Skip to content

Resource · Compliance

PDPA for Healthcare: What a Singapore Clinic Must Do

How the PDPA applies to a Singapore clinic: the obligations that matter, the 3-day data-breach rule, what a breach can cost, and how it sits alongside the HIA. Sourced from PDPC.

The PDPA is the data-protection law that already applies to your clinic today, long before your HIA deadline, and its headline duty is the 3-day data-breach rule. This page covers what the PDPA asks of a clinic, what a breach can cost, and how it fits alongside the HIA.

The 30-second version:

The PDPA (enforced by the PDPC) is Singapore’s general data-protection law, which applies to every clinic now. Its most-searched obligation is the breach rule: assess a suspected breach within 30 days, and once you decide it’s notifiable, tell the PDPC within 3 calendar days. The HIA layers health-sector duties on top; it does not replace the PDPA.

Want the health-sector picture first? Read the pillar: Health Information Act (HIA): What It Means for Your Clinic


PDPA vs HIA: two laws, one clinic

Clinics often ask whether the HIA replaces the PDPA. It doesn’t - they stack:

  • The PDPA is the general law for personal data. It applies to almost every organisation in Singapore, including your clinic, right now. The regulator is the Personal Data Protection Commission (PDPC).
  • The HIA is a sector-specific layer for health information - NEHR contribution and the cybersecurity & data security (CS/DS) Essentials - phased in by service type from 2027. The regulator is MOH (with Synapxe on the technical side).

So a clinic answers to both: the PDPA for how it handles personal data generally, and the HIA for the health-specific duties on top. The good news, covered below, is that the work overlaps - doing the HIA security work also satisfies much of the PDPA.

PDPC also publishes Advisory Guidelines for the Healthcare Sector, which interpret the PDPA specifically for clinics and hospitals - a useful companion to MOH’s HIA guidance.


The PDPA obligations that matter most for a clinic

The PDPA sets out a set of data-protection obligations. These are the ones a clinic touches every day:

  • Consent & Purpose - collect, use or disclose patient data only for purposes a reasonable person would consider appropriate, and that you’ve notified the patient about.
  • Notification - tell patients why you’re collecting their data.
  • Access & Correction - on request, give a patient access to their data and correct errors as soon as practicable.
  • Accuracy - make a reasonable effort to keep patient data accurate and complete.
  • Protection - put in place reasonable security to guard data against unauthorised access, loss or leakage. This is the one that overlaps most with the HIA’s CS/DS Essentials.
  • Retention Limitation - stop retaining data once the purpose is served and there’s no legal need to keep it.
  • Transfer Limitation - if you send data overseas (e.g. a cloud provider), ensure comparable protection.
  • Data Breach Notification - assess and report notifiable breaches (the 3-day rule below).

For a clinic, patient medical records are among the most sensitive personal data there is, which raises the stakes on the Protection and Breach obligations in particular.


The 3-day breach rule (the one everyone searches)

Since 1 February 2021, breach notification is mandatory under the PDPA. It’s a two-clock process, and clinics often confuse the two:

  1. Assess - within 30 calendar days. When you become aware of a suspected breach, you must assess whether it’s notifiable in a reasonable and expeditious manner. PDPC expects that assessment to be completed within 30 calendar days; document the steps you take, and be ready to explain any delay.
  2. Notify the PDPC - within 3 calendar days. Once you determine a breach is notifiable, you must notify the PDPC as soon as practicable and no later than 3 calendar days. This is the “3-day rule.”
  3. Notify affected individuals - as soon as practicable. Tell the affected patients at the same time as, or after, notifying the PDPC (for breaches likely to draw public attention, notify the PDPC first).

When is a breach “notifiable”?

A breach must be reported if it meets either test:

  • Significant harm - it’s likely to cause significant harm to the affected individuals, or
  • Significant scale - it affects 500 or more individuals.

Here’s the part that matters for a clinic: health and medical data is treated as sensitive, so a breach of patient records can cross the significant-harm limb even if fewer than 500 patients are affected. A clinic shouldn’t assume “only a handful of records” means “no need to report.”


What a PDPA breach can cost

The PDPA’s financial penalties were raised on 1 October 2022. The maximum is now:

  • Up to 10% of the organisation’s annual turnover in Singapore - for organisations with local annual turnover above S$10 million, or
  • S$1 million - whichever is higher.

For a typical independent clinic with turnover under S$10 million, the effective cap is S$1 million. That’s the ceiling, not the going rate - actual penalties depend on the facts - but it signals how seriously the PDPC treats a breach. On top of the financial penalty, the PDPC can issue directions (e.g. to fix your security, stop a practice, or destroy data), and there’s the reputational cost of a public enforcement decision.

The practical takeaway: the cheapest breach is the one you prevent, and the second-cheapest is the one you assess and report correctly.


How HIA readiness makes you PDPA-ready

This is where the two laws work in your favour. The HIA’s CS/DS Essentials - access controls, backups, patching, incident response, staff training - are almost exactly what the PDPA’s Protection Obligation asks for. Do the HIA security work and you’ve covered most of your PDPA security duty at the same time.

Two things to keep in mind:

  • It’s a head start, not a full tick. The PDPA also covers consent, purpose, access and correction, retention and breach notification - areas the HIA security work doesn’t touch. Treat HIA readiness as covering the security slice of the PDPA, not all of it.
  • A certified HIMS helps both. A Synapxe-certified clinic system is built to meet the CS/DS Essentials, which means it also carries much of the PDPA Protection Obligation for you - one system, two laws satisfied.

If you’re working through HIA readiness anyway, you’re already doing most of the PDPA’s heavy lifting. See the HIA compliance checklist for the security steps, and the cost of HIA compliance for how the grants fund that work.


What to do now

  • Appoint a data protection officer (DPO). Every organisation must designate one - it can be an existing staff member, and their contact must be made available.
  • Write a simple breach-response plan. Who assesses, who notifies, and the two clocks (30-day assess, 3-day notify). A breach is not the time to work out the process.
  • Tighten the Protection basics. Unique logins, 2FA for admin/remote access, backups, patching, staff training - the same list as the CS/DS Essentials.
  • Check retention and transfers. Don’t keep records longer than needed, and confirm any overseas/cloud provider gives comparable protection.
  • Fold PDPA into your HIA plan. You’re already doing the security work for the HIA - line up the PDPA obligations against it so nothing falls through the gap.

Next steps

The PDPA applies now; the HIA is coming on your service type’s timeline. Handle them together. Start with the HIA compliance checklist to see where your security stands, or read the HIA pillar for the full health-sector picture.

Want a single path that gets your clinic’s system and security in order, covering the HIA duties and most of the PDPA’s Protection Obligation at once? See how that works →


Official sources: pdpc.gov.sg ↗ (PDPC) · healthinfo.gov.sg ↗ (MOH) · Synapxe NEHR.

This article summarises the PDPA and PDPC guidance for general information only; it is not legal advice. Obligations, thresholds and penalties are set by the PDPC and may change - verify at pdpc.gov.sg before acting.

Questions

Frequently asked questions

Get your clinic HIA-ready

Book a free consultation and we'll map the simplest path to compliance.