Governance

How should clinics handle patient health data under UU PDP?

Under Indonesia’s UU PDP, clinics should treat patient health data as specific personal data, document its processing basis and purpose, limit collection and access, secure and record processing, set retention and deletion rules, assess high-risk processing, and govern processors and transfers.

Start with the legal layer. Indonesia’s Law No. 27 of 2022 on Personal Data Protection (UU PDP), dated 17 October 2022, lists health data as specific personal data in Article 4. Article 20 requires the controller to identify an applicable processing basis; explicit consent is one of six listed bases, not the automatic basis for every use. The clinic should confirm its actual controller or processor role, purpose, and basis for each processing activity with its legal or privacy team.

Turn those duties into operating controls. Map the path from the clinic’s source system through storage, model endpoints, backups, logs, support access, transfers, and deletion. Collect data for a defined purpose, restrict access by role, verify accuracy, record processing activity, apply a retention and deletion schedule, and protect confidentiality and security. Article 34 requires a Data Protection Impact Assessment for high-risk processing and expressly includes processing specific personal data; Article 35 requires technical and operational security measures based on the data’s nature and risk.

When a clinic appoints a vendor as a processor, document instructions, permitted purposes, access, subprocessors, incident handling, retention, deletion, and transfer arrangements for the actual deployment. Article 51 requires a processor to act on the controller’s instructions and obtain written controller approval before involving another processor. For an AI deployment, bind that processing map to institution-approved terms and technical access before production patient data is connected. AI Care Command Center provides a released workbench for enabled workflows, while the exact context, roles, integrations, and audit evidence remain implementation-specific.

Related questions

Does UU PDP always require patient consent for health-data processing?+
No. Article 20 lists explicit consent alongside five other processing bases. The controller must identify and document the basis that applies to the specific purpose; where consent is used, it must meet the law’s requirements.
Does a clinic need a document specifically titled DPA?+
The required legal and contractual arrangement depends on the parties’ roles, applicable law, and the clinic’s procurement policy. Relevant terms may sit in a DPA, data-processing addendum, privacy schedule, processing terms, or another contract section.
What should a clinic document before an AI vendor handles patient data?+
Document the purpose, data categories, controller and processor roles, processing basis, data flow, access, security, retention, deletion, subprocessors, transfers, incident process, human approval points, and audit evidence for the actual deployment.

Micromeet — AI for governed healthcare. MCU CoPilot, AI Scribe (Voice-to-EMR), AI Front Desk, Care Loop, Claim Readiness and AI Care Command Center — every output doctor-reviewed. AI writes. Doctors decide. See the public benchmark →