Back to BlogLegal & Compliance

HIB vs PDPA: Understanding How Singapore's Data Laws Work Together

A clear comparison of the Health Information Bill and Personal Data Protection Act - where they overlap, differ, and how healthcare providers must comply with both.

DRT

Dr. Rachel Tan

Healthcare Compliance Specialist

29 January 202511 min read
#HIB#PDPA#Data Protection#Legal#Singapore

Introduction

Singapore healthcare providers now navigate two major data protection frameworks: the Personal Data Protection Act (PDPA) and the Health Information Bill (HIB). Understanding how these laws interact is essential for comprehensive compliance.

This guide clarifies the relationship between HIB and PDPA, where they overlap, and where they differ.


The Two Laws at a Glance

╔═════════════════════════════════════════════════════════════════╗
║               HIB vs PDPA Overview                              ║
╠═════════════════════════════════════════════════════════════════╣
║                                                                 ║
║         PDPA (2012)                    HIB (2025)               ║
║     Personal Data                   Health Information          ║
║     Protection Act                       Bill                   ║
║                                                                 ║
║  ┌─────────────────────┐        ┌─────────────────────┐        ║
║  │                     │        │                     │        ║
║  │   GENERAL           │        │   HEALTHCARE        │        ║
║  │   All personal data │        │   SPECIFIC          │        ║
║  │   across all        │        │   Health info in    │        ║
║  │   industries        │        │   healthcare        │        ║
║  │                     │        │   settings          │        ║
║  │                     │        │                     │        ║
║  └─────────────────────┘        └─────────────────────┘        ║
║           │                              │                      ║
║           └──────────────┬───────────────┘                     ║
║                          │                                      ║
║                          ▼                                      ║
║                 HEALTHCARE PROVIDERS                            ║
║                  Must comply with BOTH                          ║
║                                                                 ║
╚═════════════════════════════════════════════════════════════════╝

Key Differences

1. Scope of Application

AspectPDPAHIB
What it coversAll personal dataHealth information specifically
Who it applies toAll organizationsHealthcare providers, NEHR users
IndustryCross-industryHealthcare-specific
RegulatorPDPCMOH

2. Data Sharing Requirements

╔═════════════════════════════════════════════════════════════════╗
║               Data Sharing: PDPA vs HIB                         ║
╠═════════════════════════════════════════════════════════════════╣
║                                                                 ║
║  PDPA APPROACH:                                                 ║
║  ──────────────                                                 ║
║  • Consent-based sharing                                        ║
║  • Organization decides what to collect                         ║
║  • Must have purpose for collection                             ║
║  • Generally restrictive                                        ║
║                                                                 ║
║  HIB APPROACH:                                                  ║
║  ─────────────                                                  ║
║  • MANDATORY sharing to NEHR (no consent needed)                ║
║  • Specific data categories defined by law                      ║
║  • Purpose defined by statute (care coordination)               ║
║  • Proactive sharing required                                   ║
║                                                                 ║
║  KEY DIFFERENCE: HIB overrides PDPA consent requirements        ║
║  for NEHR contribution                                          ║
║                                                                 ║
╚═════════════════════════════════════════════════════════════════╝

3. Breach Notification

AspectPDPAHIB
Notification to regulator"As soon as practicable"Within 2 hours
Threshold500+ individuals OR significant harm500+ individuals OR sensitive data
Individual notificationIf significant harm likelyIf significant harm likely
RegulatorPDPCMOH

4. Penalties

Penalty TypePDPAHIB
Maximum fine (organization)S$1 millionS$1 million OR 10% turnover
Individual liabilityLimitedUp to S$200,000 + imprisonment
Criminal sanctionsRareExplicit in law

Where They Overlap

Both Require:

  1. Data Protection Measures

    • Both mandate reasonable security safeguards
    • Encryption, access controls, monitoring
  2. Breach Response

    • Both require breach notification
    • Both require notification to affected individuals in certain cases
  3. Purpose Limitation

    • Data should be used for stated purposes
    • Unauthorized access/use prohibited
  4. Retention Limits

    • Don't keep data longer than necessary
    • Secure disposal required

Compliance Interaction

╔═════════════════════════════════════════════════════════════════╗
║               Dual Compliance Framework                         ║
╠═════════════════════════════════════════════════════════════════╣
║                                                                 ║
║                    HEALTHCARE PROVIDER                          ║
║                          │                                      ║
║            ┌─────────────┴─────────────┐                       ║
║            │                           │                       ║
║            ▼                           ▼                       ║
║    ┌─────────────────┐        ┌─────────────────┐             ║
║    │     PDPA        │        │      HIB        │             ║
║    │   Compliance    │        │   Compliance    │             ║
║    └────────┬────────┘        └────────┬────────┘             ║
║             │                          │                       ║
║             │   ┌──────────────────┐   │                       ║
║             │   │                  │   │                       ║
║             └──►│  INTEGRATED      │◄──┘                       ║
║                 │  COMPLIANCE      │                           ║
║                 │  PROGRAM         │                           ║
║                 │                  │                           ║
║                 └──────────────────┘                           ║
║                                                                 ║
║  Where HIB is silent, PDPA applies                              ║
║  Where HIB conflicts, HIB takes precedence for health data      ║
║                                                                 ║
╚═════════════════════════════════════════════════════════════════╝

Practical Scenarios

Scenario 1: Marketing to Patients

Question: Can I send marketing emails to patients about clinic services?

PDPA: Requires consent for marketing communications.

HIB: Silent on marketing (not healthcare-related).

Answer: Follow PDPA. Obtain proper consent before marketing.

Scenario 2: Sharing Data with NEHR

Question: Do I need patient consent to share data with NEHR?

PDPA: Would normally require consent for sharing.

HIB: Mandates NEHR contribution without consent.

Answer: Follow HIB. No consent needed for mandatory NEHR contribution.

Scenario 3: Data Breach at Clinic

Question: Patient records were accessed by hackers. Who do I notify?

PDPA: Notify PDPC "as soon as practicable."

HIB: Notify MOH within 2 hours.

Answer: Follow both. Notify MOH within 2 hours AND PDPC as required.

Scenario 4: Research Using Patient Data

Question: Can I use patient data for a research study?

PDPA: Requires consent OR research exceptions apply.

HIB: Requires proper approvals for research use of NEHR data.

Answer: Follow both. Ensure PDPA consent/exceptions AND HIB research requirements.

Scenario 5: Selling Clinic Database

Question: Can I sell my patient database to another clinic?

PDPA: Strict rules on data transfer/sale.

HIB: Health data has additional protections.

Answer: Follow both. Very restricted. Patients' rights paramount.


Compliance Checklist: Dual Framework

For PDPA:

  • Appointed Data Protection Officer
  • Documented data protection policies
  • Consent obtained where required
  • Data breach response plan
  • Staff trained on PDPA requirements
  • Data inventory maintained
  • Third-party contracts include data protection

For HIB:

  • NEHR integration complete
  • 2-hour breach notification capability
  • Cybersecurity controls implemented
  • Staff trained on HIB requirements
  • Patient access restrictions respected
  • Audit logging enabled
  • Incident response plan specific to HIB

Integrated:

  • Single DPO/compliance lead oversees both
  • Unified breach response process
  • Combined staff training program
  • Integrated policy documentation
  • Consistent security controls

Common Misconceptions

Misconception 1: "HIB replaces PDPA for healthcare"

Reality: HIB supplements PDPA. Both apply. HIB adds healthcare-specific requirements.

Misconception 2: "I only need to follow the stricter rule"

Reality: You must comply with both laws. Sometimes PDPA is stricter, sometimes HIB is stricter.

Misconception 3: "NEHR contribution means PDPA doesn't apply"

Reality: PDPA still applies to patient data. HIB creates an exception for NEHR contribution only.

Misconception 4: "Breach notification to one regulator is enough"

Reality: You may need to notify both MOH (under HIB) and PDPC (under PDPA) for the same breach.


Summary Table

RequirementPDPAHIBWhich to Follow
Consent for collectionRequiredNot required for NEHRHIB for NEHR; PDPA otherwise
Security measuresRequiredRequiredBoth (implement once)
Breach notificationPDPC, ASAPMOH, 2 hoursBoth regulators
Individual notificationIf significant harmIf significant harmBoth (same process)
MarketingConsent requiredSilentPDPA
ResearchConsent/exceptionsAdditional HIB rulesBoth
Data retentionPurpose-basedMOH guidelinesBoth
Max penaltyS$1MS$1M or 10%Both can apply

Key Takeaways

  1. Both laws apply - Healthcare providers must comply with PDPA AND HIB.

  2. HIB is additive - HIB doesn't replace PDPA; it adds healthcare-specific requirements.

  3. Know when HIB takes precedence - For NEHR contribution, HIB overrides PDPA consent.

  4. Stricter rule varies - Sometimes PDPA is stricter, sometimes HIB. Know both.

  5. Integrated approach works best - Build one compliance program that addresses both.


For official guidance, refer to PDPC Guidelines and MOH Health Information

Share this article

Take Free Assessment