Being HIA-ready comes down to four things: a certified clinic system, the cybersecurity Essentials in place, the grant claimed, and NEHR onboarding done - all before your deadline. This is the working checklist to get there, in the order that matters.
The 30-second version:
The steps below stack, so the one thing that matters is starting early - you can’t onboard to NEHR until your system is certified and your security gaps are closed, and the grant window closes before your contribution deadline (31 August 2027 for GPs, ahead of the 1 September 2027 go-live).
Need the background first? Start with the pillar: Health Information Act (HIA): What It Means for Your Clinic
1. Confirm your deadline and scope
- Find your service type’s deadline. GP / Outpatient Medical clinics are Batch 1 and must contribute to NEHR by 1 September 2027. Other types run to 2028 or 2030 - see the full table by service type or the visual timeline by clinic type.
- Confirm you’re in scope. In-scope HCSA-licensed providers must comply regardless of clinic size.
- Note your grant window. For GP clinics the NEHR Connect Grant opens 1 July 2026 and its application deadline is 31 August 2027 - just before the 1 September 2027 contribution deadline. Treat the grant deadline as your real cut-off, since late applications are rejected.
2. Check your clinic system (HIMS)
A clinic system can contribute to NEHR only if Synapxe has certified it as HIA-compliant. It needs all three:
- ✓ NEHR Connectivity certification - completed
- ✓ Cyber Essentials (CE) Mark or equivalent - held
- ✓ Code of Practice for Data Portability - compliance declared
The fastest check is whether your provider appears on the Synapxe certified HIMS list ↗.
- If all three are ticked: your system looks HIA-ready - proceed to onboarding.
- If any are missing: decide whether to wait (ask your provider’s certification timeline), switch (move to a certified system with a written data-migration plan from both providers), or enhance (contact Synapxe’s vendor team for a custom-built system). The pillar walks through this decision.
3. Close the cybersecurity & data security (CS/DS) gaps
MOH published the CS/DS Essentials in March 2026, and they apply even to providers not contributing to NEHR. Work through them:
Cybersecurity Essentials
- Control access - unique accounts per user, remove inactive/shared accounts, strong passwords (≥12 mixed characters), 2FA for admin/remote access.
- Update promptly - patch your OS, applications and clinic system (CMS/EMR); prioritise security patches.
- Protect devices - anti-malware with automatic signature updates and scanning.
- Connect safely - firewalls, trusted networks only, apps from trusted sources.
- Ensure backups - regular backups of critical data, stored separately, aligned to your recovery needs.
- Manage IT assets - keep a hardware/software inventory and replace unsupported assets.
Data security Essentials
- Store, transfer & copy securely - access-controlled storage, password-protected email (send the password separately), copies only by authorised staff.
- Limit access to need-to-know - staff access only patients under their care, and acknowledge their data-protection obligations before access.
Common Essentials
- Train personnel - annual CS/DS training and basic security hygiene.
- Incident response - defined roles; detect, respond and recover; notify affected persons and regulators. The HIA sets its own clock for notifiable incidents: notify MOH within 2 hours of confirming the incident, then a full incident report within 14 days, and notify affected individuals if significant harm is likely (MOH’s reporting framework launches in 2027). This sits on top of the PDPA’s 3-day breach rule - see CS/DS Essentials explained for the detail.
- Plus: business continuity, secure disposal, third-party (vendor) management, and periodic security review.
Working toward the Cyber Essentials (CE) Mark is the practical way to evidence most of these at once - see CS/DS Essentials & the Cyber Essentials Mark, explained for how it works and what it costs.
Don’t want to assemble the security piece yourself? This is where OtterSG’s partnership with Contfinity comes in. OtterSG provides the NEHR-ready clinic system; Contfinity is our cybersecurity partner, handling data security, IT protection and CISO-as-a-Service - the very controls in this section. Together they cover both sides of HIA compliance as one programme, so you close these CS/DS gaps with one partner and one point of contact instead of stitching vendors together. See how OtterSG × Contfinity works →
4. Claim the grants
HIA readiness has two cost buckets - the system, and the security work - and each has its own funding:
- NEHR Connect Grant (NCG) - covers the clinic system; a fixed S$8,400 for GP clinics. Select a certified HIMS first, then apply through the OurSG Grants Portal. See the step-by-step grant guide.
- CISOaaS (CSA, up to 70%) - security consultancy.
- PSG (EnterpriseSG, 50%, cap S$30k) - security tools; for SMEs (business in Singapore with ≤S$100m turnover or ≤200 employees), which most GP clinics are.
- TSS Part C (80%, cap S$40k) - consultancy + certification fees, but only for Members of the National Council of Social Service (NCSS) (community-care organisations such as nursing homes) - most GP clinics don’t qualify.
Apply before your deadline because late applications are rejected. For what all this actually costs, including the recurring year-3 cost once the grant is used, see Cost of HIA compliance.
5. Onboard to NEHR and go live
- Schedule onboarding early. It takes up to five weeks with your provider, including drug-inventory mapping and deployment scheduling.
- Meet the data-quality standards for the records you contribute.
- Confirm you’re live and contributing ahead of your deadline, not on it.
Next steps
Not sure where your clinic stands? Take the guided self-check and get help closing the gaps: Is my clinic HIA-ready? →
Official sources: healthinfo.gov.sg ↗ (MOH) · Synapxe NEHR.
This checklist summarises MOH’s HIA Implementation Guide for general information only; it is not legal advice and does not replace the official guidance. Requirements, dates and amounts are set by MOH and may change - verify at healthinfo.gov.sg before acting.