Written Answer · 2026-08-04 · Parliament 15

Mandatory Data Security Requirements for Patient Data Processed by AI Tools Through Third-party Cloud Services

Workers' Party MP Assoc Prof Jamus Jerome Lim asked the Coordinating Minister for Social Policies and Minister for Health in a written question whether mandatory data security requirements apply to AI tools that process patient data through third-party cloud services. Coordinating Minister for Social Policies and Minister for Health Ong Ye Kung replied yes: data security requirements apply to AI tools that process patient data whether they are hosted on third-party cloud services or on-premise, and these requirements arise under both the Healthcare Services Act and the Personal Data Protection Act. Public healthcare institutions have also adopted additional safeguards. For example, the AI model providers they work with must give legally-binding commitments that all input and output data are not stored or retained, and the AI tools must be accessed from secure environments. The answer did not describe specific technical standards or how compliance is audited.

Why it matters

Public healthcare institutions require AI model providers to give legally-binding commitments not to store input or output data, adding a layer on top of the Healthcare Services Act and the PDPA.

Key Points

  • AI tools that process patient data are subject to data security requirements under the Healthcare Services Act and the Personal Data Protection Act, whether hosted on third-party cloud services or on-premise
  • AI model providers working with public healthcare institutions must give legally-binding commitments that all input and output data are not stored or retained
  • AI tools must be accessed from secure environments
  • The answer did not set out specific technical standards or a compliance-audit mechanism
Government Position

MOH's position is clear: there is no distinction by deployment model — AI tools on third-party cloud and on-premise are equally bound by the Healthcare Services Act and the PDPA — and above that legal floor public healthcare institutions add a contractual layer (legally-binding provider commitments and secure access environments). The Government considers the existing framework sufficient for AI use cases and proposed no new dedicated legislation.

Opposition Position

Workers' Party MP Jamus Lim's concern is whether patient data, once processed by AI tools running on third-party cloud services, remains covered by mandatory rather than voluntary security requirements — in other words, whether outsourced healthcare AI leaves a regulatory gap in data protection.

Policy Signal

Singapore's data governance for healthcare AI runs on a dual track of existing law plus institutional contracts: rather than legislating separately for AI or cloud deployment, it treats the Healthcare Services Act and the PDPA as a common floor, and lets public healthcare institutions gate access through legally-binding provider commitments (no retention of input or output data) and secure access environments. This pushes the data-retention risk of large-model vendors upstream to procurement, effectively setting the entry conditions for AI in the public healthcare system.

"For example, AI model providers whom they work with must give legally-binding commitments that all input and output data are not stored or retained."

Participants (2)

Original Text (English)

SPRS Hansard · Fetched: 2026-09-04

21 Assoc Prof Jamus Jerome Lim asked the Coordinating Minister for Social Policies and Minister for Health whether mandatory data security requirements apply to AI tools that process patient data through third-party cloud services.

Mr Ong Ye Kung : Yes, data security requirements apply to AI tools that process patient data, whether hosted on third-party cloud services or on-premise. These are requirements under both the Healthcare Services Act and the Personal Data Protection Act.

Public healthcare institutions have also adopted additional practices to safeguard data. For example, AI model providers whom they work with must give legally-binding commitments that all input and output data are not stored or retained. The AI tools also need to be accessed from secure environments.

Cite this record

Singapore AI Observatory. Mandatory Data Security Requirements for Patient Data Processed by AI Tools Through Third-party Cloud Services. Retrieved 2026-09-07, https://sgai.md/debates/written-answer-23875/

More on these topics