DATA SECURITY REQUIREMENTS APPLY TO AI TOOLS THAT PROCESS PATIENT DATA
4 August 2026
NOTICE PAPER NO. 1010
NOTICE OF QUESTION FOR WRITTEN ANSWER
FOR THE SITTING OF PARLIAMENT ON 4 AUGUST 2026
Name and Constituency of Member of Parliament
Assoc Prof Jamus Jerome Lim
MP for Sengkang GRC
Question No. 1703
To ask the Coordinating Minister for Social Policies and Minister for Health whether mandatory data security requirements apply to AI tools that process patient data through third-party cloud services.
Answer
1 Yes, data security requirements apply to AI tools that process patient data, whether hosted on third-party cloud services or on-premise. These are requirements under both the Healthcare Services Act and the Personal Data Protection Act.
2 Public healthcare institutions have also adopted additional practices to safeguard data. For example, AI model providers whom they work with must give legally-binding commitments that all input and output data are not stored or retained. The AI tools also need to be accessed from secure environments.
