The digital transformation of the healthcare sector has driven hospitals to adopt Health Service Information Systems to improve the efficiency and quality of healthcare delivery. However, alongside these benefits, the implementation of such systems also increases the risks of unauthorized access, data breaches, and violations of patient confidentiality. These challenges highlight the urgent need for robust access governance that is not only technically sound but also aligned with legal frameworks governing patient data protection. This study aims to analyze the legal regulations concerning access governance in Health Service Information Systems, examine hospital compliance in implementing such governance, and assess the legal liability of hospitals for violations that compromise patient data protection. This research employs a normative legal method using statutory and conceptual approaches. The data used are secondary data obtained through library research, including legislation, legal textbooks, scientific journals, and relevant literature. The findings reveal that access governance is regulated under several legal instruments, including Law Number 17 of 2023 on Health, Law Number 27 of 2022 on Personal Data Protection, Minister of Health Regulation Number 24 of 2022 on Medical Records, and Minister of Health Regulation Number 6 of 2026 on Hospitals. Hospital compliance is demonstrated through access control mechanisms, protection of Electronic Medical Records, supervision of system usage, and the application of accountability principles. In cases of violations, hospitals may be held administratively, civilly, criminally, and corporately liable in accordance with applicable laws.