Data Security at HealthCore

Access control, activity logging, and credential encryption. Security layers already running in the system today.

Role-Based Access Control (RBAC) and MFA

Access is controlled with JWT and RBAC for five roles (admin, doctor, nurse, registration, pharmacist), with TOTP two-factor authentication.

  • JWT for user authentication sessions
  • Five-role RBAC: admin, doctor, nurse, registration, pharmacist
  • TOTP MFA for two-factor authentication

Comprehensive Audit Log for Every User Action

Every important data change is recorded in a global audit log with actor, module, and change status to support operational accountability.

  • Global audit log running at the middleware level
  • Actor, module, and change status are recorded
  • Supports governance and internal review

Credential Encryption

User credentials are hashed with bcrypt. Integration credential fields (for example for SATUSEHAT and BPJS VClaim) are encrypted with AES-256-GCM.

Personal Data Protection

Data access and logging flows in HealthCore are designed with attention to personal data protection principles under the Indonesian PDP Act (UU PDP).

SATUSEHAT and BPJS Integration Readiness

Integrated with SATUSEHAT and BPJS VClaim, prepared within the shared implementation package.

  • SATUSEHAT with FHIR R4 resource mapping
  • BPJS VClaim with protocol, HMAC signing, and encrypted response handling
Need a custom quote?

We tailor packages based on your facility needs and scale.

Talk to Sales Team