The development of artificial intelligence in healthcare increasingly depends on access to large volumes of clinical data, including electronic medical records. Although such data can support medical research and technological innovation, their secondary use for AI training raises fundamental questions concerning patient autonomy, privacy, consent, and control over health information. This article examines whether and under what circumstances electronic medical records may lawfully be used to train AI systems in Indonesia. Employing a normative juridical methodology, the study analyzes the legal status of health data, patient consent requirements, confidentiality obligations, and the principles governing secondary use of personal data. The study identifies a regulatory tension between the collective interest in advancing healthcare innovation and the individual patient's right to control sensitive health information. De-identification may reduce privacy risks but does not necessarily eliminate all legal and ethical concerns associated with data reuse. The article argues that the legitimacy of AI training using medical records should not depend solely on anonymization but should incorporate purpose limitation, proportionality, transparency, data governance, and appropriate forms of patient participation. A rights-based framework is therefore proposed to reconcile technological innovation with patient autonomy and health justice in Indonesia.
Copyrights © 2026