5 February 2025

Allen & Gledhill Partners Tham Hsu Hsien and Leong Yi-Ming contributed an article titled “Cybersecurity protection for private practice: A legal perspective” to SMA News, a publication of the Singapore Medical Association.

The proposed Health Information Bill will make it mandatory for all licensed healthcare providers, including private medical practices, to contribute data into the National Electronic Health Record (“NEHR”), and also provide them with access to patients’ summary medical records in the NEHR. This should improve healthcare delivery for patients, but the increased connectivity also increases the risk of cyberattacks. In addition, patient data are increasingly stored and used electronically across various medical and technological solutions and devices.

Data breaches involving patient data are serious events which may not only impact patient care, but also put patients at risk of targeted fraud, ransom, and scam attacks from threat actors. Ransomware attacks may even expose patients to injury through denial of healthcare. There are also business continuity and reputational concerns that doctors and private practices may face.

This article discusses some key considerations for private practices concerning cybersecurity protection and their legal implications.

© Singapore Medical Association. This article was originally published in SMA News 2024 November issue.

More