The implementation of electronic medical records improves healthcare service efficiency but also presents challenges related to patient data security and confidentiality. This study aimed to analyze the risks of patient data breaches and preventive measure for electronic medical records at Hospital X. A descriptive qualitative approach was employed, with data collected through in-depth interviews, observations, and document reviews. The findings showed that no official reports of patient data breaches had been identified however, several risks remained, including audit trail monitoring that was not conducted regularly, access rights not fully aligned with user’s roles, the absence of two-factor authentication, inactive automatic logout, cloud storage still under consideration, and human error. The study concludes that EMR security still needs to be strengthened. EMR security is recommended to receive continuous strengthening through improvements in technology, policies, monitoring, and user awareness. Strengthening policies, incident response procedures, and user training, as well as fostering a security-conscious culture, are also essential to safeguarding the confidentiality, integrity, and availability of patient data. These measures are expected to prevent security incidents while enhancing patient trust in the hospital's healthcare services.
Copyrights © 2026