← LEADERSHIP TERMINAL

PARLIAMENT OF SINGAPORE · FORMER

Gan Kim Yong

Singapore

IN THEIR OWN WORDS

Consumer complaints relating to the secondary resale market for tickets to major events and concerts have generally remained low. Nonetheless, to protect the public from scams on secondary ticket resale platforms, the Police have imposed Code of Practice requirements under the Online Criminal Harms Act to require designated online service…

CONSUMER COMPLAINTS ON SECONDARY RESALE TICKET MARKET FOR EVENTS AND CONCERTS AND ADDITIONAL MEASURES FOR TRANSPARENCY AND AUTHENTICITY VERIFICATION - 2026-07-07 · READ THE OFFICIAL RECORD

Singapore does not condone the use of forced labour. We criminalise forced labour in Singapore under various laws. Relevant Government Ministries and agencies, such as the Ministry of Manpower, Ministry of Home Affairs and Singapore Police Force, play their part in investigating complaints of suspected breaches in domestic laws that relat…

POLICY MEASURES TO PREVENT ENTITIES FROM LEVERAGING SINGAPORE’S TRADE HUB STATUS TO BYPASS GLOBAL DUE DILIGENCE STANDARDS - 2026-07-07 · READ THE OFFICIAL RECORD

The Association of Banks in Singapore (ABS) discontinued the PayNow nickname feature as scammers had been exploiting the use of nicknames to impersonate legitimate entities and trusted individuals.

PERMITTING SOME REGISTERED PAYNOW RETAIL USERS TO ADOPT NICKNAMES AS DISPLAY NAMES - 2026-07-07 · READ THE OFFICIAL RECORD

As of end-2025, around 6,900 private residential buildings have registered their solar installations with SP Group for the export of excess solar-generated electricity to the grid. The installed solar capacity of these residential buildings is 115.3 megawatt-peak (MWp), or around 5.5% of all current installed solar capacity in Singapore.

DATA ON PRIVATE RESIDENTIAL SOLAR ENERGY GRID EXPORTS AND ASSESSING CONTRIBUTIONS TO SINGAPORE'S RENEWABLE ENERGY TARGETS - 2026-07-07 · READ THE OFFICIAL RECORD

The one-year pilot extension of liquor trading hours has seen strong interest from businesses. As of 31 May 2026, the Police have approved 88 applications for the extension of liquor trading hours from public entertainment outlets in these areas.

EFFECT OF EXTENSION OF LIQUOR TRADING HOURS IN BOAT QUAY AND CLARKE QUAY AREA - 2026-07-07 · READ THE OFFICIAL RECORD

The Government does not make projections of domestic or regional demand for renewable diesel or sustainable aviation fuel. Demand depends on commercial considerations, evolving market conditions and regulatory developments across different jurisdictions.

PROJECTED DEMAND FOR RENEWABLE DIESEL AND SUSTAINABLE AVIATION FUEL PRODUCED IN SINGAPORE AGAINST PROJECTED REGIONAL REFINING CAPACITY - 2026-07-07 · READ THE OFFICIAL RECORD

The complete record

Every one of 3,841 lines we hold for Gan Kim Yong, in date order, each linked to its source. Free to read, in full, without an account. Page 38 of 77.

  1. The second level is for us to detect should something happen and there are some suspicious activities that are going on. These are the audit trails which are important, the documentation which is important. The third level, which is equally important, and that is deterrence. And that is why if we were to find someone who has made an illegal access or who has abused information or has been less than careful with the information that he is entrusted with, then we must take stern action and that is what happened to Ler and Brochez. That is why they were charged in Court. Only when we do these three would we be able to have a robust system of protecting our information. So, if Members bear in mind that Ler himself was the head of the unit, the safeguards that you put in place, even if it is effective, he had the right to access. Even if you have audit trails, most of the things that he did from our audit over the last few years, when we checked what he did, based on our investigation, they were legitimate work that he was doing with MOH. Whether or not he was careful in protecting the data that he was using is a separate issue. Many of these may not be able to stop Ler from doing what he did but the deterrence is an important part to make sure that those who want to try have to be mindful of the penalties that could be imposed on them if they were ever caught. Therefore, these three must work hand in hand to ensure we have a robust system of data security – protection, detection and deterrence.

    UNAUTHORISED POSSESSION AND DISCLOSURE OF INFORMATION FROM HIV REGISTRY - 2019-02-12 · READ THE OFFICIAL RECORD

  2. On the last question, I can confirm with my colleagues. But I would imagine that it is subject to the normal prison terms where you have remission of a certain period and then he was deported thereafter. So, perhaps my colleagues can confirm. On the Member's question about access, in fact, access to the data has always been on a need-to-know and need-to-use basis, and the number of staff in NPHU is actually very small. They are limited to a handful of people. Whenever they need the information, they would have to then access because they are all doing contact tracing, doing analysis, so all of them are actually working on the similar type of matters. At the same time, we also have to understand that Ler was the head of the unit. So, in his particular position, he needs to have oversight of all the work that the staff is working on and, therefore, he would have access to all the information in any case. So, it probably does not relate to this particular incident. The new system that we put in place has audit trail and this audit trail was not meant to watch everybody and what they do. There are certain alerts that are built into the system where if there are excessive access to the information, or where there is unusual kind of access to information, it will be flagged up. The audit trail will also allow us, when something does happen, to look back. Therefore, let me just put in perspective. We have to take a multi-pronged approach to data security. The first level is to have a system in place to prevent abuse of data – things like encrypted thumb drives. So, those are important to allow us to prevent attempts to abuse the data or illegal access to data.

    UNAUTHORISED POSSESSION AND DISCLOSURE OF INFORMATION FROM HIV REGISTRY - 2019-02-12 · READ THE OFFICIAL RECORD

  3. Sir, I thank the Member for his suggestion. Indeed, we will learn from other countries, their experiences and share their practices on how to better support persons living with HIV. We also work with advocacy groups and support groups, as well as non-government organisations and voluntary welfare organisations (VWOs), to see how we can enable them, how we can support them in the work that they do. As I have mentioned, many of these require collaborative efforts, not just from the Government. Some persons with HIV would feel more comfortable talking to people that they know, people they are more familiar with and, therefore, it is not just the Government doing it. We need to work with multiple agencies, whether it is Action for AIDS, SOS or other VWOs. We try to work with them and see how we can best reach out to these people who need support and provide the relevant and effective support. We will also look at how we can formalise these arrangements in a more structured way so that they are more sustainable and also, there is a continuity in the efforts. So, we take the Member's point and will explore other possibilities.

    UNAUTHORISED POSSESSION AND DISCLOSURE OF INFORMATION FROM HIV REGISTRY - 2019-02-12 · READ THE OFFICIAL RECORD

  4. I stand corrected. But this is, to my memory, the first case that we have seen. I will check and provide the Member with the information. On the issue of HIV testing, we do encourage persons who suspect they may have HIV, or who are uncertain whether they have HIV, to come forward to be tested. We do have anonymous test sites across Singapore. The identity of the person will be kept anonymous and MOH will only receive an aggregated number of people who have tested. We do not get the identity. So, we will continue to encourage you to come forward and be tested so that at least you will know your status. And we also encourage you to seek treatment. When you seek treatment, we will know who you are because we need to provide treatment to the patients. We will do our utmost to protect the data and the information as much as we can. Rest assured that we will do what we can to support you. The Ministry will also continue to step up efforts on public education to reduce the stigma on HIV patients. At the same time, the effort is not just the Government's alone. The society as a whole should come together and show support for these persons living with HIV. By showing them support, it will encourage more of them to come forward for testing and, more importantly, for treatment as well.

    UNAUTHORISED POSSESSION AND DISCLOSURE OF INFORMATION FROM HIV REGISTRY - 2019-02-12 · READ THE OFFICIAL RECORD

  5. Let me answer the second question. NPHU oversees public health issues which would include infectious diseases, such as Middle East Respiratory Syndrome (MERS), Bird Flu, TB, STDs and HIV. The Unit will handle many of these infectious diseases and that is part of the information and data that officers would be handling. As to the data that has been exposed, it is limited to the HIV Registry, as I had mentioned. The other question on whether a person receiving information or a link that is provided by Brochez, whether it is illegal to retain them, I have to consult my colleague. But my suggestion is, whether it is legal or illegal, please forward it to us or to the Police so that we can follow up to investigate the implications of that.

    UNAUTHORISED POSSESSION AND DISCLOSURE OF INFORMATION FROM HIV REGISTRY - 2019-02-12 · READ THE OFFICIAL RECORD

  6. On the consultation with other organisations, as the Member would appreciate, this is a very sensitive area. We had information about Brochez and Ler, and both were being charged in Court. Therefore, we did not consult outside parties. We were discussing within the Ministry, with people who had been dealing with persons with HIV. So, we were familiar with the concerns about the patients, and it was borne out with the issues that arose as a result of this disclosure. We were, therefore, quite clear that the pressure, the distress and the anxiety were real. With regard to destigmatisation of HIV persons and whether we would review the immigration policies, we do these reviews quite regularly. Every time, we would look at the practice here and around the world and take into account the concerns and interests of Singaporeans and decide on these issues. We have made adjustments along the way, as we have done so over the past few years. As I had explained, HIV remains a very serious infectious disease. Therefore, we need to be very cautious in approaching this issue. We want to make sure that we are able to manage the disease environment here and to protect Singaporeans where possible. Therefore, for persons with long-term residence in Singapore, we still have a restriction on their access to Singapore. For persons who are on short-term stay, the restriction has been lifted recently. We are also not alone in this. Australia and New Zealand also have restrictions on long-term stays for persons with HIV.

    UNAUTHORISED POSSESSION AND DISCLOSURE OF INFORMATION FROM HIV REGISTRY - 2019-02-12 · READ THE OFFICIAL RECORD

  7. Mr Speaker, Sir, this has been a regrettable incident caused by the irresponsible and deplorable actions of two individuals. Ler is a Singaporean doctor and ex-MOH officer who had been entrusted with the care of our patients, but he had betrayed the trust of the Ministry and the medical profession. I am sorry that these irresponsible actions of one of our officers has resulted in such distress to the affected persons. Ler’s case is now before the Courts and he will be dealt with according to the law. The other, Brochez, is an American citizen who had left a trail of lies and deceit and now perpetrated a reprehensible act that has affected thousands of persons with HIV. He had already spent time behind bars here for his earlier offences, and we will spare no efforts in bringing him to justice again for his latest crime. As individuals and part of the larger Singaporean community, the best way for us to respond to this incident is with sensitivity, understanding and support for those affected. If we can say no to discrimination and reduce the stigma surrounding HIV, we can turn the harm and discord which the perpetrators seek to sow into a more inclusive and supportive environment for persons with HIV.

    UNAUTHORISED POSSESSION AND DISCLOSURE OF INFORMATION FROM HIV REGISTRY - 2019-02-12 · READ THE OFFICIAL RECORD

  8. Generally, every HIV patient in public healthcare institutions is assigned to a medical social worker to provide assistance upon their diagnosis. Sir, it is easy to stigmatise something that we do not understand. MOH has, therefore, been working with stakeholders to raise awareness of the disease and reduce stigma for the disease. In 2017, the Singapore National Employers Federation (SNEF), Tan Tock Seng Hospital (TTSH) and the Health Promotion Board (HPB) worked together to introduce "Guidelines on Managing HIV and Acquired Immune Deficiency Syndrome (AIDS) in the Workplace" to help companies create enabling workplace environments for employees with HIV. More recently, the Tripartite Guidelines on Fair Employment Practices call for employers to treat employees fairly and based on merit. This includes employees with HIV. MOH will continue to work with partner organisations to step up efforts in public education, stigma reduction, prevention, testing, treatment and counselling support. But beyond this, how each of us as individuals relate to persons with HIV also matters a lot. Here, I would like to appeal to Singaporeans to stand in support of these affected individuals and our efforts to fight the stigma against persons living with HIV. I would like to urge the public and media not to share illegally obtained information and inform the Police/MOH immediately. The welfare of the affected individuals in this incident would be something of deep concern for us. We would like to encourage those with concerns to contact us at our hotline at, again, 6325 9220. You may also call the Samaritans of Singapore (SOS), TAFEP and Action for AIDS, or approach the healthcare institutions and professionals that have been providing you care and support.

    UNAUTHORISED POSSESSION AND DISCLOSURE OF INFORMATION FROM HIV REGISTRY - 2019-02-12 · READ THE OFFICIAL RECORD

  9. Several Members have called for destigmatisation of HIV and asked how we can protect people living with HIV from discrimination. Stigmatisation is an issue that all of us are concerned with. Destigmatisation requires efforts across the society. Let me cite some of the efforts by MOH, together with the Government and non-Government agencies, advocacy groups as well as voluntary welfare organisations. Persons living with HIV require lifelong treatment. HIV, therefore, continues to be a serious infectious disease that MOH closely monitors and actively manages for public health reasons. But clinically, HIV treatment has vastly improved over the years, and early treatment can delay disease progression and improve the quality of life. Over the years, MOH has increased financial support and lowered the financial barriers for HIV treatment through MediSave and MediFund. Since 2014, HIV anti-retroviral drugs can be supported under the Medication Assistance Fund (MAF). MAF provides means-tested subsidies for lower- and middle-income patients, covering up to 75% of the cost of anti-retroviral treatment. In 2015, with the introduction of MediShield Life, persons living with HIV are now covered by our national health insurance scheme should they be hospitalised. We have also made HIV testing and counselling services more widely available. For example, anonymous HIV testing is now available at 10 sites across the island. Special outreach efforts have also been made for specific groups. For instance, it is part of standard antenatal testing at our public hospitals. Support from doctors, medical social workers and healthcare workers is also widely available in public hospitals.

    UNAUTHORISED POSSESSION AND DISCLOSURE OF INFORMATION FROM HIV REGISTRY - 2019-02-12 · READ THE OFFICIAL RECORD

  10. Specifically for NPHU, MOH’s Chief Data Officer also conducted a data security review in 2016. Following the review, enhancements were made to further strengthen the NPHU systems. These include the following: (a) elevating the approval authority for downloading and decrypting Registry data to the level of the Director of our Communicable Diseases Division (CDD) or higher; (b) implementing a two-person approval process to download and decrypt Registry data, to ensure that data could not be accessed by a single person; and (c) designating a specific workstation for processing of sensitive data from the HIV Registry. This workstation is configured and locked down to prevent unauthorised removal of data. In 2017, NPHU also complied with Government-wide policy to disable the use of unauthorised portable storage devices on official computers and only allow the use of authorised and encrypted thumb drives. To give greater attention to data usage and safeguards, we had also set up a Data Analytics Group in April 2018. Within the group, a Data Governance Division was set up to formulate policies, practices and guidelines for MOH and its agencies. The aim is to protect and secure access to health sector data, in accordance with data protection requirements in the Government IMs and the Personal Data Protection Act (PDPA), and other MOH sectoral legislation. In light of the recent incident, and the increased prevalence of data use across the healthcare sector, it is important to ensure that data security and governance policies are strictly adhered to on the ground. MOH will expand the role and resourcing of this unit. We will include within it a specific mandate and team to look into the compliance and audits of data access and use.

    UNAUTHORISED POSSESSION AND DISCLOSURE OF INFORMATION FROM HIV REGISTRY - 2019-02-12 · READ THE OFFICIAL RECORD

  11. Staff were briefed on the policies, systems and processes, and regularly reminded of the sensitivity of the information, which they should access on a need-to-know basis. All of them signed an undertaking to observe confidentiality obligations under the OSA. Prior to 2012, the HIV Registry was placed in a secured network drive. The file could only be accessed and downloaded from Government issued computers, and was password protected. NPHU staff would need to download the HIV Registry in order to carry out routine data entry, contact tracing and analysis. Staff were allowed to use personal thumb drives at that time, subject to adherence to data protection guidelines and policies. As the Head of NPHU, Ler had authority to access information in the HIV Registry as required for his work. He is believed to have downloaded the HIV Registry into a thumb drive and failed to retain possession of it. Ler has been charged for mishandling the information. Mr Seah Kian Peng asked about the additional measures undertaken to ensure data security. In 2012, prior to the complaint from Brochez, the Registry database was migrated to a network-based system. NPHU staff no longer had to download a database file stored on a network drive to do their work. Instead, staff would call up records they require from the network-based system. With the implementation of a network-based Registry, the audit trail was also enhanced. In 2014, alerts of multiple failed login attempts were incorporated into the system. MOH continues to follow the security policies from the Singapore Government Instruction Manual (IM) for the Security of Classified Information. In tandem with the Government guidelines, we implemented several controls to tighten our systems.

    UNAUTHORISED POSSESSION AND DISCLOSURE OF INFORMATION FROM HIV REGISTRY - 2019-02-12 · READ THE OFFICIAL RECORD

  12. Some felt we should have just informed the affected individuals. A few wished they had not been called at all. The anxiety and concerns which some individuals felt have also been carried in various online, broadcast and print articles in recent weeks. Our medical social workers were themselves distressed by the news they had to break and felt the anguish that the patients experienced when they were told. They had to conduct the calls carefully and gently and be alert to signs of distress so that they could help the patients appropriately. At times, our medical social workers became the target of anger and blamed themselves. Nevertheless, they do their best to support the affected persons. These reactions are not unexpected and they were the reasons we made a judgement call in 2016 not to make a public announcement, and in 2018, to inform only the affected patients. Mr Speaker, Sir, Members have asked about the purpose and safeguards of the HIV Registry. MOH’s national HIV Registry contains information of persons diagnosed with HIV in Singapore. We are not unique in having such a registry. Countries, such as the US and Canada, also maintain HIV registries containing identifiable information. We need the Registry to monitor the HIV infection situation, conduct contact tracing, and assess disease prevention and management measures. The data needs to be identifiable for purposes, such as contact tracing, to protect those who are contacts of HIV patients. The security safeguards for the HIV Registry in 2012/2013 were in accordance with the prevailing Government policies on classified information and information technology (IT) security.

    UNAUTHORISED POSSESSION AND DISCLOSURE OF INFORMATION FROM HIV REGISTRY - 2019-02-12 · READ THE OFFICIAL RECORD

  13. Officers manning our hotline will then provide information on the incident and direct callers to available avenues for support. Ms Anthea Ong, Assoc Prof Walter Theseira and Assoc Prof Daniel Goh asked about the measures taken to protect the psychological welfare of the affected individuals. We know that the affected persons may have concerns and may be worried about unfair treatment arising from this incident. Prior to calling patients, our medical social workers have helped to first identify those likely to require more support, so that designated officers can exercise extra care and provide additional support when calling them. If callers request to speak to our counsellors, are in distress, or require more advice and support, counsellors are on standby to speak with them. Some affected individuals may prefer to discuss their concerns with those they are more familiar with, such as the medical social workers, nurses and doctors who have been supporting their ongoing care and treatment. We have arranged with the relevant public hospitals to have medical social workers and doctors onsite to attend to them. Agencies, such as the Life Insurance Association (LIA), MOM and the Tripartite Alliance for Fair and Progressive Employment Practices (TAFEP) have provided public assurances on common concerns. MOM shared that Singapore has employment laws to protect employees from wrongful dismissals, including on the grounds of HIV. LIA has, in turn, assured policyholders that insurers that receive information related to this incident will not use such information. They will inform the relevant authorities immediately. Understandably, despite these efforts, some will continue to be concerned. Some may decline to return to care because of the fear of future disclosure.

    UNAUTHORISED POSSESSION AND DISCLOSURE OF INFORMATION FROM HIV REGISTRY - 2019-02-12 · READ THE OFFICIAL RECORD

  14. We have quickly worked with the authorities to similarly disable access to the online content. The content that was uploaded is similar to what we had found in January, so no new individuals have been exposed. We have also been working with relevant parties to scan the Internet for indications of further sharing of the information. There have thus far been no signs of further disclosure, but we will continue to monitor. Should we detect any disclosure or online publication of the information, MOH will work with the relevant authorities and parties to take down the content and disable access to the data. Here, I would like to remind everyone that the Police will not hesitate to take stern action, including prosecution, against anyone who possesses, communicates or uses any of the confidential data that has been disclosed. The Police will also not tolerate any harassment or intimidation, of any form, towards any person, arising from this leak. Stern action will be taken against perpetrators. MOH has prioritised informing and supporting the affected individuals. We have completed attempts to contact all the affected individuals. But we are unable to reach all of them, as many had dated contact information, given that the Registry went back to 1985. Many of the foreigners were work pass applicants who never worked in Singapore, or who previously worked here but are no longer in Singapore. Amongst the affected Singaporeans diagnosed with HIV and are still living, we have reached 2,400 out of 3,500. Individuals who worry that they may be affected or who have concerns, can contact our hotline at 6325 9220. I repeat: 63259220. We seek their understanding that to maintain confidentiality of the information, we have to verify the identity of the caller.

    UNAUTHORISED POSSESSION AND DISCLOSURE OF INFORMATION FROM HIV REGISTRY - 2019-02-12 · READ THE OFFICIAL RECORD

  15. It is arguable that MOH should have made a different call. But I reject any allegation that MOH sought to cover up the incident. On all three occasions, MOH's primary concern was the well-being of the persons on the HIV Registry. Today, we still face the same dilemma as we did back in 2016 and 2018. We now know that Brochez retained some of the data after the Police seized all the files they could find in 2016. Quite possibly, he still has more files in his possession. Should MOH now make known all that Brochez may, or may not, still have in his possession? Do we contact every person whose data may, or may not, be at risk? And in the process inflict more harm on people even though it may ultimately turn out that Brochez, in fact, does not have the information? Again, we have to assess and make a judgement call. MOH has decided to continue to manage the situation in a way that reduces the possibility of further exposure. This is consistent with the decision taken in 2016 and again in 2018. It is based on what we believe to be the interest of the potentially affected persons. Mr Speaker, Sir, let me now turn to what else we are doing following the latest incident. Brochez is currently under Police investigation for various offences. He is believed to be in the US. The Police are engaging their American counterparts and are seeking their assistance in the investigations against Brochez. The Police will spare no effort pursuing all avenues to bring Brochez to justice. Following our public announcement, a few parties have come forward to inform us that Brochez had, in fact, attempted to make contact with them in 2018, and had given them links to confidential information he had uploaded online.

    UNAUTHORISED POSSESSION AND DISCLOSURE OF INFORMATION FROM HIV REGISTRY - 2019-02-12 · READ THE OFFICIAL RECORD

  16. The trial for his drug charges will be held next, as these also involve stiffer penalties, including mandatory caning. So that there is no doubt, let me say again that the OSA charge against Ler is still "live". AGC will decide on the OSA charge, after proceedings on his other charges have concluded. This is the usual course. The most recent incident in January 2019 stood on a different footing from the earlier incidents. It showed that Brochez probably still possessed the entire HIV Registry, beyond just the 31 records. He had also put the information online and provided the link to a non-Government party. This new situation meant that the likelihood of the identities of affected persons being made public by Brochez had increased significantly. MOH, therefore, decided to make a public announcement on 28 January, even though we remained deeply concerned about the impact this would have on the affected persons. We sought to quickly contact each of the affected individuals to inform them of the circumstances and also offer them assistance prior to the announcement. We worked with the Police and other relevant parties to disable access to the information as quickly as possible. Mr Speaker, Sir, at this point, let me reiterate the basis of our decisions and actions, especially on the issue of disclosure and announcement. At each juncture in May 2016, May 2018 and January 2019, MOH had to decide whether to inform the affected persons and make a public announcement. In making those decisions, MOH had a responsibility to balance the opposing considerations and exercise judgement on what would best serve the interest of the affected persons and the public. MOH made a judgement call, balancing the various considerations.

    UNAUTHORISED POSSESSION AND DISCLOSURE OF INFORMATION FROM HIV REGISTRY - 2019-02-12 · READ THE OFFICIAL RECORD

  17. In May 2018, after his deportation, Brochez sent a screenshot containing 31 records from the HIV Registry to several Government authorities. All 31 records were not new. They were a subset of the 75 which Brochez had earlier revealed to authorities in May 2016. MOH lodged another Police report. We considered again whether to inform the affected individuals and the public. The relevant factors were similar to those in 2016. But there was one difference. This time, we could not retrieve the screenshot of the 31 records in Brochez's possession because he was already out of Singapore. MOH, therefore, decided to contact the affected individuals and alert them to the matter. We did not make a public announcement as there was still no specific evidence that Brochez had more information beyond these 31 records. Furthermore, as on previous occasions, Brochez had only shared it with Government authorities and not to any wider audience. A public announcement would create anxiety and distress not just among the 31 persons but also other HIV patients whose names were in the Registry. In September 2018, Ler was convicted for abetting Brochez to commit cheating, and also of providing false information to the Police and MOH. He was sentenced to 24 months' imprisonment. Ler has appealed and this is scheduled to be heard in March 2019. Ler's charge under the OSA is currently "stood down". That means that the OSA charge has been put aside for the moment, but it remains before the Courts and will be dealt with after proceedings on his other charges have concluded. AGC decided to go to trial against Ler on the cheating and false information charges first, as they were more serious and carried stiffer penalties.

    UNAUTHORISED POSSESSION AND DISCLOSURE OF INFORMATION FROM HIV REGISTRY - 2019-02-12 · READ THE OFFICIAL RECORD

  18. On the other hand, we need to consider the impact of an announcement on the affected persons with HIV – would it serve their interest or would it harm them instead? I discussed this with my medical colleagues in MOH. They emphasised the need to pay particular attention to the concerns and needs of HIV patients. A person's HIV status is a deeply emotional and personal matter. Some patients will experience high anxiety and distress from a disclosure or announcement. Some will feel compelled to reveal their HIV status to family members or friends. Relationships can be disrupted; lives can be changed. We had to exercise care and judgement in making our decision, and the well-being of the affected persons weighed heavily in our considerations. One key factor was that there was then still no evidence that the confidential information had been disseminated to the public. Brochez had sent the information to Government authorities. The Police search was extensive and all relevant material found had been seized or deleted. While there could be no guarantee, MOH had good reason to believe that the information had been secured and the risk of future exposure significantly mitigated. Ultimately, it was a judgement call to be made based on the information we had, and the considerations for and against an announcement, and the assessed risk of future public exposure of the information. MOH judged that, on balance, an announcement then would not serve the interests of the affected individuals, when weighed against the inevitable anxiety and distress they would experience. Two years later, in April 2018, Brochez was deported from Singapore after serving his sentence and we had no basis to keep him here.

    UNAUTHORISED POSSESSION AND DISCLOSURE OF INFORMATION FROM HIV REGISTRY - 2019-02-12 · READ THE OFFICIAL RECORD

  19. Ler's charge sheet, which was public information, stated that he had had access to the HIV Registry as part of his position as the Head of NPHU in MOH, and that he had failed to take reasonable care of the information in the HIV Registry by failing to retain possession of a thumb drive on which he had saved the HIV Registry. Brochez was charged for offences under the Misuse of Drugs Act, Penal Code and Infectious Diseases Act (IDA). The Attorney-General's Chambers (AGC) decides on the charges. AGC decided not to charge him under the OSA because they assessed that he would likely be sentenced to a fine only, or, at most, a few weeks in jail. This was because there had been no wide dissemination of the information at that stage, and he had primarily used the information to complain to Government agencies, and he was already facing numerous fraud and drug-related charges, which carried far heavier penalties. AGC also assessed that any jail term under the OSA was likely to be concurrent with jail terms that he would serve under other offences. Brochez was, therefore, issued with a stern warning for the OSA offence. Brochez was subsequently convicted in March 2017 and sentenced to 28 months' imprisonment. In its judgment, the Court found that Brochez had "deliberate[ly] flout[ed] the law for personal benefit", and that there was "not a single word of regret." Mr Speaker, Sir, let me now address questions as to whether MOH should have informed the public earlier. In 2016, MOH had to decide whether to inform the affected persons and whether to make a public announcement about the incident. These were not straightforward decisions. On the one hand, there is the need to be transparent.

    UNAUTHORISED POSSESSION AND DISCLOSURE OF INFORMATION FROM HIV REGISTRY - 2019-02-12 · READ THE OFFICIAL RECORD

  20. He then provided the Police and the Government authorities 75 names and particulars from the HIV Registry. This was the first time MOH had evidence that Brochez may have access to HIV-related data. We made a Police Report on 16 May 2016. The Police raided Ler's and Brochez's premises simultaneously and seized and secured all relevant materials. These included their computers and electronic storage devices containing files with confidential information from the HIV Registry, files related to hospital services and to other infectious diseases, as well as other information likely used by Ler for his work, such as emails, HIV studies and reports. The Police searched through Brochez's email account and found that Brochez had sent the same screenshot that he had sent to Government authorities, as well as a portable document format (PDF) file of a further 46 records from the HIV Registry, to his mother. The Police then contacted Brochez's mother, who agreed to let the Police access her email account and deleted those records. At this point, the Police had seized everything they found in Ler's and Brochez's possession and had done their best to ensure that no further confidential information remained with Ler and Brochez, including in their known online accounts. It was always recognised that there was a risk that Brochez could have hidden away some more information. Unfortunately, as recent events showed, Brochez did manage to retain at least the data which he has recently disclosed, and we cannot rule out the possibility that he has more. Ler and Brochez were both charged in Court in June 2016. Ler was charged both under the Penal Code and the Official Secrets Act (OSA).

    UNAUTHORISED POSSESSION AND DISCLOSURE OF INFORMATION FROM HIV REGISTRY - 2019-02-12 · READ THE OFFICIAL RECORD

  21. At one point, he even informed MOH officers that he was leaving Singapore and did not want to continue with the investigation into his allegation. Due to his uncooperative attitude, the investigation could not make much headway. Nevertheless, we re-assigned Ler to another role in May 2013, and kept up the investigation. Ler's access to the live HIV Registry was terminated after his re-assignment. In the course of our investigations, MOH discovered in December 2013 that Brochez may have submitted fake HIV blood tests to the Ministry of Manpower (MOM) in order to retain his Employment Pass. We informed MOM and also made a Police report. Ler resigned the following month. MOH's investigations in 2012 and 2013 were on Brochez's allegation that Ler had revealed Brochez's HIV status to others. At no point in 2012 or 2013 did MOH have basis to suspect that Brochez had access to, or was in possession of, the data in the HIV Registry. Between 2014 and 2016, the Police and MOH investigated whether Brochez had submitted fake blood tests, and whether Ler had abetted this process and provided false information to investigators. These investigations were difficult as Brochez continued to be uncooperative and initially refused to provide a statement to the Police. The Police eventually recorded a statement from Brochez in May 2014, after he was stopped trying to leave Singapore. When interviewed, Brochez lied to the Police that it was his blood that was tested during a HIV test conducted in November 2013. MOH then ordered Brochez to undergo a fresh blood test for HIV to verify his claim, but Brochez refused to cooperate. In late April 2016, Brochez was arrested for repeatedly refusing to comply with MOH's order to take a blood test.

    UNAUTHORISED POSSESSION AND DISCLOSURE OF INFORMATION FROM HIV REGISTRY - 2019-02-12 · READ THE OFFICIAL RECORD

  22. Mr Speaker, Sir, thank you for allowing me to make a Statement on the Unauthorised Possession and Disclosure of Information from the Human Immunodeficiency Virus (HIV) Registry, and to respond to the various Parliamentary Questions (PQs) asked earlier. Senior Minister of State Janil Puthucheary will speak after me on matters regarding governance on data in general. Sir, on 22 January 2019, the Ministry of Health (MOH) was alerted to a case of unauthorised possession and wrongful online disclosure of information from the HIV Registry by one Mikhy K Farrera Brochez, affecting 14,200 individuals diagnosed with HIV, and 2,400 of their contacts. The incident has caused anxiety and distress to the affected persons. This matter is especially delicate as it involves persons living with HIV. Our priority is their well-being. Members have asked several questions regarding the incident. So, let me first give a brief account on what happened, the actions we took, and why. Some have asked whether MOH had known about Brochez's possible access to HIV Registry information in 2012 when he first made a complaint to MOH. Let me clarify that the issue then was not about Brochez's access to HIV Registry information, but a different one. Brochez was then a partner of Dr Ler Teck Siang who was the Head of the National Public Health Unit (NPHU), and they had lived together. In November 2012, Brochez alleged that Ler had disclosed information about Brochez to others. He later also claimed that Ler had shared screenshots of his HIV status with others. Despite multiple attempts by MOH to engage him, Brochez did not provide any evidence to support his allegation. He was uncooperative and evasive, and rejected or postponed meetings with MOH on several occasions.

    UNAUTHORISED POSSESSION AND DISCLOSURE OF INFORMATION FROM HIV REGISTRY - 2019-02-12 · READ THE OFFICIAL RECORD

  23. Automatic External Defibrillators (AEDs) are used to restart the heart when persons collapse due to cardiac arrest. AED use is associated with increased survival in Out-of-Hospital Cardiac Arrest (OHCA) patients. The latest available data is up to 2017 and indicates that AED usage rate has increased from 1.9% in 2012 to 6.4% in 20171. This increase is likely due to a growing public awareness about the use of AEDs as well as the availability of AEDs in public places.

    USAGE RATE IN PAST FIVE YEARS OF AUTOMATIC EXTERNAL DEFIBRILATORS INSTALLED IN PUBLIC PLACES - 2019-02-11 · READ THE OFFICIAL RECORD

  24. The provision of dental services, such as veneers and teeth whitening services, is a practice of dentistry. Under the Dental Registration Act, only a registered dentist is allowed to practise dentistry in Singapore. The practice must be conducted in premises licensed under the Private Hospitals and Medical Clinics Act. In the past three years, there were five reported cases on home-based dental services. Investigations into these cases are ongoing. The Ministry takes a serious view of the practice of dentistry being performed by non-dentists in unlicensed premises and will not hesitate to take tough enforcement action against any person who contravenes the law. It is unlawful for any person not registered with the Singapore Dental Council to provide dental services. If found guilty, the person shall be liable to a fine not exceeding $25,000. Repeat offenders can be fined up to $50,000, or to an imprisonment for up to six months, or to both. Additionally, any person found operating an unlicensed premises shall be liable to a fine not exceeding $20,000, or to a jail term not more than two years, or to both. The Ministry advises the public to be cautious about using healthcare services from unfamiliar sources. When in doubt, they should seek advice from their regular doctor or dentist, or they can check the list of licensed healthcare institutions and registered healthcare professionals on the Ministry of Health's and the relevant professional board's websites. The Ministry will step up our efforts on consumer education regarding unlawful dental services.

    NUMBER OF CASES AGAINST HOME-BASED SALONS PROVIDING DENTAL SERVICES IN PAST THREE YEARS - 2019-02-11 · READ THE OFFICIAL RECORD

  25. Teeth whitening products are regulated as cosmetic products under the Health Products (Cosmetic Products – ASEAN Cosmetic Directive) Regulations. They usually contain hydrogen peroxide, a bleaching agent, which may pose a risk of damage to the teeth and gums if used inappropriately. To safeguard the public, only those preparations containing 0.1% of hydrogen peroxide or less are allowed to be sold directly to consumers. Those containing more than 0.1% can only be supplied or used by registered dentists. The Health Sciences Authority (HSA) monitors the safety of health products, including cosmetics, sold in the local market. HSA conducts regular checks on the products, including those sold online. Sellers of unsafe products will be ordered to remove such products from the market. When online sale of unsafe cosmetic products is detected, HSA will work with the administrators of online platforms to remove the listings of the affected products. Any person found to contravene the regulation is liable to a fine of up to $50,000 or imprisonment of up to two years, or both. Given the widespread reach of the Internet, consumers play an important part in safeguarding their own health. They should be careful not to purchase these products from unknown vendors and should obtain them from a reliable supplier. For those products containing more than 0.1% hydrogen peroxide, they should obtain them from a dentist.

    REGULATIONS GOVERNING ONLINE SALE OF TEETH WHITENING PRODUCTS - 2019-02-11 · READ THE OFFICIAL RECORD

  26. Skin cancer was the 9th most common cancer among Singaporeans from 2013-2017. Ten percent of cases were below 50 years old, although the incidence of new cases in this group increased from 1.2 to 2.7 per 100,000 persons from 1983-1987 to 2013-2017 respectively. Studies have linked cumulative exposure to ultraviolet (UV) light with an increased risk of skin cancer. However, exposure to sunlight has health benefits as it is important for vitamin D formation and, hence, for healthy bone formation. Sufficient time outdoors can also help prevent or delay myopia in children. Singapore Armed Forces soldiers are provided with Personal Protective Equipment, such as head gear and long-sleeved combat uniform, that protects them from sun exposure. Physical training conducted in sports attire and swimming kit are typically conducted in the early mornings or late afternoons when sunlight is less intense. Likewise, in Ministry of Education schools, outdoor activities are generally conducted in the early mornings and late afternoons to minimise students' exposure to UV light. Frequent rest and water breaks under shade are incorporated into activities carried out during other parts of the day. Students are also taught to use sunscreen, broad-brimmed hats and caps, long-sleeved shirts and sunglasses to protect themselves against excessive UV exposure. There are no known local studies regarding skin cancer among young persons as the incidence of skin cancer remains low in this group. Nevertheless, it is prudent that Singaporeans take measures to protect themselves from prolonged exposure to UV light and see a doctor early if they develop symptoms.

    MEASURES TO PROTECT SOLDIERS AND STUDENTS FROM FALLING VICTIM TO SKIN CANCER FROM EXPOSURE TO ULTRAVIOLET LIGHT - 2019-02-11 · READ THE OFFICIAL RECORD

  27. MediFund utilisation has increased over the last decade to $150 million in financial year (FY) 2017. The increase was higher in the earlier years. Since FY2016, the figure has been more stable, following the introduction of MediShield Life and the Pioneer Generation package, both of which extended more healthcare financing support. There are a few reasons for the increase in MediFund utilisation over the past decade. First, we have been helping more Singaporeans, as we expanded our public healthcare capacity to serve more patients. Over the last decade, the number of MediFund applications increased by close to 10% annually, on average. Second, we have expanded the scope of coverage of MediFund to cover more services and conditions. For example, MediFund was extended to cover non-residential intermediate and long-term care services in 2012, and to polyclinics, dental services, antenatal and delivery services in 2013. Third, we have been providing greater support to those with greater healthcare needs. For example, we have enhanced the scheme through the introduction of MediFund Silver in 2007 and MediFund Junior in 2013 to better target support for young and elderly Singaporeans respectively. We will continue to monitor the MediFund utilisation to ensure that it is sustainable and no Singaporean is denied appropriate healthcare due to an inability to pay.

    TOP THREE REASONS FOR CONTINUING INCREASE IN MEDIFUND UTILISATION - 2019-02-11 · READ THE OFFICIAL RECORD

  28. The Ministry of Health will continue to monitor the affordability of subsidised care, and regularly review the financing policies, including MediSave withdrawal limits.

    VISITS TO POLYCLINICS BY ELDERLY PERSONS AND BASIS FOR SETTING WITHDRAWAL LIMITS FOR HEALTHCARE SCHEMES - 2019-02-11 · READ THE OFFICIAL RECORD

  29. In the past two years, elderly patients above 60 years of age with chronic conditions visited polyclinics and Community Health Assist Scheme (CHAS) clinics an average of six times per year, with an average annual bill of about $200 after subsidies. Those without chronic illnesses visited these healthcare facilities an average of about three times a year, with an average annual bill of about $60 after subsidies. MediSave withdrawal limits are reviewed regularly, taking into account other healthcare financing schemes, and seeking to strike the right balance between present consumption of MediSave and its use as savings for future use. The MediSave withdrawal limits are sized so that outpatient care remains affordable, after subsidies. Arising from our recent reviews, we increased the MediSave Chronic Disease Management Programme (CDMP) limit from $400 to $500 and lowered the minimum age for Flexi-MediSave to 60 in June 2018. These limits are adequate for the majority of patients at polyclinics and CHAS clinics. Any appeals for higher withdrawals, including for elderly patients, can be considered on a case-by-case basis, especially where the bill size is high. For patients who require additional financial support, they can be referred to the Medical Social Workers to consider assistance from MediFund. Any liberalisation of MediSave withdrawals, including having higher withdrawal limits based on MediSave balances, will have to be carefully considered as it may result in Singaporeans having less MediSave savings when they are retired and older, which is when they are most likely to have a need for their MediSave savings the most.

    VISITS TO POLYCLINICS BY ELDERLY PERSONS AND BASIS FOR SETTING WITHDRAWAL LIMITS FOR HEALTHCARE SCHEMES - 2019-02-11 · READ THE OFFICIAL RECORD

  30. Most recently, MOH worked with Temasek Foundation Cares to launch Project Silver Screen, a nationwide functional screening programme for seniors to check their vision, hearing and oral health. As part of the screening, seniors are advised on proper eye care, and those with abnormal vision results are referred to an optometrist or eye specialist if needed. Since January 2018, more than 40,000 seniors have benefited from Project Silver Screen, and about one in three seniors were referred for follow-up care. MOH and the healthcare family will continue to strengthen our efforts to reduce the risk of falls among our senior population.

    CAMPAIGN TO GUIDE SENIORS ON PROPER EYE CARE AND EXERCISES - 2019-02-11 · READ THE OFFICIAL RECORD

  31. Seniors fall for a variety of factors, such as poor eyesight, decreased lower body strength and dizziness. The Ministry of Health's (MOH's) efforts on fall prevention comprise both broad-based upstream prevention campaigns and outreach efforts as well as targeted interventions for those at higher risk of falls. Let me cite some examples. The Health Promotion Board (HPB) has worked with community partners to raise awareness on falls prevention. HPB started a Falls Prevention Awareness Campaign in 2016 to provide seniors with tips to reduce the risk of falls. A guidebook was released containing information on fall prevention strategies, such as wearing non-slip footwear and ensuring adequate calcium intake. The guidebooks were distributed through more than 300 touchpoints, including Community Clubs and Centres, retail pharmacies, polyclinics and hospitals. HPB also conducts regular health talks at Community Clubs and Centres, and Residents’ Committees, advising on falls prevention and on good eye care. Over 70,000 seniors have benefited from these talks over the past two years. In addition, HPB conducts exercise programmes to encourage seniors to build up muscle strength and balance to minimise their risk of falls. As part of their outreach efforts, Silver Generation Ambassadors (SGAs) conduct simple assessments of seniors’ health status during home visits. SGAs may refer seniors to relevant services, such as the Housing and Development Board's Enhancement for Active Seniors programme which subsidises home modifications, such as anti-slip treatment for tiles and installation of grab bars, to prevent falls at home. Seniors may also be linked up with service providers for care and support services.

    CAMPAIGN TO GUIDE SENIORS ON PROPER EYE CARE AND EXERCISES - 2019-02-11 · READ THE OFFICIAL RECORD

  32. Thank you! I would like to thank the Member for her encouragement. Indeed, IHiS has been working very hard over the last few years in reorganising itself, strengthening its governance, as well as rolling out many major systems. But this is an important incident and it is a very critical and regrettable incident and, IHiS' staff morale has, indeed, taken a toll from this incident. We will continue to support them. As I have mentioned in my speech, even as they go through the reorganisation, going through the repositioning, reprioritising, MOH and all our clusters will extend our full support for them and we want to encourage them to soldier on because there are still many important tasks ahead of us, and not the least, the implementation of the recommendations of the COI. On top of that, there are still many systems that they have to deliver and they have to deliver them with strong cybersecurity measures. So, I would like to thank the Member for her encouragement, and will convey this to the IHiS team and to encourage them to press on with our task. Thank you.

    GOVERNMENT'S RESPONSE TO THE REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2019-01-15 · READ THE OFFICIAL RECORD

  33. We will give them general advice on what they ought to do to ensure that their databases are protected.

    GOVERNMENT'S RESPONSE TO THE REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2019-01-15 · READ THE OFFICIAL RECORD

  34. Sir, I agree with Dr Lily Neo that it is important for us to ensure that NEHR is robust before we make it mandatory for data submission. Dr Lily Neo also mentioned how we can help private sector doctors, particularly if they are connected to NEHR. Indeed, we are aware that there is a risk, because we have many private operators which have to tap on to our NEHR in order to submit their data, and that is why we are taking additional precautions to test our NEHR cybersecurity and cyber defences to ensure that they are robust before we require everyone to submit. At the same time, we will also be developing advisories to help advise our private practitioners how to strengthen their system, how to do audits on their system to ensure that their own systems are protected. We must remember that even without NEHR, many of our doctors have their own data system and keep their own patient records. Of course, these are limited to their own patients, not national data. Nevertheless, it is also important for our private doctors to ensure that the patient data that they collect and maintain are protected from potential cyberattacks. In the past, our doctors may be using paper and pen, they have paper card records, it is less risky. But still, the sense of responsibility to safekeep these data is there among our medical practitioners. I think it is no different when it comes to electronic records. When doctors have their records kept in an electronic form, they should be quite mindful that they are also responsible to ensure that such electronic records within their own premises where they are kept, they also have to ensure that they are protected to a satisfactory extent. So, we will help them. We will give them advice from time to time, especially arising from this incident.

    GOVERNMENT'S RESPONSE TO THE REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2019-01-15 · READ THE OFFICIAL RECORD

  35. Sir, I do not know whether they have informed the union. I will inform the management. I agree with Mr Patrick Tay that it is a good practice whenever these incidents happen and we have to take disciplinary action, it is best to keep the unions informed. I do not know whether they are union members. And if they are, it would be useful for the management to keep them informed. And if they have not done so, it is still not too late. Better to do now than not to do so at all. Secondly, the Member asked about the bonuses of IHiS staff and SingHealth staff. I think other than those I mentioned as part of the disciplinary action, the rest of the staff should not be affected. Should they continue to do well, they should continue to get what they deserve. And for those who have done well, their contributions will be recognised at the end of the year.

    GOVERNMENT'S RESPONSE TO THE REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2019-01-15 · READ THE OFFICIAL RECORD

  36. Sir, I explained in my speech the significant reorganisation of IHiS, the cluster IT organisation, as well as MOH. Let me just quickly focus on the questions that the Member raised. Particularly within the cluster, currently, the GCIO is an IHiS staff and, therefore, there is a question: does he have sufficient resources, does he report to IHIS or does he report to the cluster? So, we have made it clear now that the GCIO in the clusters will report to the Board and the management of the cluster. So, he may be a secondee from IHiS, he may be a direct recruit, he may be someone that is loaned to the cluster, but his responsibility and accountability is towards the cluster. So, this provides the cluster some independence from IHiS as a system operator. Particularly on security, the Cluster ISO now reports directly to the management, he does not report to the GCIO. So, security and operations now have separate reporting lines, and this provides significant independence between security considerations as well as operational requirements. Within MOH, I mentioned that we are going to set up a separate Chief Information Security Officer (CISCO) which would report directly to the Permanent Secretary. And this will also be quite separate from IHiS' Cyber Defence Group. So, I think the separation of roles among these few key functions will provide greater independence and check and balance between operational needs and cybersecurity needs.

    GOVERNMENT'S RESPONSE TO THE REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2019-01-15 · READ THE OFFICIAL RECORD

  37. We foresee that we will probably be able to complete our review within this year and then we can make a decision at the end of this year to see when we are ready to implement then because the process is still ongoing. This is an indicative timeline and we will probably give an update nearer the time.

    GOVERNMENT'S RESPONSE TO THE REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2019-01-15 · READ THE OFFICIAL RECORD

  38. Sir, as I explained earlier in my speech, Advanced Threat Protection has been implemented in our healthcare system, generally. So, it is there to help us detect potential malicious activities. But for the private sector, it is something that we will have to work with them and see what would be applicable for them. But it is also important for us to always remember that whatever system we put in, there will always be the risk of exposure. The greatest risk for us is to assume that after putting in Advanced Threat Protection or ISS, we are quite safe and, therefore, we let our guard down. So, we always must remember "道高一尺,魔高一丈". That is, you must always be on alert and assume that we are being attacked all the time and be vigilant and get to know what is the latest development, what is the latest landscape, and continually upgrade ourselves to make sure that we are ready for them as best we can. So, this is a lesson we learnt from this incident. Dr Chia Shi-Lu also asked about the impact due to this incident. Some patient care, some processes have been slowed down because of additional steps that they have to go through. But by and large, we have not compromised the quality of care. And particularly on patient safety, we have been quite conscious about this. I have always reminded our cluster leadership to make sure that despite all the additional cybersecurity measures, we cannot compromise our patient safety. So far, I think it has been going on all right. On NEHR, I agree with Dr Chia Shi-Lu that we do not want to delay it unnecessarily. But given that it is a very large system and a very important national system, we want to be extra cautious to have it tested and tested again before we make it mandatory.

    GOVERNMENT'S RESPONSE TO THE REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2019-01-15 · READ THE OFFICIAL RECORD

  39. Thank you very much. Indeed, some of the healthcare professionals have taken the initiatives to use their own personal devices to access Internet for work. Because their personal devices are not connected to the intranet, to our database system and, therefore, they are less risky from the systems point of view. Whereas our own internal intranet system – we have imposed ISS on our own internal system and, therefore, our internal system will have no access to the Internet for surfing purposes.

    GOVERNMENT'S RESPONSE TO THE REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2019-01-15 · READ THE OFFICIAL RECORD

  40. This will not be a one-off exercise as new and evolving threats will continue to target our systems. We must continually fortify our defences, and we need a strong team working together to achieve this. Mr Speaker, Sir, to conclude, I would like to thank the COI once again for its work and the comprehensive findings and recommendations. We in the public healthcare family will take guidance from the COI report and strengthen our systems and capabilities. We must and we will emerge with stronger cyber defences. This will be the most fitting way to fulfil our responsibilities to our patients.

    GOVERNMENT'S RESPONSE TO THE REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2019-01-15 · READ THE OFFICIAL RECORD

  41. At the same time, I thank Singaporeans for their patience and understanding on the inconveniences they may have encountered at our public healthcare institutions arising from the implementation of tighter cybersecurity measures. Mr Speaker, Sir, I have sketched out the responses of the public healthcare family to the SingHealth data breach and the COI report. The public healthcare family will ensure that priority and attention are given to the implementation of COI’s recommendations as well as the cybersecurity initiatives that the public healthcare system has embarked on. We are organising our efforts into six key workstreams spanning technical measures, cybersecurity policy, organisational structures, governance enhancements, management of CII and patient engagement. Senior management and key personnel from MOH, IHiS and healthcare clusters will lead these efforts. They will report their progress regularly to the Healthcare IT Steering Committee chaired by my Permanent Secretary. The Steering Committee will oversee the implementation and closely monitor its progress. It will also tap on independent auditors to verify the completion of the follow-up actions. Mr Speaker, Sir, this cyberattack has been a regrettable and painful incident for us and for the affected patients. We must learn from it. But we must not allow it to hold back our push towards using technology to provide better care for our patients. IT systems have improved the safety and effectiveness of patient care. It remains a key enabler we cannot do without for better delivery of healthcare to benefit Singaporeans. Yet, we recognise that the cybersecurity landscape has shifted and the threat level has risen. So, the cybersecurity posture of the healthcare sector needs to be correspondingly raised.

    GOVERNMENT'S RESPONSE TO THE REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2019-01-15 · READ THE OFFICIAL RECORD

  42. I expect them to do their utmost to remedy the shortcomings and help the public healthcare family emerge stronger, so as to win back public trust. MOH and the rest of the public healthcare family will render them our full support. The COI did not identify lapses in specific individuals that are employed by SingHealth. However, SingHealth recognises its duty to its patients and its responsibility as the owner of the database system. The SingHealth senior leadership, including the Group CEO, has volunteered for a financial penalty which the Board has accepted. Sir, beyond these disciplinary actions and penalties on specific individuals, penalties have also been imposed at the organisational level. Earlier, Minister Iswaran had shared that PDPC has completed its investigations into the incident. PDPC has decided to impose financial penalties on IHiS and SingHealth, which comes to $1 million in total. This is the highest penalty meted out by PDPC to date. IHiS and SingHealth have accepted PDPC’s decision and penalties. This is the right response. Mr Speaker, Sir, in the COI report, several IHiS officers were commended for their diligence in handling the incident beyond their job scope and responsibilities. They were proactive and demonstrated resourcefulness in managing the cyberattack. The IHiS Board has presented Letters of Commendation to three IHiS staff from the Database Management Team, SCM Production Support Team and Security Management Team respectively. Each of them showed commitment to serve and had the persistence to get to the bottom of things. I am glad that their contributions have been recognised. I would also like to acknowledge members of our public healthcare family who have worked hard together to ensure patient care is not compromised by this incident.

    GOVERNMENT'S RESPONSE TO THE REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2019-01-15 · READ THE OFFICIAL RECORD

  43. His passiveness even after repeated alerts by his staff resulted in missed opportunities which could have averted or mitigated the impact of the cyberattack. Their behaviour had significant security implications and contributed to the unprecedented scale of the incident. The employment of the Citrix Team Lead and the Security Incident Response Manager has been terminated. Financial penalties were imposed on the two middle management supervisors who are accountable as supervisors of the staff that were terminated. A Cluster ISO was found to have a wrong understanding of what constituted a "security incident" and failed to comply with IHiS’ incident reporting procedures. The Board decided to demote the Cluster ISO and reassign him to another role. Let me now come to the IHiS senior management team. As the senior management team, they hold collective leadership responsibility over the organisation and the incident. They know this. IHiS CEO wrote a letter to me in December. In his letter, he expressed disappointment that he and his IHiS colleagues were not able to prevent or respond better to the cyberattack. He apologised for the incident. He and members of his senior management team acknowledged their collective responsibility. The CEO expressed that he would accept whatever the IHiS Board may decide for him. The IHiS Board has decided to impose a financial penalty, higher than that imposed on the middle management supervisors, on the CEO and four other members of the IHiS senior management team. They have all accepted the penalty. I have emphasised to the IHIS CEO and his senior management team to learn from this episode and lead the organisation and its staff through the recovery and rebuilding.

    GOVERNMENT'S RESPONSE TO THE REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2019-01-15 · READ THE OFFICIAL RECORD

  44. Even as we conduct the reviews, IHiS will implement further enhancements to strengthen cybersecurity of the NEHR system. These include software and application upgrades, additional preventive and detection measures, and enhanced process and technical controls. Mr Speaker, Sir, the COI has identified inadequacies in specific individuals employed by IHiS in preventing and responding to the cyberattack. The IHiS Board has appointed an independent human resource (HR) panel to examine the roles, responsibilities and actions of specific individuals involved and recommend the appropriate actions to be taken. The panel was chaired by an IHiS Board member and comprised two other members from the public and private sectors with relevant HR and IT expertise. In assessing the appropriate HR actions, the panel considered whether the officers had acted in accordance with their job responsibilities. It also considered whether the officers’ action or inaction had contributed directly or indirectly to the outcome. The panel has submitted its recommendations to the IHiS Board and the Board released its decision on this matter yesterday. To recap, two IHiS staff – the Team Lead of the Citrix Team and the Security Incident Response Manager – were found to be negligent and non-compliant with orders. While the Citrix Team Lead had the necessary technical competencies, his attitude and approach to management of the servers introduced unnecessary and significant risks to the system. He could have mitigated the impact of the attack if he had enforced proper compliance and exercised effective management of the servers. The Security Incident Response Manager persistently held a mistaken understanding of what constituted a "security incident" and when a security incident should be reported.

    GOVERNMENT'S RESPONSE TO THE REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2019-01-15 · READ THE OFFICIAL RECORD

  45. Apart from this small group of pilot Virtual Browser users, all other public healthcare staff will remain on ISS for now. The conduct and evaluation of the pilot is expected to take about six months. We will work closely with CSA to assess the cybersecurity adequacy of the solution. We will also evaluate the effectiveness of the Virtual Browser. This will enable us to make a more considered decision on our Internet access model in public healthcare. Earlier, I mentioned that we have also started independent security reviews of other key public healthcare IT systems. One such system being reviewed is the National Electronic Health Record (NEHR) system. Over the past few months, NEHR has been undergoing a series of cybersecurity assessments conducted by CSA, GovTech and independent firm PricewaterhouseCoopers (PwC). These cover technical architecture design and existing cybersecurity measures. In addition, we are completing a series of penetration tests to uncover any security vulnerabilities against cyberattacks. The NEHR system will be subject to further testing and reviews, including exercises to test its defences against targeted attacks, as well as business continuity and disaster recovery plans. I had informed this House in August that we would be deferring plans for mandatory contribution of patient medical data to the NEHR. As NEHR is an important large-scale national system, we want to be fully assured that all the necessary safeguards are in place to handle the evolving cybersecurity threat landscape. We will, therefore, proceed with the introduction of the Healthcare Services Bill first, and continue to defer the NEHR mandatory contributions until we have completed these reviews.

    GOVERNMENT'S RESPONSE TO THE REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2019-01-15 · READ THE OFFICIAL RECORD

  46. Our earlier trial conducted at the healthcare clusters has shown that a "Virtual Browser" is technically feasible. Our next step will be to run a pilot in an operational environment across different settings and healthcare roles, so as to assess its effectiveness in meeting both operational and cybersecurity needs. If the Virtual Browser is found to be effective, we envisage putting in place a tiered model of Internet access among our healthcare staff in the longer term. For some job roles, Internet access would not be required. For example, administrative staff handling certain backend tasks, may not need Internet access for their routine work, and these staff will not be provided Internet access. For a number of job roles, Internet access is required but can be managed through the use of separate Internet and non-Internet facing devices. This would likely be the case for the majority. ISS will remain for this group and they will have access to the Internet via a separate device. We will further improve our current arrangements so as to make it more convenient for this group of users. For some, access to the Internet and intranet systems on the same device is essential. This group could include clinicians who need to access the Internet for information from clinical reference databases and match them urgently against patients’ electronic medical records, such as information on new and complex drugs or obscure toxins. The Virtual Browser may be the best solution for this group. The pilot will begin this quarter at the National University Health System (NUHS). Virtual Browsers will be deployed in selected job functions at selected departments and clinics. Some of the job roles participating in the pilot include frontline pharmacists and emergency department clinicians.

    GOVERNMENT'S RESPONSE TO THE REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2019-01-15 · READ THE OFFICIAL RECORD

  47. This software was used by some of our hospitals which do not have inhouse specialist neurology capabilities as timely diagnosis is critical for stroke cases. A dedicated leased line to support high resolution video conferencing had to be provided to overcome this challenge. Where possible, we have put in place fixes and workarounds like this to reduce the impact to patients and healthcare staff. I thank them for their cooperation and understanding during this period of time. While we can continue to operate on this current model of ISS, we have also been looking for longer-term solutions that are more efficient and sustainable. We also need a solution that will allow us to implement new models of care in the future, such as telemedicine, that leverage the Internet to improve patient care and services in the community. This is why we have been experimenting with a "Virtual Browser" solution, even before the cyberattack. A "Virtual Browser" allows access to the Internet through strictly controlled and monitored client servers. Let me explain what a "Virtual Browser" means. If we imagine loading a webpage or downloading a file from the Internet to be like receiving a letter, the client server is like a decontamination room where the letter is opened and only a picture is taken and sent to the recipient. The recipient reads the letter only via the picture that was taken and does not touch the letter itself. This process makes things safer for the recipient as malicious material or hidden messages are left behind in the decontamination room. Although such a solution does not fully eliminate cybersecurity risks, it reduces the attack surface significantly, while minimising impact on service efficiency and patient care.

    GOVERNMENT'S RESPONSE TO THE REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2019-01-15 · READ THE OFFICIAL RECORD

  48. IHiS intends to learn from GovTech's bug bounty and vulnerability disclosure programmes and start similar efforts. This will be a further step to ensure that our systems are tested, our people are ready to deal with new challenges, and our processes are robust. Next, we will pilot a tiered model of Internet access. In its report, the COI has recommended that an Internet access strategy which minimises exposure to external threats should be implemented. Following the cyberattack, temporary ISS was implemented across our public healthcare sector. This was a necessary precaution as suspicious activity continued to be observed on the SingHealth systems, even after initial containment actions were taken. I had mentioned in my previous statement in this House that we would study the impact of ISS, determine whether ISS can be kept as a permanent measure and if long-term mitigation solutions can be developed to overcome the operational challenges arising from ISS. While the implementation of ISS was necessary, it has, indeed, posed challenges in the provision of patient care in some areas, such as emergency care, decision support for prescriptions and treatments, access to patient education resources and booking of clinical appointments. ISS also caused delays to frontline patient management and backend administrative tasks. Research and education initiatives in the public healthcare institutions have also been impacted by ISS. Let me give an example. ISS impacted the functionality of Internet-based video conferencing software used to conduct tele-consultation with the National Neuroscience Institute for suspected stroke patients.

    GOVERNMENT'S RESPONSE TO THE REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2019-01-15 · READ THE OFFICIAL RECORD

  49. We will strengthen and elevate this second line of defence by establishing a dedicated Cyber Defence Group in IHiS headed by a senior leader at or equivalent to the Deputy Chief Executive level. The strengthened group will have independent oversight of cybersecurity implementation, compliance and risk management, and will oversee incident reporting and management. This will ensure that cybersecurity is managed at the senior management level, and an appropriate balance is struck between service delivery and cybersecurity considerations. The third line of defence comprises checks and assurances independent of IHiS and our healthcare clusters, and independent of the first two lines of defence. MOH Holdings Group Internal Audit will continue to play this role. We also intend to commission and tap on independent third parties where appropriate. These changes will make our public healthcare system more resilient and robust against emerging and evolving cyber threats. Third, we will improve our staff’s cybersecurity awareness and capacity. The COI has made several recommendations in this area. We agree that the "people" element is foundational and critical to our cyber defences. Every user needs to be trained and equipped to understand the important role that they play in cyber defence. For example, to raise the competence of our security incident response personnel, IHiS will engage specialist providers to conduct realistic hands-on "Cyber Range" simulation training starting this year. This will augment the classroom discussion-style table-top exercises currently conducted for security incident response personnel. We will also tap on the expertise of the wider cybersecurity community to test our systems.

    GOVERNMENT'S RESPONSE TO THE REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2019-01-15 · READ THE OFFICIAL RECORD

  50. It will coordinate efforts to protect the CII in the healthcare sector and ensure that the sector fulfils its regulatory obligations under the Cybersecurity Act. For its part, IHiS will have its own separate Director of Cyber Security Governance. At the clusters, the cluster Group Chief Information Officer (GCIO) office will now be made fully accountable to the respective cluster management and Boards. The GCIO office will be adequately resourced to carry out its roles. The position of the Cluster Information Security Officer will be elevated to report directly to cluster management and be accountable to the IT and Risk Management Committees of the cluster Boards. Together, these moves will strengthen oversight and minimise potential conflicts of interest between cybersecurity and operational demands. Second, we will put in place a cybersecurity model with multiple lines of defence. The COI has recommended that the public healthcare sector review our cyber stack for adequacy in defending and responding to advanced threats and subject the systems to tighter control and monitoring. The CAC, too, has highlighted the need for a more robust "Three Lines of Defence" model. We agree and we will establish a more robust "Three Lines of Defence" structure within public healthcare. The first line comprises units and personnel who develop, deliver and operate the IT systems. This is the Delivery Group. We will strengthen the IT delivery group to better integrate cybersecurity into IT delivery initiatives, improve the management of network security, and increase emphasis on security architecture and monitoring. The second line of defence comprises units and personnel who have the specific responsibility to oversee security strategy, risk management and compliance.

    GOVERNMENT'S RESPONSE TO THE REPORT OF THE COMMITTEE OF INQUIRY INTO THE CYBERATTACK ON SINGHEALTH'S IT SYSTEM - 2019-01-15 · READ THE OFFICIAL RECORD