to access NEHR for each consultation and whether they need to review each record in NEHR when they do access it.
Accessing patients' NEHR information is not compulsory under the HIB. NEHR supports and complements existing clinical practices, including good history-taking and physical examinations. The HIB does not change existing standards and practices. Healthcare professionals are encouraged to consider a range of factors before deciding whether NEHR access is required for a particular consultation, such as whether more information is required based on the information gleaned from the history-taking and physical examinations or whether health records in NEHR would be relevant to the particular consultation.
Sir, we will continue to work with respective professional bodies to disseminate these guidelines to all healthcare professionals. We will also support professional bodies in ensuring their members' compliance with the Bill. Sir, on this note, I would also like to take the opportunity to thank Ms Kuah for co-chairing the NEHR Guidelines Workgroup Committee.
Sir, let me now turn to health information that sits outside of NEHR and the clauses in the HIB that will enable the sharing of such information. Ms Pereira enquired about the timeline for enabling community health partners' sharing of such health information to be covered under the HIB. Mr Louis Chua asked why the HIB enables the sharing of non-NEHR health information without consent.
Today, AIC shares data with community partners to enable them to engage and provide befriending services or care to seniors. However, on the ground, there are difficulties with obtaining consent for data-sharing. Referencing my earlier example of Mr Lim, the 72-year-old gentlemen who is managing his diabetes condition. He stopped visiting his local polyclinic and his polyclinic has faced difficulties in contacting him to obtain consent. The HIB will address this by providing an additional channel for the sharing of health information.
With the HIB, Mr Lim's polyclinic can potentially share his contact information and broad health risk indicators, such as an indication of the presence of frailty or chronic conditions with AIC, without the details of specific medical conditions. AIC can then prioritise engaging Mr Lim to check on his well-being and link him with the necessary support as needed.
On whether to include other community health partners, like Active Ageing Centres and use cases in the future, MOH will carefully assess whether these other entities and use cases facilitate quality care and care continuity for patients. We will consider their readiness to meet the various responsibilities that come with sharing health information, such as cybersecurity and data security requirements under the Bill and we will consult key stakeholders.
Senior Minister of State Tan, if I could just ask you to hold on for a minute, because you have reached your time limit. So, Deputy Leader.