IHiS and SingHealth fined total $1M by PDPC for lapses in Singapore's worst cyberattack

SingHealth cyberattack: COI releases recommendations
SingHealth cyberattack: COI releases recommendations

Singapore’s privacy watchdog has imposed its highest ever fine of $750,000 on Integrated Health Information Systems (IHiS) for lapses resulting in the nation’s worst cyberattack in history.

While IHiS is the central IT agency for the healthcare sector, SingHealth was also liable as the owner of the compromised patient database system, said the Personal Data Protection Commission (PDPC), according to a report by The Straits Times.

SingHealth was fined $250,000 – the second largest ever financial penalty imposed by PDPC.

The PDPC said in a statement on Tuesday (15 January), “Even if organisations delegate work to vendors, organisations as data controllers must ultimately take responsibility for the personal data that they have collected from their customers.”

The privacy watchdog noted that the person involved in handling security incidents concerning SingHealth was unfamiliar with the steps to respond to them. The PDPC was referring to IHiS’ cluster information security officer Wee Jia Huo.

The personal particulars of 1,495,364 patients – including that of Prime Minister Lee Hsien Loong – were stolen from SingHealth’s database during the cyberattack, which occurred between 27 June and 4 July last year.

On Monday, IHiS announced that two of its senior managers have been sacked for being “negligent” and “in non-compliance of orders” during the cyberattack.

Five members of the IHiS senior management, including CEO Bruce Liang, have also been given a “significant financial penalty” for their collective leadership responsibility. A “moderate financial penalty” will be imposed on two middle management supervisors, said IHiS.

In addition, the Cluster Information Security Officer – who was not named but is believed to be Wee – who “failed to comply with IHiS’ incident reporting processes” has been demoted and re-deployed to another role.

Related stories

SingHealth cyberattack: IHiS fires 2 managers, financial penalties for 7 including CEO

Workplace cultural issues need addressing: IHiS chief executive

SingHealth cyberattack: Suspected malware incident in January not reported

Initial responses to SingHealth cyberattack ‘piecemeal and inadequate’: Solicitor-General