← LEADERSHIP TERMINAL

PARLIAMENT OF SINGAPORE · FORMER

Tan Kiat How

Singapore

IN THEIR OWN WORDS

(In Mandarin): [Please refer to Vernacular Speech.] Thank you, Mr Speaker. Earlier I spoke about the policy objective of the Speak Mandarin Campaign, and we have remained consistent and united on this objective over the years. The question is our measures – how might we show some flexibility when it comes to movie screenings?

PROPOSAL TO REVIEW DECISION FOR "DEAR YOU" FILM TO BE DUBBED IN MANDARIN FOR GENERAL COMMERCIAL RELEASE - 2026-07-07 · READ THE OFFICIAL RECORD

Sir, I can take the Member's question first, about the institutional arrangement. IMDA works very closely with different Government agencies including the NHB. In fact, we work closely on films, the classification of films. So, there is no need for an explicit institution arrangement as they are already doing so.

PROPOSAL TO REVIEW DECISION FOR "DEAR YOU" FILM TO BE DUBBED IN MANDARIN FOR GENERAL COMMERCIAL RELEASE - 2026-07-07 · READ THE OFFICIAL RECORD

These are the primary objectives, but we will continue to see how we can think about meaningful information for family members. I know family members when they put their loved ones in nursing homes, there is a range of factors they consider.

STRENGTHENING REGULATORY REGIME FOR NURSING HOMES - 2026-07-07 · READ THE OFFICIAL RECORD

These are lessons we have learned and we will make sure that those lessons would be incorporated in our standard operating procedures in our approach next time. Lastly, I just want to thank the Member for coming by at least a few times to my constituency to speak to my merchants, the hawkers, the residents.

LESSONS ON IMPACT OF TUBERCULOSIS SCREENING ON BUSINESS PROSPECTS AT HIGH FOOTFALL LOCATIONS FROM RECENT EXERCISES AT BEDOK - 2026-07-07 · READ THE OFFICIAL RECORD

For example, there are no dialect restrictions for arts performances or content available on the Internet and online streaming services. On free-to-air television and radio, we believe that Mandarin should continue to be the mainstay.

PROPOSAL TO REVIEW DECISION FOR "DEAR YOU" FILM TO BE DUBBED IN MANDARIN FOR GENERAL COMMERCIAL RELEASE - 2026-07-07 · READ THE OFFICIAL RECORD

If there is more demand, we will discuss it with the film distributor and see how we can provide additional flexibility. But we will take a review as it comes along and it is certainly something for which we will speak to all members, industry partners, community partners about, and take their views on board.

PROPOSAL TO REVIEW DECISION FOR "DEAR YOU" FILM TO BE DUBBED IN MANDARIN FOR GENERAL COMMERCIAL RELEASE - 2026-07-07 · READ THE OFFICIAL RECORD

The complete record

Every one of 514 lines we hold for Tan Kiat How, in date order, each linked to its source. Free to read, in full, without an account. Page 2 of 11.

  1. Sir, as I said earlier in my reply, MNOs typically take six months to enhance coverage. Over the last three years, no persistent signal gaps within MRT network remained unrectified.

    MOBILE NETWORK DEAD ZONES IN MRT NETWORK AND STEPS TO RECTIFY PERSISTENT SIGNAL GAPS - 2026-03-06 · READ THE OFFICIAL RECORD

  2. They do so not just to reach out and speak to the seniors – they do befriending as well as preventive health visits – understanding the circumstances of the seniors that they visit at home, what kind of needs the seniors have, what kind of family circumstances are behind the closed door, and identify services, especially those near the seniors' homes, that are relevant to them and connect them to those services – whether it is AACs, SCCs or even mental health services. The Silver Generation Ambassadors go beyond just doing visitations. They also provide a valuable touchpoint to the community and a connector to services that are around the vicinity of the senior. We will want to do more for seniors who are socially isolated. We have been working with community partners, not just AACs and SCCs, but also other organisations in the community, including faith-based organisations and voluntary organisations to reach out to those seniors. We are working very closely with them. That is where the ICCP comes in. For seniors who are discharged from public health institutions, that is, hospitals, how can we make sure that those seniors are not left alone, are not forgotten? That is where the referral process comes in with the ICCP. ICCP will work out the assessment and care plan for those seniors and crowd in partners to reach out to those seniors, especially those who live by themselves. So, to the Member's point, I welcome any suggestions. This is an important priority for MOH in the coming years.

    COMMITTEE OF SUPPLY – HEAD O (MINISTRY OF HEALTH) - 2026-03-05 · READ THE OFFICIAL RECORD

  3. Sir, as I mentioned in my speech earlier, we have expanded the footprint of the AACs to about 230 centres. We have done so over the last two years. We serve about 100,000 seniors now and we want to do more in a few aspects. First, it is not just the number of the AACs; which is one thing. The number of AACs make it more convenient, easier for seniors to come by to an AAC near their home and in an environment they are familiar with, in a neighbourhood they are familiar with. That is why we have expanded the footprint. But beyond the number of AACs, it is also the activities that the AACs do to make it meaningful for the seniors, so that they come by and they are not socially isolated. They come by, they participate, they are engaged, they make new friends. And hopefully, they also can make changes to their lifestyle so that they can be healthier and happier. And in the coming years, we will do more to expand the number of activities that AACs do, going beyond maybe just doing, for example, activities like healthy rumba and so on, to also create more awareness about health and also having CHPs within the AACs to provide services to our seniors. And we will continue to explore how we can do more. So that it is not just quantity, but the kind of activities. 12.45 pm Thirdly, at the SGO, we have Silver Generation Ambassadors who reach out to seniors. As I mentioned, since 2022, they have engaged more than 600,000 seniors.

    COMMITTEE OF SUPPLY – HEAD O (MINISTRY OF HEALTH) - 2026-03-05 · READ THE OFFICIAL RECORD

  4. It is a voluntary effort. And like many ground-up initiatives, we certainly welcome them. And there are many funding schemes in Government to support ground-up initiatives. If Mr Fadli Fawzi knows of individuals or parties who want to support our caregivers and organise a ground-up effort, we will look at those proposals.

    COMMITTEE OF SUPPLY – HEAD O (MINISTRY OF HEALTH) - 2026-03-05 · READ THE OFFICIAL RECORD

  5. Sir, let me take the opportunity to also answer Mr Cai's question that I missed out earlier about flexible work arrangements and how can we work with different partners on that. I mentioned in my speech the different Ministries' efforts to support caregivers, and we understand the challenges that caregivers face, juggling between work and care. This is something they are working on, including flexible work arrangements and other initiatives. We will continue to work with our colleagues and other partners in the community. And Mr Fadli Fawzi's question around the caregiver passport, if I get it correctly, that he has referenced in his cut, from the UK. As I mentioned in my speech earlier, I think Mr Fawzi was not in the room, we certainly welcome all suggestions from Members, including suggestions that other Members have raised as part of this MOH COS and in other occasions. Specifically to his suggestion, I looked at it online. I must caveat to say that the information I got was what I could glean from online resources. It is a ground-up initiative in the UK and it is a way for the different parties involved ranging from hospitals to supermarkets he mentioned supermarkets earlier – to show care and support for caregivers. For example, some hospitals may provide longer visiting times. The hospital canteen may give some discounts to caregivers eating there and some supermarkets might give some discounts too. It is a ground-up initiative, where different parties come in. Because it is a ground-up initiative, I understand that the implementation can be quite uneven. Caregivers going to different parts of the city in the UK may have different experiences. Going to different supermarkets will have different experiences. Some supermarkets do provide the support, some do not.

    COMMITTEE OF SUPPLY – HEAD O (MINISTRY OF HEALTH) - 2026-03-05 · READ THE OFFICIAL RECORD

  6. So, I would say, let us take one step at a time and there are already many activities and other partners in the community providing different services and volunteering opportunities for seniors. We welcome it. It is really part of the fabric of a diverse community and very much part of the "we first" society.

    COMMITTEE OF SUPPLY – HEAD O (MINISTRY OF HEALTH) - 2026-03-05 · READ THE OFFICIAL RECORD

  7. Sir, I will try to answer the questions from Mr Cai. To Mr Cai, please correct me if I heard your questions wrongly, because I was trying to get all your four questions. One of the questions was, whether social prescriptions are part of the One Care Assessment Plan. That is actually part of the Healthier SG, where the care plan also includes the social prescription. For example, diet, lifestyle, exercise and many more other areas. So, certainly, that should be part of that care plan, but this goes beyond what the Integrated Community Care Provider does, which focuses more on seniors and the needs of those seniors. Mr Cai also asked if the the Integrated Community Care Provider and Agency for Integrated Care could cater for different sorts of activities, like faith-based volunteering or maybe for seniors who are interested in gardening as a social activity. I would say that we are just starting to roll out the the Integrated Community Care Provider framework starting this year and over the coming years, and this is a non-trivial exercise across 84 sub-regions in Singapore – bringing together different parties and partners. In each area, each sub-region, there are different providers, different parties providing different services – from befriending services, rehabilitation services and many more. So, bringing the different partners together, having a common language in which to discuss, understand and reach out and provide services to a senior is non-trivial. Having a standardised tool based on this assessment, developing a care plan, implementing this care plan and getting our seniors to go through the care plan entirely is non-trivial.

    COMMITTEE OF SUPPLY – HEAD O (MINISTRY OF HEALTH) - 2026-03-05 · READ THE OFFICIAL RECORD

  8. As the saying goes, "having a senior at home is like having a treasure". We will leverage technology to enhance care quality and ensure that seniors receive treatment in a familiar environment. We will also continue to expand these services, so that every senior can receive the care and support they need. We want our treasures – our seniors at home – to live happily and age well at home. (In English): Through the Health Information Act and other digital health priorities, we are building a more connected, responsive and secure health system. This is in support of our broader healthcare transformation to anchor care in the community with more coordinated services that wrap around our seniors. Importantly, a healthcare system that puts people first.

    COMMITTEE OF SUPPLY – HEAD O (MINISTRY OF HEALTH) - 2026-03-05 · READ THE OFFICIAL RECORD

  9. They understand the importance of maintaining good health, especially after the pandemic. To encourage seniors to maintain their physical and mental health, we have established over 230 AACs. This year we will also designate integrated community care service providers. Care teams will coordinate and plan more comprehensive healthcare according to seniors' needs. For example, if seniors need home personal care services as well as visits to senior care centres, they only need to contact one care team, reducing the hassle of liaising with different community care providers. We are also actively using technology to provide more precise and convenient care experiences for Singaporeans. For instance, seniors at risk of falling can enjoy 24-hour smart monitoring under the enhanced home personal care services. If an accident unfortunately occurs, the system can promptly notify relevant personnel to provide help. This way, family members can also have peace of mind. Nowadays, more seniors are becoming tech savvy. Therefore, we launched the LifeSG application. Through LifeSG, the SGO can interact with seniors and set personalised health plans for them. Since December last year, over 3,000 seniors have benefited. From July this year, GPs can view patients' health records previously documented by specialists, hospitals and other medical institutions in their computer systems. This way, doctors can have a more comprehensive understanding of patients' conditions, formulate the most suitable personalised health plans for them and eliminate the need for the patients to repeat their medical histories. Seniors do not need to worry about remembering the diagnoses or medications that have been prescribed by the doctors.

    COMMITTEE OF SUPPLY – HEAD O (MINISTRY OF HEALTH) - 2026-03-05 · READ THE OFFICIAL RECORD

  10. Sir, when I brought this House through the Health Information Bill in January, I said that MOH will help healthcare providers meet the provisions. I am pleased to provide an update. First, we are working with the vendors for health information management systems used by healthcare providers to comply with the necessary requirements. Second, we will provide resource guides and training to help healthcare providers and their staff understand and implement these requirements. Third, we will launch the National Electronic Health Record (NEHR) Connect Grant and open it for application in July this year. The Grant will offset the cost for providers to onboard the NEHR. For typical healthcare providers, this grant will cover up to two years of subscription costs for the health information management systems. For providers with in-house systems, the funding support covers up to 40% of enhancement cost. MOH will set aside up to $45 million for this. Let me illustrate how this work for a typical clinic with five staff. Most of them already subscribe to a health information management system. They can apply and benefit from the NEHR Connect Grant. On top of the NEHR Connect Grant, the clinic can receive up to 70% co-funding support from the Cyber Security Agency of Singapore to engage cybersecurity consultants. They also benefit from up to 50% funding support from Enterprise Singapore to adopt cybersecurity solutions, such as those for anti-malware. In total, the clinic can receive about $20,000 in grants. Sir, in Mandarin, please. (In Mandarin): [Please refer to Vernacular Speech.] During the Chinese New Year period, when exchanging greetings, I noticed that seniors would say "Gong Xi Fa Cai" less now. Instead, they often say "Good Health!".

    COMMITTEE OF SUPPLY – HEAD O (MINISTRY OF HEALTH) - 2026-03-05 · READ THE OFFICIAL RECORD

  11. This means a single party to coordinate care for seniors within each area. Currently, seniors undergo multiple care assessments done by different service providers they go to. Not only does this duplicate effort for providers and create greater inconvenience for our seniors, our seniors may also end up with uncoordinated care due to different care plans. We will streamline this entire process. From next month, seniors requiring multiple long-term care services will need only one comprehensive assessment done by the Integrated Community Care Providers using a standardised, internationally-recognised tool. Each senior will have a single community care plan developed based on this assessment. Every provider that the senior goes to will take reference from this care plan. Such an approach will ensure seniors benefit from a seamless experience and better coordinated care. We will progressively roll this out from October this year. We are enabling this new way of coordinating and delivering services through a common IT platform for community care providers. Mr Azhar Othman asked about teleconsultations. I refer the Member to Senior Minister of State Koh Poh Koon's recent response to a Parliamentary Question on this matter. Fundamentally, MOH agrees with the Member to make good use of technology to improve the healthcare experiences for our patients. 12.00 pm For example, the Productivity and Digitalisation Grant launched in 2022 has supported more than 240 projects, such as systems to automate showering and vital signs monitoring. We intend to enhance the grant to make better use of technology solutions in the healthcare sector, including harnessing robotics and AI.

    COMMITTEE OF SUPPLY – HEAD O (MINISTRY OF HEALTH) - 2026-03-05 · READ THE OFFICIAL RECORD

  12. Seniors can also join the SG Healthcare Corps to assist with basic patient care. Those aged 50 and above comprise 20% to 40% of volunteers across these programmes. We welcome more partners to join this effort. Let me turn to the topic of end of life. I agree with Mr Yip Hong Weng's point that we want our seniors to "leave well", or as the Chinese say, "安然离去". Since 2023, we have significantly expanded community palliative care services, enhanced subsidies and facilitated hospital discharges at the end of life. We want more Singaporeans to spend their final days at home, in an environment where they feel comfortable, surrounded by loved ones. The response has been positive. As of June 2025, the utilisation rate for home palliative care was around 90%. We will expand capacity as demand grows. We want to continue supporting families who wish to be with their loved ones at home during their final journey. Next, I assure Mr Cai Yinzhou and Mr Yip Hong Weng that we do track outcomes of our programmes, such as frailty prevalence, social participation and caregiver well-being. We do so with different parties, including research institutions. Let me now turn to care delivery transformation. By 2030, around 100,000 seniors will need help with at least one daily activity like eating or showering. They will likely need services from different service providers. We want their experience to be as seamless as possible and not have to run from pillar to post to receive these services. Technology will be a key enabler for tighter care coordination. I agree with Mr Cai's point that we want to make it easier for seniors to access social and health services. First, we have introduced Integrated Community Care Providers in 84 sub-regions around Singapore.

    COMMITTEE OF SUPPLY – HEAD O (MINISTRY OF HEALTH) - 2026-03-05 · READ THE OFFICIAL RECORD

  13. From 1 April, more than 5,600 eligible seniors and their caregivers can benefit from the enhanced Home Personal Care service, featuring home-based respite care, medication reminders and 24/7 technology-enabled monitoring for fall detection and incident reporting. Members also spoke about caregivers who are juggling work and care. We empathise with their challenges. Support is available through various Ministries' effort, for example, Flexible Work Arrangements and the Caregivers Training Grant, which helps to offset costs for training family caregivers and migrant domestic workers. Eligible caregivers can also tap on enhanced parental leave provisions such as the new Shared Parental Leave and Unpaid Infant Care Leave. We will continue to study Members' suggestions as we explore ways to better support our caregivers. Mr Victor Lye spoke about the unintended consequences of relying on PCHI to assess the caregiving circumstances of families. I appreciate his concerns. The PCHI means testing approach was discussed at the Budget debate last week. MOH takes dressing from this framework. However, individuals in difficult circumstances who require additional support can approach our medical social workers. Mr Lye gave a few suggestions on how we can improve the current framework. MOH will study his suggestions with the Ministry of Finance. Assoc Prof Terence Ho and Mr Eric Chua advocated for seniors to contribute to the community, including helping fellow seniors. I agree. Such involvement gives our seniors a sense of purpose. Seniors can tap on volunteering opportunities, with some organisations providing training and allowances. For example, as Silver Generation Ambassadors, they help conduct outreach to other seniors.

    COMMITTEE OF SUPPLY – HEAD O (MINISTRY OF HEALTH) - 2026-03-05 · READ THE OFFICIAL RECORD

  14. Since 2022, SGO has started preventive health visits, engaged more than 600,000 seniors and connected those with needs to services like AACs, Senior Care Centres (SCCs) and community mental health services. Recognising that younger seniors are more digitally savvy, SGO is reaching out this group through the LifeSG app. Since December last year, over 3,000 seniors have received personalised recommendations on services useful to them. For seniors who have not yet availed themselves to this service, please check out the LifeSG app. We have also grown the AAC network from 154 centres to over 230 over the last two years, now serving around 100,000 seniors. More than 150 SCCs provide day care services, including for those with dementia and respite care, and over 90 community outreach and intervention teams offer psychosocial support. We will continue to expand these services. Mr Ng Chee Meng, Mr Yip Hon Weng and Mr Fadli Fawzi spoke up for caregivers and referenced what other countries are doing to recognise and support caregivers. Like Members, we believe that caregivers play a vital role and we are doing more to support them. We are enhancing long-term care subsidies and grants. This year, we will raise the per capita household income (PCHI) threshold from $3,600 to $4,800. This will cover about seven in 10 households. I would like to assure Mr Ng Chee Meng and Ms Mariam Jaafar that these subsidies are not dependent on the number of Activities of Daily Living needs. Last year, caregivers of over 14,000 seniors benefitted from subsidised home and centre-based respite services. We will do more.

    COMMITTEE OF SUPPLY – HEAD O (MINISTRY OF HEALTH) - 2026-03-05 · READ THE OFFICIAL RECORD

  15. Sir, as shared by Minister Ong with this House earlier, welcome to super-aged Singapore. This trend will accelerate. By 2030, one in four Singaporeans will be 65 years and older, and one in four of them will be aged 80 and above. Within the next decade, by 2040, one in three seniors will be aged 80 and above. Seniors will likely need more support. For example, seniors use eight times the amount of hospital care than those who are younger. So, I agree with many Members who spoke on the implications. First, to caregivers. Today, it is not uncommon to see a working adult supporting elderly parents in their late 60s, who are in turn taking care of their parents in their late 80s. I certainly see many of such families in my constituency. With family size continuing to shrink, the burden on caregivers will get heavier. Secondly, there will be increasing pressure on the healthcare system. If half of our seniors have at least one chronic disease, we will have to care for close to half a million of them in 2030, up from about 400,000 of them last year. That is why we want our seniors to remain healthy for as long as possible. As the Minister said, it is not just about living longer, but living healthier for longer. Today, I will outline how we are doing so, with technology as an enabler. First, getting seniors to age well in the community. Second, wrapping care around them. Third, supporting healthcare providers to deliver better outcomes. As pointed out by a number of Members, many seniors face social isolation. A study has estimated that this risk is equivalent to smoking 15 cigarettes a day. Members would be familiar with the Silver Generation Office (SGO).

    COMMITTEE OF SUPPLY – HEAD O (MINISTRY OF HEALTH) - 2026-03-05 · READ THE OFFICIAL RECORD

  16. So, we are developing an AI tool for that and we hope to share more details in the later part of the year, but this is just one specific example how we are using AI technology. Not just "copying and pasting" what other countries are doing, but fine-tuning, adapting, customising for our local context, and do so in a way that creates value and adds that element of inclusivity for all Singaporeans. We hope to share more details later and hope to get the support of all Members.

    COMMITTEE OF SUPPLY – HEAD Q (MINISTRY OF DIGITAL DEVELOPMENT AND INFORMATION) - 2026-03-02 · READ THE OFFICIAL RECORD

  17. Sir, to elaborate on Minister Josephine's point about inclusivity, specifically around languages. As we know, Singapore is a multilingual society and different communities take a lot of pride in their languages, especially mother tongues. One part of the work is that MDDI looks at, specifically the "I" part of MDDI, is around information. There is a committee where we bring in academics, representatives from the media, the schools, around translation. That is the National Translation Committee, which I help to oversee. One project that we are working on, as a very good example of how we are thinking about practical tools for AI, is about translation. And translation is not just by using any tool, any large language models (LLMs), because you need local context, local nuances, for example, not everybody understands what "chope the table" is. So, how do you translate some of these local terms, especially local specific-context terms into different mother tongue languages? The National Translation Committee has been working with GovTech and Agency for Science, Technology and Research (A*STAR) on a number of LLMs and to fine tune a model for a local context. One of the objectives is to, hopefully, have a model which we can use by the later part of this year, to allow greater inclusivity and accessibility for those not speaking English to access our public-facing websites and other materials. And to support Public Service agencies translate many of the material, which is in English, into different mother tongue languages – Malay, Mandarin, Tamil – much more easily. And how can we do so across the board, at-scale, across the Public Service?

    COMMITTEE OF SUPPLY – HEAD Q (MINISTRY OF DIGITAL DEVELOPMENT AND INFORMATION) - 2026-03-02 · READ THE OFFICIAL RECORD

  18. We are working with industry experts to better support organisations in their efforts, including through training. We are also deploying two quantum-safe networks nationwide through the National Quantum Safe Network Plus (NQSN+) initiative. This provides additional options for businesses to integrate quantum-safe solutions, such as PQC and QKD, into their networks and systems. By supporting the provision of NQSN+ infrastructure and services, we aim to reduce the technical and financial barriers for organisations looking to implement quantum-safe solutions. Quantum-related technology is an evolving field. We are closely monitoring developments and will release guidance on this in due course. We are prepared to adopt different technological solutions if they prove to be effective and able to meet our needs. Sir, our digital infrastructure underpins our economy and daily life of citizens. MDDI is committed to improve the resilience and security of our digital infrastructure.

    COMMITTEE OF SUPPLY – HEAD Q (MINISTRY OF DIGITAL DEVELOPMENT AND INFORMATION) - 2026-03-02 · READ THE OFFICIAL RECORD

  19. GovTech will require Government vendors that manage critical systems and sensitive government data to meet Cyber Trust Mark requirements. CSA will also require the following three groups of entities who are operating, assessing or handling sensitive systems and data to meet Cyber Trust Mark Requirements. These are the CII owners, auditors conducting cybersecurity audits on CII systems and CSA's licensed Cybersecurity Service Providers providing penetration testing and managed security operations centre services. Consultations with relevant stakeholders are ongoing and these measures will be implemented progressively over the next two years. We are also looking ahead to prepare for tomorrow's threats. Mr Kenneth Tiong sought to clarify Singapore's approach to quantum-safe migration. We have been monitoring this technological trend closely. We also take the position that PQC will be the mainstream solution for quantum-safe migration. It is widely tested and internationally accepted. Singapore will take reference from the National Institute of Standards and Technology (NIST) standard as the baseline. As Mr Tiong pointed out, this is the position taken by many other countries. QKD is a complementary technology. It is more for niche application, like securing high assurance communications. Singapore takes a risk-oriented approach when it comes to quantum-safe migration. The Government is reviewing the practical steps we can take for quantum-safe migration, including adoption of PQC and the appropriate role of QKD, if needed. We have started investing in capabilities to support businesses in quantum-safe migration. In October 2025, CSA released a Quantum-Safe Handbook and Quantum Readiness Index to raise awareness of the associated risks.

    COMMITTEE OF SUPPLY – HEAD Q (MINISTRY OF DIGITAL DEVELOPMENT AND INFORMATION) - 2026-03-02 · READ THE OFFICIAL RECORD

  20. These devices can also be used unknowingly to launch attacks against others. The Government will do more to protect our citizens against these malicious actors. First, we will do more to ensure that the digital products that are sold in Singapore have baseline security safeguards in place. This will make these products harder to be compromised. Today, we require home routers to meet minimum cybersecurity requirements. This is because they are the gateways to networks and transmit sensitive information. They are currently required to meet Cyber Labelling Scheme, or CLS Level 1. CLS is like the energy efficiency tick label you see on household appliances, but instead of showing energy use, it tells you how cybersecure the device is. CLS ranges from Level 1 to Level 4, with Level 1 being the most basic standard. We have seen threat actors using more advanced techniques to exploit home routers. CSA and IMDA therefore intend to raise the minimum cybersecurity requirements for all routers sold in Singapore to the equivalent of CLS Level 2. Besides routers, IP cameras are another common target for cyber threat actors. Threat actors exploit these cameras to spy on individuals. Exploited images are even uploaded onto pornographic websites or used to blackmail individuals. To better protect citizens, CSA will explore requiring IP cameras to meet CLS Level 2, similar to home routers. CSA will continue to monitor and review if more digital devices should be required to meet minimum cybersecurity standards. Second, for organisations which handle sensitive data, including personally identifiable information, we are considering to introduce more stringent cybersecurity and data protection obligations. The Government will take the lead in this.

    COMMITTEE OF SUPPLY – HEAD Q (MINISTRY OF DIGITAL DEVELOPMENT AND INFORMATION) - 2026-03-02 · READ THE OFFICIAL RECORD

  21. CSA will partner with CII owners to test the use of technologies, such as AI, to help enhance their efficiency and effectiveness of their cybersecurity operations. We will share more details in due course. The defenders will also need to be competent in using these tools effectively. Therefore, CSA will work with training providers to design and curate courses that equip cybersecurity professionals with specialised knowledge and skills on how to deal with APT threats. The responsibility of securing our CII systems cannot just rest on the shoulders of our frontline cyber defenders. This is not just a technical matter. The Board and management of CII owners must also do their part. It is a leadership responsibility. We will equip them with the relevant knowledge. Since 2021, CSA has partnered the Singapore Management University to conduct the Cybersecurity Strategic Leadership Programme for C-suite leaders. The programme has trained 74 senior leaders thus far, such as Ms Dewi Anggraini from SMRT, Mr Andre Shori from Schneider Electric and Mr Kang Seng Wei from DBS. In view of the participants' positive feedback, CSA will conduct more runs of the Leadership Programme over the next few years. We intend to welcome the next batch of cybersecurity leaders by the second half of this year. Let me now turn to how we are protecting our citizens. Just last year, Members may have seen articles stating that attackers gained unauthorised access to thousands of Internet of Things (IoT) devices, including routers, around the world. Singapore has not been spared. Last year, attackers infected over 2,700 devices, such as baby monitors and routers. When such personal devices are hacked, citizens' privacy can be compromised and their daily activities being disrupted.

    COMMITTEE OF SUPPLY – HEAD Q (MINISTRY OF DIGITAL DEVELOPMENT AND INFORMATION) - 2026-03-02 · READ THE OFFICIAL RECORD

  22. Therefore, the Government will lean in to help CII owners to strengthen their defences and better respond to incidents. Typically, national security is the exclusive domain of governments, such as developing cutting-edge technological systems and training skilled operators to deal with various threat scenarios. We have decided to avail some of the Government’s expertise to the private sector, to level the playing field between the defenders and the attackers. We will help our CII owners “level up” and hold their own in a fight against APTs. First is intel. We will selectively share classified threat intelligence with our CII owners so that they are better able to spot and respond swiftly to threats that are attacking their systems. Second is tools. We will equip CII owners with proprietary threat detection systems to strengthen their abilities to detect malicious activities in their networks, especially those of state-sponsored APTs. These proprietary tools complement commercial threat detection systems used by our CII owners today. We have started deploying these tools in selected CII owners and will progressively deploy them across the rest. CII owners may need to incur cost to integrate these tools into their systems. We will consider funding support, if needed. 4.45 pm Even with these measures in place, we must be prepared that some threats will go undetected. This is why defenders must remain vigilant and constantly enhance their capabilities. This brings me to my next point on innovation. Threat actors are also not standing still. As pointed out by Mr Sharael Taha, autonomous AI agents are emerging threats. We must similarly harness technology to defend our critical systems.

    COMMITTEE OF SUPPLY – HEAD Q (MINISTRY OF DIGITAL DEVELOPMENT AND INFORMATION) - 2026-03-02 · READ THE OFFICIAL RECORD

  23. IMDA intends to provide guidance for areas such as managing virtualisation of infrastructure and credential management. We expect CII owners to comply with these requirements. CII owners currently engage third parties to conduct audits and regular penetration testings to verify their robustness of their defences. These reports are then submitted to CSA for review. In addition to relying on such third party reports, CSA wants to ensure that the security controls implemented by CII owners are not only tested and validated during audits but continuously strengthened. One way to do so will be to partner CII owners to do on-site reviews. CSA is currently discussing with the Sector Leads on the implementation plan. We will reach out to the identified CII owners when ready. Sir, regulations and compliance can only go so far. We need our sectors and our CII owners to do their part to defend their systems, consistently every day. Over the last year, I have visited the CII sectors, taking time to speak with the sector leads and the key CII owners. We have had closed door, candid discussions. Our Sector Leads and CII owners understand that the threat landscape has evolved and appreciate what is at stake. However, they shared with me that most CII owners are private companies whose business is in the delivery of essential services. They are not specialists in cybersecurity. Yet, they are up against the best-in-class, state-backed cyber threat actors. One of the Chief Information Security Officers told me that it is like he is bringing a knife to a gun fight. I empathise with his point of view. As I said, cybersecurity is a collective effort. We are on the same team.

    COMMITTEE OF SUPPLY – HEAD Q (MINISTRY OF DIGITAL DEVELOPMENT AND INFORMATION) - 2026-03-02 · READ THE OFFICIAL RECORD

  24. Sir, we have made major moves in the last decade to shore up our cybersecurity such as setting up CSA and introducing the Cybersecurity Act to protect our critical information infrastructure. But there is no room for complacency. I agree with Mr Vikram Nair’s cut to the Ministry of Home Affairs that threat actors, especially APTs, will only get more sophisticated. Mr Sharael Taha asked about the Government’s plan to protect our CII. Cybersecurity is a collective effort. CII owners must take responsibility of the systems they own and operate. The Government will also do our part. At this COS, I will speak about MDDI’s plans to first, update the cybersecurity standards and obligations; second, level up our CII owners; and third, strengthen capabilities in our cybersecurity workforce. Today, our CII owners are held to higher standards and stringent obligations are imposed on their critical systems or CII systems. This was a calibrated approach to balance national security needs and business costs. We have observed that threat actors are also targeting non-CII systems because they may be less secured and can be entry points into CII systems. CSA is therefore reviewing the scope of the current cybersecurity standards and obligations, and may include non-CII systems, such as networks that are interconnected with the CII systems. We are mindful not to impose unnecessary costs on CII owners, and will continue to take a risk-based, calibrated and pragmatic approach. Sector Leads may introduce additional sector-specific obligations that are adapted for their sector. For example, IMDA will be enhancing its cybersecurity regulations for the telecommunications operators, given the recent waves of attacks.

    COMMITTEE OF SUPPLY – HEAD Q (MINISTRY OF DIGITAL DEVELOPMENT AND INFORMATION) - 2026-03-02 · READ THE OFFICIAL RECORD

  25. On top of that, we participate actively in international bodies that set standards for resilience and cybersecurity for the space industry, for example, international standards, such as those from the International Organization for Standardization, Institute of Electrical and Electronics Engineers, and the Consultative Committee for Space Data Systems. Satellite operators and their partners adopt cybersecurity and resilience standards relevant to their specific use cases, such as for information technology, aerospace and telecommunications. And users that transmit sensitive data would also adopt stringent data encryption policies to protect the data in transit. Singapore participates actively in many of these committees. This space is evolving, the space technology is evolving rapidly, especially with commercial endeavours in this area, and Singapore continues to monitor the trends closely and participate actively.

    SECURING SINGAPORE’S CRITICAL INFORMATION INFRASTRUCTURE DEPENDENT ON SATELLITE AND SPACE SYSTEMS - 2026-02-26 · READ THE OFFICIAL RECORD

  26. Sir, I thank the Member Dr Choo for her supplementary questions. My sense of her questions is they stem from a concern around the resilience and security of our digital connectivity infrastructure, which is understandable. The digital connectivity infrastructure is increasingly essential for our economy and our daily lives. Let me set the context and elaborate on the point that I made earlier. More than 99% of our Internet traffic is via non-satellite means. Unlike other, perhaps, larger countries, Singapore is a hub for submarine cables. Most of our Internet traffic to other parts of the world is via submarine cables. We are a very submarine cable-densed hub in the world. That is the first point. The second: within Singapore, domestically, we have very robust digital connectivity infrastructure. We have fibre optic cables to almost every home and every business. In fact, Singapore is probably one of the world's first countries to have fibre optic cables to every address. That was more than 15 years ago. Complementing that is the mobile infrastructure networks. About five years ago, we rolled out the 5G standalone network, making us probably one of the first countries in the world to have nation-wide coverage of standalone 5G mobile coverage. These networks complement one another, and security and resilience are built into these networks in their design. So, 99% of our Internet traffic is through submarine cables to other parts of the world, and within Singapore, through the terrestrial networks, primarily fibre optic cables as well as our radio networks, which are mobile networks. That is the context in which we look at our digital connectivity infrastructure.

    SECURING SINGAPORE’S CRITICAL INFORMATION INFRASTRUCTURE DEPENDENT ON SATELLITE AND SPACE SYSTEMS - 2026-02-26 · READ THE OFFICIAL RECORD

  27. Sir, regardless of whether the companies are domiciled here or are domiciled outside Singapore, I think it is very clear that we have robust data protection framework to facilitate the secure processing of data. For the private sector, all organisations must comply with their obligations under the Personal Data Protection Act. Examples of these obligations include the Protection Obligation to protect personal data in their possession from unauthorised access and the Transfer Limitation Obligation, which applies when data is transferred to another country, regardless of whether they use the data for processing it for Singapore clients, or for something else, including training data for their AI models. These organisations must also comply with any additional data regulations which apply to their sectors, and as the Member has alluded to, that includes the Government as a sector, but there are also financial sectors, telecommunications, healthcare, logistics and so forth. These sectors may have its own specific set of requirements. In this House, we just had a debate on the Second Reading of the Health Information Bill as well as the Public Sector Governance Act, which impose similar requirements and safeguards to ensure high standards of data security. Such data can only be shared, and that is for the public sector data that the Member has mentioned if there is a legitimate purpose to support the public interest, and the Ministerial authorisation and contractual agreements for data protection and data security are in place. His other questions around the specifics of the commercial model, the business model, these have to be use case specific and driven by the use case problems and the relevant agencies looking after it.

    PROJECTED EXPENDITURE ON GOVERNMENT'S PURSUIT OF GLOBAL LEADERSHIP IN GROWTH AREAS AND AI-EMPOWERED ECONOMY - 2026-02-12 · READ THE OFFICIAL RECORD

  28. Sir, firstly, may I say that I am sorry to hear about that incident at Woodgrove. I know Edusave Awards mean a lot to parents and their children. And hearing this, I will ask my IMDA colleagues to take a look into this particular case. Secondly, on the issue of the how we assess SingPost's compliance with the QoS framework, IMDA gets an external, independent assessor to do a simulated letter test on a quarterly basis to determine whether SingPost has met the QoS requirements. And the results are published on IMDA's website. In terms of the comparison of our QoS standards with other countries, in fact, Singapore has one of the most stringent QoS requirements compared to many other countries. For example, in Hong Kong, for Hongkong Post, letters are typically delivered within one to three days. And for many other countries the letters are generally delivered between two and five days.

    TREND OF SINGPOST'S COMPLIANCE WITH POSTAL QUALITY OF SERVICE STANDARDS AND FEEDBACK RECEIVED ON SERVICE IMPROVEMENTS - 2026-02-04 · READ THE OFFICIAL RECORD

  29. Sir, just to clarify. Access to NEHR, even through the EMR, will be logged as an access to NEHR. But accessing a patient's records on the healthcare institutions' own EMR system is separate. It is an internal operations system for the hospitals, for the polyclinics or for the private healthcare clinics. So, it is quite different. But if you use EMR to log to NEHR, the logs will be recorded and tracked. 8.18 pm

    HEALTH INFORMATION BILL - 2026-01-12 · READ THE OFFICIAL RECORD

  30. Okay. Sir, it is quite clear that the insurance companies cannot assess NEHR for insurance or employment purposes. But in data breaches, I think it all boils down to the ethical considerations or how they access those data breaches in the first place, and that is something we have to work together with MAS, as the regulator, together with insurance companies, on understanding how they are using that information. And that is something we frown upon – using NEHR data for purpose of insurance. But it is a hypothetical scenario, something we have to think through. On a dedicated regulation around insurance, whether they should just be prohibited, to avoid putting the healthcare providers or professionals in a very difficult situation – this is something we are working through with the healthcare providers, the industry associations as well as together with MAS with the insurance industry. In fact, I had mentioned earlier in my closing speech that MOH has issued guidelines to the insurers and doctors on how we should think about the HIB when it is enacted. We will certainly work closely with MAS as the regulator for the insurance industry. But I think, it is quite clear, the principle and approach under the HIB is that we prohibit the use and access of NEHR information for employment and insurance purposes. And we have to work through the insurance associations, the MAS, the professional bodies, including the healthcare professional bodies for how it is implemented on the ground. But our assurance to the public and to those Members who spoke about it, is that our approach and position is quite clear. Did I answer all the Member's questions? Okay.

    HEALTH INFORMATION BILL - 2026-01-12 · READ THE OFFICIAL RECORD

  31. But I think what we want to avoid is having different standards of cybersecurity and data security requirements for different clinics based on the size. I think that is not the sensible and practical way to do it, as mentioned by different Members earlier. It is about making sure that different clinics and different touch points to the NEHR system meet the appropriate level of cybersecurity and data security requirements and finding ways of uplifting the different GPs and we will certainly do so in the coming months and years. If the Member could clarify on third question for me, please?

    HEALTH INFORMATION BILL - 2026-01-12 · READ THE OFFICIAL RECORD

  32. Sir, I thank the Member for his clarifications. I believe there are four clarifications and I will take them in turn. One about offering cyber insurance to GP clinics. Can I just get the Member to confirm that this is what he is asking about? Okay. Sir, in my speech, I did outline a few measures that we are putting in place and will continue to put in place to support GPs, especially smaller GPs, to comply with the HIB requirements, including data security and cybersecurity. And there are a number of support packages we are discussing with them. These details we will make known in due course. So, that is one. We are supporting them, and we want them to travel the journey together with us. And there is broad support among the doctors, including those smaller GPs who see the value of contributing to and assessing NEHR, and most of the GPs are already onboard. They understand the need for the cybersecurity and data security requirements under the Bill to protect the data, and we are working with them to look at the various whitelisted services and management systems they can adopt to meet the requirements. In terms of cybersecurity insurance, this is something we certainly will consider, but today, unfortunately, there is not a very mature market for cybersecurity insurance, specifically for GPs. So, if this is something useful, we will certainly consider as part of the support packages and discussions with the relevant stakeholders. Second, about flexibility for senior GPs or smaller GPs. I mentioned the support packages. We do intend to provide for them, including funding support, whitelisting service providers and the different mentioned systems.

    HEALTH INFORMATION BILL - 2026-01-12 · READ THE OFFICIAL RECORD

  33. Sir, we will consider their readiness to meet the various responsibilities that come with sharing health information, such as the various requirements under the Bill. Any community health partners which are added will be publicly communicated, including through MOH's website. Sir, to conclude, the HIB will help us achieve the goal of "One Patient, One Health Summary, One Care Journey". We will work with and support healthcare providers and healthcare professionals in achieving this goal. Through our collective efforts, Singaporeans can benefit from better coordinated care, enhanced quality of care and lower costs. Sir, I believe I have addressed the questions raised by all the Members and I beg to move.

    HEALTH INFORMATION BILL - 2026-01-12 · READ THE OFFICIAL RECORD

  34. Referencing my earlier example of Mr Lim, the 72-year-old gentlemen who is managing his diabetes condition. He stopped visiting his local polyclinic and his polyclinic has faced difficulties in contacting him to obtain consent. The HIB will address this by providing an additional channel for the sharing of health information. With the HIB, Mr Lim's polyclinic can potentially share his contact information and broad health risk indicators, such as an indication of the presence of frailty or chronic conditions with AIC, without the details of specific medical conditions. AIC can then prioritise engaging Mr Lim to check on his well-being and link him with the necessary support as needed. On whether to include other community health partners, like Active Ageing Centres and use cases in the future, MOH will carefully assess whether these other entities and use cases facilitate quality care and care continuity for patients. We will consider their readiness to meet the various responsibilities that come with sharing health information, such as cybersecurity and data security requirements under the Bill and we will consult key stakeholders. 8.07 pm

    HEALTH INFORMATION BILL - 2026-01-12 · READ THE OFFICIAL RECORD

  35. Sir, healthcare professionals have asked whether they will be required to access NEHR for each consultation and whether they need to review each record in NEHR when they do access it. Accessing patients' NEHR information is not compulsory under the HIB. NEHR supports and complements existing clinical practices, including good history-taking and physical examinations. The HIB does not change existing standards and practices. Healthcare professionals are encouraged to consider a range of factors before deciding whether NEHR access is required for a particular consultation, such as whether more information is required based on the information gleaned from the history-taking and physical examinations or whether health records in NEHR would be relevant to the particular consultation. Sir, we will continue to work with respective professional bodies to disseminate these guidelines to all healthcare professionals. We will also support professional bodies in ensuring their members' compliance with the Bill. Sir, on this note, I would also like to take the opportunity to thank Ms Kuah for co-chairing the NEHR Guidelines Workgroup Committee. Sir, let me now turn to health information that sits outside of NEHR and the clauses in the HIB that will enable the sharing of such information. Ms Pereira enquired about the timeline for enabling community health partners' sharing of such health information to be covered under the HIB. Mr Louis Chua asked why the HIB enables the sharing of non-NEHR health information without consent. Today, AIC shares data with community partners to enable them to engage and provide befriending services or care to seniors. However, on the ground, there are difficulties with obtaining consent for data-sharing.

    HEALTH INFORMATION BILL - 2026-01-12 · READ THE OFFICIAL RECORD

  36. MOH has worked closely with healthcare providers and professionals and have been engaging them over the last few years. We have taken their feedback on board. First, the Bill will commence in early 2027 to allow sufficient time for healthcare providers and professionals to familiarise themselves with the Bill's requirements. Second, to support their transition, guidance materials and dedicated support channels will be made available from the second quarter of this year to help providers and professionals understand their options and navigate the process. Third, should there be challenges complying with the Bill by the required timelines, MOH will consider the facts of each case carefully and assist where appropriate. Sir, now let me turn to the comments and suggestions for support for healthcare professionals. Dr Hamid Razak and Dr Choo Pei Ling enquired about how MOH intends to support healthcare professionals, noting that they have concerns about increased liability arising from the HIB. I think Dr Haresh also pointed out concerns from healthcare professionals on medical and legal liabilities and how they should think about it. We have been engaging the professional bodies and speaking to them over a period of time, and have taken their suggestions, ideas and feedback on board. MOH will publish a set of guidelines to support healthcare professionals' appropriate access and use of NEHR information. These guidelines will apply not only to doctors but also to other healthcare professionals accessing NEHR, such as dentists, nurses and allied health professionals. Let me share some examples of the guidance that will be provided.

    HEALTH INFORMATION BILL - 2026-01-12 · READ THE OFFICIAL RECORD

  37. Across the GP sector, more than 80% of them are on Clinic Management Systems. So, there are a large number of clinics, a vast number of them, already embarking on the digitalisation efforts. And we are supporting the remaining clinics to digitalise and onboard suitable systems to enable better delivery of care. To Ms Joan Pereira's query if smaller clinics could collaborate on shared resources, this is a good idea for smaller clinics to explore. Currently, clinics can already join the Primary Care Networks (PCNs). PCNs not only provide peer leadership and support to small or solo GP practices, they also offer administrative assistance through the PCN headquarters. The PCNs will continue to offer advice and support to member clinics, share resources to smoothen the clinics' journey in digitalisation and fulfilling NEHR contribution. We will further consider Mr Dennis Tan's and Ms Pereira's suggestions on shared IT support services as part of the roll-out. I would like to assure Members that MOH is mindful of the administrative effort required to contribute information to NEHR. And this is why we encourage all healthcare providers to adopt a whitelisted HIMS, which automates the process of contributing relevant health information to NEHR. That said, for smaller clinics that may require more time to digitalise, we will make available an alternative contribution channel so that these clinics will be able to start contributing data when required, while MOH continues to work with them on their digitalisation plans. Ms Kuah reflected concerns from the ground about time and effort needed for compliance, and if MOH will take these considerations in event of non-compliance, especially in the initial period.

    HEALTH INFORMATION BILL - 2026-01-12 · READ THE OFFICIAL RECORD

  38. We would like to reassure providers that with this support in place, healthcare providers will be better enabled and supported to implement the relevant requirements. We acknowledge the concerns raised by Mr Yip about potential fear-mongering tactics by some vendors. To address this, MOH is developing basic service packages specifically tailored to the needs of solo practitioners and small and medium enterprises so that they can self-help and prevent overselling of unnecessary services. We are also establishing clear guidelines for whitelisted service providers on appropriate engagement practices and transparent pricing. Healthcare providers that encounter unethical practices by whitelisted service providers can report them to MOH. Additionally, we recognise that there is a small group of what Members call the pen-and-paper clinics that may face challenges in digitalising their clinics and meeting the Bill's requirements. As Members highlighted, these clinics may require additional implementation support. Sir, digitalisation is becoming key to the provision of healthcare. It is critical for clinical documentation, transmission of information between providers and laboratories, and supports timely coordination with other providers. Today, most clinics already have some form of IT system for clinic management, accounting and billing. Going forward, digital tools will increasingly become important, enabling clinics to rely on clinical decision support systems to close care gaps and deliver safer care. Therefore, in recent years, we have strengthened the digitalisation in the private primary care sector to support Healthier SG and other national initiatives. Today, about 1,100 Healthier SG clinics are onboard suitable Clinic Management Systems and contribute to NEHR.

    HEALTH INFORMATION BILL - 2026-01-12 · READ THE OFFICIAL RECORD

  39. To Mr Fadli Fawzi's query on how significant harm will be defined, if a data breach causes or is likely to cause significant harm to an individual, for example, if it involves disclosure of health information that may be deemed more sensitive, healthcare providers must notify the affected individuals on or after notifying MOH. Additionally, MOH will only require significant breaches to be notified in alignment with the approach under existing legal frameworks such as the PDPA. These details will be set out in subsidiary legislation. Let me now turn to the support measures for healthcare providers. I appreciate the concerns that Members have raised about the support needed for smaller providers, especially smaller GP clinics. I mentioned earlier that with Healthier SG, most GP clinics have already onboarded to NEHR, with the support of MOH. MOH recognises the importance of providing healthcare providers with reasonable time to comply with the HIB requirements and will offer the necessary support for healthcare providers to prepare and adapt their systems and processes. We see them as a valuable partner in supporting the continuity of care in the community. Our support package will include measures to defray costs of subscription to whitelisted HIB-compliant HIMS to digitalise their clinical records and to contribute data to NEHR more seamlessly. There are also other support packages to engage professional services from whitelisted service providers to implement cyber and data security requirements. Additionally, resources, guidance materials and training programmes will be available to help healthcare providers, including our community health partners, to meet the HIB cybersecurity and data protection requirements on an ongoing basis.

    HEALTH INFORMATION BILL - 2026-01-12 · READ THE OFFICIAL RECORD

  40. Examples of these requirements include the use of anti-malware solutions and firewalls in computers, the backing up of essential business information and data storage practices. Healthcare providers will also need to train their staff on cyber-hygiene and data governance practices to ensure safe and secure access to health information. On the incident management framework, healthcare providers and their HIMS providers must put in place a framework to identify, resolve and mitigate cybersecurity and data breaches. This includes notifying MOH of prescribed security incidents and implementing mechanisms and processes to detect and respond to incidents such as ransomware attacks or unauthorised access to NEHR. But even with the best preventive measures, a data breach may still occur. Healthcare providers will be required to notify MOH and affected individuals of significant data breaches. Once notified, MOH will work with the healthcare providers to understand the root cause of the breach, the extent of the data exposed, the potential harm to patients, and the containment and mitigation measures that need to be implemented. In the event of any data breach, healthcare providers are expected to take necessary measures to remediate the situation and prevent such incidents from occurring again. Where MOH is of the view that the mitigation or preventive measures are inadequate, we will work with the healthcare providers on implementing the appropriate measures.

    HEALTH INFORMATION BILL - 2026-01-12 · READ THE OFFICIAL RECORD

  41. Timely hardware, software and application upgrades are implemented, which include security patches as well as security controls to detect and block suspicious traffic from external sources. MOH and Synapxe will continue to work with the Cyber Security Agency of Singapore, GovTech and independent auditing firms to conduct regular cybersecurity reviews and security assessments. I would also like to thank Mr Yip for his feedback on the need to make NEHR more user-friendly. I assure him we will continue to invest in the improvement of NEHR's technology and features to help healthcare providers quickly identify the most relevant information for their patients. Relatedly, Mr Yip, Dr Choo, Mr Hoe, Ms Joan Pereira and a number of Members like Mr Fadli Fawzi, Mr Tiong and Mr Dennis Tan asked for further details on the cybersecurity and incident management requirements, including their feasibility and the availability of MOH support. Sir, I would like to clarify that today, healthcare providers are already required to make reasonable security arrangements to protect personal health information. This is an existing requirement in laws such as the Personal Data Protection Act and Healthcare Services Act 2020. The Bill's cybersecurity and data security requirements are based on these existing standards and legal requirements, but contextualised for the healthcare sector. These include frameworks such as the Cyber Security Agency of Singapore's Cyber Essentials Mark and the Infocomm Media Development Authority's Data Protection Essentials, which were designed to be accessible and implementable by smaller organisations.

    HEALTH INFORMATION BILL - 2026-01-12 · READ THE OFFICIAL RECORD

  42. Primarily, NEHR is for continuity of care and for public health purposes, not for commercial purposes. Mr Chua suggested allowing Access Restrictions to be applied to the sharing of NEHR information for broader public health interest purposes such as policy planning and analysis. This is not advisable as it could lead to incomplete analysis and would undermine the utility of NEHR informing national policies and planning. Sir, now, let me turn to the third topic on resilience and security of the system. A number of Members, including Mr Yip and Mr Dennis Tan asked about the resilience and security standards for NEHR, particularly in light of the SingHealth data breach in 2018. I would like to reassure Members that MOH has taken in the recommendations under the Public Sector Data Security Review Committee conducted in 2019. And NEHR is complying with the relevant resilience and security requirements for Government systems recommended by this committee. NEHR is subject to security and resilience audits, with vulnerability scans, penetration tests and exercises carried out regularly to ensure that systems are secure and backup systems are operational in the event of a downtime. I must add that, really, the lesson from the SingHealth data breach is that we were open and transparent about the issue, convened a Committee of Inquiry, learned our lessons, applied them and made sure we work very hard to prevent such breaches from recurring. We took those lessons to heart as we built up our cybersecurity and data security standards. We have done so over the years. Additionally, there are several lines of defence before the NEHR database, with intrusion detection at various parts of the network.

    HEALTH INFORMATION BILL - 2026-01-12 · READ THE OFFICIAL RECORD

  43. De-identified NEHR information may also be needed for public policy analysis and planning purposes, such as to review healthcare utilisation trends or to analyse the cost effectiveness of medicines. I have given some examples to the queries raised by Members on the scenarios in which those clauses apply. As a general rule, MOH will ensure requests for NEHR information have sound basis before supporting it. For all supported requests, whether from private entities such as academic institutions and health-related organisations or from public agencies under other written laws, MOH will share only the necessary data required to fulfil the intent. Let me give another example to illustrate my point. For example, for requests from the Police to locate missing persons, we only provide administrative information about visits to healthcare providers without details of the patient's medical condition. This enables the Police to confirm if missing persons have been warded in an emergency and in turn alert worried family members. Requesting parties will also be required to protect the data against loss and against unauthorised access, use, modification, disclosure or other misuse. Mr Chua and Mr Fadli asked specifically about the use of NEHR for research. De-identified NEHR health information may be shared through established platforms such as TRUST under the National Research Foundation for research purposes. This could include training for artificial intelligence models. Where requests are received from commercial parties, possibly for commercial purposes, we are extremely cautious in assessing such requests, including whether the sharing of such data is helpful in contributing to better healthcare and better health outcomes.

    HEALTH INFORMATION BILL - 2026-01-12 · READ THE OFFICIAL RECORD

  44. Prior to changing the scope of providers that may access NEHR, we will consult relevant stakeholders and publicly communicate the changes through the MOH website. Sir, Mr Louis Chua, Mr Yip and Mr Fadli Fawzi also asked about the sharing of NEHR information for non-patient care purposes under the HIB or other written laws such as the Criminal Procedure Code 2010. NEHR was set up to facilitate patient care and the information within NEHR is primarily intended to be shared across healthcare providers for that purpose. This is a consistent principle adopted by other jurisdictions that we have studied. MOH is of the view that identifiable health information should generally be interpreted and managed by qualified healthcare professionals. Parties from outside the healthcare sector generally do not require identifiable health information for non-healthcare-related purposes. Therefore, when parties seek MOH's views on this, MOH will suggest that such parties consider alternative data sources or ways of achieving its policy intent instead of using NEHR information or involve qualified healthcare professionals to partner parties in meeting the intent. For public health purposes under the HIB, NEHR information may be needed in certain situations, for example, to quickly identify and enable healthcare providers to contact affected patients in the event of a major drug contamination incident. Another example is in the event of an outbreak of a serious infectious disease, there may not be sufficient time nor would it be feasible to seek consent from individuals to use their NEHR information to contain the outbreak.

    HEALTH INFORMATION BILL - 2026-01-12 · READ THE OFFICIAL RECORD

  45. To Dr Hamid's query on whether populations who receive care outside the conventional system, such as prison inmates, would benefit from the Bill, I would like to assure the Member that all Singaporeans key health information, including those under the care of the Singapore Prison Service, will be contributed to NEHR. To Mr Fadli's query, NEHR is designed to be a "One Health Summary". We will only require the contribution of health information prescribed in the First Schedule of the Bill and not the doctor's detailed clinical notes. The design of the system and the data pipes take in only the prescribed data types. For example, if a patient has diabetes and is prescribed with insulin, the doctor will only contribute "diabetes" as a diagnosis and "insulin" as the medication. So, only information that is needed for continuity of care. Sir, let me now turn to Dr Choo Pei Ling's suggestion to extend NEHR access to other users, such as allied health professionals working outside of licensed institutions. I would like to thank Dr Choo for her suggestion to extend the access to other users. However, I would like to reiterate that the primary purpose of the NEHR is to support and enhance the continuity of care for patients. Hence, the HIB provides for NEHR access for licensed healthcare institutions. Within these institutions, NEHR access is only provided for healthcare professionals with clinical or care planning roles. This is the core principle governing NEHR access. However, we recognise that as care models develop and evolve, we may need to grant new providers or services access to NEHR. In doing so, we will consider factors such as whether NEHR information is required for that role and whether the provider or service is able to comply with the HIB's requirements.

    HEALTH INFORMATION BILL - 2026-01-12 · READ THE OFFICIAL RECORD

  46. Dr Haresh asked if mandatory contributions, coupled with access will encourage episodic care affecting initiatives, such as Healthier SG, which encourages building a trusted relationship between patients and their family doctors. Mr Hoe asked about the requirement to contribute information in a timely and accurate manner and the treatment of overseas medical records. Mr Fadli Fawzi asked about the level of details of key health information to be contributed to NEHR. The Bill requires healthcare providers to contribute accurate and complete health information in a timely manner. This ultimately benefits patients by enabling their healthcare providers to access all relevant health information to provide the best care. Take a Healthier SG family doctor as an example. The bill will allow the doctor to deliver better patient care, taking account of the patient's medical history across different settings, including private specialist clinics. This enables the doctor to build a trusted, and hopefully lifelong relationship towards better health outcomes. And to help healthcare providers comply with the contribution requirements in the Bill, we have whitelisted health information management systems (HIMS) that have the requisite technical features and encourage all healthcare providers to subscribe to these HIMS. On overseas medical records, the HIB only applies within Singapore. Nevertheless, patients can bring their overseas health records to their local healthcare providers, who may then incorporate relevant information into their own medical records and once incorporated, these records will be contributed to NEHR.

    HEALTH INFORMATION BILL - 2026-01-12 · READ THE OFFICIAL RECORD

  47. When insurers request for health information, the current practice is for healthcare providers and professionals to rely on their medical records and patient interactions, which include history-taking, as well as physical examinations, to prepare the necessary reports for the insurer. This will continue to be the case after the HIB is enacted. NEHR must not be accessed for such insurance- and employment-related checks. To Mr Tiong's query, healthcare providers and professionals should prepare separate medical reports, memos or clinical summaries for the insurer, instead of providing their raw medical records, such as printouts from their clinical medical records. This is because raw medical records contain extensive information, including potentially irrelevant information. Where NEHR information is referred to during a medical examination, information relevant to the episode would be validated or confirmed with the patient during history taking and may be captured in the provider's own medical records, together with the doctor's clinical assessment. Such information would then be treated as part of the provider's own medical records. Healthcare providers and professionals will need to carefully assess what information in their own medical records is relevant and necessary to include in the report provided to an insurer. MOH has issued a circular to healthcare providers and a guidance note to insurers to clearly state these positions. Healthcare providers may inform MOH if there are any inappropriate requests for NEHR information for insurance purposes. Sir, let me now address questions about the contribution requirements in the Bill.

    HEALTH INFORMATION BILL - 2026-01-12 · READ THE OFFICIAL RECORD

  48. On this, I would like to reiterate three points that I have made earlier in my opening speech. First, insurers and employers do not and will not have access to NEHR. Second, healthcare professionals are also prohibited from accessing NEHR for employment or insurance purposes, except for prescribed statutory medical examinations, which I will talk on later, or where authorised by other written law or Order of the Court. Third, the HIB imposes strict penalties for any unauthorised access to NEHR, with higher penalties for prohibited employment or insurance purposes. Dr Wan Rizal asked whether statutory medical examinations may provide a backdoor for employers to gain access to NEHR information. The list of statutory medical examinations that is in the Bill is tightly scoped to those where NEHR access is necessary to protect the public and safeguard the health of the individual. This is the key principle. We have no plans to expand this list to include employment-related screenings that are not necessary to protect the public and the individual. The current practice for employment-related screenings will remain – where doctors rely on their history-taking, clinical assessment and their own existing medical records for the individual, if any, without access to NEHR. On Mr Yeo's query, on whether MOH would consider allowing individuals to give consent for their NEHR information to be accessed for insurance purposes for some situations, I would like to reiterate that NEHR is primarily for patient care purposes.

    HEALTH INFORMATION BILL - 2026-01-12 · READ THE OFFICIAL RECORD

  49. Patients may, however, restrict access to all healthcare providers, or from the second half of 2026, limit access so that only select healthcare providers, such as their own Healthier SG clinic, may access their NEHR information. Whilst in place, restricted healthcare providers will not be able to, unless required by other written law, access the patient's NEHR information, except for the essential subset of records that cover allergies and vaccination records. Next, I would like to also thank Members like Mr Yip, Mr Hoe, Mr Chua, Mr Fadli and Ms Kuah Boon Theng for highlighting the importance of educating the public on the implications of placing Access Restrictions and supporting patients who are less digitally savvy. We are likewise mindful of this point. MOH will work with the healthcare institutions to set-up physical touchpoints for those who require help with placing Access Restrictions and help them understand the implications of doing so. Alternatively, patients may seek the help of trusted individuals, like their family members and caregivers to place Access Restrictions on their behalf. Mr Yip raised the concern that the act of placing an Access Restriction may itself become a source of stigma or adverse inference. This Access Restriction will be known only to the healthcare providers managing the patient and all healthcare professionals are bound by their respective professional bodies' ethical codes and ethical guidelines to treat all patients fairly and without prejudice. Let me now move to queries around NEHR access by insurers and employers. We understand Singaporeans' concerns about the potential discrimination or stigmatisation they may face if their health information is revealed to their employer or insurer.

    HEALTH INFORMATION BILL - 2026-01-12 · READ THE OFFICIAL RECORD

  50. As I have mentioned earlier, care delivery is team-based and increasingly multi-disciplinary. It is not operationally feasible to restrict access to specific healthcare professionals but not others, when they all work in a team, in the same healthcare institution. This is aligned with good practices we observed elsewhere, like in Australia. Health information will be contributed to NEHR even if Access Restrictions are in place. As pointed out by Dr Hamid, who brings in a practitioner's perspective, an incomplete record, including if individuals opt not to contribute select healthcare information deemed to be more sensitive, will significantly reduce the utility of NEHR in supporting healthcare professionals to provide quality care and could pose a safety risk. In certain situations, access to such records in a timely manner could save lives, as I mentioned earlier in my opening speech. One example would be when a doctor or pharmacist needs to have the ability to access drug interactions and his job is hindered due to incomplete medication information, the patient could suffer unintended consequences, especially in emergency situations when the patient may not be able to respond. It also ensures that if patients change their mind in future, for instance, when they are older and remove such Access Restrictions, there would be no gap in NEHR information and this was a valuable learning point when MOH colleagues engaged other jurisdictions. The approach we are adopting aims to achieve a balance between patient choice and ensuring that patients receive better and more coordinated patient care. Sir, in summary, healthcare providers would be granted access to NEHR to support patients' continuity of care across healthcare settings by default.

    HEALTH INFORMATION BILL - 2026-01-12 · READ THE OFFICIAL RECORD