Back to Columns
Healthcare Security11 min read

How the Three-Ministry Guidelines Have Been Changing

September 14, 2026

How the Three-Ministry Guidelines Have Been Changing
Share this article

"We only finished our guideline work last year — another revision?" It is a familiar reaction from hospital staff. Japan's three-ministry guidelines keep moving with changes in regulation, technology, and the threat landscape. They are not something you comply with once and are done with.

That said, each revision rarely requires rebuilding from scratch. Most revisions do not alter the skeleton of the requirements; they accumulate in the direction of making them more specific and more precise. Understand that and your posture toward revisions becomes updating rather than chasing.

This article covers how the guidelines have moved, what happened recently, and how to prepare. It does not predict future revisions. It stays within what has been published and the direction that can reasonably be read from it.

Disclaimer: General information only. Version numbers, revision dates, and requirement detail are governed by the publications of MHLW, METI, and MIC. Where this article says a topic is "under discussion," that is not a guarantee of any future revision. Base practical decisions on current primary sources.

The Path to Version 6.0

MHLW's Guidelines for the Safe Management of Medical Information Systems were first published in the mid-2000s and have been revised several times since. For exact revision dates, consult MHLW's own page.

Viewed broadly, the revisions show scope widening in response to changes in the environment.

PhaseMain changeEffect on the guidelines
EMR adoptionPaper to electronicElectronic storage requirements: authenticity, legibility, preservability
External storage permitted and expandedStorage outside the institutionConditions for external storage, clearer supplier management
Cloud becomes normalThe on-premises assumption breaksDemarcation with providers, how to treat cloud use
Ransomware damage surfacesIncidents that suspend careMore weight on backup, BCP, incident response
Healthcare DXOnline eligibility verification, e-prescriptionsNetwork boundaries, managing external connections

The current version is 6.0 (revised May 2023), and what distinguishes it is less added content than a change in structure.

VolumeIntended reader
OverviewAnyone needing the whole picture
GovernanceDecision-makers and executives
Planning and managementSystem managers
System operationsThe people actually running systems

The four-volume design splits the text by who reads it. Previously the sheer volume meant either the IT person read all of it or nobody did. Making explicit which part executives are meant to read is not a small thing: it positions security as a management concern rather than a technical one for the floor.

Scope, meanwhile, covers "all those involved in the introduction, operation, use, maintenance, and disposal of any medical information system" — regardless of size or type, from hospitals to clinics, dental practices, and pharmacies. "We are too small for this" does not hold. See Guideline Compliance for Small Clinics, The Governance Volume, and The Planning and Management Volume.

The other half of the framework — the METI/MIC guideline for providers — is revised separately. A hospital should keep an eye on whether its suppliers are working from the current version. See The METI/MIC Guidelines.

What Happened in 2025

Two developments stand out, and neither was a new version. Both moved in the direction of making existing requirements usable.

1. Q&A on version 6.0 (May 2025). MHLW published a Q&A on version 6.0. The guideline text is written at a high level of abstraction, which leaves hospitals asking whether a given passage applies to their particular situation. A Q&A narrows that interpretive range.

Two practical consequences: official material now exists for matters previously handled by interpretation, and "we weren't sure how to read it, so we didn't act" has become a weaker explanation.

2. The cybersecurity checklist and manual (14 May 2025). MHLW published a Cybersecurity Checklist for Medical Institutions together with a manual. It is more concrete and more practical than its predecessors, with added treatment of cloud environments, BCP, IoT, and BYOD.

Read together, the direction is legible: not raising the bar, but translating the existing bar into something executable. The guidelines have long said what should be done; hospitals stalled on what specifically, and how far, was enough. The Q&A and the checklist work on exactly that blockage.

For a hospital, using them for self-assessment is the highest-return move available. See How to Use the MHLW Checklist and The Three-Ministry Compliance Checklist.

The New Axis: Reimbursement

The FY2026 fee revision cannot be left out of any account of where this is going. It was not a revision of the guidelines, but it changed their standing.

FY2026 established the electronic clinical-information coordination system enhancement addition, abolishing and merging the medical information acquisition addition and the healthcare DX promotion system addition, and building an assessment of cybersecurity measures into the result. The cybersecurity requirements of the medical record management system addition (level 1) were also migrated into it.

LevelPointsRequirements
Level 1160Common requirements plus level-1-only requirements
Level 280Common requirements

Common requirements

  • Compliance with the Guidelines for the Safe Management of Medical Information Systems
  • A dedicated medical information system safety management officer

Level 1 only

  • Backups of medical information systems by multiple methods, some held offline
  • A BCP for cyberattacks, with drills conducted

The change here is less in the content of the requirements than in their standing. Guideline compliance was long a norm whose breach had no visible direct consequence. Built into a claiming requirement, whether you comply now bears directly on revenue.

Put differently: security has moved from "do we spend on this?" to "can we claim this?" The language used with executives should move accordingly. See The FY2026 Fee Revision.

On backup method: external media (a separate medium such as RDX, with generation management), automatic transfer (to a NAS kept permanently disconnected from the network), and in-cloud backup (to a logically isolated area within a cloud service, where prompt recovery is possible) are each stated to satisfy the requirement. For generations, at least three is the stated benchmark where backups are daily; weekly and monthly practice is not stated uniformly, as it varies with hospital size and method. See Backup Design for Hospitals and BCP for Cyberattacks.

Confirm claiming requirements against the official notices and Q&A. The summary here is not a basis for a claiming decision.

Topics Currently Under Discussion

Carefully now: no future revision is settled. What follows are areas that appear in published material, deliberative forums, and industry discussion. None of this can be stated as a coming change.

1. Generative AI in clinical use. As generative AI touches clinical information more often, there is discussion of how far the existing framework reaches — handling of submitted information, use for training, responsibility for outputs. What a hospital can settle today is covered in Generative AI in Healthcare: Law and Security and Security for AI Voice Charting.

2. Supply chain risk. Attention is growing to the structure in which harm reaches a hospital not through its direct supplier but through that supplier's suppliers, or through connected medical devices. How far management should extend is genuinely difficult in practice. See Supply Chain Risk for Hospitals.

3. A realistic bar for small facilities. The guidelines apply regardless of size, yet what a clinic and a large hospital can do differ. How to express the expected level remains an ongoing question.

4. Information sharing after incidents. Affected institutions face structural disincentives to disclose, which is said to let similar incidents recur. How to build sharing mechanisms is under discussion.

Again: this is not a statement that any of it will appear in the next revision. The appropriate posture is awareness that these areas draw attention, and tracking primary sources where your own situation touches them.

Preparing So Revisions Do Not Whipsaw You

Four things make revisions manageable.

  1. Assign tracking, with a frequency. Who checks which page, how often. Twice a year is enough if it is actually assigned. Simply watching MHLW's guideline page on a schedule changes things
  2. Record your decisions together with the reasoning. You can only identify what a revision affects if the reasoning survives. Documents without it force a full re-read every time
  3. Layer your documents. Policy (rarely changes) / procedures (revisited on revision) / work instructions (change with operations). Keeping them separate limits the blast radius. One monolithic document means a small revision triggers a full rewrite
  4. Require suppliers to track too. Contract for a duty to explain their approach when the guidelines change. Some areas you cannot follow alone

These four are less about revisions specifically than about making compliance sustainable. See Implementation Steps and The Three Ministries' Two Guidelines Explained. Providers building a continuous management mechanism may find What Is an ISMS (ISO/IEC 27001)? useful.

Conclusion

  1. Revisions continue, but most accumulate specificity rather than change the skeleton
  2. The current version is 6.0 (May 2023), restructured into four volumes by reader, making explicit what executives should read
  3. 2025 brought the Q&A (May) and the checklist and manual (14 May) — translation into executable form, not a higher bar
  4. The FY2026 fee revision built guideline compliance into a claiming requirement. Its standing changed
  5. Generative AI, supply chain, the bar for small facilities, and incident information sharing are under discussion — not settled as revisions
  6. Prepare through assigned tracking, recorded reasoning, layered documents, and supplier tracking duties

For help building a structure that survives each revision, or organising your document hierarchy, contact us.

References and Sources

Note: version numbers, revision dates, and requirement detail are governed by each ministry's publications. References to topics "under discussion" do not guarantee any future revision. Confirm reimbursement requirements against the official notices and Q&A.

Share this article

Related Articles

Healthcare Security

Access Control and Privileged ID Management: What Is Realistic in a Hospital

Role-based permissions, least privilege, offboarding and transfer reviews, vendor maintenance accounts, and what to do where shared IDs genuinely cannot be eliminated. Access design that actually limits blast radius within the constraints of clinical work.

September 14, 2026
Healthcare Security

Antivirus and EDR: What a Hospital Should Decide Before Buying

How EDR differs from conventional antivirus, why it is not a product that protects you simply by being installed, how to choose an operating model for the alerts it produces, what to do about devices it cannot be installed on, and what to settle before you buy.

September 14, 2026
Healthcare Security

Logging and Audit Trails: Getting Past 'We Collect It but Nobody Looks'

What to log, how long to retain it, and the real problem — logs collected but never read. Which logs actually matter during an incident, and how to make review a sustainable routine in a hospital with limited staff.

September 14, 2026
Healthcare Security

Backup Design for Hospitals: The 3-2-1 Rule and the Tier 1 Requirement

Japan's FY2026 revision makes multi-method backup with part of it held offline a tier 1 requirement. We cover the three methods accepted as meeting it — external media, automated transfer to a permanently detached NAS, and a logically separated area within a cloud service — plus generation management and why an untested backup does not count.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.