Regulation Watch · Tourism and Health · Indonesia. The guidance applies to software as a medical device (SaMD), software in a medical device (SiMD) and software using artificial intelligence when it has a medical purpose, including products made abroad and circulated in Indonesia.
Indonesia Sets Marketing-Authorization Rules for Medical Software
Kepmenkes HK.01.07/MENKES/951/2026 sets immediate marketing-authorization requirements for software medical devices, including AI and LLM products, with local validation for specified imported products and a new authorization for clinically material updates.
- Published
- The Minister of Health established Kepmenkes HK.01.07/MENKES/951/2026 in Jakarta on 7 September 2026. The Ministry's official JDIH lists the decision as active and supplies the signed 39-page text, but records no separate promulgation, State Gazette, State Bulletin or online-publication date.
- Effective
- 7 September 2026. The fourth operative clause states that the decision took effect on the date it was established, with no general transition or grace period.
- Added to Watch
- 8 October 2026
Who is affected
Domestic and foreign software and medical-device manufacturers; PT PMA and PT PMDN product owners, importers and distributors; foreign shareholders and directors; health-tech, AI, machine-learning and LLM developers; hospitals, clinics, laboratories and other healthcare providers using regulated software; and their regulatory, clinical, quality, cybersecurity, data-protection and post-market teams.
Practical impact
Software with an intended medical purpose is now subject to a detailed Indonesian authorization dossier covering classification, quality management, technology readiness, verification, clinical evidence, labeling, cybersecurity, data governance and post-market surveillance. Producers and distributors need the relevant KBLI licences and good-manufacturing or good-distribution compliance. Specified imported products require Indonesian local clinical validation, and clinically material changes to an authorized product require a new marketing authorization rather than a simple data amendment. The decision expressly addresses continuous-learning models, generative AI and LLM hallucination controls.
The Minister of Health established Kepmenkes HK.01.07/MENKES/951/2026 on 7 September 2026 and made it effective that day. The decision adopts detailed marketing-authorization guidance for software as a medical device, software embedded in a medical device and artificial-intelligence software used for a medical purpose. Administrative, storage or operational software that does not affect a medical-device function remains outside the definition.
The authorization file must show that the product is ready for real-world operation at technology-readiness level 9 and is supported by a lifecycle quality-management system. The guidance calls for risk management, software verification and validation, clinical evidence, version traceability, interoperability, cybersecurity, labeling and clear instructions. Producers must hold the relevant KBLI licences and meet good-manufacturing requirements, while distributors and branches need the relevant licences and good-distribution compliance.
Artificial-intelligence products carry additional evidence duties. The applicant must explain input data, dataset sources and composition, annotation and curation, dataset separation, bias risks, model architecture, limitations and clinical performance. Continuous-learning systems need controlled update cycles, anomaly detection, rollback, real-world data governance, version traceability and continuing validation. A generative-AI or LLM dossier must also address hallucinations, use limitations and testing of the consistency and accuracy of medical information.
Specified imported software requires local clinical validation in Indonesia. The criteria cover products developed further or retrained with data representing the Indonesian population and medium- to high-risk AI used for diagnosis, screening or clinical decisions. Validation may run in parallel with the authorization application using the manufacturer's clinical and performance evidence, but the local result must be delivered no later than one year after authorization. A significant mismatch with the original evidence may lead to administrative action.
Software-change control is now explicit. An update affecting the indication, main function or clinical performance—including diagnostic or therapeutic algorithms, clinically relevant integrations or alarms, accuracy or sensitivity, or an operating platform that may affect safety or performance—requires a new marketing authorization. Minor interface, formatting, reporting or other nonclinical changes use an authorization amendment. An uncategorized change must be reported to the Minister with supporting data, and every change must remain documented in the quality system.
Authorization holders must continue surveillance after launch. Required records include complaints, adverse events, field safety corrective actions, technical monitoring, cyber vulnerabilities and post-market clinical-performance validation using relevant real-world data. Personal and health data must be protected across storage and transfer. A product intended to integrate with the national health-information ecosystem or SATUSEHAT must use an open design, support applicable interoperability standards and connect with the national health-data exchange platform.
Late discovery: the decision was effective from 7 September but was not previously recorded in the Regulation Watch ledger. The official Ministry of Health JDIH record and signed text were identified and verified during this cycle. Businesses with products already in development, authorization review or distribution should assess the live dossier and release process now because the instrument provides no general grace period.
Required action
- Classify each software product by intended use: determine whether it is standalone SaMD, embedded SiMD or non-medical software, and document the rationale before launch or authorization renewal.
- Confirm that the Indonesian producer, product owner, importer and distributor hold the correct KBLI-based business licences and meet the applicable good-manufacturing or good-distribution requirements, with responsibilities fixed in written agreements with any foreign developer.
- Build or update the authorization dossier with software version and traceability records, risk management, verification and validation, clinical evidence, labeling and user instructions, cybersecurity controls, interoperability, vulnerability handling and a lifecycle quality-management system. Products submitted for authorization must have reached technology-readiness level 9.
- For AI or machine-learning products, document dataset sources and representativeness, independent training, validation and test sets, bias analysis, model design, clinically meaningful performance targets, human interaction, version control and post-market monitoring. For continuous-learning models, include anomaly detection, rollback, real-world data controls and continuous validation; for generative AI or LLMs, add hallucination mitigation and medical-output consistency and accuracy testing.
- Assess imported software for Indonesian local clinical validation. Products retrained on Indonesian population data or using medium- to high-risk AI for diagnosis, screening or clinical decisions fall within the stated criteria; the validation result may be filed in parallel but must be submitted no later than one year after the marketing authorization is issued.
- Introduce release governance for every update. A change affecting indications, core functions, clinical performance, diagnostic or therapeutic algorithms, clinically relevant integrations or alarms, safety or performance parameters, or the operating platform requires a new marketing authorization; minor nonclinical changes require an authorization amendment, and uncategorized changes must be reported to the Minister for evaluation.
- Maintain complaint, adverse-event, technical-monitoring, cybersecurity-vulnerability, field-corrective-action and post-market clinical-validation records, and ensure any planned SATUSEHAT or national-health-system integration uses an open system and supported interoperability standards.
