<<

21st Century Challenges: A Connected Health Approach Megatrends in Health care

1 To find out more about Deloitte Indonesia Life Sciences and Health Care, please scan the QR code below:

2 ABBREVIATIONS

ANNCEH Australian National Consultative Committee on Electronic Health APBN National State Budget APJII Asosiasi Penyelenggara Jasa Internet Indonesia/ Association of Indonesian Internet Service Providers APP Australian Privacy Principle ATA American Telemedicine Association ART Assisted Reproductive Technology ARV Anti-Retroviral Virus ASCOF Adult Social Care Outcomes Framework ASEAN Association of Southeast Asian Nation BPJS Badan Penyelenggara Jaminan Sosial CPME Standing Committee of European Doctors CPG Clinical Practical Guidelines CFR Code of Federal Regulation CGAR compound annual growth rate CMS Centers for Medicare & Medicaid Service CoPs Conditions of Participations CISS Computer Information Security Standards CFR Code of Federal Regulations CQRS Calculating Quality Reporting Service CP-IS The Child Protection – Information Sharing project CSS Clinical Support System CTG Cardiotography CoPS Conditions of Participation CMS The Centers for Medicare & Medicaid Service CSS Clinical Support System CUI Common User Interface DAQs Digital Assessment Questionnaire DARS Data Access Request Service DoS The Directory of Services DSA Digital Signature Act EHR Electronic Health Records EYS expected years of schooling ECA Electronic Commerce Act ECEG Ethical Code Ethical Guidelines ECG Electrocardiogram EDB Electronic Development Board

3 EEA European Economic Area EHR Electronic Health Record EHealth Digital Health or technology-based health care EMR e-Medical Record EPS Electronic Prescription Service ERP Electronic medical record Support for Public health ETA Electronic Transaction Act ETP Electronic Transfer of Prescriptions FSMB Federation of State Medical Boards FDA Food and Drug Administration (U.S. FDA) FSMB Federation of State Medical Board GDPR General Data Protection Regulation GMC General Medical Council GPs General Practitioners GNI Gross national income GNIpc Gross national income per capita HAS Health Science Authority HDG Health Data Grid HDI Human Development Index HES Episode Statistics HHS Health and Human Services HIMSS Health care Information Management and Support Services HSCIC Health and Social Care Information Centre HIV/AIDS Human Immunodeficiency Virus/Acquired Immunodeficiency Syndrome HITECHT Health Information Technology for Economic and Clinical Health HHS Health and Human Services ICO Information Commissioner’s Office ICT Information and Communications Technology IDI Ikatan Dokter Indonesia IKO Indonesian Kalkulator of Oocytes IVF In Vitro Fertilization ITT Innovation and Technology Tariff Technical Notes JKN Jaminan Kesehatan Nasional/National Health Insurance LE Life expectancy Kemenkes Kementerian Kesehatan/Ministry of Health KIS Kartu Indonesia Sehat/Healthy Indonesia Card MAS Monetary Authority of Singapore MMC Malaysian Medical Council MHealth Mobile Health MIMS Monthly Index Medical Specialities MYS Mean years of schooling

4 NHS National Health Service NICE National Institute for Health and Care Excellence NESAF National eHealth Security and Access Framework NEHTA National eHealth Transition Authority OECD Organization for Economic Cooperation and Development ODHA Orang dengan HIV AIDS/People Living with HIV PDPA Personal Data Protection Act PES Prescription Exchange Service PHFCSA Private Health Care Facilities and Services Act PHFCSR Private Health Care Facilities and Services Regulation PHI Protected Health Information PRO Patients Relation Officer PLHP Personalized Lifetime Health Plan PLN Perusahaan Listrik Negara/State-owned electricity company RAG Research Advisory Group RSPI Rumah Sakit Pondok Indah R1 Release One R2 Release Two SSA Social Security Act SMC Handbook Singapore Medical Council Handbook SCR Summary Care Record SIRS Systemic Inflammatory Response Syndrome SNTG Singapore National Telemedicine Guidelines SUS Secondary Uses Practice TPO Treatment, payment, or health operation TJC The Join Commission UK United Kingdom U.S. FDA United States Food and Drug Administration WHO World Health Organization Yankes Pelayanan Kesehatan/Health Service

5 6 Foreword

With the fourth largest population in the world, Indonesia has a potential in the development of digital health technology (eHealth). The technology is expected to facilitate the people of Indonesian to gain health access more easily, which will be a benefit for more than 260 million people who lived in 17.504 islands spreadly in the country. Along with the growing eHealth industry in the country, Deloitte Indonesia, Bahar Law Firm, and Chapters Indonesia are starting to conduct a study on eHealth industry, which covers the industry growth, various type of eHealth business and services, applications, the use of technology as part of the hospital services, existing infrastructure, legal comparative studies in several countries, and a proposed road map of the eHealth development in Indonesia. The study is the first research publication on eHealth in the country, with the purpose to give inputs to the related stakeholders, specifically to the government to develop and strengthen the eHealth infrastructure for the common good.

The digital revolution in health sector is driven by eHealth development and innovation, which leads to the peer to peer approach that enable the users to share and looking for latest information, long distance-consultation with medical practitioner, which include e-prescribing, and sharing patient’s health documents sharing. The digital health development will lead to open health technology, where the users are able to have open access to more convenient ways in approaching health services.

On the other side of the coin the peer to peer (P2P) technology has an issue on the data security that can give a serious impact in the technology utilization. This issue can make a serious impact in the eHealth business continuity. The team has conducted study comparation in infrastructure and regulation with other countries, where eHealth become part of the daily life and the result shows that the business, government, association, and other related stakeholders should work together to prepare proper infrastructure and regulation to protect the users (community) and business players in the industry.

We hope that the results of this study will be a valuable input for the relevant ministries to promote infrastructure improvements in the field of eHealth which aims to protect the interests of the community and future eHealth advancements. Looking at these problems, this paper aims to deliver an outlook and recommendation for Indonesian regulators, policy makers, academics, business owners, and users about the upcoming future trends in Indonesian health care system.

7 Deloitte Indonesia, Bahar Law Firm, and Chapters Indonesia

Deloitte Indonesia Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited (“DTTL”), its global network of member firms, and their related entities. DTTL (also referred to as “Deloitte Global”) and each of its member firms are legally separate and independent entities. DTTL does not provide services to clients. Please see www.deloitte.com/about to learn more.

Deloitte is a leading global provider of audit and assurance, consulting, financial advisory, risk advisory, tax and related services. Our network of member firms in more than 150 countries and territories serves four out of five Fortune Global 500® companies. Learn how Deloitte’s approximately 264,000 people make an impact that matters at www.deloitte.com.

In Indonesia, services are provided by Imelda & Rekan, Deloitte Touche Solutions and PT Deloitte Konsultan Indonesia.

Bahar Law Firm Bahar is one of Indonesia’s leading boutique law firms, providing the highest quality legal services to domestic and international clients since 1992. To better tailor our services the firm is structured around the formation of specialist practice groups. There are currently four of these: Trade, Tourism and Industry; Transportation; Utilities & Project Finance; and Digital Business & Technology. Each group provides targeted end-to-end services to the relevant sector and is qualified to deal with the full range of transactions, including mergers, acquisitions and capital markets.

CHAPTERS Founded by Dr.Luthfi Mardiansyah in mid of 2017, Center for Healthcare Policy and Reform Studies (CHAPTERS), a non-profit institution, continue doing some studies on health care system in Indonesia, to educate people and provide analysis and insight to government not limited to KSP, Kemenkes, BPJS etc. CHAPTERS have conducted several public discussions including Media Gathering, Drug Procurement & Distribution System at JKN era , Kaleidoscope Indonesia Health Care System 2017, Indonesia Outlook 2018 and Rare Diseases Forum recently in Sept. The vision of CHAPTERS is “To Dedicate our Outmost Expertise and Initiative for Better Healthcare Environment in Indonesia”. Please visit our website www.chapters-id.com for more information.

8 Table of Contents:

Introduction 10

Unlocking The Opportunity of Digital Health 11

What are the Differences Between Telehealth, Telemedicine, and eHealth? 12

Telehealth Modalities 13

Indonesia’s Health Care Overview 13

Current eHealth implementation 19 eHealth Regulatory Issues 47

9 Introduction

The great forces in human and technology In the side of digitalized futures, technology development that affect the future in all areas and health care innovation have led to “Open of human activity, which known as megatrends1 Health” or peer-to-peer health that enables in the John Naisbitt and Patricia Aburdene’s sharing of knowledge with innovation as famous book with similar title, seem very critical shift. A digital revolution in health close to us now. Its keys that are predicted to care is speeding up. Telemedicine, predictive be happened very soon are digitalized future diagnostics, wearable sensors and a host of (technology and health care innovation), new applications will transform how people globalized industries and commodification, manage their health2. This is an evidence that universal or non-universal provision of health health care change is not immune. There is care, politics, discontinuity and demographic most likely to occur that a convergence of shifts. In terms of health care issue, the future trends will create discontinuous and abrupt are shaped by a convergence of drivers, needs changes in health care systems, no matter how and wants both in and outside of health advanced or rudimentary. care that will bring the future to a different way where we are now. There is a significant There is a rapidly growing number of health increase in the scope of possibilities for health care innovations on the horizon that both care future – health care provision will no excite and concern policy-makers. On the longer linear and continuous, predictable or other hand, policies that shape health care are immune from disruptive change. typically considered as conservative especially

Discontinuity Predictions were based on continuity from the past. With incoming disruptions, discontinuity will be the new normal.

Politics Demographic Shifts Traditional policy and regulation Key Climate change, urbanisation, making will no longer work as we increased chronic care, changing move into value-based care. Policy subtance use & global paramedics makers must drive accountability Megatrends such as viral illness & mental health from all parties, providers, public and decline are key shifts in today’s world. private.

Universal or Non-Universal Digitalised Futures: Provision of Health care Technology & Health care Universal health care as a system is Innovation financially unsustainable. The trend is to Soft changes such as the move towards move into more privatised systems, inner technologies are increasing. “Open acommodification of health care. Health” or peer-to-peer health enables sharing of knowledge with innovations as critical shift.

Globalised Industries + Commodification A new era has emerged where democratisation of health, education, science and arts is discrupting dominant models of private enterprise and government.

1 Naisbitt, J. and Aburdene, P., 1991. Megatrends 2000—Ten Dir ections for the 1990s. Megatrends 2000: Ten Directions for the 1990s. 2 https://www.economist.com/news/business/21717990-telemedicine-predictive-diagnostics-wearable-sensors-and-host-new-apps-will- transform-how

10 in terms of traditional models of clinical practice -but it is generally subjected- to measures of and provision. Although costing, large corporate interests, traditional the nature of health care is shifting dramatically clinical practice models and the development of away from these patterns of the past3, national policy. providers, governments, large corporations, insurance companies, and the clinical caregivers themselves; all seem constrained by the dogma originating from attitudes and practices from the last century. Yet, there is considerable pressure from societies for providers to become more accountable, relevant and responsive while providing greater and more equitable access to health care and well-being. The response of this pressure varies

2022 HEALTHCARE PREDICTIONS

The quantified self is alive and well • The genome generation is more informed and engaged in managing their own health

The culture in healthcare is transformed by digital technologies • Smart health care is delivering more cost-effective patient-centered care

The life sciences industry is industrialized • Advanced cognitive technologies have improved the productivity, speed and compliance of core processes Data is the new healthcare currency • Artificial intelligence and real-world evidence are unlocking value in health data

The future of is here and now • Exponential advances in life-extending and precision therapies are improving outcomes

New entrants are disrupting healthcare • The boundaries between stakeholders have become increasingly blurred

Unlocking the opportunity of digital health managing health care has been changing. The digital age holds out the promise of To be part of the competitive industry today, innovative technology and business models. health care providers need to address the Most critically, internet and smartphone major changes that are driving patient behavior penetration is growing, and the technology and adopt a customer service mindset. This infrastructure is moving to cloud-based emerging demand for customer centric services. care is driving innovation and transforming the patient-centered experience – from Along with the development of technology appointment scheduling to timely access to and the competition in business environment, billing information and transparency in health care purchasing decisions.

3 http://www.iftf.org/fileadmin/user_upload/downloads/hh/Report_U.S.Analysis_of_FutureHealthIndex.pdf

11 The proses is also manifested generally at the Telemedicine is defined by the WHO as “the use systemic level through peer-to-peer health of information and communications technology and advanced wearables that allow direct (ICT) to deliver health care particularly in personalized health information. Individuals settings where access to medical services are better informed about their symptoms and is insufficient”. The term telemedicine diseases they have and might have, and the has historically been used to refer the use availability of health care. of electronic communications channel or mediums, as well as information technology to Expectations of health care and better deliver clinical services to remote patients with outcomes for themselves are at their highest. the goal of improving a person health’s status5. Patients are true consumers, they understand they have options and use information and The broadest term in this comparison is data about themselves and provides to get telehealth. The term telehealth incorporates the best treatment at a time, place and cost not only technologies that fall under convenient to them. “telemedicine,” but also direct, electronic patient-to-provider interactions and the use of According to Forbes and Business Insider, medical devices (e.g., smartphone applications the global health care industry will initiate a (“apps”), activity trackers, automated reminders, joint progression with the data analytics and blood glucose monitors, etc.) to collect and technology industries. A research conducted transmit health information, often with by RNR Market Research forecasted a rapid the intent to monitor or manage chronic and significant compound annual growth rate conditions6. The use of telehealth also helps (CAGR) in the global telehealth industry of 27 with developing and improving health-related percent by 2021. education, health administration, and improving general public health7. Health care practitioners should keep in mind that medicine must always be patient-centric In the United Kingdom and other European treatment, and technology is merely a tool countries, the term ‘eHealth’ is also used to to improve the patient’s health outcome. describe digital health and technology-driven This approach is not about purely relying on remote health care. Barely in use before 1999; technologies or making decisions without this term now seems to serve as a general referring to any data, but to utilize state-of- “buzzword,” used to characterize not only the-art technologies that improve health care “internet medicine”, but also virtually everything services. Doing this way, professionals should related to computers and medicine. The term also have time to provide the human touch. was apparently first used by industry leaders and marketing people rather than academics. What are the Differences Between They created and used this term in line Telehealth, Telemedicine, and eHealth? with other “e-words” such as e-commerce, We often use the terms of telemedicine, e-business, e-solutions, and etc., the use telehealth, and eHealth to describe the use of of these terms is intended to convey the information technology system in health care promises, principles, excitement (and hype) industry to provide an easier access between around e-commerce (electronic commerce) health care providers and patients, especially to the health arena, and to give an account of from remote area. The terms are used to the new possibilities the internet is opening up describe a broad concept within health care, to the area of health care8. The term eHealth the use of mobile and desktop technology is generally used to describe an even broader for patient’s health care self-management. All scope of digital information tools, ranging from terms are used interchangeably but represent a electronic health records (EHRs), which facilitate different use of technology within health care4. the exchange of patient data between health However, is there any differences between care professionals. those three terminologies?

4 https://www.talkingmedicines.com/digital-health-terms-ehealth-mhealth-telehealth-telemedicine/ 5 http://electronichealthreporter.com/dividing-eHealth-telehealth-and-telemedicine/, accessed on 18 May 2018 6 https://aspe.hhs.gov/system/files/pdf/206751/Telemedicinee-HealthReport.pdf, accessed on 18 May 2018 7 http://electronichealthreporter.com/dividing-e-health-telehealth-and-telemedicine/, accessed on 18 May 2018 8 https://www.ncbi.nlm.nih.gov/pmc/articles/PMC1761894/ 12 EHealth may include computerized physician interface. As matched to a real-time physical order entry mechanisms, e-prescribing, and visit, this type of service provides an access clinical decision support tools, which provide to the health data subsequently it has been electronic information about protocols and gathered, and will involve communication standards for use in diagnosing and treating tools such as a secure email. patients to providers9. The concept of eHealth • Remote Patient : Personal is not limited only to provide long-distance health and medical data gathering from health care, but also to increase health care an individual in a certain location through efficiency as a whole10. electronic communication technologies, which is transmitted to a provider or Telehealth Modalities occasionally through a data processing Telehealth can employ a multitude of modern service in a different location for use in care technologies, transmitting information via and related support. This type of service text, audio, video, or still images to a range of allows a provider to resume tracking the medical specialists. This technology is relevant health care data for a patient once they have to a variety of disciplines including dermatology, been released back to their home or a care radiology, and cardiology. With a simple internet facility. This method reduces readmission connection, patients can conducting video rates. conference with a health care professional • Mobile Health: When mobile communication half-way around the world or sending MRI devices such as cell phones, tablet scans result through email for medical analysis. computers and PDAs support health care More remarkably, without any face-to-face and public health practice and education. interaction, doctors can distantly monitor the Applications can range from targeted text blood pressure or glucose levels of a ’s messages that promote healthy behavior to patients through a computer screen. wide-scale alerts about disease outbreaks.

In the future of the health care industry, Indonesia’s Health Care Overview telehealth almost likely will involves four Strong economic growth is leading Indonesia distinct domains of application those are towards middle-income country status. The commonly known as synchronous (live video), growth is unfortunately does not reflect in asynchronous (store-and-forward), Remote the government’s budget allocation’s national Patient Monitoring (RPM) and mobile health health budget, which is relatively low (2.9 (m-Health)12. percent of Indonesia’s total gross domestic • Synchronous domain: A live and two- product (GDP) in 2014, or 5.0 percent of the ways interaction between a person National State Budget (Anggaran Pendapatan that could act as a patient, caregiver, or dan Belanja Negara/APBN)) in 2017 - leading to provider and a provider using audiovisual insufficient facilities and workforce needed for telecommunications technology. This form public services, and encouraging the growth of service is also denoted as the “real-time” of private health facilities13. Decentralization service and might function as a substitute for has also affected the capacity of the central a real live in-person encounter when it is not Ministry of Health to maintain integration and possible. alignment across the different levels of the • Asynchronous domain: A type of health system14. transmission of recorded health history, the examples are pre-recorded videos and However, Indonesia’s health care spending is digital images (X-rays and photos) through expected to be driven by aging and growing a secure electronic communications system populations, developing market expansion, to a specialist practitioner, who uses the clinical and technological advances, and rising information to evaluate the case or render labor costs. As health care costs increases, the a service outside of a real-time or live government is pushing health care affordability

9 https://aspe.hhs.gov/system/files/pdf/206751/TelemedicineE-HealthReport.pdf, accessed on 18 May 2018 10 Ibid. 11 https://www.hcs.harvard.edu/hghr/print/spring-2011/telemedicine-developing/ 12 Center for Connected (CCHP) 13 https://www.kemenkeu.go.id/apbn2017 14 http://apps.who.int/iris/bitstream/10665/254716/1/9789290225164-eng.pdf

13 through universal health care insurance of time, namely: (1) to increase the maternal coverage (Jaminan Kesehatan Nasional- and child health status; (2) to increase disease Kartu Indonesia Sehat (JKN-KIS)) even though control effort; (3) to increase access and quality implementation wise is challenging. of and referral system, especially in remote, rural and disadvantage areas; (4) to All of the efforts conducted by the Government increase the coverage and quality management of Indonesia (GoI) in health sector is part of the of universal health care through Indonesian efforts to reach Indonesia’s national target as Care Insurance Coverage (Jaminan Kesehatan written in the National Mid-Term Development Nasional - Kartu Indonesia Sehat/JKN-KIS); (5) Plan (RPJMN) 2015-2019, which is to make fulfillment of health care workers, Indonesian people live healthier. Under this and vaccines; (6) to improve responsiveness of national target, there are six main goals of the health care system. Few RJPMN indicators that programs which implemented during the range is in-line with the implementation of eHealth includes:

Indicators Initial status Target (2019) Availability of accredited public primary care 0 (2014) 5,600 (82%) in districts across Indonesia

Availability of accredited regional public 10 (2014) 481 (94%) hospitals in cities across Indonesia

Coverage for national social security system 51.8 (2014) 95% (Sistem Jaminan Sosial Nasional / SJSN)

The following national target after 2019 is to growth rate of Indonesia between the year provide all of Indonesian people access to 2000 and 2010 stood at an average of 1.49 qualified health service in 2025. This seems percent. Surprisingly, the growth does not quite far comparing to the recent situation spread evenly, the highest was in the eastern regarding health access. of Indonesia, Papua (5.46 percent) and lowest With a population totaling around of 260 was in Central Java (0.37 percent)15. The rapid million individuals, Indonesia is now the fourth- growth and the fact that Indonesia is the largest country in terms of population size. The largest archipelago in the worlds makes it growth will continuously occurs, as stated by challenging to support and escalate the health the United Nations (UN) that the population of care services, especially in remote areas of Indonesia is estimated to exceed 270 million Indonesia. by 2025, exceed around 285 million by 2035 and another 290 million by 2045. Out of the population issue, Indonesia is often referred as the largest archipelago in the world with an estimation of 17,504 islands. The population

15 https://www.indonesia-investments.com/culture/population/item67?

14 Other issue that raised, is the health care with accessibility and quality of health care, as facilities and resources. Indonesia has a low hospitals and medical professionals are highly number of beds compared to other countries concentrated in big cities especially Jakarta. in Association of Southeast Asian Nations On the other hand, in accordance with the 9th (ASEAN)16 and Organization for Economic Package of Commitments under the ASEAN Cooperation and Development (OECD)17. Some Framework Agreement on Services (AFAS 9), health care facilities are severely underfunded, non-Indonesian physicians and dentists are and in many cases do not meet certain not allowed by the law to provide direct patient standards. Meanwhile, regarding health care care unless it is under the auspices of “transfer professional resources in Indonesia, according of knowledge”, such as training, social service, to World Health Organization (WHO) data, as and research. of in 2016, for every 1,000 residents, there are only 0.16 doctors available, this figure is lower than the average of countries in Southeast Asia (at 0.6 doctors for every 1,000 residents) and far lower than in the developed countries, such as Germany, which has 3.7 beds for every 1,000 residents. A critical note is that there are issues

16 Luthfi Mardiansyah’s presentation in Deloitte Hospital Summit, 2017 17 http://stats.oecd.org/index.aspx?queryid=30183, https://en.wikipedia.org/wiki/List_of_OECD_countries_by_hospital_beds

15 Source: Deloitte Hospital Summit, OECD, 2016 Source: Deloitte Hospital Summit, 2017 and Indonesia Health Profile, Ministry of Health, 2016

Source: Indonesia Health Profile, Ministry of Health, 2016 Source: Indonesia Health Profile, Ministry of Health, 2016

Lack of sophisticated health infrastructure in both inside and outside of their country Indonesia has also been causing Indonesian’s (including Indonesia). Overseas countries with a wealthy people to go abroad in seeking more developed technology in health care such better medical treatments, as neighboring as Singapore, Malaysia, Japan, Australia, USA countries’ health care providers are perceived and Germany are also getting involved in health as adequate to provide affordable high quality care provision in Indonesia - they are trying to care and services. Notably, in trends with meet the rising demand of high-quality health technological innovations, it has motivated care facilities18. some of those providers to develop the applications of telemedicine – targeting patients

18 International relation’s within Indonesia’s hospital sector, Dono Widiatmoko Ascobat Gani

16 Telehealth is going to be very beneficial for Dr. Nyoman Adhiarna both the developer and consumer when it is successfully implemented in Indonesia. Dr. E-Business Director, Ministry Nyoman Adhiarna, E-Business Director, Ministry of Communications and of Communication and Information Technology said that eHealth is an interesting tools, as the Information, the Government digital-based health service application will of Indonesia. benefitted the society. Indonesian population has been also utilizing internet for their health needs. For example, in regards of Indonesian “eHealth is an interesting tools, as internet usage specifically in health care the digital-based health service sector, internet is utilized for browsing health information (51.06 percent) and to consult with application will benefitted the health care professionals (14.05 percent)19. society. However, Indonesia needs Internet Utilization in Health Care to speed up the issuance of ehealth Sector regulation.”

In the near future eHealth will not just appeal centricity and data integrity, even to solve the to the wealthier-end of the Indonesian occupational health future workforce crisis. populations, but also can benefit the poorer- The e-Business Director of the Ministry of end of the Indonesian populations – especially Communication and Information Technology those located in underdeveloped rural areas. mentioned that there are three big issues Hence, both public and private sectors in in eHealth practice, which are user personal Indonesia are leveraging digital technologies. data protection, responsibility of the electronic The government has implemented digital system vendor on the information technology technology, particularly to reach patients in and electronic-based health services risk, underserved areas and to better serve JKN and important role of the central data office. participants. In private sectors, companies and The following descriptions on the practice in startups in life science and health care are Indonesia will show the development of the developing sporadically. They are leveraging eHealth practice in the country. digital technologies to improve health care service and accessibility, building patient

19 Teknopreneur.com, Asosiasi Penyelenggaran Jasa Internet Indonesia (APJII), 2017. Infografis Penetrasi & Perilaku Pengguna Internet Indonesia.

17 Dr. Nyoman Adhiarna Although health care blockchain presents numerous opportunities for health care; E-Business Director, Ministry however, it is still immature and cannot be of Communications and immediately applied. Several concerns and challenges in its practicality have also arise: data Information, the Government anonymity, cost on establishing the technology, of Indonesia. regulations and individuals’ willingness in participating are still in questioned. Other than that, various technical, organizational, “There are three big issues in and behavioral economics challenges must be eHealth practice: user personal carefully analyzed before blockchain technology can be adopted by health care organizations data protection, responsibility of nationwide. the electronic system vendor on the information technology and electronic-based health services risk, and the important role of the central data office.”

Blockchain Technology in Health Care Blockchain technology has the potential to transform health care system by simplifies data storage, increasing security, privacy, and interoperability of health data. Blockchain technology is a distributed system for recording and storing transaction records. It is a decentralized database capable of keeping secure and validated records of digital transactions. When new transactions take place, it will be grouped together with other transactions that occurred within a short time window, called a block, and sent out to that ledger’s network and all digital health events are recorded in a way that does not allow for the data to be changed or recognized until it reaches the recipient.

Blockchain technology creates unique opportunities in health care ecosystem, especially brings improvement in Health Information Exchange. It enables disintermediation of trust in exchanging health data, reducing transaction and administrative costs by making the system more efficient, enhance security in protecting patient identities, sharing real-time data across parties and secure data access.

20 https://nasional.sindonews.com/read/1019210/149/makassar-sehat-dengan-home-care-telemedicine-1435804869; dr. HJ. Naisyah T. Azikin, M.Kes (Kepala Dinas Kesehatan Kota Makassar)’s presentation: Pelayanan Telemedisin Kota Makassar (Telemedicine Service in Makassar) 21 https://nasional.sindonews.com/read/1019210/149/makassar-sehat-dengan-home-care-telemedicine-1435804869

18 Current eHealth implementation 24-hour Health Care Service in Makassar Public Sector Indonesia Government’s initiatives in digital health including:

1. Makassar’s 24-hour-homecare/ telemedicine and tele-radiology The previous Makassar’s city municipal, Ramdhan Pomanto, has initiated in implementing technology-based health care services for the sake of health equality in the city and its surrounding areas. Located in eastern Indonesia, Makassar introduced 24-hours-homecare service and telemedicine services20 by its homecare service, health care force Telemedicine map in Makassar will come to patient’s house, therefore increase the accessibility to health care professionals in the underserved areas. In its implementation, a transportation facility (Dottoro’ta) to take the patients to the health care service and vice versa is provided. Dottoro’ta is equipped with medicines, medical devices, oxygen tanks and a patient condition monitoring tool, that connects patients directly to a specialist through a wall room21.

22 https://kominfo.go.id/content/detail/11490/siaran-pers-no-224hmkominfo112017-tentang-menkominfo-dorong-bpjs-manfaat kan-big-data-bentuk-transformasi-digital-model-bisnis-bpjs/0/siaran_pers 23 https://www.bpjs-kesehatan.go.id/bpjs/index.php/post/read/2017/606/Ini-Strategi-RS-An-Nisa-Kelola-Keuangan

19 2. JKN Mobile based on branches and nearest available Badan Penyelenggara Jaminan Sosial (BPJS) location. Kesehatan, the provider of the National • Invoicing Health Insurance – Healthy Indonesia Users can find their information regarding (JKN –KIS) program, is harnessing payments, such as virtual accounts, technology to create a better national invoice notification and mobile payment. health system to serve all Indonesians. • Selective health screening This Mobile JKN application is a form of This health screening consists of digital transformation business model 47 questions regarding eating by BPJS Kesehatan which started as an habits, psychological symptoms, and administrative tools used in BPJS office exercise time, communicable and branches or health care facilities. It is then non-communicable diseases. This transformed to an app which allow their screening will be done yearly. From this user to access it with no limited time (self questionnaire, BPJS (or the government) service)22. are able to estimate the risks for , , dyslipidemia, coronary The development of the BPJS Kesehatan heart disease, stroke, kidney disease and mobile application is part of their even mental disorder. commitment in giving convenience and simplicity for an optimal experience. 3. BPJS Digital Claim Verification Through this application, users are able to (Verifikasi Digital Klaim/ Vedika) access various information regarding JKN, To improve BPJS service and operation, which is managed by BPJS Kesehatan that BPJS launched BPJS Digital Claim Verification is user friendly and snappy, anytime and Software, that can be utilized to claim anywhere. both inpatient and outpatient services. The application would be useful for Features that are offered to the users who hospital management, in terms of helping is also the insurance consumers includes: monitoring its JKN cost. Association • BPJS general information of Indonesian Hospitals in Indonesia Users are able to find their personal data (Perhimpunan Rumah Sakit Seluruh such as their membership number, pin Indonesia/ PERSI) and BPJS Kesehatan has point and preview maps of health facilities agreed to support digital claim verification24.

source: BPJS Kesehatran apps, taken 16 April 2018

24 Hasil Pertemuan Perhimpunan Rumah Sakit Seluruh Indonesia (PERSI) bersama BPJS Kesehatan, 1 February 2018

20 4. Digital Acquired Immune Deficiency institution such as the ministry of health, Syndrome (AIDS) Application25 publlic health office (Dinas Kesehatan), In 2013, Indonesia’s Ministry of Health, AIDS counting commission (Komisi together with Indonesia AIDS Coalition Penanggulangan AIDS), non-governmental (IAC), launched Digital AIDS Application. organizations (NGOs) and several key The initiative, which was run by people populations. living with Human Immunodeficiency Virus (PL-HIV) (orang dengan HIV, AIDS (ODHA)), 5. TeleECG and TeleRadiology has the aim to support AIDS prevention TeleECG and TeleRadiology are the two programs. AIDS Digital contains information telemedicine pilot projects initiated by on services comprised of HIV testing, Anti- the Ministry of Health in 2012, with the Retroviral (ARV) therapy, PL-HIV support concept of teleimaging and telediagnostic, groups, vertical prevention, sterile needle specifically in referring the results of syringe services, methadone services electrocardiography (ECG) and X-Ray. and STI services. There are also online In 2013, there are 12 primary care directories of agencies working on AIDS facilities and 2 referral center hospitals prevention programs such as Ministry of (dr. Cipto Mangunkusumo National Health, Health Office, AIDS Prevention Central General Hospital (Rumah Sakit Commission, NGOs and also key population Umum Pusat Nasional (RSUPN) Dr. Cipto networks. This app beneficial in achieving Mangunkusumo/ RSCM) & Harapan the AIDS countermeasures program. AIDS Kita Hospital) supporting both of the Digital contains range of services from telemedicine. In its implementation, HIV testing, ARV therapy, PL-HIV support Radiology and ECG data from primary cares group, vertical prevention, availability of are transferred through a server to referral sterile syringes to methadone and sexually hospitals. RSUPN RSCM acts as TeleECG’s transmitting disease (STD) services. Also referral center, while Harapan Kita Hospital available, an online directory by partnering plays a part as TeleECG’s referral center26.

MINISTRY OF HEALTH (monitoring)

LEARNING HOSPITAL

Scanner Rural Hospitals/ PUSKEMAS RSCM

Internet Radiology Server Specialist

TELE-EKG Rural Hospitals/ PUSKEMAS RS. Harapan Kita Ambulance

Internet Cardiovascular Server Specialist

source: Kebijakan Pemerintah Mengenai Telemedicine di Indonesia, 2013, Kemenkes.

25 https://www.iac.or.id/portfolio/aids-digital/ 26 Kebijakan pemerintah mengenai telemedicine di Indonesia, 2013, Kemenkes

21 6. P-Care BPJS27 P-Care BPJS is a web based application of patient information system that is provided by BPJS for primary care facilities to access data to BPJS server more easily. This application provide services including registration, diagnosing, therapy and laboratory services. This app is introduced back in 2014, and up until now it has a lot of tweaks that makes using this app seamless and easy, especially with the amount of BPJS user that keeps growing. It allows real-time and integrated patients’ services between all levels of institutions.

7. Application for Online Outpatient Registration The Government of Indonesia’s Ministry of Health launched a website-based queue management system. By accessing http:// sirs.yankes.kemkes.go.id/, patient who is seeking outpatient treatment will be able to choose the hospital and physicians. After registering themselves, they will have a registration number, to be then presented to the targeted hospital. A total of 32 State- owned General Hospital Center (RSUP) in Indonesia have been included in the system.28

27 https://www.bpjs-online.com/mengenal-pcare-bpjs-kesehatan/ 28 http://medan.tribunnews.com/2017/07/05/tak-perlu-repot-mau-berobat-rsu-p-ham-bisa-daftar-rawat-inap-secara-online?page=2

22 Private Sectors app health consultation, health and lifestyle Private sectors have more initiatives regarding guides and digital forums. the development of telemedicine, since it is believed to be the future to improve 4. HaloDoc and GoApotik33,34 the promptness and accuracy of medical Halodoc is a mobile application health diagnostics and consultations in primary care29. care platform that unites patients, doctors, It is most likely that users preference on using insurance, and into one simple the digital health care application because of health care application. Halodoc has a its practicality and convenience (see the box vision to become the number one health with title: How Does the Patients and Doctors care hub. It provides doctor consultation Like eHealth Application? Page 72). Following service by connecting general practioners, information will describe on the Indonesian pediatrician, obstetrician-gynecologist, telemedicine development from private sectors: internists, and numerous other specialists; to patients at home through chat, voice 1. AloDokter30 call and video call. They work together AloDokter is a mobile application platform with doctors who are registered by the that focuses on giving high quality medical Indonesian doctors’ association (Ikatan information that is easily understood by Dokter Indonesia/IDI) and Indonesian Medical Indonesian-speaking users. Contents from Counsils (Konsil Kedokteran Indonesia/ diseases, drugs and daily difficulties that KKI), who have a medical practice license based on research are what AloDokter (Surat Ijin Praktek/SIP and Surat Tanda provides in their website and mobile app. Registrasi/STR). In addition, they provide This platform support users to take care of tele- service, by partnering with their own health and their families. Other over 1,000 trusted pharmacies to deliver features are included in the services, such medicine to their customers’ doorstep as find drugs, doctors, hospitals, ask doctors within an hour. Halodoc sells over-the- and explanation of diseases. counter , vitamins, consumer products and prescription drugs. To 2. GO-MED order prescription drugs, customers are GO-MED is a mobile based application only required to take a photo of their created by GO-JEK and Halodoc. It is one of prescription, then upload it for verification. the features that integrated within the GO- JEK application. GO-MED provide services 5. Homedika35 which enables users to order their need of Homedika is an app created by Indonesia medicine via online application. Users can Medika, a religious grass root-based easily choose or input the product needed organization based in Malang, which its and the driver will directly buy the medicine members engaged in the collaboration of and send it to the user. scientific fields and the applicable field with health interconnection to create innovative 3. Gue Sehat32 health products. Homedika is a technology- GueSehat mobile app is the first online based social entrepreneur that connects health community in Indonesia. This health care workers and facilities with platform is also available in website form, it community/society in providing various facilitates users to share their experiences health care services, with its motto: “Making regarding health issues, and users are Indonesian Health Services Integrated, welcome to write articles which will be Connected and Collaborated”. Through the sorted by their team. Their goal is to be Homedika product, Indonesia Medika brings the company that users trust to be their several services, including; teleconsultation go to place to tell their story. They are also (Med-Talk), Med-Chat and Med-Call; medical completed with self-diagnosing features, in- e-commerce site (Med-Shop); home visit

29 Kemenkes RI, Kebijakan Pemerintah Mengenai Telemedicine di Indonesia, 2013 30 https://www.alodokter.com/about 31 https://www.go-jek.com/go-med/ 32 https://www.guesehat.com 33 https://www.halodoc.com/ 34 www.goapotik.com 35 https://www.indonesiamedika.com

23 (Med-Visit); emergency service (Med-Lance of communications and information to the and Med-Quick); healthy catering (Med- Indonesian speaking users in both medical Food); blood donor (Med-Blood); and health and non-medical matters, such as beauty articles (Med-News). and general health-related information. They provide in-app and web consultation 6. Homecare2436 through live chats with general practitioners Homecare24 is an online mobile app and specialized physicians. platform that provides 24 hours’ in-home health care services, health care workers 10. Medika App40 who are employed by this platform consists This mobile app lets the users find and of licensed doctors and nurses. The services book a consultation appointment with can be ordered straight from their website their preferable doctor at the nearest or application from smartphones and PCs, hospitals or right at their fingers tip so users need to sign-up and then log in without any problem. The app also allow to get the services they want. Services can users to find, buy and book visits with then be rated based on your preference. additional promos and packages at their partnered clinics and hospitals. Other 7. Indonesian Kalkulator of Oocyte features including booking confirmation (Indonesian Kalkulator of Oocytes/ in 30 minutes, payment options with bank IKO)37 transfer or credit card right from the IKO is a mobile application which predicts application, 12 months’ installments and ovarium’s biological age and the chance of articles or information regarding beauty and pregnancy, by knowing patient’s AMH (Anti- health are parts of the service provided. Mullerian Hormone) level. This Assisted Reproductive Technology (ART) is a result 11. Medico41 of Dr. dr. Budi Wiweko, SpOG (K)’s research, With their motto powering and that found that AMH can be utilized as a empowering, Medico is a private cloud biomaker of ovarium’s biological age. IKO based management information system in can be used as physician’s reference guide web-based platform that is able to facilitate when they provide consultation to patients hospitals or clinics with a functional IT with infertility disorders. system that allows health care workers get updates on their patients remotely. Their 8. K24 Klik38 product also has several special features K24Klik is the first online pharmacy store to provide better services for patients and in Indonesia available in mobile app workers to minimize adverse effect and platform that provides several services, human-error such as drug interaction such as consultation, order and delivery tracker, e-prescription, mobile management for 24 hours a day, 7 days a week. K24Klik reporting, medical billing system and is claimed to be online pharmacy store centralized inventory control.42 that provides the most comprehensive pharmaceutical products. They also Based on a report published in 2017, it guarantee the authenticity of the medicines was written that Medico has provided its sold. The drugs ordered can be taken or compatibility with P-Care BPJS, which allows delivered by users. primary health care facility to achieve several indicator numbers requested by 9. Klik Dokter39 BPJS.43 KlikDokter provides educational services, which provide excellent approach in terms

36 https://homecare24.id/tentang-kami 37 https://www.researchgate.net/publication/323170359 38 https://www.k24klik.com/tentang-k24klik 39 https://www.klikdokter.com/pages/tentang-kami 40 https://www.medika-platform.com/en 41 https://medico.id/aboutus.html 42 https://medico.id/index.html#learnmore 43 http://www.beritasatu.com/iptek/468896-medico-kenalkan-fitur-integrasi-dengan-pcare-bpjs.html

24 12. MIMS Indonesia44 15. Pro Sehat47 MIMS is a mobile based application Pro Sehat mobile app provide easy access that provide essential prescribing and for the user to update vaccination status drug reference guide. Established in even without leaving home. In the in-app, 1963, MIMS is a multi-channel provider the user can access services, such as of drug information, carefree vaccination appointments and and services connecting health care consultations in selected areas in Indonesia. communities working in 13 countries They also provide other services including across Asia Pacific, which licensed in the purchasing in-app medical devices, vitamins, UK. Their work empowers health care herbals and . professionals to improve patient outcomes by facilitating knowledge exchange and 16. RSPI Mobile48 better decision-making. Today, MIMS RSPI Mobile is a free mobile application is present in 13 countries across Asia managed by Rumah Sakit Pondok Indah Pacific with approximately two million (RSPI) that is specially designed to facilitate health care professional subscribers to its patients in finding doctors and hospitals, drug & resource portal, digital and print and making hospital reservations. Using publications. The MIMS mobile application is the application, patients will be able to available for free for android and IOS. access virtual member card, rate doctors, submit booking inquiry, as well as to be 13. PesanLab45 well informed about hospital’s promotion Pesanlab is the Indonesian first online web program. based platform for ordering laboratory and medical checkup services, which based in 17. TeleCTG49,50 Central Jakarta. Through Pesanlab, Jakarta TeleCTG is a mobile application based resident can request bloodwork test service medical technology start-up from Indonesia just as easy as booking a ticket. The services that developed a mobile cardiotocography offered in this app are home service and lab (CTG) referral system. TeleCTG has been online results. developed since 2015 by dr. Ari Waluyo, a Jakarta-based obstetrian-gynecologist, who 14. Periksa.id46 have immersed himself in remote areas This web platform helps doctors, clinics and in order to provide medical assistance to hospitals to make everything multifunctional mothers and children. The idea was arisen so that they can organized and control because the main factors behind pregnant everything regarding patients, medical women/mothers and children mortality record and inventory more efficiently. This cases is the fact that midwives in remote will affect the productivity and performance areas in Indonesia cannot identify fetal of doctors, clinics or hospitals, and when distress, as CTG devices are very costly. their productivity increases it will affect TeleCTG stands as a solution for a low- income and revenue. cost CTG device that can quickly deliver the output data from remote locations to obstetrician-gynecologist, who will then analyse the data and provide feedback.

44 http://corporate.mims.com/about-mims/ 45 https://www.pesanlab.com 46 https://periksa.id 47 https://www.prosehat.com/tentang-kami 48 http://www.rspondokindah.co.id/id/visitor-and-patient-information/information/detail/23/rspi-mobile 49 telectg.co.id/ 50 https://www.linkedin.com/company/telectg

25 18. Sehati51 a rise from 10 percent in 2014. The vision Sehati is a mobile application provided in of Sehati is a trilogy that aims to provide Indonesian language that assist expecting beneficial and educational information mothers in monitoring their pregnancy throughout a human’s lifecycle through through a standardized guidance and a web platform and complementary in making reservation for health check- applications. “Sehati Kehamilanku” serves as up. Sehati was founded with the aim to the entry gate to the whole “Sehati journey” improve newborns’ health and nutrition, that initially focuses on “Kehamilanku” as expecting mothers often face lack and will continue with “Anakku” and of practical information and guidance “Keluargaku”. If the implementation of the about their pregnancy. The condition is system works well, the data that is gathered also worsen especially with the fact that from the system can be a valuable source there are only about 3,500 obstetrician- for the Government of Indonesia and gynecologist nationwide - who are also the Local Government to provide proper unevenly-distributed. Meanwhile, there are approach for the health of the society. On around 5 million new expecting mothers August 2018 Sehati merged with TeleCTG every year (1.7 percent annual growth). into one application named Sehati TeleCTG As a result, according to WHO, Indonesia and shifted its model business to the is the top 9th of country with highest Low development of tehnology of the mobile Birth Weight (LBR) newborns. The total of application Sehati and the tools to check 15 percent of Indonesian newborns mainly health pregnancies. suffer from low nutrition with weight <2.5kg,

51 https://sehati.info

26 Products eHealth Application Private Public Hospital Information System (Patient • Medico • V-Claim BPJS data management/ administrative • Periksa.id • P-Care BPJS stuffs) • Ministry of health outpatient online • A system that process and integrate registration service flow in clinic or hospital in form application (SIRS of communication network. YANKES KEMKES) • JKN Mobile

E-prescribing • HaloDoc • Prosehat • Technology framework that allows health care professionals to write and send prescription electronically instead of using handwritten notes.

Clinical decision support facilities • Tele-CTG • Tele-ECG • MIMS Indonesia • Teleradiology • Health information technology designed to provide health care professionals with clinical decision support.

Patients health informatics • Guesehat • JKN Mobile • Alo Dokter • A system that provides information for patients which facilitates the promotion of self-care, promoting healthy behaviors and peer information exchange

Clinical Information Providers • MIMS Indonesia • HaloDoc • Source for trustworthy and timely • Alo Dokter health/medical news and information • Guesehat • Sehati • Homedika

Virtual health care teams • ACAP Indonesia

• A digital platform that allows health care professionals to collaborate and share information on patients

Mobile health (wearable devices) • Fitbit® • Samsung • Smart electronic devices that can Gear® be worn on the body as implants or • Apple Watch® accessories.

27 Products eHealth Application Private Public Tele-pharmacy • HaloDoc • K24Klik • Delivery of pharmaceutical care via telecommunications to patients in locations where they may not have direct contact with a pharmacist.

Tele-consultation • HaloDoc • Tele-ECG • Alo Dokter • Teleradiology • Consultation by remote • Medika app • 24-hour-homecare telecommunications, generally for the • Tele-CTG service, hospital-to- purpose of diagnosis or treatment of a • Homecare24 hospital telemedicine patient at a site remote from the patient and tele-radiology or primary physician. by targeting student hospital in remote areas.

Tele-rehabilitation

• Delivery of rehabilitation services via information technologies.

Tele-laboratory • PesanLab

• Telecommunication facility that allows patient to get result of medical tests performed in a laboratory located remote from the patient.

Tele-radiology • Tele-CTG • Tele-ECG • Teleradiology • Transmission of radiological patient Kemkes images (x-rays, CTs, MRIs) from one location to another.

Appointment scheduling • RSPI Mobile

• Application that help patients to manage appointment across clinics and health care professionals.

Research/Big Data • IKO • ACAP Indonesia • Health information collected from single • Tele-CTG - individuals to large cohort to allow all Sehati related health practitioners (parties) to work together to find evidence based solutions.

28 eHealth Application Matrix

Government-or (Possible) Application Type Benefit Private Initiative Disadvantage Mobile JKN Mobile only Government- • Through the apps user • The apps is initiative – provided can apply for JKN-KIS only available in by BPJS Kesehatan, insurance Indonesian. a state-owned enterprise, which • Users are able to find • The apps is only was initiated by personal membership available for user Ministry of Health. number, pin point and who is registered. maps of health facilities and maps of health facilties and other information regarding insurance members;

• The services that are available payment information virtual accounts, payment & health history, insurance status, invoice notification, complaints form, and mobile payment.

GueSehat • Mobile Private-initiative • The apps provide In the “book” apps or. • Web-portal (developed by PT. detailed information segment, we can guesehat.com • Additional Anugerah Arkon on trending topic on only pick up available program of Media) health, presented in a options, if not we GueSehat fresh and interesting cannot get info from is that they look, simple and smart, there, but we can use provide and colorful. “discussion forum” information facility instead. in other social • Info about man and media, such woman’s health as Twitter and symptom (the apps Instagram. provides more than 350 symptoms information available on physical and mental health); directory (about hospitals, medical doctors, clinic, spa and massage, beauty, laboratory, gym and health club, restaurant, health practitioners), ongoing events.

• Topics for the article: medical, beauty, lifestyle, sex and love, pregnancy, toddler life, discussion or chat forum on health topic.

29 GoApotik • Mobile Private initiative – • GoApotik provides application under Dexa Group services to distribute • Web-based via (pharmaceutical wide range of goapotik.com and health care pharmaceutical drugs, • Distribution product producer) goods from baby and service beauty shop. focusing on medicine or • The GoApotik apps pharmaceutical confirms that they drugs . only sell qualified and official goods, including prescription drugs.

• GoApotik is a trusted partner of big e-commerce.

• Payment to the merchant using official account of GoApotik through payment gateway.

K24 Klik apps • Mobile Private initiative by • 24 hours service and Slow delivery (based or k24klik. application K24 Pharmacy trusted products as it on the K24 app com • Web based via links to K24 Pharmacy. review) www.k24klik. com • The availability of health consultant and pharmacists.

• Redeem doctors’ prescription online.

• Easy access, easy payment method, buyer can pay using Cash on Delivery / COD payments, Internet Banking, electronic money payments, ATM transfers and credit card payments.

30 Halodoc apps • Mobile Private initiative by • Connects patients or halodoc. application Jonathan Sudharta with licensed com • Web based via doctors for online www.halodoc. consultation com (the full services • Medicine delivery provided – partners with only through pharmacies and Halodoc mobile Gojek. application) • At-home lab test service – partners with Prodia, offers various lab test package

• Halodoc wallet enables direct payment via application

• Comprehensive information and articles about health, diseases, and lifestyle

31 Challenges eHealth technology. Other than internet Despite the benefit, the obstacle in penetration, digital health literacy and EMR implementing and developing a comprehensive implementation are several concerns which eHealth environment in Indonesia can be are still faced by internet users in the country. perceived as massive, since Indonesia is still in The other concern is regarding the challenge the midst of their infrastructure development. in connectivity. While fiber optic cables are Other than that, community acceptance, going into the villages, actually in some competence of the users, interoperability, and areas, especially in rural areas, the stability of slow growth adaptation from the policy makers communication network is still not adequate are other reasons that slow down the process for the implementation of digital health.59 even more.52 A good news came from the Ministry of Communication and Information Technology, Infrastructure Limitation/Problems as they have confirmed that they are now in the Power Source process on the development of networks and As per 2017, Indonesia’s state electricity infrastructure across its region through several company (Perusahaan Listrik Negara / PLN) programs such as Desa Broadband, Palapa stated that Indonesia has 95.92 percent Ring Program and Refarming 4G60. According electrification ratio, superior to their initial to Dr. Nyoman Adhiarna, e-Business Director, target which is 92.75 by the end of 2017. Indonesian Ministry of Communications This target is not based by a certain territory and Information, due to the wide and rapid or area, instead it is based on how many innovation of eHealth practice, it cannot be houses that have access to electricity.53 This managed in a special instrument. This will be percentage shows high numbers of ratio, but a good sign that Indonesian people are able considering the vast area and magnitude of to use eHealth technology as part of their Indonesia population, this means that there integrated health system in the near future. are still 25 million people in Indonesia that On the other hand, regarding the internet do not have access to electricity, especially in availability in the hospital in the country we the eastern region.54 This was confirmed by still have to face unpleasant reality that only PLN’s statement which clarified that Eastern one out of 33 cities has 100 percent internet Nusa Tenggara and Eastern Papua only have availability, while 14 cities of them have 80-99% electrification ratio of 60 percent.55,56 availability, and the hospital in the five cities provide the percentage of under 59 percent Communication Network internet availability (see the table 32). According to Association of Indonesian Internet Service Providers (Asosiasi Penyelenggaran At the moment there are several eHealth Jasa Internet Indonesia/APJII), in 2017, more services, which provided by governmental than 50 percent (or 143.96 million Indonesian institution, one of them is the JKN Mobile populations) of the 260 million Indonesian application, which can be utilized by all of the have access to the internet57. Pertaining the Indonesians, not only covered to those who amount of internet users, Indonesia is the live in the city areas, but also the ones lives fifth highest number of internet users in the remotely. This eHealth service provided by world58, after China, India, United States, and Badan Usaha Penyelenggara Jaminan Sosial - Brazil, but in terms of internet penetration, Kesehatan or BPJS Kesehatan, a state-owned the country is considered to have low internet enterprise on national social security service penetration compared to developed countries developed by the Indonesian’s Ministry of that has implemented more advanced Health. The service covers exchange of data

52 Kebijakan Pemerintah Mengenai Telemedicine di Indonesia, 2013 53 https://katadata.co.id/berita/2018/03/06/pln-targetkan-seluruh-wilayah-indonesia-dapat-akses-listrik-tahun-ini 54 https://www.suara.com/bisnis/2017/06/07/140358/ada-25-juta-orang-indonesia-masih-tanpa-akses-listrik 55 https://katadata.co.id/berita/2018/03/06/pln-targetkan-seluruh-wilayah-indonesia-dapat-akses-listrik-tahun-ini 56 https://www.suara.com/bisnis/2017/06/07/140358/ada-25-juta-orang-indonesia-masih-tanpa-akses-listrik 57 http://jakartaglobe.id/business/indonesia-143m-internet-users-2017-apjii/ 58 https://www.statista.com/statistics/262966/number-of-internet-users-in-selected-countries/ 59 Penggunaan Telemedicine di Indonesia, Kemenekes, 2013 60 https://kominfo.go.id/content/detail/11490/siaran-pers-no-224hmkominfo112017-tentang-menkominfo-dorong-bpjs-manfaatkan- big-data-bentuk-transformasi-digital-model-bisnis-bpjs/0/siaran_pers

32 and information in attempts on expanding other developing countries, including limited informatics application, public education and resources, unreliable power, poor connectivity, research, which supported by the Ministry of and high cost for the poverty-stricken person Communication and Information Technology – those most in need. Telehealth is poised in supporting the availability of system and to improve health and health care in the technology information for the JKN – KIS, developing countries, driven by both altruistic as mentioned in the press conference on and profit motives. But on the other hand have November 15th, 2017. the desired effect, telehealth must address very specific and evidence-based health “needs” of Although there are many benefits in using each facility, region, or country; the shortage eHealth technology that nowadays are enjoyed of health workers and medical specialist by the most of Indonesian especially in the services; and the required skills upgrading and big cities, telehealth is not yet integrated training, allowing the developing countries to globally into existing health care systems. The establish their own critical mass of experts. reasons are vary: lack of proven large-scale This condition will only be achieved by raising operations, poor evidence base, inadequate awareness, understanding, and ability regarding implementation, lack of attention to the “soft telehealth capability and limitations by the side” of implementation (readiness, change coordinated political and professional as well management), and many others. Other than in as by those who involved to guide public and Indonesia, reasons can be more pragmatic in private innovation and telehealth integration.61

61 https://www.researchgate.net/publication/276337781_Telehealth_in_the_developing_world_current_status_and_future_prospects

33 Communication Device Availability in Public Hospitals in Indonesia62

Communication Device in Public Hospitals (%) No. Province Telephone Mobile Phone Internet 1 Aceh 100 16.7 84 2 North Sumatra 94.4 11.1 72.2 3 West Sumatra 100 40.9 100 4 Riau 91.3 34.8 82.6 5 Jambi 92.3 7.7 84.6 6 South Sumatra 88.5 34.6 92.3 7 Bengkulu 76.9 23.1 61.5 8 Lampung 100 28.6 71.4 9 Bangka Belitung 100 0 85.7 10 Riau Islands 81.8 45.5 54.5 11 DKI Jakarta 100 36.8 94.4 12 West Java 100 34.8 97.8 13 Central Java 100 26.2 96.7 14 DI Yogyakarta 100 40.0 90 15 East Java 100 39.5 98.7 16 Banten 100 22.2 66.7 17 Bali 100 23.1 76.9 18 West Nusa Tenggara 100 22.2 88.9 19 East Nusa Tenggara 94.1 11.8 75 20 West Kalimantan 88.9 35.3 72.2 21 Central Kalimantan 93.8 37.5 87.5 22 South Kalimantan 100 20 89.5 23 East Kalimantan 95 20 95 24 North Sulawesi 75 12.5 68.8 25 Central Sulawesi 86.7 20 66.7 26 South Sulawesi 94.3 25.7 71.4 27 Southeast Sulawesi 66.7 20 66.7 28 Gorontalo 83.3 66.7 66.7 29 West Sulawesi 100 0 66.7 30 Maluku 85.7 28.6 50 31 North Maluku 75 8.3 58.3 32 West Papua 80 40 40 33 Papua 77.8 22.2 55.6 INDONESIA 93.6 27 82

62 Kebijakan pemerintah mengenai telemedicine, kemenkes, 2013

34 Community Acceptance participating in community life. It has also be At this time the most prevalent barrier to the noted that in the HDI the freedom of choice is implementation of telemedicine programs central – someone who chooses to be hungry globally is the perception that the costs of (e.g. During religious fast) is quite different to telemedicine system are too high. In addition, someone who is hungry because he or she some medical professionals have lack of cannot afford to buy food.63 technical expertise and have not put their trust on technology yet. This kind of fear is Published on November 4th 2010, the new understandable, realizing that the risk of method in calculating the HDI combines 3 data loss, incorrect data input, connectivity dimensions:64 problem, breaching medical ethics, etc. are still • Life expectancy at birth (LE) part of the inadequate daily health practice • Mean years of schooling (MYS) and in the country. In addition to that the health expected years of schooling (EYS) care professionals may be passionate about • Gross national income (GNI) per capita telemedicine only if they are ensured that it is (GNIpc) eligible according to Indonesia’s medical ethics and regulations. The HDI has been criticized on a number of grounds, including alleged lack of consideration Human Development Index of technological development or contributions Human development index (HDI) is a composite to the human civilization; focusing exclusively statistic (composite index) of life expectancy, on national performance and ranking; lack education and per capita income indicators, of attention to development from a global which are used to rank countries into four perspective; measurement error of the tiers of human development. A country scores underlying statistics; and on the United higher HDI when the three aspects: the life Nation’s Development Programme (UNDP) span, the educational level, the GDP per capita changes in formula which can lead to severe have high scores. The index is based on the misclassification in the categorization of ‘low’, human development approach, developed by ‘medium’ or ‘very high’ HDI.65 Ul Haq, an economist from Pakistan economist. It is often framed in this index in terms of whether people are able to “be” and to “do” desirable things in life. Some of the examples include – doings: work, education, voting,

63 “Human Development Index”. Economic Times; “The Human Development concept”. UNDP. 2010. Retrieved 29 July 2011. 64 “Human Development Report 2010”. UNDP. 4 November 2010; “Technical notes” (PDF). UNDP. 2013. 65 Wolff, Hendrik; Chong, Howard; Auffhammer, Maximilian (2011). “Classification, Detection and Consequences of Data Error: Evidence from the Human Development Index”. Economic Journal. 121 (553): 843–870. doi:10.1111/j.1468-0297.2010.02408.x

35 Human Development Index in ASEAN Countries66

Table ..: Indonesia is in the fifth rank of HDI among other ASEAN countries in 2015

Indonesia’s HDI in 2015 puts them in the three levels of health information technology “medium” category and ranked 113 out of 188 interoperability: countries and territories. The HDI value is 30.5 • “Foundational” interoperability allows data percent, increased from its value in 1990. It exchange from one information technology reflects the progress Indonesia has made in life system to be received by another and does expectancy at birth, mean years of schooling, not require the ability for the receiving expected years of schooling and GNI per capita information technology system to interpret during the period. However, Indonesia’s HDI the data. falls when inequality is taken into account. • “Structural” interoperability is an Inequality-adjusted HDI (IHDI) is a measure of intermediate level that defines the structure the average level of human development of or format of data exchange (i.e., the people in a society once inequality is taken into message format standards) where there is account.67 uniform movement of health care data from one system to another such that the clinical Interoperability or operational purpose and meaning of the Interoperability is the ability of a system to data is preserved and unaltered. Structural work with or use the parts or equipment of interoperability defines the syntax of another system.68 According to the Health the data exchange. It ensures that data care Information and Management Systems exchanges between information technology Society (HIMSS), in health care, interoperability systems can be interpreted at the data field is the ability of different information technology level. systems and software applications to • “Semantic” interoperability provides communicate, exchange data, and use the interoperability at the highest level, which information that has been exchanged. In is the ability of two or more systems or practical, interoperability means the ability of elements to exchange information and health information systems to work together to use the information that has been within and across organizational boundaries in exchanged.5 Semantic interoperability order to advance the effective delivery of health takes advantage of both the structuring care for individuals and communities. There are of the data exchange and the codification of the data including vocabulary so that

66 http://hdr.undp.org/en/composite/IHDI 67 http://www.id.undp.org/content/indonesia/en/home/presscenter/pressreleases/2017/03/22/indonesia-s-human-development-in dex-rises-but-inequality-remains-.html 68 https://www.merriam-webster.com/dictionary/interoperability

36 the receiving information technology also an opportunities to provide a better care systems can interpret the data. This level for the patients. These are few of the advantage of interoperability supports the electronic in using Hospital management information exchange of patient summary information system:70 among caregivers and other authorized parties via potentially disparate electronic 1. Integrated hospital management; health record (EHR) systems and other 2. Pharmaceutical stocks and multi storage systems to improve quality, safety, floor stock can be lively updated; efficiency, and efficacy of health care 3. In and out patient, single billing statement delivery. which covers all services; 4. Complete disease and history Hospital Management Information System: (medical records) of patients that can be must exist and functional process and recalls automatically; In order to execute a future in the digital health 5. Diagnostic and operational statistical technology, a functional hospital management analysis for all patients with a standardized information system (HMIS) in hospitals and procedure by WHO; clinics is a necessity. Today, Indonesian 6. Simplify budgeting process and realizing Hospitals both public and private hospitals control; are beginning to implement the technology in 7. Simplify both actual cash-flow and cash-flow building their facilities and infrastructure, this plan; transformation is part of paving the way to the 8. Keeping data consistencies due to data world digitalization era. One of the most basic sharing for both data master (patient, service that can be implemented in hospitals doctors, nurses, admin and pharmaceutical are through the hospital management system database) and transaction data; which integrates with the online CCTV. Other 9. Usage of data output from different available service is the managed service modules as an input to avoid any process provider for booking appointments.69 redundancies within parts of the hospital.

Hospital management information system is According to a 2017 report, there are only 52 a computerized system that processes and percent of both public and private Indonesian integrates the flow of all business process and hospitals which already have and implement health care services in a coordinated network. this system. The considered as low numbers of This system provides reporting and other eHealth technology use in the hospitals shows administrative procedure for a faster, precise that the digital health technology is not yet and accurate information. In the future there well accepted and is still hampered. Although is a possibility that this system can be used in the other side of the story, a support from as an integrated system with the government the Indonesian Government on this issue has institution and also the smart city program, been shown that Indonesian Ministry of Health which not only make an advance integrated has implemented its regulation regarding hospital technology management system, but the adaptation of HIMS from back in 2009 (Permenkes No 44 Tahun 2009).71

69 http://www.yankes.kemkes.go.id/read-tahun-2018-semua-rumah-sakit-harus-sudah-punya-simrs-terintegrasi-2647.html 70 https://media.neliti.com/media/publications/78723-ID-none.pdf 71 https://gawaisehat.com/2016/12/01/baru-48-rumah-sakit-di-indonesia-yang-memiliki-simrs-fungsional/

37 eHealth Practice Benchmarking: Comparison to Developed and Developing Countries

How eHealth has been incorporated across health care supply chain

Visualization on internet penetration and mobile connectivity72

72 https://www.internetworldstats.com/america.htm#us, https://www.internetworldstats.com/stats3.htm#asia, https://www.ofcom. org.uk/about-ofcom/latest/media/facts, http://www.btrc.gov.bd/content/mobile-phone-subscribers-bangladesh-january-2018, https:// wearesocial.com/special-reports/digital-southeast-asia-2017, https://en.wikipedia.org/wiki/List_of_mobile_network_operators_of_the_ Americas#United_States, http://www.abs.gov.au/ausstats/[email protected]/mf/8153.0

38 Singapore: Big data is watching and population’s needs in retirement, housing, startups are on the rise family protection, asset enhancement and Our closest neighbor country has so far health care. Workers and employers are implementing this advance eHealth technology required to make monthly contributions to the successfully. The philosophy of Singapore’s employees’ CPF into three accounts, ordinary health care system consists of three pillars. account, special account and the Medisave Firstly, the country is aimed to build up a account. MAS, as Singapore’s central bank, healthy population with preventive health regulates the financial aspect of insurance cares and to encourage healthy lifestyles. sector. The Insurance Department of MAS Secondly, Singapore also emphasizes personal administers the insurance Act, which protects responsibility towards healthy living through the interests of policyholders and regulates the “3M” (Medisave, Medishield and Medifund) insurers’ activities, including registration and system. Last but not least, the government licensing requirements. Periodically, MAS has to keep the health care costs down by provides directions and practice notes for controlling the supply side of the health care regulating insurance activities73. services and providing heavy subsidies at public health care institutions. The provision of appropriate Singaporean health care is becoming more challenging now. In the system there are three main regulators A number of factors are contributing to this: playing roles: Minister of Health (MOH), ageing population/changing demographics, Central Provident Fund (CPF) and Monetary increasing demand for health care services, Authority of Singapore (MAS). MOH oversees changing expectations, relative shortage of the provision and regulation of health care health care professionals and caregivers, and services. Specifically, it is in charge of promoting shortfalls in health care facilities74. health education, monitoring the accessibility and quality of health care services, preventing Moving towards a preventive and futuristic and controlling diseases, allocating resources personalized health care provision, Singapore and specialists and administrating required piloted the National Electronic Health Record licenses for health care establishments. CPF is a (NEHR) that allows patient records to be shared comprehensive and compulsory social security across the health care ecosystem, both public savings plan. It ensures working Singaporeans and private health care providers. Also, to and permanent residents (PRs) to support enable cost effective outcomes in treatments, themselves in the old age. better planning for health care services, and improvements in clinical quality, Singapore CPF has expended its objectives to meet the leverages Health Data Grid (HDG), a federated

73 http://assets.ce.columbia.edu/pdf/actu/actu-singapore.pdf 74 National Telemedicine Guidelines. January 2015.

39 or virtual database that will facilitate clinical (ECG) accurate heart rate monitoring solutions, research by enabling secure data access combined with accurate heart rate for precise across separate health care databases that are calories, steps, and distance, plus clear-cut located in different health care institutions75. automatic sleep monitoring. Apart from The program provides timely information to that, Attune, the largest Cloud based health support effective preventive health care and care IT service provider in the region, has improves effectiveness in health care service pioneered Cloud based products designed delivery. In addition to that, using advanced to help the entire health care ecosystem. data technologies, clinical researchers and Attune’s solutions seamlessly integrate Labs, doctors can derive from analyzing clinical and Hospitals, Pharmacies, Blood Banks, Radiology, genetic data, thereby helping to shape potential Medical Devices, Insurance Companies, and new health care models for precision medicine. Accounting - resulting in increased revenues Beyond its use in the public sphere, Singapore and operational efficiency. Attune’s solutions has also identified Big Data and analytics as can also be deployed across the spectrum of a key economic contributor for the future. organizations – starting from single physician The Singapore Economic Development Board clinics to a network of health care providers (EDB) noted that in 2011 alone, more than 1.8 making. This startup is Southeast Asia’s highest- zettabytes of data were created, and this is funded startup in digital health. Other startups expected to increase 50 times by 202076. that provide a similar service is Klinify, which provides a simpler and more user-friendly In the last decade, information and SaaS-based product for larger scaled clinics. communication technologies (ICT) has made Pertaining data aggregation platforms, there profound and game changing inroads into is MyDoc, which is building a network of the health care sector, thanks to its strong laboratories, doctors and pharmacies through a startup ecosystem, advanced infrastructure set of services such as health screening follow- and highly educated workforce. Singaporean up tools for patients. national policy to promote the use of ICT across all sectors has also been extremely effective. Over the years, Singapore has laid the Even, Singapore has public funding for ICT foundation for a thriving ecosystem with support of programs addressing national its infrastructure of high-speed fibre optic health priorities.77 Some of the key eHealth network and extensive wireless links. In initiatives are big data, data security, telehealth terms of infocomm manpower, Infocomm technology, wearables and hearables and Media Development Authority (IMDA) works internet of things. Not surprisingly, the rising with industry and private organisations to startup and innovation hub leads Singapore to spearhead the strategic use of infocomm in land at number one of the best startup cities78- the various sectors including health care to even it outranked San Francisco, the city with meet the wellness needs of the population. Silicon Valley in its southern region. There are Using wearables and IOT technologies, they several ways of how the startups have been explore extending medical care beyond the playing in the Singapore’s region’s health care hospital premises to patients’ homes and the systems. community, where patients and those at- risk can be empowered to self-monitor their DocDoc is developed to help the consumers health vitals and seek medical help before to compare and book appointments - not just they get seriously ill. A home infocomm system within their own country borders, but also monitors selects chronically-ill patients through across their country borders. Besides, there intelligent, embedded nano sensors. Fitness are a lot of startups like RingMD in Singapore trackers, smartwatches, and other wearables that are trying to enhance consumer access will be supported by sensors installed across to physicians through an online consultation the nation to constantly transmit data79. solution. In line with that, LifeTrak Fitness Then, real time data on the patient’s health Tracker is able to provide Electrocardiogram conditions will be processed to activate alerts.

79 http://www.himssasiapac.org/content-library/exclusive-articles/5-ehealth-initiatives-singapore-2015 75 https://www.imda.gov.sg/industry-development/sectors/infocomm/healthcare-and-wellness/health-data-grid 76 http://www.infocommguide.com/big-data-is-watching/ 77 http://www.who.int/goe/data/country_report/sgp.pdf 78 https://www.forbes.com/sites/chynes/2017/08/09/singapore-tops-new-list-of-best-startup-cities/#136b5f7b167d

40 As the regulator of the telecom industry, Malaysia: Telemedicine Blueprint have IMDA also continue to promote a competitive been conceptualized – some have been market, while encouraging innovation that implemented brings benefits to companies and consumers. Other neighbor country which is experiencing Moreover, along with more pervasive use of the implementation of ehealth technology is data, IMDA also promotes and regulates data Malaysia. The country’s health system is at a protection in Singapore through the Personal crossroads at the present. A 2016 report by Data Protection Commission80. the Harvard TH Chan School of Public Health concludes that “the health system faces new Telemedicine have been helping to address a challenges in the face of a rapidly evolving number of current gaps in the system such as context – characterized by demographic making health care resources (e.g. specialist and epidemiological transitions, a shifting services) more readily available in a timely of socio-cultural environment, technological manner to those who need it, bridging the changes, and rising income levels, which constraint of distance and saving time and have contributed to a nutritional transition, costs if this is done appropriately. Patients with increasing health risks, and new user mobility issues such as the chronically ill and expectations.” It also states that the lack of the elderly will gain from the conveniences of coordination between primary and secondary telehealth. With the aim to prioritise telehealth health care results in the overcrowding of services to support its ageing population, the government hospitals83. Although foreign government’s health care technology provider, doctors have been encouraged to take Integrated Health Information Systems, will up employment in Malaysia, there is still a launch new services that let elderly people significant shortage in the medical workforce, consult a doctor through smartphones or other especially of highly trained specialists; thus, devices in their own home, which also allows certain medical care and treatment are telerehabilitation and monitoring81. available only in large cities. Recent efforts to bring many facilities to other towns have Pertaining the regulation, in 2015, the Ministry been hampered by lack of expertise to run the of Health (MOH) issued a set of National available equipment. Telemedicine Guidelines to guide health care providers in the safe and appropriate delivery There were previous attempts at introducing of health care services through telemedicine. a public insurance system called 1Care for This is complemented by the Singapore 1Malaysia in the past, but this was eventually Medical Council’s (SMC) Ethical Code and shelved. It is unclear whether there will be any Ethical Guidelines (ECEG) and accompanying new proposals for a public insurance system, Handbook on Medical Ethics issued in 2016 but two things are certain: the costs of living that set out the standards of care required are escalating, and a large proportion of of doctors practicing telemedicine. Based on Malaysians continues to depend on the public the guidelines, the standard of care expected health care system. In terms of funding, the of doctors providing telemedicine should be Malaysian government already contributes comparable to what patients would receive in some 9.5 percent of its annual budget to a face-to-face consultation. Doctors providing health care, where RM26.58 billion is being care via virtual platforms have a responsibility allocated this year. This comes up to about 4.75 to ensure that the remote diagnosis made is percent of the country’s GDP, close to the WHO accurate and that patients receive appropriate recommended proportion of 5 percent, but medical advice and management for their lower than the OECD average of 9.7 percent. conditions. If in doubt, doctors should offer But if the increase in health care spending to see the patients face-to-face to conduct a continues at its current rates – increasing an physical assessment or refer the patient to the average of 12-13 percent per year from 1997 to nearest clinic or health care institution82. 2009 – this may not be sustainable in the long run.84

80 https://www.imda.gov.sg/about/what-we-do 81 https://govinsider.asia/innovation/singapore-picks-telehealth-to-support-its-elderly/, http://edition.cnn.com/2015/06/17/asia/ telemedicine-in-singapore/index.html 82 https://www.moh.gov.sg/content/moh_web/home/pressRoom/Parliamentary_QA/2017/Telehealth-Platforms0.html 83 http://www.thesundaily.my/news/2018/01/18/sustaining-public-healthcare 84 http://www.thesundaily.my/news/2018/01/18/sustaining-public-healthcare

41 Moreover, with a rising and ageing population, into a national eHealth system by integrating Malaysian government commits to the the different players in the health enterprise. principles of universal access to high quality Computer hardware and software vendors, health care. In spite of that, a major problem system integrators, R&D organizations and with the health care sector is the lack of medical relevant high-tech service providers are invited centers for rural areas, which the government is to join MSC project. trying to counter through the development and expansion of a system called teleprimary care. Malaysia’s Telemedicine Blueprint “Leading This system is a tool for teleconsultation and Health care into the Information Age” and distance learning in health care. With the tool “Towards Excellence in Health Information doctors in the remote clinics are able to discuss Management” have outlined the concept to the problem cases through teleconsultation develop the most advanced health systems with their colleaques in the hospitals using of the world by harnessing the power of an audiovisual system. This system provides information and multimedia technology. better care in the health centers without Amongst the pilot project applications that transferring the patients to the hospitals. Only was launched was the Lifetime Health Plan patients with critical conditions are referred (LHP), a personalized health care plan for to the hospitals. This has not only reduced the the individual. Its objective is to develop a number of patients referred to the hospitals, longitudinal health record of every individual but it will reduce the cost which charges to and implement a proactive health plan thus the health care system. It will also provide a enabling continuity in care. LHP was designed more comprehensive care to the patients in to provide a continuous medical care, informing the health centres. The doctors in the health the individual and health care providers with centers are also provided training and are relevant medical information to maintain also updated on the latest information and individual’s state of health at the highest state technology in medicine. This method of training possible at all times. In order to implement this has made doctors in the health care centers project, there are sub-application that were more efficient and satisfied85. conceptualized, namely Clinical Support System (CSS), Health care Information Management Telehealth was also incorporated by the and Support Services (HIMSS) and Personalized Malaysian government under the Multimedia Lifetime Health Plan (PLHP)87. E-HIMS is an Super Corridor (MSC) project, Telehealth electronic reporting system for the collection, Flagship. The project is one of the 7 flagship collation and analysis of health information in applications of MSC grouped under the MOH facilities. A web-based reporting system ‘Multimedia Development Flagship Application’ has been developed, which all health related and has long-term objectives towards data from MOH facilities, non MOH facilities Malaysia’s Vision 2020. The project was and private sector are transacted to ensure intended to reshape the health care structure timely and quality health information. The from illness focus to self-care emphasis by data is collected through e-forms applications incorporating telecommunications, information provided by all hospitals, health office and and multimedia technologies. It is hoped clinics88. Malaysia planned to establish the that the health care services become more National Health Data Warehouse which virtual, equitable, affordable, technologically manages informations in compliance to health appropriate, environmentally appropriate and informatics standards which will allow evidence consumer friendly, resulting in efficient health based health planning in the country89. care delivery and enhanced quality of life.86 The telehealth initiative has subsequently developed

85 https://www.ncbi.nlm.nih.gov/pubmed/12109251 86 https://www.researchgate.net/profile/Mohd_Hanafi_Mat_Som/publication/261028358_Telehealth_in_Malaysia-An_overview/ links/584356c608aeda696815bf6e/Telehealth-in-Malaysia-An-overview.pdf 87 http://www.moh.gov.my/images/gallery/publications/hi/HIMS%20Blueprint.pdf, https://www.researchgate.net/ publication/261028358, https://www.researchgate.net/publication/12590822_Telemedicine_in_the_Malaysian_Multimedia_Super_ Corridor_towards_personalized_lifetime_health_plans 88 http://www.moh.gov.my/images/gallery/publications/hi/HIMS%20Blueprint.pdf, http://pik.moh.gov.my/himse.html 89 http://www.moh.gov.my/images/gallery/publications/hi/HIMS%20Blueprint.pdf

42 In the country there are several teleconsultation care system scheme in the form of Medicare, startups being developed, i.e. DoctorOnCall. therefore allowing 100 percent of the total com.my, Malaysia’s first and largest online health care expenditure of the citizens consultation platform that provides services via and permanent residents are covered by chat, audio and phone calls, that delivers access the government health care programs and to non-emergency medical care at anytime schemes including private-public partnership and anywhere, especially from the comfort of insurance schemes and health care facilities. patient’s own home. RingMD, that began in Medicare was established in 1984 as the first Singapore, is now also available to Malaysians. well established Australian national health care It allows video consultations which are system that is still operated until now. Medicare encrypted end to end, so patients can securely is a national health care system scheme that text their doctors and the system allows the is eligible to all Australian citizens. However, doctors to make clinical notes and provide Australian citizens who intend to receive prescribe medication. Other telemedicine Medicare services are required to pay a taxable ventures that work in almost the similar way, amount of 2 percent to 2.5 percent of their but provide website-based service, are u2Doc monthly income to the Australian Department and Teleme. A benefit of Teleme that it has a of Human Services (Medicare Levy). This is good feature that the system has a tie up with mandatory to all Australians, except those are pharmacies, which enable prescribed medicines considered as a low income citizen (annual to be delivered to the patient’s doorstep90. income below A$ 21,335 or A$ 33,738 for seniors and pensioners). Besides, to enhance the capability and knowledge of medical personnel, Continuing Australia is a part of the Reciprocal Health Care Professional Development (CPD) was Agreements (RHCA) that are in place with the established in Malaysia. There are many United Kingdom, Sweden, the Netherlands, services provided in CPD, which will benefit Belgium, Finland, Norway, Slovenia, Malta, Italy, the health practitioner, such as virtual library, Republic of Ireland and New Zealand, which modular distant learning (MDL), calendar entitle visitors from these countries to limited of CPD events, online activity monitoring, access to Medicare and entitles Australian online directory, complement competency residents to reciprocal rights while in one of assessment, and monitoring and evaluation of these countries. According to the Reciprocal CPD91. Health Care Agreements (RHCA), Australia’s national health care scheme is the best among In conclusion, health care delivery in Malaysia is all of the RHCA members. Apart from all of the in the process of improving its health system to magnificent health care services that Australia have a better environment in the near future. have given, the Australian government has At the moment there are more hospitals have also established the Healthdirect program, been installed with applications of telehealth a national public health information service components. The government could also take that includes helpline (available 24 hours a initiative to encourage ISP providers to expand day), an after-hours general practitioner (GP) their operation in the rural areas and provide helpline, the Healthdirect website (which other essential infrastructure facilities92. provides free health information), a mobile device application, and a symptom checker Australia Health care Industry Value & (a guided, online self-triage tool allowing Supply Chain visitors to initiate their health enquiry online). Australia’s health care industry value, supply Other than the Healthdirect program, the chain, as well as health care public policy are Australian government has also established the the best organized and regulated health care Australian National Consultative Committee on system in the world. The Australian government Electronic Health (ANCCEH) that deals with all of created a very sophisticated integrated health Australia’s Telehealth related matters.

90 https://new.medicine.com.my/2016/05/telemedicine-in-malaysia-coming-of-age/ 91 https://www.researchgate.net/publication/261028358 92 https://www.researchgate.net/publication/261028358

43 In terms of size and area, Australia is a National Telehealth Strategy paper has received massive country and it is even considered very positive feedback from the government, as a continent. According to the World Bank clinical providers and health industry players. data by 2016 Australia’s total number of population have reached 24 million people USA Health care Industry Value & Supply that are scattered around in a massive are of Chain 7,692,000 km2, because of the massive area The health care industry value and supply that the country has and there are only a few chain in the United States of America (USA) Australian citizens compared to the country’s are very well organized and regulated by size, most of the Australian citizens live in the the government, with 63 percent of the big cities in the coastal area namely Sydney, total health care expenditure are covered Melbourne, Brisbane, Gold Coast and Adelaide. by the government health care programs Due to these circumstances the Australian and schemes. The US government created a citizens are scattered around the country and couple of national health care system schemes not all of the cities in Australia have the best such as Medicare, Medicaid (including state treatment and care knowledge for all of the independent health care programs (SHIP)), existing diseases, thus for example, in certain State Children’s Health Insurance Program cases people who lives in Brisbane who need (CHIP) and Veterans Health Administration. the best and most intensive care for cancer still have to go to Melbourne just for checking up or Two main health care system schemes that are even consultation. That is why telemedicine is crucial for the government are Medicare and necessary in Australia and have worked well in Medicaid. Medicare was established in 1965 this country. alongside with Medicaid as the first United State (U.S.)’s national health care system at that time. Telemedicine in Australia has been researched Both national health care system schemes are and developed since the late 1990’s and more not eligible to all U.S. citizens, as each of them intensively in the early 2000’s, the strong have their own eligible requirements. Medicare reason is as above explained, it is necessary is only available and eligible to the U.S. citizens to give a high quality and equal health care who are 65 years old or older, under 65 years service towards all Australian citizens with a old with certain , and or have End- big possibility of health care cost reduction, Stage Renal Disease. There are four parts of which will benefit all stakeholders, especially the Medicare: Part A (hospital coverage), Part the Australian government. The Australian B (medical insurance), Part C (combines Part National Consultative Committee on Electronic A and Part B), and Part D (prescription drug Health (ANCCEH) was established in 2004. It is coverage). the first telemedicine association in Australia and until now ANCCEH is still the main umbrella On the other hand, Medicaid determines the for telehealth related matters in the country, eligibility to register to the program, which including the modern health care private- mainly depends on the level of monthly public partnership planning and schemes. income. The federal law requires the states ANCCEH is the leading telehealth association to cover certain groups of individuals. Low that represents the major ICT industry players income families, qualified pregnant women and other stakeholder groups. The Committee and children, and individuals receiving contributes to the debate around the public Supplemental Security Income (SSI) are and private health agenda in Australia with considered as the mandatory eligible groups. health promotion and provision of better States also have other coverage options and health service through applications, and to may choose to cover other groups, such as support interactions with technology in order to individuals receiving home-and-community- improve efficiency, safety and productivity. As based services and children in foster care who of 2012, ANCCEH has launched the Australian are not otherwise eligible. National Telehealth Strategy paper. The paper contains of ANCCEH’s point of view in the United States is a massive country both in importance of telehealth from national system terms of area and population. According to perspective. Telehealth offers both public and the World Bank, by 2017 United State’s total private health system an opportunity to provide number of population have reached 325.7 new models of efficient health care. ANCCEH’s million, living around in a massive area of

44 9,831,500 km2. Due to this circumstances, barrier for telemedicine, where Medicare does the U.S. citizens are scattered around the not reimburse very much in the fee-for-service country and not all of the cities in the U.S. are system. In addition to that, regulation issues well developed - most of the well-developed such as regulation to practice, licensure and cities in the U.S. are located in the west limitation of the system -where each state coast and east coast, such as New York City, have its different system- also burdens the Boston, Washington DC, Orlando, Seattle, San development of telehealth in the U.S.93 Francisco and Los Angeles. Compared to the coastal cities, the central part of the country is USA Insurance Covered Telemedicine more underdeveloped in a way that massive Services Map number of their smaller cities have limited capabilities in their health care services. This require patients from the smaller cities to travel to other cities to get more proper and better health care services. As there are only limited number of hospitals and limited practitioners with special capabilities available in the smaller cities, telemedicine is necessary in the U.S. and have been working well in the country, even in some states that are covered by the health care national scheme and state health care program.

As telemedicine is perceived as crucial, it has been researched and developed since in the early 1990’s in the United States. The American Telemedicine Association (ATA) which UK: Telehealth in Pharmaceutical Industry is the first telemedicine association in the Value & Supply Chain U.S., was established in 1993 in Washington The pharmaceutical industry value and supply DC. ATA has a membership network of more chain in the United Kingdom (UK) are very than 10,000 industry leaders and health well organized and regulated by their National care professionals until now. It is a leading Healthcare System (NHS). The UK citizen have telehealth association and is helping to to pay a very massive amount of tax that is transform the health care ecosystem in the approximately 50 percent of their monthly U.S. by helping the government improving wages, in which is included for their premium the quality, equity and affordability of health payment for the NHS services scheme. care throughout the country. As of today, Consequently, all UK citizens does not have to the practice of telemedicine has spread very pay anything else other than the monthly tax, to rapidly and is currently integrated with the receive the best health care service whenever ongoing operations of hospitals, medical it is necessary. The free-of-charge health care specialties departments, home health care services includes everything from consultation, agencies, private physician offices as well as diagnosis, surgery as well as pharmaceutical consumer’s homes and workplaces in the purchases. U.S. Thus, currently telemedicine has become a multi-billion-dollar industry. Every major Due to the involvement of the NHS in paying hospital and health care system in the U.S. have the cost of pharmaceutical products, NHS are leveraged telemedicine in order to transform putting an extensive attention towards the UK’s and to re-invent their health care systems to pharmaceutical industry value and supply chain. be more practical, efficient and effective. In As a result, UK pharmaceutical supply chain is spite of that luxurious condition, telehealth encouraged to be very efficient and effective is still facing a lot of challenges in the US, in executing its business operations. Most of primarily regarding money and regulation. the pharmaceutical products distributors and Reimbursement is commonly cited as a major wholesalers are well integrated with the health

93 https://www.nap.edu/read/13466/chapter/5#21

45 care service providers such as pharmaceutical Predictions and strategic insights retailers and hospitals, this is to reduce the on Indonesian eHealth ecosystem number of mismanagement and keeping all development parties intact with the whole management system. This lead to more efficient health care Rising demand and associated spending cost, as pharmaceutical products prices can be in Indonesia are being fueled by an aging lowered. population; the growing prevalence of chronic diseases and comorbidities; development of Due to this phenomenon, pharmaceutical costly clinical innovations; increasing patient industry retailers and wholesalers enjoyed awareness, knowledge, and expectations; and less profit margin. In return, pharmaceutical continued economic uncertainty. industry retailers and wholesalers will obtain Meanwhile, governments and other patient outcome data that includes patients’ stakeholders are trying to figure out the best feedback, experience and preferences. The path forward: Here’s how much money we have data, which will be proceed into information, is to spend on health care, here’s what we plan to valuable for their future business. do, here are the tools we need to provide high- quality care and services, equitable access, and Over the past couple of years, from the market optimal outcomes for patients at an affordable perspective, pharmaceutical industry in the UK cost. have a slightly difference in consumer or patient preferences, as there is a massive growth of demand of home care and pharmaceutical product delivery. There have been a couple The problems that is caused by the of emerging technology companies that alarming rate at which chronic diseases provide direct-to-home pharmaceutical are increasing in Southeast Asia, products delivery service by both web and coupled with the region’s lack of access mobile application basis. One of the most well-known company is Pharmacy2U, which is to quality and affordable health care, based in Leeds and was established in 1999. are unlikely to be solved with the use Pharmacy2U is the first mover in the industry, of traditional approaches. Rather than which has been approved by NHS. Its business play catch-up with ever-increasing model starts when the patient reaching out Pharmacy2U’s general practitioners (GP) they health care demand in a never-ending want to consult with. Afterwards, Pharmacy2U’s spiral, we should instead leverage GP will review the consultation results and on disruptive innovation to find new determine drugs should be dispensed and sent to the patient. In approximately in 24 hours, the solutions to age-old challenges. Health medicines will reach the patients’ doorstep. care systems need to be proactive and focused on disease prevention, In the wake of modern technology-based era, rather than reactive and focused on patients tend to be spoiled more and more due to the availability of tools that allow them to administering treatments during times enjoy much simpler life. In brief, new business of need. models that merge technologies (e.g. tele- pharmacy, that links business and consumer with a pharmaceutical industry as the supply side), suits really well with today’s business world’s necessities and customer preferences.

46 eHealth Regulatory Issues dr. Slamet, MPH, Special The use of ICT in health care raises a number of challenges related to legal, ethical and Staff for Health issue and governance issues. These concerns and Globalisation opportunities challenge not only patients and health professionals, but also the stakeholders of the implementation of eHealth, including “Ministry of Health have academics, policy makers, industrialist, etc. As we have discussed about the least two acknowledged and oversaw the mentioned issues in the aforementioned rapid growth and development chapter, the issue about the legal approach will of eHealth in the country, we will be discussed in this sub chapter. guide the industry players and Up to now, Indonesia does not have rules related parties of its practices and and regulations regarding digital health care system, so far the only tool, that developed will supervise them.” by the Government of Indonesia related to the issue is teleconsultation and teleradiology Regulation on eHealth in Indonesia guidelines or known as Hospital Pilot testing The Ministry of Health is in the discussion of Video-conference-based tele-medicine and process on the legal status of the teleradiology guideline (Rumah Sakit Uji Coba telemedicine and drafting a regulation Program Pelayanan Telemedicine berbasis on this. The existing Medical Practice Video-conference dan Teleradiologi), which regulation required face to face interaction launched by the Ministry of Health. This is an as a compulsion. One of the point in the unfortunate that any regulation regarding patient confidentiality and safety has not been draft saying that the patient should be launched yet. Although there are lack of legal accompanied by a medical doctor, who is and industry approaches from the ministries, in charge with the patient. Essentially, the the Ministry of Health acknowledged the draft is trying to protect the patient from development and promised its support and the disadvantage that might arise during guidance for the key players of the industry. telemedicine process. “Ministry of Health (MoH) have acknowledged and oversaw the rapid growth and development of eHealth in the country, we will Ministry of Health guide the industry players and related parties of its practices and will supervise them,” said dr. Slamet, MHP, Special Staff for Health issue and “The Ministry of Health is Globalisation, MoH. having internal discussion on the legal status of telemedicine and preparing a draft on this. Essentially through the draft, we want to make sure that the patient are protected from the disadvantage that might arise during telemedicine process.”

47 Important Factors to Implement provided through telemedicine, basically Telemedicine in Indonesia94 the diagnosis cannot be given by the doctor without a face-to-face meeting between the • ICT Infrastructure doctor and the patient. An important step that needs to be done to organize eHealth practice in Indonesia aside In some existing online health care of the regulation is the ICT (Information applications, they provide a disclaimer and Communications Technology) stating that: infrastructure. ICT infrastructure for health 1. IT-based health care application services includes the availability of networks providers do not replace the role of and broadband throughout Indonesia. physicians and / or health care facilities Indonesia’s vast and scattered territory and the applications is not to replace is one of the most difficult constraints face-to-face consultation functions. in providing equitable infrastructure in 2. The physician who serves in the Indonesia, ranging from doctors and nurses, application is entitled to refuse for interconnection and networking capacity, giving advise when the patient’s case is to basic infrastructure such as electricity assessed as an emergency case. and maintenance sites. Based on the 3. Answering a question will not provide aforementioned backgrounds, it is clear that a working diagnosis or a definitive the telemedicine is not only a single issue, diagnosis. The diagnostics that can be but multisectoral one. On that account written are only estimates of diagnosis Ministry of Health should get supports from or possible diagnosis that might be other parties and/or factors. One of those appealed. which is very important is infrastructure. In 4. Answering a question will not provide order to build great system of Telemedicine, definitive therapy in the form of all related factors must be standardized medicines or medical action because in advance in order to make it works well there is no definitive diagnosis. throughout Indonesia.95 5. Answering questions can only provide advice. For eHealth wearable devices (also 6. All interpretations of the statements functioned as telecommunication devices) written in the answers to the patient’s which are made, assembled, imported to questions is entirely the responsibility of be traded and/or used in the territory of the patient. Indonesia are generally required to be 7. Users of the application service are complied with the technical requirements strongly encouraged to always consult under the technology authority through to a family physician or physician for certification process (test and/or document self-medication before starting, altering evaluation). This provision indirectly or terminating an ongoing treatment requires the Electronic System Provider therapist. (ESP) for eHealth purpose in Indonesia to 8. The users are expected to consult assure that the device vendor for its eHealth with a doctor in the case of a medical operation in Indonesia has obtained device complaint.96 certificates. • Protection of Patient’s Data • Diagnosis The point to be taken into account in In providing a diagnosis for the patient, the practice of health care is to maintain the doctor should provide it based on the a complete and accessible quality of examination with the patient in accordance medical record, while maintaining patient to his or her knowledge and expertise, and confidentiality. In addition, documentation in accordance with the standards of medical of patient’s data is also required for the practice. In the case of health services is insurance of the respective patient.

94 Zubairi Djoerban, “Telemedicine Menggagas Pengobatan Jarak Jauh di Indonesia”, http://zubairidjoerban.org/telemedicine- menggagas-pengobatan-jarak-jauh-di-indonesia/, accessed on 24 November 2017. 95 Interview with dr. Slamet MHP (Expertise on Technology-based Health care and Globalization of the Ministry of Health), 8 November 2017. 96 Konsula, “Syarat dan Ketentuan”, https://www.konsula.com/id/syarat-ketentuan, accessed on 24 November 2017 & Tanya Dok, “Syarat dan Ketentuan Konsultasi TanyaDok.com”, https://www.tanyadok.com/ketentuan-ruang-konsultasi/, accessed on. 48 Please note that, in relation to the patient’s to obtain operation license from sectoral medical record, this document shall be authority). In addition to that, registration confidential and may not be shared to as ESP is mandatory, which carries out other party(ies) without the approval from services for public: owns web portal or the patients themselves. However, article online application through internet in 48 paragraph (2) of Law No. 29 of 2004 order to offer its service, owns or provides on The Practice of Doctor and Article electronic system with payment or financial 10 paragraph (2) on the Medical Record transaction within, uses electronic system opens up the possibility for other party(ies) which process, manage, or store user’s to access the patient’s medical record. data, etc. As for any patient medical record Those regulations stating that the patient’s which is in possession of the ESP, shall (i) medical record may be disclosed in the be kept confidential, secure, complete, and event: (i) for the patient’s health interest; (ii) available for the patients to amend, add, or request from the government for the law update their records at any time by the ESP; enforcement; (iii) request from the patient (ii) be based on consent; (iii) be encrypted itself; (iv) stipulated under the prevailing or stored by the ESP for certain period laws; or (v) for research, education and subject to health sector policy (at least 5 medical audit so long it does not mention years if there is no retain period policy in the identity of the patient. respective sector); (iv) be stored in a data center required to be placed in Indonesian Currently Indonesia is still not ready territory. to apply eHealth because of it’s under developed health infrastructure, lack • Informed Consent of specific regulation on electronic Based on the provisions of Article 5 of health record. The only guidance is the the Decree of the Executive Board of the Government Regulation Number 46 of Indonesian Doctors Association No. 221 / 2014 on Health Information System, which PB / A.4 / 04/2002 on the Implementation is not enough to achieve a sufficient data of the Indonesian Medical Code of Ethics center in state hospitals and community (Indonesian Medical Code of Practice) health centers in the region.97 doctors are required to obtain informed Any organizations which serve as the ESP consent prior to advising and/or acting to for eHealth in Indonesia shall (i) provide the patients and only allowed to give the standard procedure of protection which service to the patient for the benefit of the guarantee security or confidentiality of patient. Then, if a physician is unable to patient’s data (in the form of electronic perform an examination or treatment to information or documents); (ii) applying the patient, then upon the consent of the risk management upon any damage or loss patient or their family, the physician should arising out of electronic system operation; refer the patient to a physician who has the (iii) provide and carry out procedure expertise for it. Such provisions need to be and facility to protect electronic system applied and confirmed also in health care from any interference and any material through telemedicine. or immaterial loss; (iv) provide security standard covering procedure and system Apart from that, an application provider to prevent and overcome any thread or stipulates in its terms and conditions that interference attempt. an application provider is not responsible for maintaining medical confidentiality of In providing its electronic system for tele- the user (patient). The background is by health care purpose in Indonesia, basically using the application, the user has given the ESP is required to obtain corporate his consent and has notified the medical general license and if there is foreign capital information open to the public unless the participation, investment license from user uses features that provide private Indonesian Investment Coordination Board space between physicians and the user. (BKPM) is also required (No requirement However, if there is an occurrence that

97 Dr. Mahesa Paranadipa, MH (,..,m), Kamis, 2 November2017.

49 user’s data is being hacked, the application definitive therapy in the form of medicines provider shall not be liable for this and shall or medical measures because there is no be entitled to be relieved of any claims and definitive diagnosis.100 On a separate note, damages incurred.98 currently, we understand that Indonesian National Agency of Drugs and Food Control Under the Electronic Transaction Law, any is in the process to regulate regarding the use of patient personal data via electronic trading of drugs through online platform. system provided by ESP shall be based on From the draft regulation, we note that the consent from the patient (provided by only pharmacy may sell the drugs through ESP) and shall be in line with the purpose online platform and the types of drugs are made known to the patient at the time the also limited.101 data is collected. For example, should any use of data require a transfer or storage Although there is no codified regulatory of personal data outside the jurisdiction, instrument regarding e-prescribing, for any it would be best to inform such conditions future development, Electronic Transaction to the patient and obtain the consent Law widely covers e-signature function as: for transferring and/or storing such data (i) consent of the e-signer in an electronic in other jurisdictions. For reference in agreement or contract (has similar legal obtaining the consent through the provided enforcement as the manual signature); (ii) online health system, it is necessary to note a media to identify a legal subject identity. that Indonesian language is mandatory To be effectively binding, e-signature for (i) all kind of contracts (electronic or shall at least comply with the following physical) involving Indonesian as a party requirements: (i) confidential and only (person or entity); and (ii) contents in the known by the owner of e-signature; (ii) the provided system electronic deployed in authority to use is only provided strictly for Indonesia. the respective e-signature owner; (iii) the e-signature owner may at any time notice • Prescribing any change to the e-signature after its Upon the issuance of this paper, there is execution; (iv) the e-signature owner may no regulation regarding the e-prescription at any time notice any change of electronic and related to the trading of drugs through information regarding the e-signature after online platform. The Medical Code of its execution; (v) there are certain ways Ethics only stipulates that the physician to identify the e-signature owner; and (vi) shall deny to provide any form when there are certain ways to indicate that the attributed or reasonably suspected to be e-signature maker has given its approval to associated with his professional capacity the related electronic system. in prescribing the medicines, including to influence the patient’s or his family’s wish • Medical Liability to purchase or consume the medicines as There is no express regulation covers the he has received or is promised to receive provision of how far ESP liability upon any commissions or profits of pharmaceutical patient’s data leak arising out of its provided companies. Nonetheless, an application electronic system failure. Generally, the ESP provider determines that a health care may be held accountable or sued by any provider does not guarantee that patients person in the event of any loss arising from will be given with the prescription after the provided electronic system. However, the consultation using their application.99 the ESP may limit its liability towards In addition, application providers also any claim filed if the ESP can prove its confirmed that physicians serving in compliance under the prevailing law. the application provider will not provide

97 Dr. Mahesa Paranadipa, MH (,..,m), Kamis, 2 November2017. 98 Tanyadok, “Terms and Condition to Consult at TanyaDok.com”, https://www.tanyadok.com/ketentuan-ruang-konsultasi/, accessed at 24 November 2017. 99 Konsula, “Terms and Condition”, https://www.konsula.com/id/syarat-ketentuan, accessed at 24 November 2017. 100 Tanyadok, “Terms and Condition to Consult at TanyaDok.com”, https://www.tanyadok.com/ketentuan-ruang-konsultasi/, accessed at 24 November 2017. 101 Based on Indonesian Agency of Drugs and Food Control draft of regulation on Supervision of Online Drugs Distribution as of 14 December 2018.

50 • Government Relation Secondly, the business should also partner with There are several circumstances that the association related to the eHealth business. Indonesian-based start ups working in In this case IDI as the Indonesian association of eHealth issues, should pay attention for. medical practitioner (General Practitioner) has One of them is that in the first place they already developed the road map of eHealth in should define the type of business they Indonesia. The discussion or partnership with are getting into. This will be the first step the association will help the eHealth business to for the business to smooth their process take part in the conversation of the roadmap. to get the buy in from the Government. In Besides IDI, there are other associations, which terms of relationship with the governmental should be considered related to the type of agency, there are various types of health business, for eHealth business, which provide business in Indonesia, first is the type of the services related to medical equipment, they service (for instance whether it is directy should consider to have partnership, such related to public health), secondly, the type as ASPAKI (Association of Medical Equipment of the public health service (whether this is Manufacturer), Gakeslab (Association of Medical related to disease prevention and control, Equipment and Laboratorium Companies), and pharmacy and/or medical equipment). The PERSI (Association of Indonesian Hospital). business can be included one or more of relation types. In this case, the main issue The third circumstance is to be able to have is that although the service might get a relationship with other related ministries approval from the related ministry, the kind than the Ministry of Health. For TeleCTG, for of business type will need informal approval instance. The business has built a partnership of the health agencies in the ministry. There with Rural Ministry, as the service will cover are four main agencies in the Ministry of pregnant mothers in rural areas as well. Health, which the eHealth business can be associated with, namely: eHealth Regulation in Australia 1. Directorate General of Public Health (Direktorat Jenderal Kesmas/Kesehatan • Definition Masyarakat) In Australia, health services using ICT is 2. Directorate General of Health Service known as digital health that is defined as an (Direktorat Jenderal Yankes/Pelayanan electronic health information management Kesehatan) to provide health services which is safer, 3. Directorate General of Disease more efficient, and more qualified. Digital Prevention and Control (Direktorat health is used for the several health care Jenderal Pencegahan dan Pengendalian systems in Australia, known as My Health Penyakit Record, Telehealth, and Health care 4. Directorate General of Pharmacist and Identifiers Service. Medical Devices (Direktorat Jenderal Kefarmasian dan Alat Kesehatan) • Informed Consent Informed consent is required when using By keeping good relationship with the above an application, i.e. My Health Record. mentioned governmental agencies, the Before doctors upload patient health or business is not only getting support from them, a prescription into My Health Record, but on the other hand will serve as an update they need approval from the patient.102 for the ministries on the development of health The approval would be sufficient with a business landscape, this would also broadening statement or verbal consent by telling the ministry’s insight and awareness on the directly to the doctor or other health care importance of infrastructure development in providers. the eHealth business. The government relation will play a very important role of doing related In this application, the patient will be given health business in the country. And will lead to a choice regarding the types of information the success of the future of eHealth business in Indonesia.

102 Australian Digital Health Agency, “Digital health and patient consent”, https://www.digitalhealth.gov.au/using-the-my-health-record- system/maintaining-digital-health-in-your-practice/patient-consent, diakses 3 November 2017

51 which will be shown as per their request. the patient declares opt-out, patient data Patients may also be informed with the will not be recorded and entered into My health care providers who uploaded their Health Records system. Once a patient has data into this application and determine enrolled himself in the My Health Records which that allows to system, any information, health-care access their accounts. measures used and health-related data will be accessible to practitioners who provide Basically, any collection, use, and disclosure health care and they can also upload health of health information are authorized for records in My Health Records. the purposes of providing health care to the registered health care recipient and in In addition, the use or disclose any patient accordance with the access controls will be data information is also subject to the set by the recipient. Other lawful conditions Privacy Act 1988. In general, My Health for collection, use and disclosures include Records Act 2012 deals on 3 (three) things: the collection, use and disclosure: (i) for -- Duties and functions of operator; the management or operation purposes -- Registration provisions for patients and of the My Health Record system; (ii) health care providers (individuals or whenever necessary to lessen or prevent organizations) who is willing to participate a serious threats; (iii) authorized by in the My Health Records system; commonwealth, state or territory law; (iv) -- Privacy provisions (in conformity with the for any purposes with the consent of the Privacy Act 1988), which governs that health care recipient; (v) for any purposes entities may access and use information undertaken by a health care recipient in the My Health Records system, and regarding his or her My Health Record; (vi) sanctions may be imposed on the for the purposes of indemnity cover for inappropriate use of My Health Records. a health care provider; (vii) disclosure to courts and tribunals; (viii) disclosure for law Patients who is willing to use My Health enforcement purposes. Records system is required to provide personal information such as full name, date • Protection of Patient’s Data and place of birth, and gender. Meanwhile, Australia uses a national scale system for health care providers must be registered called My Health Records as a digital data in professional associations. center media containing of patient health information. This application provides The law also stipulates regarding sanctions patient health information such as allergies, for unauthorized persons to access, use and medical conditions and treatments, details disseminate the patient’s health information of medicines given to patients, test reports in My Health Records. This violation might be or scans. The data and information can be subjected to sanctions in the form of 2 (two) accessed online by health care providers years imprisonment, meaning that Australia such as doctors, specialists, and hospital is one of the countries which protect staff. personal datas under Global privacy laws and regulations called Federal Privacy Act My Health Records is officially governed and Privacy Principles (APPs) by the law, My Health Records Act 2012. In addition, basically, registered health care In order to obtain digitally recorded providers in My Health Records may access health data in My Health Records in most and use such patient data or information areas of Australia, the patient have to in My Health Records for the purpose to register in My Health Records website first. provide health services, subject to the However this requirement does not apply consent from the patient. If the registered Northern Queensland or the Nepean Blue health care provider is willing to upload the Mountains residents, who listed in the data or health information of the respective Medicare insurance program, as they will be patients into My Health Records, registered automatically enrolled into the My Health health care providers must fulfill the Records system. For residents who are requirements in which the uploaded data not willing to put their data into My Health shall be approved by the relevant patient Records, they have to use opt-out rights. If and has complied with the provisions of the

52 legislation, both at the national level and practitioners. Unlike the U.S. Government, territorial level states. However, there is the Australian Government does not exceptions on the provisions of access and regulate credentialing and privileging for disclosure of health information related to a specific eHealth care provider. The rules a serious and public safety issue in which, on credentialing and privileging in Australia the system operator is authorized to give is applied for health care providers and permission to the health care provider to practitioners in general (conventional, not IT disclose related information. based). A health care provider organization may apply to the System Operator of My Health Under the guidance, the Committee Record. In that regard, such organization is responsible for credentialing and should apply this following steps: (1) has determining the scope of practice which been assigned a health care identifier as in shall be in accordance with the prevailing Health care Identifiers Act 2010, (2) comply regulation, such as without any conflict of with My Health Record Rules enacted by interest, discrimination, and not violating the Commonwealth Minister for Health; (3) privacy and practice of trade. has agreed to be bound the conditions imposed by the system operators on In addition, the Committee is responsible registration. The Health Record Rules 2016 for ensuring that health care providers specifies, inter alia, such organization must understand their duties and responsibilities take reasonable steps to ensure that they and do their duties and responsibilities and their employees exercise due care in good faith, establishing policies and and skill: so that any record is accurate, procedures to ensure that committee update, not misleading, not defamatory; members do not have any conflict of interest and fit with purpose. Other requirements in the credentialing and privileging process. for such organization includes requirement to maintain interoperability, to provide To obtain credentials, practitioners or assistance at the System Operator request, medical personnel is require to provide and and tonly upload to a repository advanced fulfill the following requirements: 103 care planning information. Further, persons 1. Details of work experience (as medical may apply for registration as a repository personnel), attached with its by evidence operator, a portal operator, or a contracted 2. Details of educational and training service provider. For these kind of persons, data, along with relevant diplomas and they required to register with and should certificates. be linked to one or more registered health 3. Details of involvement in the clinical care provider organization, to only access My audit process, peer review activities and Health Record to the extent that they have continuing medical education programs. been instructed to do so by a linked such 4. Summary of climatic activity within the organization, to notify the System Operator last 12 (twelve) months in all locations of certain things, such as inaccurate where the medical personnel provide provenance information, error in a record, health services, including patient location, no longer linked with such organization, type of provided, procedures, diagnostic undergone material changes, etc. All those records, and consultation results. participants in My Health Record shall 5. Details of accreditation or award given by comply with security requirements as in The professional colleagues or associations Health Record Rules 2016. relating to health care. 6. Provide written consent for the • Credentialing and Privileging Committee to conduct credentials and In 2015, the Australian Commission on determine the scope of practice that will Safety and Quality in Health Care (the be provided to the respective individual “Committee”) publishes guidebooks on or organization. credentialing for health care providers and

103 Paragraph 8.6 of Standard for Credentialing and Defining the Scope of Clinical Practice.

53 Moreover, the Committee is responsible for hold the record, or take the record, outside verifying such data. Australia, or process relating to the record outside Australia. As for the ESP which provides electronic system for eHealth purpose, has to refer to • Medical Liability, Standards, and general business establishment in Australia: Malpractice Claim business entity shall obtain recognition Accreditation agencies in health care in and registration, either from an Australian Australia creates health care delivery Company or a Foreign Company, before standards in general which use electronic Australian Securities and Investments media. The following is the standards made Commission c.q. Investors and Financial by some accrediting agencies in Australia: Consumers. This includes an obligation to obtain National Business Name Registration 1. National EHealth Security and Access according to Business Names Registration Framework (NESAF) Regulation 2011 AG. As the eHealth services dealing with personal data, business entity The NESAF, published by the National shall comply Privacy Act 1988 AG and Privacy EHealth Transition Authority (NEHTA), Regulations 2013 AG through, for example, was established to provide guidance to adopting code of practice. If it is categorized all health care provider organizations, as a medical device, the supplier shall follow regardless of their organizational capacity Therapeutic Goods Act 1989 AG. Apart or complexity of eHealth services. In from those, a business entity requires IPRs general, NESAF provides guidelines for licenses (e.g. copyright, trademark, patent health care providers to establish and right, etc.) implement security systems to protect patient’s data and other assets related • E- Medical Record to eHealth to ensure patient safety and The legislation on e-medical record is My privacy, which consists of: Health Record Act 2012 which defines that a. A set of principles that guide the record as the record of information that is implementation of eHealth. created and maintained by system operator b. A framework that identifies controls in relation to the health care recipient, and over access and security. information that can be obtained by means c. A risk-based approach to support the of that record, including information in implementation of the framework, the register that relates to the health care including analysis of gaps and recipient, other information connected in the risks which can be used by the record system to the health care recipient, organizations to assess the risk levels and back-up records of such information. and compliance with the prevailing regulations. The Act 2012 substantively deals with d. Toolkit that provides comprehensive registration of health care organization and relevant information regarding the likes with the System Operator, including eHealth procedures, with security and suspension, cancelation, suspension and access functions. variation of registration. Here, the System Operator must establish and maintain a 2. Computer Information Security Register. The authorization according to Standards (CISS) that Act 2012 is also equal to authorization of collection, use or disclosure for the The Computer Information Security purposes of Privacy Act 1988. To respond Standard (CISS) provides general any complain, Privacy Commissioner has guidance on the common practice power to exercise investigation and do by providing specific guidance to anything incidental. If data breach occurs/ specific communities. This guidance aware, the health care provider information provides risk evaluation and the way to (all participants) shall notify the System increase the competency and capacity Operator, or both Privacy Commissioner in computerization and information and the System Operator as the soonest. protection. Further, the System Operator must not

54 • Malpratice determined by scanning the barcode code Patients may make claims for medical contained in the e-prescription. negligence or medical malpractice under Australian medical malpractice laws. Medical E-prescribing is guided by National negligence or medical malpractice claims Requirements for Electronic Prescriptions are made against individual health care v1.0 (DH-2625:2017). The end product of providers as well as publicly funded hospitals e-prescribing provides specification and that employ professional medical personnel. guidance documents for software systems creating and processing prescriptions All participant in the My Health System in electronic form. the DH-2625:2017 (expert for the Operator of which), they require the generation of e-prescribing shall maintain interoperability with that must meet the following criteria, inter alia, system, and if not compliance, the Operator (1) only health care professionals with may suspend the participant’s access. On the legal right to prescribe medicines can condition that a software/application is use the e-prescribing system to generate categorized as a “medical device”, such e-prescriptions; (2) the prescriber must be software or application follows offences and issued with a login and use that login to civil penalty provisions relating to medical perform all action in e-prescribing system, devices as in Therapeutic Goods Act 1989. (3) information about access to, use of Non-medical software/devices, however, do and time of uses is preserved for audit not follow such provisions, but effectuate in and enforcement purposes; (4) the issuers a software license agreement which partly of that login shall take reasonable steps is regulated by Competition and Consumer to protect that login and ensure it is not Act 2010 where in default the creator of used by another person; (5) on the display software is responsible for services included of e-prescribing system must show the in the software, subject to exceptions. particulars of the prescription required by legislations, obtain a final approval from • Prescribing the prescriber, including a unique identifier E-Prescriptions, or more commonly known of the prescriber; (6)the prescriber must as Electronic Transfer of Prescriptions re-present his/her login when approving a (ETP) is an electronic prescribing e-prescribing for a drug of dependence or management system of specialists, dentists, misuse; (7) any data of e-prescribing system ophthalmologists, nurses etc.) for patients shall be stored in a permanent and non- in Australia using an electronic system alterable. called Prescription Exchange Service (PES). Currently, there are two PES operating • Big Data for Research systems in Australia, namely eRx Script Access to health information of patients or Exchange and MediSecure. Both of these health care recipients can be obtained by PES operating systems have been approved health care provider or organizations who by the Australian Government and are already assigned health care identifiers as required to meet the prescribed standards regulated in Health care Identifiers Act 2010. relating to security and privacy. A pharmacy In assigning such identifiers, the health or medical practice may be connected to authority (Chief Executive Medicare) may one or both of the PES systems. collect information from various sources for the purposes of assigning those identifiers. How e-Prescription works is a prescriber (doctor) makes an E-prescription, then In a research activity, the Agency has official E-Prescription is inserted into the PES roles to evidence-based policy research system and automatically send to the for establishing and evaluating digital intended pharmacist. The electronic health. As for this purpose, private or prescription will be stored in PES and other researchers may request research protected by PES system until the recipe is partnership with the Agency on condition downloaded by the authorized pharmacist. their research are relevant with the Agency’s The E-Prescription is then printed by a priorities, which include public governance pharmacist. The prescription information or performance rule 2016, the national contained in the e-prescription can be digital health strategy, benefits attributable

55 to the My Health Record, the Agency Principle (APP) - Cross-border disclosure of corporate objective. Of which health strategy personal information (APP 8). APP 8 create document, the Agency opens any innovation a framework for the disclosure of personal and scientific achievements in health care information across the borders. This from entrepreneurs and researchers. As an framework generally requires health care example, that national strategy elaborates providers to ensure that the recipients of an example that mobile applications employ information will use the health information data mining methods to help diagnose in accordance with APP, and impose or pneumonia. liability on the provider if the recipient of the information use the information The specific legislation on research or big inappropriately. data on health care or eHealth, however, do not regulatory embodied by laws, except eHealth Regulation in the United States for APP (Australia Privacy Principles) as stated in Privacy Act 1988. APP delineates • Definition several basic principles for processing Beside eHealth, another common terms data where such processing shall be: (1) in United States are telehealth and open and transparent ways: e.g. a clear telemedicine. However, there is slight expressed and up-to-date privacy policy; (2) difference in the scope of services for those giving option of not identifying individuals: terms. Telehealth is a collection of tools or anonymity and pseudonymity; (3) processing methods to improve health care services, a strict necessary of data directly related to public health, and health education using functions/activities; (4) destroying unsolicited telecommunication technology. Telehealth personal data or de-identified; (5) notifying covers a wide range of technologies and data owners about their data processing systems to provide virtual medical, health, at or before the time of processing; (6) not and education services.104 Telemedicine is using or disclosing the collected personal the use of electronic communication and data for another purposes peculiar from information technology to provide a clinical primary purpose; (7) not using personal data picture of the service when participants are for direct marketing, unless data is directly in different locations (whether they are in collected from data owners, under the scope remote areas, are of in an off-site location, of reasonability expectation of individuals, or are online). Telemedicine has system and respond an objection by a data owner that can be used by health care providers at anytime; (8) not transfer personal data to to extend not only face-to-face treatment the overseas recipients, unless permitted practices. Telemedicine is often used when by laws or courts, and a data owner grants referring to traditional clinical diagnosis explicit consent; (9) not using a government and monitoring delivered by technology. related identifiers of an individual; (10) However, the term telehealth is now more collected personal data must be accurate, up commonly used because it describes a to date, and complete; (11) data controllers wide range of diagnosis and management, must adopt security measures to protect education, and other health care fields. the data; (12) granting access right for data This is including but not limited to, dental owners, right to correction, as well. services, counseling, physical therapy, home health, monitoring and management of • Cross-Country Practice chronic diseases, disaster management, and Australia does not explicitly regulate the consumer and professional education.105 disclosure of information or telemedicine practices across States in Australia. • Informed Consent However, the prevailing laws regulates There are various requirements for the cross-border disclosure of personal states in the United States (U.S.) related to information in Chapter 8 Australian Privacy informed consent in telemedicine practices.

104 The Center for Connected Health Policy, “What is Telehealth”, http://www.cchpca.org/what-is-telehealth, accessed 16 October 2017. 105 Ibid. 106 Teresa Iafolla, “Telemedicine & Informed Patient Consent: Done the Right Way”, http://blog.evisit.com/telemedicine-informed- patient-consent-done-right-way, accessed on 13 October 2017

56 Some countries require informed consent 5. Inform patients about what will happen from the patients before the treatment in the event of a technological or or telemedicine services are undertaken. equipment failure during a telemedicine However, several states do not require session and an emergency plan. informed consent, and another states only require informed consent for certain forms Furthermore, the U.S. Food and Drug of electronic communications (such as Administration’s (FDA) has formulated a plan on e-mail or text messages). Although informed informed consent, which contain several basic consent is not required by several states in elements of informed consent as follows : (i) the U.S., but it is still the recommended best provide a description of the clinical investigation practice so far. Several organizations such to be provided to the patient; (ii) provide a as the Federation of State Medical Boards description of the risks and adverse conditions (FSMB) and the American Telemedicine that may occur to the patient; (iii) the benefits of Association (ATA) recommend that that the medical action to be performed on the patient; doctors should obtain informed consent to (iv) inform the patient regarding alternative use telemedicine technology. procedures and treatments that may be beneficial to the patient; (v) confidentiality; (vi) There are three components should be medical compensation and treatment in the considered in creating informed consent:106 event of injury; (vii) contact numbers of the 1. The language used in introducing patient; (viii) a statement that the patient has and explaining the telehealth process voluntarily accepted a medical action.107 should be in a manner that it is easily understood by the patient; Patient consent usually captured on a paper 2. Describe the risks and benefits consent. Electronic consent management expected from telehealth services; and enables this process to occur in a fully 3. Other information is required for electronic manner (an electronic consent the patient to have a complete directive) and various laws, regulations, and understanding of the telehealth process policies for access and restrictions on sharing (ie: available alternatives, referral information particularly sensitive information information, etc.). are handled in an automated way health information technology (IT) system. In general, The following is the information to be there are three phases in informed consent included in the informed consent as management:108 recommended by ATA: • Phase I – Consent is captured on paper 1. To inform patients about their rights forms and scanned into HER systems. when receiving telemedicine services, These forms do not contain structured including the right to terminate or refuse data. Provider staff must read and analyze treatment; the consent from before information is 2. To tell the patients about their own shared. responsibilities when receiving • Phase II – Consent may be collected on telemedicine services; paper and then entered into an electronic 3. Have formal procedures to format, on consent may be recorded accommodate and resolve potential digitally from the start using web portal or complaints or ethical problems that devices. may arise as a result of health services • Phase III – Consent is collected (telecare); electronically and structured data is 4. Explain the potential benefits, captured. constraints, and risks (such as privacy and security) of telemedicine;

106 Teresa Iafolla, “Telemedicine & Informed Patient Consent: Done the Right Way”, http://blog.evisit.com/telemedicine-informed- patient-consent-done-right-way, accessed on 13 October 2017 107 https://www.fda.gov/downloads/RegulatoryInformation/Guidances/UCM405006.pdf, accessed on 24 January 2018. 108 https://www.healthit.gov/sites/default/files/privacy-security/ecm_finalreport_forrelease62415.pdf, accessed on 20 May 2018

57 Title 45 of Code of Federal Regulations (CFR) 3. Technical Security (§ 164.312 CFR) (known as “45 CFR”) basically stipulates that a Health care providers should implement patient’s written consent need only be obtained technical policies and procedures by a provider once. The consent document for electronic information systems in may be brief and written in general terms. At order to safeguard electronic health a minimum, it must inform the patient that information by granting access only information may be used and disclosed for to authorized persons or software treatment, payment, health care operations programs. Implementation of this (or TPO), state the patient rights to review the technical security is done by: (i) unique privacy notice, to request restrictions and to user identification; (ii) emergency access revoke consent, and be dated and signed by procedure; (iii) automatic logoff; (iv) the individual or his or her representative. encryption and decryption.

However please note that the patient may 4. Organization Security (§ 164.314 CFR) revoke in writing, except to the extent that Safeguards against the organization of the covered entity has taken action in reliance health care providers are made through on the consent, and the patient may request agreements with the government on restriction on uses or disclosures of health compliance in which the Government information for TPO. will define the security standards

• Protection of Patient’s Data 5. Required Policies and Procedures and Health care providers are required to Documents (§ 164,316) comply with the provisions of the security The health care provider shall adopt implementation standards specified in appropriate policies and procedures to Sections 164.308, 164.310, 164.312, and comply with the government standards, 164.316 of 45, Code of Federal Regulations specifications or requirements. Health (CFR) as follows: care provider entities may change their policies and procedures at any time, 1. Administrative Security (§ 164.308 CFR) provided they are documented and Health care providers should reported to the National Coordinator. implement policies and procedures to prevent, detect, post, correct In addition, the Health Information Technology violations of security procedures, and Clinical Health (HITECHT) Act also provide protect data, and apply authorization a procedure for health care providers that and approval systems from each party violates the health data/information security to each transaction. These efforts are provisions. In the event that the health care implemented by applying risk analysis, providers found any violation of the use of risk management, sanctioning, and health data/information when accessing, evaluation of information systems. modifying, recording, storing, removing, using, or disclosing information to a person’s health 2. Physical Security (§ 164.310 CFR) data, they shall notify the owner of the health Health care providers should implement data/information. Such notice shall be made policies and procedures to limit physical in no later than 60 days after they found such access to existing electronic information violation. The burden of proof of such violation systems and facilities while ensuring is charged to the party who discovered the that the access is legitimate. These violation. They shall prove that the violation efforts are implemented by creating is not committed by them and they have contingency operations, preparing notified the owner of the data/information in security facility plans, establishing accordance with the provisions in the HITECH procedures for controlling access and Act. validation, and controlling data storage including in the event of physical changes to the data.

58 A notice of violation must include the following: provisions of Section 1176 of the SSA. Section 1. A brief description of the case, including 1176 of The SSA stipulates sanctions in the the date of the violation and the date of the form of fine. The amount of fine is vary in violation has been found (if applicable). accordance with the violation. 2. Explanation of the types of health data/ information which being violated (such as • Credentialing and Privileging full name, social security number, date of The national health organization in United birth, home address, account number, or States, i.e., The Centers for Medicare & code). Medicaid Service (CMS) is responsible for 3. Steps to be taken to protect themselves accrediting and validating the competence from potential losses resulting from such of medical personnel through credentialing violation. and privileging. In the context of telehealth, 4. A brief description of the entity involved in if the CMS has to do the credentialing and violation, to reduce the loss, and to protect privileging process which used an online against further violations. health site provider in consultation, it 5. Procedures for individuals to ask additional will cause an administrative burden. To questions or information, which should mitigate this burden, the Joint Commission include phone numbers, e-mail addresses, (TJC) establishes a standard that allows websites, and residential addresses. hospitals to conduct its own credential and privileging. The provision also allows Failure of the security provisions may be subject hospitals to receive services to make to sanctions as regulated in Section 1176 and credential and privilege decisions for online 1177 Social Security Act (SSA). Section 1177 health care providers. SSA stipulates that sanctions against violations might be imposed if: However, prior to 2011, the CMS 1. Utilization of unique health identifier; rated these standards is in contrary to 2. Obtain identifiable medical information of a their current Medicare Conditions of person illegally; and Participation (CoPs). To address this, 3. Disclose an individual’s identifiable health CMS made amendments to CoPs in July information to others. 2011 that allowed hospitals to be granted proxy credential and privilege powers. TJC Failure of the above matters might be imposed followed a few months later by revising by: its standard rules in accordance with 1. Fine maximum amounting to US$50,000 or CMS (CoPs) rules. Provisions within the imprisonment for not more than one year, CoPs require that hospitals to have a or both; credentialing and privileging process for 2. If the defense is made by using false all practitioners providing health care information, fine maximum amounting to by not distinguishing the credentialing US$100,000 or imprisonment for not more and privileging for practitioners who also than five years, or both; and provide eHealth/telehealth services. In 3. If a violation is committed with a view to addition, the CoPs also stipulates that selling, transferring or using individually hospitals are required to fully accept the identifiable health information for credentialing and privileging made by commercial gain, personal gain or an online healthcare provider (eHealth/ harmful cause, subject to a maximum fine telehealth entity) for each practitioner on amounting to US$250,000 or imprisonment an online-based health service, and treat not more than 10 years, or both. as practitioners as physically present at home.109 In the case of a violation other than the action as stipulated under Section 1177 of the SSA, Against these provisions, CMS through CoPs the applicable sanctions shall refer to the determines that between the hospital and

109 Greg Billings (Senior Director of Center for Telehealth and e-Health Law), Telehealth Credentialing and Privileging Final Rule from Centers for Medicare and Medicaid Services, page. 1.

59 the online health care provider, a written The main tasks for National Coordinators agreement should be made. Through the are to review and set standards and written agreement, the organization should certification criteria for the exchange and ensure that the processes and standards use of electronic data and information of credentials and privileges from eHealth recommended by the HIT Standard service providers meets the CMS-defined Committee for adoption by the U.S. standards and compliance with those Government. standards is entirely the responsibility of eHealth health care providers. Moreover, Moreover, the HITECH Act also stipulates the agreement must be determined that clear provisions for the use of technology in the organization ensures that in providing eHealth applications, particularly in terms their services, the telemedicine entity is of electronic health records (EHR). Before required to comply with all applicable CMS it is released and can be used by the public, standards.110 the National Coordinator will ensure the To be able to take advantage of the feasibility and quality of EHR technology and credentialing and privileging process, there establish certification of the technology.111 are requirements that must be fulfilled, For health care providers who is willing to among others: adopt such technology, they will be charged 1. There must be a written agreement by the National Coordinator in which between both parties (between the the amount of the fee is adjusted to the hospital and the telehealth service condition of the health care provider. Funds provider); generated from these technology adoption 2. Hospitals which also act as telehealth payments will then be allocated to smaller, service provider must be part of low-income, and service providers in rural medicare participating hospital or areas that are medically inaccessible.112 telemedicine entity; 3. Telehealth providers obtain privileges Supervision on the quality of health from the hospital. services is also carried out at the state 4. The telehealth provider holds the license level. Government in U.S. State has the issued by the country from which the duty to administer and sponsor a health hospital location is located. care program. Against this policy, the State 5. The home hospital has an internal review Government is required to enter into an of the telehealth provider’s performance agreement with any health care provider, and provides this information to other health planning or health insurance that hospitals. the provider in the information technology system used must comply with the • Medical Liability, Standards, and standards and specifications set by the Malpractice Claim Government.113 Through the HITECH Act, the planning, implementation, and oversight of the In 2014, the telemedicine organization implementation of the eHealth program at the United States, the American has been stipulated. Moreover, based Telemedicine Association (ATA) has on HITECH Act, the National Coordinator developed a guideline for telemedicine of the Office of Health Information services, namely: Core Operational Technology (Office of National Coordinator Guidelines for Telehealth Services Involving for Health Information Technology) was Provider-Patient Interactions. The guidelines established under the Department of has been well received by the telemedicine Health and Human Services (HHS). The community and adopted in various National Coordinator is responsible for the practices, and also used in research to development of information technology in the field of health on a national scale.

110 Telehealth Resource Centers, “Credentialing and Privileging”, https://www.telehealthresourcecenter.org/toolbox-module/ credentialing-and-privileging, accessed 13 October 2017. 111 Section 3007 (a) dan (b) HITECTH Act. 112 Section 3007 (c) HITECTH Act. 113 Section 13112 HITECH Act.

60 support the practice and development of Idaho. There are also several states that telemedicine114. The guidelines is addressed prohibit online prescribing or e-prescribing to individual practitioners, groups and for certain dangerous categories of special practices, hospitals and health medicines, such as California and Arizona. care systems, and other health-related However, there are different restrictions service providers where there is telehealth on the two states. California prohibits the interaction between patients and providers provision of online dangerous medicines for health care purposes. The guidelines without direct examination of patients and applied to healthcare providers and their doctors, while Arizona determines that the patients residing in the U.S. territory. If one prescription of such a dangerous medicine or both parties are not located in the U.S., can be performed without direct physical the guidelines may be referred but should examination between medical personnel still refer to local guidelines. and patients. Examination may be performed using telemedicine services and Contemporary EHR system technology shall be supported by an EHR that meets has significant limitations, and if these the certification requirements as required may cause harm, aggrieved individuals by the Arizona Government.115 and enforcement entities have many legal resources. Plaintiffs whose alleged injuries Requirement of prescription or are associated with EHR systems could e-prescription by a pharmacist/practitioner sue health care providers for medical is basically regulated under the 21 CFR. malpractice. Those who believe that their records have been improperly disclosed to A pharmacist may dispense directly a third parties could assert privacy violation controlled substance (listed in Schedule II claims. In rare circumstances, providers of 21 CFR) that is a prescription drug only accused of negligent EHR system use could pursuant to a written prescription signed face disciplinary proceedings (initiated by by the practitioner, except in the case of professional organizations), government emergency. In the case of an emergency enforcement actions, or criminal situation (as defined in 290.10 of 21 CFR), prosecutions. a pharmacist may dispense a controlled substance upon receiving oral authorization Patients who feel that their care givers of a prescribing individual practitioner, were negligent in treating them may assert provided that: medical malpractice claims. To prevail, the plaintiff must establish the four elements (1) The quantity prescribed and dispensed of negligence :(1) a duty of care owed by is limited to the amount adequate to treat the defendant to the plaintiff,(2) breach of the patient during the emergency period that duty through conduct that fails to meet (dispensing beyond the emergency period the applicable standard of care,(3) harm must be pursuant to a paper or electronic or injury, and (4) a causal link between the prescription signed by the prescribing injury and the breach of duty. individual practitioner); (2) The prescription shall be immediately • Prescribing reduced to writing by the pharmacist and Each state has different provisions related shall contain all information required, to online prescribing or e-prescribing, except for the signature of the prescribing whereas the majority of states claimed individual practitioner; that a physical examination is required prior to prescribing. However, not all states (3) If the prescribing individual practitioner require direct physical examination. The is not known to the pharmacist, he must states that adopt the rules which require make a reasonable effort to determine direct physical examination are New that the oral authorization came from a Jersey, Indiana, Tennessee, Colorado, and registered individual practitioner, which

114US National Library of Medicine National Institute of Health, https://www.ncbi.nlm.nih.gov/pmc/articles/PMC4934495/, accessed 16 October 2017. 115 Health Current, “Controlled Substances”, https://healthcurrent.org/information-center/e prescribing/controlled-substances/, accessed on 8 January 2018.

61 may include a callback to the prescribing Initially, Medicare only replaced the individual practitioner using his phone very specific health care costs that were number as listed in the telephone directory provided through telemedicine with and/or other good faith efforts to insure his strict requirements. In recent years with identity; and the rapid growth of the telemedicine industry, Medicare has expanded the list (4) Within seven days after authorizing an of reimbursable telemedicine services, but emergency oral prescription, the prescribing still imposed many restrictions on the way individual practitioner shall cause a healthcare is delivered. written prescription for the emergency quantity prescribed to be delivered to Almost all the U.S. states (except the dispensing pharmacist. In addition to Connecticut and Rhode Island) offers conforming to the requirements of the some form of reimbursement insurance Code of Federal Regulation § 1306.05, the for telemedicine under the state prescription shall have written on its face Medicaid program. Some state Medicaid “Authorization for Emergency Dispensing,” programs provide widespread coverage and the date of the oral order. The paper for telemedicine reimbursement, without prescription may be delivered to the specifying the patient’s location boundary or pharmacist in person or by mail, but if health care provider. delivered by mail it must be postmarked within the seven day period. Upon receipt, The American Telemedicine Association the dispensing pharmacist must attach this (ATA) released a comprehensive report on paper prescription to the oral emergency Medicaid state coverage for telemedicine:116 prescription that had earlier been reduced 1. 48 Medicaid state programs include to writing. For electronic prescriptions, telemedicine the pharmacist must annotate the record 2. 24 states include telehealth for civil of the electronic prescription with the service work plans original authorization and date of the oral 3. 24 states and DC (Distric of Columbia) order. The pharmacist must notify the have no special requirements for patient nearest office of the Administration if the location prescribing individual practitioner fails to 4. 25 states recognize the patient’s home deliver a written prescription to him; failure as a place of origin of the pharmacist to do so shall void the 5. 82% of country of U.S. covering authority conferred by this paragraph to telemedicine as a whole, without dispense without a written prescription of a limitation of distance between providers prescribing individual practitioner. and patients 6. 15 states and DCs do not set limits (5) Central fill pharmacies shall not be on which health care providers can authorized under this paragraph to prepare telemedicine prescriptions for a controlled substance upon receiving an oral authorization Medicare telehealth services may be from a retail pharmacist or an individual provided to eligible Medicare beneficiaries practitioner. even though the medical personnel providing telehealth services are not located • Payment in the same place as the beneficiaries. As United States has the telemedicine a requirement, telehealth services must financing policy in which states may be provided through an interactive audio provide reimbursement on telemedicine and video telecommunication system services provided that they meet state-of- that provide in real time communication the-art efficiency, economic and quality between beneficiaries and practitioners in requirements. This provides an opportunity different places. The CMS defines “qualified for states to define program criteria that telehealth beneficiaries” as individuals earn reimbursements according to their registered under Medicare.117 policies.

116 eVisit, “Telemedicine State Policy Landscape”,https://evisit.com/state-policy-landscape/, diakses 20 Oktober 2017. 117 Scott A. Edelstein and India K. Brim, Telemedicine: An Interactive Approach to Healthcare in the Wake of Healthcare Reform, page. 2.

62 health worker providing inter-state health Unlike Medicare, CMS has not yet officially services must have a practice permit from mandated the coverage of telehealth the state where his or her patient is located. services reimbursement under the However, in the event of an emergency, Medicaid program. Each state has a policy such provisions may be disregarded. to determine the reimbursement of health services covered by Medicaid, including In addition, several states issue special telehealth applications. Medicaid will permits or certificates related to the reimbursement of health services that meet practice of telemedicine. There is also a state requirements. CMS has encouraged state that does not specifically issue a states to take advantage of this flexibility to specific telemedicine practice permit, but create an innovative payment methodology may issue a temporary medical license for telemedicine services. for a health worker from another state provided that the health worker meets the As provided by the § 54 CFR, a relevant entity requirements.118 may use and disclose ‘protected health information’ (PHI) for payment purposes. For example, the State of Indiana in the Payment is a defined term that encompasses code, IN Code, 25-1-9.5 health workers various activities of health care providers outside Indiana are not allowed to provide to obtain payment or be reimbursed for health services to Indiana residents their services and for a health plan to without the express written permission to obtain premiums, to fulfill their coverage practice issued by the Indiana Professional responsibilities and provide benefits under the Licensing Agency. The licensed health plan, and to obtain or provide reimbursement care professional of the agency is directly form the provisions of health care. considered to be subject to the law in Indiana.119 In addition to the general definition, the § 45 Different things are governed by the State CFR provides examples of common payment of Mississippi. Based on MS Code Sec. 73- activities which include, but are not limited 25-101, Mississippi regulates, acknowledges, to determining eligibility or coverage under a and becomes a member of the Federation plan and adjudication claims, risk adjustments, of State Medical Board (FSMB) that billing and collection activities, reviewing health accommodates intravenous health care by care services for medical necessity, coverage, allowing health workers to practice in other justification of charges, and the like, utilization states. review activities and disclosures to consumer reporting agencies (limited to specified eHealth Regulation in Malaysia identifying information about the individual, his or her payment history and identifying • Definition information about the covered entity). Malaysia uses telemedicine terminology for health services using ICT. The concept • Cross-Country Practice of telemedicine itself emerged in Malaysia Under Article 10 of the United since 1997 and has been regulated in the States’constitution, the state is authorized Laws of Malaysia Act 564, Telemedicine to regulate the health, security and welfare Act 1997 (Malaysia Telemedicine Act) aspects of its citizens. To be able to practice which specifically defines telemedicine as health care, every health worker is required a medical practice that uses audio, visual, to obtain a practical license from the state. and data communications. In addition to In the case of telemedicine, the requirement Malaysia Telemedicine Act, the definition to obtain a permit, the health worker shall of telemedicine by Malaysia Ministry of ensure that its activities are legally valid. Health can also be found in Malaysia’s With Telehealth, the provision of health Telemedicine Blueprint published on July services is possible by health workers and 25, 1997, which stipulates that telemedicine patients in different places (states). Each means “far-reaching medicine.” At the state has its own rules. The majority of practical level, telemedicine refers to states have strict rules governing that any the practice of providing health services

63 related to telecommunications, information relating to informed consent as below: (i) and multimedia technologies to connect Mental Health Act 2001; (ii) Guardianship participants in the health system.120 of Infants Act 1961; (iii) The Law Reform (Marriage and Divorce) Act 1876; (iv) • Informed Consent Private Healthcare Facilities and Services Information consent can be said to have Regulations 2006; (v) United Nations been given based upon a clear appreciation Convention on The Rights of the Child, and understanding of the facts, implications, 1989; and (vi) The Malaysian Medical and future consequences of an action. In Council Ethical Guideline on Audio & Visual order to give informed consent, the person Recordings. concerned must have adequate reasoning capacity and be in possession of all relevant In general, there is not any procedure, facts at the time consent is given. This term examination, surgery or treatment may was first used in a 1957 medical malpractice be undertaken on a patient without case by Paul G. Gebhard in USA. the consent of the patient, if she or he is a competent person. Consent of In relation to valid consent, the definition the patient must be obtained before of valid consent is a voluntary agreement the proposed procedure, examination, by an individual to a proposed procedure, surgery or treatment is undertaken, given after appropriate and reliable except for emergency where the need to information about the procedure, including save life is of paramount importance. A the potential risks and benefits, has been medical practitioner is obliged to disclose conveyed to the individual. It is generally information to the patient and to warn the accepted that consent to be “valid” should patient of material risks that might happen be “informed”. The requirements for before taking consent. Failure to obtain obtaining valid consent are: (i) it must a patient’s consent or disclose material be given by a person with legal capacity risks may be interpreted as a failure of the and of sufficient intellectual capacity to standard of care which would be resulting understand the implications of undergoing in a disciplinary inquiry by the MMC or may the proposed procedure; (ii) it must be be construed as a breach of duty of care taken in a language which understood by and legal action constituted. The Federal the person; (iii) it must be given freely and Court of Malaysia has, in fact, reaffirmed voluntarily, and not coerced or induced in the case of Kok Chong Seng & Sunway by fraud or deceit; (iv) it must cover the Medical Centre v Soo Cheng Lin in 2017 procedure to be undertaken; (v) the that the legal standard for the provision person must have an awareness and of information to patients is the Rogers v understanding of the proposed procedure Whitaker principle, i.e. doctors have a duty and its known potential risks; (vi) the person of care to disclose material risks. Patients must be given alternate options to the who are young person (minors under the proposed treatment or procedure; (vii) the age of 18) do not have capacity to give person must have sufficient opportunity to valid consent. Consent may be gained from seek further details or explanations about the minor’s legal guardian. With regards the proposed treatment or procedure; (viii) to infants, medical practitioners should there must be a witness or interpreter, consult or obtain the consent of the infant’s who may be another registered medical legal guardian, referring to Guardianship practitioner or a nurse, who is not directly of Infants Act 1961. For patients who are involved in the management of the patient incapable of, or impaired with, decision- nor related to the patient or the medical making ability, consent may be obtained practitioner, or any such person who can from a relative, next-of- kin or legal guardian speak the language of the patient, to attest of the patient. Complaints may be made to to the process during taking of the consent. the MMC or MOH (Ministry of Health) which regulates the profession. According to the guideline by Malaysian In addition, Malaysian Personal Data Medical Council (MMC), the main regulatory Protection Act 2010 as at 15 June 2016 body of Malaysian medical practitioners, (PDPA): any personal data consisting of the relevant laws, regulations or guidelines information as to the physical or mental

64 health or condition of a data subject purpose for which the personal data was to (sensitive personal data) shall only be be disclosed at the time of collection of the processed by a data user upon explicit personal data or a purpose directly related consent of the respective data subject. to the purpose at the time of collection), Sensitive data processing for medical personal data transfer to a place outside purposes is acceptable provided that it is Malaysia. undertaken by a health care professional or a person who under certain circumstances • Protection of Patient’s Data owes a duty of confidentiality which is The regulation of patient data protection equivalent to that which would arise if that in telemedicine is not regulated in the person was a health care professional. Malaysia Telemedicine Act. Thus, the implementation of patient data protection Notification to and consent from data refers to the general rules of personal data subject is also required for: collection protection, the Personal Data Protection Act and procession of any personal (including 2010, as follows: sensitive personal data), any disclosure (for

Regulation Explanation Protection of personal data Data controllers are prohibited: (Article 6 paragraph 1) • process personal data without consent from data owners, in the case of personal data is not sensitive; or • process personal data in case the data is sensitive, except: (i) the data owner has given consent to process the data; or (ii) data processing is required. The principle of security (Article 9) Data handler shall, when performing the processing of personal data, to take practical steps to protect personal data against any unintentional defects, misuse, modification, access or disclosure, disclosure or destruction. Right to correct data (Article 34) Patients may request correction of false / inaccurate / incomplete personal data. Right to accurate data (Article 22) Patient may request correction of wrong / inaccurate / incomplete personal data. Cancellation of data owner's consent to • The owner of the data with written notice processing of personal data (Article 38) may withdraw the consent that he has made to the personal processing. • Compulsory data handlers, upon receipt of the above mentioned notice to cease processing of personal data. • If the controllers of data violated this article by keeping data processing subject to a fine of not more than RM100,000 or imprisonment for a period not exceeding one year, or subject to fine and imprisonment.

65 The existence of a special council to The Minister appoint a person or an supervise the implementation of personal institution as a Personal Data Protection data protection (Article 47) Commissioner with the aim to supervise the implementation of the protection of personal data. Rights in the event of a violation (Article 104) Anyone who suffers a loss resulting from a violation of this rule conducted by a data controller has the right to file a legal action in the form of a written complaint addressed to the Personal Data Protection Commissioner.

Under the PDPA and the PDPA Standards • Remove the personal data which is no 2015, organizations (including companies longer in use from the organization’s and internet providers) collecting and using database; personal data must ensure the security • Prohibition of storing personal data and data integrity of any personal data in removable media devices without by implementing appropriate safeguards the written permission of senior to prevent the loss, misuse, modification, management. unauthorized access or disclosure or alteration or destruction of the personal data it 3. The key obligations under the data integrity possesses, making the organization’s obligation standards, among others: to establish internal standard operating • Ensuring that the personal data is procedures personal data management accurate, complete, not misleading and within the organization and comply with data up-to-date; protection principle in the PDPA. • Making available (online and physical) forms for data subjects to update PDPA Standards 2015 impose certain minimum personal data and data users, including standards to be adhered to by organizations (as updating personal data immediately after the ESP) to safeguard and ensure the security receiving a data correction notice. and data integrity of the personal data being stored on any platform (whether physically or • E-Medical Record electronically (e.g. on a cloud)). E-Medical Record (EMR) is classified as sensitive personal data since EMR is defined 1. The key obligations under the security as a computerized record that can be standards, among others: accessed with concerned of patient privacy, • Maintaining and limiting the right of confidential and security from multiple access to personal data; integrated system at any point of care • Setting limits upon the power of staff to within the health care organization. As EMR access personal data; keeps sensitive personal information of • Maintaining personal data records; the patient, data users are responsible and • Potential risk management of ensuring liable to ensure that the information are not that security procedures are in place and leaks to other unauthorized parties and in by controlling and recording incidences of compliance with PDPA and/or 2015 PDPA data transfers; Standards. • Physical security standard as such monitoring access to data repositories, PDPA and 2015 PDPA Standards requires putting in place closed-circuit cameras personal data to be: and storing hard copies of personal data 1. Processed and protected in any way in locked cupboards. (the Electronic medical record Support 2. The key obligations under the retention for Public health (ESP) to take practical standards, among others: steps) free from any loss, misuse, • Permanently disposed personal data modification, unauthorized or accidental once no longer required (including step access or disclosure, alteration or of disposing data collection forms within destruction; 14 days of collection, unless the forms 2. Based on consent from the personal are subject to other legal requirement); data subject.

66 PDPA applies to all personal data which is user is an offence. collected and used inside Malaysia, PDPA implying that personal data here in is • Medical Liability, Standards, and personal data which is placed in territory of Malpractice Claim Malaysia. Regarding personal data transfer The MMC regulates the professional to any place outside Malaysia shall be conduct of all doctors, irrespective of restrictedly done to place as specified by whether they are practicing in the public, the Minister of Science, Technology and private, or voluntary sectors. The MOH Innovation, upon the recommendation of enforces the laws regulating all private the Commissioner, by notification published health care facilities, which include the in the Gazette. The ESP as personal data voluntary sector. Although there is not any user shall take all reasonable precautions regulation related to the patients’ rights in and exercised all due diligence to ensure the public sector health care facilities, there that the personal data will not be processed are policies and procedures in place that in the recipient country in a way that would protect their rights. For private sector health be a contravention of the PDPA. care services and facilities, the relevant regulatory law is the Private Health Care • Credentialing and Privileging Facilities and Services Act 1998 (PHFCSA), In terms of credentialing and privileging, which provides for: (i) the provision of there is a requirement that telemedicine medical care by a registered doctor; (ii) a service providers should be able to practice grievance mechanism plan for patients in Malaysia, which is set forth in Article 3 of using the premises of the private health Malaysia Telemedicine Act, as follows: care facility or service; (iii) the manner 1. medical providers that may provide of assessing a patient’s medical records telemedicine services are: (i) registered and the manner of obtaining a patient’s medical practitioners and have practice medical report by the patient, the patient’s certificates; or a registered telemedicine representatives, or a health care provider; practitioner from outside Malaysia who (iv) the obtaining of a valid consent for a has a valid certificate of practice. surgical operation or procedure; (v) the fees 2. any person providing telemedicine that may be charged by private health care services in a manner contrary to this facilities and services; (vi) matters relating section, even if he practices outside to patients’ rights in relation to health Malaysia, shall be liable to a fine not care services provided by any healthcare exceeding RM500,000 or imprisonment facility or service, including patients’ privacy, for a period not exceeding five years. confidentiality of information, and access to patients’ medical reports and records; However, in relation to credentialing and and (vii) the minimum standards and privileging processes, the process is still requirements for all health care facilities. within the scope of general health care delivery by the Ministry of Health Malaysia, There are quality standards prescribed in hence there is no credentialing and the PHCFSR for various aspects of health privileging process undertaken specifically care. These quality standards support for telemedicine providers. patients’ rights, i.e. infection control; standards for obstetrical or gynaecological There is not any requirement to obtain care, newborn nursery facilities, paediatric operational business license as the ESP care, anaesthesia, surgical facilities and who provide electronic system for eHealth services, intensive care unit, emergency purpose. However, the ESP which is care services, pharmaceutical services, classified as data user for health care and/ dietary services, rehabilitation facilities or insurance purpose shall be registered and services, specialist outpatient facilities to the Commissioner of the Department and services, ambulatory care centres; of Personal Data Protection (the special requirements for central sterilising Commissioner). Failure to register of data and supply facilities and services, blood bank and blood transfusion services, haemodialysis facilities and services, radiological or diagnostic imaging services

67 and radiotherapy and radioisotope services; there are policies and procedures put in standards for private nursing homes and place by the MOH and the boards of the special provisions for and palliative University hospitals that protect patients’ care services. rights. Patients and their families can avail themselves of the grievance mechanisms Grievance mechanism in private health care that are in place in the public sector health facilities: care facilities. Complaints about a doctor • The licensee or person in charge of can be made to the MMC; complaints about a health care facility has to provide both private and public sector health care a patient grievance mechanism plan facilities can be sent to the Medical Practices which include the appointment of a Division of the MOH. Claim for medical patient relations officer (PRO) to serve negligence or malpractice on medical as a liaison between the patient and the treatment can also be made through facility; the extent of decision-making litigation process. Such claims are usually authority given to the PRO; a method handled by Medico Legal Branch which by which each patient will be informed will work along with the Attorney General’s of the PRO and how he or she may be Chamber and the Law Advisor Office of the contacted; and the documentation of all MOH. complaints. • Any grievance against the facility may A breach of the provisions of the PDPA be submitted by the patient orally or in (e.g. personal data leak or misuse) can writing to the PRO or to any healthcare result in a range of fines, imprisonment, or professional of the facility at any time. both. Especially for failure to comply with A complaint submitted to the latter has individual’s personal data protection in to be forwarded to the PRO by the next section 9 of PDPA is an offence punishable working day. by a fine of up to MR100,000 and/or • The PRO is required to document all imprisonment for up to two years. For the complaints received and resolve the ESP as data user non-compliance with any of matter. If the PRO cannot resolve the the security standards under the 2015 PDPA complaint, it has to be referred to the Standards may result in the ESP being held licensee or person in charge immediately liable to a fine not exceeding RM250,000 or or within three working days. imprisonment not exceeding two years, or • The licensee or person in charge has to both. institute an investigation and provide a reply, which includes the result of the • Prescribing investigation to the complainant within Nearly all prescriptions in the country are 10 working days after the complaint was written by hard, except for a selected few received by the licensee or person in hospitals that utilize the e-prescribing charge. system. This is because, as mentioned • The report of the investigation to the above, the eHealth project is ongoing and complainant has to state that if he electronic systems in most aspects are or she is dissatisfied with the reply of expected to be available nationwide in 5 the licensee or person in charge, the years. complainant could refer matter to the Relevant legislations (non-exhaustive): Director-General of Health. • Sale of Drugs Act 1952 • The Director-General will then institute • Control of Drugs and Cosmetics an investigation of the complaint and Regulations 1984 inform the complainant and the facility • Dangerous Drugs Act 1952 of his findings or any recommendations • Poisons Act 1952 based on the findings. • Medicines (Advertisement & Sale) Act 1956 For public sector health care facilities Any negligence or malpractice found on There is not any specific law regarding the the part of doctors in prescribing may be provision of health care or treatment in complained or reported to the MOH or public sector health care facilities. However, MCC who regulates the profession. Any negligence or malpractice found on the 68 part of pharmacists in prescribing may be system. In the private sector, private complained or reported to the Pharmacy health insurance is voluntary, with various Practice & Development Division or the premiums being charged on the basis of MOH. individual health status, type of health insurance, and coverage level. Meanwhile, Both digital signatures (stipulated under public health services are funded through the Digital Signature Act 1997 (DSA)) and general taxation, with an annual health electronic signatures (stipulated under the budget allocated by the Ministry of Finance Electronic Commerce Act 2006 (ECA)) are to the Ministry of Health, where the recognized in Malaysia. proportion of revenues allocated to the Ministry of Health in the National State 1. E-signature Budget (APBN) is decided every year. In Broadly defined as any letter, character, addition, there is a scheme in which the number, sound, or any other symbol workforce is formally employed for monthly or any combination thereof created contributions to the Employee Provident in an electronic form adopted by a Fund and the savings will be distributed as person as a signature. A signature of pension and medical expenses. For public a person will be deemed as electronic sector employees, they will get free access signature if: (a) attached to or logically to medical services provided by public associated with the document; (b) health providers. In relation to telemedicine, adequately identifies the signer and his until now, there is no scientific paper or approval of the information to which regulations regarding the reimbursement the signature relates; (c) is as reliable as system for telemedicine services. is appropriate given the purpose and circumstances for which the signature • Cross-Country Practice is required; (d) the means of creating Relevant legislations and regulations: the electronic signature is linked to - Medical Act 1971 and under the control of the signer - Medical (Amendment) Act 2012 only; (e) any change to the e-signature - Medical Regulations 1974 post signing is detectable; and (f) any - Medical (Setting of Examination for change to the document post signing is Provisional Registration) Regulations detectable. 2015

2. Digital Signature Pursuant to the Medical Act 1971, any Defined as a transformation of person (including non-Malaysian) who a message using an asymmetric wishes to practice medicine in Malaysia cryptosystem such that a person having needs to be registered with the MMC. The the initial message and the signer’s Council maintains a Medical Register for this public key can accurately determine purpose. (a) whether the transformation was Eligibility for registration and the process for created using the private key that gaining registration generally depends on: corresponds to the signer’s public key (i) The place where the applicant obtained and (b) whether the message had been his or her primary medical qualification; altered since the transformation was (ii) Nationality; and made. (iii) Professional background and experience The ECA does not preclude the use of digital signatures (as defined in Types of registration for foreign doctors the DSA) in electronic commercial who wish to practice medicine in Malaysia: transactions. As such, parties are free (i) Full registration (with conditions) (section to choose to use a digital signature 14(3)); (ii) Temporary registration (section as an electronic signature in any 16); and (iii) Specialist registration commercial transaction. Registration applications are to be • Payment approved or refused by two Evaluation Malaysia has a mixed health financing

69 Committees established by the MMC: (i) choose which one is the scientific knowledge, Evaluation Committee for Primary Medical and which one is not, and also the accuracy of Qualifications; or (ii) Evaluation Committee the information as well. for Specialist Medical Qualifications.

Non-Malaysian applicants may have to undertake and pass certain medical exams How Does the Patients and Doctors and shall provide proof of efficiency in Malay Like the eHealth Application? (Malaysian language) and English as part of the requirements. As any other Malaysian doctors, cross country medical staff will be A pair of surveys on the consumers of eHealth regulated by the Ministry of Health and the behavior towards the application have been MMC and bound by all relevant legislations conducted during May – July 2018. and regulations. The first survey which targeted to general public as participants reached 102 respondents. From The Health Education Impact of eHealth all the respondents, 32.4% (33 respondents) for the Public of them have already used digital healthcare application while the other 67.6% (69 Since ehealth known by the public as part of respondents) have not. From 33 respondents the health industry, there is a change in the who already used digital health care application, society related to health information. People the majority have use Alodokter (21 responses) used to depends on the doctor, media, or other and HaloDoc (12 responses). Meanwhile, formal channel of health information as the other applications like Go-Med (2 responses), main resource of information. But since the GueSehat, JKN Mobile, FatSecret, WebMD and eHealth era has arrived, health information is Mayo Clinic can be assumed is less preferred no longer known only in the consultancy room, (only one responses each). but become information, which is publicly available. In one side this unavoidable shift From the survey, practicality and convenience has changed the role and the work nature of were the major reason of using digital health medical practitioner, on the other side the care application. While low cost and variety of health knowledge sharing has opened the choices came at the second place. The other eyes of general public, as they become more reasons cover: higher reliability, obliged due aware on the importance of keeping good to certain circumstances and as a source health, and always seek knowledge updates. for getting second opinion. Based on the In this case their thirst of knowledge has been experience the respondents had, 84.4% were met with the service that is provided by health satisfied, while the other 15.6% of them were applications, which always provide updated dissatisfied with digital health care application health knowledge as part of their services. which they use. There were some concerns that the respondents have includes: data privacy, Several health applications for instance Gue miscommunication, diagnostic accuracy, Sehat, Alodokter, HaloDoc, Homedika provide unexperienced doctors, and legal protection. various format of health information, which However, issues regarding diagnostic accuracy are accessible not only for people who are was one which participants were most concern registered in the application, but for wider about. public as well. In this case the eHealth plays Build upon the respondents, inputs for digital important role to strengthen health education healthcare application platform varies range and promotion in the society. This is important from improvement of service quality, user to enhance health understanding, but the interface, speed, service varieties and reliability. people should also have the knowledge to The majority of the respondents (61.2%), have not use digital health care application due to the trust issue. Most of them believe that seeing medical doctors and do face-to-face consultation is much more reliable. Several other reasons for not using digital health care application include: the respondents did not know that health care applications were exist,

70 the feel of unnecessity, and issues regarding of this application are 100% satisfied with confidentiality. Meanwhile, several factors which the application which they use and have no can drive them to try to use the application concerns or issues regarding the digital health were certainty regarding accuracy assurance, care application. However, in their point of view, legal protection, data privacy, ease of use, and the incentive given should be adjusted. promotions. Improvement Area Improvement Area (Healthcare Workers) (General Public)

1% 22% Service Quality Bonus & Incentive 16% 34% 22% User Interface Legal Security

Speed User Education 18% 22% Service Varieties Promotion 22% 20% Trustability

23% List of Medicine Availability

Reasons for Not Using Reasons for Not Using Digital Health Applications Digital Health Applications (Healthcare Workers) (General Public)

Regulation & Legal Security 15% 16% Low Incentive 18% 22% No Need 8% Low Number of Users Trusting Face-To-Face 13% 18% 10% Lack of Opportunity Confidentiality Nesnience No Trust 47% 33%

Not Knowing How To Register

The second survey was responded by 27 While the others tend have not used the digital medical doctors, 2 pharmacists and 2 midwife. healthcare application platform mostly due to The majority of the respondents never the lack of opportunity. In addition, some other delivered service though digital application factors include: the uncertainty of regulation platform (26 respondents) while the other four and legal securities, the low-trust on digital delivers service through Alodokter (2 reponses), or online application, small market number, DokterChat, Telemed FKUB application with unattractive incentive, and lack of knowledge on the main motivation of expand his service how to apply or join. coverage via online application. The users This survey does not produce any further discussions nor include any assumptions since the survey only aim to understand the market expectations from real users’ point of view. Hopefully this survey can be used as a

71 Recommendations for Future eHealth Strategy

Indonesian eHealth Implementation Timeline Rules & Regulation

• Palapa Ring Project on progress • Broadband connectivity • Infrastructure development in connectivity: -- West project (100%) is established across -- Smart home care -- Middle project (75%) 7 main islands of -- Telemedicine -- East Project (40%) Indonesia (Jawa, Sumatera, Kalimantan, • In the interest of broadband Sulawesi, Maluku, Nusa connection availability across Tenggara, Papua) Indonesia (34 Provinces) • Palapa Ring Project • Targeted to finish by the end of supports in: 2018, available for 2019. -- Apps growth Infrastructure especially for • Universal Healthcare Coverage distant learning, is targeted to be fully telemedicine, implemented by 2019. e-government and other apps

• Cloud (data storage) • Cloud storage available • Cloud storage development and expansion Accessibility is on progress (KOMINFO) Data Storage

Smart hospital using Integrated • Blockchain • Artificial intelligence/ • Robotic health care Management Information System Implementation chat-bot diagnostic assistants • Medical cloud: Integration • Comprehensive device • Augmented reality across the health system historical medical • Home diagnostic glasses, that allows (supported by BPJS) record and current equipment for doctors to view the • Smarter access to health care health condition. teleconsultation patient’s computed facility, billing information and • Autonomous cars and support. tomography (CT) scan purchasing decisions drones for delivering and perform spinal

eHealth • Smart and integrated medicine. surgery by projecting the ‘wearables devices’ and • Insurance companies/ patient’s spine in 3D Actualization ‘smartphone use as a medical BPJS using IoT devices • Genomic database- device’ to monitor real-time based 3D printing to lifestyle and diets produce artificial organs for transplantation. • Mobile clinic program with • Big data analysis- • Personalized and Robo-lab: artificial telehealth car/bus based drug R&D, e.g. precise health intelligence guides the • Utilization of Google trends for in developing precision treatment based on lab of the future. Machine surveillance of epidemics and medicine. family’s & individuals’ learning automates diseases • Health map of infectious genetic the processes of • Digitalization in R&D/clinical disease for epidemic pharmaceutical discovery research protection: predicting and innovation. • Training and continuing medical patterns and putting up education safeguards before the eHealth • “Smart pill” or “smart sensors” diseases takes out.

Actualization containers • Replacement of debit or credit cards with a unique biological identifier (e.g. fingerprint).

72 Issuance of eHealth Roadmap Amendment of eHealth Amendment of eHealth Laws and Regulations covering, among others: Law and Regulations covering artificial intelligence / chat-bot diagnostic i. the definition of telehealth, covering the integrated device, biometric technology, personalized and telemedecine, tele-pharmacy, citizen registration precise health treatment, robo-lab, robotic healthcare tele-consultation, tele- number online system assistants, 3D technology. This laws and regulations rehabilitation, tele-laboratory, (e.g. for integration or will set out the scope of services and liability for the tele-radiology and eHealth; automatic linkage between stakeholders (“Development of eHealth Matters”). ii. protection of personal data; citizen ID with medical iii. mobile health (wearable records and insurance Issuance of Guidance on the Development of devices); allocation), technology eHealth Matters to support the above regulation. iv. informed consent via wearable on autonomous cars and devices; drones, specific standards Regulation and Policy v. business license, scope of of electronic system services and liability for the provided by electronic stakeholders; system provider, standard vi. e-prescribing; for electronic tools and vii. electronic system audit devices used for data operation; processing and connect viii. electronic certification; to telecommunication ix. credentialing and privileging; network. x. centralization of data; xi. sharing and standardization of Guidance on blockchain data center; and technology to support xii. system audit operation; ehealth system. xiii. medical procedure and claim of malpractice via electronic Regulation on Digital system, payment / billing Signage Placement in system; patient’s mobile, personal xiv. insurance system integration; computers, or digital xv. clinical decision support wearable devices. system; Issuance of Health map xvi. health knowledge of infectious disease for management by an authorized epidemic protection. body or organization (hereinafter referred as “eHealth Matters”).

Codified Law of eHealth Practice in Indonesia to provide the main legal referral and core principles of national eHealth by considering the prevailing conventional medical practice law and regulation as well as covers the eHealth Matters as mentioned above.

Amendment or Issuing New Regulations on specific matters, among others: (i) Conventional Medical Practice, (ii) Citizen Registration System, and (iii) Healthcare National Insurance (BPJS), in order to support the enforcability of codified law of eHealth Practice in Indonesia as well as Code of Conduct of Indonesian Medical

73 recommendation or to give a sight on what market really needs – which so that all stakeholders can work together and take part to create and improve the eHealth program.

1. Legal Provision in Indonesia, Malaysia, and Australia

eHealth Indonesia Malaysia Australia Application a. Definition The term “eHealth” in Malaysia uses telemedicine Health services using ICT Indonesia is known terminology for health services is known as digital health. mostly for the health using ICT. Telemedicine Act 1997 Digital health is defined as an digital application, which (“Malaysia Telemedicine Act”) electronic health information is famous because of the specifically defines telemedicine as management to provide health awareness lately. a medical practice that uses audio, health services which is safer, Indonesia does not have visual, and data communications. In more efficient, and more specific rules and regulation addition to Malaysia Telemedicine qualified. Digital health is regarding digital health Act, the definition of telemedicine by used for several health care care system yet, but the Malaysian Ministry of Health can also systems in Australia, namely only regulation related is be found in Malaysia’s Telemedicine My Health Record, Telehealth, the teleconsultation and Blueprint published on July 25, 1997, and Health care Identifiers teleradiology guidelines which says that telemedicine literally Service. (namely Hospital Pilot means “far-reaching medicine.” testing of Video-conference- based tele-medicine and teleradiology guideline or known as Rumah Sakit Uji Coba Program Pelayanan Telemedicine berbasis Video-conference dan Teleradiologi). b. Language Bahasa Indonesia is There are no specific language No statutory requirements, mandatory for: requirements for any electronic though contracts are i. all kind of contracts system targeting or electronic contract generally in English. (electronic or physical) involving the Malaysian market. involving Indonesian as a Practically, most websites targeting party (person or entity); the Malaysian market tend to be in ii. contents in the system dual languages, which are English and electronic deployed in Malaysian National language (Malay). Indonesia.

74 eHealth Indonesia Malaysia Australia Application c. Informed In Indonesia Doctors are In Malaysia informed consent can be In Australia informed consent Consent required to obtain informed said to have been given based upon a is required when using an consent prior to advising and clear appreciation and understanding application, i.e. My Health / or acting to the patients of the facts, implications, and Record. Before doctors and only allowed to give future consequences of an action. upload patient health or an service to the patient for In order to give informed consent, e-prescription into My Health the benefit of the patient. In the person concerned must have Record, they need approval addition, any use of patient adequate reasoning capacity and be from the patient. The approval personal data via electronic in possession of all relevant facts at would be sufficient with a system provided by the time consent is given. Failure to statement or verbal consent electronic system provider obtain a patient’s consent or disclose by telling directly to the (“ESP”) shall be based on material risks may be interpreted as a doctor or other health care consent from the patient failure of the standard of care which providers. (consent form provided by would be resulting in a disciplinary ESP) and shall be in line with inquiry by the MMC or may be Collection, use and disclosure the purpose made known construed as a breach of duty of care of health information are to the patient at the time and legal action constituted. authorized for the purposes the data is collected. This is of providing health care to required under Law No. 11 Malaysian Personal Data Protection the registered health care of 2008 regarding Electronic Act 2010 as at 15 June 2016 (PDPA): recipient and in accordance Information and Transaction with the access controls set as lastly amended by Law No. Any personal data consisting of by that recipient. 19 of 2016 (Law 11/2008) information as to the physical or and Government Regulation mental health or condition of a No. 82 of 2012 regarding data subject (sensitive personal Implementation of Electronic data) shall only be processed by System and Transaction (GR a data user upon explicit consent 82/2012). of the respective data subject. Sensitive data processing for medical For example, should any use purposes is acceptable provided of data require a transfer that it is undertaken by a health or storage of personal data care professional or a person who in outside the jurisdiction, it certain circumstances owes a duty of would be best to inform such confidentiality which is equivalent to conditions to the patient that which would arise if that person and obtain the consent was a health care professional. for transferring and/or storing such data in other Notification to and consent from data jurisdictions. subject is also required for: collection and procession of any personal (including sensitive personal data), any disclosure (for purpose for which the personal data was to be disclosed at the time of collection of the personal data or a purpose directly related to the purpose at the time of collection), personal data transfer to a place outside Malaysia.

75 eHealth Indonesia Malaysia Australia Application d. Electronic In Indonesia the ESP shall: In Malaysia the implementation In Australia a health care System i. provide standard of patient data protection refers provider organization may and Data procedure of protection to the general rules of personal apply to the System Operator Protection which guarantee security/ data protection, the Personal Data of My Health Record. In that confidentiality of patient’s Protection Act 2010 in which data regard, such organization data (in the form of controllers are prohibited: (i) process must (1) has been assigned electronic information/ personal data without consent from a health care identifier as documents); data owners, in the case of personal in Healthcare Identifiers Act ii. applying risk data is not sensitive; or process 2010, (2) comply with My management upon any personal data in case the data is Health Record Rules enacted damage or loss arising sensitive, except: (i) the data owner by Commonwealth Minister out of electronic system has given consent to process the data; for Health; (3) has agreed operation; or (ii) data processing is required. to be bound the conditions iii. provide and carry out imposed by the system procedure and facility to Under the PDPA and the PDPA operators on registration. protect electronic system Standards 2015, organizations The Health Record Rules from any interference (including companies and internet 2016 specifies, inter alia, and any material or providers) collecting and using such organization must take immaterial loss; personal data must ensure the reasonable steps to ensure iv. provide security standard security and data integrity of any that they and their employees covering procedure and personal data by implementing exercise due care and skill, so system to prevent and appropriate safeguards to prevent that any record is accurate, overcome any thread or the loss, misuse, modification, update, not misleading, not interference attempt. unauthorized access or disclosure defamatory; and fit with or alteration or destruction of the purpose. Other requirements Furthermore, in providing personal data it possesses, making for such organization includes its electronic system for the organization’s obligation to requirement to maintain tele-health care purpose establish internal standard operating interoperability, to provide in Indonesia, basically the procedures for personal data assistance at the System ESP is required to obtain management within the organization Operator request, and to corporate general license and comply with data protection only upload to a repository and if there is foreign capital principle in the PDPA. advanced care planning participation, investment information. license from Indonesian PDPA Standards 2015 impose certain Investment Coordination minimum standards to be adhered Further, persons may apply Board (BKPM) is also to by organizations (as the ESP) to for registration as a repository required (No requirement safeguard and ensure the security operator, a portal operator, or to obtain operation license and data integrity of the personal data a contracted service provider. from sectoral authority). being stored on any platform (whether For these kind of persons, Beside, registration as physically or electronically (e.g. on a they required to register with ESP is mandatory for ESP cloud)). and must be linked to one or which carries out services more registered health care for public: owns web i. The key obligations under the provider organization, to only portal or online application security standards, among others: access My Health Record to through internet in order • Maintaining and limiting the the extent that they have to offer its service, owns/ right of access to personal been instructed to do so by provides electronic system data; a linked such organization, to with payment or financial • Setting limits upon the power notify the System Operator transaction within, uses of staff to access personal of certain things, such as electronic system which data; inaccurate provenance process, manage, or store • Maintaining personal data information, error in a record, user’s data, etc. records; no longer linked with such organization, undergone material changes, etc.

76 eHealth Indonesia Malaysia Australia Application • Potential risk management All those participants in My of ensuring that security Health Record shall comply procedures are in place and with security requirements as by controlling and recording in The Health Record Rules incidences of data transfers; 2016. • Physical security standard as such monitoring access to data repositories, putting in place closed-circuit cameras and storing hard copies of personal data in locked cupboards.

ii. The key obligations under the re- tention standards, among others: • Permanently disposed personal data once no longer required (including step of disposing data collection forms within 14 days of collection, unless the forms are subject to other legal requirement); • Remove the personal data which is no longer in use from the organization’s database; • Prohibition of storing personal data in removable media devices without the written permission of senior management.

iii. The key obligations under the data integrity standards, among others: • Ensuring that the personal data is accurate, complete, not misleading and up-to-date; • Making available (online and physical) forms for data subjects to update personal data and data users updating personal data immediately af- ter receiving a data correction notice.

77 eHealth Indonesia Malaysia Australia Application e. Business In Indonesia the ESP is In Malaysia no requirement to obtain To operate business in License required to obtain business operational business license as the Australia, business entity general license and if there ESP who provide electronic system shall obtain recognition is foreign capital participa- for eHealth purpose. However, the and registration, either an tion, investment license from ESP which is classified as data user Australian Company or a BKPM. No requirement to for health care and/or insurance Foreign Company, before obtain operation license purpose shall be registered to the Australian Securities and from sectoral authority. Commissioner of the Department Investments Commission of Personal Data Protection (the c.q. Investors and Financial “Commissioner”). Failure to register of Consumers. This includes an data user is an offence. obligation to obtain National Business Name Registration according to Business Names Registration Regulation 2011 AG.

As the eHealth services dealing with personal data, business entity shall comply with Privacy Act 1988 AG and Privacy Regulations 2013 AG through, for example, adopting code of practice. If it is categorized as a medical device, the supplier shall follow Therapeutic Goods Act 1989 AG. Apart from those, a business entity requires IPRs licenses (e.g. copyright, trademark, patent, etc.).

78 eHealth Indonesia Malaysia Australia Application f. E-Medical In Indonesia as for any In Malysia E-Medical Record (“EMR”) is Record patient medical record which classified as sensitive personal data is in possession of the ESP, it since EMR is defined as a comput- shall be (i) kept confidential, erized record that can be accessed secure, complete, and with concerned of patient privacy, available for the patient to confidential and security from multiple amend, add, or update his/ integrated system at any point of care her record at any time by the within the health care organization. As ESP; (ii) based on consent; (iii) EMR keeps sensitive personal infor- encrypted/stored by the ESP mation of the patient, data users are for certain period subject to responsible and liable to ensure that health sector policy (at least the information are not leaks to other 5 years if there is no retain unauthorized parties and in compli- period policy in respective ance with PDPA and/or PDPA Stand- sector); and (iv) stored in ards 2015. data center required to be placed in Indonesia territory. PDPA and PDPA Standards 2015 requires personal data to be: i. processed and protected in any way (the ESP to take practical steps) free from any loss, misuse, modification, unauthorized or accidental access or disclosure, alteration or destruction (see point 1.c above); ii. based on consent from the personal data subject (see point 1.b above).

For personal data retention require- ments please see point 1.c above.

No express requirement to store personal data in Malaysia territory. However, since PDPA applies to personal data which is collected and used inside Malaysia, PDPA implying that personal data herein is personal data which is placed in territory of Malaysia. Regarding personal data transfer to any place outside Malaysia shall be restrictedly done to place as specified by the Minister of Science, Technology and Innovation, upon the recommendation of the Commissioner, by notification published in the Gazette. The ESP as personal data user shall take all reasonable precautions and exercised all due diligence to ensure that the personal data will not be processed in the recipient country in a way that would be a contravention of the PDPA.

79 eHealth Indonesia Malaysia Australia Application g. E-Prescribing In Indonesia no regulation In Malaysia nearly all prescriptions In Australia E-prescribing in telecommunication, in the country are written by hand, is guided by National digital, and technology except for a selected few hospitals Requirements for Electronic sector specifying the use of that utilize the E-prescribing system. Prescriptions v1.0 (DH- e-signature in e-prescribing. This is because, as mentioned above, 2625:2017). The end product However, Law No.11 of 2008 the eHealth project is ongoing and of e-prescribing provides on The Information and electronic systems in most aspects are specification and guidance Electronic Transaction as expected to be available nationwide in documents for software amended by Law No. 19 of 5 years. systems creating and 2016 on The Amendment of processing prescriptions Law No.11 of 2008 on The Both digital signatures (stipulated in electronic form. the Information and Electronic under the Digital Signature Act 1997 DH-2625:2017 require the Transaction widely covers (“DSA”)) and electronic signatures generation of e-prescribing e-signature function as: (stipulated under the Electronic must meet the following i. consent of the e-signer in Commerce Act 2006 (“ECA”)) are criteria, inter alia, (1) only an electronic information/ recognized in Malaysia. health care professionals contract (has the same with the legal right to legal enforcement/affect i. E-signature prescribe medicines can use as the conventional Broadly defined as any letter, the e-prescribing system to signature); character, number, sound, or any generate e-prescribing; (2) ii. a media to identify a legal other symbol or any combination the prescriber must be issued subject identity. thereof created in an electronic with a login and use that form adopted by a person as a login to perform all action To be effectively binding, signature. A signature of a person in e-prescribing system, (3) e-signature shall at least will be deemed as electronic information about access comply with the following signature if: (a) attached to or to, use of and time of uses requirements: logically associated with the is preserved for audit and i. confidential and only document; (b) adequately identifies enforcement purposes; (4) known by the owner of the signer and his approval of the issuers of that login shall e-signature; the information to which the take reasonable steps to ii. the authority to use is signature relates; (c) is as reliable protect that login and ensure only provided strictly for as is appropriate given the purpose it is not used by another the respective e-signature and circumstances for which the person; (5) on the display of owner; signature is required; (d) the means e-prescribing system must iii. the e-signature owner of creating the electronic signature show the particulars of the may at any time notice any is linked to and under the control prescription required by change to the e-signature of the signer only; (e) any change legislations, obtain a final after its execution; to the e-signature post signing approval from the prescriber, iv. the e-signature owner is detectable; and (f) any change include a unique identifier may at any time notice to the document post signing is of the prescriber; (6) the any change of electronic detectable. prescriber must re-present information regarding his/her login when approving the e-signature after its ii. Digital Signature a e-prescription for a drug execution; Defined as a transformation of of dependence or misuse; v. there are certain ways to a message using an asymmetric (7) any data of e-prescribing identify the e-signer; and cryptosystem such that a person system shall be stored in a vi. there are certain ways to having the initial message and the permanent and non-alterable. indicate that the e-signer signer’s public key can accurately has given its approval determine (a) whether the to the related electronic transformation was created using system. the private key that corresponds to the signer’s public key and (b) whether the message had been altered since the transformation was made.

80 eHealth Indonesia Malaysia Australia Application Besides, Decree of the The ECA does not preclude the use Executive Board of the of digital signatures (as defined in the Indonesian Doctors DSA) in electronic commercial trans- Association. 221 / PB actions. As such, parties are free to / A.4 / 04/2002 on the choose to use a digital signature as an Implementation of the electronic signature in any commercial Indonesian Medical Code of transaction. Ethics (The Medical Code of Ethics) only stipulates that In non-ICT infrastructure perspective, the physician shall deny Malaysia’s pharmaceutical and to provide any form when pharmaceutical regulations, which attributed or reasonably are the Poisons Act 1952 (Revised suspected to be associated 1989) and the 1951 Registration with his professional capacity of Pharmacist Act (Revised 1989) in prescribing the medicines, are basis for e-prescribing practice. including to influence the Hence, telemedicine must follow patient’s or his family’s wish the conventional provisions on to purchase or consume the prescribing, where drug delivery medicines as he has received should be carried out to the patient or is promised to receive directly and there should be systems commissions or profits of and mechanisms for detecting and pharmaceutical companies. verifying prescribing signatures Nonetheless, an application present in e-prescribing. provider determines that a health care provider does not guarantee that patients will be given prescription after the consultation using their application. In addition, application providers also confirmed that physicians serving at the application provider will not provide definitive therapy in the form of medicines or medical measures because there is no definitive diagnosis.

81 eHealth Indonesia Malaysia Australia Application h. Clinical No regulation in No specific regulatory measure (from In Australia, the supporting Decision telecommunication, digital, IT/Communication sector) found in system for clinical decision Support and technology sector Malaysia. include e-signature, eHealth System specifying clinical decision interoperability framework, support system in Indonesia. eHealth specifications and standards, secure messaging, and the National eHealth Security and Access Framework (NESAF). Each of those is governed by several recommendations documents. In e-signature, for example, a clinical document is assigned with three roles: author of the document, responsible person for the document contents/acts., and approver who signs approval of document’s release. The mechanism for eSignature is operated by (1) assigning an identifier to organization and individual who deliver a patient care: (2) employing private key for the both care provider; (3) allowing a digital seal using those private keys to verify the sealing party and authenticity of a document/ message. (eSignature Final Recommendation v1.0 dated 12 March 2012) i Health No regulation in No specific regulatory measure (from The principle coordinator Knowledge telecommunication, digital, IT/Communication sector) found. for health knowledge Management and technology sector management is held by the specifying health knowledge Australian Digital Health management. Agency (Agency). This agency already produced a clinical terminology list, Australian medicine terminology model, and pathology terminology and information model. For those, the agency provides online digital health training resources, digital health for pharmacists, and on demand training. j. Virtual Health No regulation in No specific regulatory measure (from No specific regulatory Care Teams telecommunication, digital, IT/Communication sector) found. measure (from IT/ and technology sector Communication sector) found specifying assignment of human resources or certain facility to deploy a virtual health care.

82 eHealth Indonesia Malaysia Australia Application k. Mobile Health No regulation in No specific regulatory measure (from No specific regulatory (wearable telecommunication, IT/Communication sector) found. measure (from IT/ devices) digital, and technology Communication sector) found, sector specifying wearable but the transmission of health devices specification and care information shall comply certification/standardization with the Secure Messaging for mobile health. v.1.0.3

However, eHealth wearable devices which are also functioned as telecommunication devices made, assembled, imported to be traded and/ or used in the territory of Indonesia are required to be complied with the technical requirements under the technology authority through certification process (test and/or document evaluation). This provision indirectly requires ESP to assure that the device vendor for its eHealth operation in Indonesia has obtained device certificates. l. Tele-pharmacy No regulation in No specific regulatory measure (from No specific regulatory telecommunication, digital, IT/Communication sector) found. measure (from IT/ and technology sector Communication sector) found. specifying the tele-pharmacy.

m. Tele- No regulation in No specific regulatory measure (from No specific regulatory consultation telecommunication, IT/Communication sector) found. measure (from IT/ digital, and technology Communication sector) found. sector specifying the tele- consultation.

n. Tele- No regulation in No specific regulatory measure (from No specific regulatory rehabilitation telecommunication, IT/Communication sector) found. measure (from IT/ digital, and technology Communication sector) found. sector specifying the tele- rehabilitation.

o. Tele- No regulation in No specific regulatory measure (from No specific regulatory laboratory telecommunication, IT/Communication sector) found. measure (from IT/ digital, and technology Communication sector) found. sector specifying the tele- laboratory.

p. Tele-radiology No regulation in No specific regulatory measure (from No specific regulatory telecommunication, digital, IT/Communication sector) found. measure (from IT/ and technology sector Communication sector) found. specifying the tele-radiology.

83 eHealth Indonesia Malaysia Australia Application q. Hospital No regulation in No specific regulatory measure (from No specific regulatory Information telecommunication, IT/Communication sector) found. measure (from IT/ System digital, and technology Communication sector) found. (Patient data sector specifying hospital management/ information system. administrative) r. Research/ Big The requirements imposed No specific regulatory measure (from Access to health information Data for using outsourced data IT/Communication sector) found. of patients/health care processing service providers recipients can be obtained (third party) for patient by health care providers/ profilling, marketing, etc: organizations who already i. the ESP shall keep the assigned health care patient data confidential, identifiers as regulated in secure, complete, and Healthcare Identifiers Act available for the patient to 2010. In assigning such amend, add, or update his/ identifiers, the health her record at any time; authority (Chief Executive ii. the data processing Medicare) may collect is based on consent information from various collected by the ESP; and sources for the purposes of iii. the ESP shall have proper assigning those identifiers. and speedy procedures to overcome any unexpected In research, the Agency has event to reduce the official roles to evidence- severity of any impact based policy research for resulting from any incident, establishing and evaluating fraud or system failure digital health. As for this, private or other researchers may request research partnership with the Agency on condition their research are relevant with the Agency’s priorities, which include public governance/ performance rule 2016, the national digital health strategy, benefits attributable to the My Health Record, the Agency corporate objective. Of which health strategy document, the Agency opens any innovation and scientific achievements in health care from entrepreneurs and researchers. For example, that national strategy elaborates an example that mobile apps employ data mining methods to help diagnose asthma or pneumonia.

The specific legislation on research or big data on health care or eHealth, however, do not regulatory embodied by laws, except for APP (Australia Privacy Principles) as in Privacy Act

84 eHealth Indonesia Malaysia Australia Application 1988. APP delineates several basic principles for processing data where such processing shall be (1) open and transparent ways: e.g. a clear expressed and up-to- date privacy policy; (2) giving option of not identifying individuals: anonymity and pseudonymity; (3) processing a strict necessary of data directly related to functions/ activities; (4) destroying unsolicited personal data or de-identified; (5) notifying data owners about their data processing at or before the time the processing; (6) not using or disclosing the collected personal data for another purposes peculiar from primary purpose; (7) not using personal data for direct marketing, unless data is directly collected from data owners, under the scope of reasonability expectation of individuals, and respond an objection by a data owner anytime; (8) not transfer personal data to the overseas recipients, unless permitted by laws/ courts, and a data owner grants explicit consent; (9) not using a government related identifiers of an individual; (10) collected personal data must be accurate, up to date, and complete; (11) data controllers must adopt security measures to protect the data; (12) granting access right for data owners, right to correction, as well.

s. Consumer No regulation in No specific regulatory measure (from No specific regulatory Health telecommunication, digital, IT/Communication sector) found. measure (from IT/ Informatics and technology sector Communication sector) found. specifying consumer health informatics.

85 eHealth Indonesia Malaysia Australia Application t. Medical The ESP may be held For private sector health care services All participant in the My Liability accountable or sued by and facilities, the relevant regulatory Health System (except for any person in the event of law is the Private Health Care Facilities the Operator of which), they any loss arising from the and Services Act 1998 (PHFCSA), shall maintain interoperability provided electronic system. which provides for: (i) the provision with that system, and if not However, the ESP may limit of medical care by a registered compliance, the Operator its liability towards any claim doctor; (ii) a grievance mechanism may suspend the participant’s filed if the ESP can prove plan for patients using the premises access. On condition that a its compliance under the of the private health care facility or software/app is categorized prevailing law. service; (iii) the manner of assessing as a “medical device”, such a patient’s medical records and software or app follows the manner of obtaining a patient’s offences and civil penalty medical report by the patient, the provisions relating to medical patient’s representatives, or a health devices as in Therapeutic care provider; (iv) the obtaining Goods Act 1989. Non- of a valid consent for a surgical medical software/devices, operation or procedure; (v) the fees however, do not follow such that may be charged by private provisions, but effectuate in health care facilities and services; (vi) a software license agreement matters relating to patients’ rights which partly is regulated by in relation to health care services Competition and Consumer provided by any health care facility Act 2010 where in default or service, including patients’ privacy, the creator of software is confidentiality of information, and responsible for services access to patients’ medical reports included in the software, and records; and (vii) the minimum subject to exceptions. standards and requirements for all health care facilities. In terms of malpractice, patients may make claims There are quality standards for medical negligence prescribed in the PHCFSR for various or medical malpractice aspects of health care. These quality committed through medicare standards support patients’ rights, under Australian medical i.e. infection control; standards for malpractice laws. Medical obstetrical or gynecological care, negligence or medical newborn nursery facilities, etc. malpractice claims are made against individual health For public sector health care facilities, care providers as well as there is no specific law regarding the publicly funded hospitals that provision of health care or treatment. employ professional medical However, there are policies and personnel. procedures put in place by the MOH and the boards of the university hospitals that protect patients’ rights. Patients and their families can avail themselves of the grievance mechanisms that are in place in the public sector health care facilities. Complaints about a doctor can be made to the MMC; complaints about both private and public sector health care facilities can be sent to the Medical Practices Division of the MOH. Claim for medical negligence or

86 eHealth Indonesia Malaysia Australia Application malpractice on medical treatment can also be made through litigation process. Such claims are usually handled by Medico Legal Branch which will work along with the Attorney General’s Chamber and the Law Advisor Office of the MOH.

A breach of the provisions of the PDPA (e.g. personal data leak or misuse) can result in a range of fines, imprisonment, or both. Especially for failure to comply with individual’s personal data protection in section 9 of PDPA is an offence punishable by a fine of up to MR100,000 and/or imprisonment for up to two years.

For the ESP as data user non- compliance with any of the security standards under the PDPA Standards 2015 may result in the ESP being held liable to a fine not exceeding RM250,000 or imprisonment not exceeding two years, or both. u. Payment/ No regulation in No specific regulatory measure (from eHealth strategy in Australia Billing telecommunication, digital, IT/Communication sector) found. does not include provision and technology sector on payment/billings as these specifying payment/ On the payment scheme, Malaysia issues might be addressed billing method for eHealth has a mixed health financing system. by other subject matter practice. However, please In the private sector, private health legislations. However, note that registration as insurance is voluntary, with varying financing of health services ESP is mandatory for ESP premiums being charged on the basis in the Australia is done by which carries out services of individual health status, type of Practice Intensive Program, for public: owns web health insurance, and coverage level. which includes eHealth portal or online application Meanwhile, public health services are Incentives. through internet in order funded through general taxation, with to offer its service, owns/ an annual health budget allocated by provides electronic system the Ministry of Finance to the Ministry with payment or financial of Health, where the proportion of transaction within, uses revenues allocated to the Ministry of electronic system which Health in the APBN is decided every process, manage, or store year. In addition, there is a scheme user’s data, etc. whereby the workforce is formally employed for monthly contributions to the Employee Provident Fund, which the savings will be distributed as pension and medical expenses. For public sector employees, they will get free access to medical services provided by public health providers. Associated with telemedicine, until now there has been no scientific paper or regulations regarding the reimbursement system for telemedicine services. Thus, we have not been informed whether patients who have social health insurance can reimburse the fees that already paid.

87 eHealth Indonesia Malaysia Australia Application v. Collaboration, No regulation in No specific regulatory measure (from The agency has role on Partnership, telecommunication, digital, IT/Communication sector) found. engagement, innovation, and Endorsement and technology sector clinical quality and safety of specifying collaboration, digital health for patients, partnership, and consumers, and the health endorsement. care providers. This agency has advisory committees, including Clinical and Technical Advisory Committee, Jurisdictional Advisory Committee, Consumer Advisory Committee, Privacy and Security Advisory Committee, Digital Health Safety and Quality Governance Committee, and Audit and Risk Committee. w. Cross Country No specific regulatory Pursuant to the Medical Act 1971, Australia does not explicitly Practice stipulates this matter. any person (including non- Malaysian) regulate the disclosure of who wishes to practice medicine in information or telemedicine Malaysia needs to be registered with practices across States in the MMC. The Council maintains a Australia. However, regulating Medical Register for this purpose. cross-border disclosure Eligibility for registration and the of personal information in process for gaining registration Chapter 8 Australian Privacy generally depends on: (i) the place Principle (“APP”) - Cross- where the applicant obtained his or border disclosure of personal her primary medical qualification; information (“APP 8”). (ii) nationality; and (iii) professional background and experience. APP 8 create a framework for the disclosure of personal Non-Malaysian applicants may have to information across the undertake and pass certain medical borders. This framework exams and shall provide proof of generally requires health care efficiency in Bahasa Malaysia and providers to ensure that the English as part of the requirements. recipients of information will Like all Malaysian doctors, cross use the health information country medical staff will be regulated in accordance with APP, by the Ministry of Health and the MMC and impose liability on the and bound by all relevant legislations provider if the recipient of and regulations. the information use the information inappropriately. x. Supervision Ministry of Communication The Ministry of Science, Technology Australian Digital Health and Provision and Informatics. and Innovation, Commissioner of Agency (established 20 Jan the Department of Personal Data 2016, operated in 1 July 2016). Protection. An initiative agency formerly is NEFTA (National eHealth Transition Authority Ltd) operated from 2005 to 2015

88 eHealth Indonesia Malaysia Australia Application y. Credentialing No specific regulatory In terms of credentialing and To obtain credentials, and Privileging stipulates this matter. privileging, there is a requirement practitioners or medical that telemedicine service providers personnel require to provide should be able to practice in Malaysia. and fulfill the requirement, However, in relation to credentialing among others: (i) details of and privileging processes, the process work experience (as medical is still within the scope of general personnel), attached with health care delivery by the Ministry its by evidence; (ii) details of Health Malaysia, hence there of educational and training is no credentialing and privileging data, along with relevant process undertaken specifically for diplomas and certificates; telemedicine providers. and (iii) details of involvement in the clinical audit process, peer review activities and continuing medical education programs.

As for the ESP which provides electronic system for e-Health purpose, has to refer to general business establishment in Australia: business entity shall obtain recognition and registration, either an Australian Company or a Foreign Company, before Australian Securities and Investments Commission c.q. Investors and Financial Consumers. This includes an obligation to obtain National Business Name Registration according to Business Names Registration Regulation 2011 AG. As the eHealth services dealing with personal data, business entity shall comply Privacy Act 1988 AG and Privacy Regulations 2013 AG through, for example, adopting code of practice. If it is categorized as a medical device, the supplier shall follow Therapeutic Goods Act 1989 AG. Apart from those, a business entity requires IPRs licenses (e.g. copyright, trademark, patent, etc.)

89 2. Legal Provision in Singapore, UK , and USA

Health Singapore UK USA Application a. Definition In Singapore, the terminology The terminology used for Beside eHealth, another used in health services health services using ICT common terms are telehealth using ICTs is telehealth and in the UK is digital health, and telemedicine. Telehealth is a telemedicine, as stated in the in which digital health has collection of tools or methods to Ministry of Health: Telemedicine several sub-segments, improve health care services, public Guidelines Summary Card namely (i) telehealth (a health, and health education using (“Singapore Telemedicine long-range health service telecommunication technology. Guidelines Summary Card”). using ICT between patient Telehealth covers a wide range and physician); (ii) telecare of technologies and systems to Telemedicine or telehealth (referring to the provision provide virtual medical, health, and refers to the systematic of health services using education services. Telemedicine is provision of health services clinical data exchange the use of electronic communication through a physically separate between patients and and information technology to environment between patients medical practitioners); and provide a clinical picture of the and healthcare providers, (iii) mHealth (referring to service when participants are in conducted through ICT. mobile applications related to different locations (remote /off-site/ health).121 online). Telemedicine is the use Furthermore, the exchange of electronic communication and of information for clinical information technology to provide a purposes between health care clinical picture of the service when providers and patients via participants are in different locations telephone, text messaging (SMS) (whether they are in remote areas, or other similar applications are of in an off-site location, or are (eg iMessage, WhatsApp) is online). Telemedicine has system that also included in the scope and can be used by health care providers definition of telemedicine. In to extend not only face-to-face addition to defining telehealth treatment practices. or telemedicine, the same source also provides definitions of (i) tele-collaboration; (ii) tele- treatment; (iii) tele-monitoring; and (iv) tele-support. b. Language There are no specific language As the common law system, There are no specific language requirements for any electronic the UK does not enact requirements for any electronic system that targets or electronic legislation on language, and system that targets or electronic contract that involves the even the English language contract that involves the States’ Singaporean market. However, does not have an “official” market. However, as English is the as English is the working status in law. Nonetheless, the working language in United States of language in Singapore, most de facto official language of America, most websites that target websites that target the the United Kingdom is English the States’ market tend to be in the Singapore market tend to be in which is used by 98% of the English language. the English language. population.

121 UK Department of Health, UK Trade & Investment, dan National Health Services, The UK: Your Partner for Healthcare Solutions, Digital Health, accessed from https://www.gov.uk/ government/uploads/system/uploads/attachment_data/file/402227/Healthcare_UK_Digital_Health_Jan_2015.pdf on 31 January 2018.

90 2. Legal Provision in Singapore, UK , and USA Health Singapore UK USA Application Health c. Informed The ESP as data user when UK has no specific rules There are vary requirements for Singapore UK USA Application Consent handling personal data in regarding informed consent the states in the U.S related to their possession, shall take in the domain of telemedicine. informed consent in telemedicine a. Definition In Singapore, the terminology The terminology used for Beside eHealth, another into account main concept of Thus, the implementation practices. Some countries require used in health services health services using ICT common terms are telehealth Personal Data Protection Act of informed consent in the patient informed consent before using ICTs is telehealth and in the UK is digital health, and telemedicine. Telehealth is a 2012 (PDPA), as follows: domain of telemedicine treatment/ telemedicine services telemedicine, as stated in the in which digital health has collection of tools or methods to refers to the provision of are undertaken. However, some Ministry of Health: Telemedicine several sub-segments, improve health care services, public i. Consent – the ESP may conventional medical services states do not require informed Guidelines Summary Card namely (i) telehealth (a health, and health education using collect, use, or disclose established by the National consent. Some states only require (“Singapore Telemedicine long-range health service telecommunication technology. personal data only with Health Service. In this regard, informed consent for certain forms Guidelines Summary Card”). using ICT between patient Telehealth covers a wide range the individual’s knowledge the existing law on consent of electronic communications (such and physician); (ii) telecare of technologies and systems to and consent (with some is Data Protection Act 1998 as e-mail or text messages). Although Telemedicine or telehealth (referring to the provision provide virtual medical, health, and exceptions, see point 2.q which is going to repealed by informed consent is not required by refers to the systematic of health services using education services. Telemedicine is below); new Data Protection bill (on some states in the U.S., it is still the provision of health services clinical data exchange the use of electronic communication going enactment, dated 14 best practice recommended to do. through a physically separate between patients and and information technology to ii. Purpose – the ESP may Sep 2017) along with GDPR Organizations such as the Federation environment between patients medical practitioners); and provide a clinical picture of the collect, use, or disclose (General Data Protection of State Medical Boards (“FSMB”) and healthcare providers, (iii) mHealth (referring to service when participants are in personal data in an Regulation) on 25 May 2018. and the American Telemedicine conducted through ICT. mobile applications related to different locations (remote /off-site/ appropriate manner for the In the existing law, there Association (“ATA”) recommend that health).121 online). Telemedicine is the use circumstances, and only are two basic conditions for doctors obtain informed consent to Furthermore, the exchange of electronic communication and if they have informed the consent where, for sensitive use telemedicine technology. of information for clinical information technology to provide a individual of purposes for the personal data (e.g. physical or There are three components to purposes between health care clinical picture of the service when collection, use, or disclosure; mental health or conditions), consider in creating informed providers and patients via participants are in different locations and the data owner shall have consent in the USA:122 telephone, text messaging (SMS) (whether they are in remote areas, given “explicit consent”, 1. The language used in introducing or other similar applications are of in an off-site location, or are iii. Reasonableness – the ESP while for any personal data and explaining the telehealth (eg iMessage, WhatsApp) is online). Telemedicine has system that may collect, use, or disclose only requires data owner’s process in a manner that it should also included in the scope and can be used by health care providers personal data only for consent. No legal definition, be easily understood by the definition of telemedicine. In to extend not only face-to-face purposes that would be however, between consent patient; addition to defining telehealth treatment practices. considered appropriate to and explicit consent in the 2. Describe the risks and benefits or telemedicine, the same a reasonable person in the existing law. Notwithstanding, expected from telehealth services; source also provides definitions given circumstances. GDPR and the Bill set out an and of (i) tele-collaboration; (ii) tele- informed consent shall be in a 3. Other information is required for treatment; (iii) tele-monitoring; Under the Spam Control Act, written declaration (e.g. not a the patient to have a complete and (iv) tele-support. any electronic message is pre-ticking box) giving before understanding of the telehealth b. Language There are no specific language As the common law system, There are no specific language unsolicited if the recipient (the processing taking place, and process (ie: available alternatives, requirements for any electronic the UK does not enact requirements for any electronic patient or eHealth system user) shall be clearly presented referral information, etc.). system that targets or electronic legislation on language, and system that targets or electronic did not request to receive or in an intelligible and easily contract that involves the even the English language contract that involves the States’ consent to the receipt the accessible form, using clear Patient consent usually captured on Singaporean market. However, does not have an “official” market. However, as English is the electronic message. and plain language. As for a paper consent. Electronic consent as English is the working status in law. Nonetheless, the working language in United States of ‘explicit consent’, GDPR does management enables this process to language in Singapore, most de facto official language of America, most websites that target Furthermore, the regulation not elaborate in detail, but occur in a fully electronic manner websites that target the the United Kingdom is English the States’ market tend to be in the of informed consent on the Working Party 29 of the Singapore market tend to be in which is used by 98% of the English language. telemedicine can also be found EU (European Commission) the English language. population. in the Singapore National emphasizes the term ‘explicit’ Telemedicine Guidelines refers to the way consent compiled by the Academy is expressed by the data of Medicine Singapore, the subject where, in practice, a Ministry of Health (“Singapore clear trail and explicit consent Telemedicine Guidelines”). can be proven where the available options and the consequences have been made clear. For example, by two stages verification for a written consent.

122 Teresa Iafolla, “Telemedicine & Informed Patient Consent: Done the Right Way”, http://blog.evisit.com/telemedicine-informed-patient-consent-done-right-way, accessed on 13 October 2017

91 Health Singapore UK USA Application At point 1.6 of the Singapore (an electronic consent directive) Telemedicine Guidelines, it and various laws, regulations, and is stipulated that the patient policies for access and restrictions shall be granted the freedom on sharing information particularly of making informed decisions. sensitive information are handled in Thus, it is important for the an automated way health information patient, as in a conventional technology (IT) system. Generally, face-to-face consultation, to be there are three phases in informed informed of any details deemed consent management: (https:// important by the patient, and www.healthit.gov/sites/default/files/ informed consent must be privacy-security/ecm_finalreport_ provided in accordance with forrelease62415.pdf) applicable legislation. • Phase I – Consent is captured on paper forms and scanned into HER systems. These forms do not contain structured data. Provider staff must read and analyze the consent form before information is shared. • Phase II – Consent may be collected on paper and then entered into an electronic format, on consent may be recorded digitally from the start using web portal or devices. • Phase III – Consent is collected electronically and structured data is captured.

Title 45 of Code of Federal Regulations (CFR or“45 CFR”) basically stipulates that a patient’s written consent need only be obtained by a provider once. The consent document may be brief and written in general terms. At a minimum, it must inform the patient that information may be used and disclosed for treatment, payment, health care operations (“TPO”), state the patient rights to review the privacy notice, to request restrictions and to revoke consent, and be dated and signed by the individual or his/her representative.

However please note that the patient may revoke in writing, except to the extent that the covered entity has taken action in reliance on the consent, and the patient may request restriction on uses or disclosures of health information for TPO.

92 Health Singapore UK USA Application d. Electronic Electronic Transactions Act Regulatory landscape for Health care providers are required System 2010 (“ETA”) generally provides e-System is GDPR and to comply with the provisions of Protection and obligation of security procedure NHS Confidentiality Code the security implementation stand- Protection of for the purpose of verifying of Practice 2003. GDPR ards specified in Sections 164.308, Patient’s Data that an electronic record is requires the controller 164.310, 164.312, and 164.316 of 45, that of a specific person or (or e-system operator) Code of Federal Regulations (“CFR”) detecting error or alteration in adopt data protection and consisting of: administrative security, the communication, content, security policies, technical physical security, technical security, or storage of an electronic certifications (subject to organization security and required record since a specific point conditions), data encryption, policies and procedures and doc- in time, which may require the and record keeping practice. uments. In addition, the Health ESP to use algorithms or codes, Other responsibilities include Information Technology and Clinical identifying words or numbers, (i) ensuring the ongoing Health (HITECHT) Act also provide a encryption, answerback or confidentiality, integrity, procedure for health care providers acknowledgement procedures, availability and resilience that violates the health data/infor- or similar security devices. of processing systems mation security provisions security, and services, (ii) the ability physical ecurity, technical security, According to PDPA, all contracts to restore the availability and organization security. and transactions documents and access to personal generally (also including online data in a timely manner Title 21 of Code of Federal contracts) containing personal in the event of a physical Regulations (CFR) which is reserved data shall be removed by the or technical incident; (iii) for rules of the Food and Drug ESP (the ESP to cease retaining), process for regularly testing, Administration/FDA (“21 CFR”) as soon as the purpose for assessing and evaluating the requires the electronic system that which that personal data was effectiveness of technical and support the electronic information collected is no longer being organizational measures for for FDA- regulated clinical served by retention of the ensuring the security of the investigation to be secure with personal data, and/or retention processing. As for NHS Code restricted access and should include is no longer necessary for legal of Practice, this only applies methods to ensure confidentiality or business purposes. The data where the data is directly regarding the subject identity, subject may ask the ESP to stop about patient to clinician. study participation, and personal collecting, using, or disclosing Such data follows a duty information after informed consent their personal data, however by of confidentiality in health has been obtained. considering the above provision, care system that requires to the ESP is not required to delete protect patient’s information, General requirements such as, or destroy the data subject’s inform the patient how their encryption obligation upon the personal data and may retain it data is used, provide choice subject’s information within an for as long as there are business for the patient in disclosure electronic system, unless the entity or legal needs. of data, and improve documents why encryption is not better ways to safeguards reasonable and appropriate in From health care perspective, confidentiality for patient their specific circumstances and the arrangements on patient (e.g. not tell unauthorized implements a reasonable data protection are included personnel how the security in the Singapore Telemedicine system operates, not breach Guidelines. At point 1.5 of the security themselves, not share guidelines, it is stipulated that login, use a strong password, the confidentiality of patient tracked access of data). information or data is one of the main issues in telemedicine practices. Accordingly, telemedicine providers shall ensure that patient information and data are protected through a patient’s data confidentiality policy.

93 Health Singapore UK USA Application Health providers are also and appropriate equivalent measure, required to comply with is applied to the entity holding the applicable regulations to ensure subject’s personal information under that patient health information the Health Insurance Portability and is protected. Accountability Act of 1996 (“HIPAA”) (Public Law No. 104-191) or as for In addition, other data retention a business associate of a HIPAA- requirements also exist for tax covered entity, the HIPAA Privacy, and other financial purposes. Security, and Breach Notification Rules is applied (45 CFR regarding Standards for Privacy of Individually Identifiable Health Information, Final Rule). This rule requires the relevant entity to take reasonable steps to limit the use or disclosure of and request for Protected Health Information (“PHI”) to the minimum necessary to accomplish the intended purpose. The relevant entity’s policies and procedures must clearly identify the persons or positions within the organization who need access to the information to carry out their job duties, the types of PHI needed, and the conditions appropriate to such access. (technicalhelp4u.com/The%20 Privacy%20Act.pdf)

e. Business No specific regulatory measure Register eHealth business as No specific regulatory measure (from License (from IT/Communication sector) a sole trader, limited company IT/Communication sector) found. found. or partnership to Companies House of Department for Business, Energy and Industrial Strategy with tax payments (see Companies Act 2006; registration by online or post). Apply for license notification to process personal data on the Information Commissioner’s Office (ICO). Adopting Confidentiality: NHS Code of Practice. Request guidance and advice to the National Institute for Health and Care Excellence (NICE) which is the body that provides national guidance and advice to improve health and social care < https://www.nice.org. uk/>.

94 Health Singapore UK USA Application f. E-Medical The PDPA does not expressly The safeguards for e-Medical The HITECH Act stipulates the use of Record restrict the storage of data Records follows the technology in eHealth applications, on the cloud. However, when organizational and technical particularly in terms of electronic personal data is stored by any measures in the GDPR and health records (EHR). Before it is means, the ESP has certain NHS Confidentiality Code of released and can be used by the obligations that are outlined in Practice 2003 as has been public, the National Coordinator will the PDPA, such as ensuring the stipulated. Specifically, the ensure the feasibility and quality accuracy and protection of the UK’s eMedical Record is SCR of EHR technology and establish personal data (see point 2.b and (Summary Care Records) certification of the technology. For 2.c above). used by authorized staff in health care providers who is willing other areas of the health to adopt such technology, they and care system involved in will be charged by the National the patient’s direct care. At Coordinator in which the amount of a minimum, the SCR holds the fee is adjusted to the condition important information about; of the health care provider. Funds current medication, allergies generated from these technology and details of any previous adoption payments will then be bad reactions to medicines, allocated to smaller, low-income, and the name, address, date of service providers in rural areas that birth and NHS number of the are medically inaccessible. patient. SCR’ users must have a smart card with the correct Federal law has been a driving force codes set to access the in Health Information Technology/ system. Patient’s participation HIT’s implementation and use by to SCRs is voluntary, and (among others) requiring federal patients can opt-out or agencies to use HIT and provide withhold from SCRs (if they do for its voluntary use by private not want SCRs). providers, applying privacy and security requirements and penalties to HIT and required audits and enforcement, securing incentive payments through the Centers for Medicare and Medicaid Services (CMS) for professionals and hospitals that are deemed eligible based on their “meaningful use” of certified electronic health record (EHR) technologies. (https://www.cdc.gov/phlp/docs/ datasharing-laws.pdf)

95 Health Singapore UK USA Application g. E- ETA provides the electronic Until now the regulation Each state has different provisions Prescribing methods (such as e-signature) and implementation of related to online prescribing or that can be used by people e-prescribing is still very e-prescribing, whereas the majority to indicate their intention limited. NHS Connecting for of states claimed that a physical with regards to electronic Health defines e-prescribing examination is required prior to documents, which in this case as “the use of electronic prescribing. However, not all states health care provider’s signature systems to facilitate and require direct physical examination. for e-prescribing purpose. improve communications The states that adopt the rules which A signature is defined as a related to prescription or drug require direct physical examination method (electronic or otherwise) ordering, multiply options, are New Jersey, Indiana, Tennessee, used to identify a person and and simplify administrative Colorado, and Idaho. There are to indicate the intention of processes” also some states that prohibit that person in respect of the online prescribing or e-prescribing information contained in a GDPR and the UK Data for certain dangerous categories record. Although e-signature Protection Act does not of medicines, such as California have become increasingly deal with e-prescribing, but and Arizona. However, there are prevalent in Singapore as more the basic requirement for differences between those two business move online due to intermediary eHealth provider states. California prohibits the convenience, certain contract (e.g. apps) shall indeed provision of online dangerous must be signed by hand and follows the GDPR, NHS code medicines without direct examination cannot be signed electronically, of practice, Data Protection of patients and doctors, while Arizona these include, execution of a Act and Human Right Act. determines that the prescription will, and any contract for the The UK only regulates of such a dangerous medicine sale of transfer of immovable e-prescribing for general can be performed without direct property or any interest in such practitioners and other physical examination between property. health care professionals, medical personnel and patients. namely EPS (Electronic Examination may be performed using Prescription Service). EPS telemedicine services and shall be allows prescribers to send supported by an EMR that meets prescriptions electronically the certification requirements as to a dispenser (such as a required by the Arizona Government. pharmacy) of the patient’s choice. Prescriptions must Requirement of prescription or be generated and signed e-prescription by a pharmacist/ electronically by a prescriber practitioner is basically regulated before being sent to a under the 21 CFR. patient’s nominated pharmacy using their smart card. Apart A pharmacist may dispense directly from EPS, paper copies of a controlled substance (listed in electronic prescriptions Schedule II of 21 CFR) that is a (called tokens) shall be sent to prescription drug only pursuant to the NHS Prescription Service a written prescription signed by the at the end of every month. practitioner,

96 Health Singapore UK USA Application except in case of emergency. In the case of an emergency situation (as defined in 290.10 of 21 CFR), a pharmacist may dispense a controlled substance upon receiving oral authorization of a prescribing individual practitioner, provided that:

(1) The quantity prescribed and dispensed is limited to the amount adequate to treat the patient during the emergency period (dispensing beyond the emergency period must be pursuant to a paper or electronic prescription signed by the prescribing individual practitioner);

(2) The prescription shall be immediately reduced to writing by the pharmacist and shall contain all information required, except for the signature of the prescribing individual practitioner;

(3) If the prescribing individual practitioner is not known to the pharmacist, he must make a reasonable effort to determine that the oral authorization came from a registered individual practitioner, which may include a callback to the prescribing individual practitioner using his phone number as listed in the telephone directory and/or other good faith efforts to insure his identity; and

(4) Within 7 days after authorizing an emergency oral prescription, the prescribing individual practitioner shall cause a written prescription for the emergency quantity prescribed to be delivered

97 Health Singapore UK USA Application to the dispensing pharmacist. In addition to conforming to the requirements of 1306.05, the prescription shall have written on its face “Authorization for Emergency Dispensing,” and the date of the oral order. The paper prescription may be delivered to the pharmacist in person or by mail, but if delivered by mail it must be postmarked within the 7-day period. Upon receipt, the dispensing pharmacist must attach this paper prescription to the oral emergency prescription that had earlier been reduced to writing. For electronic prescriptions, the pharmacist must annotate the record of the electronic prescription with the original authorization and date of the oral order. The pharmacist must notify the nearest office of the Administration if the prescribing individual practitioner fails to deliver a written prescription to him; failure of the pharmacist to do so shall void the authority conferred by this paragraph to dispense without a written prescription of a prescribing individual practitioner.

(5) Central fill pharmacies shall not be authorized under this paragraph to prepare prescriptions for a controlled substance upon receiving an oral authorization from a retail pharmacist or an individual practitioner. h. Clinical No specific regulatory measure No specific regulatory No specific regulatory measure (from Decision (from IT/ Communication sector) measure (from IT/ IT/Communication sector) found. Support found. Communication sector) found. However, NHS Digital, a national information and technology partner of the UK Department of Health & Social Care, deliver technology-lead systems and services, inter alia, NHSmail, SCR, EPS, NHS e-Referral Service, Adult Social Care Outcomes Framework (ASCOF), The Calculating Quality Reporting Service (CQRS), The Child Protection - Information Sharing project (CP-IS), Common User Interface (CUI), Data Access Request Service (DARS), The Directory of Services (DoS), iView and iViewPlus, M-Connect 2, etc. i. Health No specific regulatory measure No specific regulatory No specific regulatory measure (from Knowledge (from IT/Communication sector) measure (from IT/ IT/Communication sector) found. Management found. Communication sector) found.

98 Health Singapore UK USA Application j. Virtual Health- No specific regulatory measure No specific regulatory No specific regulatory measure (from care teams (from IT/Communication sector) measure (from IT/ IT/Communication sector) found. found. Communication sector) found. k. Mobile Health The Health Sciences Authority No specific regulations on The Food, Drug, Cosmetic Act (wearable (“HSA”) guidelines on telehealth mHealth, but, in April 2017, (“FD&C Act”) provides basic devices) devices as of September 2016 the NHS Digital launched a regulatory framework. In FD&C Act, defines Telehealth Devices as NHS Apps Library webpage manufacturers’ intended use of all forms of devices, including that declares a small selection their product is a major factor of the hardware devices, software of digital health and care tools definition of a medical device. If a and mobile applications, used (or trusted patient-facing manufacturer claims that its product in the delivery of Telehealth apps) to ensure they meet is intended for use in the diagnosis services. Under this guideline, the high standard of quality, treatment or prevention of disease, HSA propose only telehealth safety and effectiveness or is intended to affect human body, devices which are classified people expect from the NHS the product is subject to regulations as medical devices to be . For mHealth developers regulatory controls, including who want to be listed in The FD&C Act classifies medical product registration. Telehealth NHS Apps Library, they must devices into three categories based devices which are classified as pass the Digital Assessment on the risks to human body: medical devices above are, for Questionnaire (DAQs). DAQs • Class I: Exempt from premarket example, application used for assess several principal procedures measurement of heart rate and aspects such as digital tool • Class II: Required to go through ECG – single measurements, information, indicators of 510(k) notification. Marketable software for prediction of low effectiveness, regulatory only after FDA clears the blood glucose level episodes in approval, clinical safety, notification. patients based on past glucose privacy & confidentiality, • Class III: Clinical trial and approval measurements and diet, security, usability & by FDA required application used for continuous accessibility, interoperability, measurement and monitoring technical stability, and change The FDA has published non-binding, of ECG and irregular heart rate management. For example, but influential guidance applicable to management in cardiac patients, an mHealth app shall have a wearable devices. The guidance list or application for measurement clarity of purpose & intended two categories of general wellness of blood glucose in whole use, a certification (OWASP products: blood and recommendation of Mobile AppSec Verification), medication dosage. encryption, approval from Care Quality Commission, Safety Standards (SCCI0129), etc. Digital tools, then, are labelled “NHS Approved” or “Being Tested in the NHS”.

99 Health Singapore UK USA Application Guidance on Medical Device However, medical devices/ 1) products of Product Registration: products are regulated and which the intended use relates to i. Immediate Route. Criteria: 2 controlled by Medicines maintaining or encouraging a general reference agency approvals, & Health care products state of health or a healthy activity 3 years marketing history Regulatory Agency. This without any reference to diseases or with no major safety issues. agency assesses health care conditions; and 2) products of which Standalone mobile application products in collaboration with the intended use relates the role of (new) 1 reference agency several certification bodies, healthy lifestyle with reference to approval and no major safety interalia, Amtac Certification diseases or conditions. issues globally Services Ltd (0473), BSI ii. Expedited Route. Criteria: 2 Healthcare (0086), Lloyd’s Given the rapid expansion and broad reference agency approvals or Register Quality Assurance applicability of mobile applications, 1 reference agency approval + Ltd (0088), etc. This agency the FDA issued “Mobile Medical 3 years marketing history with is importation from Directive Applications: Guidance for Industry no major safety issues globally 93/42/EEC of 14 June and Food and Drug Administration iii. Abridged Route. Criteria: 1 1993 concerning medical Staff” in 2015. In the Guidance, the reference agency approval devices (as amended), FDA makes it clear that it does not iv. Full evaluation. No reference Commission communication intend to regulate mobile apps that agency approval. in the framework of the may meet the definition of medical implementation of the devices, but pose a lower risk to the Council Directive 93/42/ public. EEC concerning medical devices, and the directive importation legislations in the UK, particularly, The Medical Devices Regulations 2002. l. Tele-pharmacy No specific regulatory measure No specific regulatory No specific regulatory measure (from (from IT/Communication sector) measure (from IT/ IT/Communication sector) found. found. Communication sector) found, but NHS Digital may require mHealth app developers to comply with NHS Code of Practice and DAQs m. Tele- No specific regulatory measure No specific regulatory No specific regulatory measure (from consultation (from IT/Communication sector) measure (from IT/ IT/Communication sector) found. found. Communication sector) found, but NHS Digital may require mHealth app developers to comply with NHS Code of Practice and DAQs n. Tele- No specific regulatory measure No specific regulatory No specific regulatory measure (from rehabilitation (from IT/Communication sector) measure (from IT/ IT/Communication sector) found. found. Communication sector) found, but NHS Digital may require mHealth app developers to comply with NHS Code of Practice and DAQs o. Tele- No specific regulatory measure No specific regulatory No specific regulatory measure (from laboratory (from IT/Communication sector) measure (from IT/ IT/Communication sector) found. found. Communication sector) found, but NHS Digital may require mHealth app developers to comply with NHS Code of Practice and DAQs

100 Health Singapore UK USA Application p. Tele-radiology No specific regulatory measure No specific regulatory No specific regulatory measure (from (from IT/Communication sector) measure (from IT/ IT/Communication sector) found. found. Communication sector) found, but NHS Digital may require mHealth app developers to comply with NHS Code of Practice and DAQs

q. Hospital No specific regulatory measure No regulation in No specific regulatory measure (from Information (from IT/Communication sector) telecommunication, digital, IT/Communication sector) found. System found. and technology sector (Patient data specifying on this issue, but a management/ relevant system initiative by administrative) NHS Digital is HES (Hospital Episode Statistics). HES is a data warehouse containing details of all admissions, outpatient appointments and A and E attendances at NHS hospitals in England. This system gives benefits to monitor trends and patterns in NHS hospital activity, assess effective delivery of care, support local service planning, and so forth. Any disclosure or data mining to this database shall be kept anonymous with a strict statistical disclosure control to ensure that patient confidentiality is maintained.

101 Health Singapore UK USA Application r. Research/big Any activities of using personal Partly provided by HES The 45 CFR establishes the data data for example for marketing publications (monthly conditions under which PHI may purpose is allowed, provided and annually). Health be used or disclosed by covered that it complies with PDPA and care research functions is entities for research purposes. A ETA requirements (see point 2.c facilitated by NHS Digital covered entity may always use or and 2.d above). through RAG (Research disclose for research purposes Advisory Group). RAG brings health information which has Use of personal data without the research community been de-identified. The 45 CFR initial consent is allowed among together to advance the use also defines the means by which others if: and effectiveness of NHS individuals/human research subjects i. The use is necessary for any Digital’s data and services. are informed of how medical purpose which is clearly in Group membership consists information about themselves will the interest of the individual, of senior representatives be used or disclosed and their rights if consent for its use cannot from across research, the with regard to gaining access to be obtained in a timely way third sector and NHS Digital. information about themselves, when or the individual would not RAG has a sub-group, namely such information is held by covered reasonably be expected to Future NHS Digital services entities. withhold consent; for research - Innovation ii. The use is necessary to sub-group. RAG members are, Under the 45 CFR, the relevant respond to an emergency interalia, Medical Research entities are permitted to use and that threatens the life, health, Council (MRC), Department disclose PHI for research with or safety of the individual or of Health and Social Care individual authorization, or without another individual; (DHSC), Economics and Social individual authorization under limited iii. The use is necessary in the Research Council (ESRC), circumstances set forth in the 45 national interest, or for any Representative of academia CFR. To use or disclose PHI without investigation or proceedings; (England), Charity sector, The authorization by the research iv. Etc Association of the British participant, a covered entity must Pharmaceutical Industry, obtain one of the following: Disclosure of personal data etc. In August 2017, NHS without initial consent is allowed Digital supports Life Science among others if: Industrial Strategy written by i. The disclosure is necessary scholars and professionals for any purpose which is where areas for innovation clearly in the interest of the include: remote data access individual, if consent for its environment (e.g. Sandbox disclosure cannot be obtained concept), data donation in timely way;

102 Health Singapore UK USA Application ii. The disclosure is necessary bank, support modernizing & • Documentation that an alteration to respond to an emergency improving clinical trials, data or waiver of research participants’ that threatens the life, health linkage, and secondments & authorization for use/disclosure or safety of the individual or placements. of information about them for another individual; research purposes has been iii. The disclosure is necessary Moreover, the developers of approved by an Institutional Review in the national interest, mHealth app are obligated Board (IRB) or a Privacy Board or for any investigation or to involve and follow the • Representations from the proceedings; Health Developer Network researcher, either in writing or iv. The personal data is publicly Information, a website to help orally, that the use of disclosure available; developers create software of the PHI is solely to prepare a v. The personal data is disclosed for health and social care, research protocol or for similar to any officer of a prescribed including its forums and purposes preparatory to research, law enforcement agency, sites to get involved in the that the researcher will not remove upon production of written community thereof and representation that PHI for head or director of that law which access is sought is necessary enforcement agency or a for the research purpose. person of a similar rank, • Representations from the certifying that the personal researcher, either in writing or data is necessary for the orally, that the use or disclosure purpose of the functions or being sought is solely for research duties of the officer., on the PHI of decedents, that the vi. Etc. PHI being sought is necessary for the research, and, at the request of the covered entity, documentation of the death of the individuals about whom information is being sought.

The 45 CFR also permits covered entities to use and disclose PHI for research purposes when a research participant authorizes the use or disclosure of information about him or herself. s. Consumer No specific regulatory measure No specific regulatory No specific regulatory measure (from Health (from IT/Communication sector) measure (from IT/ IT/Communication sector) found. Informatics found. Communication sector) found, but CR also provide information for patients. Patients can ask to view or add information to their SCR by visiting their GP (General Practitioners) practice. Medical staff will ask patient’s permission to look at his/her SCR (except in an emergency where a patient is unconscious, for example) and only staff with the right levels of security clearance can access the system. A patient can ask an organization to show a record of who has looked at patient’s SCR - called a Subject Access Request.

103 Health Singapore UK USA Application t. Medical The ESP as data user non- With regard to the Digital Through the HITECH Act, the Liability, compliance with certain Apps Library, the named planning, implementation, and Standards, requirements (e.g. personal data supplier listed is the entity oversight of the implementation and requirements under the PDPA), solely responsible for the of the eHealth program has been Malpractice a regulatory authority can tool/app. NHS Digital or stipulated which includes clear Claim require the ESP to comply with the approving body is not provisions for the use of technology the applicable provisions and responsible or liable for in eHealth applications, particularly the authority can also impose any advice, or any other in terms of EHR. Before it is released fines and imprisonment if the information, services or and can be used by the public, the requirements are breached. products obtained through National Coordinator will ensure the use of the tool/apps listed the feasibility and quality of HER If the ESP as the electronic on the Digital Apps Library technology and establish certification channel provider uses third . of the technology. For health care party content online without providers who is willing to adopt such obtaining the relevant rights, NHS Digital or the approving technology, they will be charged by it could be exposed to claims body has set standards for the National Coordinator in which of intellectual property reviewing the tools/apps the amount of the fee is adjusted infringement. as detailed in this library, to the condition of the health care but NHS Digital does not provider. Funds generated from There are statutory offences mean that NHS Digital or the these technology adoption payments that could potentially be approving body has itself will then be allocated to smaller, low- committed through the reviewed all aspects of the income, and service providers in rural online publication of obscene tool/app, or version of the areas that are medically inaccessible. material and can result in both same tool/app. The Digital imprisonment and fine. (Under Apps Library is intended to Supervision on the quality of health the Undesirable Publications provide supportive relevant services is also carried out at the Act). information only. It does not state level. Government in the U.S. provide medical advice and State has the duty to administer For liability limitation of network it is not a substitute for a and sponsor a health care program. service providers in Singapore, medical consultation. Against this policy, the State the government though ETA Government is required to enter into specifies that network service In terms of malpractice in UK, an agreement with any health care providers will not be subject to general malpractice lawsuits provider, health planning or health criminal or civil liability for such are addressed to the NHS and insurance that the provider in the third-party material, in relation the NHS Trust, not individual information technology system used to which they are merely the doctors. In this case, NHS and must comply with the standards host. the NHS Trust are responsible and specifications set by the for their employees’ negligent Government.126 and negligent acts, including doctors and nurses. This responsibility arises from the maintenance tasks assigned by the NHS Trust to their patients. The adoption of this representative responsibility has resulted in a government policy known as the NHS compensation policy. Given this policy, the NHS may be liable for financial / medical damages for medical negligence / malpractice.

104 Health Singapore UK USA Application In addition, the telemedicine organization in the U.S., the American Telemedicine Association (“ATA”) has developed a guideline for telemedicine services, namely: Core Operational Guidelines for Telehealth Services Involving Provider-Patient Interactions.

Contemporary EHR system technology has significant limitations, and if these cause harm, aggrieved individuals and enforcement entities have many legal resources. Plaintiffs whose alleged injuries are associated with EHR systems could sue health care providers for medical malpractice. Those who believe that their records have been improperly disclosed to third parties could assert privacy violation claims. In rare circumstances, providers accused of negligent EHR system use could face disciplinary proceedings (initiated by professional organizations), government enforcement actions, or criminal prosecutions.

Patients who feel that their care givers were negligent in treating them may assert medical malpractice claims. To prevail, the plaintiff must establish the four elements of negligence: (1) a duty of care owed by the defendant to the plaintiff, (2) breach of that duty through conduct that fails to meet the applicable standard of care, (3) harm or injury, and (4) a causal link between the injury and the breach of duty.

105 Health Singapore UK USA Application u. Payment/ In terms of IT infrastructure in Tariff in health and social care Billing relation with payment, there is is ruled by Health and Social no specific regulatory measure Care Act 2012 where Article (from IT/Communication 115 of this law sets out “If a sector) found. However, in health care service is specified terms of payment scheme, as in the national tariff, the price in the US and EU, health care payable for the provision of financing is generally done that service for the purposes by reimbursement, in which of the NHS is such price as the programs are divided is determined in accordance into several forms, namely: (i) with the national tariff on the Medisave; (ii) Medishield; (iii) basis of the price specified Medifund; and (iv) Eldershield. in the national tariff for that However, in the provision of service.” But “If not specified telemedicine services, not all in the national tariff, the price payments on services rendered payable of which services receive reimbursement. shall comply with rules provide for in the national tariff for that purposes” Of which national tariff, NHS published national tariff guidance for every two years. For this years, the in-force document is the 2017/18 and 2018/19 National Tariff Payment System containing a set of prices and rules to help providers of NHS care and commissioners provide best value to their patients.

In regard to eHealth apps, NHS unveiled a supporting document to the 2017/18 and 2018/19 National Tariff Payment System, namely Innovation and Technology Tariff 2017 to 2019: technical notes (“ITT”). ITT was introduced to incentivise the adoption and spread of transformational innovation in the NHS. Approach of ITT is by using several mechanisms to fund innovation which meet the required theme specifications (from 1 to 6 themes). For themes (2,3,4,5), NHS guarantee automatic reimbursements to providers when a selected device, app or platform is used (“Paid for centrally by NHS”). For theme 1 provider will be reimbursed based on use.

106 Health Singapore UK USA Application For theme 6 provider are funded under the National Tariff for this innovation.

Hereby, six themes of ITT category which NHS gives incentive are: 1. Guided mediolateral for episiotomy to minimize the risk of obstetric and anal sphincter injury (charged per use, GBP 16) 2. Reduction of bacterial contamination and accidental administration of medication (charged per use, GBP 2) 3. Prevention of ventilated associated pneumonia in critically ill patients (charged per use, GBP 150) 4. Web-based applications for the self-management of chronic obstructive pulmonary disease (charged per patient registration, GBP 20) 5. Frozen faecal microbiota transplantation (FMT) for recurrent Clostridium difficile infection (charged per patient use, GBP 95) 6. Treatment of lower urinary tract symptoms of benign prostatic hyperplasia as a day case (charged per spell, n/a as this not included in ITT but in National Tariff as above)

NHS England will cover the costs of the innovations identified in ITT as outlined in each theme specification. Additional costs associated with implementation are not covered by the ITT and should form the basis of local discussions.

Furthermore, regarding the reimbursement of telemedicine services,

107 Health Singapore UK USA Application the NHS has provided a choice of 20 telemedicine programs that can be reimbursed automatically, such as MyCOPD, AliveCor and Pneux applications. Thus, it can be said that UK citizens do not have to pay anything related to health services, given the high taxes paid by UK citizens, where the free service includes all health services including consultation, examination, operation and all drug purchase. v. Collaboration, No specific regulatory measure NHS does not endorse the No specific regulatory measure (from Partnership, (from IT/Communication sector) eHealth app listed in the IT/Communication sector) found. Endorsement found. Digital Apps Library. Medical staff and GPs, however, could endorse eHealth app for patients, but they reportedly reluctant to recommend an app as they do not want to be held contributory liable if app use to lead to patient harm in the health service since the GPs already held accountable for their prescribing decisions. The collaboration in eHealth innovation principally is facilitated by NHS and NHS Digital, including partnership with RAG or the Health Developer Network as above.

108 Health Singapore UK USA Application w. Cross-Country Singapore does not clearly In the UK there is no specific Under Article 10 of the U.S. Practice govern telemedicine practices regulation on telemedicine Constitution, the state is authorized across countries. However, services conducted to regulate the health, security and the Singapore National across countries, so in its welfare aspects of its citizens. To be Telemedicine Guidelines implementation it refers to able to practice health care, every provides that telemedicine health regulations. In the health worker is required to obtain providers originating or residing UK itself, there is a special a practical license from the State. in Singapore are required to be requirement for medical In the case of telemedicine, the registered and possess licenses practitioners who wish to requirement to obtain a permit, the originating from the competent practice in the UK, which is health worker shall ensure that its entity. Furthermore, as to the required to be registered in activities are legally valid. qualifications of health-care full at the General Medical providers, Article 13 paragraph Council (“GMC”), or qualify for With Telehealth, the provision of (1) of the Singapore Medical inclusion in the GMC specialist health services is possible by health Registration Act Chapter list. Although conditions workers and patients in different 174 also affirms that no one apply to non-UK medical places (states). Each state has its may practice as a medical practitioners, there are own rules. The majority of States practitioner or perform any differences in requirements have strict rules governing that any action as a medical practitioner between medical practitioners health worker providing inter-state unless he is registered under from countries that are health services must have a practice the terms of this rule and has members of the European permit from the State where his or certificate for valid practice. Economic Area (“EEA”) and her patient is located. However, in medical practitioners from the event of an emergency, such outside the EEA. provisions may be disregarded.

In addition, some states issue special permits or certificates related to the practice of telemedicine. There is also a state that does not specifically issue a specific telemedicine practice permit, but may issue a temporary medical license for a health worker from another state provided that the health worker meets the requirements. x. Supervision The Health Sciences Authority NHS is National Health Department of Health and Human and Provision (HSA) Service , an executive non- Secretary of Planning and Evaluation. departmental public body of the Department of Health and Social Care. Subsidiary of NHS is NHS Digital, a national information and technology partner of the UK Department of Health & Social Care

109 Health Singapore UK USA Application y. Credentialing Associated with credentialing In the UK alone, there are The national health organization in and Privileging and privileging, at present, there special requirements for the United States, i.e., The Centers for is no special permission for medical practitioners who Medicare & Medicaid Service (“CMS”) medical practitioners to practice wish to practice in the UK, is responsible for accrediting and telemedicine in Singapore. which is required to be validating the competence of medical However, the Singapore registered in full at the personnel through credentialing Telemedicine Guidelines General Medical Council and privileging. In the context of provides that telemedicine (“GMC”), or qualify for telehealth, if the CMS has to do the service providers originating inclusion in the GMC specialist credentialing and privileging process or residing in Singapore are list. Although conditions which used an online health site required to be registered and apply to non-UK medical provider in consultation, it will cause possess licenses originating practitioners, there are an administrative burden. To mitigate from a competent entity. differences in requirements this burden, the Joint Commission between medical practitioners (TJC) establishes a standard that Furthermore, as to the from countries that are allows hospitals to conduct its qualifications of health care members of the European own credential and privileging. The providers, Article 13 paragraph Economic Area (“EEA”) and provision also allows hospitals to (1) of the Singapore Medical medical practitioners from receive services to make credential Registration Act Chapter outside the EEA. and privilege decisions for online 174 also affirms that no one health care providers. may practice as a medical practitioner or perform any Furthermore, CMS through action as a medical practitioner Medicare Conditions of Participation unless he is registered under determines that between the hospital the terms of this rule and has and the online health care provider, a certificate for valid practice. written agreement should be made. Through the written agreement, the organization should ensure that the processes and standards of credentials and privileges from eHealth service providers meets the CMS-defined standards and compliance with those standards is entirely the responsibility of eHealth health care providers.

Conclusion: Required Matters & Board of the Indonesian Doctors Association. The Importance of Regulation 221 / PB / A.4 / 04/2002 on the Implementation of the Indonesian Medical Code of Ethics (The Challenges in implementing telemedicine are Medical Code of Ethics). Furthermore, a more substantial, and it varies from funding, regulations, detailed legal framework is also needed to allow adoptions and evidence of cost savings. Aside from the implementation of eHealth system, such as costs, regulations and adoptions are things that regulation on data protection, quality of care, should be solved in timely manner. It is reassuring liability and reimbursement, e-prescribing, for those entrepreneurs who enter telehealth in patient confidentiality, and patient safety. the 20th century, to understand that the Indonesian government’s response is slow but surely accepting In addition, government also needs to set clear telemedicine. regulation on authorized body to supervise, As mentioned before, the existing medical practice monitor, control, and regulate eHealth practice regulation required face to face interaction as a in Indonesia as until today, the supervision of compulsion. The government needs to provide eHealth practice in Indonesia is divided under regulation that make such telemedicine practice the Ministry of Health and the Ministry of to be feasible to conduct but also protecting the Communication and Information. patient from the disadvantage that might arise during telemedicine process. As to this condition, other than In regards to government’s support in eHealth providing the regulations to support implementation implementation in Indonesia, Ministry of Health of eHealth in Indonesia, the related stakeholders also has confirmed its support on the eHealth issue, needs to amend regulations which are contradictive that the Ministry will work with other related to government’s plan in developing eHealth ministries to implement the eHealth system in implementation, such as Decree of the Executive Indonesia.

110 dr. Slamet, MPH, Special Staff for Other than challenges caused by technical developments on eHealth platforms, we see Health issue and Globalisation, that challenges caused by lack of regulatory Ministry of Health: framework in eHealth is also a big hole for the implementation of eHealth in Indonesia. With support from stakeholders, particularly “We are willing and trying to the relevant ministries, we believe that the execute eHealth system in development and investment in eHealth will Indonesia by working together be boosted in timely manner. with other ministries, such as Ministry of Public Works, Ministry of Information and Communications, State owned Electricity Company.”

111 112 113 Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited (“DTTL”), its global network of member firms, and their related entities. DTTL (also referred to as “Deloitte Global”) and each of its member firms and their affiliated entities are legally separate and independent entities. DTTL does not provide services to clients. Please see www.deloitte. com/about to learn more.

Deloitte is a leading global provider of audit and assurance, consulting, financial advisory, risk advisory, tax and related services. Our network of member firms in more than 150 countries and territories serves four out of five Fortune Global 500® companies. Learn how Deloitte’s approximately 286,000 people make an impact that matters at www.deloitte.com.

Deloitte Asia Pacific Limited is a company limited by guarantee and a member firm of DTTL. Members of Deloitte Asia Pacific Limited and their related entities provide services in Australia, Brunei Darussalam, Cambodia, East Timor, Federated States of Micronesia, Guam, Indonesia, Japan, Laos, Malaysia, Mongolia, Myanmar, New Zealand, Palau, Papua New Guinea, Singapore, Thailand, The Marshall Islands, The Northern Mariana Islands, The People’s Republic of China (incl. Hong Kong SAR and Macau SAR), The Philippines and Vietnam. In each of these, operations are conducted by separate and independent legal entities.

About Deloitte Indonesia In Indonesia, services are provided by PT Deloitte Konsultan Indonesia.

This communication contains general information only, and none of Deloitte Touche Tohmatsu Limited, its member firms, or their related entities (collectively, the “Deloitte Network”) is, by means of this communication, rendering professional advice or services. Before making any decision or taking any action that may affect your finances or your business, you should consult a qualified professional adviser. No entity in the Deloitte Network shall be responsible for any loss whatsoever sustained by any person who relies on this communication.

© 2019 PT Deloitte Konsultan Indonesia

114