Patient data security in electronic medical records (EMR) is a major concern in healthcare facilities. This study aims to analyze EMR data security based on the ISO 27001 standard through a literature review method. Data were collected from various previous studies that discussed aspects of information security in the implementation of EMR. The results of the study indicate that although security mechanisms such as authentication, encryption, and access control have been implemented, weaknesses are still found in the management of access rights, recording user activities, and security policies. Several healthcare facilities have not fully met the ISO 27001 standard, especially in the aspects of risk management documentation and security evaluation. Therefore, it is necessary to improve security policies, train medical personnel, and provide periodic evaluations to ensure better protection of patient data.
Copyrights © 2025