Permenkes 24/2022 Kemenkes | Every health facility — hospital, puskesmas, clinic, pharmacy, laboratory and telemedicine provider — must operate electronic medical records, compatible and interoperable with the SATUSEHAT platform. | Assess the RME estate and its integrations as one system, including the provider you depend on, and rebuild the downtime procedure the electronic record replaced. | Integration risk register, tested downtime procedure |
UU PDP Republik Indonesia | Health data is specific personal data, requiring a stronger lawful basis, tighter access control, and breach notification within 72 hours. | Access model built around clinical roles rather than IT convenience, and a notification runbook that survives contact with a hospital's own governance. | DPIA, role-based access model, runbook |
PSE registration Komdigi | Electronic system providers operating in Indonesia must be registered — including the RME vendor a facility relies on. | Supplier assessment that checks registration and integration status rather than accepting a sales assurance. | Supplier assurance file |
IEC 80001-1 Guidance | Risk management for IT networks incorporating medical devices — the reference for handling equipment that cannot simply be patched. | Segmentation and compensating controls for devices where the answer is genuinely not to touch the device, agreed with biomedical engineering. | Device zone model, compensating controls |
ISO 27001 Certifiable | Information security management system across the organisation, increasingly asked for in accreditation and payer contracting. | Implementation scoped so clinical systems are inside it rather than carved out to make certification simpler. | Certifiable ISMS with clinical systems in scope |