Start here
This page is the whole plan. Everything after it is reference, jump to what you need, don't read start to finish.
Independent guidance, free to use, built from MOH's own published documents. It is not official MOH material and carries no MOH endorsement.
Your starting position
Assumption: your CMS is whitelisted
This plan assumes your HIMS is Synapxe NEHR Connectivity–certified and Cyber Essentials (CE) certified. Not sure? Check the Synapxe integration status list, or ask your vendor, before relying on this.
That already clears two things for you:
- Two-factor authentication (item 2e), already satisfied. Skip that setup.
- NEHR Connect Grant eligibility: already met, if you ever need it.
How to use the rest of this deck
- Not meant to be read front to back
- Use the sidebar to jump straight to the item you need
- Each section stands alone, its own MOH citation, its own steps
- Come back here and tick off the tracker as you go
Your policy document
Assumption: you're using the template
This deck assumes you've got CSDS-Policy-Template-Solo-GP.docx open: a complete Cybersecurity and Data Security Policy, already written, for a fictional clinic. Every clause from Part 1, plus every register and form from Parts 2 and 3, filled in with a realistic worked example. The parts specific to that fictional clinic are highlighted yellow. Find & Replace them with your own clinic's details in Word, and you're done.
That covers the whole tracker below in one file. The slides after this page don't ask you to write anything from scratch, they explain what's already in the template, why it's worded that way, and the one or two gaps you still have to fill in yourself.
Do this first, this morning
This morning
Buy nothing today. Send the vendor email from item 9 to confirm your backup details, how often, where, tested how recently. Your CMS's certification already covers its compliance status; this is about your specific backup arrangement.
Then open Windows Update on your own PC and turn on automatic updates. Five minutes: the single most useful thing on this list.
Your tracker
| # | Item | Done |
|---|---|---|
| 5 | Health info identified, locked away, copied and sent safely | ☐ |
| 6 | Health information marked or defined in policy | ☐ |
| 7 | Access restricted to those who need it | ☐ |
| 8 | Annual training done and recorded | ☐ |
| 9 | Vendor questions sent and answered in writing | ☐ |
| 10 | Self-review scheduled (we suggest annually) | ☐ |
| 12 | Business Continuity Plan written (printed copy recommended) | ☐ |
| 13 | Incident Response Plan written (printed copy recommended) | ☐ |
Your tracker, Parts 2 and 3
| # | Item | Done |
|---|---|---|
| 1 | Automatic updates on, every PC | ☐ |
| 2 | Defender, firewall, accounts, passwords, lockout, secure settings, 2FA already done | ☐ |
| 4 | Asset register filled, EOS assets identified | ☐ |
| 3 | Backup running, drive unplugged, restore tested | ☐ |
| 11 | Secure paper disposal in place, wipe procedure written | ☐ |
A Windows walkthrough for a solo GP clinic
Thirteen items. Every instruction mapped to a page of MOH's own Implementation Guide.
Who this is for
- A solo GP, or a doctor with one or two staff
- Windows 10 or Windows 11 PCs, bought as ordinary consumer or small-business machines
- No company network, no server room, no Active Directory, no IT vendor on retainer
If that's you, this guide covers everything.
Your timeline
1 September 2027
NEHR contribution and CS/DS measures must be in place by this date. Outpatient Medical Service (GP) is Batch 1. Specialist, dental and dialysis services each follow their own date. (MOH's Implementation Guide, Chapter 1, Table 1, page 3, and Table 4, page 10)
The NEHR Connect Grant application window closes 31 August 2027 (the Guide, Table 4, page 10).
Where this comes from
Four MOH documents, all fetched 18 August 2026:
- CS/DS, Cybersecurity and Data Security Essentials, first edition, March 2026 (16pp)
- MOH's Implementation Guide, HIA Implementation Guide for Healthcare Providers, Version 2.0, August 2026 (74pp)
- FAQ: FAQs for Healthcare Providers on the HIA, v1.1, 13 August 2026 (24 questions)
- MOH Circular MOH-MHC-0018-2026, 6 March 2026
The FAQ has already moved from v1.0 to v1.1 in five months. If you're reading this months after today, check the HIA website before your final sign-off.
One legal note, said once
MOH's own Implementation Guide says its sample clauses "are not intended to be an authoritative statement of the law or a substitute for legal or other professional advice" (MOH's Implementation Guide, Annex C, page 47). The same applies here.
This is free, pro bono, practical guidance built on MOH's documents. Get a lawyer involved for the genuinely high-stakes situations, a live data breach, a dispute with your CMS vendor over liability. Not for the routine work ahead.
The money answer, up front
Only two of the thirteen items need any spending, provided your PCs are still supported and you can already lock paper away. CS/DS assumes both.
MOH says this themselves
Note what MOH does and does not say. It says Defender may be sufficient for a simple setup, and it asks you to weigh your own risk profile. It does not tell you what to buy, and it does not tell you not to buy. Our own reading, not MOH's: for a single-PC clinic on a simple network, there is nothing here you need to purchase.
And on paying for help
If a vendor tells you otherwise, that's your answer. The FAQ adds that providers should report unethical conduct by service providers to MOH. It handles pricing differently, by having CSA-qualified CISOaaS providers publish standardised packages with transparent pricing.
What you actually need
| What you need | Cost | Source |
|---|---|---|
| Anti-malware | Nothing to buy: Windows Defender ships with Windows | MOH accepts it for a simple setup, MOH's FAQ, question 14 |
| Firewall | Nothing to buy: Windows Defender Firewall ships with Windows | MOH accepts it for a simple setup, question 14 |
| Two-factor authentication | Free: Microsoft Authenticator app | MOH's Implementation Guide, Annex A, A5, page 27 |
| Staff training | Free: PDPC self-help resources accepted | the CS/DS Essentials, clause C.1.1 |
| Every policy, register, plan and template | Free: templates in the Guide, Annexes B–E | the Guide, pages 38–59 |
The two things you may need to buy
A hard drive for backups (MOH's Implementation Guide, Annex A page 34, Annex D3 page 49), and a paper shredder if you keep paper (the Guide, Annex B15, page 46). The Guide requires both but states no prices anywhere. The only dollar figures in it are grant amounts. About S$60–100 and S$30–50 are our own market estimates, not MOH's.
If you do need to spend
NEHR Connect Grant (NCG)
Fixed S$8,400 for a GP clinic under an Outpatient Medical Services licence. Pick a Synapxe-certified HIMS before you apply, at oursggrants.gov.sg. Closes 31 Aug 2027. (MOH's Implementation Guide, Table 2, page 5)
CISO-as-a-Service (CISOaaS)
Up to 70% of a CS/DS consultancy package, through CSA. Optional per MOH's FAQ, question 23. Apply at services2.imda.gov.sg/ctoaas/tag/hia. (the Guide, Table 2, page 4)
And one more
Productivity Solutions Grant (PSG)
50% of qualifying security products, capped at S$30,000. Apply at apply.gov.sg/grants/business. (MOH's Implementation Guide, Table 2, page 4)
One scheme to ignore
NCSS Transformation Sustainability Scheme
MOH's Implementation Guide, page 5 lists this at 80% funding, capped S$40,000, but it's open only to Community Care Organisations that are NCSS members. A private GP clinic is not one. The Guide doesn't say so on the page that lists it, so it's easy to chase this by mistake.
Every item, mapped to MOH's documents
Use this to jump straight to any item, or to hand an auditor a trace.
Part 1: the paperwork (free)
| CS/DS item | Covers | Essentials ref | Guide ref |
|---|---|---|---|
| 5. Secure | Know, store, copy and send health info safely | B.1–B.7 | Annex B5–B9, C |
| 6. Identify | Mark documents as health information | B.8–B.9 | Annex B10 |
| 7. Access | Only people who need it get access | B.10 | Annex B11, C |
| 8. Training | Annual security awareness training | C.1–C.2 | Annex B12 |
Part 1: the paperwork, continued
| CS/DS item | Covers | Essentials ref | Guide ref |
|---|---|---|---|
| 9. Vendor | Know what your CMS provider does | C.3–C.5 | Annex B13, D Table 7 |
| 10. Review | Check yourself periodically | C.6–C.8 | Annex B14, B16 |
| 12. Contingency | Business Continuity Plan | C.10 | Annex D |
| 13. Incident response | Incident Response Plan and reporting | C.11–C.14 | Annex E |
Part 2: Windows settings (free unless a PC is unsupported)
| CS/DS item | Covers | Essentials ref | Guide ref |
|---|---|---|---|
| 1. Updates | Install software updates promptly | A.1 | Annex A, A1 |
| 2. Secure/Protect | Anti-malware, firewall, accounts, passwords, 2FA, lockout, logging, settings | A.2–A.12 | Annex A A2–A8; Annex B1–B2B |
| 4. Asset | List hardware and software, replace what's unsupported | A.15–A.18 | Annex B3B, B4, B4A |
Part 3: the two purchases
| CS/DS item | Covers | Essentials ref | Guide ref |
|---|---|---|---|
| 3. Backup | Back up essential data, store separately, test the restore | A.13–A.14 | Annex A A8-4; B3, B3A; D3 |
| 11. Disposal | Shred paper, wipe drives | C.9 | Annex B15 |
Two things not on this list
Self-assessment questions
MOH's own self-check questions are at MOH's Implementation Guide, Chapter 3, Table 5, pages 15–18. You don't need to read them, every one is answered by a section ahead.
the Guide, Annex F, the NEHR use policy
A sample policy on who in your clinic may look at NEHR, and why (pages 60–61). Not one of the 13 CS/DS items. Do this separately, when you onboard to NEHR.
Already in your template
CS/DS item 5. Clauses B.1–B.7. MOH's Implementation Guide, Annex B5–B9, pages 41–44; Annex C, page 47.
Already in your template. Section 1
Your organisation's health information is stored in [your clinic software] and [your filing cabinet, named by location], retained for the patient's lifetime plus six years (anything electronic, including scans) and six years from the last day of consultation (paper outpatient), with at least 15 years for high risk cases. Copies are made only when needed, on clinic equipment, never left at the photocopier. Emailed files are password-protected with the password sent a separate way. WhatsApp is scheduling only, no medical content.
Find & Replace the yellow brackets with your own details. The slides after this one give you the citation and the gap note behind each line, in case you or an auditor ever need to check where it came from.
The number is in your licence conditions
Already filled in for you
The retention period is the one figure that is not in the Implementation Guide or the Essentials. It is in a separate document your clinic is already bound by: the Licence Conditions on the Retention Periods of Patient Health Records, imposed under section 13(1) of the Healthcare Services Act. Your template now carries all four periods from it. See 5b, ahead, for what they are.
Know what health info you hold, and handle it safely
Three questions the template above already answers: Where does your patient data live, physically and digitally? How do you stop copies leaking? How do you send it to someone else without exposing it?
5a. Where it lives
The source behind the first paragraph of your template. MOH's Implementation Guide, section B5 (page 41) gives you the sentence:
List every place: the CMS database, the filing cabinet behind reception, the old box of records in the store room, the clinic laptop. Paper records at a commercial storage facility? the CS/DS Essentials, clause B.3 wants you to have checked that facility's security and to keep a list of what you sent there.
5b. How long you keep it
The source behind the retention line in your template. The CS/DS Essentials, clause B.4, tells you to set retention periods but doesn't give the numbers. It points to the Licence Conditions on the Retention Periods of Patient Health Records, imposed under section 13(1) of the Healthcare Services Act. Those are the numbers.
Table 1, and paragraphs 13 and 16
Anything electronic, including paper you have scanned: the patient's lifetime plus six years. A scanned record counts as electronic from the moment you scan it (paragraph 9), which is why this period is the one that binds most GP clinics.
Paper outpatient records: six years from the last day of consultation or treatment, whichever is later.
High risk patients and cases: at least 15 years. Three things count as high risk, and the licence conditions name them: complications during treatment, an open complaint, and a patient who lacked mental capacity, or you suspect lacked it, at the time.
A complaint or legal action underway, or one you can see coming: keep the whole record until it is over, even if the period above has run out.
Two things worth knowing. "Lifetime" means the patient's actual lifetime, or 110 years where you don't know the date of death. And you may cull paper after four years, provided you keep the 15 categories listed in paragraph 8: discharge summaries, operation reports, consent forms, x-ray and histopathology reports, treatment and progress notes, prescription orders, and the rest.
These are licence conditions, not guidance. A breach is actionable under section 20 of the HCSA. They are also minimums: keep records longer if you want, never shorter.
5c. Copies
The source behind the third paragraph of your template. MOH's Implementation Guide, section B8, page 43. Copies made only when needed for work, on clinic equipment. Never leave a printout at the photocopier. Shred misprints and jams immediately.
5d. Sending
The source behind the fourth paragraph of your template. MOH's Implementation Guide, section B9, page 44; the CS/DS Essentials, clause B.7.4: the rule that catches people out:
Password and delivery route must never match
Any file with patient information sent by email must be password-protected. The password goes a different route, phone call or SMS, never the same email. MOH's FAQ, question 17: if the email account is compromised, sending both together exposes both at once.
5d. Sending, in practice
Free ways to password-protect a file:
- Word/Excel:
File→Info→Protect Document/Workbook→Encrypt with Password - Any file: 7-Zip (free) → right-click →
7-Zip→Add to archive→AES-256→ set a password
5e. WhatsApp
The source behind the last paragraph of your template. MOH's FAQ, question 18. Fine for basic appointment scheduling: dates and times, no medical content. Anything with medical information goes through the clinic's official email instead.
5f. Confidentiality clauses
the CS/DS Essentials, clause B.1. MOH's Implementation Guide has two ready-made contract clauses (one for vendor and contractor agreements, one for employment contracts) each prohibiting unauthorised disclosure of health information.
Not for your policy document
These two clauses are separate from the CS/DS Policy in your template. They go into your actual employment contracts and vendor/contractor agreements instead, new hires and new vendors from here on, and existing ones at your next renewal.
Where to find the full clause text
Already in your template, and marked to delete
Both full clauses are already typed out in your template, right after this section, under "Confidentiality clause for contracts." They're not part of the policy itself, your template says so in plain text, and tells you exactly what to do: copy each clause into the matching contract, then delete that whole section from your policy document.
The Implementation Guide's own description page (Annex C, page 47) just explains that these clauses exist, the real text is appended as the final two pages of the 74-page PDF (pages 73–74), which is why MOH's own guide is awkward to copy from directly.
Already in your template
CS/DS item 6. Clauses B.8–B.9. MOH's Implementation Guide, Annex B10, page 44. Free. Already in Section 2 of your template. The point: anyone picking up a document knows it needs protecting. MOH accepts either marking every document, or (easier, and what a solo GP should use) stating in your policy what counts as health information and skipping individual labels (the CS/DS Essentials, clause B.8.2):
Optional extra: a rubber stamp reading "Health Information," about S$10, for your paper files. Not required.
Already in your template
CS/DS item 7. Clause B.10. MOH's Implementation Guide, Annex B11, page 44. Free. Already in Section 3 of your template. Two conditions must both be met before someone can see patient data: they need it for their job, and they've been told the rules and acknowledged them. Adapted from the Guide, section B11 for a clinic where you're the authority:
\
the CS/DS Essentials, footnote 14: an email reply saying "I understand the data security measures" counts, as does an attendance record from a briefing. For a solo practice this is one page and one email from your clinic assistant.
The technical half of this item (giving each person their own login) is item 2c, ahead in Part 2.
Already in your template
CS/DS item 8. Clauses C.1–C.2. MOH's Implementation Guide, Annex B12, page 45. Free. Already in Section 4 of your template, verbatim from MOH's Implementation Guide, the two clauses this item actually asks you to have in writing:
Already in your template. Section 4
All personnel must ensure that they attend cybersecurity and data security-related awareness training at least once every year. This is necessary to ensure that all personnel are aware of and kept up-to-date on the applicable security measures, and their roles and responsibilities in ensuring the security of health information.
All personnel must abide by any cybersecurity or data security policies and practices that may be implemented by our organisation in our operations.
What to do
the CS/DS Essentials, clause C.1.1 accepts in-house, external vendor, or PDPC's free self-help resources, that third route:
- Go to pdpc.gov.sg and find their data protection self-help and e-learning resources
- Sit with your staff for an hour. Cover phishing emails, strong passphrases, not leaving records on the counter
- Write the date, who attended, and what you covered on a single page. Sign it. File it
That page is your evidence. Repeat annually.
Do not pay a vendor to run a session for two people.
One click
CS/DS item 9. Clauses C.3–C.5. MOH's Implementation Guide, Annex B13, page 45; Annex D Table 7, pages 49–50. Free. Everything you need is right here, the full subject line and all ten questions, ready to send as-is. Nothing else to look up.
One click
Open this as a ready-to-send email →, opens in your email app with the subject and all ten questions already filled in. Just add your vendor's address and send.
The email: part 1
Subject: HIA CS/DS Essentials: questions about our clinic's data
We are preparing for the HIA cybersecurity and data security requirements. Could you answer the following in writing?
- Is your system HIA-compliant, NEHR Connectivity certification, Cyber Essentials (CE) certification submitted to NEHR, and Code of Practice for Data Portability compliance declared? If not yet, what's your timeline?
- What data of ours is backed up, all patient records, appointment histories and clinical notes?
- How often do backups run, and where are they stored, same server as live data, or separate?
The email: part 2
- Are our backups stored in Singapore? If not, which country?
- How do you verify backups actually work? When was a restore last tested successfully?
- Are our backups encrypted, and who on your side can access them?
- If we lost data tomorrow, how quickly could you restore it, and how far back can you go?
The email: part 3
- Is there anything we need to do on our end for backups to run correctly? Will you notify us if one fails?
- Who is responsible for what if there's a security incident or breach?
- Will you send us regular updates on security issues and vulnerabilities affecting our system?
This is a phone call, not a purchase
the CS/DS Essentials, clause C.4 needs you to understand where your patient data is stored, what safeguards the vendor has, and who's responsible for what when something goes wrong.
Question 1 is already answered
If your CMS is on MOH's whitelist (Synapxe NEHR Connectivity–certified and Cyber Essentials certified) you already know it's HIA-compliant. Send question 1 anyway, for a written record; the rest of this email is where the real work is.
What the reply confirms
What being whitelisted already gives you
NEHR Connect Grant eligibility (a Synapxe-certified HIMS is the precondition), and the 2FA setup in item 2e, both already sorted. Still worth checking your CMS's status yourself at the Synapxe integration status list, in case it's changed.
Keep the reply: that email thread is your vendor management evidence.
Already in your template
CS/DS item 10. Clauses C.6–C.8. MOH's Implementation Guide, Annex B14, page 45; B16, page 46. Free. Already in Section 6 of your template. No external auditor required: the CS/DS Essentials, clause C.7 says self-assessment is acceptable. From the Guide, section B14:
Set a calendar reminder for the month your template already names. Your review: reread this guide, walk the thirteen items, note what's drifted, fix it, write the date on the page.
Already in your template, continued
MOH's Implementation Guide, section B16, page 46, also wants a named person accountable for explaining the policy to new hires, that's you:
Already in your template
CS/DS item 12. Clause C.10. MOH's Implementation Guide, Annex D, pages 48–52. Free. Your CMS is down at 9am and there are patients in the waiting room. This is the plan for that. Already assembled for you, in Section 8 of your template.
Already in your template. Section 8
Critical functions. Consultations and dispensing must continue during any outage. Everything else can wait.
Paper fallback. Printed stacks of a blank consultation note, an appointment sheet, and a billing slip are kept at [location, e.g. reception, consultation room]. Paper notes from the outage are entered into the CMS as soon as practically feasible after restoration.
Already in your template, continued
Already in your template. Section 8, continued
High-risk patients. An offline list of patients on critical medication is kept at [location], for contacting during a multi-day outage.
Communications. Staff numbers, [CMS vendor]'s support number ([number]), and [your mobile] are on paper at [location]. Not only in a phone.
Testing. This plan is tested once a year, in [month], by running one morning on the paper templates above.
Print Section 8 on its own, a digital plan is useless when the systems holding it are down.
Where each line comes from
MOH's Implementation Guide, Annex D is six sections of questions (D1–D6). Talking points MOH expects you to have thought through, not a fill-in form.
Where each line comes from, continued
Critical functions (D1, page 48)
Consultations and dispensing must continue. Everything else can wait.
Paper fallback (D2, page 48)
Keep printed stacks: a blank consultation note, an appointment sheet, a billing slip. Store them somewhere obvious. Write: "Paper notes from the outage are entered into the CMS as soon as practically feasible after restoration."
High-risk patients (D2.2, page 49)
A short offline list of patients on critical medication who'd need contacting during a multi-day outage.
Communications (D5, page 52)
Staff phone numbers, your CMS vendor's support number, your own mobile, on paper, not only in your phone.
Testing
Test it once a year: run one morning on paper templates. MOH's Implementation Guide (Annex D, page 52) asks only whether you have “a realistic schedule” and sets no cadence. Once a year is our recommendation, not MOH's requirement.
Who does what
CS/DS item 13. Clauses C.11–C.14. MOH's Implementation Guide, Annex E, pages 53–59. Free. the Guide, Table 9, page 54, lists four roles: incident commander, IT/technical lead, Data Protection Officer, communications and legal lead.
You do not need four people
The Guide says so on the same page: in a solo practice it may be you and one or two trusted staff, each with a defined role.
Incident commander, DPO and communications: [your name], [your mobile] Technical response: [CMS vendor name], [their support number] Recording what happened: [clinic assistant's name], or you if alone
How you spot an incident
MOH's Implementation Guide, Table 10, page 55, the signs a GP clinic actually sees:
- Files renamed with odd extensions, or a payment-demand message on screen
- Patient records that opened yesterday won't open today
- Emails going out from the clinic account that nobody sent
- An email with patient results sent to the wrong person
- A clinic laptop or paper file that can't be found
- A former staff member's login still active after they left
The ransomware response card
MOH built an actual printable card for this (MOH's Implementation Guide, Table 8, page 51), not just steps to read, a card to fill in and pin up. Print this one and stick it inside a cupboard door.
How to spot it: does something look wrong? Files cannot be opened or have strange names. A ransom message has appeared on screen.
The card: steps 1 to 3
1) Disconnect. Unplug the network cable or turn off Wi-Fi on affected computers. Do not switch the computer off completely, this destroys forensic evidence needed for investigation.
2) Stop and assess. Can you still see patients safely? If yes, consider activating your BCP (switch to paper records, item 12). If no, consider diverting patients, telling them promptly, or rescheduling.
3) Call for help. Keep names and numbers ready: your CMS provider / IT vendor, and key personnel in your clinic.
The card: steps 4 to 6
4) Do not pay the ransom. Paying does not guarantee recovery. Consult and wait for advice from your IT vendor first.
5) Report if patient data is affected. Have the reporting hotline numbers of the relevant authorities ready (reporting timelines, next).
6) Wait for the "all clear." Only restart and restore systems once your IT vendor confirms it's safe. Change all passwords after restoration.
The card: after the incident
After the incident: write down what happened and when. Your organisation will need this for reporting, and to prevent it happening again, times, which machines, what patient information might be involved, roughly how many patients, what you did. Photograph error messages. Use a clean device for reporting and for contacting patients about urgent medical matters.
Print the card with this line at the bottom, filled in:
Prepared by: [your name] | Version: [1] | Date: [today's date]
Wrong-recipient email, not a hack? MOH's Implementation Guide, Table 11: try to recall it immediately, then contact the recipient and ask them to delete it without opening the attachment.
Reporting: and the gap you need to know about
MOH's reporting timelines (MOH's Implementation Guide, Table 12, page 59):
| Who | When | What |
|---|---|---|
| MOH | Within 2 hours of confirming it | All confirmed cybersecurity incidents, and data breaches likely to cause significant harm or affecting 500+ people |
| PDPC | Within 72 hours | Breaches likely to cause significant harm, or 500+ people |
| SPF | As soon as possible | Ransomware or monetary loss |
Plus a full report to MOH within 14 days. Tell affected patients at the same time as MOH if likely to cause them significant harm (the CS/DS Essentials, Table 2, page 16).
The gap
MOH's own reporting form doesn't exist yet
MOH's Implementation Guide, Table 12: the MOH "Reporting Method" column says "The link to the MOH incident reporting form will be added here in 2027." the CS/DS Essentials, clause C.14 says the same. Both the two-hour obligation and the form are dated to 2027. Plan for the obligation arriving first. This is MOH's gap, not yours.
Until the form appears
Check whether MOH's form has gone live at your annual review.
Do this on every PC
CS/DS item 1. Clause A.1. MOH's Implementation Guide, Annex A, A1, page 20. Free. This is the single highest-value five minutes in the whole guide.
Windows 11: Settings → Windows Update
Windows 10: Settings → Update & Security → Windows Update
Do this on every PC, continued
- Click
Check for updates. Install everything offered. Restart when asked Advanced options→ turn onReceive updates for other Microsoft products: this keeps Word, Excel and Outlook patched too- Still in
Advanced options, setActive hoursto your clinic hours so restarts never happen mid-consultation - Turn on
Get the latest updates as soon as they're available, if you see it
Include the reception machine.
Your CMS or HIMS is separate. Its updates are the vendor's job. That's question 10 in the vendor email at item 9.
Part 2 is the clicking-through-Windows-settings part, budget two hours per PC for the first one, twenty minutes for each after. If a menu name doesn't match what's shown, use the Windows search box.
2a. Anti-malware
CS/DS item 2. Clauses A.2–A.12. MOH's Implementation Guide, Annex A, A2–A8, pages 21–33; Annex B1–B2B, pages 38–39. Free. The biggest item: seven parts, a–g, starting here. the CS/DS Essentials, clause A.2. The Guide, Annex A, A2, page 21.
Windows Defender is already on your PC, and MOH has confirmed it meets this requirement for a clinic your size (MOH's FAQ, question 14). No extra anti-virus purchase is needed to comply.
Path: Settings → Privacy & security → Windows Security → Virus & threat protection
2a. Anti-malware, continued
Under Virus & threat protection settings → Manage settings, all four should be On: Real-time protection, Cloud-delivered protection, Automatic sample submission, Tamper protection.
Then: Protection updates → Check for updates. Then: Scan options → Full scan → Scan now, once today.
2a. USB drives
If a specialist or lab sends you a drive too large to scan properly, MOH's FAQ, question 15 says you're not required to deep-scan the whole thing:
Real-time protection, already on. Nothing more to do.
2b. Firewall
the CS/DS Essentials, clause A.3. MOH's Implementation Guide, Annex A, A2 continued, page 22.
clause A.3: for "a simple organisation setup... comprising just endpoints connecting to the internet," the OS firewall plus your router's is what's expected. No hardware purchase.
Path: Windows Security → Firewall & network protection: Domain, Private and Public network must all say On.
Then log into your router's admin page and confirm its firewall is enabled (usually on by default). While there, change the router's admin password if it's still the factory default (clause A.8 requires it).
2c. One login per person
the CS/DS Essentials, clause A.5–A.7, A.9–A.10. MOH's Implementation Guide, Annex A, A3–A4, pages 23–26; Annex B2, B2A, pages 38–39.
The rule: nobody shares a login. Not the doctor's, not reception's.
Create an account: Settings → Accounts → Other users → Add account → I don't have this person's sign-in information → Add a user without a Microsoft account
Set the account type: click the account → Change account type → Standard User. Only your own account should be Administrator (clause A.6.2).
2c. Removing a login
Remove an account when someone leaves: Settings → Accounts → Other users → click it → Remove. the CS/DS Essentials, clause A.6.1 gives 60 days of inactivity as the marker for a sweep.
See every account: Windows key → type netplwiz.
2c. The account register
the CS/DS Essentials, clause A.5.1 wants a list with six fields, MOH's Implementation Guide, Annex B2, page 38, has the template. For a two-person clinic:
| Name | Username | Department | Role | Access created | Last log-on |
|---|---|---|---|---|---|
| Dr [name] | [username] | Clinical | Administrator | [date] | [date] |
| [assistant] | [username] | Reception | Standard user | [date] | [date] |
Add rows for CMS logins and any vendor account.
2c. Requesting access: the email
MOH's Implementation Guide, Annex B2A, page 64. Every access change (a new hire, a role change, a vendor login) starts as a written request. MOH gives you the exact email.
One click
Open a ready-to-send access request →, subject and fields already filled in, edit the brackets and send.
2c. Approving access
MOH's Implementation Guide, Annex B2A, page 65. Not an email: three checks before you say yes, plus a log entry.
- Access is granted only to the specific system requested
- Access matches what the role actually needs. Ask "why does this person need this?"
- The doctor (or IT support) records the access in the register above
Example row from MOH's own sample log:
| Name | System | Department | Role | From | To |
|---|---|---|---|---|---|
| Nurse Alice | Patient Records / Billing Folder | Clinic Operations | User | 05 Apr 2026 | NA |
2c. Revoking access
MOH's Implementation Guide, Annex B2A, page 66. When someone leaves, or a vendor's work ends, same day, not "when you get around to it."
One click
Open a ready-to-send access revocation →, subject and fields already filled in, edit the brackets and send.
2c. Third-party logins
Third parties
the CS/DS Essentials, clause A.9.1: any vendor or contractor login needs a signed NDA first. Sign before handing over access; remove the account when the work ends.
Where MOH actually put it
MOH's Implementation Guide, Annex A, A4, page 26, just describes that a sample NDA exists, the real clause text is on page 63. For a solo clinic, the vendor/contractor confidentiality clause already in Section 1 of your template covers the same ground; use the Guide, Annex A page 63 directly only if a vendor specifically wants a standalone NDA.
2c. Third-party access request form
MOH's Implementation Guide, Annex A, A4, page 63. The other half of the same page, what the vendor fills in before you grant them anything.
Contractor name · Contact details · What they need access to · Why they need it · Start date · End date · Tick all that apply: General data only / Patient health information required / IT equipment required (specify) · Your organisation's name · Your signature · Date
2d. Passwords
the CS/DS Essentials, clause A.8. MOH's Implementation Guide, Annex B2B, page 39.
A strong passphrase: 12+ characters, mixed case and special characters, not a common word or obvious pattern (the Essentials, footnote 4).
- Change any password still on a factory default, router, CMS admin, network printer, anything
- Write the rule into your policy: passwords change immediately on any suspected compromise or lost token (the Guide, section B2B)
- To change a Windows password:
Ctrl+Alt+Delete→Change a password
2d. Passwords, in practice
Tell staff: four unrelated words plus a number and symbol. "Kopi7Bicycle!Rain" beats "Cl1n1c@2026" on both strength and memorability.
2e. Two-factor authentication
the CS/DS Essentials, clause A.8.2. MOH's Implementation Guide, Annex A, A5, page 27. Free.
A code from your phone on top of your password, for admin and remote access to important systems.
Already done, on your setup
The Guide, Annex A, A5 footnote, page 27: "Skip this part if you are using CE-certified HIMS to process and store all your health information." Your CMS is on the whitelist (Synapxe NEHR Connectivity–certified and Cyber Essentials certified) so this item is done. Nothing to click.
2e. If that ever changes
If you switch to a HIMS that isn't CE-certified, or add a system outside it: install Microsoft Authenticator (free). For Microsoft/Office 365: account.microsoft.com → Security → Advanced security options → Two-step verification → scan the QR code. For your CMS: ask the vendor to enable it on your admin account.
2f. Lock the account after failed logins
the CS/DS Essentials, clause A.8.3. MOH's Implementation Guide, Annex A, A6, page 28. Free.
Stops someone guessing passwords all afternoon. clause A.8.3 gives 10 failed attempts as the example.
Group Policy is not available on Windows Home
The Guide's Annex A uses gpedit.msc. Most clinic PCs won't have it. Here's what works on every edition, Home included.
2f. The command that works everywhere
- Windows key → type
cmd - Right-click
Command Prompt→Run as administrator - Type and Enter:
net accounts /lockoutthreshold:10 /lockoutduration:15 /lockoutwindow:15
Confirm with net accounts: check the "Lockout threshold" line. Recent Windows 11 builds may already ship a default of 10; run net accounts first to check.
2g. Secure settings
the CS/DS Essentials, clause A.12. MOH's Implementation Guide, Annex A, A8, pages 31–33. Free. One pass per PC: new machines ship with risk switched on by default.
Turn off unused Windows features (the Guide, section A8, page 31): Control Panel → Programs → Turn Windows features on or off. Uncheck: Windows Media Player, Microsoft XPS Document Writer, SMB Direct, Windows TIFF IFilter, and SMB 1.0/CIFS File Sharing Support if it appears (a known ransomware route).
Stop auto-connecting to Wi-Fi (the Guide, section A8-2, page 32; clause A.12.3): Settings → Network & internet → Wi-Fi → Manage known networks → each network → uncheck Connect automatically when in range. Delete any network you don't recognise.
2g. Secure settings, continued
Turn off AutoPlay (MOH's Implementation Guide, section A8-3, page 33), stops a USB drive running something the moment it's plugged in.
Windows 11: Settings → Bluetooth & devices → AutoPlay → Off
Windows 10: Settings → Devices → AutoPlay → Off
Screen locks (the CS/DS Essentials, clause B.2): Settings → Accounts → Sign-in options → If you've been away, when should Windows require you to sign in again? → When PC wakes up from sleep. Then Settings → System → Power & battery → screen off after 5–10 minutes. Teach everyone Windows key + L (the Guide, section B6.4).
2g. Secure settings, last bit
Privacy filter (the CS/DS Essentials, clause B.7.3; MOH's Implementation Guide, section B9.3): turn the reception monitor away from the waiting area, free, and usually enough. A privacy filter is about S$40 if you want one.
Login logging (clause A.11; the Guide, Annex A, A7, pages 29–30): Windows keeps this automatically. Windows key → Event Viewer → Windows Logs → Security. Event ID 4624 is a successful sign-in, 4625 a failed one. You don't need to read these daily, just know where they are.
The template
CS/DS item 4. Clauses A.15–A.18. MOH's Implementation Guide, Annex B3B, page 40 (form, page 70); B4, page 41 (register, page 71); B4A, page 41 (form, page 72). MOH's own sample asset register (the Guide, Annex B4, page 71) uses different columns than you might expect, asset name and type, not serial numbers:
| Asset ID | Asset name | Type | User | Location | Approval | Status | EOS date |
|---|
The template, filled in
MOH's own worked example, your register should look like this:
| Asset ID | Asset name | Type | User | Approval | Status | EOS date |
|---|---|---|---|---|---|---|
| e.g. 01 | Laptop A | Hardware | , | 01 Jan 2026 | Active | 01 Dec 2028 |
| e.g. 02 | Computer A | Hardware | Dr. Smith | 01 Jan 2026 | Active | 01 Dec 2028 |
| e.g. 04 | Laptop B | Hardware | Nurse Ang | 01 Dec 2018 | Removed | 01 Jun 2018 |
That last row is the one MOH's own guide references elsewhere: an asset with an EOS date of 1 June 2018, removed rather than kept running.
Compiling your list
You can't protect equipment you've forgotten about. This is an afternoon of walking around with a notebook.
What to list: every PC, laptop, tablet and printer, your router, any external drive or USB stick used for clinic data, and every piece of software.
Find a PC's Windows version: Windows key → type winver.
The End-of-Support question
the CS/DS Essentials, clause A.17: hardware and software past End-of-Support must be replaced. Meaning the maker has stopped issuing security patches.
For a clinic, check your Windows version:
- Windows 11, supported, nothing to do
- Windows 10, Microsoft ended support in October 2025. Upgrade free via
Settings→Windows Updateif the hardware qualifies, or plan to replace the machine before September 2027 - Windows 8.1, 7, or older: replace it. The one line item here that can cost real money
Windows Home is fine
Home edition is fine
Whether your PCs run Windows Home or Pro makes no difference. Microsoft's licence doesn't restrict Home to personal use, and nothing in the CS/DS Essentials requires a Pro-only feature. The word "encrypt" appears once in the whole CS/DS Essentials, at C.9, about wiping a drive before disposal (item 11), which Home does perfectly well. Don't spend money upgrading to Pro for compliance.
If a machine has to stay
If you must keep an unsupported machine running a while, the CS/DS Essentials, clause A.18 requires you to write down the risk, approve continued use yourself, and monitor it until replaced. MOH's EOS form (MOH's Implementation Guide, Annex B4A, page 72) is the fastest way to do that, fill in the fields below for the machine.
A. Equipment name (e.g. laptop, clinic system, software name): B. Location (e.g. Room 1, Counter): C. User (e.g. Dr Tan / Nurse A): D. End-of-Support date (if unsure, write "Unknown"), E. Reason: tick still needed for patient care or no replacement yet, F. Planned replacement date.
The EOS form: risks and safety measures
G. Risks (tick all that apply): no security updates · higher risk of virus or malware infection · patient data may be exposed or leaked · may stop working suddenly · slow performance · no technical support if problems occur · cannot connect properly to newer systems · data may be lost if the system fails · backups may not work properly.
H. Safety measures (tick all that apply): only authorised staff use this · not connected to public internet · important data is backed up.
The EOS form: approval
Approval: Decision: approved to continue using / not approved. Approver name (senior management, i.e. you as clinic owner), signature, date.
Grant it before you buy it
If you do need to replace hardware, apply for the grant before you spend. NCG gives GP clinics a fixed S$8,400; PSG covers 50% up to S$30,000. Applying after the fact doesn't work.
Authorising new equipment
the CS/DS Essentials, clause A.15 also wants a protocol for authorising new equipment, for a solo clinic, one sentence in your policy is enough: "No computer, tablet or software is used for clinic work unless [your name] has approved it and added it to the asset register."
MOH's own request form (MOH's Implementation Guide, Annex B3B, page 70), if you'd rather use one: Item name · Type (tick: computer / software / medical device / other) · Requested by · Purpose or business reason · Approved by · Signature · Date.
Recording the split, the actual template
CS/DS item 3. Clauses A.13–A.14. MOH's Implementation Guide, Annex A A8-4, page 34; Annex B3, B3A, page 40; Annex D3, page 49. One-time cost: S$60–100. Your patient records are almost certainly in your CMS, and your vendor is backing them up, questions 2–8 in the item 9 vendor email cover this. What's not covered: everything sitting on your PCs, which you back up yourself.
MOH's own form for recording the split (the Guide, Annex B3A, page 67), one page, fill in once:
Service name · Provider · Responsibilities of the cloud service provider (tick: infrastructure backup, platform availability, disaster recovery, other) · Responsibilities of your clinic (tick: our data backup and recovery, our user account management, compliance with regulations, other) · Documented by · Date.
If you use a cloud backup provider, the email
MOH's Implementation Guide, Annex B3, page 68. Only relevant if you're paying for a separate cloud backup service beyond your CMS, not needed if the drive below is your whole plan.
One click
Open a ready-to-send clarification request →, subject and questions already filled in.
What to buy, and how
One external hard drive, 1TB or 2TB, about S$60–100. That's the entire purchase.
Option A, File History (simplest): Control Panel → System and Security → File History → select your drive → Turn on. Advanced settings → Save copies of files → Daily.
Option B, Backup and Restore: Control Panel → System and Security → Backup and Restore (Windows 7) → Set up backup → choose your drive → Let Windows choose → Save settings and run backup. Set the schedule to daily, after clinic hours.
Windows 11's Windows Backup app goes to OneDrive, not a local drive, fine as a second copy, not your only one.
The first rule people get wrong
Store it separately
the CS/DS Essentials, clause A.13.3: backups must be "stored separately and isolated from the operating environment." MOH's Implementation Guide, section D3.1(b): a drive left permanently plugged in gets encrypted by the same ransomware that hits your PC.
Run the backup, then unplug the drive and lock it in a drawer. Better: two drives, alternated, one kept off-site. A free OneDrive or Google Drive tier can serve as that second copy for non-patient files.
Writing the plan down
MOH's own form for a two-copy backup plan (MOH's Implementation Guide, Annex B3, page 69):
Primary backup, Cloud provider (if you have one) · Service · Frequency (e.g. every 30 days). Secondary backup: your external hard drive · Frequency (e.g. monthly) · Location (e.g. clinic's lockable cabinet). Documented by · Date.
No cloud provider? Leave the primary section blank and just fill in the secondary, the hard drive is your whole plan.
The second rule people get wrong
Test the restore
MOH's Implementation Guide, section D3.2, page 49: "A backup that has never been verified may be corrupted, incomplete, or inaccessible precisely when you need it most." Do this once, today, pick a file, delete it, restore it, confirm it opens. Write the date on your policy. Repeat yearly.
An untested backup is not a backup.
Part 3 is the two things on this whole list that cost money, this drive, and the shredder in item 11, next. Both are one-time purchases.
Paper
CS/DS item 11. Clause C.9. MOH's Implementation Guide, Annex B15, page 46. One-time cost: S$30–50, and only if you keep paper. The Guide, section B15.1: hardcopy documents with health information go through designated secure waste containers or approved shredding equipment. A cross-cut shredder is about S$30–50. A clinic that keeps no paper with patient information on it has nothing to shred and nothing to buy, and should say so in its policy rather than claim a control it does not have.
Put it next to reception. One rule for staff:
the CS/DS Essentials, footnote 20 points to two NIST media sanitisation standards. You don't need to read them to shred paper in a GP clinic. A cross-cut shredder covers it.
Computers and drives: free
MOH's Implementation Guide, section B15.2: drives encrypted before reformatting, then overwritten multiple times.
- Check encryption:
Settings→Privacy & security→Device encryption. On Pro,Control Panel→System and Security→BitLocker Drive Encryption→Turn on BitLocker. Neither available? Skip to step 2: it still does the job Settings→System→Recovery→Reset this PC→Remove everything→Change settings→Clean data: Yes. This overwrites the drive, not just the index. Takes a few hours: let it run overnight- Drive can't be wiped because the machine is dead? The Guide, section B15.2(a): have the storage media physically destroyed, or use a destruction service
Don't forget these
The one everyone forgets
MOH's Implementation Guide, section B15.2(b): printers and photocopiers store copies internally. Before disposing of one, ask the supplier to wipe or remove its storage.
Keep a disposal record
MOH's Implementation Guide, section B15.3 requires dates, method and who did it:
| Date | What was disposed | Method | Done by |
|---|
B15.3(a): if you use a professional shredding or disposal service, get a certificate of destruction from them and keep it with this record, that's your proof the destruction actually happened, not just that you paid for it.
Where MOH's own guidance falls short
Four things you should know, so you're not left thinking you missed something.
1. The MOH incident reporting form doesn't exist yet
You must notify MOH within 2 hours of confirming a cybersecurity incident (MOH's Implementation Guide, Table 12, page 59). The same table says the reporting-form link "will be added here in 2027." Both the obligation and the mechanism are dated to 2027. Plan for the obligation arriving first.
Use the interim path from item 13: email hia_enquiries@moh.gov.sg, plus the PDPC form and an SPF report, both work today.
2. The retention period numbers are in a document CS/DS only footnotes
The CS/DS Essentials, clause B.4, tells you to set retention periods, then footnotes out to the Licence Conditions on the Retention Periods of Patient Health Records. The only figure inside CS/DS itself is 15 years, for adult inpatient paper records, which is not the number a GP clinic needs.
Read the licence conditions instead. Table 1 gives you the patient's lifetime plus six years for anything electronic, and six years from the last day of consultation for paper outpatient records. Paragraph 16 adds at least 15 years for high risk cases, paragraph 13 adds a hold while a complaint or legal action is live. Your template carries all four. Item 5 walks through them.
That document is versioned and may be amended. Check hcsa.gov.sg for the current version at your annual review.
3. The footnotes go a long way outside the document
CS/DS Essentials carries 24 footnotes, several point to PDPC advisory guidelines, PDPC ICT systems practices, PDPC printing guides, NIST media sanitisation standards.
You don't need to read any of them
Every one of those references is answered in practical terms across this deck. The exception: PDPC's free training resources at pdpc.gov.sg, which you should actually use, the zero-cost route to item 8.
4. MOH's own dates have already moved once
The Circular (6 March 2026) said patient-selectable NEHR sharing and access-restriction features would arrive "in the later part of 2026." The FAQ, five months later, says the "break-glass" feature will be available "from 2027."
Treat the later document as current, but don't build a plan around either date, check the HIA website.
Being behind is not ignoring it
Being behind ≠ ignoring it
MOH Circular, para 13: non-compliance with contribution requirements "is not an offence in the first instance, as MOH recognises that there may be genuine challenges onboarding to NEHR." Where the problem is technical difficulty, MOH's stated first response is to help you fix it. Enforcement escalates only for deliberate or reckless non-compliance.
Still on paper?
Still on paper?
MOH's FAQ, question 22: clinics licensed before 2027 that have difficulty digitalising will get an Alternate Contribution Channel from MOH. Details are still pending. You are not automatically non-compliant.
Who to ask
- MOH questions: hia_enquiries@moh.gov.sg
- NEHR account and onboarding: NEHR.Feedback@synapxe.sg
- Grant applications: nehr.grants@synapxe.sg
About this guide
Independent guidance, free to use, written for a Windows clinic. It is not official MOH material and carries no MOH endorsement. Everything in it is built from MOH's own published documents, listed below. Where MOH's material has a genuine gap, this deck says so rather than filling it in.
Prepared from the HIA Implementation Guide v2.0 (Aug 2026), the CS/DS Essentials (first edition, March 2026), the HIA FAQs v1.1 (13 Aug 2026), and MOH Circular MOH-MHC-0018-2026 (6 Mar 2026). All sources retrieved 18 August 2026. Assumes a Synapxe-certified, Cyber Essentials–certified CMS/HIMS, reconfirm if that changes.