Singapore legislation
Regulation 38
Regulation 38
Protection of patient health records
Subregulation 1
A licensee must keep every patient health record confidential and ensure that —
the confidentiality, integrity and security of every patient health record is maintained at all times; and
every personnel handling any patient health record is aware of his or her role and responsibility in maintaining the confidentiality, integrity and security of the records.
Subregulation 2
In addition, where any information in patient health records is in the form of an extract or aggregated compilation, the licensee must ensure that the confidentiality, integrity and security of the information in the extract or aggregated compilation is maintained at all times.
Subregulation 3
A licensee must —
implement adequate safeguards and appropriate protocols and processes to protect the patient health records against accidental or unlawful loss, modification or destruction, or unauthorised access, disclosure, copying, use or modification;
periodically monitor and evaluate the safeguards, protocols and processes mentioned in sub‑paragraph (a) to ensure that they are effective and being complied with by the staff involved in handling the patient health records; and
take reasonable care in the disposal or destruction of the patient health records so as to prevent unauthorised access to the records.