Writing / Article

Reading the SingHealth COI Report Eight Years Later: The Cyber Attack on Singapore’s Patient Database

An analysis of the SingHealth COI findings, the multi-phase attack route, key operational weaknesses, and a practical cybersecurity roadmap for healthcare organizations.

Contents

This post is written with hindsight in mind. The goal is not to claim the warning signs were obvious at the time, but to learn from the COI’s findings and explain what the incident still teaches healthcare cybersecurity teams today.

In July 2018, Singapore disclosed what was described as its worst personal data breach at the time.

The Committee of Inquiry (COI) reported that SingHealth suffered a cyberattack in June and July 2018. The attack led to the exfiltration of personal data and medication records affecting about 1.5 million individuals, including the records of then Prime Minister Lee Hsien Loong.

The COI did not present the breach as a simple malware incident. It found that the attacker was a skilled and sophisticated actor bearing the characteristics of an Advanced Persistent Threat (APT) group. It also found that cyber defences may not be impregnable, but the attacker’s success in obtaining and exfiltrating the data was not inevitable.

That is the core lesson.

The issue was not only that an attacker entered the network. The bigger issue was that the attacker was able to move through the environment, reach the electronic medical records (EMR) system, and exfiltrate data before being stopped.


What Happened

Based on the COI report and later case-study analysis, the attack unfolded over several phases.

This diagram below is a simplified view of the attack path based on public COI materials and later case-study analysis. It shows the broad movement from initial compromise to data exfiltration, but it does not capture every missed signal, response delay, or organisational issue discussed in the COI report.

Initial compromise (Workstation A)

Public analysis described the first known compromise as Workstation A in Aug 2017, likely through phishing-delivered malware.

Lateral movement (Workstations and Admin accounts)

The attacker moved across devices and administrator accounts from Dec 2017 to Jun 2018 while trying to reach the SCM database.

SCM access (SCM/EHR database)

Public analysis stated that an SCM software vulnerability was exploited to access the EHR database environment.

Data exfiltration (Patient Data Stolen)

Personal data of about 1.5M patients and medication records of about 159,000 patients were exfiltrated from 27 Jun to 4 Jul 2018.


How It Happened

The COI’s findings point to a chain of weaknesses rather than a single failure.

1. Insufficient cybersecurity awareness and readiness

The COI found that employees did not have adequate cybersecurity awareness, training, and resources to appreciate the security implications of what they saw or to respond effectively.

2. Weak incident response and escalation

The COI found that employees in key security incident response and reporting roles failed to act in an appropriate, effective, or timely way.

This is one of the clearest operational lessons from the breach. Security teams need escalation rules that are simple enough to use under pressure. Suspicious callbacks, unusual administrative access, repeated failed attempts to reach critical systems, and abnormal database queries should not depend on personal judgement alone. Setting up simple incident response and escalation rules helps streamline this behavior.

3. Vulnerabilities, weaknesses, and misconfigurations

The COI found that vulnerabilities, weaknesses, and misconfigurations in the network and systems contributed to the attacker’s success. It also found that many could have been remedied before the attack.

This shows why vulnerability management cannot stop at scanning or penetration testing. Findings need owners, deadlines, risk acceptance, remediation evidence, and independent validation. Implementing a rigorous vulnerability management workflow prevents these openings from lingering.

4. Weak privileged access controls

The COI recommendations stated that privileged administrator accounts should be subject to tighter control and greater monitoring.

This points to the need for privileged access management, MFA, session monitoring, just-in-time access, and stronger detection for abnormal administrator activity. Reviewing controls against standards like the MAS Cyber Hygiene guidelines is standard practice here.

5. Inadequate protection around electronic medical records

The COI recommendations called for enhanced safeguards to protect electronic medical records.

For healthcare, EHR systems should be treated as crown-jewel systems. Access should be tightly controlled, monitored, and reviewed. Unusual access patterns should trigger investigation.


Why It Happened

The COI’s findings indicate that the breach succeeded because several weaknesses aligned.

AreaCOI-supported findingProfessional analysis
PeopleStaff lacked adequate awareness, training, and resourcesTraining must be tied to real escalation scenarios
ResponseKey personnel failed to act effectively and in timeIncident response needs clear triggers and authority
TechnologyVulnerabilities and misconfigurations contributed to the attacker’s successSecurity findings must be tracked to closure
Privileged accessPrivileged accounts needed tighter control and monitoringAdmin access should be temporary, monitored, and risk-based
Medical recordsEHR safeguards needed strengtheningEHR access should be monitored like access to financial crown jewels

The breach should not be described as inevitable. The COI explicitly found the opposite: while preventing an APT from entering the perimeter may be difficult, the attacker’s success in obtaining and exfiltrating data was not inevitable.


The COI recommendations covered people, process, technology, and partnerships.

The recommendations included improving staff awareness, improving incident response competence, adopting enhanced security structure and readiness, performing stronger checks on Critical Information Infrastructure (CII) systems, tightening control over privileged administrator accounts, improving incident response processes, treating security risk assessments seriously, implementing robust patch management, reviewing the cyber stack, strengthening electronic medical record safeguards, securing domain controllers, and improving government-industry partnerships.

The recommendations are practical because they do not depend on one control. They assume that attackers may bypass outer defences. They focus on layered defence, faster detection, better escalation, and stronger protection of critical systems.


Lessons for Healthcare Cybersecurity

Lesson 1: Do not write “assume breach” as defeatism

The COI did not say organisations should give up on prevention. It said cyber defences will never be perfect, and that success by the attacker was not inevitable.

The correct approach is prevention plus detection plus response. Healthcare organisations should still patch, harden, segment, and reduce exposure. But they must also be ready to detect an attacker already inside the network.

Lesson 2: Treat incident response as a clinical safety function

The COI found that response and reporting failures created missed opportunities.

In healthcare, cyber incidents can affect privacy, trust, and care delivery. Incident response should involve IT, security, clinical operations, legal, communications, and senior management.

Lesson 3: Protect privileged access first

The COI specifically recommended tighter control and monitoring of privileged administrator accounts.

Many serious breaches become severe only after the attacker gains administrator access. Healthcare providers should prioritise privileged access management before buying more advanced tools.

Lesson 4: Track remediation to closure

The COI found that weaknesses and misconfigurations contributed to the breach, and that many could have been fixed before the attack.

A finding marked “closed” should require evidence. For high-risk findings, closure should be independently verified.


Singapore Healthcare Cybersecurity Direction Beyond 2019

1. Stronger baseline controls for healthcare providers

MOH stated in February 2026 that it would issue revised Cyber Security and Data Security Essentials for healthcare providers. MOH said these controls would align with CSA cyber hygiene standards and be suitable for smaller providers, including solo practitioners.

This is a necessary step. Smaller clinics cannot be expected to operate like large healthcare clusters. They need clear, affordable, minimum controls.

2. Cybersecurity requirements linked to health information sharing

MOH stated during the Health Information Bill debate that the Bill’s cybersecurity and data security requirements are based on existing standards and legal requirements, but contextualised for the healthcare sector. MOH also referenced frameworks such as CSA’s Cyber Essentials Mark and IMDA’s Data Protection Essentials.

This points to a shift from voluntary good practice to sector-wide baseline expectations.

3. NEHR-compatible systems and vendor responsibility

MOH stated that healthcare providers would be informed of NEHR-compatible systems that meet the Bill’s cybersecurity requirements and automate contribution of key health information.

This makes vendor assurance more important. If clinics depend on clinic management systems and NEHR-connected platforms, security must be built into the product and not left entirely to each provider. This requires standard third-party risk management audits to establish ecosystem assurance.

4. Continued accountability for critical systems, including cloud-based models

CSA stated that the Cybersecurity Act establishes the framework for protecting Critical Information Infrastructure and that amendments were passed in May 2024. CSA also stated that the amendments ensure CII owners remain responsible for cybersecurity and cyber resilience even when adopting models such as cloud computing.

Outsourcing, cloud adoption, and SaaS do not remove accountability. They change the control model. Healthcare leaders still need assurance over identity, logging, resilience, incident reporting, and vendor access.


Practical Roadmap for Healthcare Organisations

This roadmap is professional analysis based on the COI findings and current Singapore direction.

Identity & Privileged Access

  • Enforce MFA for privileged, remote, and administrative access.
  • Remove shared administrator accounts.
  • Use privileged access management for critical systems.
  • Monitor privileged sessions.
  • Review dormant and excessive access regularly.

Endpoint & Server Defence

  • Deploy endpoint detection and response on workstations and servers.
  • Prioritise patching for internet-facing systems, domain controllers, EHR systems, and remote access.
  • Harden domain controllers.
  • Remove unsupported systems.
  • Monitor suspicious admin tools and credential access behaviour.

Network Segmentation

  • Separate user, server, clinical, database, and management zones.
  • Restrict lateral movement.
  • Monitor east-west traffic.
  • Limit administrative pathways.
  • Review firewall rules regularly.

EHR & Database Monitoring

  • Monitor access to patient records.
  • Alert on unusual query volume.
  • Alert on unusual VIP or sensitive record access.
  • Review access by role and purpose.
  • Maintain clear audit trails by establishing secure, centralized logging.

Incident Response & Escalation

  • Define clear escalation triggers.
  • Run tabletop exercises with senior management and clinical teams.
  • Test ransomware and data breach scenarios.
  • Prepare patient notification workflows.
  • Maintain forensic readiness.
  • Test recovery of critical clinical systems.

Vendor & Ecosystem Security

  • Require secure-by-design clinic management systems.
  • Include logging, MFA, patching, vulnerability disclosure, and incident notification in vendor contracts.
  • Assess vendors with access to patient data or production systems.
  • Prefer shared baseline controls for smaller clinics.
  • Use sector-wide threat sharing where practical.

About Airgapping VIP Records

The case-study analysis suggested that organisations may consider limiting EHR digitisation, including keeping VIP records on paper, as one possible measure for highly sensitive records.

This should be framed carefully.

Offline handling may reduce remote cyber exposure for a very small class of records. But it can also create clinical, operational, and audit risks. It should not be presented as a general solution. The default should be strong digital controls: strict access, monitoring, break-glass workflows, dual approval for exceptional access, and real-time alerting.


Final Takeaway

Reading the COI report eight years later is not about blaming people with the benefit of hindsight. It is about understanding how small gaps in awareness, escalation, access control, and monitoring can combine into a major breach.

The SingHealth breach should not be reduced to “phishing caused a breach” or “an APT could not be stopped.”

The COI’s message was more precise:

The attacker had the characteristics of an APT. The perimeter may not have been impregnable. But the success of the attacker in obtaining and exfiltrating the data was not inevitable.

For healthcare, the lesson is clear: prevent where possible, detect early, escalate fast, protect EHRs deeply, and make cyber resilience part of patient safety.