[01]
Permenkes 24/2022
Electronic Medical Records — aligned with the 28-criteria assessment.
[02]
UU 27/2022 PDP
Consent, access, deletion, portability rights.
[03]
Audit trail
Tamper-evident audit trail (SHA-256 hash chain) over medical-record operations; retention policy follows Permenkes 24/2022 (5 yrs / 25 yrs for minors).
[04]
Encryption
Field-level AES-256-GCM for sensitive data at rest, TLS 1.2/1.3 in transit.
[05]
MFA
TOTP (RFC 6238) + passkey/WebAuthn + single-use backup codes; accounts can be required to use MFA.
[06]
Field-level encryption
Deterministic (searchable) for NIK, BPJS, and passport number; other sensitive data uses a random IV.
[07]
Granular RBAC
Scalable permission system per role and module, synced between application and database.
[08]
Electronic signature support
Adievia provides BSrE integration for hospitals that wish to enable e-signatures on medical resumes, doctor certificates, and clinical consent. The BSrE signature service and certificate are a separate subscription from the provider — not included in the Adievia license.
[09]
Legal hold
Data freeze mechanism for litigation support — scheduled for the pre-go-live hardening phase.
[10]
Backup verification
Periodic restore tests in sandbox — procedures verified and finalized in the pre-go-live phase.