Enterprise Security
Is Personal Data Protection Awareness Still Being Overlooked in Indonesian Healthcare?
Indonesia's healthcare sector is becoming increasingly digital, but protecting patient information requires more than regulations and security technology. It also requires awareness, responsible behavior, and a strong data protection culture.
Hospitals and healthcare providers manage some of the most sensitive personal information a person can share.
A single patient record may contain a full name, national identification number, home address, medical history, laboratory results, diagnostic information, prescription records, insurance details, payment information, and other information that can directly affect an individual's privacy and well-being.
As Indonesia's healthcare sector continues its digital transformation, more of this information is being collected, stored, processed, exchanged, and accessed electronically.
Electronic medical records, hospital information systems, online registration platforms, telemedicine services, mobile applications, laboratory systems, digital imaging platforms, and national health-data integration can improve the quality and efficiency of healthcare services.
However, digitalization also increases responsibility.
The central question is therefore not only whether healthcare organizations have implemented security technology.
It is also whether every person who interacts with patient information understands how to protect it.
A Question That Requires a Balanced Answer
The title of this article asks whether personal data protection awareness is still being overlooked in Indonesian healthcare.
The answer should not be simplified into a claim that all hospitals or healthcare workers lack awareness.
Indonesia has introduced an increasingly clear regulatory and digital-health framework. Many healthcare organizations are also improving their systems, internal policies, infrastructure, and security controls.
At the same time, awareness cannot be measured only by the existence of a policy, a security product, or a compliance document.
True awareness is reflected in everyday behavior:
- How employees handle patient documents.
- How user accounts and passwords are managed.
- Whether access is limited according to job responsibilities.
- How suspicious emails are identified and reported.
- How patient data is shared internally and externally.
- Whether incidents are reported quickly.
- Whether staff members understand why security procedures exist.
There is no single publicly available national dataset that comprehensively measures personal data protection awareness across every hospital and every healthcare worker in Indonesia.
For that reason, this article does not attempt to rank hospitals or estimate how many institutions are secure or insecure.
Instead, it examines the areas where awareness remains important as healthcare becomes more connected and data-driven.
Why Healthcare Data Requires Special Protection
Healthcare data is different from many other categories of information.
A compromised password can be reset.
A payment card can be blocked and replaced.
Medical history, genetic information, diagnostic results, or records of a person's previous treatment cannot simply be changed after exposure.
Healthcare information can also reveal highly personal aspects of an individual's life, including:
- Physical or mental health conditions.
- Medication and treatment history.
- Disability information.
- Pregnancy-related information.
- Genetic or biometric information.
- Insurance and financial details.
- Family and emergency-contact information.
Under Indonesia's Personal Data Protection Law, health information is included within specific personal data that requires appropriate protection.
This makes patient-data protection more than an operational IT concern. It is also connected to privacy, professional responsibility, public trust, and the rights of the individual whose data is being processed.
Digital Transformation Is Expanding the Data Environment
Healthcare services increasingly depend on interconnected technology.
A patient's information may move through several systems during a single episode of care:
Patient Registration
Hospital Information System
Electronic Medical Record
Doctor or Clinical Department
Laboratory and Pharmacy Systems
Billing and Insurance
National Health Data Integration
Each integration can improve efficiency and provide healthcare professionals with faster access to relevant information.
However, each connection also introduces questions:
- Who is allowed to access the data?
- How is the user's identity verified?
- Is the connection protected?
- Is sensitive information recorded in audit logs?
- Can excessive access be detected?
- How long is the data retained?
- How are third-party systems evaluated?
- What happens if an account or endpoint is compromised?
The security of a digital healthcare ecosystem is influenced by all of its components.
A well-protected database may still be exposed if credentials are shared, access privileges are excessive, sensitive exports are stored carelessly, or information is sent through an unauthorized communication channel.
Current Situation and Key Challenges
The following table presents a qualitative overview of important data-protection areas in Indonesian healthcare.
It does not represent a statistical ranking or claim that every healthcare organization has the same level of maturity.
| Aspect | Current Situation in Indonesia | Key Challenge |
|---|---|---|
| Personal data regulation | Indonesia has a national Personal Data Protection Law covering the rights of data subjects and responsibilities related to personal-data processing. Health information is treated as specific personal data. | Translating legal obligations into consistent operational procedures, technical controls, and measurable accountability across different organizations. |
| Electronic medical records | Healthcare digitalization and electronic medical records are part of the national healthcare transformation. Healthcare providers are increasingly expected to manage medical records electronically. | Ensuring that digital adoption is accompanied by adequate access control, authentication, encryption, monitoring, backup, and staff training. |
| National health-data integration | SATUSEHAT supports standardization and integration of health information across healthcare systems. | Securing interoperability, maintaining data quality, controlling system-to-system access, and ensuring that integration does not create unnecessary exposure. |
| Security awareness | Cybersecurity and privacy receive increasing attention within healthcare and other critical sectors. | Awareness levels may vary by organization, job role, location, available resources, and management commitment. Awareness must become continuous rather than limited to annual training. |
| Access control | Most digital healthcare platforms provide accounts, roles, or permission-management capabilities. | Preventing shared accounts, excessive privileges, inactive accounts, weak approval processes, and access that is not reviewed regularly. |
| Password and authentication practices | Organizations increasingly recognize the importance of stronger authentication and Multi-Factor Authentication. | Legacy applications, operational convenience, shared workstations, and resistance to workflow changes may limit consistent adoption. |
| Data sharing | Patient information must sometimes be exchanged between departments, laboratories, insurers, healthcare providers, and other authorized parties. | Avoiding unauthorized channels, uncontrolled spreadsheet exports, personal messaging applications, incorrect recipients, and insufficient data minimization. |
| Third-party systems | Healthcare organizations commonly depend on software vendors, cloud platforms, integration partners, laboratories, insurers, and managed-service providers. | Evaluating vendor security, defining contractual responsibilities, controlling external access, and responding to incidents involving third parties. |
| Legacy technology | New digital platforms may operate alongside older applications, operating systems, medical devices, or infrastructure. | Maintaining compatibility without allowing unsupported or unpatched systems to become permanent security weaknesses. |
| Medical and IoT devices | Connected medical equipment can improve monitoring and clinical workflows. | Device inventory, patching limitations, default credentials, network segmentation, manufacturer support, and visibility into abnormal device behavior. |
| Audit logging | Modern information systems can record login activity, access events, administrative actions, and data changes. | Ensuring logs are actually reviewed, protected from unauthorized modification, retained appropriately, and connected to a meaningful response process. |
| Incident response | Awareness of cybersecurity incidents is increasing, and organizations are developing response procedures. | Staff may not know what constitutes an incident, where to report it, or how quickly it must be escalated. Delayed reporting can increase impact. |
| Backup and recovery | Backup remains an important part of healthcare availability and business continuity. | Ensuring backups are isolated, protected, tested, monitored, and capable of supporting recovery from ransomware or destructive incidents. |
| Data retention and disposal | Medical information may need to be retained according to legal, clinical, and operational requirements. | Preventing indefinite retention without purpose and ensuring secure deletion or destruction of electronic files, printed documents, storage devices, and backups. |
| Physical documents | Paper forms, printed medical records, labels, prescriptions, and administrative documents continue to exist alongside digital systems. | Preventing documents from being left unattended, photographed, discarded improperly, or accessed by unauthorized individuals. |
| Workforce training | Many organizations conduct induction sessions, policy briefings, or cybersecurity awareness programs. | Training may become a checklist exercise unless it is role-based, practical, recurring, measured, and supported by leadership. |
| Patient transparency | Patients are increasingly aware that healthcare providers collect and process their personal information. | Communicating clearly about data use, access, correction, retention, sharing, and incident handling in language that patients can understand. |
| Governance and accountability | Data protection increasingly involves legal, compliance, IT, security, risk, clinical, operational, and management stakeholders. | Avoiding fragmented responsibility and ensuring there is clear ownership for decisions, risks, controls, and incident escalation. |
Regulation Does Not Automatically Create Awareness
Regulation provides an important foundation.
It establishes expectations, obligations, responsibilities, and rights.
However, publishing a policy or asking employees to sign a confidentiality statement does not automatically mean that security awareness has become part of organizational culture.
An employee may know that patient information is confidential but still:
- Share an account because it is faster.
- Leave an unlocked workstation unattended.
- Copy a patient file to a personal device.
- Send information through a personal chat account.
- Click a convincing phishing link.
- Photograph a screen containing patient information.
- Dispose of printed documents in a general waste bin.
- Ignore unusual system activity because reporting feels complicated.
These actions are not always motivated by malicious intent.
They may result from workload pressure, unclear procedures, inadequate tools, insufficient training, or systems that do not match operational reality.
This is why awareness programs should not focus only on telling employees what they must not do.
Organizations should also understand why unsafe workarounds appear and improve the process that encourages them.
Technology Alone Cannot Eliminate Human Risk
Healthcare organizations may invest in:
- Firewalls.
- Endpoint security.
- Email protection.
- Encryption.
- Identity and Access Management.
- Multi-Factor Authentication.
- Data Loss Prevention.
- Security monitoring.
- Backup and recovery.
- Vulnerability management.
These controls are important, but none of them completely removes the need for human judgment.
| Security Control | What It Helps Protect | Why Awareness Is Still Required |
|---|---|---|
| Encryption | Protects data from being read without the appropriate key or authorization. | Authorized users can still expose decrypted information through screenshots, exports, email, printing, or incorrect sharing. |
| Multi-Factor Authentication | Reduces the risk of account compromise when a password is stolen. | Users must still recognize fraudulent approval requests, phishing attempts, and suspicious login activity. |
| Access control | Limits information according to roles and permissions. | Managers must approve access carefully, and users must not share accounts or use privileges beyond their responsibilities. |
| Firewall | Controls network communication based on defined rules. | Unsafe behavior can still occur through permitted applications, stolen accounts, social engineering, or internal misuse. |
| Endpoint protection | Detects or blocks many malicious files and behaviors. | Users must still avoid unauthorized software, suspicious downloads, and attempts to bypass security controls. |
| Audit logging | Records actions that may support monitoring and investigation. | Someone must review meaningful events, identify anomalies, and respond to warning signs. |
| Backup | Supports recovery from data loss or system disruption. | Backups must be tested, protected, and included in a documented recovery process. |
| Data Loss Prevention | Identifies or restricts certain transfers of sensitive information. | Data must be classified correctly, and users must understand acceptable sharing practices. |
Awareness Must Include More Than Phishing
Security-awareness programs are often associated primarily with phishing emails.
Phishing is important, but healthcare data protection involves a wider range of behaviors.
A comprehensive awareness program should cover:
Patient confidentiality
Employees should understand that curiosity is not a valid reason to access a record.
The ability to view information does not automatically create a legitimate business or clinical need.
Safe communication
Staff members should know which channels are approved for sharing patient information and how to verify recipients before sending sensitive data.
Account security
Users should understand why shared credentials, predictable passwords, and approval of unexpected MFA requests create risk.
Physical information handling
Printed records, patient labels, prescriptions, appointment lists, and handwritten notes should not be treated as harmless because they are not digital.
Incident reporting
Employees need a simple and well-understood method to report:
- Suspicious emails.
- Lost devices.
- Incorrectly shared documents.
- Unexpected login notifications.
- Malware warnings.
- Unusual system behavior.
- Suspected unauthorized access.
Social engineering
Attackers may impersonate patients, doctors, executives, IT personnel, vendors, regulators, or insurance representatives.
Verification procedures should be part of normal operations.
Privacy during daily work
Screens, conversations, documents, and printed materials should not expose patient information to visitors or unauthorized personnel.
Different Roles Face Different Risks
A single generic training presentation is unlikely to address every healthcare role effectively.
| Role | Example Data-Protection Risk | Recommended Awareness Focus |
|---|---|---|
| Doctors and nurses | Accessing records from shared workstations or discussing patient information in open areas. | Secure workstation use, appropriate record access, confidentiality, and safe communication. |
| Registration staff | Collecting identification documents and demographic information. | Identity verification, document handling, consent, minimum necessary collection, and secure scanning. |
| Laboratory personnel | Processing test results and exchanging information with other departments. | Recipient verification, access restrictions, secure integration, and handling of printed results. |
| Pharmacy staff | Accessing prescriptions and medication history. | Confidentiality, correct patient verification, and prevention of unauthorized disclosure. |
| Finance and insurance staff | Processing billing, claims, identity, and payment information. | Secure file transfer, fraud awareness, email verification, and restricted access. |
| IT administrators | Holding privileged access to systems and infrastructure. | Privileged-access management, logging, change control, backup protection, and separation of duties. |
| Vendors and contractors | Receiving temporary or remote access to systems. | Time-limited access, contractual responsibilities, monitoring, approval, and account removal. |
| Executives and management | Receiving sensitive reports and approving organizational priorities. | Governance, incident decision-making, business risk, accountability, and investment in security culture. |
Role-based training makes security guidance more relevant because it connects protection requirements to actual daily work.
What a Strong Data Protection Culture Looks Like
A mature data-protection culture does not mean that incidents never occur.
It means that the organization is prepared to prevent, detect, report, contain, learn from, and respond to them.
Indicators of a healthy culture may include:
- Employees feel safe reporting mistakes quickly.
- Security policies reflect real operational workflows.
- Access is granted based on documented responsibilities.
- User access is reviewed regularly.
- Security training uses healthcare-relevant scenarios.
- Management participates in awareness initiatives.
- Incidents and near-misses are used as learning opportunities.
- Third-party access is monitored and removed when no longer required.
- Patient information is not collected or retained without a valid purpose.
- Security teams cooperate with clinical, legal, compliance, and operational teams.
- Security is considered during system design rather than added only after deployment.
The goal should not be to create fear.
Employees who fear punishment may hide mistakes, increasing the potential impact of an incident.
A stronger approach combines accountability with a clear and supportive reporting process.
Practical Actions Healthcare Organizations Can Take
1. Establish clear ownership
Define who is accountable for:
- Personal-data governance.
- Security operations.
- Privacy inquiries.
- Access approval.
- Vendor risk.
- Incident escalation.
- Regulatory communication.
- Patient notification where required.
Responsibility should not be assumed to belong only to the IT department.
2. Classify information
Identify which information is:
- Public.
- Internal.
- Confidential.
- Highly sensitive.
- Subject to legal or clinical retention requirements.
Classification helps determine suitable access, storage, transmission, and disposal controls.
3. Apply least privilege
Employees should receive only the access required for their responsibilities.
Access should be updated when an employee changes roles and removed promptly when employment or contracts end.
4. Strengthen authentication
Use stronger authentication for remote access, privileged administration, cloud services, and systems containing sensitive information.
Shared accounts should be minimized or eliminated wherever technically possible.
5. Conduct role-based training
Training should use practical examples relevant to clinical, administrative, technical, and management roles.
Short and recurring sessions may be more effective than a single long annual presentation.
6. Make incident reporting simple
Employees should know:
- What to report.
- How to report it.
- Who receives the report.
- What immediate action they should take.
- Why fast reporting matters.
7. Test organizational readiness
Exercises can include:
- Phishing simulations.
- Lost-device scenarios.
- Ransomware tabletop exercises.
- Incorrect-recipient email scenarios.
- Third-party compromise scenarios.
- System outage and recovery drills.
8. Review third-party access
Vendors should receive only the access required for a defined purpose and period.
Remote access should be approved, authenticated, logged, monitored, and disabled when no longer required.
9. Protect the complete data lifecycle
Collect
Use
Store
Access
Share
Archive
Dispose Securely
Security controls should apply at every stage.
10. Measure improvement
Awareness programs should be measured using more than course-completion rates.
Possible indicators include:
- Phishing reporting rate.
- Time required to report incidents.
- Number of shared accounts removed.
- Access-review completion.
- Percentage of inactive accounts disabled.
- Number of unauthorized data-sharing events.
- Recovery-test success rate.
- Completion of third-party access reviews.
- Reduction in repeated policy violations.
- Employee understanding measured through practical scenarios.
Metrics should be used to identify opportunities for improvement, not merely to create a favorable dashboard.
What Healthcare Professionals Can Do
Individual behavior remains an important layer of protection.
Healthcare professionals can help protect patient information by consistently following several basic principles:
- Use only their own authorized account.
- Never share passwords or authentication codes.
- Lock workstations before leaving them.
- Verify recipients before sending sensitive information.
- Use approved communication and storage platforms.
- Avoid storing patient information on personal devices.
- Report suspicious emails or login activity.
- Avoid discussing patient information in public areas.
- Collect only the information required for a valid purpose.
- Follow procedures for printing, storing, transporting, and destroying documents.
- Report mistakes immediately rather than attempting to hide them.
- Ask for guidance when procedures are unclear.
Security awareness is not demonstrated by memorizing policy language.
It is demonstrated through repeated decisions made during everyday work.
Patient Trust Is Part of Healthcare Quality
Healthcare quality is often discussed in terms of clinical outcomes, safety, accessibility, efficiency, and patient experience.
Information protection should also be considered part of healthcare quality.
Patients provide information because they expect healthcare professionals to use it responsibly.
A data breach or inappropriate disclosure can create consequences beyond financial loss.
It may cause:
- Embarrassment.
- Discrimination.
- Psychological distress.
- Identity misuse.
- Loss of confidence.
- Reluctance to seek treatment.
- Damage to the relationship between patients and healthcare providers.
Trust can take years to build and only a moment to damage.
Protecting patient information is therefore not merely a technical obligation. It is part of respecting the individual behind the data.
So, Is Awareness Still Being Overlooked?
It would be unfair and inaccurate to claim that every Indonesian healthcare organization overlooks data protection.
Progress is visible in regulation, digital-health policy, electronic medical records, interoperability initiatives, and growing attention to cybersecurity.
However, awareness must keep pace with the speed of digital transformation.
A healthcare organization can have modern infrastructure and still face significant exposure if security responsibilities are unclear, training is treated as a formality, users rely on unsafe workarounds, or incidents are not reported promptly.
The more healthcare becomes digital and interconnected, the more important human awareness becomes.
The correct conclusion is therefore not that technology has failed or that healthcare workers cannot be trusted.
It is that effective data protection requires three elements to work together:
People
+
Process
+
Technology
=
Sustainable Data Protection
Removing any one of these elements weakens the overall protection model.
Final Thoughts
Personal data protection in healthcare is not a one-time project.
It is an ongoing responsibility that must evolve with new systems, new integrations, new threats, and new ways of delivering healthcare.
Regulations provide direction.
Technology provides protection capabilities.
Policies define expectations.
But awareness connects all of them to everyday behavior.
Every individual who accesses patient information becomes part of the healthcare organization's security posture.
Protecting patient data is ultimately about more than preventing an incident.
It is about preserving dignity, confidentiality, safety, and trust.
Disclaimer
This article reflects the author's personal views and observations regarding cybersecurity awareness and personal data protection in healthcare.
It is intended solely for educational and professional discussion purposes.
This article does not assess, rank, criticize, or represent any specific hospital, healthcare organization, government institution, employee, technology provider, or other entity.
The discussion of healthcare practices is general and should not be interpreted as a statement regarding the compliance, security maturity, or operational condition of any particular organization.
The qualitative table in this article is not based on a nationwide statistical survey and should not be used to estimate the number or percentage of Indonesian healthcare organizations that have or have not implemented specific security measures.
This article does not constitute legal, regulatory, medical, or professional consulting advice. Organizations should consult qualified legal, privacy, security, and healthcare-governance professionals when determining their specific responsibilities.
References
- Republic of Indonesia, Law Number 27 of 2022 concerning Personal Data Protection.
- Ministry of Health of the Republic of Indonesia, Regulation Number 24 of 2022 concerning Medical Records.
- Ministry of Health of the Republic of Indonesia, SATUSEHAT Platform documentation and interoperability guidance.
- Ministry of Health of the Republic of Indonesia, SATUSEHAT health-data integration and monitoring resources.
Created on April 17, 2026.
Written by Jason Sariwating.