Compliance with Japan's three-ministry healthcare guidelines does not advance while you are staring at a list of things to do. It advances the moment you know specifically what your own organization is failing to do. Where compliance has stalled, the cause is usually not unwillingness — it is not knowing where you stand.
There is also a new reason it is harder to defer. The electronic clinical-information coordination system enhancement addition, established in the FY2026 fee revision, includes compliance with the MHLW guidelines and the appointment of a dedicated medical information system safety management officer among its requirements. Security has moved from a cost question to a reimbursement question. Knowing your position is now a precondition for deciding whether you can claim it.
This article is a checklist for establishing that position, across three domains: governance, technical operations, and outsourcing/cloud. For implementation sequence itself see Implementation Steps for the Three-Ministry Guidelines; this article concentrates on assessment and prioritization.
Disclaimer: This checklist is an aid to self-assessment. It neither exhausts the guidelines' requirements nor certifies compliance. The authoritative texts are the publications of MHLW, METI, and MIC. For reimbursement requirements, always consult the official notices and Q&A.
Three Things to Settle Before You Start
1. Scope. Which systems? Only the EMR, or also departmental systems, online eligibility verification, booking, in-house Wi-Fi, networked medical devices? Too wide and the first pass never finishes. Limit round one to systems handling clinical information; widen in round two.
2. Who answers. The administrator cannot fill this in alone; different items have different respondents, and some can only be answered by the vendor. Assign respondents before distributing and you will get responses back.
3. What "done" means. The most important decision. "We think we do this" and "we have a record of doing this" are different things. In guideline practice, what is not recorded is treated as not done. Use three grades:
| Grade | Meaning |
|---|---|
| ○ | Done, and demonstrable by document or record |
| △ | Done, but unrecorded, person-dependent, or partial |
| × | Not done, or status unknown |
Whether your team can honestly mark △ determines the quality of the exercise. An assessment returning all ○ is usually not an assessment.
Note that MHLW published a Cybersecurity Checklist for Medical Institutions and its accompanying manual on 14 May 2025 — more concrete than its predecessors, with added treatment of cloud environments, BCP, IoT, and BYOD. Use that first; treat the list below as a complement. See How to Use the MHLW Checklist.
Governance Items
Version 6.0 of the guidelines is organized into four volumes — overview, governance, planning and management, and system operations — separating what each role is responsible for. Executives read the governance volume. Nothing in this domain can be solved with technology, and nothing gets deferred more often.
| # | Item | How to judge |
|---|---|---|
| 1 | A medical information system safety management officer is appointed and known internally | Appointment record and documented role. Dedicated appointment also bears on the fee addition |
| 2 | An information security policy exists in writing | Date, approver, revision history |
| 3 | A forum involving executives meets and keeps minutes | How often, and what was decided |
| 4 | An asset register (systems, devices, data) exists and is maintained | Updated within the last year. Without it nothing else can be assessed |
| 5 | Risk assessment performed and treatments decided | Records, including acceptance of residual risk |
| 6 | Staff training delivered to a plan | Annual plan, delivery records, attendance |
| 7 | A list of suppliers and providers is maintained | Does it reach subcontractors? |
| 8 | Incident reporting lines and contacts are documented | Including nights and weekends; current? |
| 9 | A BCP for cyberattacks exists | A requirement for level 1 — drills as well as the plan |
| 10 | Someone tracks guideline revisions, by a defined procedure | Who, how often |
If item 4 is blank, every later item loses accuracy — you cannot judge whether something is protected when you do not know it exists. If you know you lack a register, skip ahead and start there.
See The Role of the Medical Information Safety Management Officer and Building a Hospital Security Structure.
Technical and Operational Items
Technical checklists sprawl, but working backwards from the structure common to reported incidents narrows the priorities sharply. What recurs: an internet-facing appliance left unpatched, backups sitting on the same network and encrypted with everything else, and recovery procedures that were never written down.
| # | Item | How to judge |
|---|---|---|
| 11 | Externally connected devices (VPN, remote maintenance lines) are inventoried | Count, model, support expiry |
| 12 | Their firmware is current, with a defined update procedure | Last update. Any end-of-support devices left? |
| 13 | The internal network is segmented by purpose | Clinical, administrative, and guest not on one segment |
| 14 | Backups are taken by more than one method | Level 1 requires multiple methods, some held offline |
| 15 | Some backups are disconnected from the network | Not only an always-on NAS |
| 16 | Backup generations are managed | For daily backups, at least three generations is the stated benchmark |
| 17 | Restores have actually been tested, with a record | "Backed up" and "restorable" differ. Test annually |
| 18 | User accounts are reviewed periodically | Leavers and transfers removed? |
| 19 | Privileged IDs are not shared, and their use is logged | Shared accounts make attribution impossible |
| 20 | Multi-factor authentication protects critical systems | Especially external access paths |
| 21 | Audit logs are collected, retained to a defined period, and reviewed | Collection without review is common |
| 22 | Endpoint protection and management cover every device | Including devices departments bought themselves |
| 23 | Rules exist for removable media | And actual practice matches them |
| 24 | The security of networked medical devices is understood | Not left entirely to the maintenance vendor |
Items 14–17 are the highest priority right now — both because they became a reimbursement requirement and because they directly determine whether you can recover. On method: external-media backup (a separate medium such as RDX, with generation management), automatic transfer to a NAS kept permanently disconnected from the network, and backup to a logically isolated area within a cloud service where prompt recovery is possible are each stated to satisfy the requirement. See Backup Design for Hospitals: the 3-2-1 Rule.
Also see Managing VPN Appliance Vulnerabilities, Network Segmentation and Asset Management, Access Design and Privileged ID Management, and Log Management and Audit Trails.
Outsourcing and Cloud Items
This domain is the one left until last, and the one you cannot complete alone. Most answers require asking the vendor.
| # | Item | How to judge |
|---|---|---|
| 25 | Responsibility demarcation with suppliers is documented | A matrix in the contract or an annex. Demarcating Responsibility |
| 26 | The supplier can evidence its own (provider-side) guideline compliance | Evidence, not a claim. The METI/MIC Guidelines |
| 27 | Subcontracting and subcontractors are known | For cloud, can you see the actual storage provider? |
| 28 | Incident notification terms are concrete in the contract | Trigger events, recipients, deadline in hours |
| 29 | Log retention and disclosure terms are known | Long enough for an investigation? Chargeable? |
| 30 | Data location (country, region) is known | How far can you specify it contractually? |
| 31 | Return and deletion of data at termination is settled | Format, deadline, certificate of deletion |
| 32 | Supplier posture is re-confirmed periodically | An annual report or audit arrangement |
| 33 | External storage requirements are confirmed | Guideline Compliance When Using the Cloud |
| 34 | The scope of the supplier's certifications is confirmed | Does the scope include the service in question? |
On item 34, be careful: holding ISO/IEC 27001 does not by itself mean compliance with the three-ministry guidelines. It becomes useful evidence only once you have confirmed that the certification scope covers the service. See What Is an ISMS (ISO/IEC 27001)? and Security Check Sheets for Vendors.
Working Through the Items Marked ×
A first pass typically produces around twenty items at △ or ×. You cannot address them simultaneously. A workable order:
First — the prerequisites. Item 4 (asset register) and item 1 (appointed officer), because without them nothing else can be planned. Do not aim for a perfect register; start with a single page covering systems that handle clinical information and externally connected devices.
Second — what determines the size of the damage. Items 14–17 (backups) and 11–12 (external device vulnerabilities). These two groups decide whether care stops when you are attacked, and they offer the best return on effort.
Third — what bears on the fee addition. Item 1 (dedicated officer), item 9 (BCP and drills), items 14–15 (multiple backup methods, some offline). If you intend to claim, verify these against the official notices before building.
Fourth — records. Most △ items — done but unrecorded — belong here. Turning what you already do into something recorded is far cheaper than adding new controls, and it moves the score more. Training attendance, log review records, committee minutes: those three alone convert a large share of △ to ○.
Record what you decide not to do. You need not implement everything. Where you judge an item unnecessary given your size and risk profile, record the decision and the reasoning. Unimplemented-and-undocumented and unimplemented-by-decision are different qualities of compliance. See Guideline Compliance for Small Clinics.
Conclusion
- Compliance stalls because you cannot see where you stand — assess first
- "Done" means demonstrable by record. Grade honestly across ○/△/×
- If the asset register is blank, every other assessment is unreliable. Start there
- Technically, backups and externally connected devices come first; they determine the scale of the damage
- The outsourcing and cloud domain cannot be completed alone — plan to ask suppliers for evidence
- Most △ items resolve through recordkeeping, which is worth doing before new investment
- Where you decide not to act, record the decision and why
If the assessment leaves items you cannot address in-house, contact us. For implementation sequence see Implementation Steps, and for judging the vendor's share see The METI/MIC Guidelines.
References and Sources
- Guidelines for the Safe Management of Medical Information Systems | MHLW
- Version 6.0 full text (PDF) | MHLW
- On the FY2026 fee revision | MHLW
- Information-technology Promotion Agency (IPA)
- National center of Incident readiness and Strategy for Cybersecurity (NISC)
Note: this checklist supports self-assessment and does not exhaust the guidelines' requirements. Guidelines and reimbursement requirements are subject to revision; confirm claiming requirements against the official notices and Q&A.