The digitalization of health services has transformed the relationship between patients, health professional, health care facilities, and electronic system providers through telemedicine, electronic medical records, health applications, and digital medical data management. Although these innovations improve access, efficiency, and flexibility in health care delivery, they also create legal challeges, particularly medical data breaches and potential malpractice in telemedicine services. This study aims to analyze the legal regulation of patient medical data protection and telemedicine services in Indonesia, and to examine the construction of criminal liability for medical data breaches and telemedicine malpractice as a form of patient rights protection. This research uses a normative juridical method with statutory, conceptual, and case approaches. The findings show that the regulation of digital health services in Indonesia remains dispersed across several legal regimes, including health law, personal data protection law, electronic information and transaction law, and medical records regulation. Criminal liability cannot be imposed merely because harm occurs; it must be based on proof of an unlawful act, fault, causation, and patient harm. This study concludes that regulatory harmonization, clear telemedicine standards, secure electronic medical record management, and proportional criminal law enforcement are necessary to protect patient rights without obstructing innovation in digital health services.
Copyrights © 2026