This study aims to analyze in depth the strategic role of hospital management at RSU Agung Mulia in formulating policies, implementing cyber protection systems, and overcoming operational constraints to ensure health information security and prevent patient data breaches. A qualitative approach with a descriptive research type was applied to uncover facts directly in the field through a natural setting. The primary data collection technique was conducted through in-depth interviews with three key informants, namely the Director, the Head of the Information Technology Unit, and the Head of the Medical Records Department, which was further strengthened by objective direct observation methods. The data analysis procedure followed an interactive model encompassing data reduction, data display, and conclusion drawing stages. The results of the study indicate that management policies are focused on formulating strict internal regulations, restricting medical data access rights based on job roles, and mandating the signing of staff integrity pacts. The main obstacles faced by the institution include operational budget constraints, outdated hardware conditions, and low digital literacy among administrative staff, which trigger human errors in the service area. Managerial efforts to circumvent these limitations are realized through a financial cluster strategy with hardware leasing options, optimizing operating systems using open-source software, and conducting periodic phishing attack simulations. The implementation of a reward and punishment system combined with the appointment of cyber pioneers has proven successful in altering staff behavior to become more disciplined and increasing operational compliance in safeguarding patient data confidentiality.