Singapore legislation

Regulation 38

of Healthcare Services (General) Regulations 2021

Regulation 38

Protection of patient health records

Subregulation 1

A licensee must keep every patient health record confidential and ensure that —

(a)

the confidentiality, integrity and security of every patient health record is maintained at all times; and

(b)

every personnel handling any patient health record is aware of his or her role and responsibility in maintaining the confidentiality, integrity and security of the records.

Subregulation 2

In addition, where any information in patient health records is in the form of an extract or aggregated compilation, the licensee must ensure that the confidentiality, integrity and security of the information in the extract or aggregated compilation is maintained at all times.

Subregulation 3

A licensee must —

(a)

implement adequate safeguards and appropriate protocols and processes to protect the patient health records against accidental or unlawful loss, modification or destruction, or unauthorised access, disclosure, copying, use or modification;

(b)

periodically monitor and evaluate the safeguards, protocols and processes mentioned in sub‑paragraph (a) to ensure that they are effective and being complied with by the staff involved in handling the patient health records; and

(c)

take reasonable care in the disposal or destruction of the patient health records so as to prevent unauthorised access to the records.