Back to Columns
Healthcare Security13 min read

A Three-Ministry Guidelines Compliance Checklist

September 14, 2026

A Three-Ministry Guidelines Compliance Checklist
Share this article

Compliance with Japan's three-ministry healthcare guidelines does not advance while you are staring at a list of things to do. It advances the moment you know specifically what your own organization is failing to do. Where compliance has stalled, the cause is usually not unwillingness — it is not knowing where you stand.

There is also a new reason it is harder to defer. The electronic clinical-information coordination system enhancement addition, established in the FY2026 fee revision, includes compliance with the MHLW guidelines and the appointment of a dedicated medical information system safety management officer among its requirements. Security has moved from a cost question to a reimbursement question. Knowing your position is now a precondition for deciding whether you can claim it.

This article is a checklist for establishing that position, across three domains: governance, technical operations, and outsourcing/cloud. For implementation sequence itself see Implementation Steps for the Three-Ministry Guidelines; this article concentrates on assessment and prioritization.

Disclaimer: This checklist is an aid to self-assessment. It neither exhausts the guidelines' requirements nor certifies compliance. The authoritative texts are the publications of MHLW, METI, and MIC. For reimbursement requirements, always consult the official notices and Q&A.

Three Things to Settle Before You Start

1. Scope. Which systems? Only the EMR, or also departmental systems, online eligibility verification, booking, in-house Wi-Fi, networked medical devices? Too wide and the first pass never finishes. Limit round one to systems handling clinical information; widen in round two.

2. Who answers. The administrator cannot fill this in alone; different items have different respondents, and some can only be answered by the vendor. Assign respondents before distributing and you will get responses back.

3. What "done" means. The most important decision. "We think we do this" and "we have a record of doing this" are different things. In guideline practice, what is not recorded is treated as not done. Use three grades:

GradeMeaning
Done, and demonstrable by document or record
Done, but unrecorded, person-dependent, or partial
×Not done, or status unknown

Whether your team can honestly mark △ determines the quality of the exercise. An assessment returning all ○ is usually not an assessment.

Note that MHLW published a Cybersecurity Checklist for Medical Institutions and its accompanying manual on 14 May 2025 — more concrete than its predecessors, with added treatment of cloud environments, BCP, IoT, and BYOD. Use that first; treat the list below as a complement. See How to Use the MHLW Checklist.

Governance Items

Version 6.0 of the guidelines is organized into four volumes — overview, governance, planning and management, and system operations — separating what each role is responsible for. Executives read the governance volume. Nothing in this domain can be solved with technology, and nothing gets deferred more often.

#ItemHow to judge
1A medical information system safety management officer is appointed and known internallyAppointment record and documented role. Dedicated appointment also bears on the fee addition
2An information security policy exists in writingDate, approver, revision history
3A forum involving executives meets and keeps minutesHow often, and what was decided
4An asset register (systems, devices, data) exists and is maintainedUpdated within the last year. Without it nothing else can be assessed
5Risk assessment performed and treatments decidedRecords, including acceptance of residual risk
6Staff training delivered to a planAnnual plan, delivery records, attendance
7A list of suppliers and providers is maintainedDoes it reach subcontractors?
8Incident reporting lines and contacts are documentedIncluding nights and weekends; current?
9A BCP for cyberattacks existsA requirement for level 1 — drills as well as the plan
10Someone tracks guideline revisions, by a defined procedureWho, how often

If item 4 is blank, every later item loses accuracy — you cannot judge whether something is protected when you do not know it exists. If you know you lack a register, skip ahead and start there.

See The Role of the Medical Information Safety Management Officer and Building a Hospital Security Structure.

Technical and Operational Items

Technical checklists sprawl, but working backwards from the structure common to reported incidents narrows the priorities sharply. What recurs: an internet-facing appliance left unpatched, backups sitting on the same network and encrypted with everything else, and recovery procedures that were never written down.

#ItemHow to judge
11Externally connected devices (VPN, remote maintenance lines) are inventoriedCount, model, support expiry
12Their firmware is current, with a defined update procedureLast update. Any end-of-support devices left?
13The internal network is segmented by purposeClinical, administrative, and guest not on one segment
14Backups are taken by more than one methodLevel 1 requires multiple methods, some held offline
15Some backups are disconnected from the networkNot only an always-on NAS
16Backup generations are managedFor daily backups, at least three generations is the stated benchmark
17Restores have actually been tested, with a record"Backed up" and "restorable" differ. Test annually
18User accounts are reviewed periodicallyLeavers and transfers removed?
19Privileged IDs are not shared, and their use is loggedShared accounts make attribution impossible
20Multi-factor authentication protects critical systemsEspecially external access paths
21Audit logs are collected, retained to a defined period, and reviewedCollection without review is common
22Endpoint protection and management cover every deviceIncluding devices departments bought themselves
23Rules exist for removable mediaAnd actual practice matches them
24The security of networked medical devices is understoodNot left entirely to the maintenance vendor

Items 14–17 are the highest priority right now — both because they became a reimbursement requirement and because they directly determine whether you can recover. On method: external-media backup (a separate medium such as RDX, with generation management), automatic transfer to a NAS kept permanently disconnected from the network, and backup to a logically isolated area within a cloud service where prompt recovery is possible are each stated to satisfy the requirement. See Backup Design for Hospitals: the 3-2-1 Rule.

Also see Managing VPN Appliance Vulnerabilities, Network Segmentation and Asset Management, Access Design and Privileged ID Management, and Log Management and Audit Trails.

Outsourcing and Cloud Items

This domain is the one left until last, and the one you cannot complete alone. Most answers require asking the vendor.

#ItemHow to judge
25Responsibility demarcation with suppliers is documentedA matrix in the contract or an annex. Demarcating Responsibility
26The supplier can evidence its own (provider-side) guideline complianceEvidence, not a claim. The METI/MIC Guidelines
27Subcontracting and subcontractors are knownFor cloud, can you see the actual storage provider?
28Incident notification terms are concrete in the contractTrigger events, recipients, deadline in hours
29Log retention and disclosure terms are knownLong enough for an investigation? Chargeable?
30Data location (country, region) is knownHow far can you specify it contractually?
31Return and deletion of data at termination is settledFormat, deadline, certificate of deletion
32Supplier posture is re-confirmed periodicallyAn annual report or audit arrangement
33External storage requirements are confirmedGuideline Compliance When Using the Cloud
34The scope of the supplier's certifications is confirmedDoes the scope include the service in question?

On item 34, be careful: holding ISO/IEC 27001 does not by itself mean compliance with the three-ministry guidelines. It becomes useful evidence only once you have confirmed that the certification scope covers the service. See What Is an ISMS (ISO/IEC 27001)? and Security Check Sheets for Vendors.

Working Through the Items Marked ×

A first pass typically produces around twenty items at △ or ×. You cannot address them simultaneously. A workable order:

First — the prerequisites. Item 4 (asset register) and item 1 (appointed officer), because without them nothing else can be planned. Do not aim for a perfect register; start with a single page covering systems that handle clinical information and externally connected devices.

Second — what determines the size of the damage. Items 14–17 (backups) and 11–12 (external device vulnerabilities). These two groups decide whether care stops when you are attacked, and they offer the best return on effort.

Third — what bears on the fee addition. Item 1 (dedicated officer), item 9 (BCP and drills), items 14–15 (multiple backup methods, some offline). If you intend to claim, verify these against the official notices before building.

Fourth — records. Most △ items — done but unrecorded — belong here. Turning what you already do into something recorded is far cheaper than adding new controls, and it moves the score more. Training attendance, log review records, committee minutes: those three alone convert a large share of △ to ○.

Record what you decide not to do. You need not implement everything. Where you judge an item unnecessary given your size and risk profile, record the decision and the reasoning. Unimplemented-and-undocumented and unimplemented-by-decision are different qualities of compliance. See Guideline Compliance for Small Clinics.

Conclusion

  1. Compliance stalls because you cannot see where you stand — assess first
  2. "Done" means demonstrable by record. Grade honestly across ○/△/×
  3. If the asset register is blank, every other assessment is unreliable. Start there
  4. Technically, backups and externally connected devices come first; they determine the scale of the damage
  5. The outsourcing and cloud domain cannot be completed alone — plan to ask suppliers for evidence
  6. Most △ items resolve through recordkeeping, which is worth doing before new investment
  7. Where you decide not to act, record the decision and why

If the assessment leaves items you cannot address in-house, contact us. For implementation sequence see Implementation Steps, and for judging the vendor's share see The METI/MIC Guidelines.

References and Sources

Note: this checklist supports self-assessment and does not exhaust the guidelines' requirements. Guidelines and reimbursement requirements are subject to revision; confirm claiming requirements against the official notices and Q&A.

Share this article

Related Articles

Healthcare Security

Access Control and Privileged ID Management: What Is Realistic in a Hospital

Role-based permissions, least privilege, offboarding and transfer reviews, vendor maintenance accounts, and what to do where shared IDs genuinely cannot be eliminated. Access design that actually limits blast radius within the constraints of clinical work.

September 14, 2026
Healthcare Security

Antivirus and EDR: What a Hospital Should Decide Before Buying

How EDR differs from conventional antivirus, why it is not a product that protects you simply by being installed, how to choose an operating model for the alerts it produces, what to do about devices it cannot be installed on, and what to settle before you buy.

September 14, 2026
Healthcare Security

Logging and Audit Trails: Getting Past 'We Collect It but Nobody Looks'

What to log, how long to retain it, and the real problem — logs collected but never read. Which logs actually matter during an incident, and how to make review a sustainable routine in a hospital with limited staff.

September 14, 2026
Healthcare Security

Backup Design for Hospitals: The 3-2-1 Rule and the Tier 1 Requirement

Japan's FY2026 revision makes multi-method backup with part of it held offline a tier 1 requirement. We cover the three methods accepted as meeting it — external media, automated transfer to a permanently detached NAS, and a logically separated area within a cloud service — plus generation management and why an untested backup does not count.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.