Privacy Trust

Protecting Privacy Build Trust
        • Enhance your cybersecurity posture and safeguard your digital assets with our comprehensive Managed Security Service. Our team of experts is dedicated to monitoring, detecting, and responding to threats, so you can focus on growing your business with confidence.


          Ensure the security of your organization's endpoints with our Managed Endpoint Security Service. Safeguard against cyber threats and vulnerabilities to maintain business continuity and protect sensitive data.


          Protecting your organization's data is crucial in today's digital landscape. With DPO-as-a-Service, ensure compliance with data protection regulations without the overhead of hiring a full-time Data Protection Officer.

          Empowering Your Journey to Data Protection Achieving PDPA compliance isn't just about meeting regulations; it's about building trust. Our services help you navigate data protection with confidence.


          Elevate Your Brand with Data Protection Trustmark Certification Achieve international recognition and solidify customer trust with PrivacyTrust's Data Protection Trustmark Certification Service.


          Discover how our comprehensive data protection training can help your organization comply with the Singapore Personal Data Protection Act (PDPA) and safeguard sensitive information.

          Discover how our Vulnerability Assessment and Security Audit Service can fortify your organization's defenses against potential cyber attacks.


          Discover and address vulnerabilities in your networks, applications, and websites with our comprehensive penetration testing services.


          Equip your team to defend against evolving threats and safeguard your organization's assets. Our comprehensive cybersecurity training programs offer tailored solutions to address your workforce's diverse needs.


          Conducting DPIAs is crucial for safeguarding sensitive data and ensuring compliance with evolving privacy regulations. Our tailored solutions help you identify, assess, and mitigate privacy risks, paving the way for responsible data handling and building trust.

        • Protect your sensitive information from breaches and cyber threats. Ensure compliance with global privacy regulations and foster trust with your customers through our advanced security practices and innovative technologies


          Empower your organization with robust data privacy solutions that go beyond compliance. Transform privacy into a strategic asset that drives business value and fosters trust.


          Safeguard your business from insider threats with PrivacyTrust's comprehensive security solutions. Detect, prevent, and mitigate internal risks to maintain data integrity and business continuity.


          Dive Into Data Security with PrivacyTrust Backup Solutions

          Stay ahead of today's advanced email attacks Protect your business's email from modern threats.


          Secure your mobile devices and applications against threats with our mobile security solutions.


          Break free from the cycle of cyber threats and safeguard your business reputation. Discover how our Phishing Attack Protection Solutions can help you stay one step ahead of cybercriminals.


          Protect Your Business Against Ransomware Threats Safeguard Your Data, Secure Your Future.


          Embrace proactive cybersecurity measures and stay one step ahead of cybercriminals. Secure your endpoints today to safeguard your business from evolving cyber threats and maintain uninterrupted operations.

  • Contact Us

Industry Insight

Privacy

Key Provisions of the Health Information Bill: Enhancing the National Electronic Health Record (NEHR) 

The Health Information Bill (HIB) introduces significant changes to how health information is collected, accessed, and shared in Singapore. A central component of this bill is the National Electronic Health Record (NEHR), a secure, centralized repository established in 2011 to streamline health information management across public and private healthcare institutions. 

Mandating Data Contributions

Under the new bill, all healthcare providers licensed under the Healthcare Services Act (HCSA) are required to contribute selected health information to the NEHR. This mandate also extends to other approved contributors, such as retail pharmacists, who will be required to provide specific types of health data to enhance the completeness of the NEHR. 

Types of Health Information Required

Only certain types of health information will be mandated for contribution to the NEHR. This includes: 

  • Patient Demographics: Basic personal details like name, address, and contact information. 

  • Visits: Records of hospital admissions, general practitioner visits, and other healthcare interactions. 

  • Medical Diagnoses and Allergies: Information on patient diagnoses and known allergies. 

  • Medical Procedures and Treatments: Details of surgeries, treatments, and other procedures performed. 

  • Discharge Summaries: Summaries provided upon a patient’s discharge from a healthcare facility. 

  • Medications: Information about prescribed medications. 

  • Investigation Reports: Results of laboratory tests and radiological investigations, such as X-rays. 

Exclusions and Considerations

Detailed clinical notes and day-to-day progress reports are not required to be contributed to the NEHR. This decision is based on the need to keep the system user-friendly and relevant. Healthcare providers will only need to contribute information generated during their interactions with patients. For instance, a general practitioner (GP) who does not prescribe medication does not need to enter prescription data. Similarly, if a clinical laboratory conducts a test, the lab, not the referring GP, is responsible for contributing the test results to the NEHR. 

Certain groups, like short-term visit pass holders, are excluded from the data submission requirements. These individuals, such as tourists receiving temporary care, do not benefit significantly from long-term data storage in the NEHR, making the cost of inclusion outweigh the potential benefits. 

Regulating Access to the NEHR

A. Controlled Access for Healthcare Providers

Access to the NEHR is strictly regulated under the new bill. Healthcare licensees and approved users must obtain authorization from the Ministry of Health (MOH) to access the system. Licensees are typically granted access through their HCSA license, while non-HCSA licensees must apply separately to the MOH. 

B. Purpose-Based Access

Access to patient records in the NEHR is limited to direct patient care or other uses explicitly authorized by the Minister for Health. These purposes can include clinical care, administrative tasks directly related to patient care (like scheduling appointments or arranging transfers), or statutory requirements under other laws (such as medical examinations related to the Enlistment Act). 

To protect patient privacy and autonomy, even authorized healthcare providers cannot access records for individuals who have restricted access to their data unless they have obtained explicit consent from the patient. 

Conclusion

The Health Information Bill represents a transformative approach to managing health data in Singapore. By mandating contributions to the NEHR and regulating access, the bill aims to create a comprehensive, secure, and accessible health information system that benefits both patients and healthcare providers. 

Are you prepared for the changes introduced by the Health Information Bill? Ensure your organization is compliant and ready to leverage the NEHR by staying informed about these new regulations and provisions. 

Get a free HIB assessment today to ensure you’re compliant with the latest cybersecurity standards and protect your patients’ data effectively. Contact our experts now!