The rapid growth of information technology in the healthcare sector has increased the risk of patient data breaches, making legal protection increasingly important in Indonesia, where weaknesses in hospital data security systems remain evident. This study analyzes legal protections for patient data and evaluates the effectiveness of their implementation. A normative juridical literature review method was used, involving systematic analysis of books, scientific articles, research reports, and relevant legal documents. The findings show that patient data protection is normatively regulated under Law Number 44 of 2009 on Hospitals, Law Number 17 of 2023 on Health, and Law Number 27 of 2022 on Personal Data Protection. These laws emphasize hospitals’ obligations to maintain patient confidentiality and restrict data access and use based on explicit consent. However, in practice, a significant gap remains between legal provisions and implementation. Weak data security infrastructure, limited awareness among healthcare personnel, and suboptimal law enforcement contribute to ongoing vulnerabilities. In conclusion, although the legal framework for patient data protection is well established, its effectiveness is still constrained by implementation challenges. Strengthening supervision, improving enforcement, and enhancing human resource capacity are essential to ensure more effective protection of patient data in Indonesia.
Copyrights © 2026