Cyber Essentials mark — HIA Entities

Singapore clinics now have to prove they protect patient data.

Cyber Essentials (HIA Entities) is the certification that proves it. MedPath, the team that builds ClinicPlus, gets your clinic through it: the paperwork, the fixes, and the audit.

The obligation comes with being connected to NEHR and holding patient records. It is not optional, and the clinic is the one accountable for it — not your IT supplier.

The free call

Thirty minutes, and you know where you stand.

  • A straight answer on whether this applies to your clinic.
  • The shape of your gap — what has to be written, what has to be configured, what has to be replaced.
  • A dated plan, after we have looked at your setup.

No obligation and no quote on the call itself.

Scope

Does this apply to my clinic?

  • 01Your clinic is connected to NEHR.
  • 02You hold patient records in any form — including paper files.
  • 03You use a clinic system supplied by a vendor.

If any one of these is true, this applies to your clinic, whatever its size. A two-doctor practice is held to the same standard as a twenty-doctor one.

The basics

What Cyber Essentials actually is

Who requires it

It is a CSA certification, issued by a certification body appointed by CSA. For a clinic it is tied to your obligations as a HIA entity.

What it looks at

The everyday basics — staff habits, devices, who can open what, backups, and what you do when something goes wrong — plus how health information is handled, on paper as well as on screen.

What it takes

A set of documents you almost certainly do not have yet, some changes to how your machines and accounts are set up, and one audit.

The self-assessment

This is what you would have to answer on your own.

The assessment is 56 mandatory requirements. Answer “No” to any one of them and the whole assessment fails.

Mandatory requirements

Answered “Yes”

Skipped letters are recommended, not mandatory, so they are left out. A.10 keeps the B and C numbering of its HIA-specific source.

Each cell is one mandatory requirement.

Starting point: all 56 answered “Yes”, ready for certification.
Read all 56 requirements
  1. A.1.aSecurity & data-protection training for all staff
  2. A.1.bWritten cyber-hygiene guidelines for daily work
  3. A.2.aUp-to-date hardware & software asset inventory
  4. A.2.fRemove unauthorised and end-of-support assets
  5. A.2.gRisk-assess and get management sign-off to keep an EOS asset
  6. A.2.hAuthorisation process before new hardware/software goes in
  7. A.2.iRecord the approval date in the inventory
  8. A.2.jNo unapproved hardware or software in use
  9. A.2.kWipe health information before disposing of hardware
  10. A.3.aInventory of business-critical data with retention periods
  11. A.3.cProtect that data — encrypt at rest and in transit
  12. A.3.dStop staff, vendors and contractors leaking data
  13. A.3.eSecurely destroy paper and physical media
  14. A.4.aAnti-malware installed on every endpoint
  15. A.4.bScan files automatically on access
  16. A.4.cSignature updates run automatically
  17. A.4.eFirewall configured and deployed
  18. A.4.hStaff install only authorised software
  19. A.4.iStaff use only trusted networks for clinic data
  20. A.4.jSuspicious email reported immediately
  21. A.5.aMaintain an inventory of all accounts
  22. A.5.bInventory covers user, admin, vendor and service accounts
  23. A.5.cDocumented approval to grant and revoke access
  24. A.5.dStaff can reach only what their role needs
  25. A.5.eRemove dormant, shared and duplicate accounts
  26. A.5.fAdmin accounts approved, and not used day to day
  27. A.5.gThird-party access limited and removed when done
  28. A.5.hVendors handling health data sign an NDA
  29. A.5.jPhysical access control — locked cabinets, cable locks
  30. A.5.lDefault passwords replaced with strong passphrases
  31. A.5.mAccounts lock after repeated failed logins
  32. A.5.nPasswords changed on any suspected compromise
  33. A.5.oMFA on admin access to systems holding health data
  34. A.6.aSecurity baseline applied to devices and servers
  35. A.6.bReplace weak protocols — HTTPS, WPA2/3, no SMBv1
  36. A.6.cTurn off unused services and features
  37. A.6.dVendors must secure their own delivery environment
  38. A.6.fDisable auto-connect to open networks and autorun
  39. A.6.gAudit logging switched on
  40. A.7.aCritical patches applied promptly from trusted sources
  41. A.8.aIdentify and back up business-critical data and systems
  42. A.8.bBack up on a schedule matched to your tolerance for loss
  43. A.8.fBackups protected from unauthorised access
  44. A.8.gBackups stored separately from the live environment
  45. A.9.aA written incident response plan with roles and timelines
  46. A.9.bEvery staff member with IT access knows the plan
  47. A.10.B.5Copies of health information only by authorised people
  48. A.10.B.6Keep possession of copies made outside the clinic
  49. A.10.B.7Rules for carrying and emailing health information
  50. A.10.B.8Mark documents that contain health information
  51. A.10.B.9Assess how marking is applied
  52. A.10.C.6Review your safeguards periodically
  53. A.10.C.7Run compliance checks or audits
  54. A.10.C.8Fix any lapse promptly
  55. A.10.C.10A business continuity plan
  56. A.10.C.14Report incidents to MOH within the required thresholds

Sections A.1–A.10

What it actually checks

The mandatory clauses are not spread evenly. Two sections carry 23 of the 56 between them.

CodeSectionMandatoryWhat it means for a clinic
A.1People2Everyone who touches patient data is trained, and daily practice is written down.
A.2Hardware & Software7You know every device and application in the clinic, and unsupported ones are removed or formally accepted.
A.3Data4You know what data you hold, how long you keep it, and it is encrypted.
A.4Virus & Malware7Anti-malware and a firewall on everything, and staff who know what to do with a strange email.
A.5Access Control13Who can open what, approved by whom, removed when they leave. The heaviest section.
A.6Secure Configuration6Devices are set up to a baseline instead of left on factory defaults.
A.7Software Updates1Critical patches go on promptly, from the vendor.
A.8Backup4Critical data is backed up on a schedule, protected, and kept apart from the live system.
A.9Incident Response2A written plan, and staff who know it exists.
A.10HIA Data Security10The health-information rules: copies, marking, review, continuity, MOH reporting.

The questionnaire runs to 85 clauses. 56 are mandatory and decide pass or fail; the other 29 are recommended.

Common gaps

Where clinics actually fail

Three findings account for most of the remediation work we see.

A.2

Windows 10 reached end of support.

Most clinic front-desk and consult-room PCs are now unsupported, and A.2 requires you to remove them or formally accept the risk with management sign-off. This is usually the only line item that costs real money.

A.5

Access control is 13 of the 56.

Shared logins, one admin account everyone uses, staff who left last year still enabled, no record of who approved what.

A.3

Encryption at rest.

A clinic holds enough personal data to trigger the requirement, which means full-disk encryption on every machine — and evidence of it.

Documents

What you have to hand in

The certification body expects seven documents, plus the completed self-assessment.

  1. 01Scoping statement
  2. 02Organisation chart
  3. 03Business description
  4. 04System & network diagram
  5. 05Device / system inventory
  6. 06Software / service inventory
  7. 07List of operating locations
  8. +The completed self-assessment

A clinic has none of these on day one. We produce all of them.

Process

How we work

Five steps. Most of the work sits with us; what needs your clinic is scheduled, not open-ended.

  1. 01

    Scoping workshop

    Decide what is in and out, and keep it as small as is honest.

  2. 02

    Gap assessment

    All 56 scored, and every gap tagged write it / configure it / buy it.

  3. 03

    Document pack

    Policies, procedures, registers and blank forms your team signs.

  4. 04

    Remediation and evidence

    Configuration changes, screenshots, training, the register.

  5. 05

    Audit

    We submit with you and stay through the audit.

The timeline is driven by hardware replacement and account clean-up, not by paperwork. We give you a dated plan after step 2.

Engagement

Three engagement levels

Quoted by clinic size and endpoint count.

Assessment

For clinics that want to know where they stand.

  • Scoping workshop
  • Gap report against all 56 mandatory requirements
  • Prioritised remediation roadmap
Request a quote

Guided

For clinics with someone in-house to do the work.

  • Everything in Assessment
  • Full document pack — policies, procedures, registers
  • Remote remediation support
Request a quote

Full

Most complete

For clinics who want it handled.

  • Everything in Guided
  • On-site remediation and evidence collection
  • We submit with you and stay through the audit
  • We handle the certification body
Request a quote

Certification body audit fees are charged separately by the certification body.

Why MedPath

We did the harder version of this ourselves.

HIMS Vendors edition: all 85 clauses

The HIMS Vendors edition — all 85 clauses, 46 controlled documents. Certified.

We build clinic software

We make ClinicPlus, so we know where clinic data actually lives.

Registers come out of the system, not typed by hand

If you run ClinicPlus, the hardest registers — account inventory with last-login dates, the role/permission matrix, audit logs, MFA status — come straight out of the system.

We supply our own vendor evidence

Requirement A.6.d asks you to evidence your software vendor’s security. We supply that evidence pack for our own product.

MedPath holds the Cyber Essentials for HIMS Vendors certification.

FAQ

Questions clinics ask

Does a small clinic really need this?

If you are connected to NEHR or hold health information, the obligation applies regardless of clinic size. A two-doctor practice answers the same 56 requirements as a twenty-doctor one.

What does it cost?

Two parts. The certification body charges an audit fee — first-time certification may be eligible for a CSA grant, limited to Singapore-registered SMEs and NPOs with 200 or fewer employees or turnover of S$100M or less. Our fee is quoted by clinic size and endpoint count.

How long does it take?

It depends on hardware replacement and account clean-up, not on paperwork. You get a dated plan after the gap assessment.

Can we do it without ClinicPlus?

Yes. The registers simply take longer, because they are compiled by hand instead of exported.

Are the documents just templates?

They are parameterised controlled documents, plus blank forms your team must genuinely sign. We will not manufacture training records or approvals.

What happens after we pass?

Clauses C.6, C.7 and C.8 require ongoing review, checks and correction. The certificate runs on a three-year cycle, and we offer annual maintenance.

You should not have to work out on your own whether this applies to you.

A free scoping call takes about thirty minutes and tells you what your clinic is actually in for.

MedPath is not a certification body. Certification is issued by a CSA-appointed certification body. MedPath holds the Cyber Essentials for HIMS Vendors certification.