Singapore’s Health Information Bill is expected to reshape how healthcare data is shared across providers, creating new opportunities for continuity of care, patient outcomes and digital health innovation. At the same time, greater interoperability raises questions around data protection, infrastructure resilience and the security of increasingly connected healthcare environments.
As healthcare organisations across APAC adopt AI, connected platforms and standardised data frameworks, cybersecurity is becoming central to trust in digital health. In this interview, Wai Kit Cheah, APAC CISO & Connected Ecosystem Leader at Lumen Technologies, discusses how healthcare providers can strengthen governance, protect sensitive patient data and build resilience into digital infrastructure.
With the Health Information Bill (HIB) having been introduced to mandate the sharing of patient data, how do you see this framework fundamentally changing the medical landscape and data portability within Singapore?
The Health Information Bill (HIB) represents a significant step towards a more connected healthcare ecosystem, enabling secure and high-quality data sharing across providers to improve continuity of care and patient outcomes.
However, greater data portability also means greater responsibility. As sensitive personal information moves more extensively across interconnected systems, organisations must expand their focus beyond protecting data at rest to securing data in transit and ensuring the resilience of the digital infrastructure that enables these exchanges.
This comes at a time when the cyber threat landscape is becoming significantly more sophisticated. Threat actors are increasingly targeting edge infrastructure and leveraging AI to automate and scale attacks, as reported in our 2026 Lumen Defender Threatscape Report. In healthcare environments, this could translate into risks like compromised connected medical devices, patient monitoring systems, or internet-facing healthcare platforms being exploited as entry points to access sensitive data or disrupt critical clinical services.
Securing these interconnected systems and the pathways through which health data moves will be critical. Healthcare organisations must embed cyber resilience into the design of their digital infrastructure through secure connectivity, end-to-end visibility and robust governance to ensure early threat detection and minimise operational disruption.
As data sharing becomes standard under the HIB, resilience will become a strategic imperative. Healthcare organisations that can securely share information while maintaining trust, service availability and regulatory compliance will be best positioned to realise the full benefits of a connected healthcare ecosystem.
As healthcare providers increasingly integrate AI for diagnostics and operational efficiency, what specific protocols are necessary to ensure that sensitive patient data remains secure and resistant to unauthorized manipulation?
As healthcare providers adopt AI for diagnostics and operational efficiency, security must extend beyond protecting patient data to safeguarding the integrity of the AI systems and decisions that depend on that data. In a clinical setting, the risks are not limited to data breaches; they also include data poisoning, unauthorised model manipulation, adversarial inputs, and synthetic content such as deepfakes that could undermine trust in clinical or operational workflows.
Healthcare organisations should start with strong data governance. This includes strict controls over how patient data is collected, labelled, accessed, shared and used to train or fine-tune AI models. Sensitive data should be encrypted, access should be limited based on least privilege, and all use of patient information should be logged and auditable. Where possible, privacy-preserving approaches such as data minimisation, anonymisation or tokenisation should also be applied.
Just as importantly, AI systems need model governance. Healthcare providers should validate models before deployment, continuously monitor them for drift or abnormal behaviour, and maintain clear human oversight for high-impact clinical decisions. This helps ensure that AI outputs remain explainable, traceable and clinically appropriate, rather than becoming a black box embedded within critical workflows.
From a cybersecurity perspective, AI workloads should be isolated from broader IT environments through network segmentation and Zero Trust principles. Continuous monitoring, threat detection and incident response capabilities are also essential to identify suspicious behaviour early, including attempts to manipulate data inputs, compromise APIs, or move laterally across connected healthcare systems.
Ultimately, trust in healthcare AI depends on the resilience of the entire ecosystem around it — the data, models, infrastructure, governance and people. AI can improve clinical efficiency and patient outcomes, but only if healthcare organisations can prove that the systems are secure, auditable and resistant to manipulation.
Beyond Singapore, how will these standardized data frameworks influence digital health integration and cybersecurity posture across the larger APAC region?
Across the APAC region, standardised healthcare data frameworks will play an important role in enabling more connected digital health ecosystems. Frameworks such as Fast Healthcare Interoperability Resources (FHIR) and Health Level Seven (HL7) provide a common language for clinical data exchange, making it easier for healthcare providers, public agencies, insurers and technology partners to share information securely and consistently. Over time, this can improve continuity of care, support better clinical decision-making and create a stronger foundation for regional digital health innovation.
At the same time, greater interoperability also expands the cyber risk landscape and attack surface. As more healthcare organisations exchange high volumes of sensitive patient data across platforms, cloud environments and partner ecosystems, the number of potential entry points increases. A vulnerability in one part of the ecosystem can quickly become a wider operational or data protection issue.
This is why standardisation must be accompanied by stronger cybersecurity and governance standards. Healthcare organisations across APAC will need to align interoperability with secure connectivity, identity-based access control, encryption, auditability, data residency considerations and clear accountability for third-party risk. These controls are especially important in a region where regulatory requirements, cloud adoption maturity and healthcare infrastructure vary significantly across markets.
Regional integration will also raise expectations around operational resilience. Healthcare organisations must assume that threats such as ransomware, data exfiltration, supply chain compromise and AI-enabled attacks will continue to target critical health systems. Resilience therefore requires not only prevention, but also continuous monitoring, tested incident response, immutable backups and recovery capabilities that protect the availability of critical clinical services.
Ultimately, standardised data frameworks can accelerate healthcare transformation across APAC, but only if trust is built into the ecosystem from the start. The organisations that succeed will be those that treat interoperability and cybersecurity as two sides of the same agenda: enabling data to move where it is needed, while ensuring it remains protected, governed and resilient.
Given the evolving threat landscape, what proactive steps should healthcare organizations take to remain resilient against malicious activity while maintaining the availability of critical digital services?
The threat landscape is now characterised by AI-driven attackers - such as automated phishing and deepfake social engineering - and double-extortion ransomware campaigns targeting highly valuable patient data.
To remain resilient, healthcare organisations must shift from reactive IT defences to a proactive, policy-aligned “resilience by design” approach that prioritises continuous clinical availability, even in the face of a cyber incident.
In practice, this involves strengthening the security of clinical applications, electronic health record systems, and connected healthcare platforms, while continuously monitoring for signs of compromise that could affect the integrity of patient data. Combined with global network visibility and advanced threat intelligence, emerging threats can be identified and neutralised before they ever reach the organisation’s network perimeter.
Relying on fragmented legacy IT systems is no longer sustainable. Healthcare providers must unify their identity, data, network, and AI defence strategies within an integrated Zero Trust framework that guarantees continuous 24/7 monitoring, rapid incident response, and comprehensive compliance readiness.
As healthcare becomes increasingly digital and interconnected, resilience will be defined not by whether organisations face cyber threats, but by how effectively they anticipate, withstand and recover from them while maintaining uninterrupted patient care.