Back to Columns
Healthcare Security13 min read

Key Points of the MHLW Guidelines for the Safe Management of Medical Information Systems, Edition 6.0

September 14, 2026

Key Points of the MHLW Guidelines for the Safe Management of Medical Information Systems, Edition 6.0
Share this article

Japan's FY2026 medical fee revision changed the standing of security work in healthcare institutions. The newly created electronic clinical information coordination add-on requires compliance with the MHLW's "Guidelines for the Safe Management of Medical Information Systems" and the appointment of a dedicated medical information system security manager.

Until now, security sat in the category of "worth doing, but it does not show up in revenue." That is precisely why it never rose up the internal priority list. From FY2026 this no longer holds: without compliance, you cannot claim the add-on. It is no longer a question of cost but of whether you can bill.

Which brings institutions back to the MHLW guidelines, Edition 6.0. The document runs to several hundred pages and is not something to read front to back. This article sets out who the document is written for and what it contains, so you can find your own entry point. Each part is covered in its own article.

Disclaimer: This article is general information. The authoritative sources for interpreting the guidelines and for fee-schedule requirements are the MHLW's published text, notices, and Q&A. Base filing decisions on those and on confirmation from your Regional Bureau of Health and Welfare.

Compliance Became a Billing Requirement in FY2026

The FY2026 revision abolished the medical information acquisition add-on and the healthcare DX promotion structure add-on, merging and reorganising them into the new electronic clinical information coordination add-on. At the same time, the cybersecurity requirements previously attached to medical records management structure add-on 1 were transferred into this new add-on.

In other words, the evaluation of healthcare DX (online eligibility verification, electronic prescriptions, the electronic health record information sharing service) and the evaluation of cybersecurity were consolidated into a single add-on. The outpatient tiers and facility standards are covered in FY2026 Fee Revision: Cross-Specialty Changes.

For the inpatient tiers, the security requirements are arranged as follows.

TierPointsRequirements
Tier 1160Common requirements plus tier-1-only requirements
Tier 280Common requirements

Common requirements (both tiers)

  • Compliance with the Guidelines for the Safe Management of Medical Information Systems
  • Appointment of a dedicated medical information system security manager

Tier 1 only

  • Backups by multiple methods, with some held offline
  • A BCP for cyberattacks, plus drills

Two things follow. First, the guidelines are now named as the reference standard. Second, what is required is structure (a person in post) and operations (backups, BCP, drills) — not something a purchase order can satisfy. Appointment of the manager is covered in The Medical Information Security Manager: Role and Appointment.

Specific figures circulate in secondary sources for EDR mandates, vulnerability-assessment and staff-training frequencies, and transitional deadlines. This article states only what could be confirmed against primary sources; treat those other figures as requiring verification against the primary text.

What Edition 6.0 Is

The formal title is the Guidelines for the Safe Management of Medical Information Systems (MHLW). The current version is Edition 6.0, revised in May 2023.

The common shorthand "three ministries, two guidelines" refers to this MHLW document together with the guidelines issued jointly by METI and the MIC for providers of information systems and services that handle medical information. Reading them as a division of labour helps.

MinistryDocumentAddressed to
MHLWGuidelines for the Safe Management of Medical Information SystemsHealthcare institutions (hospitals, clinics, pharmacies)
METI / MICGuidelines for providers of systems and services handling medical informationVendors and cloud providers

You read the MHLW side; you hold your vendors to the METI/MIC side. For the overall picture, start with The Three Ministries' Two Guidelines Explained.

The defining feature of Edition 6.0 is that it was split into four parts by reader. Up to Edition 5.2, board-level decisions and technical specifications sat in a single document; Edition 6.0 separates them by role.

PartIntended readerContent
OverviewAnyone wanting the whole picturePurpose, structure, terminology, relationship to other regimes
GovernanceDecision-makers and executivesExecutive responsibility, policy, resourcing, responsibility when outsourcing
Planning and managementSystem administratorsRisk assessment, procedures, supplier management, training
System operationsOperatorsAccess control, logging, backups, equipment, incident response

The split does not mean you may ignore the parts addressed to others. It means responsibility has been located by role. The governance part in particular rules out the position that "the systems are the administrator's and the vendor's problem."

Scope Does Not Depend on Size

Edition 6.0 applies to "all those involved in the introduction, operation, use, maintenance, and disposal of medical information systems."

This is widely misread. Hospitals, clinics, dental practices, and pharmacies are all in scope, regardless of size. "We are a ten-person clinic, so this is for large hospitals" does not hold. If you run an EMR, submit claims electronically, and operate online eligibility verification, you are in scope.

Being in scope is not the same as building a large hospital's apparatus, however. The guidelines call for treatment proportionate to risk, and risk varies with size and data volume. Where a small practice should realistically begin is covered in Guideline Compliance for Small Clinics: How Far to Go.

The second principle to internalise is that outsourcing does not transfer responsibility. Even where an EMR vendor or cloud provider runs the systems, accountability for patient data stays with the institution. Your vendor's compliance with the three-ministry guidelines is a precondition, not an indemnity. This is the central theme of The Governance Part: What Executives Are Accountable For.

Two Documents Published in May 2025

Because the text alone often left practitioners unsure, two supporting documents appeared in 2025.

1. Q&A on Edition 6.0 (May 2025)

The MHLW published a Q&A on Edition 6.0, giving practical readings of the more abstract requirements. When you are unsure whether what you have done is enough, checking the Q&A for a comparable question is the fastest route.

2. Cybersecurity checklist and manual for healthcare institutions (14 May 2025)

Also from the MHLW, a checklist with an accompanying manual. It is more concrete and practical than earlier material, and adds treatment of cloud environments, BCP, IoT devices, and BYOD.

The two serve different purposes. The guidelines say what must be satisfied; the checklist tells you where you currently stand. In practice the workable order is assess your position with the checklist, then read the relevant part of the guidelines for whatever is missing.

Where to Start Reading

Your roleRead firstThen
Director, board member, administratorOverview → GovernancePlanning and management (to know what to ask of your staff)
IT / medical informatics staffOverview → Planning and managementSystem operations
Operators and vendor liaisonsSystem operationsPlanning and management (the basis for your tasks)
Billing and health information managersOverviewSystem operations (logging and access control)

Each part is covered here in its own article.

If you use cloud services, see Cloud Security for Healthcare Institutions. For designing controls in at procurement or replacement, see Security by Design for Medical Systems. For the step-by-step compliance route, see Practical Steps for Three-Ministry Guideline Compliance.

To understand the standard your suppliers are held to, the certification regime on the vendor side is covered in What Is an ISMS (ISO/IEC 27001)?.

Conclusion

  1. FY2026 made guideline compliance and a dedicated security manager conditions of an add-on. Security moved from optional good practice to a billing requirement
  2. In the inpatient tiers, tier 1 (160 points) adds multi-method backups with an offline copy, plus a cyber BCP and drills
  3. Edition 6.0 has four parts — overview, governance, planning and management, system operations — split by role
  4. Scope covers "all those involved in medical information systems," regardless of size or type; the depth of treatment scales with risk
  5. Outsourcing does not transfer the institution's responsibility. Vendor compliance is a precondition, not a defence
  6. A workable starting order is assess with the May 2025 checklist, then read the relevant part for the gaps

If building this internally is difficult, or you want help working out where to start ahead of filing for the add-on, get in touch. Where the vendor side needs to evidence its own security posture, we also offer ISMS certification support.

References and Sources

Note: the guidelines are revised and fee-schedule requirements are clarified through official Q&A. This article reflects material published at the time of writing. Base filing and billing decisions on the current notices and on confirmation from your Regional Bureau of Health and Welfare.

Share this article

Related Articles

Healthcare Security

Access Control and Privileged ID Management: What Is Realistic in a Hospital

Role-based permissions, least privilege, offboarding and transfer reviews, vendor maintenance accounts, and what to do where shared IDs genuinely cannot be eliminated. Access design that actually limits blast radius within the constraints of clinical work.

September 14, 2026
Healthcare Security

Antivirus and EDR: What a Hospital Should Decide Before Buying

How EDR differs from conventional antivirus, why it is not a product that protects you simply by being installed, how to choose an operating model for the alerts it produces, what to do about devices it cannot be installed on, and what to settle before you buy.

September 14, 2026
Healthcare Security

Logging and Audit Trails: Getting Past 'We Collect It but Nobody Looks'

What to log, how long to retain it, and the real problem — logs collected but never read. Which logs actually matter during an incident, and how to make review a sustainable routine in a hospital with limited staff.

September 14, 2026
Healthcare Security

Backup Design for Hospitals: The 3-2-1 Rule and the Tier 1 Requirement

Japan's FY2026 revision makes multi-method backup with part of it held offline a tier 1 requirement. We cover the three methods accepted as meeting it — external media, automated transfer to a permanently detached NAS, and a logically separated area within a cloud service — plus generation management and why an untested backup does not count.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.