Amid increasing demands for healthcare service quality, clinics are no longer only expected to provide excellent medical services. Compliance with regulations, document management, and patient data protection have now become inseparable components of healthcare facility governance.
These issues were discussed during an educational forum for clinic managers and healthcare professionals featuring Prof. drg. Suryono, S.H., M.M., Ph.D. as the main speaker. In his presentation, he warned that many legal issues faced by clinics originate from administrative negligence that is often considered insignificant.
According to him, clinic managers must understand that legal risks can arise from various aspects, ranging from incomplete licensing requirements to healthcare practices that do not comply with applicable regulations.
“The first thing is to avoid legal risks. Therefore, it is important to discuss legal matters from the perspective of an institution,” said Prof. Suryono.
He provided an example of doctor replacement practices, which frequently occur in several healthcare facilities. According to him, replacing doctors is permitted under certain circumstances but cannot be carried out routinely without following the appropriate mechanisms.
“Replacing one doctor with another has its own regulations. It should be incidental, not routine,” he explained.

Patient Data Is Becoming Increasingly Vulnerable
Beyond licensing issues, patient data protection has become a growing concern. Digital transformation in the healthcare sector has indeed simplified services, but it has also introduced new risks in the form of personal data breaches.
Prof. Suryono emphasized that medical records and all patient information are confidential data that must be protected.
“Patient data is confidential. We must not easily provide data to external parties without approval from the owner of that data,” he said.
According to him, data breaches are not only a matter of professional ethics but can also lead to serious legal consequences. Therefore, every clinic must have clear procedures regarding patient data management and access control.
The increasing adoption of electronic medical records has made data security issues even more relevant. On one hand, digitalization accelerates healthcare services. On the other hand, poorly prepared systems may create opportunities for data misuse.
Documents as a Line of Defense
During the forum, clinic managers were also reminded of the importance of maintaining complete legal and administrative documentation. Various documents, including operational permits, standard certificates, and medical records, must be properly stored and easily traceable when needed.
Experiences from handling various cases have shown that problems often become more complicated when healthcare facilities are unable to provide the supporting documents required during inspections or investigations.
Therefore, Prof. Suryono encouraged clinic managers to conduct regular evaluations of all documents and keep up with continuously changing regulations.
“Review every licensing document and medical record carefully. Monitor regulatory changes and adjust them according to current requirements,” he said.
The Challenge of Regulatory Adaptation
Changes in the licensing system through digital platforms such as the Online Single Submission (OSS) system also became a focus of discussion. Clinic managers were encouraged to understand business classifications, Business Identification Numbers (Nomor Induk Berusaha/NIB), and other administrative requirements to prevent future legal complications.
In practice, not all healthcare business operators have the same ability to adapt to regulatory changes. This situation makes socialization and assistance increasingly important.

Maintaining Trust as the Foundation
Behind all regulations and procedures lies one fundamental element of healthcare services: patient trust.
Patients visit clinics not only to receive treatment but also to provide highly sensitive personal information. When confidentiality is maintained, public trust will grow. Conversely, a single data breach can damage a reputation that has taken years to build.
Therefore, good clinic governance is not solely intended to fulfill legal obligations. More importantly, it represents a moral responsibility to protect the rights and dignity of every patient seeking assistance.
The discussion, which continued until the end of the event, demonstrated participants’ strong interest in issues related to data protection, diagnostic confidentiality, and legal compliance in healthcare practices. The continuous flow of questions reflected that today’s challenges in clinic management no longer exist only within examination rooms but also extend into governance and the protection of patient rights.
(Reporter: Andri Wicaksono, Photographer: Dody Hendro Wibowo)