According to Data Bridge Market Research (2024), the Healthcare IT market in Singapore is projected to grow from USD 2.6 billion in 2024 to USD 11.7 billion by 2032. More remarkably, the software segment is expected to record the fastest growth, with a CAGR of 35.52% over the 2024–2032 forecast period.
With the rapid growth of healthcare technology comes a greater need to protect personal data. Data breaches have become a pressing global issue, and Singapore is no exception. PDPC reported that the number of large-scale data breaches in Singapore, those affecting more than 500 individuals, increased by 41% in just one year. Notably, cyber incidents accounted for 82% of enforcement cases where organizations were found to have inadequate security measures, with ransomware behind 62% of those.
As cyber threats continue to rise, the PDPC has stepped up enforcement of the Personal Data Protection Act (PDPA), making PDPA compliance a critical priority for healthcare software providers. In this article, we'll explore how the PDPA applies to healthcare data security, privacy, and compliance, the responsibilities of software vendors, and the key things healthcare organizations should know to stay compliant.
Key takeaways
-
Singapore's Healthcare IT market is projected to reach USD 11.7B by 2032.
-
Large-scale data breaches in Singapore rose 41% in one year, and cyber incidents accounted for 82% of enforcement cases where organizations were found to have inadequate security measures
-
Organizations must provide an individual with his or her personal data in their possession and information about the ways in which the personal data may have been used or disclosed during the past year.
-
A software development vendor that processes personal data on behalf of a client is considered a Data Intermediary under the PDPA and must comply with applicable obligations, including the Protection and Retention Limitation Obligations.
-
The PDPA does not require data residency in Singapore; personal data can be transferred overseas if it meets the requirements under the law
PDPA Overview
What is the PDPA?
According to pdpc (2023), the Personal Data Protection Act (PDPA) sets the baseline standard for protecting personal data in Singapore. The PDPA establishes a set of rules governing how organizations collect, use, disclose, store, and protect personal data.
In the PDPA, personal data is defined as “data, whether true or not, about an individual who can be identified from that data or from that data and other information to which the organization has or is likely to have access”. While some data may necessarily relate to an individual, other data may not, on its own, relate to an individual. Such data would not constitute personal data unless it is associated with a particular individual. Generic information that does not relate to a particular individual may also form part of an individual’s personal data when combined with personal data or other information to enable an individual to be identified.
Understanding the PDPA is essential for any healthcare business operating in Singapore. Whether collecting customer information, employee records, or business data, organizations must comply with the Act to ensure healthcare data compliance, reduce legal and financial risks, and build trust with customers and partners.
Objectives of the PDPA
The PDPA aims to protect individuals' personal data while allowing organizations to collect, use, and disclose personal data for legitimate and reasonable purposes. It establishes clear rules to ensure personal data is handled responsibly and helps prevent misuse beyond its intended purpose.
More importantly, the PDPA supports Singapore's vision of becoming a trusted business hub for businesses.
Scope of the PDPA
The PDPA applies to personal data in both electronic and physical formats.
PDPA in Healthcare Software Development
Personal data in the healthcare sector
The PDPA protects personal data, but what types of data in the healthcare sector are classified as personal data under the PDPA? Based on the PDPA's definition, personal data in the healthcare sector can generally be grouped into the following categories:
|
Category |
Details |
|
Patient identification data |
Full name, NRIC/FIN, passport number, patient ID, date of birth, gender, address, email, phone number |
|
Medical & Clinical information |
Medical records, diagnoses, prescriptions, laboratory results, imaging reports, allergies, immunization records |
|
Appointment & Care management data |
Appointment history, admission and discharge records, referrals, attending physician, care plans |
|
Billing & insurance information |
Billing records, payment history, insurance policy details, insurance claims |
|
Digital health data |
Telemedicine consultation records, wearable device data, patient portal activity, remote patient monitoring (RPM) data, mobile health app data |
|
Administrative & Communication records |
Consent forms, emergency contact details, next-of-kin information, communication records, complaint records |
The Access and Correction Obligations (PDPA sections 21, 22 and 22A) state that an organization must provide an individual with his or her personal data in the possession or under the control of the organization and information about the ways in which the personal data may have been used or disclosed during the past year.
For healthcare organizations, this obligation means enabling patients to access the personal data held about them. They must also be able to inform patients how their personal data has been used or disclosed over the previous year, in accordance with the PDPA. EHR and EMR integration is one of the most common scenarios where PDPA compliance becomes critical, as it involves the exchange of sensitive patient information across multiple healthcare systems, applications, and third-party platforms. During the integration process, healthcare organisations must ensure that personal data is collected, accessed, transferred, and processed securely in accordance with PDPA requirements.
Data breach in healthcare software development
Healthcare data security, privacy, and compliance are essential. When companies choose software development outsourcing, the risk of a data breach can increase because personal data is shared with third-party vendors, stored across multiple systems or shared storage platforms, and transferred across borders.
A notable example occurred in Singapore in 2021, when the personal data of more than 150,000 patients and employees of a healthcare services provider's corporate clients was accessed without authorization and offered for sale on a dark web forum, including identity numbers, bank account details, and health information. The Personal Data Protection Commission (PDPC) found that the healthcare provider had unnecessarily uploaded sensitive personal data to an online drive shared with its software vendor.
This incident highlights an important lesson for healthcare organizations: Healthcare data compliance should be a top priority when outsourcing software development. Before partnering with an offshore software development vendor, organizations should ensure that they follow PDPA Compliance and implement appropriate technical measures to protect client data.
PDPA Advisory Guidelines for healthcare software development
PDPA obligations for software development partners
The PDPA establishes 11 key data protection obligations, including the Accountability, Notification, Consent, Purpose Limitation, Accuracy, Protection, Retention Limitation, Transfer Limitation, Access and Correction, Data Breach Notification, and Data Portability Obligations.
Under PDPA, an organization processing personal data on behalf of a Data Controller (DC) pursuant to a contract is considered a Data Intermediary (DI). The DI may carry out any operation in relation to the personal data such as recording; holding; organization, adaptation or alteration; retrieval; combination; transmission; and erasure or destruction.
-
A DI is subject to the Data Protection Provisions relating to protection of personal data (Protection Obligation) and retention of personal data (Retention Limitation Obligation) when processing personal data on behalf of the data controllers.
-
If a DI uses or discloses personal data in its possession or control beyond the remit granted by the DC, the DI will be responsible for complying with all the Data Protection Provisions under the PDPA.
A software development vendor is considered a Data Intermediary (DI) when it processes personal data on behalf of their client under a contractual arrangement. As such, vendors are expected to comply with the relevant PDPA obligations:
-
Protection Obligation: Implement reasonable security measures to protect personal data from unauthorized access, use, disclosure, or other security risks.
-
Retention Limitation Obligation: Retain personal data only as long as necessary and securely dispose of it when it is no longer required for business or legal purposes.
Cross-border transfer of health data when offshore software development to Vietnam
Requirements for cross-border transfer of personal data
The PDPA does not require data residency in Singapore. Under the Transfer Limitation Obligation (TLO), personal data can be transferred overseas if it meets the requirements under the law, unless exempted by the PDPC. This obligation ensures that personal data remains protected even after leaving Singapore.
For data transfer within ASEAN
For cross-border personal data transfers within ASEAN, businesses may utilize the ASEAN Model Contractual Clauses (MCCs) as a standard contractual framework to ensure personal data protection when transferring data between organizations across ASEAN Member States.
This framework is particularly relevant for Singapore businesses outsourcing healthcare software development to Vietnam. As project delivery often requires the transfer of patients, employee, or business data to an offshore development team, organizations should establish appropriate contractual safeguards with their Vietnamese vendors. Adopting the ASEAN MCCs can help demonstrate PDPA compliance with the Transfer Limitation Obligation while providing a consistent framework for protecting personal data across ASEAN.
Risks of cross-border transfer of personal data
When engaging with an offshore software development partner, businesses should carefully manage risks related to cross-border data transfer.
-
Failure to comply with PDPA Transfer Limitation Obligation: Failure to implement appropriate contractual safeguards or assess the overseas recipient may lead to non-compliance.
-
Lack of control over third-party data handling: Once personal data is transferred overseas, organizations may have limited visibility into how the vendor accesses, stores, or deletes the data. Without proper governance, personal data may be handled in ways that do not meet PDPA requirements.
-
Data breaches during transfer: Personal data may be exposed or intercepted during cross-border transmission if secure transfer methods are not used.
Technical controls required for PDPA Compliance
Technical controls play a key role in helping organizations comply with the PDPA:
01. Data Encryption
Encrypt personal data both in transit and at rest to prevent unauthorized access during storage and cross-border transmission. Encryption is particularly important when handling sensitive healthcare information.
02. Role-based access control (RBAC)
Restrict access to personal data based on users' roles and responsibilities. Applying the principle of least privilege helps ensure that only authorized personnel can access sensitive healthcare data.
03. Multi-factor authentication (MFA)
Require users to verify their identity using multiple authentication factors before accessing systems containing personal data. MFA provides an additional layer of security against unauthorized access.
04. Regular data audits
Conduct regular audits to monitor how personal data is accessed, processed, and stored. Audit logs also help identify security gaps and support compliance monitoring.
05. Incident response
Establish a documented incident response plan to quickly detect, contain, investigate, and recover from data breaches. Clear response procedures also help organizations meet the PDPA's data breach notification requirements where applicable.
A practical checklist for Healthcare Software Development vendor
When selecting a healthcare software development vendor, organizations should evaluate not only technical capabilities but also the vendor's ability to support PDPA compliance throughout the software development lifecycle.
01. PDPA awareness and compliance
The vendor should understand Singapore PDPA requirements and implement policies for handling personal data responsibly.
02. Security certifications
Look for recognized certifications such as ISO 27001 and ISO 9001:2015 to demonstrate a mature information security management system.
03. Cross-border data transfer safeguards
If personal data is transferred overseas, verify that the vendor can support the PDPA's Transfer Limitation Obligation through appropriate contractual and technical safeguards.
04. Data breach response process
The vendor should have a documented incident response plan and be able to promptly notify your organization in case of a security incident.
05. Regular security assessment
Check whether the vendor conducts vulnerability assessments, penetration testing, and periodic security reviews to identify and address security risks.
What the PDPA Does Not Cover
The PDPA is the baseline for personal data protection in Singapore, not the full compliance requirement for a healthcare product. A system can satisfy every PDPA obligation and still fail a Ministry of Health licensing review. Teams that treat the PDPA as the complete specification usually find the gap late, when the data model is already fixed, and the cost of changing it is highest.
Four gaps matter most when scoping a healthcare software project.
01. Organizations and Data Outside the PDPA's Scope
The PDPA does not apply to:
-
Individuals acting in a personal or domestic capacity.
-
Individuals acting in the course of their employment with an organization. The obligation sits with the employer, not the employee.
-
Public agencies. Government bodies follow the Public Sector (Governance) Act and the Government's own data governance rules rather than the PDPA, as the Ministry of Digital Development and Information has set out in Parliament.
-
Business contact information provided for business purposes, such as a name, job title, business phone number, business address, or business email.
The public agency exclusion is the one that catches product teams. It does not mean health data held by the public sector is unprotected. It means a different rulebook applies, with different obligations and a different regulator. If your product is connected to a public healthcare institution, confirm which regime governs that counterparty before you design consent, access, or audit flows. The PDPA answer does not automatically transfer.
02. Licensing Sits with the Healthcare Services Act
The PDPA governs how personal data is handled. It says nothing about whether you are permitted to deliver the clinical service in the first place.
That sits with the Healthcare Services Act (HCSA), administered by MOH, which replaced the Private Hospitals and Medical Clinics Act. The HCSA licenses providers by the Licensable Healthcare Service they deliver and by the Mode of Service Delivery they use, rather than by physical premises. That shift is how care delivered remotely, outside a clinic, is brought into regulatory scope.
For a software team, the consequence is practical. PDPA compliance does not make a telemedicine platform lawful to operate. The provider running it needs the correct HCSA licence and mode of service delivery, and the licence conditions attached will constrain product decisions such as record keeping, identity verification, and clinical governance workflows. Those constraints belong in the requirements document, not in a post-launch remediation ticket.
03. Record Retention: The PDPA Sets a Ceiling, the HCSA Sets a Floor
This is where the two regimes pull in opposite directions, and it is the single most common architectural mistake in Singapore healthcare products.
The PDPA's Retention Limitation Obligation requires an organization to stop retaining personal data once retention no longer serves the purpose it was collected for, or any legal or business purpose.
The HCSA pushes the other way. Under MOH Circular No. 85/2022, issued as licence conditions pursuant to Regulation 37(1) of the Healthcare Services (General) Regulations 2021, HCSA licensees must retain patient health records for prescribed minimum periods, including:
-
Computerized or electronic patient health records: lifetime plus six years.
-
Paper inpatient records for adults: 15 years from the last day of stay, consultation, or treatment, whichever is later.
-
Paper outpatient records: 6 years from the last day of consultation or treatment, whichever is later, unless the case is classified as high risk.
Read those two obligations together, and a common product assumption breaks. A "delete my data" control that hard-deletes a patient record is not a PDPA feature. For a licensee client, it is an HCSA breach waiting to happen. The workable design is almost always a separation: clinical records retained on the HCSA schedule under restricted access and full audit logging, and non-clinical data such as marketing preferences, analytics identifiers, and abandoned registrations purged on a PDPA-driven schedule.
The retention obligation belongs to the licensee, not to the software vendor. But the vendor builds the mechanism, and a system that cannot honor the schedule makes the client non-compliant.
04. Data Residency Is Not a PDPA Requirement
Nothing in the PDPA requires personal data to remain in Singapore. Under the Transfer Limitation Obligation, personal data may be transferred overseas where the requirements under the law are met, unless the PDPC exempts the transfer.
This is regularly misread during vendor selection. Buyers reject offshore delivery based on a residency rule the PDPA does not contain, while accepting local vendors with no documented transfer safeguards at all. The PDPA question is not where the data physically sits. It is whether the receiving party is bound to a comparable standard of protection, and whether you can evidence that binding.
Residency may still be imposed on you from elsewhere: a contract clause, a client's internal security policy, a public sector procurement requirement, or a licence condition. Those are real constraints. They are simply not PDPA constraints, and the distinction matters when you are negotiating scope.
What This Means When You Brief a Vendor
PDPA compliance is necessary and not sufficient. Before development starts, map three things separately: which PDPA obligations apply to the data, which HCSA licence conditions apply to your client's service, and which contractual or procurement terms apply to the engagement. A vendor that only answers the first is answering a third of the question.
About Adamo APAC
Adamo APAC - A reliable offshore software development partner for Singapore businesses
Adamo APAC is the Singapore arm of Adamo Software. We build smart software solutions faster, with AI at the core. We deliver three core services for businesses scaling digital products across Asia-Pacific by combining Singapore-based engagement leadership with a Vietnamese senior engineering team.
Why choose us for healthcare software development
-
Compliance is standard, not an upsell: We hold ISO 27001 and ISO 9001:2015 certifications. Every engagement includes PDPA-aligned data handling, NDAs signed within 24 hours, and full IP and source-code ownership transferred to the client from day one.
-
Asia-Pacific markets focus: Have an understanding of local payment gateways, regional requirements, and cultural nuances.
-
Deep healthcare knowledge: Proven experience delivering software solutions for healthcare organizations, providing a strong understanding of industry workflows, regulations, and operational challenges.
Discover our real-world healthcare case studies:
-
My Emergency Doctor - Healthcare operations data pipeline replaces what would otherwise be manual reporting, scattered spreadsheets, and reconciliation work. MED's operations team works from a single source of truth for billing, SLA performance, and workforce intelligence.
-
ONEai Health - An All-in-one remote monitoring technology to elevate patient care. By moving routine monitoring to the patient’s home, it reduces the need for unnecessary hospital stays and in-person check-ups.
-
AI-powered Mediverse – An all-in-one telehealth ecosystem integrating clinics, laboratories, imaging centers, and global pharmacy networks into one connected platform enables online medical consultations and rapid diagnostic processing,
Our healthcare service offerings:
-
Telehealth & Telemedicine
-
EHR/EMR Systems & Health Information Exchange
-
Remote Patient Monitoring (RPM)
-
Hospital & Clinic Management
-
Mobile Health (mHealth) Solutions
-
Healthcare Data Analytics
FAQs
01. How do you ensure healthcare software is compliant with PDPA?
First, we identify regulation apply to your solution - PDPA for Singapore. We then design data architecture, access controls, encryption, and audit logging to meet those requirements.
02. How do you handle data migration from legacy healthcare systems?
Our approach includes: full data audit and mapping before migration, validation of data integrity at each stage, audit trails for every migrated record, and zero-downtime migration approaches where production systems serve active patients. We test migration on staging environments thoroughly before touching production data.
03. How do you handle patient data security?
Patient data is protected at multiple layers: strong encryption for data in storage and transmission, role-based access controls limiting who sees what, comprehensive audit logging, and secure cross-border data transfer mechanisms. Our development environments are accessed only via VPN, engineers are background-checked, and we operate under ISO 27001 information security management. For projects involving sensitive health data, we offer additional measures including data residency options.