Home/ Courses/ ISC2/ HCISPP
ISC2 Authorised Intermediate · Healthcare 2026 ECO Healthcare-Specialised

HCISPP
Healthcare Info Security & Privacy

ISC2's healthcare-specific security and privacy credential. The cert for security and privacy professionals in MY's hospitals, health insurance, telemedicine and digital-health startups — mapped to MOH PDPA, HL7 FHIR and HIPAA.

Duration: 4 days / 32 hrs
💻Format: Instructor-Led + Healthcare Sims
🌐Delivery: On-site · Virtual · Hybrid
Pass rate: 92%
📅Next intake: 9 Jun 2026
HCISPP training session at Nexperts Academy
🩺

Healthcare data flow

HL7 FHIR, EMR / EHR, HIE, claims data, telemedicine streams

📋

Healthcare regulation

MY MOH PDPA, HIPAA, GDPR Art. 9 (special-category data)

🔐

Privacy + security controls

Consent, de-identification, breach response, BAAs

📊

Risk + governance

Healthcare-specific risk, third-party risk, MA-eclipse + telemed

What this course is

Where healthcare data stops
being just personal data.

HCISPP is ISC2's healthcare-specific security and privacy credential. It is the cert for security and privacy professionals working in MY's hospitals, health insurance, telemedicine, hospital networks and digital-health startups — organisations bound by both PDPA and the special-category-data treatment of medical information.

At Nexperts, HCISPP is delivered as a 4-day intensive that walks the seven exam domains in real-world MY healthcare scenarios — KPJ Healthcare, IHH, MOH hospitals, BookDoc, DoctorOnCall, and digital-health players. By day 4 you've designed privacy controls for an EMR, run a hospital breach simulation and defended a third-party-risk programme.

MY's healthcare digitisation — telemedicine, MyHEALTH, MySejahtera — has created a real demand for privacy-and-security professionals who understand healthcare data specifically. HCISPP is the only cert that signals this dual literacy.

HCISPP is the most healthcare-specific cert in the global landscape. We map every conversation to MY's MOH-PDPA hospital framework, the GLC-hospital procurement guidelines and the digital-health regulatory environment in ASEAN.

Who should take this course
🩺

Hospital IT / security leads

Owning EMR security and PDPA at hospitals and group networks.

🔐

DPOs in healthcare

Owning data protection at health insurers, hospital networks, MyHEALTH.

👨‍⚕️

Digital-health startups

BookDoc, DoctorOnCall, Naluri, Klinik MyKad. Privacy is a moat.

📚

Health-insurance compliance

Allianz, AIA, Etiqa health-insurance teams. Claims data + privacy.

📈

Pharma compliance

Pharma data (clinical trials, real-world evidence). HCISPP is recognised.

📜

Healthcare auditors

CISA holders moving into healthcare-specific risk and compliance.

Prerequisites
2 years of cumulative paid work experience
Experience must be in 1 of the 7 HCISPP domains
1 of the 2 years must be in healthcare-related work
ISC2 endorsement required after exam pass
Don't yet meet experience? Pass the exam to become an ISC2 Associate; full cert grants when experience is met.