Audit Sistem Informasi Rekam Medis Elektronik (RME) Berbasis Kriteria ISO/IEC 27001:2022 di UPT Puskesmas Cibiuk
Downloads
How to Cite
Digitalisasi layanan fasilitas kesehatan menjadi tuntutan yang tidak dapat dihindari pada era abad ke-21, termasuk pada layanan Rekam Medis Elektronik (RME) di lingkungan Fasilitas Pelayanan Kesehatan Tingkat Pertama (FKTP). Urgensi audit keamanan RME di FKTP semakin meningkat seiring dengan maraknya insiden kebocoran data kesehatan dan belum meratanya penerapan standar keamanan informasi di tingkat primer. Penelitian ini bertujuan untuk mengaudit keamanan sistem informasi RME pada UPT Puskesmas Cibiuk guna mengevaluasi proses tata kelola perlindungan privasi data pasien yang masih berjalan tanpa standar keamanan baku dan rentan terhadap kebocoran akses. Metode yang digunakan adalah Audit Sistem Informasi melalui pendekatan Gap Analysis (Analisis Kesenjangan), yang dijalankan dengan mengevaluasi 8 kontrol pada Annex A.6 People Controls dan 23 kontrol internal pada Annex A.8 Technological Controls ISO/IEC 27001:2022. Subjek penelitian adalah pengelola IT dan tenaga medis pengguna sistem di UPT Puskesmas Cibiuk, sedangkan objek penelitian adalah sistem RME yang saat ini digunakan secara aktif di poli pelayanan. Hasil penelitian menunjukkan bahwa tingkat kematangan (maturity level) keamanan sistem berada pada rata-rata 2.30 (Repeatable) dengan persentase kesesuaian sebesar 47,09%. Temuan risiko tertinggi ditemukan pada kontrol backup yang belum diuji restore dengan risk score 20 (Sangat Tinggi). Celah keamanan paling signifikan ditemukan pada praktik berbagi kata sandi (password sharing) antar perawat dan ketiadaan enkripsi pada proses pencadangan (backup) data. Implementasi audit terbukti efektif memetakan kerentanan sistematis pada operasional puskesmas. Penelitian ini menyimpulkan bahwa kerangka kerja ISO/IEC 27001:2022 sangat relevan diterapkan pada evaluasi sistem informasi berskala layanan kesehatan primer karena ketatnya standar yang mengakomodasi perlindungan data medis.
Audit of Electronic Medical Record (EMR) Information System Based on ISO/IEC 27001:2022 Criteria at UPT Puskesmas Cibiuk
Abstract
The digitalization of healthcare facilities has become an unavoidable demand in the 21st century, including Electronic Medical Record (EMR) services in Primary Healthcare Facilities. The urgency of auditing EMR security in primary healthcare facilities is increasing along with the rise in health data breach incidents and the uneven implementation of information security standards at the primary level. This study aims to audit the security of the EMR information system at UPT Puskesmas Cibiuk to evaluate the governance of patient data privacy protection, which is currently running without standard security protocols and is vulnerable to access breaches. The method used is Information Systems Audit through a Gap Analysis approach, conducted by evaluating 8 controls in Annex A.6 People Controls and 23 internal controls in Annex A.8 Technological Controls of ISO/IEC 27001:2022. The research subjects were IT administrators and medical personnel using the system at UPT Puskesmas Cibiuk, while the object of research was the EMR system currently actively used in outpatient clinics. The results showed that the system's security maturity level is at an average of 2.30 (Repeatable) with a compliance percentage of 47.09%. The highest risk finding was found in the backup control that had not been restore-tested, with a risk score of 20 (Very High). The most significant security vulnerabilities were found in the practice of password sharing among nurses and the lack of encryption in the data backup process. The implementation of the audit proved effective in mapping systematic vulnerabilities in the community health center's operations. This study concludes that the ISO/IEC 27001:2022 framework is highly relevant for evaluating information systems at the primary healthcare level due to its strict standards accommodating medical data protection.
Ardianto, E. T., Sabran, S., & Nurjanah, L. (2024). Analisis aspek keamanan data pasien dalam implementasi rekam medis elektronik di Rumah Sakit X. Jurnal Rekam Medik & Manajemen Informasi Kesehatan, 3(2), 18–30. https://doi.org/10.47134/rmik.v3i2.54
Arif, A., Linawati, L., & Noak, P. A. (2026). Implementasi SNI ISO/IEC 27001:2022 terhadap perlindungan data rekam medis elektronik (RME) pada fasilitas pelayanan kesehatan di Indonesia. MAINTEKKES: The Journal of Management Information and Health Technology, 4(1), 1–8. https://doi.org/10.36049/qgkk3906
Asih, H. A., Indrayadi, I., Soraya, S., & Khairunnisa, K. (2024). Evaluasi keamanan data pasien pada rekam medis elektronik dengan systematic literature review. Jurnal Ilmiah FIFO, 16(2). https://doi.org/10.22441/fifo.2024.v16i2.001
Bahaudin, M. H., & Rizqi, A. W. (2024). Evaluasi Kesesuaian Penerapan Sistem Manajemen Keselamatan dan Kesehatan Kerja (SMK3) Berdasarkan ISO 45001: 2018 Menggunakan Metode Gap Analysis dan PDCA:(Studi kasus: PT Swabina Gatra). Jurnal Teknologi dan Manajemen Industri Terapan, 3(I), 766-773. https://doi.org/10.55826/jtmit.v5i2.1716
Fathurohman, A., & Witjaksono, R. W. (2020). Analysis and design of information security management system based on ISO 27001: 2013 using Annex Control (Case Study: District of Government of Bandung City). Bulletin of Computer Science and Electrical Engineering, 1(1), 1-11. https://doi.org/10.25008/bcsee.v1i1.2
Igayanti, I. B., Deviga, L., Mathar, I., & Ramadanintyas, K. N. (2026). TINJAUAN PENERAPAN REKAM MEDIS ELEKTRONIK BERBASIS E-LINK DI UPT PUSKESMAS MOJOPURNO. Enfermeria Ciencia, 4(2), 148-169. https://doi.org/10.56586/ec.v4i2.113
Ikawati, F. R., & Ansyori, A. (2025). Literature Review: Analisis Keamanan Data Rekam Medis Elektronik di Fasilitas Kesehatan. Jurnal Manajemen Informasi Kesehatan (Health Information Management), 10(2), 230-237. https://doi.org/10.51851/jmis.v10i2.673
Ikawati, F. R., Ansyori, A., & Permatasari, D. A. S. (2025). Literature review: Analisis keamanan data rekam medis elektronik di fasilitas kesehatan. Jurnal Manajemen Informasi Kesehatan (Health Information Management), 10(2), 230–237. https://doi.org/10.51851/jmis.v10i2.673
International Organization for Standardization. (2022). ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements.
International Organization for Standardization. (2022). ISO/IEC 27002:2022 Information security, cybersecurity and privacy protection — Information security controls.
Kementerian Kesehatan Republik Indonesia. (2022). Peraturan Menteri Kesehatan Nomor 24 Tahun 2022 tentang Rekam Medis.
Mariani, N. K. (2025). Analisis aspek keamanan data rekam medis dalam implementasi rekam medis elektronik di Rumah Sakit Umum Klungkung. MAINTEKKES: The Journal of Management Information and Health Technology, 3(2), 79–91. https://doi.org/10.36049/maintekkes.v3i2.420
Pramesti, D. P. A., Ayuningtyas, D., & Verdi, R. (2024). Keamanan dan kerahasiaan data medis pasien dalam implementasi rekam medis elektronik: Tinjauan sistematis. PREPOTIF: Jurnal Kesehatan Masyarakat, 8(3). https://doi.org/10.31004/prepotif.v8i3.38445
Rani, D. M., & Widyaningrum, B. N. (2025). Information security evaluation of the electronic medical records system at Sultan Agung Islamic Hospital. Jurnal Manajemen Informasi Kesehatan (Health Information Management), 10(1), 52–62. https://doi.org/10.51851/jmis.v10i1.636
Republik Indonesia. (2022). Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi.
Rumetna, M. S., Lina, T. N., Santoso, A. B., Karay, J., Komansilan, R., & Kaitelapatay, B. G. (2022). Pengetahuan serta peran auditor secara komprehensif dalam menghadapi dampak perkembangan teknologi informasi. Jurnal Komtika (Komputasi dan Informatika), 6(1), 26-38. https://doi.org/10.31603/komtika.v6i1.6776
Setyaningrum, E., & Ricky, A. V. (2025). Analisis keamanan data pasien dalam rekam medis elektronik berdasarkan CIA Triad di RSUD X Jawa Tengah. Jurnal Ners, 9(3), 4216–4221. https://doi.org/10.31004/jn.v9i3.46352
Simanullang, M. J., Aritonang, M. A. S., & Sinaga, F. M. (2026). Analisis Keamanan Data Pasien pada Sistem Informasi Manajemen Rumah Sakit (SIMRS). Jurnal Desain Dan Analisis Teknologi, 5(1), 44-50. https://doi.org/10.58520/jddat.v5i1.98
Soraya, S., Oktoriyani, E. N., & Mawan, M. S. A. (2025). Evaluasi keamanan dan privasi sistem rekam medis elektronik: Studi kasus di Rumah Sakit Wava Husada. JRMIK (Jurnal Rekam Medis dan Informasi Kesehatan), 6(1). https://doi.org/10.58535/jrmik.v6i1.78
We’e, A., Nugroho, H., & Siswatibudi, H. (2023). Evaluasi aspek keamanan dan kerahasiaan rekam medis elektronik di Rumah Sakit Panti Nugroho. Jurnal Permata Indonesia, 14(2), 72–81. https://doi.org/10.59737/jpi.v14i2.265
Copyright (c) 2026 Nur Rizal Fahmana, Purnomo, Dinar Rahayu

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Authors who publish with Empiricism Journal agree to the following terms:
- For all articles published in Empiricism Journal, copyright is retained by the authors. Authors give permission to the publisher to announce the work with conditions. When the manuscript is accepted for publication, the authors agrees to implement a non-exclusive transfer of publishing rights to the journals.
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution-ShareAlike 4.0 International License that allows others to share the work with an acknowledgment of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgment of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work (See The Effect of Open Access).

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
