Review of Medical Record Data and Information Security in the Medifirst application at Bakti Pajajaran Regional Hospital
Keywords:
Review, Data security, MediFirst appAbstract
Objective: This study aims to identify the data and information security of medical records in the MediFirst application at Bakti Pajajaran Regional General Hospital (RSUD Bakti Pajajaran) based on three key factors: confidentiality, integrity, and availability.
Methods: This research employed a descriptive qualitative method, utilizing observations and interviews analyzed qualitatively to provide a direct overview of data security within the MediFirst application at RSUD Bakti Pajajaran. The study was conducted at Bakti Pajajaran Regional General Hospital, located at Jl. KSR Dadi Kusmayadi No. 27, Cibinong District, Bogor Regency, West Java 16914, on October 5, 2024. The study included 8 informants: 5 medical record staff members, 2 IT officers, and 1 head of the medical records department.
Results: Based on the findings at RSUD Bakti Pajajaran, the MediFirst application has implemented various data and information security mechanisms covering confidentiality, integrity, and availability. In terms of confidentiality, the system uses data encryption with the Advanced Encryption Standard (AES) algorithm to protect patient data and implements access control through individual usernames and passwords based on Role-Based Access Control (RBAC). Additionally, biometric systems, Virtual Private Networks (VPNs), and Non-Disclosure Agreements (NDAs) are utilized to prevent unauthorized access and maintain patient privacy. Regarding integrity, the MediFirst application utilizes audit logs, hash functions, and digital signatures to ensure data remains accurate and unaltered without authorization. Audit trails are used to transparently monitor user activities, while system updates and security patches are applied periodically after evaluation and testing phases. Regarding availability, the hospital has implemented routine data backups, redundancy and failover systems, and periodic monitoring to maintain application stability and ensure medical record data remains accessible when needed. Overall, the security measures in the MediFirst application effectively support medical record protection, though further developments, such as implementing two-factor authentication, are still required to enhance system security.
Conclusions: In terms of confidentiality, the MediFirst application utilizes individual authentication mechanisms (usernames and passwords) for each user, restricting medical record access based on respective personnel authority. The system also records login activities for oversight and internal audit support. Regarding integrity, the application successfully maintains the accuracy and completeness of medical records through access restrictions and user activity logging, minimizing the risk of unauthorized data alterations. For availability, the MediFirst system adequately supports service operations by allowing authorized personnel to access medical records as needed. System maintenance and IT support actively help maintain availability, although potential technical disruptions and network dependency remain challenges that require ongoing attention.
Downloads
References
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Furqon Sabiq Husaini, Laela Indawati (Author)

This work is licensed under a Creative Commons Attribution 4.0 International License.




