# CS/DS Essentials: a Windows walkthrough for a solo GP clinic

A step-by-step guide to the 13 Cybersecurity and Data Security Essentials under the Health Information Act, written for one doctor running a clinic on ordinary Windows PCs with no IT staff.

Every instruction here points back to a page of MOH's own Implementation Guide so you (or anyone auditing you later) can check the source.

---

## Before you start

**Who this is for.** A solo GP or a doctor with one or two staff. Windows 10 or Windows 11 PCs bought as normal consumer or small-business machines. No company network, no server room, no Active Directory, no IT vendor on retainer. If that is you, this guide covers everything.

**Your timeline.** Outpatient Medical Service (GP) is Batch 1. You must be contributing to NEHR and have the CS/DS measures in place by **1 September 2027**; specialist, dental and dialysis services each follow their own date (MOH's Implementation Guide, Chapter 1, Table 1, page 3, and Table 4, page 10). The NEHR Connect Grant application window closes **31 August 2027** (the Guide, Table 4, page 10).

**Where my information comes from.** I am working from MOH's own documents, cached on 18 August 2026:

- Cybersecurity and Data Security Essentials, first edition, March 2026 (16 pages). Cited below as "CS/DS".
- HIA Implementation Guide for Healthcare Providers, Version 2.0, August 2026 (74 pages). Cited below as "the Guide".
- FAQs for Healthcare Providers on the HIA v1.1, 13 August 2026 (24 questions). Cited below as "FAQ".
- MOH Circular MOH-MHC-0018-2026, 6 March 2026.

All four were fetched today, so nothing here is stale. The FAQ has already moved from v1.0 to v1.1 in five months, so check the HIA website before your final sign-off if that is months from now.

**One legal note, said once.** MOH's own Implementation Guide states that its sample clauses "are not intended to be an authoritative statement of the law or a substitute for legal or other professional advice" (the Guide, Annex C, page 47). The same applies to this guide. It is free, pro bono, practical guidance built on MOH's documents, and not official MOH guidance. Get a lawyer involved for the genuinely high-stakes situations: a live data breach, or a dispute with your CMS vendor about who is liable for what. Not for the routine work below.

---

## The money answer, up front

Only two of the thirteen items need any spending. The other eleven cost you nothing except your own time.

MOH says this themselves. MOH's FAQ, question 14 asks the exact question you are probably asking:

> "For organisations such as solo practitioners or small clinic chains with simple system setups, Microsoft Defender may provide sufficient firewall protection. This principle applies similarly to antivirus requirements, where built-in operating system security features, such as Microsoft Defender, can meet basic protection needs for less complex environments."

And question 23, on whether you need to hire a consultant:

> "Engaging professional CS/DS consultancy services is optional, as not every healthcare provider requires such services to meet the necessary CS/DS requirements."

If a vendor tells you otherwise, that line is your answer. The FAQ adds that you can report a vendor's unethical conduct or pricing to MOH through HIA enquiries.

| What you need | Cost | Source |
|---|---|---|
| Anti-malware | Free. Windows Defender is already installed. | question 14 |
| Firewall | Free. Windows Defender Firewall is already installed. | question 14 |
| Two-factor authentication | Free. Microsoft Authenticator app. Skip it entirely if your HIMS is Cyber Essentials certified. | MOH's Implementation Guide, Annex A, A5 footnote, page 27 |
| Staff training | Free. PDPC self-help resources are explicitly accepted. | the CS/DS Essentials, clause C.1.1 |
| Every policy, register, plan and template | Free. Templates are in the Guide, Annexes B to E. | the Guide, pages 38–59 |
| **External hard drive for backups** | **One-time, about S$60 to S$100** | the Guide, Annex A page 34, Annex D3 page 49 |
| **Paper shredder** | **One-time, about S$30 to S$50** | the Guide, Annex B15, page 46 |
| Replacing a PC that is genuinely End-of-Support | Only if you have one. NCG or PSG offsets it. | the Guide, Table 2, page 4 |

Subsidies, if you do end up spending:

- **NEHR Connect Grant (NCG).** Fixed **S$8,400** for a GP clinic under an Outpatient Medical Services licence. Covers roughly two years of HIMS subscription, or 40% of the cost of upgrading the one you have. Apply at oursggrants.gov.sg. You must pick a Synapxe-certified HIA-compliant HIMS *before* you apply. Applications submitted after 31 August 2027 are rejected. (the Guide, Chapter 2C, pages 9–10)
- **CISO-as-a-Service (CISOaaS).** Up to **70%** of the cost of a CS/DS consultancy package, through CSA. Apply at services2.imda.gov.sg/ctoaas/tag/hia. Optional, per question 23. (the Guide, Table 2, page 4)
- **Productivity Solutions Grant (PSG).** 50% of the cost of qualifying security products, capped at S$30,000. Apply at apply.gov.sg/grants/business. (the Guide, Table 2, page 4)

The Guide also lists the NCSS Transformation Sustainability Scheme Part C on page 5, at 80% funding capped at S$40,000. **Ignore it.** It is open only to Community Care Organisations that are NCSS members. A private GP clinic is not one, and the Guide does not say so on the page where it lists the scheme.

---

## Every section, mapped to MOH's documents

Work through this guide top to bottom. This table exists so you can check any instruction against the source, or hand an auditor a trace.

| CS/DS item | What it covers | Essentials ref | Guide ref | Section below | Cost |
|---|---|---|---|---|---|
| 5. Secure | Know what health info you hold, store it safely, copy and send it safely | B.1 to B.7 | Annex B5-B9, pages 41–44; Annex C, page 47 | Part 1, §1 | Free |
| 6. Identify | Mark documents as health information | B.8 to B.9 | Annex B10, page 44 | Part 1, §2 | Free |
| 7. Access | Only people who need it get access | B.10 | Annex B11, page 44; Annex C, page 47 | Part 1, §3 | Free |
| 8. Training | Annual security awareness training | C.1 to C.2 | Annex B12, page 45 | Part 1, §4 | Free |
| 9. Vendor management | Know what your CMS provider does and does not do | C.3 to C.5 | Annex B13, page 45; Annex D Table 7, pages 49–50 | Part 1, §5 | Free |
| 10. Security review | Check yourself periodically | C.6 to C.8 | Annex B14, page 45; B16, page 46 | Part 1, §6 | Free |
| 12. Contingency | Business Continuity Plan | C.10 | Annex D, pages 48–52; Table 8, page 51 | Part 1, §7 | Free |
| 13. Incident response | Incident Response Plan and reporting | C.11 to C.14 | Annex E, pages 53–59; Tables 9-12 | Part 1, §8 | Free |
| 1. Updates | Install software updates promptly | A.1 | Annex A, A1, page 20 | Part 2, §9 | Free |
| 2. Secure/Protect | Anti-malware, firewall, accounts, passwords, 2FA, lockout, logging, secure settings | A.2 to A.12 | Annex A, A2-A8, pages 21–33; Annex B1-B2B, pages 38–39 | Part 2, §10 | Free |
| 4. Asset | List your hardware and software, replace what is unsupported | A.15 to A.18 | Annex B3B, page 40; B4 and B4A, page 41 | Part 2, §11 | Free (unless a PC is EOS) |
| 3. Backup | Back up essential data, store it separately, test the restore | A.13 to A.14 | Annex A, A8 part 4, page 34; Annex B3, page 40; Annex D3, page 49 | Part 3, §12 | One-time buy |
| 11. Disposal | Shred paper, wipe drives | C.9 | Annex B15, page 46 | Part 3, §13 | One-time buy |

The self-assessment questions MOH wants you to ask yourself first are in MOH's Implementation Guide, Chapter 3, Table 5, pages 15 to 18. You do not need to read them. Every one of them is answered by a section below.

There is also **the Guide, Annex F, pages 60-61**, a sample policy on the use of NEHR. That is not one of the 13 CS/DS items. It is about who in your clinic may look at NEHR and why. Do it when you onboard to NEHR, separately from this work.

---

# Part 1: the paperwork

Free, and you can finish most of it in an afternoon. Do this first, because none of it depends on anything else and it clears eight of the thirteen items.

Open one Word document. Call it **"[Your Clinic Name] Cybersecurity and Data Security Policy"**. Everything in Part 1 goes into that single file. MOH's Annex B is written as clauses you paste in and fill.

A note on the templates before you start. The Guide, Annex B repeats the phrase "[Insert personnel in charge]" throughout, as though you have an IT department. You do not. **Write your own name in every one of those brackets.** the Guide confirms this is fine for a solo practice at Annex E, page 54: an incident response team "does not need to be a large or specialised group (e.g. in a solo practice, it may simply be you and one or two trusted staff members, each with a clearly defined role)."

---

## §1. Know what health information you hold, and handle it safely
**CS/DS item 5 (Secure). the CS/DS Essentials, clause B.1 to B.7. MOH's Implementation Guide, Annex B5 to B9, pages 41–44; Annex C, page 47. Free.**

### What this actually asks

Three things. Where is your patient data, physically and digitally. How do you stop copies leaking. How do you send it to someone else without exposing it.

### What to write down

**1a. Where it lives.** the Guide, section B5 (page 41) gives you the sentence. Fill in the blanks:

> "All personnel must note that our organisation's health information is stored in [our HIMS: name it] and [your filing cabinet, named by location]."

List every place. The CMS database. The filing cabinet behind reception. The old box of records in the store room. The clinic laptop. If you have paper records in a commercial storage facility, clause B.3 wants you to have checked that facility's security and to keep a list of what you sent there.

**1b. How long you keep it.** clause B.4 tells you to set retention periods but does not give you the numbers. It points to a separate document, the [Licence Conditions on the Retention Periods of Patient Health Records](https://isomer-user-content.by.gov.sg/7/66fedf54-1071-481b-8f7b-105d28bcd30b/lcs-on-retention-periods-of-patient-health-records_1-0.pdf), imposed under section 13(1) of the Healthcare Services Act. That is where the numbers are, and your clinic is already bound by them.

Table 1, for a GP clinic:

- **Anything electronic, including paper you have scanned: the patient's lifetime plus six years.** A scanned record becomes an electronic one the moment you scan it (paragraph 9), so this is the period that binds most clinics in practice. "Lifetime" means the patient's actual lifetime, or 110 years where you do not know the date of death.
- **Paper outpatient records: six years from the last day of consultation or treatment,** whichever is later.
- **High risk patients and cases: at least 15 years** from the last day of consultation or treatment (paragraph 16). Three things count, and the licence conditions name them: a patient who suffered complications during treatment, a complaint still open, and a patient who lacked mental capacity, or whom you suspect lacked it, at the time you saw them.
- **A complaint, legal action or disciplinary proceeding that has started, or that you can reasonably see coming: keep that patient's complete record until it concludes** (paragraph 13), even if the period above runs out first.

You may cull paper after four years, provided you keep the fifteen categories in paragraph 8 for the rest of the period: discharge summaries, operation reports, all consent forms, x-ray reports, histopathology reports, maternity and neonatal and labour records, work injury compensation reports, insurance forms, medico-legal forms, treatment and progress notes, inpatient medication charts, prescription orders and blood transfusion records.

These are licence conditions, not guidance. A breach is actionable under section 20 of the HCSA (paragraph 3). They are minimums, so you may keep records longer, never shorter.

Your policy template carries all four of these. Then fill in the retention schedule table at the Guide, Table 6, page 43. The licence conditions are versioned and may be amended, so check hcsa.gov.sg for the current version at your annual review.

**1c. Rules for copies.** From the Guide, section B8, page 43. Plain version for a solo clinic:

> "Copies of patient records are made only when needed for a specific work purpose. Use clinic equipment. Never leave a printout at the photocopier. Shred misprints and paper jams immediately."

**1d. Rules for sending.** From the Guide, section B9, page 44, and clause B.7.4. The one rule that catches people out:

> "Any file containing patient information sent by email must be password-protected. The password goes by a different route: phone call or SMS. Never in the same email. Check the recipient's address before you press send."

MOH's FAQ, question 17 says the same thing and explains why: if the email account is compromised, sending both together exposes both at once.

To password-protect a file for free, with no download:

- Word: `File` → `Info` → `Protect Document` → `Encrypt with Password`
- Excel: `File` → `Info` → `Protect Workbook` → `Encrypt with Password`
- Any file type: install 7-Zip (free), right-click the file → `7-Zip` → `Add to archive` → set `Encryption method` to `AES-256` and enter a password

**1e. WhatsApp.** question 18 is clear and worth knowing before a staff member asks. Instant messaging is fine for basic appointment scheduling with dates and times and no medical content. Anything containing medical information should go through the clinic's official email instead.

**1f. Confidentiality clauses.** clause B.1 wants a clause prohibiting unauthorised disclosure in your employment contracts, and in any agreement with a vendor or contractor. The Guide, Annex C, page 47, has two ready-made sample clauses: one for third-party agreements, one for employment contracts. They are attachments inside the PDF. Open them, paste them, put your clinic's name in.

---

## §2. Mark your health information
**CS/DS item 6 (Identify). the CS/DS Essentials, clause B.8 to B.9. MOH's Implementation Guide, Annex B10, page 44. Free.**

The point is that anyone picking up a document knows it needs protecting.

You have two options, and MOH accepts either. Marking every document is the first. If that is impractical, clause B.8.2 explicitly allows the second: state in your policy what counts as health information and skip the individual labels.

For a solo GP, take the second option. Write this clause (the Guide, section B10, page 44 gives the shape):

> "All information in medical reports, patient consultation notes, treatment plans, prescription letters, referral letters and laboratory results is health information and must be handled under this policy."

If you want the physical version too, a rubber stamp reading "Health Information" costs about S$10 and covers your paper files. Optional, not required.

---

## §3. Restrict access to health information
**CS/DS item 7 (Access). the CS/DS Essentials, clause B.10. MOH's Implementation Guide, Annex B11, page 44. Free.**

Two conditions must both be met before someone can see patient data: they need it for their job, and they have been told the rules and acknowledged them.

The clause, adapted from the Guide, section B11 for a clinic where you are the authority:

> "Personnel may access health information only where necessary to carry out their work, and only as authorised by [your name], the doctor-in-charge. Access is limited to what the role requires. No one is given access before they have read this policy and confirmed in writing that they understand it."

"Confirmed in writing" can be an email reply. the Essentials, footnote 14 says so directly: an email where the recipient responds "I understand the data security measures" counts, as does an attendance record from a briefing.

For a solo practice this is one page and one email from your clinic assistant. The technical half of this item, giving each person their own login, is §10c below.

---

## §4. Train your staff once a year
**CS/DS item 8 (Training and education). the CS/DS Essentials, clause C.1 to C.2. MOH's Implementation Guide, Annex B12, page 45. Free.**

You need each person to attend cybersecurity and data security awareness training at least once a year. clause C.1.1 accepts three routes: in-house, external vendor, or **self-help resources such as the official ones published by PDPC**. That third route is free, and it is the one to use.

What to do:

1. Go to pdpc.gov.sg and find their data protection self-help and e-learning resources.
2. Sit with your staff for an hour, work through the material, cover phishing emails, strong passphrases, and not leaving records on the counter.
3. Write the date, who attended, and what you covered on a single page. Sign it. File it.

That page is your evidence. Repeat annually. Do not pay a vendor to run a session for two people.

---

## §5. Ask your CMS vendor the right questions
**CS/DS item 9 (Outsourcing and vendor management). the CS/DS Essentials, clause C.3 to C.5. MOH's Implementation Guide, Annex B13, page 45; Annex D Table 7, pages 49–50. Free.**

This is a phone call, not a purchase. clause C.4 says you need to understand where your patient data is stored, what safeguards the vendor has, and who is responsible for what when something goes wrong.

Send your CMS provider this email. The questions come from the Guide, Table 7, pages 49–50, condensed:

> Subject: HIA CS/DS Essentials: questions about our clinic's data
>
> We are preparing for the HIA cybersecurity and data security requirements. Could you answer the following in writing?
>
> 1. Is your system HIA-compliant? Specifically: NEHR Connectivity certification completed, Cyber Essentials (CE) certification obtained and submitted to NEHR, and compliance with the Code of Practice for Data Portability declared. If not yet, what is your timeline?
> 2. What data of ours is backed up? Does that include all patient records, appointment histories and clinical notes? Is anything not covered?
> 3. How often do backups run, and where are they stored? Are they on the same server as our live data, or somewhere separate?
> 4. Are our backups stored in Singapore? If not, which country?
> 5. How do you verify backups actually work? When was a restore last tested successfully?
> 6. Are our backups encrypted, and who on your side can access them?
> 7. If we lost data tomorrow, how quickly could you restore it, and how far back can you go?
> 8. Is there anything we need to do on our end for backups to run correctly? Will you notify us if one fails?
> 9. Who is responsible for what if there is a security incident or breach?
> 10. Will you send us regular updates on security issues and vulnerabilities affecting our system?

The answer to question 1 also decides two other things: whether you qualify for the NEHR Connect Grant (you must select a Synapxe-certified HIMS before applying), and whether you can skip the 2FA setup in §10e. Check your CMS's status yourself at the Synapxe integration status list before you send the email.

Keep the reply. That email thread is your vendor management evidence.

---

## §6. Review yourself, on a schedule
**CS/DS item 10 (Security reviews and internal audit). the CS/DS Essentials, clause C.6 to C.8. MOH's Implementation Guide, Annex B14, page 45; B16, page 46. Free.**

No external auditor is required. clause C.7 says self-assessment is acceptable.

Write this into your policy (from the Guide, section B14):

> "[Your name] will review this policy and the clinic's compliance with it every twelve months, in [pick a month]. Any lapse found will be fixed at once, and additional training given where needed."

Then set a calendar reminder. Your review is: reread this guide, walk the thirteen items, note what has drifted, fix it, write the date on the page.

The Guide, section B16, page 46, also wants a named person accountable for explaining the policy to new hires. That is you:

> "[Your name] is accountable for explaining this Policy to all new staff. All personnel must comply with it."

---

## §7. Business Continuity Plan
**CS/DS item 12 (Emergency planning for contingency). the CS/DS Essentials, clause C.10. MOH's Implementation Guide, Annex D, pages 48–52. Free.**

The question this answers: your CMS is down at 9am on a Monday and there are patients in the waiting room. What happens?

The Guide, Annex D is six sections of questions to think through (D1 to D6, pages 48–52). For a solo GP the plan is short. Write these and print it:

**Critical functions (the Guide, section D1, page 48).** Consultations and dispensing must continue. Everything else can wait.

**Paper fallback (the Guide, section D2, page 48).** Print and keep physical stacks of: a blank consultation note template, an appointment sheet, a receipt or billing slip. The Guide, section D2(b) asks whether staff know where these are, so store them somewhere obvious: consultation room, reception, dispensary. The Guide, section D2(c) asks how you get back to digital afterwards, so write the sentence: "Paper notes from the outage are entered into the CMS as soon as practically feasible after restoration."

**High-risk patients (the Guide, section D2.2, page 49).** Keep a short offline list of patients on critical medication who would need contacting during a multi-day outage.

**Communications (the Guide, section D5, page 52).** Your staff's phone numbers, your CMS vendor's support number, and your own mobile, written on paper, not only in your phone. The Guide, section D5.2 specifically asks whether contacts are "accessible in a non-digital format".

**Testing.** MOH's Implementation Guide (Annex D, page 52) asks whether you have “a realistic schedule” for testing and sets no cadence. Our recommendation: once a year, run one morning on paper templates. The Guide's own line: "A BCP that has never been tested is a plan that may fail when it matters most."

Print the finished plan. The Guide says this explicitly at Annex D overview, page 48: keep a paper copy, because a digital plan is useless when the systems holding it are down.

---

## §8. Incident Response Plan
**CS/DS item 13 (Incident response). the CS/DS Essentials, clause C.11 to C.14. MOH's Implementation Guide, Annex E, pages 53–59. Free.**

### Who does what

The Guide, Table 9, page 54, lists four roles: incident commander, IT/technical lead, Data Protection Officer, communications and legal lead. **You do not need four people.** the Guide says so on the same page: in a solo practice it may be you and one or two trusted staff, each with a defined role.

Write it as:

> Incident commander, DPO and communications: [your name], [your mobile]
> Technical response: [CMS vendor name], [their support number]
> Recording what happened: [clinic assistant's name], or [your name] if alone

### How you spot an incident

The Guide, Table 10, page 55, lists the signs. The ones a GP clinic actually sees:

- Files renamed with odd extensions, or a message on screen demanding payment
- Patient records that opened yesterday will not open today
- Emails going out from the clinic account that nobody sent
- An email with patient results sent to the wrong person
- A clinic laptop or a paper file that cannot be found
- A former staff member's login still active after they left

### What to do in the first ten minutes

From the Guide, Table 8, page 51 (the ransomware card) and Table 11, pages 56–58. Print this and stick it inside a cupboard door:

1. **Disconnect.** Unplug the network cable or switch off Wi-Fi on the affected PC. Disconnect any other PC showing the same problem.
2. **Do not switch the computer off.** the Guide is specific about this. Powering down destroys forensic evidence.
3. **Do not restart it.** Do not make changes to it.
4. **Can you still see patients safely?** If yes, switch to paper (your BCP, §7). If no, divert or reschedule and tell patients promptly.
5. **Call your CMS vendor.** Number is on the card.
6. **Do not pay a ransom.** the Guide, Table 8: "Paying does not guarantee recovery."
7. **Write down what you saw and when.** Times, which machines, what patient information might be involved, roughly how many patients, what you did. Take photos of error messages.
8. **Use a clean device** for reporting and for contacting patients about urgent medical matters.
9. Change every password once your vendor confirms it is safe to restore.

If it is a wrong-recipient email rather than a hack, the Guide, Table 11 says: try to recall it immediately, then contact the recipient and ask them to delete it without opening the attachment.

### Reporting, and the gap you need to know about

MOH's reporting timelines, from the Implementation Guide, Table 12, page 59:

| Who | When | What |
|---|---|---|
| MOH | Within 2 hours of confirming it | All confirmed cybersecurity incidents, **and** data breaches likely to cause significant harm or affecting 500+ people |
| PDPC | Within 72 hours | Data breaches likely to cause significant harm, or affecting 500+ people |
| SPF | As soon as possible | Ransomware or monetary loss |

Plus a full incident report to MOH within 14 days, and you must tell affected patients at the same time as MOH if the incident is likely to cause them significant harm (the Essentials, Table 2, page 16).

**Here is the problem.** The "Reporting Method" column for MOH in the Guide, Table 12 says: *"The link to the MOH incident reporting form will be added here in 2027, when the incident reporting framework is launched."* The two-hour obligation exists. The form to comply with it does not, yet. clause C.14 says the same thing: "Specific details of how HIA entities can report the incidents to MOH will be shared shortly."

This is MOH's gap, not yours. Until the form appears, put this in your plan:

> If MOH's incident reporting form is not yet live, email hia_enquiries@moh.gov.sg within 2 hours with the incident details, and keep the sent copy. File the PDPC notification through the PDPC form at pdpc.gov.sg (that channel works today) and lodge a police report through the SPF e-service form where ransomware or monetary loss is involved.

Check whether MOH's form has gone live at your annual review.

---

# Part 2: Windows settings and account habits

Now the clicking. Budget two hours per PC for the first one, twenty minutes for each after that.

Where a path differs between Windows 10 and Windows 11, both are given. If a menu name does not match exactly, use the Windows search box (press the Windows key and start typing).

---

## §9. Turn on automatic updates
**CS/DS item 1 (Updates). the CS/DS Essentials, clause A.1. MOH's Implementation Guide, Annex A, A1, page 20. Free.**

Updates carry the security patches that close the holes attackers use. This is the single highest-value five minutes in the whole guide.

**Windows 11:** `Settings` → `Windows Update`
**Windows 10:** `Settings` → `Update & Security` → `Windows Update`

Then:

1. Click `Check for updates`. Install everything offered. Restart when asked.
2. Click `Advanced options`. Turn **on** `Receive updates for other Microsoft products`. This is what keeps Word, Excel and Outlook patched, not just Windows.
3. Still in `Advanced options`, set `Active hours` to your clinic hours so restarts never happen mid-consultation.
4. Turn **on** `Get the latest updates as soon as they're available` if you see it.

Do this on every PC in the clinic, including the reception machine.

Your CMS or HIMS is separate. Its updates are the vendor's job, which is question 10 in the vendor email at §5.

---

## §10. Anti-malware, firewall, accounts and secure settings
**CS/DS item 2 (Secure/Protect). the CS/DS Essentials, clause A.2 to A.12. MOH's Implementation Guide, Annex A, A2 to A8, pages 21–33; Annex B1 to B2B, pages 38–39. Free.**

This is the biggest item. It breaks into seven parts.

### §10a. Anti-malware
**clause A.2. The Guide, Annex A, A2, page 21.**

Do not buy antivirus software. Windows Defender is already on your PC and MOH has confirmed it is enough for a clinic your size (MOH's FAQ, question 14, quoted above).

**Path:** `Settings` → `Privacy & security` → `Windows Security` → `Virus & threat protection`
(Or press the Windows key, type `Windows Security`, press Enter.)

Under `Virus & threat protection settings`, click `Manage settings`. Four toggles, all should be **On**:

- `Real-time protection`
- `Cloud-delivered protection`
- `Automatic sample submission`
- `Tamper protection`

Then go back and click `Protection updates` → `Check for updates`. That confirms clause A.2.1, the automatic signature updating.

Then click `Scan options` → select `Full scan` → `Scan now`. Run one full scan today. After that, Defender's own scheduled scanning covers clause A.2.2.

**On USB thumb drives.** If a specialist or lab sends you a drive too large to scan properly, question 15 says you are **not** required to deep-scan the whole thing:

> "Healthcare providers are not required to perform a full, deep-scan of the entire USB content of the thumb drive. Instead, they should ensure their built-in anti-malware systems are configured to provide real-time protection by automatically detecting and scanning for malicious files upon access."

Real-time protection, which you just confirmed is on, does exactly that. Nothing more to do.

### §10b. Firewall
**clause A.3. The Guide, Annex A, A2 continued, page 22.**

clause A.3 is explicit that for "a simple organisation setup, comprising just endpoints connecting to the internet and/or cloud-based applications", the firewall built into the operating system plus the one in your router is what is expected. No hardware purchase.

**Path:** `Windows Security` → `Firewall & network protection`

You will see three entries: `Domain network`, `Private network`, `Public network`. All three must say **On**. If one says off, click it and switch it on.

Then log into your clinic router's admin page (the address is usually printed on the router itself) and confirm its firewall is enabled. It almost always is by default. While you are there, change the router's admin password if it is still the factory default, which clause A.8 requires.

### §10c. One login per person
**clause A.5 to A.7, A.9 to A.10. The Guide, Annex A, A3, pages 23–24; A4, pages 25–26; Annex B2 and B2A, pages 38–39.**

The rule is simple: nobody shares a login. Not the doctor's, not reception's.

**To create an account for a staff member:**

`Settings` → `Accounts` → `Other users` → `Add account`

If they do not have a Microsoft account, click `I don't have this person's sign-in information`, then `Add a user without a Microsoft account`. Give them a username and a passphrase.

**Then set their account type correctly.** Click the account → `Change account type` → set to `Standard User`. Only your own account should be `Administrator`. clause A.6.2 says administrator accounts should only be used for administrator tasks.

**To remove an account** when someone leaves:

`Settings` → `Accounts` → `Other users` → click the account → `Remove`

clause A.6.1 wants this done for shared, duplicate, obsolete, dormant and inactive accounts, and gives 60 days of inactivity as the marker. Do a sweep at your annual review.

**To see every account on the machine**, including ones you forgot: press the Windows key, type `netplwiz`, press Enter.

**The register.** clause A.5.1 wants a list of accounts with six fields. The Guide, Annex B2, page 38, provides the template as an attachment. For a two-person clinic it is a table with two rows:

| Name | Username | Department | Role / account type | Date access created | Last log-on |
|---|---|---|---|---|---|
| Dr [name] | [username] | Clinical | Administrator | [date] | [date] |
| [assistant] | [username] | Reception | Standard user | [date] | [date] |

Add rows for your CMS logins and any vendor account. The Guide, Annex B2A, page 39, also gives sample emails for requesting, approving and revoking access. For a solo clinic, keep it simple: when someone joins or leaves, update the table and date it.

**Third parties.** If your CMS vendor or an IT contractor gets a login, clause A.9.1 requires them to sign a non-disclosure agreement. The Guide, Annex A, A4, page 26, has the sample NDA clauses as an attachment. Get it signed before you hand over access, and remove the account when the work is done.

### §10d. Passwords
**clause A.8. The Guide, Annex B2B, page 39.**

A strong passphrase is at least **12 characters**, with a mix of upper case, lower case and special characters, and it must not be a common word or an obvious pattern (the Essentials, footnote 4).

Three things to do:

1. Change any password still set to a factory default. Router, CMS admin account, network printer, anything.
2. Write the rule into your policy. The Guide, section B2B, page 39, gives the wording: passwords must be changed immediately on any suspected compromise or lost token.
3. To change a Windows password: press `Ctrl` + `Alt` + `Delete` → `Change a password`.

Practical version to tell your staff: pick four unrelated words plus a number and a symbol. "Kopi7Bicycle!Rain" is stronger and easier to remember than "Cl1n1c@2026".

### §10e. Two-factor authentication
**clause A.8.2. The Guide, Annex A, A5, page 27. Free.**

Two-factor means a code from your phone on top of your password. It applies to administrative and remote access to important systems.

**Check this first.** the Guide, Annex A, A5 carries a footnote on page 27: *"Applicable for important systems (e.g. Health Information Management Systems (HIMS)) only. Skip this part if you are using CE-certified HIMS to process and store all your health information."*

So: if your CMS is Cyber Essentials certified and all your patient data lives in it, this item is already done for you. That is one of the answers you are asking for in the vendor email at §5.

If you do need to set it up, or you want it on your clinic email:

1. Install **Microsoft Authenticator** on your phone from the App Store or Google Play. Free.
2. For a Microsoft or Office 365 account: go to account.microsoft.com → `Security` → `Advanced security options` → `Two-step verification` → turn on, and scan the QR code with the app.
3. For your CMS: ask the vendor to enable it on your admin account and follow their instructions.

### §10f. Lock the account after failed logins
**clause A.8.3. The Guide, Annex A, A6, page 28. Free.**

This stops someone sitting at a clinic PC guessing passwords all afternoon. clause A.8.3 gives 10 failed attempts as the example.

The Guide's Annex A uses Group Policy (`gpedit.msc`) for this. **Group Policy is not available on Windows Home**, which most clinic PCs run. Here is the method that works on every edition, Home included.

1. Press the Windows key, type `cmd`
2. Right-click `Command Prompt` → `Run as administrator`
3. Type this and press Enter:

```
net accounts /lockoutthreshold:10 /lockoutduration:15 /lockoutwindow:15
```

That locks an account for 15 minutes after 10 failed attempts. To confirm it took, type `net accounts` and check the "Lockout threshold" line.

Recent builds of Windows 11 already ship with a lockout policy on by default. Run `net accounts` first. If it already shows a threshold of 10, you are done.

### §10g. Secure settings
**clause A.12. The Guide, Annex A, A8, pages 31–33. Free.**

New PCs arrive with features on that you will never use and that create risk. Turn them off. One pass, per PC.

**Turn off unused Windows features.** the Guide, section A8, page 31, names four specifically.

`Control Panel` → `Programs` → `Turn Windows features on or off`

Uncheck, unless you have a genuine reason to keep it:
- `Windows Media Player`
- `Microsoft XPS Document Writer`
- `SMB Direct`
- `Windows TIFF IFilter`

While you are there, also uncheck `SMB 1.0/CIFS File Sharing Support` if it appears. It is an obsolete file-sharing protocol and a known ransomware route.

Click OK and restart when prompted.

**Stop auto-connecting to Wi-Fi.** the Guide, section A8 part 2, page 32. clause A.12.3 requires automatic connection to open networks to be disabled.

`Settings` → `Network & internet` → `Wi-Fi` → `Manage known networks` → click each network → uncheck `Connect automatically when in range`

Delete any network in that list you do not recognise, and any cafe or hotel network.

**Turn off AutoPlay.** the Guide, section A8 part 3, page 33. This stops a USB drive running something the moment it is plugged in.

**Windows 11:** `Settings` → `Bluetooth & devices` → `AutoPlay` → switch `Use AutoPlay for all media and devices` to **Off**
**Windows 10:** `Settings` → `Devices` → `AutoPlay` → **Off**

**Set the screen to lock itself.** clause B.2 and the CS/DS Essentials summary both require screen locks on devices holding health information.

`Settings` → `Accounts` → `Sign-in options` → under `Additional settings`, set `If you've been away, when should Windows require you to sign in again?` to `When PC wakes up from sleep`

Then: `Settings` → `System` → `Power & battery` → `Screen and sleep` → set the screen to turn off after 5 or 10 minutes.

Teach everyone `Windows key` + `L`. That locks the screen instantly when they step away from the front desk. The Guide, section B6.4, page 42, requires exactly this.

**Privacy filter.** clause B.7.3 and the Guide, section B9.3 ask you to stop screens being read by people walking past. Either turn the reception monitor away from the waiting area, which is free, or buy a privacy filter for about S$40. Turning the monitor is usually enough.

**Login logging.** clause A.11 and the Guide, Annex A, A7, pages 29–30, want a record of who logs in and out. Windows keeps this automatically. To check it:

Press the Windows key, type `Event Viewer`, press Enter → `Windows Logs` → `Security`. Event ID 4624 is a successful sign-in, 4625 is a failed one.

You do not need to read these daily. You need to know where they are if something goes wrong. the Essentials, footnote 5 adds that if logging is impossible on a system, keep a manual log instead.

---

## §11. List your hardware and software
**CS/DS item 4 (Asset). the CS/DS Essentials, clause A.15 to A.18. MOH's Implementation Guide, Annex B3B, page 40; B4 and B4A, page 41. Free unless something is unsupported.**

You cannot protect equipment you have forgotten about. This is an afternoon of walking around with a notebook.

**What to list.** Every PC, laptop, tablet and printer. Your router. Any external drive or USB stick used for clinic data. Every piece of software: Windows and its version, your CMS, Office, your PDF reader, anything else installed.

**The template** is at the Guide, Annex B4, page 41, as an attachment. The columns you need:

| Asset ID | What it is | Where it is | Serial / model | Windows version | Date authorised | End-of-Support date | Status |
|---|---|---|---|---|---|---|---|

**To find a PC's Windows version:** press the Windows key, type `winver`, press Enter.

**The End-of-Support question.** clause A.17 says hardware and software past End-of-Support must be replaced. End-of-Support means the maker has stopped issuing security patches for it. The Guide, section B4, page 41, gives the example of an asset whose EOS date was 1 June 2018 and which should therefore be replaced.

For a clinic, the practical check is your Windows version:

- **Windows 11:** supported. Nothing to do.
- **Windows 10:** Microsoft's end of support for Windows 10 was October 2025. If a clinic PC is still on Windows 10, either upgrade it to Windows 11 free (`Settings` → `Windows Update` will offer it if the hardware qualifies), or plan to replace the machine before September 2027.
- **Windows 8.1, Windows 7 or anything older:** replace it. This is the one line item in this guide that can cost real money.

**Home edition is fine.** Whether your PCs run Windows Home or Windows Pro makes no difference here. Microsoft's licence does not restrict Home to personal use, and nothing in the CS/DS Essentials requires a Pro-only feature. Full-disk encryption is not asked for anywhere. The word "encrypt" appears once in the whole CS/DS Essentials, at C.9, and only about wiping a drive before you throw it out, which Home does perfectly well (§13). Do not spend money upgrading to Pro for compliance.

If you must keep an unsupported machine running for a while, clause A.18 and the Guide, section B4A, page 41, require you to write down the risk, approve the continued use yourself as clinic owner, and monitor it until replaced. The Guide, section B4A has the form.

**If you do need to replace hardware,** apply for the grant before you spend. NCG gives GP clinics a fixed S$8,400 and PSG covers 50% of qualifying purchases up to S$30,000. Applying after the fact does not work.

clause A.15 also wants a protocol for authorising new equipment. For a solo clinic that is one sentence in your policy: "No computer, tablet or software is used for clinic work unless [your name] has approved it and added it to the asset register." the Guide, section B3B, page 40, has a request form template if you prefer a form.

---

# Part 3: the two things that cost money

Both are one-time purchases.

---

## §12. Back up your data, and test the restore
**CS/DS item 3 (Backup). the CS/DS Essentials, clause A.13 to A.14. MOH's Implementation Guide, Annex A, A8 part 4, page 34; Annex B3 and B3A, page 40; Annex D3, page 49. One-time cost: about S$60 to S$100.**

### Start with the honest answer

Your patient records are almost certainly in your CMS, and your CMS vendor is the one backing them up. Your first move is not to buy anything. It is question 2 through 8 in the vendor email at §5. Get their answers in writing. That is what clause A.14 means by understanding the split of responsibility between you and your provider, and the Guide, Annex B3A, page 40, gives you a template to record it.

What is not covered by the vendor is everything sitting on your PCs: scanned documents, letters, spreadsheets, referral PDFs, your policy documents. That is what you back up yourself.

### What to buy

One external hard drive, 1TB or 2TB, about S$60 to S$100 from any electronics shop. That is the entire purchase.

### Setting up the backup

Plug in the drive. Then, whichever of these your Windows version shows:

**Option A, File History (simplest):**
`Control Panel` → `System and Security` → `File History` → select your external drive → `Turn on`

Click `Advanced settings` and set `Save copies of files` to `Daily`.

**Option B, Backup and Restore:**
`Control Panel` → `System and Security` → `Backup and Restore (Windows 7)` → `Set up backup` → choose your external drive → `Let Windows choose` → `Save settings and run backup`

Click `Change schedule` and set it to run daily, after clinic hours.

Windows 11 also has a `Windows Backup` app, but it backs up to OneDrive rather than a local drive. Use it as a second copy if you like, not as your only one.

### The two rules people get wrong

**Store it separately.** clause A.13.3 requires backups to be "stored separately and isolated from the operating environment". The Guide, section D3.1(b), page 49, spells out why: a backup drive left permanently plugged in gets encrypted by the same ransomware that hits your PC.

So: run the backup, then **unplug the drive and lock it in a drawer**. Better still, use two drives and alternate them, keeping one off the premises. The Guide, section D3.1(c) asks whether you have at least one copy that would survive your premises being destroyed. A free OneDrive or Google Drive tier can serve as that second copy for non-patient files.

**Test the restore.** the Guide, section D3.2, page 49, is direct about it: "A backup that has never been verified may be corrupted, incomplete, or inaccessible precisely when you need it most."

So do this once, today. Pick one file. Delete it. Restore it from the backup. Confirm it opens. Write the date on your policy document. Repeat once a year at your review.

An untested backup is not a backup.

---

## §13. Dispose of things properly
**CS/DS item 11 (Disposal). the CS/DS Essentials, clause C.9. MOH's Implementation Guide, Annex B15, page 46. One-time cost: about S$30 to S$50.**

### Paper

Buy a cross-cut shredder. About S$30 to S$50. The Guide, section B15.1, page 46, requires hardcopy documents containing health information to go through designated secure waste containers or approved shredding equipment.

Put it where the paper is, next to reception. Rule for staff, one line in your policy:

> "No document containing patient information goes into a normal bin. Everything is shredded, including misprints, paper jams and test copies."

the Essentials, footnote 20 points to two NIST media sanitisation standards for this. Those are United States federal standards for wiping storage media. **You do not need to read them to shred paper in a GP clinic.** Buy the shredder.

### Computers and drives

Free. The Guide, section B15.2, page 46, wants drives encrypted before reformatting, then overwritten multiple times.

**Before you dispose of, sell or return any PC:**

1. Check encryption. `Settings` → `Privacy & security` → `Device encryption`. If you have Windows Pro, `Control Panel` → `System and Security` → `BitLocker Drive Encryption` → `Turn on BitLocker`. If neither is available on your machine, skip to step 2, which still does the job.
2. `Settings` → `System` → `Recovery` → `Reset this PC` → `Remove everything` → then click `Change settings` and set `Clean data` to **Yes**. This overwrites the drive rather than just deleting the index. It takes a few hours. Let it run overnight.
3. If the drive cannot be wiped because the machine is dead, the Guide, section B15.2(a) says have the storage media physically destroyed. Remove the drive and drill through it, or use a destruction service.
4. The Guide, section B15.2(b) catches the one everyone forgets: **printers and photocopiers store copies internally.** Before disposing of one, ask the supplier to wipe or remove its storage.

**Keep a disposal record.** the Guide, section B15.3, page 46, requires dates, method and who did it. One more table in your policy document:

| Date | What was disposed | Method | Done by |
|---|---|---|---|

---

# Where MOH's own guidance falls short

Four things you should know, so you are not left thinking you missed something.

**1. The MOH incident reporting form does not exist yet.** You are required to notify MOH within 2 hours of confirming a cybersecurity incident (the Guide, Table 12, page 59). The same table says the link to the reporting form "will be added here in 2027, when the incident reporting framework is launched." The obligation is live and the mechanism is not. Use the interim path in §8: email hia_enquiries@moh.gov.sg, plus the PDPC form and an SPF report, both of which work today.

**2. The retention period numbers are not in either document.** clause B.4 tells you to set retention periods and footnotes out to a separate document, the HCSA Licence Conditions on Retention Periods of Patient Health Records, which itself notes it "may be amended from time to time". The only figure MOH gives inside the CS/DS Essentials is the 15-year example for adult inpatient paper records, which is not the number a GP clinic needs. Read the licence conditions themselves, linked at 1b above: Table 1 gives the patient's lifetime plus six years for anything electronic and six years from the last day of consultation for paper outpatient records, paragraph 16 adds at least 15 years for high risk cases, and paragraph 13 adds a hold while a complaint or legal action is live. Your template carries all four.

**3. The footnotes go a long way outside the document.** CS/DS Essentials carries 24 footnotes, several of which point to PDPC advisory guidelines, PDPC ICT systems practices, PDPC printing guides, and NIST media sanitisation standards. **You do not need to read any of them** to comply as a solo GP. Every one of those references is answered in practical terms above. The exception is PDPC's free training resources at pdpc.gov.sg, which you should use, because they are the zero-cost route to item 8.

**4. MOH's own dates have moved once already.** The Circular of 6 March 2026 said the patient-selectable NEHR sharing and access-restriction features would arrive "in the later part of 2026". The FAQ, updated five months later on 13 August 2026, says the enhanced access controls and "break-glass" feature will be available "from 2027". Treat the later document as the current position, but do not build a plan around either date. Check the HIA website.

One more thing worth knowing, because it changes how the deadline feels. The MOH Circular, paragraph 13, says plainly that non-compliance with contribution requirements "is not an offence in the first instance, as MOH recognises that there may be genuine challenges onboarding to NEHR". Where the problem is technical difficulty, MOH's stated first response is to help you fix it. Enforcement escalates only for deliberate or reckless non-compliance. Being behind and working on it is a different position from ignoring it.

And if you run on pen and paper and have not adopted a CMS at all: MOH's FAQ, question 22 confirms that for clinics licensed before 2027 that have difficulty digitalising, MOH will provide an Alternate Contribution Channel. Details are still pending. You are not automatically non-compliant.

---

# Your tracker

Print this. Tick as you go. Thirteen items.

| # | Item | Done | Date | Where |
|---|---|---|---|---|
| 5 | Health info identified, locked away, copied and sent safely | ☐ | | §1 |
| 6 | Health information marked or defined in policy | ☐ | | §2 |
| 7 | Access restricted to those who need it | ☐ | | §3 |
| 8 | Annual training done and recorded | ☐ | | §4 |
| 9 | Vendor questions sent and answered in writing | ☐ | | §5 |
| 10 | Self-review scheduled (we suggest annually) | ☐ | | §6 |
| 12 | Business Continuity Plan written (printed copy recommended) | ☐ | | §7 |
| 13 | Incident Response Plan written (printed copy recommended) | ☐ | | §8 |
| 1 | Automatic updates on, every PC | ☐ | | §9 |
| 2 | Defender, firewall, accounts, passwords, 2FA, lockout, secure settings | ☐ | | §10 |
| 4 | Asset register filled, EOS assets identified | ☐ | | §11 |
| 3 | Backup running, drive unplugged, restore tested | ☐ | | §12 |
| 11 | Secure paper disposal in place, wipe procedure written | ☐ | | §13 |

---

# Do this first

Buy nothing today. Send the vendor email in §5 to your CMS provider this morning. Their answers decide three separate things: whether you can skip the two-factor setup, whether your patient records are already being backed up properly, and whether you qualify for the S$8,400 NEHR Connect Grant.

Then open Windows Update on your own PC and turn on automatic updates. That takes five minutes and it is the single most useful thing on this list.

Questions MOH will answer directly: hia_enquiries@moh.gov.sg. NEHR account and onboarding questions: NEHR.Feedback@synapxe.sg. Grant application questions: nehr.grants@synapxe.sg.

---

*Prepared from the HIA Implementation Guide v2.0 (August 2026), the Cybersecurity and Data Security Essentials (first edition, March 2026), the HIA FAQs for Healthcare Providers v1.1 (13 August 2026), and MOH Circular MOH-MHC-0018-2026 (6 March 2026). All sources retrieved 18 August 2026.*
