Japan's FY2026 medical fee revision changed the standing of security work in healthcare institutions. The newly created electronic clinical information coordination add-on requires compliance with the MHLW's "Guidelines for the Safe Management of Medical Information Systems" and the appointment of a dedicated medical information system security manager.
Until now, security sat in the category of "worth doing, but it does not show up in revenue." That is precisely why it never rose up the internal priority list. From FY2026 this no longer holds: without compliance, you cannot claim the add-on. It is no longer a question of cost but of whether you can bill.
Which brings institutions back to the MHLW guidelines, Edition 6.0. The document runs to several hundred pages and is not something to read front to back. This article sets out who the document is written for and what it contains, so you can find your own entry point. Each part is covered in its own article.
Disclaimer: This article is general information. The authoritative sources for interpreting the guidelines and for fee-schedule requirements are the MHLW's published text, notices, and Q&A. Base filing decisions on those and on confirmation from your Regional Bureau of Health and Welfare.
Compliance Became a Billing Requirement in FY2026
The FY2026 revision abolished the medical information acquisition add-on and the healthcare DX promotion structure add-on, merging and reorganising them into the new electronic clinical information coordination add-on. At the same time, the cybersecurity requirements previously attached to medical records management structure add-on 1 were transferred into this new add-on.
In other words, the evaluation of healthcare DX (online eligibility verification, electronic prescriptions, the electronic health record information sharing service) and the evaluation of cybersecurity were consolidated into a single add-on. The outpatient tiers and facility standards are covered in FY2026 Fee Revision: Cross-Specialty Changes.
For the inpatient tiers, the security requirements are arranged as follows.
| Tier | Points | Requirements |
|---|---|---|
| Tier 1 | 160 | Common requirements plus tier-1-only requirements |
| Tier 2 | 80 | Common requirements |
Common requirements (both tiers)
- Compliance with the Guidelines for the Safe Management of Medical Information Systems
- Appointment of a dedicated medical information system security manager
Tier 1 only
- Backups by multiple methods, with some held offline
- A BCP for cyberattacks, plus drills
Two things follow. First, the guidelines are now named as the reference standard. Second, what is required is structure (a person in post) and operations (backups, BCP, drills) — not something a purchase order can satisfy. Appointment of the manager is covered in The Medical Information Security Manager: Role and Appointment.
Specific figures circulate in secondary sources for EDR mandates, vulnerability-assessment and staff-training frequencies, and transitional deadlines. This article states only what could be confirmed against primary sources; treat those other figures as requiring verification against the primary text.
What Edition 6.0 Is
The formal title is the Guidelines for the Safe Management of Medical Information Systems (MHLW). The current version is Edition 6.0, revised in May 2023.
The common shorthand "three ministries, two guidelines" refers to this MHLW document together with the guidelines issued jointly by METI and the MIC for providers of information systems and services that handle medical information. Reading them as a division of labour helps.
| Ministry | Document | Addressed to |
|---|---|---|
| MHLW | Guidelines for the Safe Management of Medical Information Systems | Healthcare institutions (hospitals, clinics, pharmacies) |
| METI / MIC | Guidelines for providers of systems and services handling medical information | Vendors and cloud providers |
You read the MHLW side; you hold your vendors to the METI/MIC side. For the overall picture, start with The Three Ministries' Two Guidelines Explained.
The defining feature of Edition 6.0 is that it was split into four parts by reader. Up to Edition 5.2, board-level decisions and technical specifications sat in a single document; Edition 6.0 separates them by role.
| Part | Intended reader | Content |
|---|---|---|
| Overview | Anyone wanting the whole picture | Purpose, structure, terminology, relationship to other regimes |
| Governance | Decision-makers and executives | Executive responsibility, policy, resourcing, responsibility when outsourcing |
| Planning and management | System administrators | Risk assessment, procedures, supplier management, training |
| System operations | Operators | Access control, logging, backups, equipment, incident response |
The split does not mean you may ignore the parts addressed to others. It means responsibility has been located by role. The governance part in particular rules out the position that "the systems are the administrator's and the vendor's problem."
Scope Does Not Depend on Size
Edition 6.0 applies to "all those involved in the introduction, operation, use, maintenance, and disposal of medical information systems."
This is widely misread. Hospitals, clinics, dental practices, and pharmacies are all in scope, regardless of size. "We are a ten-person clinic, so this is for large hospitals" does not hold. If you run an EMR, submit claims electronically, and operate online eligibility verification, you are in scope.
Being in scope is not the same as building a large hospital's apparatus, however. The guidelines call for treatment proportionate to risk, and risk varies with size and data volume. Where a small practice should realistically begin is covered in Guideline Compliance for Small Clinics: How Far to Go.
The second principle to internalise is that outsourcing does not transfer responsibility. Even where an EMR vendor or cloud provider runs the systems, accountability for patient data stays with the institution. Your vendor's compliance with the three-ministry guidelines is a precondition, not an indemnity. This is the central theme of The Governance Part: What Executives Are Accountable For.
Two Documents Published in May 2025
Because the text alone often left practitioners unsure, two supporting documents appeared in 2025.
1. Q&A on Edition 6.0 (May 2025)
The MHLW published a Q&A on Edition 6.0, giving practical readings of the more abstract requirements. When you are unsure whether what you have done is enough, checking the Q&A for a comparable question is the fastest route.
2. Cybersecurity checklist and manual for healthcare institutions (14 May 2025)
Also from the MHLW, a checklist with an accompanying manual. It is more concrete and practical than earlier material, and adds treatment of cloud environments, BCP, IoT devices, and BYOD.
The two serve different purposes. The guidelines say what must be satisfied; the checklist tells you where you currently stand. In practice the workable order is assess your position with the checklist, then read the relevant part of the guidelines for whatever is missing.
Where to Start Reading
| Your role | Read first | Then |
|---|---|---|
| Director, board member, administrator | Overview → Governance | Planning and management (to know what to ask of your staff) |
| IT / medical informatics staff | Overview → Planning and management | System operations |
| Operators and vendor liaisons | System operations | Planning and management (the basis for your tasks) |
| Billing and health information managers | Overview | System operations (logging and access control) |
Each part is covered here in its own article.
- The Governance Part: What Executives Are Accountable For — what to decide, what you answer for, and how outsourcing works
- The Planning and Management Part — risk assessment, procedures, supplier management, training, and how much to document
- The System Operations Part — access control, logging, backups, equipment, incident response
- The Medical Information Security Manager — who to appoint, whether the role can be combined, and what works in a small practice
- Guideline Compliance for Small Clinics — how to prioritise and what your vendor can carry
If you use cloud services, see Cloud Security for Healthcare Institutions. For designing controls in at procurement or replacement, see Security by Design for Medical Systems. For the step-by-step compliance route, see Practical Steps for Three-Ministry Guideline Compliance.
To understand the standard your suppliers are held to, the certification regime on the vendor side is covered in What Is an ISMS (ISO/IEC 27001)?.
Conclusion
- FY2026 made guideline compliance and a dedicated security manager conditions of an add-on. Security moved from optional good practice to a billing requirement
- In the inpatient tiers, tier 1 (160 points) adds multi-method backups with an offline copy, plus a cyber BCP and drills
- Edition 6.0 has four parts — overview, governance, planning and management, system operations — split by role
- Scope covers "all those involved in medical information systems," regardless of size or type; the depth of treatment scales with risk
- Outsourcing does not transfer the institution's responsibility. Vendor compliance is a precondition, not a defence
- A workable starting order is assess with the May 2025 checklist, then read the relevant part for the gaps
If building this internally is difficult, or you want help working out where to start ahead of filing for the add-on, get in touch. Where the vendor side needs to evidence its own security posture, we also offer ISMS certification support.
References and Sources
- Guidelines for the Safe Management of Medical Information Systems | MHLW
- Edition 6.0 full text (PDF) | MHLW
- On the FY2026 medical fee revision | MHLW
- Personal Information Protection Commission
- Information-technology Promotion Agency (IPA)
Note: the guidelines are revised and fee-schedule requirements are clarified through official Q&A. This article reflects material published at the time of writing. Base filing and billing decisions on the current notices and on confirmation from your Regional Bureau of Health and Welfare.