Keywords:
Data Security, Digital Health, Personal Data Protection, Telemedicine, Telemedicine RegulationAbstract
Indonesia’s post-pandemic digital health surge has expanded the use of telemedicine, but it has also raised urgent legal concerns regarding patient data security, privacy, and accountability. This article examines two main questions: how effective are Indonesia’s existing regulations in governing telemedicine data security, and why is a specific telemedicine data security regulation urgent in the post-pandemic digital health landscape? Using a normative legal research approach, this study analyzes Indonesian cyber law, personal data protection law, telemedicine regulation, and medical record regulation through statutory and conceptual approaches. The discussion shows that existing regulations provide an initial legal foundation through general electronic system obligations, personal data protection principles, telemedicine service rules, and electronic medical record provisions. However, these instruments remain fragmented and insufficiently specific for telemedicine’s risk profile. The article finds that Indonesia urgently needs sector-specific regulation covering platform security, digital consent, actor-based responsibility, breach notification, supervision, and sanctions to ensure legal certainty, patient protection, and accountable digital health governance.