If you run a GP, dental, TCM, physio or aesthetic clinic, chances are you're already messaging patients on WhatsApp β it's fast and everyone uses it. That's fine. You just want to do it in a way that doesn't quietly put your clinic on the hook. Let's keep it plain.
Reminders and care messages β generally fine
When a patient gives you their number to book an appointment, using it to remind them of that appointment, confirm a reschedule, or send a simple care instruction is generally okay under the PDPA. It's the reason they gave you the number, and it's what they expect. You don't need a special extra consent for the ordinary business of running their appointment. Keep those messages to what the patient would reasonably expect, and you're on safe ground.
Marketing blasts are a different thing β you need express consent
A patient giving you their number for appointments is not the same as them agreeing to receive promotions. The moment you want to send marketing β a package promo, a new-treatment blast, a festive offer β that needs separate, express consent. "They're already my patient" doesn't count. On top of that, Singapore's Do Not Call (DNC) rules apply to marketing sent by SMS and phone calls, so if you also blast those channels, you have to check the DNC registry first. The safe habit: treat marketing as its own opt-in, separate from care messages. (More on this in our guide to consent and marketing.)
The big gap: staff using their own personal phones
This is the one most clinics miss, and it's the one that actually bites. When a receptionist or assistant messages patients from their own personal WhatsApp, three quiet problems appear:
- 1You're still accountable. The clinic is responsible for that patient data under the PDPA β even though it's sitting on a phone you don't own and can't see.
- 2It lives outside your control. The chats, the numbers, the photos β none of it is in your clinic system. You can't audit it, back it up, or lock it down.
- 3It walks out the door. When that staff member leaves, the patient conversations β and their contact details β leave with them, still on their personal phone.
None of this is about distrusting your team. It's just that personal phones were never set up to hold your clinic's patient data β so the data ends up somewhere you can't protect it.
The fix β a company WhatsApp, not a personal one
You don't have to ban WhatsApp. You just move it onto rails the clinic controls:
- βUse a company WhatsApp Business number that the clinic owns β not a staff member's personal number. The account, the chats and the contacts stay with the clinic when people join or leave.
- βKeep the real records in your clinic system β not in the chat. WhatsApp is for the conversation; the patient's file, history and results belong in your proper system.
- βWrite a short staff rule β one page: use the company number for patient chats, don't use personal WhatsApp, don't save patient photos to personal galleries.
- βSecure the devices β a screen lock and passcode on whatever phone or tablet runs the clinic WhatsApp.
- βDelete on offboarding β when someone leaves, remove their access to the company account and make sure no patient data lingers on their device.
One more habit: don't store records in WhatsApp
WhatsApp is a great place to talk to a patient and a bad place to keep their information. Don't let it become your filing cabinet β no storing scans of IC, medical records, referral letters, or photos of a patient's condition in the chat as your only copy. Move anything that matters into your clinic system, then it's backed up, access-controlled, and not sitting in a chat thread on someone's phone.
Who sets all this up? Your DPO.
This is exactly the kind of everyday gap a Data Protection Officer is there to close β picking the company-number setup, writing the one-page staff rule, and making sure offboarding actually removes access. Every clinic in Singapore has to appoint a DPO anyway, so this is a natural part of that job rather than extra work. If you're not sure whether you've got that base covered, start with our guide: does my clinic need a DPO?
Common questions
Yes. Appointment reminders and care-related messages are generally fine if the patient gave you their number for that purpose. Keep the messages to what the patient expects, and keep the real records in your clinic system rather than in the chat.
It's risky and best avoided. Your clinic is still accountable for that patient data even when it sits on a staff member's personal phone, it lives outside your control, and it walks out the door when the staff member leaves. Use a company WhatsApp Business number instead.
Yes. Marketing and promotional blasts need separate express consent, which isn't the same as a patient giving you their number for appointments. Do Not Call rules also apply to marketing by SMS and phone calls, so treat promotions as their own opt-in.
Use a company WhatsApp Business number that the clinic owns and controls, not a staff member's personal number. That keeps the account, the chats and the patient contacts under the clinic when people join or leave.
Sources
- Personal Data Protection Commission (PDPC) β pdpc.gov.sg (consent for marketing; Do Not Call provisions; Healthcare Sector Advisory Guidelines, rev. Sept 2023)
- Ministry of Health (MOH) β record-keeping requirements & the Healthcare Services Act (HCSA)
Want this handled for your clinic?
We help Singapore clinics set up WhatsApp, consent and records the right way β and stand in as your outsourced DPO. Done for you. Let's talk.