Maintaining Patient Data Sovereignty in the Era of Smart Medical Navigation

1197

Author: Nagiot Cansalony Tambunan, Ministry of Health Policy Analyst and Member of INAKI

A major leap is underway in Indonesian medical research laboratories. The Indonesian Ministry of Health, along with local researchers, is currently overseeing a high-tech project developed by Indonesians: the Indonesian Spinal Navigation Device (NTBI). This intelligent, artificial intelligence-based device (Artificial Intelligence./AI) is designed to be able to read three-dimensional images from CT Scan The patient's condition is automatically assessed. Through intelligent algorithm processing, the system instantly calculates the safest mathematical route and direction for the doctor to insert the spinal stabilizing screws with millimeter accuracy to avoid the risk of fatal paralysis.

The presence of AI and cutting-edge innovations still in development at the research team level not only promises clinical efficiency but also carries the mission of protecting national strategic assets oriented towards Intellectual Property Rights (IPR). This awareness of protecting the IPR of the nation's children and securing the digital ecosystem aligns with the direction of the Ministry of Health leadership to provide standardized regulations governing how patient data is captured and stored by AI-based medical devices. This policy momentum is reinforced by intensive coordination so that the development of this smart navigation technology is fully supported and accelerated to quickly move to the trial phase. Regulatory Sandbox Ministry of Health. Although currently NTBI has not officially entered into sandbox In light of this, this research pause presents a crucial time for the government to examine a fundamental concern: how do we formulate adaptive laws that not only safeguard patient data privacy but also protect the intellectual property rights of local innovators from being unilaterally exploited by global tech giants?

Legal Gaps and the Threat of Clinical Bias

We must acknowledge the wide gap between the pace of digital innovation in research laboratories and the readiness of technical regulations in the healthcare sector. Indonesia has indeed enacted Law No. 17 of 2023 concerning Health and Government Regulation No. 28 of 2024 concerning Implementing Regulations for the Health Law. However, neither the Health Law nor the implementing regulations—including all derivative regulations currently issued—apparently lack specific norms capable of governing the dynamic and continuously learning characteristics of AI (continuous learning) in the context of medical service needs. Existing regulations still serve as general macro-legal umbrellas, such as the Personal Data Protection Law (PDP Law) No. 27/2022.

Also Read  MICROPLASTIC EXPOSURE CONTROL: A Strategic Agenda to Protect Indonesian Public Health

This specific norm vacuum is confirmed by empirical research from Brilliant, Jayanti, and Fikri (2026) in the journal Research Horizon (Legal and Ethical Challenges in Regulating the Use of Health TechnologyThey caution that positive law in Indonesia lacks the doctrinal readiness to address the ethical-legal complexities of AI-based medical technology. The static, conventional medical contract model leaves us unable to protect patients' digital rights while simultaneously raising the risk of algorithmic bias at the data collection stage.data acquisition).

If the AI ​​medical device is only trained using a data set (dataset) from one urban hospital in a large city, its medical navigation calculations may be inaccurate when applied to regional patients with different anatomical characteristics. This concern or risk was validated by Weiner's study. et al. (2025) in the journal PLOS Digital Health (Ethical Challenges and Evolving Strategies in the Integration of Artificial Intelligence into Clinical PracticeThey emphasized that bias in algorithm design is a real threat to clinical safety. To mitigate this risk, Indonesian regulations mandate the adoption of the international standard ISO/IEC 5259 (Data Quality Standard for Analytics and Machine Learning) to ensure completeness, annotation quality, and diversity. dataset medical.

Data Visitation, Digital Sovereignty and IPR Protection

The second risk that is no less looming is the threat to information sovereignty due to the lack of preparedness of data storage architecture (data storage). If research developers are forced to submit raw data (raw data) patients physically leave healthcare facilities to train AI, such actions are vulnerable to triggering cyber breaches. A scientific study by Price and Cohen (2019) in the journal Nature Medicine (Privacy in the Age of Medical Big Data) mathematically proves that medical big data processing is highly vulnerable to cyber re-identification attacks. Traditional anonymization methods have been shown to fail to protect privacy if raw data is allowed to be freely copied (data copying) by third parties.

Also Read  Mesenchymal Stem Cell Research, Balitbangkes Collaboration with Daewoong Infion to Find Alternative COVID-19 Therapy

​This is where the OECD (2021) report hits State of Implementation of the OECD AI Principles providing direction for global solutions. The OECD emphasizes the importance of the principles of technical accountability and traceability of data origin (data lineage) to build a trusted technology ecosystem (trustworthy AI). In line with the OECD accountability principle, Indonesia must make a paradigm leap through an approach Systemic Design (Systemic Design): moving from physical data delivery practices to mechanisms Visitation Data (Data Visit) using architecture Federated Learning.

This innovative step must be strictly monitored by the ISO/IEC 23894:2023 standard (Guidelines for Artificial Intelligence Risk Management). Through ISO/IEC 23894:2023, the ministry identifies and mitigates the risks of AI model performance degradation (model drift) throughout the technology life cycle. In the regulatory blueprint, this risk management is operationalized through policies Zero-Copy Architecture in the Secure Data Environment (SDE). AI algorithms act as “guests” that visit the data behind firewall Local health facilities. The only output allowed is the model parameter weights encrypted using AES-256 (256-bit Symmetric Block Encryption Standard).

This storage strategy must be supported by strengthening national strategic infrastructure. Indonesia currently only has one National Data Center (PDN), operating in Cikarang, West Java. The government's plan to establish two additional PDNs in Batam, Riau Islands, and the capital city of Indonesia (IKN) must be accelerated and secured by the Ministry of Health as the primary database for processing national health AI algorithms.

Paradigm Visitation Data and this local PDN-based SDE revolutionarily protects the IPR interests of national research teams. By locking dataset local clinical within domestic servers (date of residence), ownership of data assets will not be transferred to foreign infrastructure corporations. Local developers, like the NTBI research team, retain full control over the intellectual property, in the form of the unique algorithmic model formulations they develop, without the risk of their data being "stolen" or unilaterally commercialized by global entities.

Also Read  Capacity Building HTA

Returning Autonomy to the Patient

Ultimately, the strongest bulwark of health technology governance is the enforcement of human-centered ethical values ​​(human-centricThe 2021 World Health Organization (WHO) global guidance document on the Ethics and Governance of AI in Health strictly mandates that the integration of AI in medicine must not infringe on patient autonomy (patient autonomy). WHO strongly rejects the blanket model of consent for medical procedures (blanket consent) without transparent details of secondary data utilization.

The Indonesian Ministry of Health must embody the WHO's ethical mandate and the OECD's accountability principles by injecting features Dynamic & Layered Consent directly into the SatuSehat Mobile platform. Medical consent forms must clearly separate the primary purpose of medical services from the secondary purpose of using medical data for AI development. If patients object, they must be provided with the right to digitally withdraw their data (Opt-out) at any time of the algorithm training cycle without losing their basic right to standard health care.

Although currently NTBI spinal navigation technology is still being developed at the research team level, the Ministry of Health has a golden opportunity in history to produce down-to-earth but globally standardized regulations before this innovation moves to the next stage. Regulatory SandboxBy combining ISO/IEC 23894:2023 risk protection, ISO/IEC 5259-based data quality control, AES-256 encryption-based cybersecurity, and WHO-approved patient rights protection, we are sending a clear message to the world: Indonesia is ready to celebrate the future of medical technology and protect the intellectual property rights of its citizens, without compromising the privacy of its citizens and national health sovereignty.