Who requires it
It is a CSA certification, issued by a certification body appointed by CSA. For a clinic it is tied to your obligations as a HIA entity.
Cyber Essentials mark — HIA Entities
Cyber Essentials (HIA Entities) is the certification that proves it. MedPath, the team that builds ClinicPlus, gets your clinic through it: the paperwork, the fixes, and the audit.
The obligation comes with being connected to NEHR and holding patient records. It is not optional, and the clinic is the one accountable for it — not your IT supplier.
The free call
No obligation and no quote on the call itself.
Scope
If any one of these is true, this applies to your clinic, whatever its size. A two-doctor practice is held to the same standard as a twenty-doctor one.
The basics
It is a CSA certification, issued by a certification body appointed by CSA. For a clinic it is tied to your obligations as a HIA entity.
The everyday basics — staff habits, devices, who can open what, backups, and what you do when something goes wrong — plus how health information is handled, on paper as well as on screen.
A set of documents you almost certainly do not have yet, some changes to how your machines and accounts are set up, and one audit.
The self-assessment
The assessment is 56 mandatory requirements. Answer “No” to any one of them and the whole assessment fails.
Each cell is one mandatory requirement.
Sections A.1–A.10
The mandatory clauses are not spread evenly. Two sections carry 23 of the 56 between them.
| Code | Section | Mandatory | What it means for a clinic |
|---|---|---|---|
| A.1 | People | 2 | Everyone who touches patient data is trained, and daily practice is written down. |
| A.2 | Hardware & Software | 7 | You know every device and application in the clinic, and unsupported ones are removed or formally accepted. |
| A.3 | Data | 4 | You know what data you hold, how long you keep it, and it is encrypted. |
| A.4 | Virus & Malware | 7 | Anti-malware and a firewall on everything, and staff who know what to do with a strange email. |
| A.5 | Access Control | 13 | Who can open what, approved by whom, removed when they leave. The heaviest section. |
| A.6 | Secure Configuration | 6 | Devices are set up to a baseline instead of left on factory defaults. |
| A.7 | Software Updates | 1 | Critical patches go on promptly, from the vendor. |
| A.8 | Backup | 4 | Critical data is backed up on a schedule, protected, and kept apart from the live system. |
| A.9 | Incident Response | 2 | A written plan, and staff who know it exists. |
| A.10 | HIA Data Security | 10 | The health-information rules: copies, marking, review, continuity, MOH reporting. |
The questionnaire runs to 85 clauses. 56 are mandatory and decide pass or fail; the other 29 are recommended.
Common gaps
Three findings account for most of the remediation work we see.
Most clinic front-desk and consult-room PCs are now unsupported, and A.2 requires you to remove them or formally accept the risk with management sign-off. This is usually the only line item that costs real money.
Shared logins, one admin account everyone uses, staff who left last year still enabled, no record of who approved what.
A clinic holds enough personal data to trigger the requirement, which means full-disk encryption on every machine — and evidence of it.
Documents
The certification body expects seven documents, plus the completed self-assessment.
A clinic has none of these on day one. We produce all of them.
Process
Five steps. Most of the work sits with us; what needs your clinic is scheduled, not open-ended.
Decide what is in and out, and keep it as small as is honest.
All 56 scored, and every gap tagged write it / configure it / buy it.
Policies, procedures, registers and blank forms your team signs.
Configuration changes, screenshots, training, the register.
We submit with you and stay through the audit.
The timeline is driven by hardware replacement and account clean-up, not by paperwork. We give you a dated plan after step 2.
Engagement
Quoted by clinic size and endpoint count.
For clinics that want to know where they stand.
For clinics with someone in-house to do the work.
For clinics who want it handled.
Certification body audit fees are charged separately by the certification body.
Why MedPath
The HIMS Vendors edition — all 85 clauses, 46 controlled documents. Certified.
We make ClinicPlus, so we know where clinic data actually lives.
If you run ClinicPlus, the hardest registers — account inventory with last-login dates, the role/permission matrix, audit logs, MFA status — come straight out of the system.
Requirement A.6.d asks you to evidence your software vendor’s security. We supply that evidence pack for our own product.
MedPath holds the Cyber Essentials for HIMS Vendors certification.
FAQ
If you are connected to NEHR or hold health information, the obligation applies regardless of clinic size. A two-doctor practice answers the same 56 requirements as a twenty-doctor one.
Two parts. The certification body charges an audit fee — first-time certification may be eligible for a CSA grant, limited to Singapore-registered SMEs and NPOs with 200 or fewer employees or turnover of S$100M or less. Our fee is quoted by clinic size and endpoint count.
It depends on hardware replacement and account clean-up, not on paperwork. You get a dated plan after the gap assessment.
Yes. The registers simply take longer, because they are compiled by hand instead of exported.
They are parameterised controlled documents, plus blank forms your team must genuinely sign. We will not manufacture training records or approvals.
Clauses C.6, C.7 and C.8 require ongoing review, checks and correction. The certificate runs on a three-year cycle, and we offer annual maintenance.
A free scoping call takes about thirty minutes and tells you what your clinic is actually in for.
MedPath is not a certification body. Certification is issued by a CSA-appointed certification body. MedPath holds the Cyber Essentials for HIMS Vendors certification.