The digitization of the healthcare sector through the Hospital Management Information System (HMIS) increases the risk of patient data security due to the potential for unauthorized access and misuse of sensitive information. The large volume of activity log data makes conventional sampling-based auditing processes ineffective in identifying security threats in real time. This study aims to implement user data access variables into the Isolation Forest algorithm framework to build an intelligent anomaly detection mechanism in the information system of Dr. M. Djamil Padang General Hospital. The research methodology applies an unsupervised machine learning-based Isolation Forest algorithm to isolate deviant behavior through anomaly scoring on random isolation trees. The pre-processing stage involves extracting request, status, and data size variables and performing numerical transformation using Z-Score standardization to maintain computational stability. The research dataset is sourced from the activity logs of the HMIS web server at Dr. M. Djamil Padang General Hospital, with a total sample of 5000 user access transactions. The analysis results show that the model successfully identified 718 data points, or 14.36%, as anomalies with an accuracy rate identical to that of manual calculations. The application and implementation of the Isolation Forest technique proved to be effective in solving the problem of early detection of suspicious data traffic patterns in large data flows. The contribution of this research enhances hospital information security management through a data-based early warning system to improve the overall accountability of health information access.