ZENTARA

Industries · Healthcare

An outage here is a clinical event.

Since January 2024 every fasyankes in Indonesia has been required to run electronic medical records, interoperable with SATUSEHAT. Care that used to survive a system failure on paper no longer can. Zentara works with hospitals and clinics on the question a director actually asks — not whether the data is safe, but whether patients can still be treated at 3am when it is not.

1 Jan 2024
Electronic medical records became mandatory
Permenkes 24/2022 — every fasyankes, including telemedicine
SATUSEHAT
Interoperability is part of the obligation
Kemenkes health data integration platform
Specific
Health data is a protected category
UU PDP — a stronger basis than ordinary personal data
72 hrs
To notify a personal data breach
UU PDP

What we are defending

Where an IT decision becomes a clinical one.

01

RME and SATUSEHAT

The record and its integration. Your obligation does not stop at your own system — your RME provider must be officially integrated and registered, and their exposure is now yours.

02

Biomedical devices

Infusion pumps, monitors, analysers. Vendor-certified, frequently unpatchable, and on the same network as everything else because that is how they were installed.

03

Imaging and PACS

Large, old, and quietly reachable. Imaging archives are among the most consistently exposed systems we find in a hospital estate.

04

The ward at 3am

Downtime procedure is not an IT artefact. It is whether the nurse on shift can safely administer without the system, and whether anyone has practised it.

05

Pharmacy and supply

Dispensing, stock and cold chain. An outage here is a patient safety issue within hours rather than days.

06

Shared clinical workstations

Fast user switching, badge access, session timeouts that clinicians will defeat if the timeout is set by someone who has never run a clinic.

Instrument · Obligation · Clinical outcome

The record went electronic. The fallback did not get rebuilt.

Permenkes 24/2022 made electronic records compulsory and SATUSEHAT interoperability part of the deal. Both are the right direction. Both also removed the paper process that used to absorb a system failure, and very few facilities replaced it with a rehearsed one.

Permenkes 24/2022

Kemenkes

Requires

Every health facility — hospital, puskesmas, clinic, pharmacy, laboratory and telemedicine provider — must operate electronic medical records, compatible and interoperable with the SATUSEHAT platform.

We do

Assess the RME estate and its integrations as one system, including the provider you depend on, and rebuild the downtime procedure the electronic record replaced.

What the facility ends up with

Integration risk register, tested downtime procedure

UU PDP

Republik Indonesia

Requires

Health data is specific personal data, requiring a stronger lawful basis, tighter access control, and breach notification within 72 hours.

We do

Access model built around clinical roles rather than IT convenience, and a notification runbook that survives contact with a hospital's own governance.

What the facility ends up with

DPIA, role-based access model, runbook

PSE registration

Komdigi

Requires

Electronic system providers operating in Indonesia must be registered — including the RME vendor a facility relies on.

We do

Supplier assessment that checks registration and integration status rather than accepting a sales assurance.

What the facility ends up with

Supplier assurance file

IEC 80001-1

Guidance

Requires

Risk management for IT networks incorporating medical devices — the reference for handling equipment that cannot simply be patched.

We do

Segmentation and compensating controls for devices where the answer is genuinely not to touch the device, agreed with biomedical engineering.

What the facility ends up with

Device zone model, compensating controls

ISO 27001

Certifiable

Requires

Information security management system across the organisation, increasingly asked for in accreditation and payer contracting.

We do

Implementation scoped so clinical systems are inside it rather than carved out to make certification simpler.

What the facility ends up with

Certifiable ISMS with clinical systems in scope

Downtime · The only question at 3am

Can you still treat patients?

Every other question in healthcare security is downstream of this one. Before 2024 the answer was usually yes — the ward reverted to paper, because paper was still how half the process worked. Mandatory electronic records removed that cushion without anyone deliberately deciding to, and most facilities have not rebuilt it. This is not an argument against RME, which is plainly the right direction. It is an argument that the downtime procedure is now a clinical control and needs to be drilled like one.

Clinical downtime capability

  1. 1

    Improvised

    No downtime procedure. Staff work it out on the night, differently on each ward.

  2. 2

    Written

    A procedure exists in a folder. Nobody on the current roster has used it.

  3. 3

    Drilled

    Practised on one ward, on a quiet day, by staff who knew it was coming.

  4. 4

    Sustained

    Care deliverable for days, across departments, with reconciliation back into the record planned.

  5. 5

    Exercised whole

    Full-facility exercise including reconciliation, with clinical leadership present and findings acted on.

Highlighted: where a facility has to be before it can say care continues through an outage.

Framing derived from Permenkes 24/2022 and clinical continuity practice

Sector threat model

  • Ransomware against clinical systems, where the fallback is a paper process nobody under thirty has used
  • Patient records exfiltrated — a category of data that cannot be reissued the way a card number can
  • Biomedical devices running vendor-locked software that may not be patched without voiding certification
  • SATUSEHAT and RME integrations widening the blast radius of a single supplier
  • Referral and telemedicine paths that reach outside the hospital perimeter by design
  • Credential sharing on shared clinical workstations, because the alternative slows a ward round

What this sector answers to

The regulatory landscape for healthcare. Our own accreditations are listed on certifications.

Permenkes 24/2022SATUSEHAT interoperabilityUU PDPPSE registrationIEC 80001-1 — guidanceISO 27001

Track record

Penetration testing delivered for global pharmaceutical companies.

For puskesmas, clinics and small facilities

The same obligation, one person, no budget line.

Permenkes 24/2022 does not scale its requirements to the size of the facility. A puskesmas carries the RME obligation, the SATUSEHAT integration and the UU PDP duty with an IT function that is frequently one person doing it alongside another job. Pretending that is a smaller version of a hospital problem is why the gap persists.

  • Downtime procedure first — for a facility with one administrator, a rehearsed paper fallback is worth more than any tool.
  • Supplier assessment shared across facilities using the same RME provider, because the exposure is the same exposure.
  • Practical access control that clinicians will actually use, rather than a policy that gets defeated by the second week.
  • Training that leaves someone on staff able to answer a UU PDP question without calling a consultant.

Before you have to justify us internally

Bringing in a security vendor is itself a risk you have to evidence.

So here is the answer to the questions your risk committee will ask, before they ask them.

Nothing active in a clinical environment without clinical sign-off

Testing that touches a system in use is scoped with the clinical lead, not only with IT, and stops when they say stop. A finding is never worth a patient safety incident.

Patient data does not leave the facility

We work on site, on your systems, and take no clinical data away. Where we need evidence for a report it is redacted before it leaves the room.

We will not tell you to patch a certified device

Where a device cannot be changed without voiding certification, the answer is segmentation and compensating control, agreed with biomedical engineering — not a finding that nobody can action.

Written for a director, not only a CISO

Many facilities have no CISO. Reports are written so a hospital director and a head of nursing can act on them without translation.

We work around clinical hours

Assessment scheduled around theatre lists and ward rounds. Convenience for us is not a reason to interrupt care.

No case studies, no named facilities

Healthcare reputational harm attaches to the institution and lands on its patients. Nothing about an engagement is published, ever.

VAPT & Offensive Security

Penetration testing for Healthcare

27 services in the catalog apply to Healthcare — from point-in-time pentests to red team and continuous validation.

Explore all 27
Penetration Test

External Network Penetration Test

Black-box test of internet-facing assets, perimeter exposure, and exploitable services.

Penetration Test

Internal Network Penetration Test

Assumed-breach lateral movement, AD abuse, sensitive data discovery from inside.

Penetration Test

Network Segmentation Validation

Verifies VLAN/firewall isolation between zones (CDE, OT, corporate).

Penetration Test

Active Directory / Entra ID Security Assessment

Kerberoasting, AS-REP, ACL abuse, BloodHound paths, hybrid identity review.

Assessment

Firewall, Router & Switch Configuration Review

Rule base hygiene, ACL drift, hardening against CIS Benchmarks.

Penetration Test

VPN Security Assessment

IKE/IPsec, SSL VPN, split tunneling, ZTNA migration readiness.

Assessment

Email & DNS Security Review

SPF/DKIM/DMARC, MTA-STS, DNSSEC, BIMI, phishing surface.

Penetration Test

Web Application Penetration Test

OWASP Top 10, business logic, authenticated/unauthenticated flows.

Securing healthcare?

Start with a scored maturity baseline or go straight to a specialist conversation.