[Regulatory Guide] Permenkes 24/2022

EMR under Permenkes 24/2022.

Criteria groups, the deadline, sanctions, and an EMR readiness checklist — explained by a vendor that builds its own system, complete with an honest mapping of what is already full and what is still being matured.

Summary

An EMR is not a suggestion — it is an obligation with a deadline.

Permenkes 24/2022 on Medical Records requires health facilities to implement Electronic Medical Records, with a deadline for implementation no later than 31 December 2023. Compliance is not merely installing an application — it demands meeting criteria for content, security, retention, and interoperability.

This guide maps those criteria thematically, explains the risk of non-compliance without scaremongering, and then presents a checklist hospitals can use to assess themselves.

28 criteria, 4 groups

What gets assessed.

The EMR assessment criteria can be grouped into four broad themes. This is a map to make them easier to assess, not a replacement for the official Permenkes text.

[01]

Implementation & medical record content

The EMR must be maintained from patient admission through discharge, capturing complete and structured medical record content (identity, history/SOAP, examination results, procedures, and care outcomes).

[02]

Data security & integrity

Protection of the confidentiality, integrity, and availability of data — covering access control, audit trails over medical record operations, and protection against unauthorized changes.

[03]

Storage & retention

Storage aligned with retention periods: patient medical records for at least 5 years from the last visit, with longer terms required for certain records.

[04]

Ownership, disclosure & interoperability

Data belongs to the patient/health facility with regulated access rights, plus readiness for data sharing (interoperability) — including connectivity to the national health data ecosystem.

Honest mapping to Adievia

What's full, and what's still being matured.

Transparency is our main weapon. Here it is as it stands — not a claim of "100% compliant".

Fully in production

  • Structured SOAP clinical documentation & e-prescriptions
  • Tamper-evident audit trail (SHA-256 hash chain) over medical record operations
  • Granular RBAC (access rights per role & module)
  • Retention policy with auto-flagged storage periods
  • Data export to standard formats (CSV, FHIR R4 JSON, SQL) — no vendor lock-in

Being matured (partial)

  • Full MFA coverage (TOTP/WebAuthn) — being matured
  • End-to-end field-level encryption for all sensitive data — partly complete
  • Complete audit trail across every criterion — refined incrementally
  • Legal hold (freezing data for litigation) — scheduled for the pre-launch phase
  • Formalized backup verification procedures — being matured toward launch

Self-assess

EMR readiness checklist.

Seven concise points to gauge how ready your hospital is — and, at the same time, a list of questions to put to a prospective vendor.

  • The EMR replaces paper across all core clinical workflows (not just the registration module)
  • Role-based access control and audit trails cover access to patient data
  • Sensitive data is protected both at rest and in transit
  • A retention policy is applied and can be demonstrated
  • Data can be exported at any time (no vendor lock-in)
  • The EMR is ready to serve as the data source for submission to SATUSEHAT
  • A data protection officer (DPO) & PDP policy are in place on the hospital side

FAQ

Questions about Permenkes 24/2022.

Permenkes 24/2022 (the medical records regulation) requires health facilities to implement Electronic Medical Records, with a deadline for implementation no later than 31 December 2023. After that, health facilities that have not adopted an EMR may be subject to guidance and administrative sanctions.

Non-compliance can lead to escalating administrative sanctions — starting with a warning, and affecting assessment/accreditation as well as licensing. Concrete sanctions follow the applicable guidance and oversight provisions; this page does not aim to alarm, but to map the risk reasonably.

EMR readiness assessment refers to a set of assessment criteria (often cited as 28 criteria) covering implementation, medical record content, security, retention, and interoperability. On this page we group them thematically and map them honestly to system capabilities — including the ones we are still maturing.

The EMR becomes the data source for submission to SATUSEHAT (interoperability), while UU 27/2022 (the personal data protection / PDP law) governs the protection of patients' personal data. All three are interconnected: a compliant EMR makes SATUSEHAT and PDP compliance easier at the same time.

Next step

Ready to close your EMR compliance gap?