Questioning the Adequacy of Medical Data Privacy Protection in Indonesia

Amidst the current outbreak of the COVID-19 pandemic, the issue of medical data privacy becomes more crucial to be addressed as it becomes more prone to be threatened. When President Joko Widodo publicly announced the first two patients of COVID-19 in Indonesia in March, their personal data were subsequently widely spread in various social media platforms, which include their home address, family members, pictures, occupations, and workplace.[1] On the other hand, there was also a subsequent case where a database of COVID-19’s patients’ names went viral on Twitter.[2]  These very cases indicate how the protection of medical data privacy in Indonesia has been insufficient insofar – although the dissemination of personal data itself is regulated in Article 26 and 45 of the Information and Electronic Transaction Laws – especially in regards to certain diseases considered as “taboo.” For instance, last year, in Solo, Central Java, 14 elementary school students were ostracised by other students’ parents due to the fear of transmitting HIV/AIDS, which they suffer from,[3] which means that their medical records were publicly leaked. This article argues that strengthening the cybersecurity measures of technological equipment in the medical sector, as well as fostering information transparency and data privacy protection, is equally crucial to further bolster medical data privacy protection efforts in Indonesia.

Strengthening Cybersecurity Measures in the Medical Sector

During the outbreak of the current pandemic, it might indeed be more difficult to bolster protection efforts on technological equipment in hospitals from cyber threats as cyber attackers may capitalize on the status quo to steal personal medical information. Reflecting from the case of two local hospitals in Jakarta being severely attacked by the WannaCry ransomware back then in 2017, which had encrypted all archived personal medical records of the patients,[4] it is important to address and scrutinize the current cybersecurity measures that have been applied to protect hospitals’ IT systems and anticipate the case as mentioned earlier from re-occurring in the future. First, as there have been a huge proportion of investments on upgrading technological equipment and systems in hospitals, it is important to also take into account the availability and preparedness of human resources that could operate those systems well and fixing them subsequent to any damages, which could be done through capacity-building measures. On the other hand, the network of the systems that archive patients’ medical records should be separated from the public network to anticipate any possible infringement carried out with the patients’ data; therefore, only the permitted cyber officers could gain access to the database.  Moreover, it is also crucial to ensure that the most updated anti-malware software and hardware are installed to further secure the systems from potential cyber-attacks in the future.

Fostering Information Transparency and Data Privacy Protection

Information transparency and data privacy protection frequently could not go hand in hand. While information regarding medical data records of patients is disseminated to foster openness and anticipate future transmission of the diseases, they are also often over-leaked, in which personal data that are exposed are too much, and many of them are unnecessary or insignificant to be widely known. As in the case of the unethical public dissemination of the data of the first two patients of COVID-19, it could be seen that the knowledge of information ethics still lacks in Indonesia. While it is essential to publicly announce the places where those patients went to prevent future transmissions of the virus, many unnecessary personal information was leaked, which therefore has hindered their privacy. In tackling this challenge, the government needs to establish good communications with the public in responding to the dissemination of information regarding the track records of patients, in which hoaxes and infringement to patients’ data privacy rights could subsequently be anticipated. The public should be notified and educated on how to respond to false or unethical information that has already been widespread. The chain of the news could eventually be broken if people are aware of the possible implications resulted from the widespread of that information. For instance, how it would be difficult for people to honestly tell their symptoms of the disease to medical officers and refuse a treatment if they predict that their privacy will be at stake in the future.

Author: Felice Valeria
Editor: Amelinda Pandu Kusumaningtyas

Read more articles written by Felice Valeria
 


[1] Suhardi, G., 2020. Rahasia Rekam Medis. [online] Media Indonesia. Available at: [Accessed 20 April 2020].

[2] Novianty, D. and Utami, L., 2020. Namanya Tersebar, Warganet Sebut Ada Kebocoran Data Pasien Virus Corona. [online] suara.com. Available at: [Accessed 20 April 2020].

[3] BBC News Indonesia. 2019. ‘Karena Mengidap HIV/AIDS’, 14 Murid SD Di Solo Ditolak Orang Tua Siswa. [online] Available at: [Accessed 20 April 2020].

[4] Kertopati, L., 2017. Dua Rumah Sakit di Jakarta Kena Serangan Ransomware Wannacry. [online] CNN Indonesia. Available at: [Accessed 20 April 2020].