The digitalization of healthcare has transformed the management and exchange of patient information through electronic medical records (EMRs). While EMRs enhance continuity and efficiency of care, they also expose highly sensitive health information to cybersecurity threats and unauthorized disclosure. This article examines the legal responsibility of hospitals when electronic medical records are leaked, accessed without authorization, or otherwise compromised. The study employs normative legal research by examining Indonesian health legislation, personal data protection regulations, and principles governing the confidentiality of medical information. Particular attention is given to the relationship between hospitals' obligations as healthcare providers and their responsibilities as entities processing sensitive personal data. The analysis finds that the existing regulatory framework establishes multiple obligations concerning confidentiality, data security, and patient rights, but the distribution of responsibility between hospitals, healthcare professionals, technology providers, and other data processors remains insufficiently articulated. This fragmented framework may create uncertainty regarding remedies and accountability following a data breach. The article argues that hospital liability should be assessed through a risk-based framework emphasizing preventive security measures, organizational control, breach notification, and effective remedies for affected patients. Strengthening institutional accountability is essential to ensure that digital healthcare development remains consistent with the fundamental right to privacy and the broader principle of health justice.