Skip to content

Resource · Compliance

CS/DS Essentials & the Cyber Essentials Mark, Explained for Clinics

What the HIA's cybersecurity & data security (CS/DS) Essentials require of a Singapore clinic, how the Cyber Essentials Mark fits, who must comply by when, and what it costs after grants. Sourced from MOH.

The CS/DS Essentials are the HIA’s baseline security requirements for your clinic, and the Cyber Essentials Mark is the recognised way to prove you meet them. This page explains what the Essentials cover, who must comply and by when, how the Cyber Essentials Mark fits, and what it costs once the grants are applied.

The 30-second version:

The CS/DS (cybersecurity & data security) Essentials are the security measures the HIA requires of clinics - published by MOH in March 2026. Meeting them is the requirement; achieving the Cyber Essentials Mark (a CSA certification) is the practical way to evidence them, and it’s what the security grants fund. They apply even to clinics that won’t contribute to NEHR - by September 2028 for those providers.

Want the full HIA picture first? Read the pillar: Health Information Act (HIA): What It Means for Your Clinic


What the CS/DS Essentials are

The CS/DS Essentials are a baseline set of security controls MOH expects every in-scope clinic to have in place. They come in three groups:

  • Cybersecurity Essentials - the technical basics: access control (unique logins, 2FA for admin/remote access), prompt patching, anti-malware, safe networks and firewalls, regular backups stored separately, and an IT asset inventory.
  • Data Security Essentials - protecting the data itself: identifying and securing health information (including retention periods), labelling it so staff handle it correctly, secure transfer (e.g. password-protected email with the password sent separately), and limiting access to a need-to-know basis.
  • Common Essentials - the organisational side: annual staff training, an incident-response plan, business continuity, secure disposal, third-party (vendor) management, and periodic security review.

This page explains the shape of the requirement; for the full item-by-item working list you can tick off, use the HIA compliance checklist.


Who must comply, and by when

Two points catch clinics out here:

  • It’s not only for NEHR contributors. The headline HIA duty is contributing records to NEHR, but the CS/DS Essentials apply more broadly. In-scope providers that won’t contribute to NEHR must still implement the CS/DS measures - by September 2028.
  • The deadline follows your service type. For clinics that do contribute to NEHR, the security work has to be done ahead of your contribution deadline (1 September 2027 for GP clinics). You can’t onboard to NEHR with open security gaps. See the deadline by clinic type.

So “we’re a small clinic” or “we’re not on NEHR yet” doesn’t remove the obligation - it only changes the date.


CS/DS Essentials vs the Cyber Essentials Mark

These two terms get used interchangeably, but they’re not the same thing:

  • The CS/DS Essentials are what you must do - the controls above.
  • The Cyber Essentials Mark is a national cybersecurity certification from the Cyber Security Agency of Singapore (CSA), aimed at SMEs and valid for two years, assessed by a CSA-appointed certification body.

Here’s the nuance MOH’s guidance makes explicit. MOH worked with HIMS vendors to embed key cybersecurity controls - prompt updates, two-factor authentication for system-configuration changes, secure configuration, and protected backups - into their systems; vendors that do so are Cyber Essentials (CE) certified. So a CE-certified clinic system carries part of the cybersecurity Essentials for you, and holding the CE Mark (or equivalent) is also one of the three criteria Synapxe checks before certifying a system for NEHR.

But MOH is equally clear that implementation in your other IT is still required, and that the data-security and common practices - marking data, need-to-know access, staff training, vendor management, incident response - remain your clinic’s own responsibility. Don’t assume a certified system means your clinic is automatically covered; most of the Essentials are organisational and can’t be delivered by any software.


What the Cyber Essentials Mark costs (and the grants that cover it)

This is the question most clinics search for, and the honest answer is: there’s no single fixed price. The certification fee is set by the appointed certification body and varies. But the fee is the small part - the real cost is the preparation work, and that’s grant-funded:

  • CISOaaS (CSA, up to 70%) - funds the security consultants who help you close gaps and prepare for certification.
  • PSG (EnterpriseSG, 50%, cap S$30k) - funds the security tools (firewalls, anti-malware, and similar). PSG is for SMEs - a business in Singapore with ≤S$100m turnover or ≤200 employees, which most GP clinics are.

For NCSS community-care members (e.g. nursing homes), a third scheme, TSS Part C (80%, cap S$40k), applies, but a commercial GP clinic doesn’t qualify, so plan around CISOaaS and PSG.

Watch the renewal. The Cyber Essentials Mark is valid for two years, then must be renewed. The grants above help most with the initial certification push, so treat CS/DS - the certification and the tools behind it - as a recurring cost, not a one-off. The cost of HIA compliance breaks down what stays on your books over time.


How your clinic gets certified

The practical path, in order:

  1. Assess your gaps against the CS/DS Essentials (use the checklist).
  2. Tap CISOaaS for consultant help to close the gaps, and PSG for the tools you need.
  3. Get assessed by an appointed certification body for the Cyber Essentials Mark.
  4. Keep it current - review your controls periodically and renew the mark before it lapses.

Starting early matters: the certification is only meaningful once the underlying controls are actually in place, and NEHR onboarding can’t begin until your security gaps are closed.


The HIA’s own incident-reporting clock

Incident response is one of the Common Essentials, and the HIA attaches its own reporting timeline to it - separate from, and tighter than, the PDPA’s. Once you confirm a cybersecurity incident or data breach (i.e. there’s reasonable evidence it has occurred - your IT provider confirms a compromise, or you see clear signs of malware, unauthorised access or system damage), you must:

  • Notify MOH within 2 hours of that confirmation (an initial notification), then
  • Submit an incident report within 14 days of the initial notification, and
  • Notify affected individuals at the same time as, or as soon as practicable after, MOH if the incident is likely to cause significant harm.

The notifiable threshold mirrors the PDPA’s: likely significant harm to an individual, or significant scale (500 or more individuals), and separately you notify the PDPC within 72 hours and the police as soon as possible for cybercrime such as ransomware. This HIA clock sits on top of the PDPA’s own breach-notification duty - see PDPA for healthcare for that regime. MOH’s incident-reporting framework (and the reporting form) is set to launch in 2027, so build the capability now and watch for the go-live.


How this overlaps with the PDPA

The good news is you’re not doing this work only for the HIA. The CS/DS Essentials map almost one-to-one onto the PDPA’s Protection Obligation, which already applies to your clinic today. Closing your CS/DS gaps also satisfies most of your PDPA security duty at the same time - see PDPA for healthcare for how the two laws stack.


Next steps

Meeting the CS/DS Essentials is one of the two big buckets of HIA readiness (the other is a certified clinic system). Work through the HIA compliance checklist to see where your security stands, and the cost of HIA compliance for what it adds up to after grants.

Prefer not to assemble the security piece yourself? OtterSG delivers an HIA-compliant HIMS, and our cybersecurity partner Contfinity handles the CS/DS side - data security, IT protection and CISO-as-a-Service, so your clinic meets the CS/DS Essentials and qualifies for the grants, with one partner and one point of contact. See how OtterSG × Contfinity works →


Official sources: healthinfo.gov.sg ↗ (MOH) · Cyber Security Agency of Singapore (CSA) · Synapxe NEHR.

This page summarises MOH’s HIA Implementation Guide and the CS/DS Essentials for general information only; it is not legal or security advice. Requirements, schemes and amounts are set by the government and may change - verify at healthinfo.gov.sg before acting.

Questions

Frequently asked questions

Get your clinic HIA-ready

Book a free consultation and we'll map the simplest path to compliance.