1. What counts as patient data
Most clinic owners picture the clinical records — diagnoses, prescriptions, scans. Those obviously count. But the PDPA covers any data about an identifiable individual, and in a clinic that net is far wider than the case notes.
It also includes:
- 1The appointment book and the sign-in sheet on the counter
- 2WhatsApp threads with patients, and photos sitting on a staff phone
- 3CCTV footage at reception
- 4The billing and debt-collection spreadsheet
- 5A Google review you replied to by name
- 6The CV of the locum who covered last Tuesday
2. The five duties you already have
These aren't optional extras you switch on when you get round to it. They apply to your clinic today.
- 1Consent & purpose. Collect only what you need, say what it's for, don't quietly reuse it. Treating someone is not the same as marketing to them — that's a separate consent.
- 2Protection. Make reasonable security arrangements. This is the duty breached most often, and it's usually something dull: a shared password, an open folder, a stale account.
- 3Retention. Don't keep it forever. MOH expects clinical records kept for a set period; the PDPA says stop holding data once the purpose has passed. You reconcile the two by writing the policy down.
- 4Accuracy. Keep it correct — a wrong allergy on a wrong record is both a data problem and a clinical one.
- 5Access & correction. A patient can ask what you hold and ask you to fix it. You need a way to answer that isn't "the doctor will look when he's free."
3. Do you actually need a DPO?
Yes. Every organisation in Singapore that handles personal data must appoint at least one Data Protection Officer and make their contact details publicly available. There is no small-clinic exemption. A single-doctor practice needs one exactly as much as a thirty-clinic chain.
What surprises people is how little the appointment itself involves — you can name someone today. The work is what makes it mean anything: knowing what data you hold, a written policy, a trained front desk, a way to answer an access request, and a plan for the day something leaks.
You can appoint internally, and many clinics do. The honest trade-off is that the named person is usually the practice manager, who already has a full job — so the role quietly becomes a title nobody has time for. That's the state that turns a small mistake into a published decision.
4. What actually gets clinics fined
Let's deal with the objection directly, because every clinic owner has it: does anyone actually get caught? Yes — and the decisions are published on the PDPC's own site with the organisation named.
- 1Fullerton Healthcare Group — S$58,000. A clinic chain. The breach was at its IT vendor, which left a drive open for around twenty months. The clinic group was fined more than the vendor was.
- 2Farrer Park Hospital — S$58,000. One email auto-forward rule exposed roughly 2,000 people. Not a hack — a setting nobody reviewed.
- 3Fei Fah Medical — S$5,000. A small operator with an unsecured website and weak password hashing; 900+ customers affected.
5. Your biggest risk isn't hackers
Look again at those three cases. One was a vendor. One was an email rule. One was an unpatched website. None was someone breaking through a firewall.
- 1Your practice-management system. Who has a login? Does the locum from March still? Can everyone see every record, or only what they need?
- 2Your vendors. The Fullerton lesson: you stay accountable for data your supplier holds. Their mistake becomes your decision notice.
- 3Staff phones. Patient photos and WhatsApp threads on a personal device that leaves the building every evening.
- 4The front desk. A screen angled at the queue, a sign-in sheet showing the last nine names, a full name called out in a small waiting room.
6. If it happens: the first 72 hours
Assume one day you'll get the call. What you do in the first few days decides whether it stays an incident or becomes a decision with your name on it.
The one-page clinic checklist
Print this page and go through it with whoever runs your front desk. Nothing here needs a consultant, a new system, or a budget — most of it is an afternoon's work. If you can tick every box, you are ahead of most clinics in Singapore.
Where this comes from
- Personal Data Protection Act 2012 — sso.agc.gov.sg
- PDPC Advisory Guidelines for the Healthcare Sector — pdpc.gov.sg
- PDPC data breach management guidance — pdpc.gov.sg
- Enforcement decisions cited above are published in full at pdpc.gov.sg/all-commissions-decisions
Or let someone else hold this
HeyAda acts as the outsourced DPO for Singapore clinics — the appointment, the policy, the staff training, the annual review, and someone to call when a patient asks a question you'd rather not guess at. No lock-in.
See how it works →This guide is general information about the PDPA, not legal advice.
If you'd rather not hold this yourself
Singapore law says your clinic must appoint a Data Protection Officer. It doesn't say it has to be someone who already has a full-time job running your practice.
HeyAda acts as the outsourced DPO for Singapore clinics — the appointment, the written policy, the staff training, the annual review, and someone to call when a patient asks a question you'd rather not guess at. No lock-in.
Tell me what system you use and how many staff have a login, and I'll tell you honestly whether you have a problem worth paying to fix.
heyada.io/dpo — what the service covers and what it costs
HeyAda Pte. Ltd. · UEN 202602669E · Singapore