Electronic Medical Record Breaches and Hospital Liability: Protecting Patients' Privacy under Indonesian Health and Data Protection Law

Authors

  • Siska Ayudevi Universitas Negeri Surabaya Author

DOI:

https://doi.org/10.65815/hvzwtk22

Keywords:

Electronic medical records, data breach, hospital liability, patient privacy, data protection

Abstract

The digitalization of healthcare has transformed the management and exchange of patient information through electronic medical records (EMRs). While EMRs enhance continuity and efficiency of care, they also expose highly sensitive health information to cybersecurity threats and unauthorized disclosure. This article examines the legal responsibility of hospitals when electronic medical records are leaked, accessed without authorization, or otherwise compromised. The study employs normative legal research by examining Indonesian health legislation, personal data protection regulations, and principles governing the confidentiality of medical information. Particular attention is given to the relationship between hospitals' obligations as healthcare providers and their responsibilities as entities processing sensitive personal data. The analysis finds that the existing regulatory framework establishes multiple obligations concerning confidentiality, data security, and patient rights, but the distribution of responsibility between hospitals, healthcare professionals, technology providers, and other data processors remains insufficiently articulated. This fragmented framework may create uncertainty regarding remedies and accountability following a data breach. The article argues that hospital liability should be assessed through a risk-based framework emphasizing preventive security measures, organizational control, breach notification, and effective remedies for affected patients. Strengthening institutional accountability is essential to ensure that digital healthcare development remains consistent with the fundamental right to privacy and the broader principle of health justice.

Downloads

Download data is not yet available.

References

Abouelmehdi, Karim, Abderrahim Beni-Hessane, and Hayet Khaloufi. 2018. “Big Healthcare Data: Preserving Security and Privacy.” Journal of Big Data 5: 1–18. https://doi.org/10.1186/s40537-018-0110-7.

Al-Issa, Yara, Mustafa A. Ottom, and Ahmed Tamrawi. 2019. “eHealth Cloud Security Challenges: A Survey.” Journal of Healthcare Engineering 2019: 1–15. https://doi.org/10.1155/2019/7516035.

Argaw, Seleshi T. et al. 2020. “Cybersecurity of Hospitals: A Systematic, Organizational Perspective.” BMC Medical Informatics and Decision Making 20.

Cohen, I. Glenn, et al. 2020. “Doctors Routinely Share Health Data Electronically under HIPAA, and Sharing with Patients and Patients’ Third-Party Health Apps Is Consistent: Interoperability and Privacy Analysis.” Journal of Medical Internet Research 22 (9): e19818.

Coventry, Lynne, and Yvonne Branley. 2018. “Cybersecurity in Healthcare: A Narrative Review of Trends, Threats and Ways Forward.” Maturitas 113: 48–52.

De Simone, Donna M. 2019. “When Is Accessing Medical Records a HIPAA Breach?” Journal of Nursing Regulation 10 (3): 34. https://doi.org/10.1016/S2155-8256(19)30146-2.

Gariépy-Saper, Katherine, and Nicholas Decarie. 2021. “Privacy of Electronic Health Records: A Review of the Literature.” Journal of the Canadian Health Libraries Association 42 (1). https://doi.org/10.29173/jchla29496.

Indonesia. 2022. Law Number 27 of 2022 concerning Personal Data Protection. State Gazette of the Republic of Indonesia 2022, No. 196.

Indonesia. 2022. Regulation of the Minister of Health Number 24 of 2022 concerning Medical Records.

Indonesia. 2023. Law Number 17 of 2023 concerning Health. State Gazette of the Republic of Indonesia 2023, No. 105.

Indonesia. 2024. Government Regulation Number 28 of 2024 concerning Implementing Regulations of Law Number 17 of 2023 concerning Health. State Gazette of the Republic of Indonesia 2024, No. 135.

Keshta, Ismail, and Alaa Odeh. 2019. “Security and Privacy of Electronic Health Records: Concerns and Challenges.” Egyptian Informatics Journal 22 (2): 177–183. https://doi.org/10.1016/j.eij.2020.07.003.

Kruse, Clemens Scott, R. S. Frederick, T. Jacobson, and D. Monticone. 2017. “Cybersecurity in Healthcare: A Systematic Review of Modern Threats and Trends.” Technology and Health Care 25 (1): 1–10.

Li, Jinhong, et al. 2023. “Assessing the Impact of Health Information Exchange on Hospital Data Breach Risk.” International Journal of Medical Informatics 177: 105149. https://doi.org/10.1016/j.ijmedinf.2023.105149.

Oh, Se-Ra, Young-Duk Seo, Euijong Lee, and Young-Gab Kim. 2021. “A Comprehensive Survey on Security and Privacy for Electronic Health Data.” International Journal of Environmental Research and Public Health 18 (18): 9668. https://doi.org/10.3390/ijerph18189668.

Piasecki, Jan, Ewa Walkiewicz-Żarek, Justyna Figas-Skrzypulec, Anna Kordecka, and Vilius Dranseika. 2021. “Ethical Issues in Biomedical Research Using Electronic Health Records: A Systematic Review.” Medicine, Health Care and Philosophy 24: 633–658.

Snyder, et al. 2022. “Human Factors in Electronic Health Records Cybersecurity Breach: An Exploratory Analysis.” Journal of Medical Internet Research.

World Health Organization. 2021. Ethics and Governance of Artificial Intelligence for Health: WHO Guidance. Geneva: World Health Organization.

Downloads

Published

2026-03-25

Issue

Section

Articles

How to Cite

Electronic Medical Record Breaches and Hospital Liability: Protecting Patients’ Privacy under Indonesian Health and Data Protection Law. (2026). Indonesian Health Justice Review, 3(1), 27-52. https://doi.org/10.65815/hvzwtk22