TTIS Fasyankes Implementation Strategy: A Compliance Guide for Ministry of Health SEB 2026 Mandate
Strategi Implementasi TTIS Fasyankes: Panduan Kepatuhan Mandat SEB Kemenkes 2026
Pernah nggak sih, kamu mikir, seberapa aman sih data rekam medis kamu di rumah sakit? Atau data pasien yang tersimpan di server klinik tempat kamu berobat?
Jujur aja, selama ini kita mungkin lebih sering khawatir soal data pribadi bocor dari aplikasi belanja online atau media sosial. Tapi data kesehatan? Itu jauh lebih sensitif. Data medis bukan cuma nama dan alamat. Tapi riwayat penyakit, hasil lab, bahkan kondisi psikologis. Kalau sampai bocor atau disandera peretas, dampaknya bukan main-main.
Nah, pemerintah sadar betul soal ini. Makanya, lewat Surat Edaran Bersama (SEB) Kementerian Kesehatan No. 18 Tahun 2026, setiap Fasilitas Pelayanan Kesehatan (Fasyankes) wajib membentuk Tim Tanggap Insiden Siber (TTIS). Bukan cuma bentuk formalitas, tapi tim yang benar-benar siap siaga menghadapi serangan siber.
Dan yang lebih penting lagi: batas waktu pembentukan TTIS adalah 30 September 2025. Kalau lewat? Siap-siap urusan registrasi ke BSSN molor dan kena sanksi.
Tenang, artikel ini akan memandu kamu langkah demi langkah. Dari dasar hukum, struktur organisasi, dokumen yang dibutuhkan, sampai cara daftar registrasi di BSSN. Tanpa basa-basi, tanpa bikin pusing. Yuk, kita mulai.
Kenapa TTIS Fasyankes Wajib Dibentuk?
Coba bayangkan. Suatu hari, seluruh sistem rekam medis elektronik di sebuah rumah sakit tiba-tiba terkunci. Muncul pesan: "Data Anda telah dienkripsi. Kirim tebusan 10 Bitcoin untuk mengembalikan akses."
Gawat, kan? Dokter nggak bisa akses riwayat pasien, jadwal operasi kacau, apotek nggak bisa baca resep. Semua layanan lumpuh.
Ini bukan cerita horor. Ini ancaman nyata. Apalagi Indonesia punya 7.347 aplikasi pelayanan kesehatan di berbagai daerah. Masing-masing punya celah kerentanan yang bisa dieksploitasi.
Makanya, pembentukan TTIS adalah mandat imperatif. Bukan opsi. Bukan saran. Tapi keharusan yang dilandasi oleh beberapa regulasi kuat:
- UU No. 17 Tahun 2023 (Kesehatan): Mewajibkan perlindungan data kesehatan dalam sistem elektronik.
- UU No. 27 Tahun 2022 (PDP): Mengharuskan pengendali data menjamin keamanan data pribadi pasien.
- PMK No. 24 Tahun 2022 (Rekam Medis Elektronik): Mengatur keamanan dalam migrasi dan pengelolaan RME.
- Peraturan BSSN No. 1 Tahun 2024: Mewajibkan penanganan insiden siber secara terorganisir.
Intinya: kalau Fasyankes kamu belum punya TTIS, kamu sedang melanggar hukum. Dan konsekuensinya nggak main-main.
Struktur Organisasi TTIS: Siapa Melakukan Apa?
Banyak yang salah kaprah. Mereka pikir TTIS cukup ditunjuk satu orang IT dan selesai. Padahal, TTIS harus punya struktur yang jelas, sesuai dengan Kepmenkes No. HK.01.07/MENKES/542/2025. Struktur ini dirancang biar tim bisa bergerak cepat dan efektif saat terjadi insiden.
Berikut elemen pelaksana TTIS yang wajib ada:
| Bidang | Tugas Utama |
|---|---|
| Monitoring dan Aksi | Deteksi serangan, pemilahan insiden, analisis risiko, penanganan kerentanan, dan pendampingan pemulihan. |
| Kehumasan | Komunikasi publik, manajemen krisis, pemantauan media, dan edukasi keamanan siber internal. |
| Hukum | Pendampingan regulasi, legalitas pengelolaan data, kepatuhan hukum siber. |
| Peningkatan Kapasitas SDM | Pengembangan kompetensi personel teknis dan fungsional dalam menghadapi ancaman siber. |
Selain empat bidang di atas, ada satu peran penting yang sering dilupakan: Pejabat Penghubung (Liaison Officer). Orang ini adalah jembatan komunikasi antara Fasyankes dengan BSSN dan Kementerian Kesehatan. Saat terjadi insiden, dialah yang pertama memberi laporan.
Poin penting: Semua bidang ini harus tercantum dalam Surat Keputusan (SK) Tim TTIS. Tanpa SK resmi, timmu secara hukum tidak eksis. Dan registrasi ke BSSN pun batal.
Roadmap Pendaftaran TTIS: Batch IV - VI Tahun 2026
Setelah SK terbit, langkah selanjutnya adalah mendaftarkan TTIS ke BSSN untuk mendapatkan Surat Tanda Registrasi (STR). STR ini adalah bukti resmi bahwa TTIS-mu diakui oleh otoritas nasional.
Pendaftaran dibagi dalam beberapa gelombang (batch) sepanjang tahun 2026. Pilih batch yang paling sesuai dengan kesiapan dokumenmu.
| Batch | Tahapan | Rentang Tanggal |
|---|---|---|
| Batch IV | Registrasi & Validasi Berkas Revisi Berkas & Uji Komunikasi (A) Revisi Berkas & Uji Komunikasi (B) Penerbitan STR |
16 Maret – 10 April 13 April – 17 April 20 April – 24 April 27 April – 1 Mei |
| Batch V | Permohonan & Penjadwalan Validasi Berkas & Uji Komunikasi Revisi & Persetujuan Berita Acara Penerbitan STR |
4 Mei – 8 Mei 11 Mei – 15 Mei 18 Mei – 22 Mei 25 Mei – 29 Mei |
| Batch VI | Permohonan & Penjadwalan Validasi Berkas & Uji Komunikasi Revisi & Persetujuan Berita Acara Penerbitan STR |
1 Juni – 5 Juni 8 Juni – 12 Juni 15 Juni – 19 Juni 22 Juni – 26 Juni |
Perhatian! Tahap Uji Komunikasi dan Persetujuan Berita Acara adalah titik kritis. Kalau gagal di sini, seluruh proses registrasi di batch tersebut batal. Kamu harus mengulang dari awal di batch berikutnya. Jadi, persiapan matang itu wajib.
Persyaratan Dokumen: Jangan Sampai Kurang
Dokumentasi adalah nyawa dari proses registrasi. BSSN akan menilai kelengkapan dan kesesuaian dokumenmu. Kalau ada yang kurang atau salah format, proses bakal tertahan.
Berikut checklist dokumen wajib yang harus kamu siapkan:
- SK Tim TTIS Fasyankes — Mengacu pada template resmi di Kepmenkes 542/2025. Pastikan struktur organisasi sesuai.
- Dokumen Profil CSIRT — Berisi deskripsi kapabilitas tim dan aset informasi yang dilindungi.
- Form Penilaian IIV — Instrumen untuk menilai kematangan penanganan insiden (bisa diunduh dari portal BSSN).
- Panduan Operasional CSIRT (SOP) — Prosedur standar penanganan insiden, dari deteksi hingga pemulihan.
Kabar baiknya, BSSN menyediakan "CSIRT Starter Kit" yang berisi template dan panduan teknis lengkap. Kamu bisa mengunduhnya di portal resmi registrasi. Untuk akses, gunakan kredensial berikut:
- Password: infoCSIRT123#
Setelah semua dokumen lengkap, kirimkan melalui email resmi ke registrasi.ttis@bssn.go.id dengan tembusan (CC) ke d33.pm@bssn.go.id.
Koordinasi dan Verifikasi: Hubungi PIC dengan Tepat
Proses registrasi nggak bisa hanya mengandalkan email. Kamu juga perlu berkoordinasi langsung dengan Person In Charge (PIC) dari BSSN. Mereka akan membantu memvalidasi berkas dan menjadwalkan Uji Komunikasi.
Berikut kontak strategis yang wajib kamu catat:
- PIC Personil & Admin: Laila Nur Khofifah — WhatsApp: +62 851-7427-0561
- PIC Institusi: Direktorat KSS Pembangunan Manusia, BSSN
- Email Resmi: registrasi.ttis@bssn.go.id (CC: d33.pm@bssn.go.id)
Proses verifikasi akan melibatkan Uji Komunikasi untuk memastikan saluran respons insiden berfungsi 24/7. Setelah uji komunikasi dinyatakan berhasil, akan diterbitkan Berita Acara yang menjadi dasar penerbitan STR.
Catatan penting: Nomor WhatsApp PIC melayani koordinasi administrasi dan personil sekaligus. Jadi gunakan dengan bijak, ya. Nggak usah spam.
Operasionalisasi TTIS: Bukan Sekadar Administrasi
Setelah STR terbit, jangan merasa selesai. TTIS bukan sekadar tim di atas kertas. Mereka harus aktif menjalankan fungsinya. Bayangkan seperti pemadam kebakaran. Nggak mungkin kan, pemadam cuma ada atributnya tapi nggak pernah latihan atau siaga?
TTIS punya dua jenis layanan utama:
- Layanan Reaktif: Saat insiden terjadi — forensik digital, isolasi ancaman, pembersihan sistem, dan restorasi backup.
- Layanan Proaktif: Pencegahan — audit keamanan rutin, pemindaian kerentanan, dan uji penetrasi.
Contoh nyata keberhasilan bisa kita lihat dari RSNU Tuban dengan inisiatif "Merawat Raga Menjaga Data". Mereka berhasil meningkatkan kecepatan deteksi ancaman dari hitungan hari menjadi menit/detik. Insiden besar yang mengganggu layanan juga berhasil diminimalisir.
Target jangka panjang yang realistis:
- Meraih sertifikasi ISO 27001:2022 untuk manajemen keamanan informasi.
- Mendapatkan Trustmark Bintang 3 dari BPJS Kesehatan.
- Menurunkan jumlah insiden siber yang berdampak pada gangguan layanan publik.
Ini bukan sekadar gengsi. Ini bukti nyata bahwa data pasien benar-benar aman di tanganmu.
Kesalahan Umum yang Sering Terjadi
Dari pengalaman berbagai Fasyankes yang sudah mendaftar, ada beberapa jebakan yang sering terjadi. Coba hindari, ya:
- SK Tim Terbit Terlambat. Deadline 30 September 2025 adalah harga mati. Jangan tunggu mepet. Proses administrasi di internal Fasyankes sering makan waktu berbulan-bulan.
- Dokumen Tidak Lengkap. Banyak yang lupa menyertakan Profil CSIRT atau Form Penilaian IIV. Akibatnya, berkas dikembalikan dan harus mengulang dari awal.
- Uji Komunikasi Gagal. Ini karena saluran komunikasi darurat nggak diuji sebelumnya. Pastikan nomor kontak dan email darurat benar-benar aktif 24 jam.
- Anggota Tim Tidak Kompeten. TTIS butuh orang yang paham keamanan siber, bukan sekadar staf IT biasa. Investasi pelatihan sangat dianjurkan.
- Nggak Ada Tindak Lanjut Pasca-Registrasi. Setelah STR terbit, banyak tim yang "mati suri". Padahal, keamanan siber butuh pemeliharaan terus-menerus.
Belajar dari kesalahan orang lain itu lebih murah daripada belajar dari kesalahan sendiri. Jadi, perhatikan poin-poin di atas.
FAQ (Pertanyaan yang Sering Diajukan)
1. Apa yang terjadi jika Fasyankes tidak membentuk TTIS sampai 30 September 2025?
Sanksinya bertahap. Mulai dari teguran tertulis, pembekuan registrasi, hingga pencabutan izin operasional. Selain itu, Fasyankes juga tidak bisa mendaftar ke batch registrasi 2026, sehingga status legalitas TTIS-nya nunggak.
2. Berapa biaya yang dibutuhkan untuk membentuk dan mendaftarkan TTIS?
Secara regulasi, tidak ada biaya pendaftaran resmi. Tapi tentu ada biaya operasional internal, seperti pelatihan SDM, pengadaan perangkat keamanan, dan konsultasi. Besaran bervariasi tergantung skala Fasyankes.
3. Apakah TTIS boleh diisi oleh tenaga outsourcing atau hanya pegawai tetap?
Idealnya, anggota TTIS adalah pegawai tetap yang kompeten di bidangnya. Namun, untuk tenaga teknis tertentu, bisa melibatkan tenaga ahli outsourcing asalkan diawasi dan dikoordinasi oleh penanggung jawab internal.
4. Bagaimana jika terjadi insiden siber di luar jam kerja?
TTIS wajib menyediakan saluran respons 24/7. Uji Komunikasi dalam proses registrasi bertujuan memastikan hal ini. Setiap anggota tim harus siap dihubungi kapan saja.
5. Apakah sertifikasi ISO 27001 wajib untuk TTIS?
Tidak wajib secara regulasi, tapi sangat direkomendasikan. Sertifikasi ini menjadi pengakuan internasional bahwa tata kelola keamanan informasi Fasyankes sudah sesuai standar. Bisa menjadi nilai tambah dalam kepercayaan publik dan kemitraan.
Penutup: Saatnya Bertindak, Bukan Menunggu
Keamanan data pasien adalah bagian tak terpisahkan dari keselamatan pasien itu sendiri. Di era digital, melindungi data adalah melindungi nyawa.
Deadline sudah di depan mata. 30 September 2025 bukanlah waktu yang lama. Mulai dari sekarang:
- Segera terbitkan SK Tim TTIS.
- Unduh CSIRT Starter Kit dan lengkapi dokumen.
- Hubungi PIC BSSN untuk penjadwalan registrasi batch 2026.
- Integrasikan TTIS dengan pengelolaan Rekam Medis Elektronik (RME).
Jangan biarkan Fasyankesmu menjadi sasaran empuk peretas. Jangan tunggu sampai insiden terjadi baru sadar. Karena saat itu terjadi, penyesalan datang terlambat.
Amankan data pasien. Jaga kepercayaan publik. Bangun ketahanan siber dari sekarang.
TTIS Fasyankes Implementation Strategy: A Compliance Guide for Ministry of Health SEB 2026 Mandate
Ever wondered how secure your medical records really are? Or the patient data stored in your local clinic's server?
Honestly, we often worry about our personal data leaking from e-commerce apps or social media. But health data? That's far more sensitive. Medical records aren't just names and addresses. They contain disease histories, lab results, even psychological conditions. If breached or held for ransom, the impact goes beyond inconvenience—it threatens lives.
The Indonesian government understands this well. That's why, through Joint Circular (SEB) of Ministry of Health No. 18 of 2026, every Healthcare Facility (Fasyankes) is mandated to establish a Cyber Incident Response Team (TTIS). Not as a mere formality, but as a fully operational team ready to face cyber threats.
And here's the kicker: the deadline for TTIS establishment is September 30, 2025. Miss it, and your BSSN registration process gets delayed—along with potential sanctions.
Relax. This article will walk you through everything. From legal foundations, organizational structure, required documents, to the BSSN registration process. No fluff, no headache. Let's dive in.
Why Is TTIS Mandatory for Healthcare Facilities?
Picture this. One day, a hospital's entire electronic medical record system locks down. A message pops up: "Your data has been encrypted. Pay 10 Bitcoin ransom to restore access."
Scary, right? Doctors can't access patient histories, surgery schedules are in chaos, pharmacies can't read prescriptions. All services grind to a halt.
This isn't a horror story. It's a real threat. Especially since Indonesia has 7,347 health service applications across regions. Each one has vulnerabilities that could be exploited.
That's why establishing a TTIS is an imperative mandate. Not an option. Not a suggestion. It's backed by multiple strong regulations:
- Law No. 17 of 2023 (Health): Mandates health data protection in electronic systems.
- Law No. 27 of 2022 (PDP): Requires data controllers to ensure the security of patients' personal data.
- Ministerial Regulation No. 24 of 2022 (Electronic Medical Records): Governs security in EMR migration and management.
- BSSN Regulation No. 1 of 2024: Mandates organized cyber incident handling by organizational response teams.
Bottom line: If your Fasyankes doesn't have a TTIS, you're breaking the law. And the consequences are no joke.
Organizational Structure: Who Does What?
Many get this wrong. They think a TTIS is just one IT person assigned to the role. In reality, a TTIS must have a clear structure, as outlined in Minister of Health Decree No. HK.01.07/MENKES/542/2025. This structure ensures the team can respond quickly and effectively when an incident occurs.
| Division | Primary Duties |
|---|---|
| Monitoring & Action | Threat detection, incident triage, risk analysis, vulnerability handling, and recovery assistance. |
| Public Relations | Public communication, crisis management, media monitoring, and internal cybersecurity awareness. |
| Legal | Regulatory compliance, data management legality, and cyber law adherence. |
| HR Capacity Building | Competency development for technical and functional personnel in facing cyber threats. |
Besides these four divisions, there's one often-overlooked role: the Liaison Officer (Pejabat Penghubung). This person acts as the communication bridge between the Fasyankes, BSSN, and the Ministry of Health. When an incident occurs, they're the first to report.
Key point: All these divisions must be listed in the TTIS Decree (SK). Without an official SK, your team legally doesn't exist. And BSSN registration becomes impossible.
Registration Roadmap: Batch IV - VI 2026
Once the SK is issued, the next step is registering your TTIS with BSSN to obtain a Registration Certificate (STR). This certificate is official proof that your TTIS is recognized by the national authority.
Registration is divided into several batches throughout 2026. Choose the batch that best fits your document readiness.
| Batch | Phases | Date Range |
|---|---|---|
| Batch IV | Registration & Document Validation Document Revision & Comms Test (A) Document Revision & Comms Test (B) STR Issuance |
16 Mar – 10 Apr 13 Apr – 17 Apr 20 Apr – 24 Apr 27 Apr – 1 May |
| Batch V | Application & Scheduling Document Validation & Comms Test Revision & Minutes Approval STR Issuance |
4 May – 8 May 11 May – 15 May 18 May – 22 May 25 May – 29 May |
| Batch VI | Application & Scheduling Document Validation & Comms Test Revision & Minutes Approval STR Issuance |
1 Jun – 5 Jun 8 Jun – 12 Jun 15 Jun – 19 Jun 22 Jun – 26 Jun |
Heads up! The Communication Test and Minutes Approval stages are critical. If you fail here, the entire registration process for that batch is void. You'll have to restart from scratch in the next batch. So, thorough preparation is non-negotiable.
Document Requirements: Don't Leave Anything Out
Documentation is the lifeblood of the registration process. BSSN will assess the completeness and conformity of your documents. Missing or incorrectly formatted files will stall the process.
Here's the mandatory document checklist you need to prepare:
- TTIS Decree (SK) — Following the official template in Ministerial Decree 542/2025. Ensure the organizational structure is correct.
- CSIRT Profile Document — Describes the team's capabilities and the information assets being protected.
- IIV Assessment Form — An instrument to assess incident handling maturity (downloadable from the BSSN portal).
- CSIRT Operational Guidelines (SOP) — Standard procedures for incident handling, from detection to recovery.
Good news: BSSN provides a "CSIRT Starter Kit" containing templates and complete technical guidance. You can download it from the official registration portal. Use the following credentials:
- Password: infoCSIRT123#
Once all documents are complete, send them via the official email: registrasi.ttis@bssn.go.id with a CC to d33.pm@bssn.go.id.
Coordination and Verification: Contact the Right PIC
Registration can't rely solely on email. You also need to coordinate directly with BSSN's Person In Charge (PIC). They'll help validate your documents and schedule the Communication Test.
Here are the key contacts you must note:
- Personnel & Admin PIC: Laila Nur Khofifah — WhatsApp: +62 851-7427-0561
- Institutional PIC: Directorate of KSS Human Development, BSSN
- Official Email: registrasi.ttis@bssn.go.id (CC: d33.pm@bssn.go.id)
The verification process involves a Communication Test to ensure the incident response channel operates 24/7. Once the test is successful, a Minutes of Meeting will be issued, which serves as the basis for STR issuance.
Important: The WhatsApp number serves both administrative and personnel coordination. Use it wisely, okay? No spamming.
Operationalizing Your TTIS: More Than Paperwork
Once the STR is issued, the work isn't over. A TTIS isn't just a team on paper. They must be active in their functions. Think of them like firefighters. You wouldn't have a fire department that never drills or stands ready, right?
TTIS has two main service categories:
- Reactive Services: When an incident happens — digital forensics, threat isolation, system cleansing, and backup restoration.
- Proactive Services: Prevention — regular security audits, vulnerability scanning, and penetration testing.
A real-world success story is RSNU Tuban with their "Caring for the Body, Protecting Data" initiative. They managed to accelerate threat detection from days to minutes/seconds. Major incidents disrupting services were also minimized.
Realistic long-term goals:
- Achieve ISO 27001:2022 certification for information security management.
- Obtain Trustmark Bintang 3 from BPJS Kesehatan.
- Reduce the number of cyber incidents impacting public service delivery.
This isn't just for prestige. It's tangible proof that patient data is truly secure in your hands.
Common Mistakes to Avoid
Based on experience from various Fasyankes that have gone through registration, here are some frequent pitfalls. Try to avoid them:
- Team Decree Issued Too Late. September 30, 2025 is non-negotiable. Don't wait until the last minute. Internal administrative processes can take months.
- Incomplete Documents. Many forget to include the CSIRT Profile or IIV Assessment Form. Result: files are returned, and you start over.
- Communication Test Failure. This happens because emergency contact channels weren't tested beforehand. Ensure contacts and emergency emails are truly 24/7 active.
- Incompetent Team Members. TTIS needs people who understand cybersecurity, not just general IT staff. Invest in training.
- No Post-Registration Follow-up. After the STR is issued, many teams go "dormant." Cybersecurity requires continuous maintenance.
Learning from others' mistakes is cheaper than learning from your own. Pay attention to the points above.
FAQ (Frequently Asked Questions)
1. What happens if a Fasyankes doesn't establish a TTIS by September 30, 2025?
Sanctions are graduated. Starting from written warnings, registration suspension, to operational license revocation. Plus, the Fasyankes won't be able to register for the 2026 batches, leaving their TTIS legal status unresolved.
2. How much does it cost to establish and register a TTIS?
Officially, there are no registration fees. However, there are internal operational costs like staff training, security device procurement, and consulting. The amount varies depending on the Fasyankes's scale.
3. Can TTIS members be outsourced staff, or must they be permanent employees?
Ideally, TTIS members are competent permanent employees. However, for certain technical roles, outsourced experts can be involved as long as they're supervised and coordinated by internal responsible personnel.
4. What if a cyber incident occurs outside working hours?
TTIS must provide a 24/7 response channel. The Communication Test in the registration process ensures this. Every team member must be reachable at any time.
5. Is ISO 27001 certification mandatory for TTIS?
Not mandatory by regulation, but highly recommended. This certification serves as international recognition that the Fasyankes's information security governance meets global standards. It adds value to public trust and partnerships.
Conclusion: Act Now, Don't Wait
Patient data security is an inseparable part of patient safety itself. In the digital era, protecting data means protecting lives.
The deadline is right around the corner. September 30, 2025 isn't that far away. Start now:
- Immediately issue the TTIS Decree.
- Download the CSIRT Starter Kit and complete all documents.
- Contact BSSN PIC for 2026 batch registration scheduling.
- Integrate TTIS with Electronic Medical Record (EMR) management.
Don't let your Fasyankes become an easy target for hackers. Don't wait until an incident strikes before taking action. Because by then, regret will come too late.
Secure patient data. Protect public trust. Build cyber resilience starting today.
Terima kasih sudah mampir! Jika kamu menikmati konten ini dan ingin menunjukkan dukunganmu, bagaimana kalau mentraktirku secangkir kopi? 😊 Ini adalah gestur kecil yang sangat membantu untuk menjaga semangatku agar terus membuat konten-konten keren. Tidak ada paksaan, tapi secangkir kopi darimu pasti akan membuat hariku jadi sedikit lebih cerah. ☕️
Thank you for stopping by! If you enjoy the content and would like to show your support, how about treating me to a cup of coffee? �� It’s a small gesture that helps keep me motivated to continue creating awesome content. No pressure, but your coffee would definitely make my day a little brighter. ☕️ Buy Me Coffee

Post a Comment for "TTIS Fasyankes Implementation Strategy: A Compliance Guide for Ministry of Health SEB 2026 Mandate"
Post a Comment
You are welcome to share your ideas with us in comments!