For the best experience, openVeritaskon desktop.
Legal Updates

Minister of Health Decree No. 951/2026 Tightens Regulations on AI-Based Medical Devices

11 September 2026
Nadia Nurul Ramadhanty, S.H.
Legal Updates
Kepmenkes 951/2026 Perketat Aturan Alat Kesehatan Berbasis AI

Introduction

On 7 September 2026, the Minister of Health of the Republic of Indonesia issued Minister of Health Decree No. HK.01.07/MENKES/951/2026 concerning Guidelines for Marketing Authorization of Software-Based Medical Devices (“Minister of Health Decree No. 951/2026”). These Guidelines serve as a reference for the government, medical device business actors, and other stakeholders in the administration of marketing authorization for software-based medical devices in Indonesia, covering Software as a Medical Device (SaMD), Software in a Medical Device (SiMD), as well as medical devices incorporating artificial intelligence applications.

Minister of Health Decree No. 951/2026 was formulated in response to developments in digital technology and the increasingly widespread use of artificial intelligence in healthcare services. These developments have created a need for more specific regulation of safety, benefits, quality, cybersecurity, interoperability, and the management of data and software updates. Through these Guidelines, the government establishes requirements and licensing mechanisms while strengthening oversight of software-based medical devices to ensure that products placed on the market meet safety, benefit, and quality standards.

Key Provisions

  • Scope of Software-Based Medical Devices

Dictum SECOND of this regulation stipulates that software-based medical devices comprise three principal types:

    1. Software as a Medical Device (SaMD);

    2. Software in a Medical Device (SiMD); and

    3. medical devices incorporating artificial intelligence applications.

These devices are classified as medical devices if they have an independent medical purpose (such as disease detection, diagnosis, and mitigation recommendations) without achieving their primary intended action through pharmacological, immunological, or metabolic processes.

  • Quality Management System and Artificial Intelligence Obligations

Party / Aspect

Obligation

Manufacturer

Must possess business licensing in accordance with the relevant KBLI and comply with Good Manufacturing Practices (Cara Pembuatan yang Baik/CPB) in the production of software-based medical devices.

Distributor 

Must possess business licensing in accordance with the relevant KBLI and comply with Good Distribution Practices (Cara Distribusi yang Baik/CDB) in distributing software-based medical devices.

Quality Management System

Manufacturers and Distributors must implement a quality management system to ensure the safety, benefits, and quality of software-based medical devices. The Guidelines may refer, among others, to:

  • ISO 13485;

  • ISO 14971; 

  • ISO 60601-1;

  • ISO 61010-1;

  • IEC 62366-1;

  • IEC 62304; 

  • IEC 82304;

  • IEC 63450;

  • IEC 63521;

  • ISO 27001.

AI/ML - GMLP

For medical devices with AI/ML features, Manufacturers must apply Good Machine Learning Practice (GMLP) principles throughout the product life cycle to ensure safety, clinical performance, quality, and effectiveness.

Data dan Bias

Manufacturers must ensure the representativeness of clinical data, the independence of training, validation, and testing datasets, and the identification and mitigation of bias, including through performance analysis for specific patient groups.

AI Transparency and Oversight

Manufacturers must provide information concerning the intended use, performance, limitations, data input requirements, and device integration. Model performance must also be continuously monitored, and any updates or retraining must be subject to change control.

Data Security and Privacy

AI/ML products must ensure the security and privacy of patient data, implement data minimization, regulate data retention and deletion based on patient consent, and have mechanisms for reporting data incidents/data breaches and mitigating cybersecurity threats. 

  • Clinical Trials, Regulatory Sandbox, and Local Clinical Validation

Minister of Health Decree No. 951/2026 requires clinical validation for all software-based medical devices. Where clinical evidence concerning accuracy, safety, and performance in the Indonesian population is insufficient, business actors may conduct independent clinical trials or limited testing through a regulatory sandbox. A regulatory sandbox is conducted in a limited and controlled environment to evaluate performance, safety, governance, and regulatory compliance. Digital health innovation products submitted for marketing authorization must achieve TKT 9, meaning that they have been demonstrated to operate successfully in an actual operational environment in accordance with their intended use.

Need deeper analysis?Try Veritask AI Legal Assistant

Specifically for imported software-based medical devices, local clinical validation in Indonesia is required where the product is developed or retrained using data representing the Indonesian population and/or uses medium- to high-risk AI for diagnosis, screening, or clinical decision-making. Validation may be conducted at hospitals, higher education institutions, accredited laboratories, or technical implementation units of the Ministry of Health, and may proceed in parallel with the submission of the marketing authorization application. The results must be submitted no later than 1 year from the issuance of the marketing authorization, while continuing to take into account the safety, benefits, quality, and risk level of the product.

  • Integration with SIKN/SATUSEHAT and Personal Data Protection

Pursuant to Appendix CHAPTER IV letter A numbers 2–4, holders of marketing authorization for software-based medical devices must implement cybersecurity and personal data protection throughout the product life cycle, including in design, development, distribution, maintenance, and updates. Specifically, for software using AI/machine learning, business actors must also ensure the security and privacy of patient data, implement the principle of data minimization, regulate data retention and deletion based on patient consent, manage AI security risks, and have mechanisms for reporting incidents and personal data breaches. Marketing authorization holders are also responsible for the processing, reporting, utilization, and storage of data generated from the use of the software.

In addition, marketing authorization holders must commit to ensuring that examination data outputs can be integrated with the National Health Information System (Sistem Informasi Kesehatan Nasional/SIKN) or SATUSEHAT to support healthcare services, patient referrals, surveillance, research, and policy analysis. Where integration with SIKN is intended, the product must be designed as an open system, support applicable interoperability standards, and be capable of connecting to the national health data exchange platform. This provision places interoperability and data security as part of the requirements for the administration of software-based medical devices, while also supporting continuity of care and the quality of clinical decision-making.

  • Supervision

In accordance with Appendix CHAPTER V, supervision of marketing authorization for software-based medical devices is conducted by the Minister through routine and incidental supervision. Routine supervision includes examination of reports submitted by business actors covering complaint handling, technical monitoring, and post-market clinical performance validation, as well as routine field inspections once every 1 year. Complaint handling includes monitoring of adverse events, complaint trends, and Field Safety Corrective Actions (FSCA), while technical monitoring includes safety, performance, functionality, and cybersecurity vulnerabilities throughout the marketing period. Post-market clinical performance validation is conducted using relevant data, including real-world data, to ensure the safety, effectiveness, accuracy, and clinical performance of the product.

Meanwhile, incidental supervision is conducted through field inspections at specific times in accordance with the provisions of laws and regulations. In both routine and incidental supervision, the monitoring results may serve as the basis for control measures, including safety warnings, corrective actions, and/or product recalls where risks are identified that may affect the safety, effectiveness, or performance of software-based medical devices.

Closing

Minister of Health Decree No. 951/2026 expands the regulatory framework for medical devices by adapting marketing authorization requirements to the characteristics of software-based technologies, including the use of AI/machine learning. The regulation does not stop at compliance with pre-market requirements, but also encompasses clinical validation, cybersecurity, personal data protection, interoperability, change control, and post-market surveillance.

For business actors, these provisions require more comprehensive preparedness in the development and management of products, ranging from the quality and representativeness of data, safety and clinical performance, to monitoring mechanisms and risk management after the product has been placed on the market. Accordingly, Minister of Health Decree No. 951/2026 serves as an important reference for the administration of software-based medical devices that are safe, beneficial, of high quality, and aligned with the digital transformation of healthcare in Indonesia.

Related Regulations

Click a regulation to view details.

Learn More Than Just Articles with VeritaskLearning

Get more practical material through ready-to-use templates, webinar recordings, compliance checklists, and online classes from Veritask Learning.

Templates

A collection of ready-to-use standard legal documents for a range of business needs.

Webinar Recording

Access recordings of in-depth discussions with experienced legal practitioners.

Online Class

Structured classes to master specific legal topics comprehensively.

Compliance

Practical checklists to keep your business compliant with regulations.

Explore Veritask Learning
Share to:

Log in to comment

Log in

What isVeritask

Veritask is an integrated AI-powered legal platform that helps with regulatory research, document preparation, and compliance management in one dashboard.

Free Subscription

Free Subscription

Subscribe to receive a free weekly email with the latest legal analysis.

7-Day Free Trial

Full access to all premium features for 7 days.
Faster legal research and analysis with AI.
No commitment, start right away.