Electronic medical records (EMR) require sound data security management to preserve the confidentiality, accuracy, and availability of patient information. This study describes the knowledge, compliance, efforts, and policy alignment of medical record and health information officers (PMIK) regarding EMR data security at Humana Prima Hospital, Bandung. A descriptive qualitative method was applied through observation, in-depth interviews, and document review involving 12 PMIK staff and 1 Head of the Medical Record Unit selected through total sampling. Data were analyzed using the Miles and Huberman interactive model and validated through source triangulation. Results show that staff knowledge still varies and is influenced by training history and D3 Medical Record educational background. Staff compliance is relatively high, although a gap remains in the form of failure to log out in the Emergency Department due to high workload. Efforts to safeguard data security have covered confidentiality, integrity, and availability, but audit trail implementation has not been fully applied. The three written SPOs complement one another but do not yet fully regulate daily operational behavior or storage room monitoring. EMR data security risks are found more at the implementation level than the policy level, so strengthening training and supervision should be prioritized.
Copyrights © 2026