Back to Columns
Healthcare Security13 min read

Selecting a Cloud Provider: Seven Things a Hospital Must Check

September 14, 2026

Selecting a Cloud Provider: Seven Things a Hospital Must Check
Share this article

Every proposal for a cloud EMR or departmental system says "compliant with the three-ministry guidelines." What that line means varies enormously between vendors. Sometimes it means everything the guidelines require of a provider has been implemented. Sometimes it means the provider has counted items the hospital is supposed to perform and written "we can support this."

The difficulty with cloud is that the range a hospital can verify for itself narrows sharply. With an on-premises server you can walk to the rack, open the configuration screen, pull the logs yourself. In the cloud, nearly all of that moves into territory where you depend on what the provider tells you. Which makes what you require them to explain the heart of selection.

This article sets out seven things to check when choosing the cloud provider that will hold your medical information. For the broader question of cloud use and internal arrangements, see Cloud Security for Healthcare Organisations; for the regulatory side of offsite storage, Requirements for External Storage of Medical Information.

Disclaimer: This article is general information. The authoritative texts are the MHLW guidelines and the METI/MIC provider guidelines. Consult counsel on contract terms.

The Seven Criteria at a Glance

#CriterionWhat to verifyRisk if you cannot
1Guideline alignmentWhich ministry's guideline, which requirement, performed by whom"Compliant" cannot be checked
2Data residencyCountry/region for production, backups and logs separatelyOffshore storage surfaces and cannot be moved
3CertificationName, number, certified scope, expiryCertified — but your service is out of scope
4Subcontracting transparencyPlatform, monitoring, development, supportAn unseen third tier touches production
5Segregation and encryptionTenant separation method, encryption at rest and in transitA multi-tenant incident propagates
6Availability and recoverySLA, RTO/RPO, backup method, restore testingYou cannot meet the fee criteria
7Exit and data returnFormat, deadline, cost, proof of deletionEffective lock-in

Of these, items 2, 3, 4 and 7 cannot be changed after signing. Residency is baked into the architecture, certification scope is the provider's own business decision, the subcontracting chain is their business model, and return terms cannot be added later if they are not in the contract. Put the weight of your selection on those four.

Verifying Guideline Alignment

Bound partyMinistryGuideline
HospitalsMHLWGuidelines for the Safe Management of Medical Information Systems (6.0, May 2023)
ProvidersMETI / MICGuidelines for safe management by providers of systems and services handling medical information

A cloud provider is directly bound by the latter. The MHLW guidelines come in four volumes — overview, governance, planning, and operations — addressed respectively to decision-makers, managers and operators. Where cloud is used, parts of the planning and operations requirements end up performed by the provider.

In practice the effective step is to require a mapping table giving the performing party for each requirement. A one-line "we comply" cannot be checked; a table forces blanks and "performed by the hospital" entries into view, and doubles as the blueprint for your own arrangements. See The Three-Ministry Guidelines and Implementation Steps.

MHLW published a Q&A on edition 6.0 in May 2025, and on 14 May 2025 a cybersecurity checklist and manual for healthcare organisations covering cloud, BCP, IoT and BYOD — a useful base for building your provider questions.

Ask About Residency in Three Parts

Plenty of providers will answer yes to "is the data stored in Japan?" The question is insufficient, because production data, backups and logs can live in different places.

SubjectHow to askCommon reality
ProductionState the region where data is storedUsually a domestic region
BackupsState the region where backups are storedOften a second region for redundancy; sometimes offshore
Logs and audit trailsState where logs are held and for how longFrequently forwarded to a monitoring SaaS, sometimes offshore
Operator locationState the countries where staff operating production are located24/7 monitoring is often run from an overseas site
Temporary copiesIs data copied elsewhere during fault investigation?Copying to a development environment is often unprocedured

The fourth row is a separate question from physical residency. Data in a domestic region that is administered by people abroad is, in effect, accessible across the border. Do not stop at "the data is in Japan" — ask who touches it.

The fifth is also missed. Copying production data to a development environment or a support engineer's machine during fault investigation is common. Agree before signing whether it is prohibited or governed by a procedure — request, approval, time limit, deletion afterwards.

Reading Certifications: Not Whether, But How Far

CertificationSubjectWhat it means to a hospital
ISO/IEC 27001 (ISMS)Information security management generallyThe most broadly applicable evidence; scope must be checked
ISO/IEC 27017Cloud-specific controlsAdditional evidence for a provider holding medical data in cloud
ISO/IEC 27018Personal data in public cloudControls on handling personal data
Privacy MarkPersonal information (domestic scheme)Well recognised in Japan; limited to personal data
SOC 2Service organisation controlsA report, not a certification — you must read the report itself

What matters is not possession but three things:

  1. Certified scope — which sites and services; is the service you are buying inside it?
  2. Validity — not lapsed or suspended; the accreditation body's register can be checked by certificate number
  3. Platform versus provider — "AWS/Azure holds the certification" and "the provider building on it holds one" are different facts

The third comes up constantly. Proposals do present a platform's certification as if it were the provider's own. A physically hardened platform says nothing about the permission model or logging design of the application above it — those are the provider's responsibility. Separate which side of the shared responsibility model is being discussed. See Security Design and the Shared Responsibility Model for AI EMRs.

Japan's ISMS accreditation body is ISMS-AC. On how certification and scope work, see What Is an ISMS? and Defining ISMS Scope.

Transparency of Subcontracting

Cloud services are structurally layered. Behind the provider you contract with sit the platform, monitoring services, a CDN, mail delivery, outsourced development. Sign without seeing that chain and, when something goes wrong, you cannot even locate where it went wrong.

TypeWhat to verify
PlatformProvider, region, services used
Monitoring and operationsWhether outsourced, to whom, with what access
Development and maintenanceCountry of the development site; any offshoring
Support deskWhether outsourced; whether it can reach patient data
Change notificationWhether you are told before a subcontractor changes

The last row is the practical one. Verifying the chain at signature is not enough — it changes during the term. Whether a prior-notice clause exists determines whether your picture stays current. See Supply Chain Risk for Hospitals.

Data Return on Exit

The most neglected criterion at selection, and the most regretted later. Cloud migration costs are high, and without return terms in the contract you lose all leverage at the next replacement.

ItemWhat the contract should say
FormatCSV, a standard format (e.g. SS-MIX2), or a database dump — avoid proprietary-only
CoverageClinical data only, or also attachments, images and audit logs
DeadlineHow many days after termination delivery occurs
CostWhether the work is chargeable, and how it is calculated
Migration cooperationWhether they will brief the successor vendor and disclose data specifications
DeletionWhen deletion completes including backups, and issuance of a certificate

Format is the crux. If data can only leave in a proprietary shape, migration acquires a conversion project, with the cost and schedule that implies. Make "must be exportable in a standard format" a requirement at purchase. See Security Requirements for EMR Replacement and The EMR Data Migration Guide.

Backup deletion is again the item that slips. Deleting production leaves generations in backup. Confirm whether "deletion complete" includes them, and by when.

Availability, Recovery, and the Fee Criteria

Level 1 of the FY2026 electronic clinical information coordination system development addition requires backups by multiple methods with part held offline, plus a BCP for cyberattacks with exercises. On a cloud system, whether you can satisfy this depends on how the provider delivers the service.

Official Q&A indicates that a cloud-internal approach — backup to a logically separated area within the cloud service, where prompt recovery is possible — also satisfies the criterion. So cloud is not disqualifying. But you must confirm whether the architecture genuinely constitutes a "logically separated area." A copy into another bucket inside the same account is lost with the account.

Check specifically:

  • Whether backups sit behind a different permission boundary from production
  • The number of generations retained (at least three is indicated for daily backups)
  • Whether restore tests have actually been performed, and how often
  • Measured — not estimated — recovery time

See Backup Design for Hospitals: the 3-2-1 Rule, A BCP for Cyberattacks, and The FY2026 Fee Revision.

Conclusion

  1. Weight selection towards the four things you cannot change after signing: residency, certified scope, subcontracting, exit terms
  2. Verify guideline alignment through a mapping table of who performs each requirement, not a declaration
  3. Ask about residency separately for production, backups and logs — and about where operators are
  4. For certifications, read scope, validity, and platform-versus-provider
  5. Subcontractors change during the term; require prior notice
  6. Put format, coverage, deadline, cost, cooperation and deletion into the contract; refuse proprietary-only export
  7. To meet the fee criteria, confirm backups sit behind a different permission boundary

Comparing cloud providers from proposals alone rarely reveals differences; differences appear once you build the questions and line up the answers. For a review of existing cloud contracts or requirements ahead of a replacement, contact us. If you are on the provider side and being asked to evidence your posture, see ISMS certification support.

References and Sources

Note: guideline requirements and fee criteria change with revisions and official Q&A. Check the latest published material.

Share this article

Related Articles

Healthcare Security

Access Control and Privileged ID Management: What Is Realistic in a Hospital

Role-based permissions, least privilege, offboarding and transfer reviews, vendor maintenance accounts, and what to do where shared IDs genuinely cannot be eliminated. Access design that actually limits blast radius within the constraints of clinical work.

September 14, 2026
Healthcare Security

Antivirus and EDR: What a Hospital Should Decide Before Buying

How EDR differs from conventional antivirus, why it is not a product that protects you simply by being installed, how to choose an operating model for the alerts it produces, what to do about devices it cannot be installed on, and what to settle before you buy.

September 14, 2026
Healthcare Security

Logging and Audit Trails: Getting Past 'We Collect It but Nobody Looks'

What to log, how long to retain it, and the real problem — logs collected but never read. Which logs actually matter during an incident, and how to make review a sustainable routine in a hospital with limited staff.

September 14, 2026
Healthcare Security

Backup Design for Hospitals: The 3-2-1 Rule and the Tier 1 Requirement

Japan's FY2026 revision makes multi-method backup with part of it held offline a tier 1 requirement. We cover the three methods accepted as meeting it — external media, automated transfer to a permanently detached NAS, and a logically separated area within a cloud service — plus generation management and why an untested backup does not count.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.