CS/DS Essentials for Solo GPs

CS/DS Essentials for Solo GPs Free and pro bono. Independent guidance, not official MOH material. A Windows walkthrough mapped to MOH's HIA Implementation Guide v2.0
Start here
Your action plan

Start here

This page is the whole plan. Everything after it is reference, jump to what you need, don't read start to finish.

Independent guidance, free to use, built from MOH's own published documents. It is not official MOH material and carries no MOH endorsement.

Your starting position

Your starting position

Assumption: your CMS is whitelisted

This plan assumes your HIMS is Synapxe NEHR Connectivity–certified and Cyber Essentials (CE) certified. Not sure? Check the Synapxe integration status list, or ask your vendor, before relying on this.

That already clears two things for you:

  • Two-factor authentication (item 2e), already satisfied. Skip that setup.
  • NEHR Connect Grant eligibility: already met, if you ever need it.
How to use the rest of this deck

How to use the rest of this deck

  • Not meant to be read front to back
  • Use the sidebar to jump straight to the item you need
  • Each section stands alone, its own MOH citation, its own steps
  • Come back here and tick off the tracker as you go
Your policy document

Your policy document

Assumption: you're using the template

This deck assumes you've got CSDS-Policy-Template-Solo-GP.docx open: a complete Cybersecurity and Data Security Policy, already written, for a fictional clinic. Every clause from Part 1, plus every register and form from Parts 2 and 3, filled in with a realistic worked example. The parts specific to that fictional clinic are highlighted yellow. Find & Replace them with your own clinic's details in Word, and you're done.

That covers the whole tracker below in one file. The slides after this page don't ask you to write anything from scratch, they explain what's already in the template, why it's worded that way, and the one or two gaps you still have to fill in yourself.

Do this first, this morning

Do this first, this morning

This morning

Buy nothing today. Send the vendor email from item 9 to confirm your backup details, how often, where, tested how recently. Your CMS's certification already covers its compliance status; this is about your specific backup arrangement.

Then open Windows Update on your own PC and turn on automatic updates. Five minutes: the single most useful thing on this list.

Your tracker

Your tracker

#ItemDone
5Health info identified, locked away, copied and sent safely
6Health information marked or defined in policy
7Access restricted to those who need it
8Annual training done and recorded
9Vendor questions sent and answered in writing
10Self-review scheduled (we suggest annually)
12Business Continuity Plan written (printed copy recommended)
13Incident Response Plan written (printed copy recommended)
Your tracker, Parts 2 and 3

Your tracker, Parts 2 and 3

#ItemDone
1Automatic updates on, every PC
2Defender, firewall, accounts, passwords, lockout, secure settings, 2FA already done
4Asset register filled, EOS assets identified
3Backup running, drive unplugged, restore tested
11Secure paper disposal in place, wipe procedure written
A Windows walkthrough for a solo GP clinic
HIA · CS/DS Essentials

A Windows walkthrough for a solo GP clinic

Thirteen items. Every instruction mapped to a page of MOH's own Implementation Guide.

Who this is for

Who this is for

  • A solo GP, or a doctor with one or two staff
  • Windows 10 or Windows 11 PCs, bought as ordinary consumer or small-business machines
  • No company network, no server room, no Active Directory, no IT vendor on retainer

If that's you, this guide covers everything.

Your timeline

Your timeline

1 September 2027

NEHR contribution and CS/DS measures must be in place by this date. Outpatient Medical Service (GP) is Batch 1. Specialist, dental and dialysis services each follow their own date. (MOH's Implementation Guide, Chapter 1, Table 1, page 3, and Table 4, page 10)

The NEHR Connect Grant application window closes 31 August 2027 (the Guide, Table 4, page 10).

Where this comes from

Where this comes from

Four MOH documents, all fetched 18 August 2026:

  • CS/DS, Cybersecurity and Data Security Essentials, first edition, March 2026 (16pp)
  • MOH's Implementation Guide, HIA Implementation Guide for Healthcare Providers, Version 2.0, August 2026 (74pp)
  • FAQ: FAQs for Healthcare Providers on the HIA, v1.1, 13 August 2026 (24 questions)
  • MOH Circular MOH-MHC-0018-2026, 6 March 2026

The FAQ has already moved from v1.0 to v1.1 in five months. If you're reading this months after today, check the HIA website before your final sign-off.

One legal note, said once

One legal note, said once

MOH's own Implementation Guide says its sample clauses "are not intended to be an authoritative statement of the law or a substitute for legal or other professional advice" (MOH's Implementation Guide, Annex C, page 47). The same applies here.

This is free, pro bono, practical guidance built on MOH's documents. Get a lawyer involved for the genuinely high-stakes situations, a live data breach, a dispute with your CMS vendor over liability. Not for the routine work ahead.

The money answer, up front
Background

The money answer, up front

Only two of the thirteen items need any spending, provided your PCs are still supported and you can already lock paper away. CS/DS assumes both.

2 / 13
2 / 13
items need any spending
11 / 13
need nothing bought
S$8,400
NEHR Connect Grant, if you need it
MOH says this themselves

MOH says this themselves

The adequacy of security solutions depends on the specific system setup and network complexity. For organisations such as solo practitioners or small clinic chains with simple system setups, Microsoft Defender may provide sufficient firewall protection. This principle applies similarly to antivirus requirements, where built-in operating system security features, such as Microsoft Defender, can meet basic protection needs for less complex environments. However, organisations should evaluate their specific risk profile in the case of multi-tier architecture when determining whether built-in security solutions adequately address their cybersecurity needs or whether additional enterprise-grade solutions are necessary.
MOH's FAQ, question 14, in full

Note what MOH does and does not say. It says Defender may be sufficient for a simple setup, and it asks you to weigh your own risk profile. It does not tell you what to buy, and it does not tell you not to buy. Our own reading, not MOH's: for a single-PC clinic on a simple network, there is nothing here you need to purchase.

And on paying for help

And on paying for help

Engaging professional CS/DS consultancy services is optional, as not every healthcare provider requires such services to meet the necessary CS/DS requirements.
MOH's FAQ, question 23

If a vendor tells you otherwise, that's your answer. The FAQ adds that providers should report unethical conduct by service providers to MOH. It handles pricing differently, by having CSA-qualified CISOaaS providers publish standardised packages with transparent pricing.

What you actually need

What you actually need

What you needCostSource
Anti-malwareNothing to buy: Windows Defender ships with WindowsMOH accepts it for a simple setup, MOH's FAQ, question 14
FirewallNothing to buy: Windows Defender Firewall ships with WindowsMOH accepts it for a simple setup, question 14
Two-factor authenticationFree: Microsoft Authenticator appMOH's Implementation Guide, Annex A, A5, page 27
Staff trainingFree: PDPC self-help resources acceptedthe CS/DS Essentials, clause C.1.1
Every policy, register, plan and templateFree: templates in the Guide, Annexes B–Ethe Guide, pages 38–59
The money answer

The two things you may need to buy

A hard drive for backups (MOH's Implementation Guide, Annex A page 34, Annex D3 page 49), and a paper shredder if you keep paper (the Guide, Annex B15, page 46). The Guide requires both but states no prices anywhere. The only dollar figures in it are grant amounts. About S$60–100 and S$30–50 are our own market estimates, not MOH's.

If you do need to spend

If you do need to spend

NEHR Connect Grant (NCG)

Fixed S$8,400 for a GP clinic under an Outpatient Medical Services licence. Pick a Synapxe-certified HIMS before you apply, at oursggrants.gov.sg. Closes 31 Aug 2027. (MOH's Implementation Guide, Table 2, page 5)

CISO-as-a-Service (CISOaaS)

Up to 70% of a CS/DS consultancy package, through CSA. Optional per MOH's FAQ, question 23. Apply at services2.imda.gov.sg/ctoaas/tag/hia. (the Guide, Table 2, page 4)

And one more

And one more

Productivity Solutions Grant (PSG)

50% of qualifying security products, capped at S$30,000. Apply at apply.gov.sg/grants/business. (MOH's Implementation Guide, Table 2, page 4)

One scheme to ignore

One scheme to ignore

NCSS Transformation Sustainability Scheme

MOH's Implementation Guide, page 5 lists this at 80% funding, capped S$40,000, but it's open only to Community Care Organisations that are NCSS members. A private GP clinic is not one. The Guide doesn't say so on the page that lists it, so it's easy to chase this by mistake.

Every item, mapped to MOH's documents
Background

Every item, mapped to MOH's documents

Use this to jump straight to any item, or to hand an auditor a trace.

Part 1: the paperwork (free)

Part 1: the paperwork (free)

CS/DS itemCoversEssentials refGuide ref
5. SecureKnow, store, copy and send health info safelyB.1–B.7Annex B5–B9, C
6. IdentifyMark documents as health informationB.8–B.9Annex B10
7. AccessOnly people who need it get accessB.10Annex B11, C
8. TrainingAnnual security awareness trainingC.1–C.2Annex B12
Part 1: the paperwork, continued

Part 1: the paperwork, continued

CS/DS itemCoversEssentials refGuide ref
9. VendorKnow what your CMS provider doesC.3–C.5Annex B13, D Table 7
10. ReviewCheck yourself periodicallyC.6–C.8Annex B14, B16
12. ContingencyBusiness Continuity PlanC.10Annex D
13. Incident responseIncident Response Plan and reportingC.11–C.14Annex E
Part 2: Windows settings (free unless a PC is unsupported)

Part 2: Windows settings (free unless a PC is unsupported)

CS/DS itemCoversEssentials refGuide ref
1. UpdatesInstall software updates promptlyA.1Annex A, A1
2. Secure/ProtectAnti-malware, firewall, accounts, passwords, 2FA, lockout, logging, settingsA.2–A.12Annex A A2–A8; Annex B1–B2B
4. AssetList hardware and software, replace what's unsupportedA.15–A.18Annex B3B, B4, B4A
Part 3: the two purchases

Part 3: the two purchases

CS/DS itemCoversEssentials refGuide ref
3. BackupBack up essential data, store separately, test the restoreA.13–A.14Annex A A8-4; B3, B3A; D3
11. DisposalShred paper, wipe drivesC.9Annex B15
Two things not on this list

Two things not on this list

Self-assessment questions

MOH's own self-check questions are at MOH's Implementation Guide, Chapter 3, Table 5, pages 15–18. You don't need to read them, every one is answered by a section ahead.

the Guide, Annex F, the NEHR use policy

A sample policy on who in your clinic may look at NEHR, and why (pages 60–61). Not one of the 13 CS/DS items. Do this separately, when you onboard to NEHR.

Already in your template

Already in your template

CS/DS item 5. Clauses B.1–B.7. MOH's Implementation Guide, Annex B5–B9, pages 41–44; Annex C, page 47.

Already in your template. Section 1

Your organisation's health information is stored in [your clinic software] and [your filing cabinet, named by location], retained for the patient's lifetime plus six years (anything electronic, including scans) and six years from the last day of consultation (paper outpatient), with at least 15 years for high risk cases. Copies are made only when needed, on clinic equipment, never left at the photocopier. Emailed files are password-protected with the password sent a separate way. WhatsApp is scheduling only, no medical content.

Find & Replace the yellow brackets with your own details. The slides after this one give you the citation and the gap note behind each line, in case you or an auditor ever need to check where it came from.

The number is in your licence conditions

The number is in your licence conditions

Already filled in for you

The retention period is the one figure that is not in the Implementation Guide or the Essentials. It is in a separate document your clinic is already bound by: the Licence Conditions on the Retention Periods of Patient Health Records, imposed under section 13(1) of the Healthcare Services Act. Your template now carries all four periods from it. See 5b, ahead, for what they are.

Know what health info you hold, and handle it safely

Know what health info you hold, and handle it safely

Three questions the template above already answers: Where does your patient data live, physically and digitally? How do you stop copies leaking? How do you send it to someone else without exposing it?

5a. Where it lives

5a. Where it lives

The source behind the first paragraph of your template. MOH's Implementation Guide, section B5 (page 41) gives you the sentence:

"All personnel must note that our organisation's health information is stored in [our HIMS: name it] and [your filing cabinet, named by location]."

List every place: the CMS database, the filing cabinet behind reception, the old box of records in the store room, the clinic laptop. Paper records at a commercial storage facility? the CS/DS Essentials, clause B.3 wants you to have checked that facility's security and to keep a list of what you sent there.

5b. How long you keep it

5b. How long you keep it

The source behind the retention line in your template. The CS/DS Essentials, clause B.4, tells you to set retention periods but doesn't give the numbers. It points to the Licence Conditions on the Retention Periods of Patient Health Records, imposed under section 13(1) of the Healthcare Services Act. Those are the numbers.

Table 1, and paragraphs 13 and 16

Anything electronic, including paper you have scanned: the patient's lifetime plus six years. A scanned record counts as electronic from the moment you scan it (paragraph 9), which is why this period is the one that binds most GP clinics.

Paper outpatient records: six years from the last day of consultation or treatment, whichever is later.

High risk patients and cases: at least 15 years. Three things count as high risk, and the licence conditions name them: complications during treatment, an open complaint, and a patient who lacked mental capacity, or you suspect lacked it, at the time.

A complaint or legal action underway, or one you can see coming: keep the whole record until it is over, even if the period above has run out.

Two things worth knowing. "Lifetime" means the patient's actual lifetime, or 110 years where you don't know the date of death. And you may cull paper after four years, provided you keep the 15 categories listed in paragraph 8: discharge summaries, operation reports, consent forms, x-ray and histopathology reports, treatment and progress notes, prescription orders, and the rest.

These are licence conditions, not guidance. A breach is actionable under section 20 of the HCSA. They are also minimums: keep records longer if you want, never shorter.

5c. Copies

5c. Copies

The source behind the third paragraph of your template. MOH's Implementation Guide, section B8, page 43. Copies made only when needed for work, on clinic equipment. Never leave a printout at the photocopier. Shred misprints and jams immediately.

5d. Sending

5d. Sending

The source behind the fourth paragraph of your template. MOH's Implementation Guide, section B9, page 44; the CS/DS Essentials, clause B.7.4: the rule that catches people out:

Password and delivery route must never match

Any file with patient information sent by email must be password-protected. The password goes a different route, phone call or SMS, never the same email. MOH's FAQ, question 17: if the email account is compromised, sending both together exposes both at once.

5d. Sending, in practice

5d. Sending, in practice

Free ways to password-protect a file:

  • Word/Excel: FileInfoProtect Document/WorkbookEncrypt with Password
  • Any file: 7-Zip (free) → right-click → 7-ZipAdd to archiveAES-256 → set a password
5e. WhatsApp

5e. WhatsApp

The source behind the last paragraph of your template. MOH's FAQ, question 18. Fine for basic appointment scheduling: dates and times, no medical content. Anything with medical information goes through the clinic's official email instead.

5f. Confidentiality clauses

5f. Confidentiality clauses

the CS/DS Essentials, clause B.1. MOH's Implementation Guide has two ready-made contract clauses (one for vendor and contractor agreements, one for employment contracts) each prohibiting unauthorised disclosure of health information.

Not for your policy document

These two clauses are separate from the CS/DS Policy in your template. They go into your actual employment contracts and vendor/contractor agreements instead, new hires and new vendors from here on, and existing ones at your next renewal.

Where to find the full clause text

Where to find the full clause text

Already in your template, and marked to delete

Both full clauses are already typed out in your template, right after this section, under "Confidentiality clause for contracts." They're not part of the policy itself, your template says so in plain text, and tells you exactly what to do: copy each clause into the matching contract, then delete that whole section from your policy document.

The Implementation Guide's own description page (Annex C, page 47) just explains that these clauses exist, the real text is appended as the final two pages of the 74-page PDF (pages 73–74), which is why MOH's own guide is awkward to copy from directly.

Already in your template

Already in your template

CS/DS item 6. Clauses B.8–B.9. MOH's Implementation Guide, Annex B10, page 44. Free. Already in Section 2 of your template. The point: anyone picking up a document knows it needs protecting. MOH accepts either marking every document, or (easier, and what a solo GP should use) stating in your policy what counts as health information and skipping individual labels (the CS/DS Essentials, clause B.8.2):

"All information in medical reports, patient consultation notes, treatment plans, prescription letters, referral letters and laboratory results is health information and must be handled under this policy."
Suggested wording for your policy, not MOH's

Optional extra: a rubber stamp reading "Health Information," about S$10, for your paper files. Not required.

Already in your template

Already in your template

CS/DS item 7. Clause B.10. MOH's Implementation Guide, Annex B11, page 44. Free. Already in Section 3 of your template. Two conditions must both be met before someone can see patient data: they need it for their job, and they've been told the rules and acknowledged them. Adapted from the Guide, section B11 for a clinic where you're the authority:

"Personnel may access health information only where necessary to carry out their work, and only as authorised by [your name], the doctor-in-charge. Access is limited to what the role requires. No one is given access before they have read this policy and confirmed in writing that they understand it."
Restrict access

\

the CS/DS Essentials, footnote 14: an email reply saying "I understand the data security measures" counts, as does an attendance record from a briefing. For a solo practice this is one page and one email from your clinic assistant.

The technical half of this item (giving each person their own login) is item 2c, ahead in Part 2.

Already in your template

Already in your template

CS/DS item 8. Clauses C.1–C.2. MOH's Implementation Guide, Annex B12, page 45. Free. Already in Section 4 of your template, verbatim from MOH's Implementation Guide, the two clauses this item actually asks you to have in writing:

Already in your template. Section 4

All personnel must ensure that they attend cybersecurity and data security-related awareness training at least once every year. This is necessary to ensure that all personnel are aware of and kept up-to-date on the applicable security measures, and their roles and responsibilities in ensuring the security of health information.

All personnel must abide by any cybersecurity or data security policies and practices that may be implemented by our organisation in our operations.

What to do

What to do

the CS/DS Essentials, clause C.1.1 accepts in-house, external vendor, or PDPC's free self-help resources, that third route:

  1. Go to pdpc.gov.sg and find their data protection self-help and e-learning resources
  2. Sit with your staff for an hour. Cover phishing emails, strong passphrases, not leaving records on the counter
  3. Write the date, who attended, and what you covered on a single page. Sign it. File it
Train your staff

That page is your evidence. Repeat annually.

Do not pay a vendor to run a session for two people.

One click

One click

CS/DS item 9. Clauses C.3–C.5. MOH's Implementation Guide, Annex B13, page 45; Annex D Table 7, pages 49–50. Free. Everything you need is right here, the full subject line and all ten questions, ready to send as-is. Nothing else to look up.

One click

Open this as a ready-to-send email →, opens in your email app with the subject and all ten questions already filled in. Just add your vendor's address and send.

The email: part 1

The email: part 1

Subject: HIA CS/DS Essentials: questions about our clinic's data

We are preparing for the HIA cybersecurity and data security requirements. Could you answer the following in writing?

  1. Is your system HIA-compliant, NEHR Connectivity certification, Cyber Essentials (CE) certification submitted to NEHR, and Code of Practice for Data Portability compliance declared? If not yet, what's your timeline?
  2. What data of ours is backed up, all patient records, appointment histories and clinical notes?
  3. How often do backups run, and where are they stored, same server as live data, or separate?
The email: part 2

The email: part 2

  1. Are our backups stored in Singapore? If not, which country?
  2. How do you verify backups actually work? When was a restore last tested successfully?
  3. Are our backups encrypted, and who on your side can access them?
  4. If we lost data tomorrow, how quickly could you restore it, and how far back can you go?
The email: part 3

The email: part 3

  1. Is there anything we need to do on our end for backups to run correctly? Will you notify us if one fails?
  2. Who is responsible for what if there's a security incident or breach?
  3. Will you send us regular updates on security issues and vulnerabilities affecting our system?
This is a phone call, not a purchase

This is a phone call, not a purchase

the CS/DS Essentials, clause C.4 needs you to understand where your patient data is stored, what safeguards the vendor has, and who's responsible for what when something goes wrong.

Question 1 is already answered

If your CMS is on MOH's whitelist (Synapxe NEHR Connectivity–certified and Cyber Essentials certified) you already know it's HIA-compliant. Send question 1 anyway, for a written record; the rest of this email is where the real work is.

What the reply confirms

What the reply confirms

What being whitelisted already gives you

NEHR Connect Grant eligibility (a Synapxe-certified HIMS is the precondition), and the 2FA setup in item 2e, both already sorted. Still worth checking your CMS's status yourself at the Synapxe integration status list, in case it's changed.

Keep the reply: that email thread is your vendor management evidence.

Already in your template

Already in your template

CS/DS item 10. Clauses C.6–C.8. MOH's Implementation Guide, Annex B14, page 45; B16, page 46. Free. Already in Section 6 of your template. No external auditor required: the CS/DS Essentials, clause C.7 says self-assessment is acceptable. From the Guide, section B14:

"[Your name] will review this policy and the clinic's compliance with it every twelve months, in [pick a month]. Any lapse found will be fixed at once, and additional training given where needed."

Set a calendar reminder for the month your template already names. Your review: reread this guide, walk the thirteen items, note what's drifted, fix it, write the date on the page.

Already in your template, continued

Already in your template, continued

MOH's Implementation Guide, section B16, page 46, also wants a named person accountable for explaining the policy to new hires, that's you:

"[Your name] is accountable for explaining the Policy to all new hires and other personnel. All personnel are required to familiarise themselves with, and comply with, this Policy. Failure to comply with this Policy may result in disciplinary and other action."
Already in your template

Already in your template

CS/DS item 12. Clause C.10. MOH's Implementation Guide, Annex D, pages 48–52. Free. Your CMS is down at 9am and there are patients in the waiting room. This is the plan for that. Already assembled for you, in Section 8 of your template.

Already in your template. Section 8

Critical functions. Consultations and dispensing must continue during any outage. Everything else can wait.

Paper fallback. Printed stacks of a blank consultation note, an appointment sheet, and a billing slip are kept at [location, e.g. reception, consultation room]. Paper notes from the outage are entered into the CMS as soon as practically feasible after restoration.

Already in your template, continued

Already in your template, continued

Already in your template. Section 8, continued

High-risk patients. An offline list of patients on critical medication is kept at [location], for contacting during a multi-day outage.

Communications. Staff numbers, [CMS vendor]'s support number ([number]), and [your mobile] are on paper at [location]. Not only in a phone.

Testing. This plan is tested once a year, in [month], by running one morning on the paper templates above.

Print Section 8 on its own, a digital plan is useless when the systems holding it are down.

Where each line comes from

Where each line comes from

MOH's Implementation Guide, Annex D is six sections of questions (D1–D6). Talking points MOH expects you to have thought through, not a fill-in form.

Where each line comes from, continued

Where each line comes from, continued

Critical functions (D1, page 48)

Consultations and dispensing must continue. Everything else can wait.

Paper fallback (D2, page 48)

Keep printed stacks: a blank consultation note, an appointment sheet, a billing slip. Store them somewhere obvious. Write: "Paper notes from the outage are entered into the CMS as soon as practically feasible after restoration."

High-risk patients (D2.2, page 49)

A short offline list of patients on critical medication who'd need contacting during a multi-day outage.

Communications (D5, page 52)

Staff phone numbers, your CMS vendor's support number, your own mobile, on paper, not only in your phone.

Testing

Testing

Test it once a year: run one morning on paper templates. MOH's Implementation Guide (Annex D, page 52) asks only whether you have “a realistic schedule” and sets no cadence. Once a year is our recommendation, not MOH's requirement.

A BCP that has never been tested is a plan that may fail when it matters most.
MOH's Implementation Guide, Annex D
Who does what

Who does what

CS/DS item 13. Clauses C.11–C.14. MOH's Implementation Guide, Annex E, pages 53–59. Free. the Guide, Table 9, page 54, lists four roles: incident commander, IT/technical lead, Data Protection Officer, communications and legal lead.

You do not need four people

The Guide says so on the same page: in a solo practice it may be you and one or two trusted staff, each with a defined role.

Incident commander, DPO and communications: [your name], [your mobile] Technical response: [CMS vendor name], [their support number] Recording what happened: [clinic assistant's name], or you if alone

How you spot an incident

How you spot an incident

MOH's Implementation Guide, Table 10, page 55, the signs a GP clinic actually sees:

  • Files renamed with odd extensions, or a payment-demand message on screen
  • Patient records that opened yesterday won't open today
  • Emails going out from the clinic account that nobody sent
  • An email with patient results sent to the wrong person
  • A clinic laptop or paper file that can't be found
  • A former staff member's login still active after they left
The ransomware response card

The ransomware response card

MOH built an actual printable card for this (MOH's Implementation Guide, Table 8, page 51), not just steps to read, a card to fill in and pin up. Print this one and stick it inside a cupboard door.

How to spot it: does something look wrong? Files cannot be opened or have strange names. A ransom message has appeared on screen.

The card: steps 1 to 3

The card: steps 1 to 3

1) Disconnect. Unplug the network cable or turn off Wi-Fi on affected computers. Do not switch the computer off completely, this destroys forensic evidence needed for investigation.

2) Stop and assess. Can you still see patients safely? If yes, consider activating your BCP (switch to paper records, item 12). If no, consider diverting patients, telling them promptly, or rescheduling.

3) Call for help. Keep names and numbers ready: your CMS provider / IT vendor, and key personnel in your clinic.

The card: steps 4 to 6

The card: steps 4 to 6

4) Do not pay the ransom. Paying does not guarantee recovery. Consult and wait for advice from your IT vendor first.

5) Report if patient data is affected. Have the reporting hotline numbers of the relevant authorities ready (reporting timelines, next).

6) Wait for the "all clear." Only restart and restore systems once your IT vendor confirms it's safe. Change all passwords after restoration.

The card: after the incident

The card: after the incident

After the incident: write down what happened and when. Your organisation will need this for reporting, and to prevent it happening again, times, which machines, what patient information might be involved, roughly how many patients, what you did. Photograph error messages. Use a clean device for reporting and for contacting patients about urgent medical matters.

Print the card with this line at the bottom, filled in:

Prepared by: [your name] | Version: [1] | Date: [today's date]

Wrong-recipient email, not a hack? MOH's Implementation Guide, Table 11: try to recall it immediately, then contact the recipient and ask them to delete it without opening the attachment.

Reporting: and the gap you need to know about

Reporting: and the gap you need to know about

MOH's reporting timelines (MOH's Implementation Guide, Table 12, page 59):

WhoWhenWhat
MOHWithin 2 hours of confirming itAll confirmed cybersecurity incidents, and data breaches likely to cause significant harm or affecting 500+ people
PDPCWithin 72 hoursBreaches likely to cause significant harm, or 500+ people
SPFAs soon as possibleRansomware or monetary loss

Plus a full report to MOH within 14 days. Tell affected patients at the same time as MOH if likely to cause them significant harm (the CS/DS Essentials, Table 2, page 16).

The gap

The gap

MOH's own reporting form doesn't exist yet

MOH's Implementation Guide, Table 12: the MOH "Reporting Method" column says "The link to the MOH incident reporting form will be added here in 2027." the CS/DS Essentials, clause C.14 says the same. Both the two-hour obligation and the form are dated to 2027. Plan for the obligation arriving first. This is MOH's gap, not yours.

Until the form appears

Until the form appears

If MOH's incident reporting form is not yet live, email hia_enquiries@moh.gov.sg within 2 hours with the incident details, and keep the sent copy. File the PDPC notification through the PDPC form (works today) and lodge a police report through the SPF e-service form where ransomware or monetary loss is involved.

Check whether MOH's form has gone live at your annual review.

Do this on every PC

Do this on every PC

CS/DS item 1. Clause A.1. MOH's Implementation Guide, Annex A, A1, page 20. Free. This is the single highest-value five minutes in the whole guide.

Windows 11: SettingsWindows Update Windows 10: SettingsUpdate & SecurityWindows Update

Do this on every PC, continued

Do this on every PC, continued

  1. Click Check for updates. Install everything offered. Restart when asked
  2. Advanced options → turn on Receive updates for other Microsoft products: this keeps Word, Excel and Outlook patched too
  3. Still in Advanced options, set Active hours to your clinic hours so restarts never happen mid-consultation
  4. Turn on Get the latest updates as soon as they're available, if you see it
Turn on updates

Include the reception machine.

Your CMS or HIMS is separate. Its updates are the vendor's job. That's question 10 in the vendor email at item 9.

Part 2 is the clicking-through-Windows-settings part, budget two hours per PC for the first one, twenty minutes for each after. If a menu name doesn't match what's shown, use the Windows search box.

2a. Anti-malware

2a. Anti-malware

CS/DS item 2. Clauses A.2–A.12. MOH's Implementation Guide, Annex A, A2–A8, pages 21–33; Annex B1–B2B, pages 38–39. Free. The biggest item: seven parts, a–g, starting here. the CS/DS Essentials, clause A.2. The Guide, Annex A, A2, page 21.

Windows Defender is already on your PC, and MOH has confirmed it meets this requirement for a clinic your size (MOH's FAQ, question 14). No extra anti-virus purchase is needed to comply.

Path: SettingsPrivacy & securityWindows SecurityVirus & threat protection

2a. Anti-malware, continued

2a. Anti-malware, continued

Under Virus & threat protection settingsManage settings, all four should be On: Real-time protection, Cloud-delivered protection, Automatic sample submission, Tamper protection.

Then: Protection updatesCheck for updates. Then: Scan optionsFull scanScan now, once today.

2a. USB drives

2a. USB drives

If a specialist or lab sends you a drive too large to scan properly, MOH's FAQ, question 15 says you're not required to deep-scan the whole thing:

Healthcare providers are not required to perform a full, deep-scan of the entire USB content. Instead, they should ensure their built-in anti-malware systems are configured to provide real-time protection.
question 15

Real-time protection, already on. Nothing more to do.

2b. Firewall

2b. Firewall

the CS/DS Essentials, clause A.3. MOH's Implementation Guide, Annex A, A2 continued, page 22.

clause A.3: for "a simple organisation setup... comprising just endpoints connecting to the internet," the OS firewall plus your router's is what's expected. No hardware purchase.

Path: Windows SecurityFirewall & network protection: Domain, Private and Public network must all say On.

Then log into your router's admin page and confirm its firewall is enabled (usually on by default). While there, change the router's admin password if it's still the factory default (clause A.8 requires it).

2c. One login per person

2c. One login per person

the CS/DS Essentials, clause A.5–A.7, A.9–A.10. MOH's Implementation Guide, Annex A, A3–A4, pages 23–26; Annex B2, B2A, pages 38–39.

The rule: nobody shares a login. Not the doctor's, not reception's.

Create an account: SettingsAccountsOther usersAdd accountI don't have this person's sign-in informationAdd a user without a Microsoft account

Set the account type: click the account → Change account typeStandard User. Only your own account should be Administrator (clause A.6.2).

2c. Removing a login

2c. Removing a login

Remove an account when someone leaves: SettingsAccountsOther users → click it → Remove. the CS/DS Essentials, clause A.6.1 gives 60 days of inactivity as the marker for a sweep.

See every account: Windows key → type netplwiz.

2c. The account register

2c. The account register

the CS/DS Essentials, clause A.5.1 wants a list with six fields, MOH's Implementation Guide, Annex B2, page 38, has the template. For a two-person clinic:

NameUsernameDepartmentRoleAccess createdLast log-on
Dr [name][username]ClinicalAdministrator[date][date]
[assistant][username]ReceptionStandard user[date][date]

Add rows for CMS logins and any vendor account.

2c. Requesting access: the email

2c. Requesting access: the email

MOH's Implementation Guide, Annex B2A, page 64. Every access change (a new hire, a role change, a vendor login) starts as a written request. MOH gives you the exact email.

One click

Open a ready-to-send access request →, subject and fields already filled in, edit the brackets and send.

2c. Approving access

2c. Approving access

MOH's Implementation Guide, Annex B2A, page 65. Not an email: three checks before you say yes, plus a log entry.

  1. Access is granted only to the specific system requested
  2. Access matches what the role actually needs. Ask "why does this person need this?"
  3. The doctor (or IT support) records the access in the register above

Example row from MOH's own sample log:

NameSystemDepartmentRoleFromTo
Nurse AlicePatient Records / Billing FolderClinic OperationsUser05 Apr 2026NA
2c. Revoking access

2c. Revoking access

MOH's Implementation Guide, Annex B2A, page 66. When someone leaves, or a vendor's work ends, same day, not "when you get around to it."

One click

Open a ready-to-send access revocation →, subject and fields already filled in, edit the brackets and send.

2c. Third-party logins

2c. Third-party logins

Third parties

the CS/DS Essentials, clause A.9.1: any vendor or contractor login needs a signed NDA first. Sign before handing over access; remove the account when the work ends.

Where MOH actually put it

MOH's Implementation Guide, Annex A, A4, page 26, just describes that a sample NDA exists, the real clause text is on page 63. For a solo clinic, the vendor/contractor confidentiality clause already in Section 1 of your template covers the same ground; use the Guide, Annex A page 63 directly only if a vendor specifically wants a standalone NDA.

2c. Third-party access request form

2c. Third-party access request form

MOH's Implementation Guide, Annex A, A4, page 63. The other half of the same page, what the vendor fills in before you grant them anything.

Contractor name · Contact details · What they need access to · Why they need it · Start date · End date · Tick all that apply: General data only / Patient health information required / IT equipment required (specify) · Your organisation's name · Your signature · Date

2d. Passwords

2d. Passwords

the CS/DS Essentials, clause A.8. MOH's Implementation Guide, Annex B2B, page 39.

A strong passphrase: 12+ characters, mixed case and special characters, not a common word or obvious pattern (the Essentials, footnote 4).

  1. Change any password still on a factory default, router, CMS admin, network printer, anything
  2. Write the rule into your policy: passwords change immediately on any suspected compromise or lost token (the Guide, section B2B)
  3. To change a Windows password: Ctrl + Alt + DeleteChange a password
2d. Passwords, in practice

2d. Passwords, in practice

Tell staff: four unrelated words plus a number and symbol. "Kopi7Bicycle!Rain" beats "Cl1n1c@2026" on both strength and memorability.

2e. Two-factor authentication

2e. Two-factor authentication

the CS/DS Essentials, clause A.8.2. MOH's Implementation Guide, Annex A, A5, page 27. Free.

A code from your phone on top of your password, for admin and remote access to important systems.

Already done, on your setup

The Guide, Annex A, A5 footnote, page 27: "Skip this part if you are using CE-certified HIMS to process and store all your health information." Your CMS is on the whitelist (Synapxe NEHR Connectivity–certified and Cyber Essentials certified) so this item is done. Nothing to click.

2e. If that ever changes

2e. If that ever changes

If you switch to a HIMS that isn't CE-certified, or add a system outside it: install Microsoft Authenticator (free). For Microsoft/Office 365: account.microsoft.com → SecurityAdvanced security optionsTwo-step verification → scan the QR code. For your CMS: ask the vendor to enable it on your admin account.

2f. Lock the account after failed logins

2f. Lock the account after failed logins

the CS/DS Essentials, clause A.8.3. MOH's Implementation Guide, Annex A, A6, page 28. Free.

Stops someone guessing passwords all afternoon. clause A.8.3 gives 10 failed attempts as the example.

Group Policy is not available on Windows Home

The Guide's Annex A uses gpedit.msc. Most clinic PCs won't have it. Here's what works on every edition, Home included.

2f. The command that works everywhere

2f. The command that works everywhere

  1. Windows key → type cmd
  2. Right-click Command PromptRun as administrator
  3. Type and Enter: net accounts /lockoutthreshold:10 /lockoutduration:15 /lockoutwindow:15

Confirm with net accounts: check the "Lockout threshold" line. Recent Windows 11 builds may already ship a default of 10; run net accounts first to check.

2g. Secure settings

2g. Secure settings

the CS/DS Essentials, clause A.12. MOH's Implementation Guide, Annex A, A8, pages 31–33. Free. One pass per PC: new machines ship with risk switched on by default.

Turn off unused Windows features (the Guide, section A8, page 31): Control PanelProgramsTurn Windows features on or off. Uncheck: Windows Media Player, Microsoft XPS Document Writer, SMB Direct, Windows TIFF IFilter, and SMB 1.0/CIFS File Sharing Support if it appears (a known ransomware route).

Stop auto-connecting to Wi-Fi (the Guide, section A8-2, page 32; clause A.12.3): SettingsNetwork & internetWi-FiManage known networks → each network → uncheck Connect automatically when in range. Delete any network you don't recognise.

2g. Secure settings, continued

2g. Secure settings, continued

Turn off AutoPlay (MOH's Implementation Guide, section A8-3, page 33), stops a USB drive running something the moment it's plugged in.

Windows 11: SettingsBluetooth & devicesAutoPlayOff Windows 10: SettingsDevicesAutoPlayOff

Screen locks (the CS/DS Essentials, clause B.2): SettingsAccountsSign-in optionsIf you've been away, when should Windows require you to sign in again?When PC wakes up from sleep. Then SettingsSystemPower & battery → screen off after 5–10 minutes. Teach everyone Windows key + L (the Guide, section B6.4).

2g. Secure settings, last bit

2g. Secure settings, last bit

Privacy filter (the CS/DS Essentials, clause B.7.3; MOH's Implementation Guide, section B9.3): turn the reception monitor away from the waiting area, free, and usually enough. A privacy filter is about S$40 if you want one.

Login logging (clause A.11; the Guide, Annex A, A7, pages 29–30): Windows keeps this automatically. Windows key → Event ViewerWindows LogsSecurity. Event ID 4624 is a successful sign-in, 4625 a failed one. You don't need to read these daily, just know where they are.

The template

The template

CS/DS item 4. Clauses A.15–A.18. MOH's Implementation Guide, Annex B3B, page 40 (form, page 70); B4, page 41 (register, page 71); B4A, page 41 (form, page 72). MOH's own sample asset register (the Guide, Annex B4, page 71) uses different columns than you might expect, asset name and type, not serial numbers:

Asset IDAsset nameTypeUserLocationApprovalStatusEOS date
The template, filled in

The template, filled in

MOH's own worked example, your register should look like this:

Asset IDAsset nameTypeUserApprovalStatusEOS date
e.g. 01Laptop AHardware,01 Jan 2026Active01 Dec 2028
e.g. 02Computer AHardwareDr. Smith01 Jan 2026Active01 Dec 2028
e.g. 04Laptop BHardwareNurse Ang01 Dec 2018Removed01 Jun 2018

That last row is the one MOH's own guide references elsewhere: an asset with an EOS date of 1 June 2018, removed rather than kept running.

Compiling your list

Compiling your list

You can't protect equipment you've forgotten about. This is an afternoon of walking around with a notebook.

What to list: every PC, laptop, tablet and printer, your router, any external drive or USB stick used for clinic data, and every piece of software.

Find a PC's Windows version: Windows key → type winver.

The End-of-Support question

The End-of-Support question

the CS/DS Essentials, clause A.17: hardware and software past End-of-Support must be replaced. Meaning the maker has stopped issuing security patches.

For a clinic, check your Windows version:

  • Windows 11, supported, nothing to do
  • Windows 10, Microsoft ended support in October 2025. Upgrade free via SettingsWindows Update if the hardware qualifies, or plan to replace the machine before September 2027
  • Windows 8.1, 7, or older: replace it. The one line item here that can cost real money
Windows Home is fine

Windows Home is fine

Home edition is fine

Whether your PCs run Windows Home or Pro makes no difference. Microsoft's licence doesn't restrict Home to personal use, and nothing in the CS/DS Essentials requires a Pro-only feature. The word "encrypt" appears once in the whole CS/DS Essentials, at C.9, about wiping a drive before disposal (item 11), which Home does perfectly well. Don't spend money upgrading to Pro for compliance.

If a machine has to stay

If a machine has to stay

If you must keep an unsupported machine running a while, the CS/DS Essentials, clause A.18 requires you to write down the risk, approve continued use yourself, and monitor it until replaced. MOH's EOS form (MOH's Implementation Guide, Annex B4A, page 72) is the fastest way to do that, fill in the fields below for the machine.

A. Equipment name (e.g. laptop, clinic system, software name): B. Location (e.g. Room 1, Counter): C. User (e.g. Dr Tan / Nurse A): D. End-of-Support date (if unsure, write "Unknown"), E. Reason: tick still needed for patient care or no replacement yet, F. Planned replacement date.

The EOS form: risks and safety measures

The EOS form: risks and safety measures

G. Risks (tick all that apply): no security updates · higher risk of virus or malware infection · patient data may be exposed or leaked · may stop working suddenly · slow performance · no technical support if problems occur · cannot connect properly to newer systems · data may be lost if the system fails · backups may not work properly.

H. Safety measures (tick all that apply): only authorised staff use this · not connected to public internet · important data is backed up.

The EOS form: approval

The EOS form: approval

Approval: Decision: approved to continue using / not approved. Approver name (senior management, i.e. you as clinic owner), signature, date.

Grant it before you buy it

If you do need to replace hardware, apply for the grant before you spend. NCG gives GP clinics a fixed S$8,400; PSG covers 50% up to S$30,000. Applying after the fact doesn't work.

Authorising new equipment

Authorising new equipment

the CS/DS Essentials, clause A.15 also wants a protocol for authorising new equipment, for a solo clinic, one sentence in your policy is enough: "No computer, tablet or software is used for clinic work unless [your name] has approved it and added it to the asset register."

MOH's own request form (MOH's Implementation Guide, Annex B3B, page 70), if you'd rather use one: Item name · Type (tick: computer / software / medical device / other) · Requested by · Purpose or business reason · Approved by · Signature · Date.

Recording the split, the actual template

Recording the split, the actual template

CS/DS item 3. Clauses A.13–A.14. MOH's Implementation Guide, Annex A A8-4, page 34; Annex B3, B3A, page 40; Annex D3, page 49. One-time cost: S$60–100. Your patient records are almost certainly in your CMS, and your vendor is backing them up, questions 2–8 in the item 9 vendor email cover this. What's not covered: everything sitting on your PCs, which you back up yourself.

MOH's own form for recording the split (the Guide, Annex B3A, page 67), one page, fill in once:

Service name · Provider · Responsibilities of the cloud service provider (tick: infrastructure backup, platform availability, disaster recovery, other) · Responsibilities of your clinic (tick: our data backup and recovery, our user account management, compliance with regulations, other) · Documented by · Date.

If you use a cloud backup provider, the email

If you use a cloud backup provider, the email

MOH's Implementation Guide, Annex B3, page 68. Only relevant if you're paying for a separate cloud backup service beyond your CMS, not needed if the drive below is your whole plan.

One click

Open a ready-to-send clarification request →, subject and questions already filled in.

What to buy, and how

What to buy, and how

One external hard drive, 1TB or 2TB, about S$60–100. That's the entire purchase.

Option A, File History (simplest): Control PanelSystem and SecurityFile History → select your drive → Turn on. Advanced settingsSave copies of filesDaily.

Option B, Backup and Restore: Control PanelSystem and SecurityBackup and Restore (Windows 7)Set up backup → choose your drive → Let Windows chooseSave settings and run backup. Set the schedule to daily, after clinic hours.

Windows 11's Windows Backup app goes to OneDrive, not a local drive, fine as a second copy, not your only one.

The first rule people get wrong

The first rule people get wrong

Store it separately

the CS/DS Essentials, clause A.13.3: backups must be "stored separately and isolated from the operating environment." MOH's Implementation Guide, section D3.1(b): a drive left permanently plugged in gets encrypted by the same ransomware that hits your PC.

Run the backup, then unplug the drive and lock it in a drawer. Better: two drives, alternated, one kept off-site. A free OneDrive or Google Drive tier can serve as that second copy for non-patient files.

Writing the plan down

Writing the plan down

MOH's own form for a two-copy backup plan (MOH's Implementation Guide, Annex B3, page 69):

Primary backup, Cloud provider (if you have one) · Service · Frequency (e.g. every 30 days). Secondary backup: your external hard drive · Frequency (e.g. monthly) · Location (e.g. clinic's lockable cabinet). Documented by · Date.

No cloud provider? Leave the primary section blank and just fill in the secondary, the hard drive is your whole plan.

The second rule people get wrong

The second rule people get wrong

Test the restore

MOH's Implementation Guide, section D3.2, page 49: "A backup that has never been verified may be corrupted, incomplete, or inaccessible precisely when you need it most." Do this once, today, pick a file, delete it, restore it, confirm it opens. Write the date on your policy. Repeat yearly.

An untested backup is not a backup.

Part 3 is the two things on this whole list that cost money, this drive, and the shredder in item 11, next. Both are one-time purchases.

Paper

Paper

CS/DS item 11. Clause C.9. MOH's Implementation Guide, Annex B15, page 46. One-time cost: S$30–50, and only if you keep paper. The Guide, section B15.1: hardcopy documents with health information go through designated secure waste containers or approved shredding equipment. A cross-cut shredder is about S$30–50. A clinic that keeps no paper with patient information on it has nothing to shred and nothing to buy, and should say so in its policy rather than claim a control it does not have.

Put it next to reception. One rule for staff:

"No document containing patient information goes into a normal bin. Everything is shredded, including misprints, paper jams and test copies."

the CS/DS Essentials, footnote 20 points to two NIST media sanitisation standards. You don't need to read them to shred paper in a GP clinic. A cross-cut shredder covers it.

Computers and drives: free

Computers and drives: free

MOH's Implementation Guide, section B15.2: drives encrypted before reformatting, then overwritten multiple times.

  1. Check encryption: SettingsPrivacy & securityDevice encryption. On Pro, Control PanelSystem and SecurityBitLocker Drive EncryptionTurn on BitLocker. Neither available? Skip to step 2: it still does the job
  2. SettingsSystemRecoveryReset this PCRemove everythingChange settingsClean data: Yes. This overwrites the drive, not just the index. Takes a few hours: let it run overnight
  3. Drive can't be wiped because the machine is dead? The Guide, section B15.2(a): have the storage media physically destroyed, or use a destruction service
Don't forget these

Don't forget these

The one everyone forgets

MOH's Implementation Guide, section B15.2(b): printers and photocopiers store copies internally. Before disposing of one, ask the supplier to wipe or remove its storage.

Keep a disposal record

Keep a disposal record

MOH's Implementation Guide, section B15.3 requires dates, method and who did it:

DateWhat was disposedMethodDone by

B15.3(a): if you use a professional shredding or disposal service, get a certificate of destruction from them and keep it with this record, that's your proof the destruction actually happened, not just that you paid for it.

Where MOH's own guidance falls short
Wrap up

Where MOH's own guidance falls short

Four things you should know, so you're not left thinking you missed something.

1. The MOH incident reporting form doesn't exist yet

1. The MOH incident reporting form doesn't exist yet

You must notify MOH within 2 hours of confirming a cybersecurity incident (MOH's Implementation Guide, Table 12, page 59). The same table says the reporting-form link "will be added here in 2027." Both the obligation and the mechanism are dated to 2027. Plan for the obligation arriving first.

Use the interim path from item 13: email hia_enquiries@moh.gov.sg, plus the PDPC form and an SPF report, both work today.

2. The retention period numbers are in a document CS/DS only footnotes

2. The retention period numbers are in a document CS/DS only footnotes

The CS/DS Essentials, clause B.4, tells you to set retention periods, then footnotes out to the Licence Conditions on the Retention Periods of Patient Health Records. The only figure inside CS/DS itself is 15 years, for adult inpatient paper records, which is not the number a GP clinic needs.

Read the licence conditions instead. Table 1 gives you the patient's lifetime plus six years for anything electronic, and six years from the last day of consultation for paper outpatient records. Paragraph 16 adds at least 15 years for high risk cases, paragraph 13 adds a hold while a complaint or legal action is live. Your template carries all four. Item 5 walks through them.

That document is versioned and may be amended. Check hcsa.gov.sg for the current version at your annual review.

3. The footnotes go a long way outside the document

3. The footnotes go a long way outside the document

CS/DS Essentials carries 24 footnotes, several point to PDPC advisory guidelines, PDPC ICT systems practices, PDPC printing guides, NIST media sanitisation standards.

You don't need to read any of them

Every one of those references is answered in practical terms across this deck. The exception: PDPC's free training resources at pdpc.gov.sg, which you should actually use, the zero-cost route to item 8.

4. MOH's own dates have already moved once

4. MOH's own dates have already moved once

The Circular (6 March 2026) said patient-selectable NEHR sharing and access-restriction features would arrive "in the later part of 2026." The FAQ, five months later, says the "break-glass" feature will be available "from 2027."

Treat the later document as current, but don't build a plan around either date, check the HIA website.

Being behind is not ignoring it

Being behind is not ignoring it

Being behind ≠ ignoring it

MOH Circular, para 13: non-compliance with contribution requirements "is not an offence in the first instance, as MOH recognises that there may be genuine challenges onboarding to NEHR." Where the problem is technical difficulty, MOH's stated first response is to help you fix it. Enforcement escalates only for deliberate or reckless non-compliance.

Still on paper?

Still on paper?

Still on paper?

MOH's FAQ, question 22: clinics licensed before 2027 that have difficulty digitalising will get an Alternate Contribution Channel from MOH. Details are still pending. You are not automatically non-compliant.

Who to ask

Who to ask

  • MOH questions: hia_enquiries@moh.gov.sg
  • NEHR account and onboarding: NEHR.Feedback@synapxe.sg
  • Grant applications: nehr.grants@synapxe.sg

About this guide

Independent guidance, free to use, written for a Windows clinic. It is not official MOH material and carries no MOH endorsement. Everything in it is built from MOH's own published documents, listed below. Where MOH's material has a genuine gap, this deck says so rather than filling it in.

Prepared from the HIA Implementation Guide v2.0 (Aug 2026), the CS/DS Essentials (first edition, March 2026), the HIA FAQs v1.1 (13 Aug 2026), and MOH Circular MOH-MHC-0018-2026 (6 Mar 2026). All sources retrieved 18 August 2026. Assumes a Synapxe-certified, Cyber Essentials–certified CMS/HIMS, reconfirm if that changes.