Data Security at HealthCore
Access control, activity logging, and credential encryption. Security layers already running in the system today.
Role-Based Access Control (RBAC) and MFA
Access is controlled with JWT and RBAC for five roles (admin, doctor, nurse, registration, pharmacist), with TOTP two-factor authentication.
- JWT for user authentication sessions
- Five-role RBAC: admin, doctor, nurse, registration, pharmacist
- TOTP MFA for two-factor authentication
Comprehensive Audit Log for Every User Action
Every important data change is recorded in a global audit log with actor, module, and change status to support operational accountability.
- Global audit log running at the middleware level
- Actor, module, and change status are recorded
- Supports governance and internal review
Credential Encryption
User credentials are hashed with bcrypt. Integration credential fields (for example for SATUSEHAT and BPJS VClaim) are encrypted with AES-256-GCM.
Personal Data Protection
Data access and logging flows in HealthCore are designed with attention to personal data protection principles under the Indonesian PDP Act (UU PDP).
SATUSEHAT and BPJS Integration Readiness
Integrated with SATUSEHAT and BPJS VClaim, prepared within the shared implementation package.
- SATUSEHAT with FHIR R4 resource mapping
- BPJS VClaim with protocol, HMAC signing, and encrypted response handling