Cybersecurity 2026

SINGAPORE Law and Practice Contributed by: Lim Chong Kin, David N Alfred, Albert Pichlmaier and Goh Boon Yeow, Drew & Napier LLC

as described in the First Schedule of the Health Prod - ucts Act 2007. At the time of writing, Singapore’s parliament is also debating the Health Information Bill, which will estab - lish a dedicated statutory framework for contribut - ing to and accessing the National Electronic Health Record system, as well as for wider health information sharing and protection. Under the Health Information Bill, healthcare providers are required to report a con - firmed cybersecurity incident or data breach to the Ministry of Health, with an initial report required within two hours and a detailed incident report required with - in 14 days. This framework also includes cybersecu - rity and data security requirements for healthcare pro - viders and other persons who contribute to or access the National Electronic Health Record system.

296 CHAMBERS.COM

Powered by