Audit Sistem Informasi Rekam Medis Elektronik (RME) Berbasis Kriteria ISO/IEC 27001:2022 di UPT Puskesmas Cibiuk

Audit Sistem Informasi RME Keamanan Informasi ISO/IEC 27001:2022

Authors

Downloads

How to Cite

Fahmana, N. R. ., Purnomo, & Rahayu, D. . (2026). Audit Sistem Informasi Rekam Medis Elektronik (RME) Berbasis Kriteria ISO/IEC 27001:2022 di UPT Puskesmas Cibiuk. Empiricism Journal, 7(3), 2651-2663. https://doi.org/10.36312/ej.v7i3.6542

Digitalisasi layanan fasilitas kesehatan menjadi tuntutan yang tidak dapat dihindari pada era abad ke-21, termasuk pada layanan Rekam Medis Elektronik (RME) di lingkungan Fasilitas Pelayanan Kesehatan Tingkat Pertama (FKTP). Urgensi audit keamanan RME di FKTP semakin meningkat seiring dengan maraknya insiden kebocoran data kesehatan dan belum meratanya penerapan standar keamanan informasi di tingkat primer. Penelitian ini bertujuan untuk mengaudit keamanan sistem informasi RME pada UPT Puskesmas Cibiuk guna mengevaluasi proses tata kelola perlindungan privasi data pasien yang masih berjalan tanpa standar keamanan baku dan rentan terhadap kebocoran akses. Metode yang digunakan adalah Audit Sistem Informasi melalui pendekatan Gap Analysis (Analisis Kesenjangan), yang dijalankan dengan mengevaluasi 8 kontrol pada Annex A.6 People Controls dan 23 kontrol internal pada Annex A.8 Technological Controls ISO/IEC 27001:2022. Subjek penelitian adalah pengelola IT dan tenaga medis pengguna sistem di UPT Puskesmas Cibiuk, sedangkan objek penelitian adalah sistem RME yang saat ini digunakan secara aktif di poli pelayanan. Hasil penelitian menunjukkan bahwa tingkat kematangan (maturity level) keamanan sistem berada pada rata-rata 2.30 (Repeatable) dengan persentase kesesuaian sebesar 47,09%. Temuan risiko tertinggi ditemukan pada kontrol backup yang belum diuji restore dengan risk score 20 (Sangat Tinggi). Celah keamanan paling signifikan ditemukan pada praktik berbagi kata sandi (password sharing) antar perawat dan ketiadaan enkripsi pada proses pencadangan (backup) data. Implementasi audit terbukti efektif memetakan kerentanan sistematis pada operasional puskesmas. Penelitian ini menyimpulkan bahwa kerangka kerja ISO/IEC 27001:2022 sangat relevan diterapkan pada evaluasi sistem informasi berskala layanan kesehatan primer karena ketatnya standar yang mengakomodasi perlindungan data medis.

 

 

Audit of Electronic Medical Record (EMR) Information System Based on ISO/IEC 27001:2022 Criteria at UPT Puskesmas Cibiuk

 

Abstract

The digitalization of healthcare facilities has become an unavoidable demand in the 21st century, including Electronic Medical Record (EMR) services in Primary Healthcare Facilities. The urgency of auditing EMR security in primary healthcare facilities is increasing along with the rise in health data breach incidents and the uneven implementation of information security standards at the primary level. This study aims to audit the security of the EMR information system at UPT Puskesmas Cibiuk to evaluate the governance of patient data privacy protection, which is currently running without standard security protocols and is vulnerable to access breaches. The method used is Information Systems Audit through a Gap Analysis approach, conducted by evaluating 8 controls in Annex A.6 People Controls and 23 internal controls in Annex A.8 Technological Controls of ISO/IEC 27001:2022. The research subjects were IT administrators and medical personnel using the system at UPT Puskesmas Cibiuk, while the object of research was the EMR system currently actively used in outpatient clinics. The results showed that the system's security maturity level is at an average of 2.30 (Repeatable) with a compliance percentage of 47.09%. The highest risk finding was found in the backup control that had not been restore-tested, with a risk score of 20 (Very High). The most significant security vulnerabilities were found in the practice of password sharing among nurses and the lack of encryption in the data backup process. The implementation of the audit proved effective in mapping systematic vulnerabilities in the community health center's operations. This study concludes that the ISO/IEC 27001:2022 framework is highly relevant for evaluating information systems at the primary healthcare level due to its strict standards accommodating medical data protection.