[Clinical Module] Electronic Medical Records

Electronic Medical Records for Hospitals.

The core of a compliant HMS: structured SOAP clinical documentation, e-prescribing, attending physician signatures, and a tamper-evident audit trail — designed with reference to the 28 criteria of Permenkes 24/2022, with data that stays entirely owned by the hospital.

Context

EMR is not just paperless digitization — it is a regulatory obligation.

Electronic Medical Records (EMR) is the electronic recording of a patient’s health history. Since Permenkes 24/2022, running an EMR is mandatory for healthcare facilities — not optional. A proper EMR is not merely a "digital form", but a system that safeguards data integrity, security, retention, and openness to the applicable standards.

Adievia EMR is built from the code up by practitioners who understood these rules from the start — compliance is embedded in the architecture, not patched on after an audit. This page explains what already runs fully and what is still being matured, as it is.

Read the full guide to the 28 criteria of Permenkes 24/2022

Workflow

From registration to attending physician signature.

One connected clinical flow — no duplicate entry between units, because the EMR is the backbone of every other module.

[01]

Registration & identification

Patient registration is linked to automatic BPJS SEP issuance in outpatient care; a single patient identity is used across every clinical and financial module.

[02]

SOAP assessment

Structured clinical documentation (Subjective, Objective, Assessment, Plan) with per-unit templates — not free-text notes that are hard to audit.

[03]

E-prescribing

Electronic prescribing linked to the Pharmacy module (real-time dispensing) and narcotics control in line with Permenkes 4/2018 (the narcotics prescribing regulation).

[04]

Attending physician signature

Signing of clinical documents by the attending physician (DPJP). For certified electronic signatures, BSrE integration is available (module ready; the certificate subscription is arranged separately by the hospital).

Security & integrity

Built to be auditable.

Medical-record data is the most sensitive data in a hospital. Here are the technical controls that protect it — including those we are still maturing.

[01]

Tamper-evident audit trail

Every medical-record operation is written to a tamper-evident audit trail based on a SHA-256 hash chain, so data changes remain traceable.

[02]

Field-level AES-256-GCM encryption

Sensitive data is encrypted at the column level at rest; transport is secured with TLS 1.2/1.3. Part of the field coverage is still being matured toward launch.

[03]

Granular RBAC

Access rights per role and per module, kept in sync between the application and the database — access to patient data follows the need-to-know principle.

[04]

MFA (being matured)

TOTP (RFC 6238), passkey/WebAuthn, and backup-code options are being matured; accounts can be required to use MFA once the feature is finalized.

An honest note: the DPO, data-protection policy, and organizational compliance remain the responsibility of the hospital as data controller. Adievia provides the technical controls — it does not replace organizational compliance.

Connected

The EMR becomes the source of truth for the whole system.

Because the EMR is the backbone, data flows to other clinical modules — Emergency, ICU, Outpatient & Inpatient, Pharmacy, Laboratory, Radiology — without re-entry.

FAQ

Questions about Adievia EMR.

Adievia EMR is designed with reference to the 28 assessment criteria of Permenkes 24/2022 (the electronic medical records regulation) from the architecture up. Some controls already run fully (structured SOAP, e-prescribing, hash-chain audit trail, retention policy), while others — such as MFA coverage, comprehensive field-level encryption, legal hold, and backup verification — are still being finalized toward launch. We state this status as it is, rather than claiming to be "100% compliant".

In line with Permenkes 24/2022: patient medical records are kept for at least 5 years from the last visit, and children’s medical records follow longer retention provisions. The system auto-flags records when the retention period is reached.

Yes. Hospital data can be exported to standard CSV, FHIR R4 JSON, and SQL dump formats at any time. There is no vendor lock-in — data ownership stays with the hospital.

The EMR is the data source for bridging to SATUSEHAT (FHIR R4 resource mapping). The bridging module is ready; production activation follows each hospital’s organization registration and SATUSEHAT certification.

Next step

Ready to evaluate an EMR that is honest about compliance?