The Integrated Health Information Systems Pte Ltd ("IHiS") andSingapore Health Services Pte Ltd ("SingHealth") were fined forbreaching their data protection obligations under the Personal Data ProtectionAct (PDPA), according to a press release issued by PDPC.
SingHealth's patient database system suffered cyberattack in mid 2018,which led to the disclosure of personal information of 1.5 million patients,including Singaporean Prime Minister Lee Hsien Loong.
PDPC found that IHiS, which was assigned by SingHealth to operate itspatient database system, had failed to take adequate security measures toprotect the personal data in its possession and thus has imposed a financialpenalty of 750,000 SGD (around 556,000 USD).
Meanwhile, a financial penalty of 250,000 SGD was also imposed onSingHealth as the owner of the patient database system.
In a statement released on the same day, SingHealth's CEO Ivy Ngapologised to patients and accepted the fine. The company is making changes toenhance its cyber-security governancestructures and improve management oversight of its critical systems, she said.
SingHeath is the largest healthcare group in Singapore. Founded in 2000,it comprises four public hospitals and five national specialty centers.-VNA