← Insights Say hi 👋
HeyAda
A free guide for Singapore clinic owners

Patient data: what a clinic actually has to do

The PDPA in plain English. What counts as patient data, the five duties you already have, whether you really need a DPO, what actually gets clinics fined — and what to do in the first 72 hours if something goes wrong.

Written by Eugene Teo, HeyAda
Published 22 August 2026
heyada.io/guides/patient-data

General information about the PDPA, not legal advice.
Free guide · Data protection

Patient data: what a clinic actually has to do

The short version

Every clinic in Singapore must appoint a DPO — there's no small-clinic exemption. Beyond that you have five duties that already apply today, whether anyone has told you or not. Most clinics that get fined weren't hacked: it was a vendor, an email rule, or a stale login. Fines mostly land between S$5,000 and S$58,000 — but the decision is published with your clinic's name on it, and that lasts longer than the fine.

Want it as a PDF?

The whole guide as a designed PDF — including the one-page clinic checklist you can print and go through with your front desk.

We ask for consent separately, say what it's for, and let you withdraw it. That's the PDPA standard — and the same one we set up for the clinics we act as DPO for.

1. What counts as patient data

Most clinic owners picture the clinical records — diagnoses, prescriptions, scans. Those obviously count. But the PDPA covers any data about an identifiable individual, and in a clinic that net is far wider than the case notes.

It also includes:

The one that catches people out: health data is treated as sensitive. At breach time a health-data leak can trigger mandatory notification even when fewer than 500 people are affected — the test is whether it's likely to cause significant harm, not how many records were lost.

2. The five duties you already have

These aren't optional extras you switch on when you get round to it. They apply to your clinic today.

3. Do you actually need a DPO?

Yes. Every organisation in Singapore that handles personal data must appoint at least one Data Protection Officer and make their contact details publicly available. There is no small-clinic exemption. A single-doctor practice needs one exactly as much as a thirty-clinic chain.

What surprises people is how little the appointment itself involves — you can name someone today. The work is what makes it mean anything: knowing what data you hold, a written policy, a trained front desk, a way to answer an access request, and a plan for the day something leaks.

You can appoint internally, and many clinics do. The honest trade-off is that the named person is usually the practice manager, who already has a full job — so the role quietly becomes a title nobody has time for. That's the state that turns a small mistake into a published decision.

4. What actually gets clinics fined

Let's deal with the objection directly, because every clinic owner has it: does anyone actually get caught? Yes — and the decisions are published on the PDPC's own site with the organisation named.

Being straight with you: healthcare fines here mostly land between S$5,000 and S$58,000 — not the millions you see in headlines, and several cases end in a warning with no fine at all. So the real reason to care isn't the money. It's that the decision is published, with your clinic's name on it, and stays searchable long after the fine is paid. Patients read it.

5. Your biggest risk isn't hackers

Look again at those three cases. One was a vendor. One was an email rule. One was an unpatched website. None was someone breaking through a firewall.

Who can see what in a clinic system A permission grid. Front desk sees appointments, contact details and billing but not clinical notes. Nurse sees appointments, contact and notes. Doctor sees everything. A locum whose last shift has ended should see nothing, but often still can. Appointments Contact Clinical notes Billing Front desk Nurse Doctor Locum, last shift was in March Should have none
Everyone can see something. Almost nobody needs to see everything — and the account you forgot to close still sees all of it.

6. If it happens: the first 72 hours

Assume one day you'll get the call. What you do in the first few days decides whether it stays an incident or becomes a decision with your name on it.

What to do in the first 72 hours of a data breach Four steps: contain it immediately, assess whether it is notifiable, notify the PDPC within three calendar days of that assessment and tell the people affected, and document what you did throughout. 1 Contain it Revoke the access. Take the page down. Stop the rule. Straight away — before you understand it fully 2 Assess whether it's notifiable Significant harm, or scale. For health data the harm test usually gets there first. This assessment starts the clock 3 Notify The PDPC, and the people affected. Within 3 calendar days 4 Write down what you did A clinic that responded properly is treated very differently from one that can't say what happened.
The three days run from the moment you decide it's notifiable — not from the moment you finish fixing it.

The one-page clinic checklist

Print this page and go through it with whoever runs your front desk. Nothing here needs a consultant, a new system, or a budget — most of it is an afternoon's work. If you can tick every box, you are ahead of most clinics in Singapore.

If most boxes are blank, don't panic. Nearly every clinic starts here. Work down the list in order — the front desk and the logins are where the real risk sits, and both are free to fix.
At the front desk
Logins and access
Phones and devices
The people who hold your data
Consent and requests
If something goes wrong

Where this comes from

Or let someone else hold this

HeyAda acts as the outsourced DPO for Singapore clinics — the appointment, the policy, the staff training, the annual review, and someone to call when a patient asks a question you'd rather not guess at. No lock-in.

See how it works →

This guide is general information about the PDPA, not legal advice.

If you'd rather not hold this yourself

Singapore law says your clinic must appoint a Data Protection Officer. It doesn't say it has to be someone who already has a full-time job running your practice.

HeyAda acts as the outsourced DPO for Singapore clinics — the appointment, the written policy, the staff training, the annual review, and someone to call when a patient asks a question you'd rather not guess at. No lock-in.

Talk it through — no charge, no pitch
Tell me what system you use and how many staff have a login, and I'll tell you honestly whether you have a problem worth paying to fix.