How should clinics handle patient health data under UU PDP?
Under Indonesia’s UU PDP, clinics should treat patient health data as specific personal data, document its processing basis and purpose, limit collection and access, secure and record processing, set retention and deletion rules, assess high-risk processing, and govern processors and transfers.
Start with the legal layer. Indonesia’s Law No. 27 of 2022 on Personal Data Protection (UU PDP), dated 17 October 2022, lists health data as specific personal data in Article 4. Article 20 requires the controller to identify an applicable processing basis; explicit consent is one of six listed bases, not the automatic basis for every use. The clinic should confirm its actual controller or processor role, purpose, and basis for each processing activity with its legal or privacy team.
Turn those duties into operating controls. Map the path from the clinic’s source system through storage, model endpoints, backups, logs, support access, transfers, and deletion. Collect data for a defined purpose, restrict access by role, verify accuracy, record processing activity, apply a retention and deletion schedule, and protect confidentiality and security. Article 34 requires a Data Protection Impact Assessment for high-risk processing and expressly includes processing specific personal data; Article 35 requires technical and operational security measures based on the data’s nature and risk.
When a clinic appoints a vendor as a processor, document instructions, permitted purposes, access, subprocessors, incident handling, retention, deletion, and transfer arrangements for the actual deployment. Article 51 requires a processor to act on the controller’s instructions and obtain written controller approval before involving another processor. For an AI deployment, bind that processing map to institution-approved terms and technical access before production patient data is connected. AI Care Command Center provides a released workbench for enabled workflows, while the exact context, roles, integrations, and audit evidence remain implementation-specific.
Related questions
Does UU PDP always require patient consent for health-data processing?+
Does a clinic need a document specifically titled DPA?+
What should a clinic document before an AI vendor handles patient data?+
Micromeet — AI for governed healthcare. MCU CoPilot, AI Scribe (Voice-to-EMR), AI Front Desk, Care Loop, Claim Readiness and AI Care Command Center — every output doctor-reviewed. AI writes. Doctors decide. See the public benchmark →