BPJS Kesehatan Trust Mark

BPJS Kesehatan Trust Mark Socialization Notes

Agenda

  • BPJS Trust Mark: Definition, Objectives, Benefits, Framework, Assessment, Flow, Mechanisms, Implementation, Understanding of Assessment Criteria

Ekosistem Digital BPJS Kesehatan

  • Collaboration & Partnership:
    • Banking: > 1 Million Payment Channels (Bank, Non-Bank, Retail, e-Commerce)
    • Fasilitas Kesehatan: Puskesmas, Private Practice Doctors, Primary Clinics, Dentists, Class D Hospitals, Hospitals, Main Clinics, Pharmacies, Opticians (> 32,000)
    • Ministries/Institutions: Kemenkes, Kemenkeu, Kemensos, Kemendagri, OJK, KPK, PT Taspen, BPJS-TK, POLRI, ATR-BPN, Kemenperin, BKN (±30)
    • Application Service Provider (ASP) & Payment Services: >30
    • Indonesian Population: > 278 Million
    • Companies/Business Entities: > 250,000 working together

Definisi BPJS Kesehatan Trust Mark

  • Alignment Efforts: Harmonizing Information System Management within the BPJS Kesehatan Digital Ecosystem regarding the use and utilization of BPJS Kesehatan information systems.
  • Alignment: Encompasses aspects of Confidentiality, Integrity, and Availability of IT services.
  • Data and Information Security: Utilizing the Information System Management Maturity Level method for alignment.
  • Maturity Mechanism: Enhancing the understanding of risk mitigation mechanisms concerning Personal Data Protection (PDP).
  • Personal Data Protection (PDP)

Tujuan BPJS Kesehatan Trust Mark

  • Commitment: BPJS Kesehatan is dedicated to fostering high-quality and standardized information system governance among its partners.
  • Standard Implementation: Establish standards implementable by all FKRTL Partners, covering Technical Aspects, IT Service Aspects, and Information Security Aspects to ensure uniformity and quality of information system management across all BPJS Kesehatan Partners, aiming for optimal Interoperability and Data Integration.
  • Continuous Improvement: Encourage partners to continuously improve and monitor their information systems, thereby creating good and sustainable governance.
  • Commitment:
    • BPJS Kesehatan
    • Data and Information Security
    • Continuous Improvement

Manfaat BPJS Kesehatan Trust Mark

  • Enhanced Data Security Control: Prevents potential misuse/loss of personal data, medical records, and payment transactions, ensuring greater privacy and security for JKN participants' data.
  • Increased JKN Participant Trust: Boosts trust through the reliability of partner information systems, achieved via well-managed processes for handling disruptions and ensuring IT service availability, thereby providing JKN participants with easier and more convenient access to healthcare services.

Kerangka Kerja Trust Mark

  • BPJS Kesehatan Trust Mark uses a process maturity method, assessing 3 Process Maturity Standards:
    • Information Security
    • IT Service Management
    • Technical Standards
  • External Regulations
    • UU No 27 Tahun 2022 (Personal Data Protection)
    • UU No 1 Tahun 2024 (Information and Electronic Transactions)
    • Permenkes No 24 Tahun 2022 (e-Medical Records)
  • Internal Regulations
    • Perdir NO 36 Tahun 2021
    • BPJS Kesehatan Trust Mark Guidelines

Trust Mark Assessment Criteria

  • Main Criteria:
    • Physical Controls
    • Organizational Controls
    • Personnel Controls
    • Technology Controls
  • Maturity Standards:
    • Information Security
    • IT Service Management
    • Technical Standards
  • Other Criteria:
    • Service Offering and Request
    • Service Guarantee
    • Relationship and Agreement
    • Service Portfolio
    • Service Fulfillment and Resolution
    • System Development Standards
    • Technical Standards for Facilities
    • Technical Standards for Infrastructure

Trust Mark Maturity Assessment

  • How Maturity Level Measurement Helps Healthcare Facilities:
    • Realization of reliable and secure service performance for BPJS Kesehatan and healthcare facilities.
    • Opportunity for improved IT governance for healthcare facilities within the BPJS Kesehatan's information technology ecosystem.
    • Fostering collaboration and increased engagement in the IT area between BPJS Kesehatan and Healthcare Facilities.
    • Ensuring information transparency, making the BPJS Kesehatan Trust Mark implementation trustworthy.
  • Aspects:
    • Information Security and Service Management
    • Communication and Collaboration
    • Process Implementation
    • Trust

Penilaian Kematangan (Maturity Assessment)

  • Levels:
    • 0: No evidence of process implementation.
    • 1: Process is implemented sporadically.
    • 2: Process is implemented consistently but based on individual understanding.
    • 3: Process is implemented consistently following formal procedures.
    • 4: Process is implemented consistently, following formal procedures, and evaluated.
    • 5: Process is implemented consistently, following formal procedures, evaluated, and includes follow-up actions for improvement.
  • The higher the maturity level, the more measurable the implementation and process improvement.

Penilaian Kematangan (Maturity Assessment) - Criteria Examples

  • Rating Criteria & Questions:
    • Rating 1: Process is done only when requested. No plan for regular execution. Clear explanation of the process; roles and responsibilities defined; some documented samples.
    • Rating 3: Regular execution with documented evidence. Aligned with facility regulations and procedures. A procedure exists with steps, objectives, and expectations.
    • Rating 4: Regular execution, evaluation of procedure implementation, and documentation (e.g., changes to existing procedures).
    • Rating 5: Showing follow-up actions based on the evaluations (Rating 4).

Penilaian Kematangan - Rating Values

  • Rating 1: < 1.49. The applied process achieves the process objective.
  • Rating 2: >1.5 s/d 2.49. The process is implemented in a managed manner (planned, monitored, and adjusted); work results are appropriately maintained.
  • Rating 3: >2.5 s/d 3.49. The managed process is implemented using defined processes within documented requirements and can achieve process results.
  • Rating 4: >3.5 s/d 4.49. The established process is evaluated to fulfill requirements.
  • Rating 5: >4.5. The process is continuously improved to meet current relevant assessment requirements and ongoing improvement.

Mekanisme Penyelarasan (Alignment Mechanism)

  • Hybrid Implementation: BPJS Kesehatan Trust Mark implementation can be done hybrid (online or offline).
  • Steps:
    • Trust Mark socialization.
    • Technical guidance to partners.
    • Portal registration & self-assessment.
    • Facility selection that is recommended.
    • Verification.
    • Rating validation.
    • Rank Validation
    • Awarding of Appreciation
    • Re-assessment submission (Minimum 1 year from the last assessment)
  • BPJS Kesehatan & Faskes involvement.
  • Trust Mark Portal: https://trustmark.bpjs-kesehatan.go.id/

Trust Mark Registration Flow

  1. FKRTL registers on the Trust Mark portal.
  2. FKRTL fills in FKRTL identity data.
  3. FKRTL fills out the self-assessment form (Technical Standards, IT Services, Information Security).
  4. After completing the self-assessment form, FKRTL submits the form.

Trust Mark Verification Flow

  1. FKRTL prepares self-assessment documents and reviews the completed self-assessment.
  2. Verification scheduled for FKRTL recommended by BPJS Kesehatan.
  3. Verification team conducts verification either onsite/online.
  4. Proposed rating results are submitted to the Rating Team (decision-making committee).
  5. Upon approval, a certificate/award is issued and signed by the Director of IT BPJS Kesehatan.

Trust Mark Implementation

  • Criteria:
    • I. Information Security Criteria
      • a. Physical Control
      • b. Organization Control
      • c. Personnel Control
      • d. Technology Control
    • II. Information Technology Service Criteria
      • a. Service Portfolio
      • b. Relationships and agreements
      • c. Supply and Demand
      • d. Designing, creating and transitioning service
      • e. Resolution and fulfillment
      • f. Service Guarantees
    • III. Technical Standard Criteria
      • a. Technical Infrastructure Standards
      • b. System Development Standards
      • c. Technical Standards Facilities
        *Pengisian penilaian mandiri melibatkan unit kerja pada FKRTL
        *I. Kriteria Keamanan Informasi a. Bagian Pengelolaan Sumber Daya Manusia b. Bagian Pengelolaan Aset Informasi (SIMRS, Rekam Medis) c. Bagian Pengelolaan Fasilitas RS (Genset, UPS, CCTV) d. Bagian Operasional TI II. Kriteria Layanan TI a. Bagian Pengelola server dan Database, b. Bagian Pengelolaan Operasional TI (Pengelola Pengembangan Aplikasi) c. Bagian Pengelolaan Operasional TI (Bagian Penanganan Gangguan TI) d. Bagian Pengelolaan Keberlangsungan Operasional/Bisnis, e. Bagian Penganggaran TI III. Kriteria Standar Teknis: a. Bagian Pengelolaan Keberlangsungan Operasional/Bisnis, b. Bagian Pengelolaan Operasional TI

Trust Mark Implementation - Physical Checks

  • A physical check is conducted for the following main criteria, penilaian and aspects:
    • Technical Standards Infrastructure:
      • Server Usage Standards:
        • Super user account usage.
        • Strong and secure password usage.
        • Using OS versions still supported for security.
        • Routine maintenance activities to maintain server security and availability.
      • Database Usage Standards:
        • Database account and authorization management.
        • Secure passwords.
        • Using supported database versions.
        • Review of SIMRS database backups from the last 2 weeks and database recovery results from the last 6 months.
      • Network Infrastructure Standards:
        • WIFI access security, Internal Network access security, Remote Access security (VPN).
        • Implementation of network segmentation & authentication application.
      • Firewall Infrastructure Standards:
        • Active Firewall, traffic filtering, implemented on more than 75% of devices (PC/Laptop & Server).
        • Periodic review of firewall configuration.
      • Application Development Security Standards:
        • Storing and using BPJS Kesehatan cons-IDs on partner applications.
        • If using an application development vendor, having an NDA and clauses in the agreement for BPJS Kesehatan cons-ID usage requirements.
      • Facility Availability Standards:
        • Providing backup power (Genset and UPS) to support server devices.
        • Routine maintenance performed within the last 1-2 months.
    • Information Security:
      • Physical Security Perimeter:
        • Restrictions for data processing and archive areas: walls, glass, fences.
        • Access restrictions to the data processing and archive areas: room/rack keys, entry permit processes for non-personnel.
      • Entry Access:
        • Application of entry access to data processing and archive areas.
        • Identity verification for entry in addition to special personnel.
      • Security Monitoring:
        • 24/7 monitoring with CCTV.
        • Cameras and DVRs functioning well and regularly maintained.
      • Indoor Security (securing rooms and facilities):
        • Restrictions for data processing and archive areas: walls, glass, fences.
        • Access restrictions to the data processing and archive areas.
      • Work Devices (user end point devices):
        • Restrictions on installing games or personal apps on computers.
        • Controlling the use of personal laptops for accessing patient medical systems/information.

Verifikasi BPJS Kesehatan Trust Mark dapat dilakukan secara hybrid (online maupun off-line)

Verifikasi Mekanisme

  1. Ensure the suitability of values from the self-filling with the maturity level of the process
  2. Giving the chances for Health Facilities to understand the goals from the valuation criteria
  3. Each other gives implementation examples well done by BPJS Health or health facilities from each criterion

Verifikasi Objektif

  • Onsite/Off Line
  • On Line Via Zoom
  • Pelaksanaan Verfikasi dilakukan dengan metode Luring, Tim langsung datang ke Faskes dan Daring mengunaan media Online via zoom

Source Verifikasi

  • BPJS Kesehatan

Verifikasi

  • Verification can be conducted in a hybrid manner (online or offline).
    1. Ensuring the relevance of values from self-assessment with process maturity level criteria.
    2. Providing opportunities for Healthcare Facilities to understand the purpose of the assessment criteria.
    3. Sharing examples of good practices implemented by both BPJS Kesehatan and healthcare facilities from each other.

Trust Mark Assessment Report - Example

  • TI Service Management: Mitra - 4.53, Penilai - 2.47
  • Information Security Management: Mitra - 5.00, Penilai - 1.83
  • Standarisasi Teknis TI Management: Mitra - 1.83, Penilai - 1.33
  • Conclusion:
    • Majority of the management process is done consistently but based on the individual understanding of each personnel, improvement done consistently and following the SOP.

Potential Cyber Attacks

  • Criminal Sanctions: threat Criminal imprisonment for at most 5 years whoever is responsible with PSE / Personal Data Controller
  • BSSN, 2024: 593 suspected cyber incidents
  • Data Breach: 2% x Total Revenue x Violation Variables
  • Indonesia, 2024: ± 300 Million anomaly traffic
  • ± 60.000.000 data exposed leaked and 461 institutions affected during 2024 (healthcare industry ranked 6th)
  • Top 5 Cyber Attacks: Data leaks, illegal access, web hacking, ransomware, anomaly traffic darknet exposure.
    • Health Sector 2%
  • TOP 5 Ancaman Siber POTENSI SERANGAN SIBER 24

Potensi Serangan Siber

  • Cyber incidents is The 1st Global Business Risk 2024. according to Allianz Risk Barometer.
  • Data Breaches are The Most Feared menurut Allianz Risk Barometer 2024.

Jejak Digital Implementasi Trustmark

  • Radar Solo, 9 Sep 2024. focus on IT control and data security and IT service.
  • Pemprov Sumsel, 26 Agu 2024 - FGD to conduct implement Trust Mark.
  • Instagram, 24 Jul 2024 - Verifikasi importance to make sure our system follow The Standard.
  • Rumah Sakit Soeharto Heerdjan, 20 Mei 2024 - The target is to strength data control and data protection.
  • RRI.co.id, 24 Jul 2024 assessment to strength data control and data protection.
  • Bangkapos.com, 24 Jul 2024 implementation focus on data protection.
  • RS PKU SOLO, Mendapatkan Sertifikat Apresiasi BPJS Kesehatan Trust Mark @JKTI.

Jejak Digital Implementasi Trustmark

  • Instagram-rsukotatarakan, 24 Jul 2024 verifikasi BPJS untuk memperkuat sistem
  • Rumah Sakit Ernaldi Bahar, 27 Aug 2024.
  • RRI.co.id, 24 Jul 2024.
  • Instagram - rs.maryamcitramedika, 05 Januari 2024.
  • Rumah Sakit Bali Mandara, 22 Jun 2023.
  • PWMU.CO, 10 Oct 2024

Konsekuensi UU PDP

  • Sanksi Pidana kurungan penjara 5 tahun.
  • Sanksi Denda 2% x Pendapatan total from violation..

Example Cyber Attacks

  • Bjorka Peringatkan BCA dan BSI Ada Ancaman Ransomware. 06 Feb 2025
  • Serangan Siber ke Pusat Data Nasional Ganggu Layanan …. 24 Jun 2024
  • Ransomware Lockbit 3.0 Klaim Lumpuhkan BSI dan Curi … 13 Mei 2023
  • Biznet Gio korban peretasan. 2 hours ago
  • Kelompok peretas Stormous menyerang laman milik PT Kereta Api Indonesia (KAI).
  • Peretas yang menamakan dirinya TopiAx membocorkan data Badan Kepegawaian Negara (BKN). 10 Agustus 2024
  • Perusahaan penukaran kripto, Indodax, mengalami gangguan sistem akibat peretasan sehingga rugi senilai US$22 juta.

Example Cyber Attacks cont.

  • RSUD dr. Soetomo di Surabaya mengalami sekitar 15.000 upaya peretasan terhadap sistem data mereka. Selama periode Januari hingga Juli 2024.
  • Kebocoran data pribadi dan kesehatan lebih dari 100 juta individu pada Change Healthcare, penyedia layanan perangkat lunak dan teknologi medis di Amerika Serikat yang mengalami serangan ransomware.
  • Dua rumah sakit di Inggris mengalami serangan siber yang mengakibatkan tertundanya 1.130 operasi yang dijadwalkan dan mempengaruhi 2.190 pasien poliklinik

Example Cyber Attacks cont..

  • Running Text RSUZA Diretas, Muncul Pesan 'Harap Lebih Ramah Sesama Manusia' 26 Juli 2024
  • Akun IG Diretas, RSHS Imbau Masyarakat Waspada 28 November 2023
  • Bobolnya PDN Berdampak ke Data Kesehatan, Riwayat Sakit Pasien Bisa Terungkap ke Publik 2 Juli 2024

Portal BPJS Kesehatan

  • Form Penilaian
  • Form Verifikasi