News & Events

  • Share:



Indonesian Private Healthcare Group Secures Its Hospital Information System with Immutable Cross-Region Backup on AWS

Healthcare

One of Indonesia’s largest private healthcare groups was running mission-critical clinical systems with no centralised backup, no cross-region copy and no protection against ransomware deleting its recovery points. PT Metrodata Electronics Tbk rebuilt the foundation.

~1 hr

WORM

2 Regions

0% → centralised

To a recovered, accessible server (4-hour objective)

Immutable backups under Vault Lock compliance mode

Automated cross-region backup copy

Backup coverage across mission-critical workloads

ABOUT THE CUSTOMER

The customer is one of Indonesia’s largest private healthcare groups, operating a network of hospitals across multiple cities and delivering care to millions of patients each year. The organisation runs a Hospital Information System as its mission-critical platform, supporting patient registration, electronic medical records, pharmacy, laboratory, radiology, doctor scheduling and billing alongside its clinical and administrative operations. Because hospital services run 24 hours a day, every day of the year, uninterrupted availability of that platform is directly connected to continuity of patient care.

CUSTOMER CHALLENGE

As the group expanded its hospital network and digital health services, it required a cloud platform capable of carrying mission-critical clinical workloads while maintaining security, governance and operational resilience. Several problems needed solving at once: managing multiple application environments under centralised governance across production, development and shared services; securing communication between interconnected clinical applications without adding operational complexity; and protecting clinical workloads against infrastructure failure, ransomware, accidental deletion and regional outage.

The starting position carried significant risk. There was no centralised backup solution, so backup coverage was effectively zero and what protection existed was manual, inconsistent and error-prone. All data resided in a single region with no cross-region copy, leaving the estate exposed to a regional event. No immutable backup protection existed, which meant a successful ransomware attack or a malicious insider with sufficient privilege could encrypt or delete backup copies along with production data — the failure mode that turns a recoverable incident into an unrecoverable one. Recovery time and recovery point were both undefined and realistically measured in days.

For a healthcare provider these are not solely technical exposures. Interruption to hospital systems affects patient safety, clinical workflow and emergency response. Loss of electronic medical records carries regulatory consequences under healthcare data protection obligations, and demonstrating compliance with backup retention, auditability and business continuity requirements was difficult with manual processes and no centralised reporting.

PARTNER SOLUTION

PT Metrodata Electronics Tbk designed and implemented a secure cloud foundation combining an AWS Landing Zone, centralised networking and multi-region backup protection, delivered in four phases.

The first phase established governance. Metrodata implemented an AWS Landing Zone using AWS Control Tower and AWS Organizations, with a multi-account architecture separating production, development and shared services workloads. This provides security isolation between environments, centralised governance and IAM management, transparent cost attribution, and containment of operational risk within account boundaries as additional hospitals are onboarded.

The second phase built the network. All AWS accounts were interconnected through AWS Transit Gateway, providing secure communication across workloads while keeping network management centralised rather than growing a mesh of peering connections. Traffic inspection was consolidated through a next generation firewall, allowing consistent enforcement of security policy across the whole AWS environment from a single point of control.

The third phase delivered the backup capability. Metrodata implemented AWS Backup to automate enterprise backup operations across the estate, including scheduled backup, lifecycle management, retention policy, centralised monitoring and compliance reporting. Critically, it configured automated cross-region backup copy from the Asia Pacific (Jakarta) Region to the Asia Pacific (Singapore) Region, establishing a recovery point outside Jakarta and therefore outside the reach of a regional event. A dedicated recovery VPC and subnet, security groups, route tables and IAM roles were pre-provisioned in the recovery region, configured to match production, so that a restore lands in a ready environment rather than one that has to be built first.

The fourth phase addressed cyber resilience. Metrodata enabled AWS Backup Vault Lock in compliance mode, making backup copies immutable under a write-once-read-many model. During the configured retention period no party can delete, modify or encrypt those copies — including privileged administrators and including AWS itself. This is the control that specifically defeats the ransomware pattern in which an attacker destroys backups before encrypting production, and it is enforced technically rather than by policy. All backup data is encrypted using AWS Key Management Service.

Metrodata provided support services before and after implementation: architecture design, account structure and network build, backup policy design and deployment, and vault lock configuration during the implementation phase; and ongoing monitoring, managed support, backup compliance reporting and periodic recovery validation afterward, together with training for the customer’s infrastructure team on restore procedures.

RESULTS AND BENEFITS

The recovery capability was validated in two disaster recovery drills on consecutive days — an in-Region restore in Jakarta, and a cross-Region restore working from a recovery point copied to the Singapore Region. In each, the team restored a production Hospital Information System server into the pre-provisioned recovery environment. From declaration, the restore completed and the instance reached a running state within about 50 minutes, administrative login to the recovered server succeeded within about an hour, and full application user access was verified within about two hours. Hostname, network, routing and DNS were confirmed normal and application services verified running. Every checkpoint was recorded as completed, and both drills were signed off by the partner and the customer’s infrastructure team.

A recovered, accessible server within about an hour and full application access within about two hours — proven in both an in-Region and a cross-Region restore — sits well inside the four-hour recovery time objective for mission-critical hospital systems, replacing a starting position in which recovery was undefined and realistically measured in days.

 

Measure

Before

After

Backup coverage

0%, no centralised solution

Centralised across mission-critical workloads

Cross-region protection

None, single region

Automated Jakarta → Singapore copy

Immutable backup

None, backups deletable

AWS Backup Vault Lock, compliance mode WORM

Backup operation

Manual and inconsistent

Automated scheduling, lifecycle and retention

Recovery time, measured

Undefined, days

~1 hr to accessible server; ~2 hr full app (4-hr objective)

Recovery validation

Never tested

Two drills (in-Region + cross-Region), signed off

Governance

Single environment

Multi-account Landing Zone with workload isolation

 

The result is a materially different risk position for the group. Clinical data that previously existed in one region with no immutable copy is now replicated automatically to a second region and held under technical controls that prevent deletion or encryption during the retention period, including by a privileged account. Recovery has moved from an undefined multi-day proposition to a tested procedure with a measured 90-minute result and a signed-off drill record. Backup administration that was manual and inconsistent is now automated and centrally reported, which both removes a class of human error and provides the audit evidence that healthcare compliance obligations require. And the multi-account Landing Zone gives the group a foundation that scales as further hospitals are onboarded without the manual overhead the previous arrangement would have imposed.

ABOUT THE PARTNER

PT Metrodata Electronics Tbk (IDX: MTDL) is one of Indonesia’s leading digital solution providers and an AWS Advanced Tier Services Partner, trusted by more than 200 organisations across healthcare, financial services, manufacturing, retail, mining and the public sector in adopting and implementing cloud solutions. Metrodata currently holds the AWS Migration and Modernization Competency and the AWS Glue Service Delivery designation, demonstrating validated technical expertise in cloud migration, data integration, and business continuity. Delivering through its consulting and system integration subsidiaries PT Mitra Integrasi Informatika and PT Sinergi Transformasi Digital, the company maintains a dedicated practice of certified AWS solutions architects and engineers supporting customers throughout Indonesia.

Back To List
Metrodata logo

PT. Metrodata Electronics, Tbk.

APL Tower 37th Floor 
Jl. Letjen S. Parman Kav. 28
Jakarta 11470

Contact Us:

P: (62-21) 2934 5888
F: (62-21) 2934 5899
E: info.metrodata@metrodata.co.id

social media