This is one of the most common gaps I see in Singapore clinics, and almost nobody thinks of it as a data problem. It just looks like staff being helpful. Let's keep it plain and walk through why it matters and what to do.
What actually happens on the ground
Picture an ordinary week at a GP, dental, TCM or physio clinic. A nurse photographs a patient's chart or a wound to "send to the doctor". The front desk WhatsApps a patient from their own number to confirm an appointment. An assistant saves a regular patient's contact into their personal phone so it's handy. None of it is malicious — it's people trying to move fast. But every one of those actions quietly copies patient data onto a device your clinic doesn't own and can't see.
Why this is a real PDPA risk, not a small thing
Here's the part owners miss: under Singapore's PDPA, the clinic stays accountable for that data no matter where it ends up. If a nurse's photo of a patient record is on her personal phone, that's still the clinic's responsibility to protect. And you can't protect what you can't see. That phone might have no lock, might get lost on the MRT, might be backed up to a personal cloud account, might be sold second-hand with photos still on it. You'd never know — until a patient complains or something leaks.
Because you're handling health data, the bar is higher for you than for a regular shop. The PDPC treats medical information as data where a breach causes significant harm, and clinics also sit under MOH rules. A record living on a random personal phone is exactly the kind of exposure that turns a small mistake into a reportable incident.
The bit that really bites: staff leave
This is the one that catches owners off guard. When a staff member resigns, whatever patient data is on their personal phone leaves with them. The photos of records, the saved patient contacts, the WhatsApp history — you have no way to retrieve it, no way to verify it was deleted, and no control over what happens next. In a small clinic where people come and go, that's a slow leak of your patients' information out of the practice, one departure at a time.
The fix — and it's not complicated
You don't need expensive systems. You need a few sensible habits that keep patient data on the clinic's side of the line:
- 1Use clinic-controlled devices & a company number — patient photos and messaging happen on a clinic-owned phone or a shared clinic number, never a personal one. If you message patients, use a clinic account. (See our guide to using WhatsApp with patients.)
- 2Keep the real record in the clinic system — the source of truth is your clinic software or file, not a camera roll or a chat thread. If a photo is needed, it goes into the system and is deleted from the device.
- 3Write a short staff data-handling policy — one page, plain language: what's OK, what isn't, and why. People follow rules they understand.
- 4Lock every device — any phone or tablet that ever touches patient data needs a PIN or biometric lock, and no shared logins.
- 5Add a hand-over-and-delete step to offboarding — when someone leaves, patient contacts and photos come back into the clinic system and are wiped from their personal device, and clinic accounts are revoked.
- 6Train the team — a short session so everyone knows the personal-phone habit is the risk, and the clinic device is the easy alternative.
Who sets this up?
This is exactly the kind of everyday, practical gap your Data Protection Officer (DPO) is meant to close. The DPO maps where patient data actually lives (including phones and chats), writes the short policy, sets the offboarding step, and trains staff. If you're not sure whether your clinic even needs a DPO, or who it should be, start with our guide on whether your clinic needs a DPO — it's the pillar this all sits under.
So — what should you do this week?
Ask one honest question: where does patient data live in my clinic right now — and is any of it on someone's personal phone? If the answer is yes (and for most clinics it is), you don't need to panic. Get a clinic device or number in place, move the real records into your system, write the one-page policy, and add the delete-on-exit step. Quiet, cheap, and it closes a gap that most clinics don't even know they have.
Common questions
They often do, but it's a real risk. Under the PDPA the clinic stays accountable for patient data even when it sits on a staff member's own phone. Once a record is in someone's camera roll or a private chat, it's outside your control and you can't properly secure, retrieve or delete it. The safer path is clinic-controlled devices and keeping the real record in your clinic system.
Yes. When a staff member messages patients from a personal number, the patient's contact and the conversation live on a private phone the clinic doesn't control — and they leave with that person. Use a clinic-owned number or account instead, and keep the notes that matter in the clinic system rather than in the chat.
If patient photos, contacts and chats are on a personal phone, they walk out the door with the person. You can't verify what was deleted, and the clinic is still accountable for it. That's why offboarding needs a hand-over-and-delete step — and why the real records should never have lived only on a personal device in the first place.
Give staff a clinic-owned device or number for patient contact, keep the real records in the clinic system rather than the camera roll or chat, write a short staff data-handling policy, require a lock or PIN on any device that touches patient data, add a hand-over-and-delete step to offboarding, and train the team. A DPO sets this up and keeps it running.
Sources
- Personal Data Protection Commission (PDPC) — pdpc.gov.sg (organisational accountability; Healthcare Sector Advisory Guidelines, rev. Sept 2023)
- Ministry of Health (MOH) — record-keeping requirements & the Healthcare Services Act (HCSA)
Want this handled for your clinic?
We help Singapore clinics get PDPA-ready and stand in as your outsourced DPO — devices sorted, policy written, staff trained, done for you. Let's talk.