← Insights Say hi πŸ‘‹
Data protection Β· Clinics

Patient access & correction requests: how a clinic handles them

The short answer

Your patients have two rights you must honour. Under Singapore's PDPA, a patient can ask to see the personal data you hold about them (and how you've used or disclosed it in the past year), and to correct anything that's wrong. Your job is to respond as soon as practicable, verify who's asking before you hand anything over, and know the few things you're allowed to withhold. Get the identity check wrong and you cause a breach yourself. Here's the calm, step-by-step way to handle it.

If you run a GP, dental, TCM, physio or aesthetic clinic, sooner or later a patient will ask "can I get a copy of my records?" or "that date of birth is wrong, please fix it." These are formal rights under the PDPA β€” not favours. Handled well, they take ten minutes. Handled badly, they become a complaint. Let's keep it plain.

The two rights, in plain terms

The PDPA gives every individual β€” your patients included β€” two connected rights:

Notice the first right has two halves: the data itself, and the "who did you share it with" history. Clinics usually remember the first and forget the second.

Respond as soon as practicable β€” and mind the 30 days

The PDPA says you must respond to an access or correction request as soon as reasonably practicable. There's no "we'll get to it eventually." If you can't respond within 30 days, the law requires you to write to the patient and tell them by when you will. The one thing you cannot do is go quiet past the 30-day mark. Put a simple diary reminder on every request so nothing slips.

Verify who's asking β€” before you hand anything over

This is the step clinics skip, and it's the dangerous one. If you email a patient's records to someone who claims to be them but isn't, you've caused a data breach yourself β€” the exact thing the access right is meant to protect against. So before you retrieve or release anything:

What you may refuse β€” or redact

Access isn't unconditional. Some things you must hold back, and a few you may:

How medical records fit in

Yes β€” a patient can ask for a copy of their medical records under the access right. But two things sit alongside the PDPA. First, MOH record-keeping rules mean you keep the original record intact β€” an access request is about giving a copy, not surrendering the file. Second, on correction, there's a sensible line between facts and clinical opinion: a wrong NRIC, misspelled name or incorrect date of birth should simply be corrected; but a diagnosis or clinical note the patient disagrees with is usually handled by keeping the original and adding the patient's requested correction as an annotation β€” you don't erase a clinician's record. When you do correct a fact, the PDPA also asks you to pass the correction on to other organisations you shared that data with in the past year (unless that clearly serves no purpose).

Keep a log of every request

Write it down. A one-line log β€” who asked, when, what they wanted, how you verified them, what you released or refused, and the date you responded β€” is your proof that you handled it properly. If a patient ever complains to the PDPC, that log is the difference between "here's exactly what we did" and an awkward silence. It's also the kind of record a Data Protection Officer keeps as a matter of course.

The simple step-by-step

When a request lands, run it through five steps every time:

So β€” what should you do?

Have a written mini-process for access and correction requests, make sure your front desk knows to verify identity first, and keep a log. It's not complicated, but it has to be consistent β€” because the one time you rush it and email records to the wrong person is the time it becomes a real problem. If you'd rather not build this from scratch, that's exactly what an outsourced DPO sets up for you.

On cost: getting your clinic PDPA-ready β€” including a clean access-and-correction process β€” is more affordable than most owners expect, and right now we're running a founding-clinic offer (a substantial first-year discount) to make it easy to start. Ask us about it.
This is general information to help clinic owners understand the PDPA β€” it isn't legal advice. For your clinic's specific situation, check the PDPC's official guidance, the MOH healthcare guidelines, or a qualified professional.

Common questions

Yes. Under the PDPA a patient can make an access request to see the personal data your clinic holds about them and how it has been used or disclosed in the past year. You still verify their identity first, and you may withhold parts that would reveal another person's data or that the law lets you refuse.

You must respond as soon as reasonably practicable. If you cannot respond within 30 days, the PDPA requires you to tell the patient in writing when you will be able to. Do not just go silent past 30 days.

Sometimes. You must refuse or redact the parts that would reveal another individual's personal data, and the PDPA lets you decline in certain cases β€” for example where giving access could cause serious harm to health or safety. You cannot refuse simply because the request is inconvenient, and you should explain what you are withholding and why.

That is a correction request. Where the data is factually wrong you should correct it and, unless it clearly makes no sense, send the corrected data to other organisations you shared it with in the past year. For a clinical opinion you disagree with, the usual practice is to keep the original and note the patient's requested correction alongside it rather than erase the record.

Sources

  • Personal Data Protection Commission (PDPC) β€” pdpc.gov.sg (Access and Correction Obligation; Healthcare Sector Advisory Guidelines, rev. Sept 2023)
  • Ministry of Health (MOH) β€” record-keeping requirements & the Healthcare Services Act (HCSA)
Eugene
Eugene

I build websites and help Singapore businesses run them well. HeyAda is my Singapore web studio β€” design, SEO, and the practical side of running a business online, including the patient data your clinic collects. I write these guides in plain English, and I can be your clinic's outsourced DPO. Getting your clinic PDPA-ready? Say hi.

Want this handled for your clinic?

We help Singapore clinics get PDPA-ready and stand in as your outsourced DPO β€” a clean access-and-correction process, staff trained, done for you. Let's talk.