SingHealth Case

Estimated reading: 6 minutes 76 views

Singapore Health Services & Integrated Health Information Systems[2019] SGPDPC 3

Facts of the Case (In Brief)

This case involves the worst personal data breach in Singapore’s history, resulting from an unprecedented cyber attack on the patient database system of Singapore Health Services Pte. Ltd. (SingHealth). Between June 27 and July 4, 2018, the personal data of approximately 1.5 million patients and the outpatient prescription records of nearly 160,000 patients were illegally accessed and exfiltrated. The compromised Sunrise Clinical Manager (SCM) database contained highly sensitive details, including patient names, NRIC numbers, addresses, clinical episode information, diagnoses, and dispensed medication records. The Personal Data Protection Commission (PDPC) investigated both SingHealth and its IT provider, Integrated Health Information Systems Pte. Ltd. (IHiS), finding both in breach of their data protection obligations. SingHealth was fined $250,000 and IHiS was fined $750,000.


Relationship Between SingHealth and IHiS

  • Corporate Structure: Both SingHealth and IHiS are wholly-owned subsidiaries of MOH Holdings Pte Ltd (MOHH), the holding company through which the Singapore government owns corporatised public healthcare institutions.
  • Data Intermediary Role: IHiS is the central national IT agency for the public healthcare sector. Under the PDPA, IHiS acted as a data intermediary for SingHealth, tasked with managing, maintaining, and securing SingHealth’s IT networks and the SCM database.
  • Shared Personnel and Accountability: To consolidate public healthcare IT, staff employment was centralised under IHiS. Under this arrangement, IHiS employed and deployed key IT security leaders—specifically the Group Chief Information Officer (GCIO) and the Cluster Information Security Officer (CISO)—to work directly within SingHealth. The GCIO reported directly to SingHealth’s executive management but remained concurrently accountable to the CEO of IHiS.

Steps Taken by the Hacker

Forensic investigations revealed a highly disciplined, multi-stage attack by a sophisticated threat actor:

  1. Initial Foothold (August 2017): The attacker gained entry by infecting an end-user workstation, likely via a phishing email, allowing them to install malware and hacking tools.
  2. Workstation Infection & Lateral Movement (December 2017 – May 2018): The attacker used customized malware to infect and remotely control other workstations. Through this lateral movement, they compromised two dormant administrative and service accounts.
  3. Citrix Server Access: Using the compromised accounts, the attacker logged into legacy Citrix servers at the SGH campus (SGH Citrix Servers), establishing a direct path to the SCM database.
  4. SCM Client Exploitation (June 26, 2018): Although the attacker lacked the database credentials to log directly into SCM, they successfully exploited an inherent coding vulnerability in the SCM client application on the H-Cloud Citrix server to retrieve the SCM database login credentials.
  5. Data Exfiltration (June 27 – July 4, 2018): Armed with the stolen database credentials, the attacker logged into the SCM database from a compromised SGH Citrix Server, executed numerous bulk queries, and exfiltrated the patient records back through compromised workstations to overseas Command and Control (C2) servers.

Staff Response During the Incident

  • Initial Detection (June 11–13, 2018): An IHiS database administrator noticed multiple failed attempts to log into the SCM database using invalid credentials. By June 13, she recognized this as unauthorized access. A chat group was created to monitor the situation, which included the IHiS Security Incident Response Manager (SIRM) and the SingHealth CISO.
  • Failure to Escalate: Despite knowing about the suspicious login attempts and subsequent remediation efforts, neither the SIRM nor the SingHealth CISO escalated the matter to higher management, and the Security Incident Response Team (SIRT) was not formally activated. The SIRM (who was overseas part of the time) incorrectly assumed an incident only required escalation once “confirmed”. The SingHealth CISO passively waited for updates, abdicated decision-making to the SIRM, and failed to grasp the gravity of the threat.
  • Containment (July 4, 2018): An IHiS Assistant Lead Analyst observed performance monitor alerts indicating unusual database queries. He, along with application, Citrix, and database teams, quickly developed an automated script to terminate the unauthorized queries, log them, and block SCM database connections originating from SGH Citrix Servers, effectively halting the exfiltration.
  • Late Escalation & Formal Response (July 9–10, 2018): SingHealth’s GCIO and senior management were only alerted on July 9. The GCIO promptly escalated the incident. On July 10, a “war room” was established, the Cyber Security Agency of Singapore (CSA) was notified, and IHiS/CSA initiated aggressive containment measures (resetting credentials, clearing Citrix servers, tightening firewall rules, and placing the security centre on high alert). Affected patients were later notified via SMS and letters.

Specific Security Shortcomings Identified by the PDPC

SingHealth’s Shortcomings (Supervisory Failures)

  • CISO’s Operational Failure: The CISO failed to comply with incident response SOPs, did not exercise independent judgment to escalate a potential Category 1 CII breach, and failed to provide leadership or coordinate investigative efforts.
  • Systemic Staffing Deficiencies: The CISO was the only staff member specifically dedicated to security and worked entirely alone with no supporting team or adequate coverage when he was away (such as on medical leave), which was inadequate for an organisation of SingHealth’s scale.

IHiS’s Shortcomings (Technical & Policy Failures)

  • Unimplemented Firewall Rules: IHiS management instructed its Citrix Team in July 2017 to enable software firewalls on SGH Citrix Servers to block Remote Desktop Protocol traffic. The team failed to do so, and supervisors falsely reported to the CISO that the audit remediation had been completed.
  • Unprotected Connections: There were no firewalls or security controls isolating or monitoring communications between the legacy SGH Citrix Servers and the SCM database located at the H-Cloud data centre.
  • Weak Local Administrator Password: The compromised local administrator account was secured with an easily guessed, 8-character password (“P@ssw0rd”) that had not been changed since 2012. This violated IHiS’s password policy, which required a 15-character length and rotation every three to six months.
  • Passwords Stored in Cleartext: A Citrix Administrator created a script containing local administrator credentials in cleartext on an SGH Citrix Server, defying explicit instructions from supervisors to clean up and encrypt stored passwords.
  • Incomplete Dormant Account Disabling: Automated sweeps designed to detect and disable dormant accounts only scanned “domain” accounts, leaving local administrator and service accounts unmonitored.
  • Inadequate Reporting Training and Policies: IHiS had no written security incident reporting policy or structured training program for its non-security staff, relying instead on passive and temporary measures like emails, wallpapers, and intranet banners.
  • Lapses by the SIRM: In January 2018, the SIRM ignored suspicious callback alerts to a foreign IP address from compromised workstations and failed to block the IP or investigate. He also failed to escalate the mid-June database login failures, delaying reporting due to concerns about management pressure.

Leave a Reply

Your email address will not be published. Required fields are marked *

Share this Doc

SingHealth Case

Or copy link

CONTENTS

Antimanual

Ask our AI support assistant your questions about our platform, features, and services.

You are offline
Chatbot Avatar
What can I help you with?