Most hospitals already hold a disaster BCP: assembly criteria, stockpiles, emergency power, written around earthquakes, flooding, and outages. Apply that plan to a cyberattack, though, and several of its premises fail.
The biggest difference is that the time to recovery cannot be estimated. After an earthquake, surveying the damage gives you a rough horizon. After a cyberattack, you must identify the intrusion path, find an uncompromised backup, and restore in stages while verifying safety — and on day one you cannot say how long that takes. Meanwhile, care continues on paper.
The second difference is that help does not shorten it much. In a disaster, people and supplies accelerate recovery. With a cyberattack, bringing in specialists does not change the fact that investigation and verification set the pace.
Japan's FY2026 fee revision made developing and drilling a cyberattack BCP a tier-1 requirement of the new coordinated electronic clinical information add-on. The cyber BCP is now a document the system expects you to hold.
Disclaimer: This article is general information. Reimbursement requirements and guideline obligations are governed by MHLW notices and Q&A and by the Guidelines for the Safe Management of Medical Information Systems.
How It Differs from Disaster Planning
Building on the existing BCP is sensible, but unless the differences are stated explicitly the result is unusable.
| Aspect | Disaster BCP | Cyber BCP |
|---|---|---|
| Assessing damage | Visible; an early horizon | Scope takes time to establish; no horizon on day one |
| Recovery time | Broadly estimable | Unknown — days to months |
| Buildings and staff | Affected | Intact. You have people; you just have no systems |
| Outside help | People and supplies move it forward | Investigation is the bottleneck; more hands help little |
| Backups | Safe if held remotely | Encrypted with everything else if on the same network |
| Communication | Telecoms damage | Internal systems unusable; the call tree may be lost too |
| Deciding to resume | Restore once safety is confirmed | Nothing restores until the cause is closed |
| Legal workstream | Limited | Breach reporting, disclosure, and police liaison run in parallel |
"People but no systems" is the condition disaster plans do not model. Staff arrive, the building and power are fine, and the EHR will not open. How to run care in that state is the heart of a cyber BCP.
See Reporting a Personal Data Breach and First Response to Ransomware.
Prioritising Clinical Functions
The body of the BCP is the ordered list of what cannot stop. Because a cyberattack halts everything at once, without a pre-agreed order departmental demands collide.
| Function | Patient impact if stopped | Fallback | Priority reasoning |
|---|---|---|---|
| Emergency intake | Life-critical | Diversion to neighbours (loads the whole region) | Highest. Pre-agree intake criteria |
| Surgery and obstetrics | Life-critical | Elective can defer; emergency cannot | Secure a means to continue emergencies |
| Dialysis | Life-critical within days | Referral, paper orders | Assume continuation; design paper flow |
| Inpatient care | Medium–high | Paper order books and prescriptions | Stockpiled forms essential |
| Booked outpatients | Medium | Reduce, defer | Decide to scale down early |
| Labs and imaging | Medium | External referral, handwritten requests | Alternative request and result paths |
| Pharmacy | High | Paper prescriptions | Design the checking process too |
| Billing and claims | Low at first | Settle later | Bites later — delayed claims hit cash flow |
Billing looks unimportant on day one and becomes critical at week three. Include how claims are handled during an extended outage.
Setting RTO and RPO in Numbers
| Metric | Meaning | The question in a hospital |
|---|---|---|
| RTO (recovery time objective) | How quickly operations resume | "How many days without the EHR can we tolerate?" |
| RPO (recovery point objective) | How much data loss is acceptable | "How many hours of records can we lose and still treat safely?" |
RPO is fixed by backup frequency: daily backups mean accepting the loss of a day of clinical records in the worst case. If that is unacceptable, shorten the interval or decide in advance how paper records will fill the gap. RTO turns on whether recovery procedures are documented and tested — a procedure that lives in one person's head collapses the moment they are away.
The FY2026 tier-1 backup requirement reads naturally in this light.
| Tier-1 backup requirement | Methods stated to satisfy it |
|---|---|
| Backups by multiple methods, with some held offline | ① Removable media (e.g. RDX), with generation management<br>② Automated transfer to NAS or similar, kept disconnected from the network at all times<br>③ Within a cloud service, to a logically separated area, where prompt recovery is possible |
For daily backups, retaining at least three generations is indicated; weekly and monthly retention is not stated uniformly because it depends on hospital size and method. See Backup Design: the 3-2-1 Rule.
Designing the Paper Fallback
Paper is where unpreparedness shows. "We'll use paper if it comes to that" usually means no forms exist, nobody knows how to complete them, and there is no plan for getting the records back into the system.
- Pre-printed forms — prescriptions, orders, test requests, nursing records, consent, admission and discharge. Physical stock, not PDFs: with no network you cannot print
- Reference information — inpatient lists, allergies and contraindications, the day's surgical and test schedule. Decide what is exported regularly and held offline
- Completion rules — how patients are identified when IDs cannot be looked up, who recorded what, and times
- Physical handling — paper moves around the hospital. Handover records and departmental files prevent loss and mix-ups
- Getting back to electronic — who re-enters what, when, and in what order; whether scanning suffices or keying is required
Aim to be able to answer "how many days can we run on paper?" with a number. Stock levels, storage space, and the staff hours needed afterwards give you the ceiling.
Holding reference data offline creates its own leak risk — decide storage and disposal. See Endpoint Management and Managing Removable Media.
Drill, Then Revise the Plan
The tier-1 requirement covers drills, not just the document. Beyond compliance, an undrilled plan does not work.
| Stage | Format | Duration | What it tests |
|---|---|---|---|
| 1 | Read-through | ~1 hour | Are roles and contacts current? Is the vocabulary shared? |
| 2 | Tabletop scenario | Half a day | Decision order, authority, information flow |
| 3 | Partial live degraded operation | Half to full day | Can people actually complete the paper forms, and how long does it take? |
| 4 | Restoration test | Scheduled | Can you actually restore from backup, and how long does it take? |
Do not skip stage 4. Taking backups and being able to restore from them are different claims. Restoration is often automated in the taking and never once tested in the restoring. The measured result becomes the evidence for your RTO.
See Designing Staff Training and Drills, Incident Response Planning, and Key Points of the FY2026 Fee Revision.
Conclusion
- The decisive differences are the unknowable recovery horizon and the "people but no systems" state
- Rank clinical functions; billing is low priority on day one and critical in a long outage
- Set RTO and RPO numerically. RPO follows backup frequency; RTO follows documented, tested procedures
- Tier 1 requires backups by multiple methods with some offline — removable media, disconnected automated transfer, or a logically separated cloud area
- Design the paper fallback down to physical stock and the route back to electronic
- Escalate drills in stages and always include a restoration test
A cyber BCP is your existing disaster plan plus the premises that are specific to attacks. Prioritisation and restoration testing are hard to finish without system-side understanding. Pottech advises from that standpoint — contact us. For assessing a supplier's continuity posture, see What Is an ISMS (ISO/IEC 27001)?.
References and Sources
- FY2026 Medical Fee Revision | MHLW
- Guidelines for the Safe Management of Medical Information Systems | MHLW
- Information-technology Promotion Agency (IPA)
- National center of Incident readiness and Strategy for Cybersecurity (NISC)
Note: reimbursement requirements are given concrete form by notices and Q&A and are subject to change. Confirm the current text with MHLW publications.