Hospital Legal Responsibilities for Misuse of Patient Personal Data In Electronic Medical Records

Authors

  • Dian Ayu Lukitasari Universitas Hang Tuah Surabaya
  • Mohammad Zamroni Universitas Hang Tuah Surabaya
  • Andika Persada Putera Universitas Hang Tuah Surabaya

DOI:

https://doi.org/10.56371/jirpl.v5i1.164

Keywords:

electronic medical record, hospital, personal data

Abstract

The purpose of this study was to analyze the patient's personal data protection law in the electronic medical record and to analyze the legal responsibility of the hospital for the misuse of patient's personal data in the electronic medical record. This research uses normative research methods and uses statutory and conceptual approaches. The issuance of Regulation of the Minister of Health Number 24 of 2022 concerning Medical Records which requires hospitals to maintain electronic medical records no later than December 31, 2022. The transition from conventional medical records to electronic medical records carries the risk of misusing patient personal data. The results of this study conclude that hospitals as personal data controllers and electronic system operators are required to implement Law Number 27 of 2022 concerning Protection of Personal Data in organizing electronic medical records except those specifically regulated by other laws and regulations and hospitals as corporations have legal responsibilities for misuse of patient personal data in electronic medical records, namely administrative liability, civil liability and criminal liability.  

 

Downloads

Download data is not yet available.

References

Legislation

Civil Code (KUHPerdata), Burgerlijk Wetboek Indonesia Staatsblad 1847 Number 23. Translated by R. Subekti and R. Tjitrosudibio, Cet.41, Balai Pustaka, Jakarta, 2014.

Criminal Code (KUHP), Translated by Moeljatno. Bumi Aksara, Jakarta, 2021.

Law Number 8 of 1999 concerning Consumer Protection. State Gazette of 1999 Number 22. Supplement to State Gazette Number 3821.

Law Number 39 of 1999 concerning Human Rights. State Gazette of 1999 Number 165. Supplement to State Gazette Number 3886.

Law Number 29 of 2004 concerning Medical Practice. 2004 State Gazette Number 166. Supplement to State Gazette Number 4431.

Law Number 11 of 2008 concerning Information and Electronic Transactions. State Gazette of the Republic of Indonesia 2008 Number 58. Supplement to State Gazette of the Republic of Indonesia Number 4843.

Law Number 35 of 2009 concerning Narcotics. State Gazette of the Republic of Indonesia 2009 Number 143. Supplement to State Gazette of the Republic of Indonesia Number 5062.

Law Number 18 of 2014 concerning Mental Health. 2014 State Gazette Number 185. Supplement to State Gazette Number 5571.

Law Number 36 of 2009 concerning Health. 2009 State Gazette Number 128. Supplement to State Gazette Number 6236.

Law Number 44 of 2009 concerning Hospitals, State Gazette of the Republic of Indonesia of 2009 Number 153. Supplement to State Gazette of the Republic of Indonesia Number 5072.

Law Number 24 of 2013 concerning Amendments to Law Number 23 of 2006 concerning Population Administration. State Gazette of the Republic of Indonesia 2013 Number 232. Supplement to State Gazette of the Republic of Indonesia Number 5475.

Law Number 38 of 2014 concerning Nursing, State Gazette of the Republic of Indonesia of 2014 Number 307. Supplement to State Gazette of the Republic of Indonesia Number 5612.

Law Number 19 of 2016 concerning Amendments to Law Number 11 of 2008 concerning Information and Electronic Transactions. State Gazette of the Republic of Indonesia 2016 Number 251. Supplement to State Gazette of the Republic of Indonesia Number 5952.

Law Number 27 of 2022 concerning Personal Data Protection. State Gazette of the Republic of Indonesia for 2022 Number 196, Supplement to State Gazette of the Republic of Indonesia Number 6820.

Government Regulation Number 40 of 2019 concerning Implementation of Law Number 23 of 2006 concerning Population Administration as amended in Law Number 24 of 2013 concerning Amendments to Law Number 23 of 2006 concerning Population Administration. State Gazette of the Republic of Indonesia 2019 Number 102. Supplement to State Gazette of the Republic of Indonesia Number 6354.

Regulation of the Minister of Communication and Information of the Republic of Indonesia Number 20 of 2016 concerning Protection of Personal Data in Electronic Systems. State Gazette of the Republic of Indonesia Number 1829.

Regulation of the Minister of Health of the Republic of Indonesia Number 4 of 2018 concerning Hospital Obligations and Patient Obligations. State Gazette of the Republic of Indonesia Number 416.

Minister of Communication and Information Technology Regulation Number 5 of 2020 concerning Implementation of Private Scope Electronic Systems. State Gazette of the Republic of Indonesia 2020 Number 1376.

Regulation of the Minister of Health of the Republic of Indonesia Number 24 of 2022 concerning Medical Records. State Gazette of the Republic of Indonesia Number 829.

Decree of the Minister of Health, Number HK.01.07/MENKES/1423/2022 concerning Guidelines for Variables and Meta Data in the Implementation of Electronic Medical Records.

Book

Abdul Kadir Muhamad, Indonesian Company Law, First Edition, Citra Aditya Bakti, Bandung, 2010.

Indriyatno, Privacy and Personal Data Protection, Banyumurti.net, Jakarta, 2018.

Johny Ibrahim, Theory and Methodology of Normative Legal Research, Bayumedia, Malang, 2006.

Moeljatno, Principles of Criminal Law, Sixth Edition, PT. Rineke Cipta, Jakarta, 2000.

Moeljatno, Criminal Acts and Responsibility in Criminal Law, Rinneka Cipta, Jakarta, 1993.

M. Zamroni, Health Law: Liability of Doctors and Hospitals in the Practice of Medical Services, Scopindo Media Pustaka, Surabaya, 2022.

Nasution, Bahder Johan, Health Law: Doctors' Liability. Rineka Cipta, Jakarta, 2013

Peter Mahmud Marzuki, Introduction to Legal Studies, Kencana, Jakarta, 2008.

Rasyid Ariman & Fahmi Raghib, Criminal Law, Second printing, Setara Press, Malang, 2016.

Rizky PP Karo Karo, Teguh Prasetyo, Personal Data Protection Regulations in Indonesia Perspective of the Theory of Dignified Justice, Nusa Medika, Bandung, 2020.

Soekidjo Notoadmojo, Health Ethics and Law, First Edition, Rineke Cipta, Jakarta, 2010.

Titik Triwulan and Shinta Febrian, Legal Protection for Patients, Second Printing, Achievement Pustaka, Jakarta, 2010.

Thesis

Bagus Satryo Ramadha, Ability of Criminal Law Against Cyber Related to Personal Data Protection in Indonesia, Thesis, Master of Law, Islamic University of Indonesia. 2021.

Sri Lestari, The Role of Electronic Medical Records as Evidence of Therapeutic Transactions, Thesis, Master of Law University 17 August 1945 Semarang, 2021.

Journal

Afifaah Fitri Apsari, Anifatun Lutfiyah, et al, Protection of Patient Personal Data against Cyber Crime Attacks, Sansakara Journal of Law and Human Rights, Volume 1, Number 2, 2022.

Anggraeni Endah Kusumaningrum, Juridical Review of the Rights and Obligations of Patients as Consumers in Medical Services, Journal of the Supremacy of Law, Volume 2, Number 1, 2013.

Asa Intan Primanta, Criminal Liability for Misuse of Personal Data, Jurist-Diction Journal, Volume 3, Number 4, 2020.

Basyarudin, Juridical aspects of electronic medical records used as evidence if health service errors occur, Cakrawala Ilmiah Journal, Volume 1 Number 12, 2022.

Calvin Anthony Putra, Analysis of Hospital Liability Regarding Potential Leakage of Electronic Medical Record Data Due to Cyber Crime, Novum Journal, Volume 1, number 1, 2022.

Edy Santoso, Andriana, Insecurity in Consumer Data Protection in the eHealth Sector, De Jure Legal Research Journal, Volume 23, Number 1, 2023.

Endison Ravindo, Ariawan Gunadi, Legal Protection of Health Data Through Ratification of the Personal Data Protection Bill, Adigama Law Journal, Volume 4, Number 2, 2021.

Eriawan Agung Nugroho, Implementation of Republic of Indonesia Law No. 11 of 2008 regarding Information & Electronic Transactions on Electronic Medical Records, Juristic Journal, Volume 1, Number 3, 2020.

Evelyn Angelita Pinondang Manurung, Emmy Febriani Talib, Juridical Review of Personal Data Protection Based on Law Number 27 of 2022, Saraswati Law Journal, Volume 4, Number 2, 2022.

Faiz Rahman, Legal Framework for Personal Data Protection in the Implementation of Electronic-Based Government Systems in Indonesia, Indonesian Legislation Journal, Volume 18, Number 1, 2021.

Handryas Praseyo Utomo, Elisatris Gultom, Anita Afriana, The Urgency of Legal Protection of Patient Personal Data in Technology-Based Health Services in Indonesia, Galuh Justiti Scientific Journal, Number 2, Volume 8, 2020.

HP Utomo. E. Gultom, and A. Afroana. The Urgency of Legal Protection of Patient Personal Data in Technology-Based Health Services in Indonesia, Galuh Justiti Journal, Volume 8, Number 2, 2020.

Indah Maria Maddalena Simamora, Legal Protection of the Right to Privacy and Confidentiality of Disease Identity for Covid-19 Patients, Sibatik Journal Faculty of Law, Taumanagara University. Volume 1, number 7, 2022.

Jessy Anastasia Aruan, Legal Responsibility of Electronic Health System Managers in Indonesia as Electronic Providers in Relation to Data Protection, Dharmasisya Journal of the Master of Law Program, Faculty of Law, University of Indonesia, Volume 1, 2022.

Krista Yunita, Yuni Purwati, Sajiyati, Bambang Sukarjono, Implications and Socialization of the Law on Personal Data Protection in Maintaining the Confidentiality of One's Personal Data, DAYA-MAS Journal, Volume 7 Number 2, 2022.

Mirnayanti, Judhariksasawan, Analysis of Personal Data Security Regulations in Indonesia, Living Law Journal, Number 1, Volume 15, 2023.

Muhamad Hasan Rumlus, Hanif Hartadi, Policy for Combating Personal Data Theft in Electronic Media. Human Rights Journal, Volume 11, Number 2, 2020.

Muhammad Nur Afif, Information Security in Hospitals, Sabhanga Journal. Number 1, Volume 2, 2020.

Naya Amin Zaini, Legal Study of the Obligation to Fulfill and Protect Human Rights in the Indonesian Constitution, Legal Panorama Journal, No. 2 Volume 1, 2016.

Neng Sari Rubiyanti, Implementation of Electronic Medical Records in Hospitals in Indonesia: Juridical Study, Alilah: Journal of Politics, Social, Law and Humanoria, Number 1, Volume 1, 2023.

Prilian Cahyani & Astutik, Criminal Liability for Misuse of Electronic Medical Records in Health Services, Soepra Health Law Journal, Volume 5, Number 2, 2019.

Sahat Maruli Tua Situmeang, Misuse of Personal Data as a Perfect Form of Crime from a Cyber Law Perspective, SASI Journal, Volume 27, Number 1, 2021.

Sekaring Ayumeida Kusnadi, Andy Usmina Wijaya, Legal Protection of Personal Data as a Right to Privacy, Al-Wasath Journal, Volume 2, Number 1, 2021, p.27

Siti Yuniarti, Legal Protection of Personal Data in Indonesia, BECOSS Journal, Volume 1, Number 1, 2019.

Teguh Prasetyo, Jamalum Sinambela, Application of Administrative Sanctions and Criminal Sanctions for Theft of Personal Data from the Perspective of the Theory of Dignified Justice. Legal Spectrum Journal, Volume 20, Number 1, 2023.

Tongon Fernando Hutasoit, Pan Lindawaty, Suherman Sewu, The Principle of Lex Specialis Derogate Legi Generalis is Linked to the Principle of Lex Superioti Derogat Legi Inferiori in Electronic Medical Records in Indonesia. Syntax Literate: Indonesian Scientific Journal. Number 12, Volume 7. 2022.

Wicipto Setiadi, Administrative Sanctions as a Law Enforcement Instrument in Legislation, Indonesian Legation Journal, Volume 6, Number 4, 2009.

Page

Ananthia Ayu, et al, Protection of Privacy Rights over Personal Data in the Digital Economy Era, Research Results of the Center for Case Research and Study and Library Management of the Registrar's Office and Secretariat General of the Constitutional Court, 2019.https://mkri.idaccessed on May 20 2023 at 19.30 WIB.

Government explanation (Ministry of Communication and Information) regarding the Personal Data Protection Bill in a working meeting with Commission I DPR RI, Jakarta, 25 February 2020.https://dpr.go.id. Accessed February 15, 2023.

Kominfo, 2022, Kominfo Responds to Alleged Data Leak of the Ministry of Health.https://aptika.kominfo.go.id. Accessed on February 20 2023, at 20.03 WIB.

KBBI. "Understanding Data".https://kbbi.web.id.Accessed on February 22 2023 at 19.00 WIB.

KBBI. “Personal Understanding.https://www.kbbi.idaccessed on February 22 2023 at 19.08 WIB.

Wahyudi Djafar, Paper presented as material in the public lecture "Legal Challenges in the Era of Big Data Analysis", Postgraduate Program, Faculty of Law, Gadjah Mada University, Yogyakarta, 26 August 2019.https://law.ugm.ac.id. accessed on May 15 2023 at 18.30 WIB.

Downloads

Published

2023-10-18

How to Cite

Lukitasari, D. A., Zamroni, M., & Putera, A. P. (2023). Hospital Legal Responsibilities for Misuse of Patient Personal Data In Electronic Medical Records . JILPR Journal Indonesia Law and Policy Review, 5(1), 60–74. https://doi.org/10.56371/jirpl.v5i1.164