If you run a GP, dental, TCM, physio or aesthetic clinic, sooner or later a patient will ask "can I get a copy of my records?" or "that date of birth is wrong, please fix it." These are formal rights under the PDPA β not favours. Handled well, they take ten minutes. Handled badly, they become a complaint. Let's keep it plain.
The two rights, in plain terms
The PDPA gives every individual β your patients included β two connected rights:
- 1Access β they can ask to see the personal data you hold about them, and a rundown of how that data has been used or disclosed in the year before the request.
- 2Correction β if something you hold is wrong or incomplete, they can ask you to fix it.
Notice the first right has two halves: the data itself, and the "who did you share it with" history. Clinics usually remember the first and forget the second.
Respond as soon as practicable β and mind the 30 days
The PDPA says you must respond to an access or correction request as soon as reasonably practicable. There's no "we'll get to it eventually." If you can't respond within 30 days, the law requires you to write to the patient and tell them by when you will. The one thing you cannot do is go quiet past the 30-day mark. Put a simple diary reminder on every request so nothing slips.
Verify who's asking β before you hand anything over
This is the step clinics skip, and it's the dangerous one. If you email a patient's records to someone who claims to be them but isn't, you've caused a data breach yourself β the exact thing the access right is meant to protect against. So before you retrieve or release anything:
- βConfirm identity β check it's genuinely the patient (or someone properly authorised, like a parent of a young child or a person with legal authority).
- βBe careful with third parties β a spouse, adult child or employer asking on someone's behalf needs real authorisation, not just "I'm her husband."
- βSend it safely β deliver to a verified email or in person, not to whatever number messaged your front desk.
What you may refuse β or redact
Access isn't unconditional. Some things you must hold back, and a few you may:
- βAnother person's data β if a record would reveal someone else's personal data (a family member mentioned in the notes, another patient), you must redact or withhold that part.
- βSerious harm β the PDPA lets you decline where giving access could cause serious harm to the health or safety of the patient or another person.
- βNot a blanket excuse β you can't refuse just because it's inconvenient, or to hide a mistake. If you withhold part, tell the patient what and why.
How medical records fit in
Yes β a patient can ask for a copy of their medical records under the access right. But two things sit alongside the PDPA. First, MOH record-keeping rules mean you keep the original record intact β an access request is about giving a copy, not surrendering the file. Second, on correction, there's a sensible line between facts and clinical opinion: a wrong NRIC, misspelled name or incorrect date of birth should simply be corrected; but a diagnosis or clinical note the patient disagrees with is usually handled by keeping the original and adding the patient's requested correction as an annotation β you don't erase a clinician's record. When you do correct a fact, the PDPA also asks you to pass the correction on to other organisations you shared that data with in the past year (unless that clearly serves no purpose).
Keep a log of every request
Write it down. A one-line log β who asked, when, what they wanted, how you verified them, what you released or refused, and the date you responded β is your proof that you handled it properly. If a patient ever complains to the PDPC, that log is the difference between "here's exactly what we did" and an awkward silence. It's also the kind of record a Data Protection Officer keeps as a matter of course.
The simple step-by-step
When a request lands, run it through five steps every time:
- 1Receive β note the request and start the clock (as soon as practicable; 30-day marker).
- 2Verify β confirm the requester really is the patient, or is properly authorised.
- 3Retrieve β pull the data they're entitled to, plus the past-year use/disclosure history for an access request.
- 4Redact β remove any other person's data, and anything you're permitted to withhold.
- 5Respond β deliver it safely, explain any redactions, log the whole thing. For a correction, fix the fact (or annotate the opinion) and notify anyone you shared it with.
So β what should you do?
Have a written mini-process for access and correction requests, make sure your front desk knows to verify identity first, and keep a log. It's not complicated, but it has to be consistent β because the one time you rush it and email records to the wrong person is the time it becomes a real problem. If you'd rather not build this from scratch, that's exactly what an outsourced DPO sets up for you.
Common questions
Yes. Under the PDPA a patient can make an access request to see the personal data your clinic holds about them and how it has been used or disclosed in the past year. You still verify their identity first, and you may withhold parts that would reveal another person's data or that the law lets you refuse.
You must respond as soon as reasonably practicable. If you cannot respond within 30 days, the PDPA requires you to tell the patient in writing when you will be able to. Do not just go silent past 30 days.
Sometimes. You must refuse or redact the parts that would reveal another individual's personal data, and the PDPA lets you decline in certain cases β for example where giving access could cause serious harm to health or safety. You cannot refuse simply because the request is inconvenient, and you should explain what you are withholding and why.
That is a correction request. Where the data is factually wrong you should correct it and, unless it clearly makes no sense, send the corrected data to other organisations you shared it with in the past year. For a clinical opinion you disagree with, the usual practice is to keep the original and note the patient's requested correction alongside it rather than erase the record.
Sources
- Personal Data Protection Commission (PDPC) β pdpc.gov.sg (Access and Correction Obligation; Healthcare Sector Advisory Guidelines, rev. Sept 2023)
- Ministry of Health (MOH) β record-keeping requirements & the Healthcare Services Act (HCSA)
Want this handled for your clinic?
We help Singapore clinics get PDPA-ready and stand in as your outsourced DPO β a clean access-and-correction process, staff trained, done for you. Let's talk.