Evaluating the Security of Electronic Medical Records in Indonesia’s SIMPUS Application Using the CIA Framework
DOI:
https://doi.org/10.47738/ijiis.v8i3.263Keywords:
Electronic Medical Records, Data Security, SIMPUS, Confidentiality, Integrity, Availability, Health InformaticsAbstract
Ensuring the security of electronic medical records (EMRs) is a critical challenge in the digital transformation of healthcare systems, particularly in developing countries. This study evaluates the security of Indonesia’s Community Health Center Information System (SIMPUS) based on the principles of confidentiality, integrity, and availability (CIA). A qualitative descriptive approach was employed, combining interviews and direct observation of SIMPUS implementation across multiple user roles. The findings reveal that while confidentiality is supported through user authentication, vulnerabilities remain due to shared account usage and the absence of automatic log-off features. Data integrity is maintained through restricted editing rights, but the lack of an audit trail limits the system’s ability to detect unauthorized changes. Data availability is generally sufficient; however, reliance on manual backup processes exposes the system to potential data loss. The study highlights the need for enhanced audit mechanisms, automated backup solutions, and staff training to strengthen data security compliance with national regulations and international standards such as ISO 27001 and HIPAA. Strengthening these measures will help ensure that SIMPUS can function as a secure and reliable platform for managing electronic medical records in Indonesia’s primary healthcare system.References
-
Downloads
Published
Issue
Section
License
Authors who publish with IJIIS : International Journal on Informatics and Information Systems agree to the following terms: Authors retain copyright and grant the IJIIS : International Journal on Informatics and Information Systems right of first publication with the work simultaneously licensed under a Creative Commons Attribution License (CC BY-SA 4.0) that allows others to share (copy and redistribute the material in any medium or format) and adapt (remix, transform, and build upon the material) the work for any purpose, even commercially with an acknowledgement of the work's authorship and initial publication in IJIIS : International Journal on Informatics and Information Systems. Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in IJIIS : International Journal on Informatics and Information Systems. Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work (See The Effect of Open Access).

