"We only finished our guideline work last year — another revision?" It is a familiar reaction from hospital staff. Japan's three-ministry guidelines keep moving with changes in regulation, technology, and the threat landscape. They are not something you comply with once and are done with.
That said, each revision rarely requires rebuilding from scratch. Most revisions do not alter the skeleton of the requirements; they accumulate in the direction of making them more specific and more precise. Understand that and your posture toward revisions becomes updating rather than chasing.
This article covers how the guidelines have moved, what happened recently, and how to prepare. It does not predict future revisions. It stays within what has been published and the direction that can reasonably be read from it.
Disclaimer: General information only. Version numbers, revision dates, and requirement detail are governed by the publications of MHLW, METI, and MIC. Where this article says a topic is "under discussion," that is not a guarantee of any future revision. Base practical decisions on current primary sources.
The Path to Version 6.0
MHLW's Guidelines for the Safe Management of Medical Information Systems were first published in the mid-2000s and have been revised several times since. For exact revision dates, consult MHLW's own page.
Viewed broadly, the revisions show scope widening in response to changes in the environment.
| Phase | Main change | Effect on the guidelines |
|---|---|---|
| EMR adoption | Paper to electronic | Electronic storage requirements: authenticity, legibility, preservability |
| External storage permitted and expanded | Storage outside the institution | Conditions for external storage, clearer supplier management |
| Cloud becomes normal | The on-premises assumption breaks | Demarcation with providers, how to treat cloud use |
| Ransomware damage surfaces | Incidents that suspend care | More weight on backup, BCP, incident response |
| Healthcare DX | Online eligibility verification, e-prescriptions | Network boundaries, managing external connections |
The current version is 6.0 (revised May 2023), and what distinguishes it is less added content than a change in structure.
| Volume | Intended reader |
|---|---|
| Overview | Anyone needing the whole picture |
| Governance | Decision-makers and executives |
| Planning and management | System managers |
| System operations | The people actually running systems |
The four-volume design splits the text by who reads it. Previously the sheer volume meant either the IT person read all of it or nobody did. Making explicit which part executives are meant to read is not a small thing: it positions security as a management concern rather than a technical one for the floor.
Scope, meanwhile, covers "all those involved in the introduction, operation, use, maintenance, and disposal of any medical information system" — regardless of size or type, from hospitals to clinics, dental practices, and pharmacies. "We are too small for this" does not hold. See Guideline Compliance for Small Clinics, The Governance Volume, and The Planning and Management Volume.
The other half of the framework — the METI/MIC guideline for providers — is revised separately. A hospital should keep an eye on whether its suppliers are working from the current version. See The METI/MIC Guidelines.
What Happened in 2025
Two developments stand out, and neither was a new version. Both moved in the direction of making existing requirements usable.
1. Q&A on version 6.0 (May 2025). MHLW published a Q&A on version 6.0. The guideline text is written at a high level of abstraction, which leaves hospitals asking whether a given passage applies to their particular situation. A Q&A narrows that interpretive range.
Two practical consequences: official material now exists for matters previously handled by interpretation, and "we weren't sure how to read it, so we didn't act" has become a weaker explanation.
2. The cybersecurity checklist and manual (14 May 2025). MHLW published a Cybersecurity Checklist for Medical Institutions together with a manual. It is more concrete and more practical than its predecessors, with added treatment of cloud environments, BCP, IoT, and BYOD.
Read together, the direction is legible: not raising the bar, but translating the existing bar into something executable. The guidelines have long said what should be done; hospitals stalled on what specifically, and how far, was enough. The Q&A and the checklist work on exactly that blockage.
For a hospital, using them for self-assessment is the highest-return move available. See How to Use the MHLW Checklist and The Three-Ministry Compliance Checklist.
The New Axis: Reimbursement
The FY2026 fee revision cannot be left out of any account of where this is going. It was not a revision of the guidelines, but it changed their standing.
FY2026 established the electronic clinical-information coordination system enhancement addition, abolishing and merging the medical information acquisition addition and the healthcare DX promotion system addition, and building an assessment of cybersecurity measures into the result. The cybersecurity requirements of the medical record management system addition (level 1) were also migrated into it.
| Level | Points | Requirements |
|---|---|---|
| Level 1 | 160 | Common requirements plus level-1-only requirements |
| Level 2 | 80 | Common requirements |
Common requirements
- Compliance with the Guidelines for the Safe Management of Medical Information Systems
- A dedicated medical information system safety management officer
Level 1 only
- Backups of medical information systems by multiple methods, some held offline
- A BCP for cyberattacks, with drills conducted
The change here is less in the content of the requirements than in their standing. Guideline compliance was long a norm whose breach had no visible direct consequence. Built into a claiming requirement, whether you comply now bears directly on revenue.
Put differently: security has moved from "do we spend on this?" to "can we claim this?" The language used with executives should move accordingly. See The FY2026 Fee Revision.
On backup method: external media (a separate medium such as RDX, with generation management), automatic transfer (to a NAS kept permanently disconnected from the network), and in-cloud backup (to a logically isolated area within a cloud service, where prompt recovery is possible) are each stated to satisfy the requirement. For generations, at least three is the stated benchmark where backups are daily; weekly and monthly practice is not stated uniformly, as it varies with hospital size and method. See Backup Design for Hospitals and BCP for Cyberattacks.
Confirm claiming requirements against the official notices and Q&A. The summary here is not a basis for a claiming decision.
Topics Currently Under Discussion
Carefully now: no future revision is settled. What follows are areas that appear in published material, deliberative forums, and industry discussion. None of this can be stated as a coming change.
1. Generative AI in clinical use. As generative AI touches clinical information more often, there is discussion of how far the existing framework reaches — handling of submitted information, use for training, responsibility for outputs. What a hospital can settle today is covered in Generative AI in Healthcare: Law and Security and Security for AI Voice Charting.
2. Supply chain risk. Attention is growing to the structure in which harm reaches a hospital not through its direct supplier but through that supplier's suppliers, or through connected medical devices. How far management should extend is genuinely difficult in practice. See Supply Chain Risk for Hospitals.
3. A realistic bar for small facilities. The guidelines apply regardless of size, yet what a clinic and a large hospital can do differ. How to express the expected level remains an ongoing question.
4. Information sharing after incidents. Affected institutions face structural disincentives to disclose, which is said to let similar incidents recur. How to build sharing mechanisms is under discussion.
Again: this is not a statement that any of it will appear in the next revision. The appropriate posture is awareness that these areas draw attention, and tracking primary sources where your own situation touches them.
Preparing So Revisions Do Not Whipsaw You
Four things make revisions manageable.
- Assign tracking, with a frequency. Who checks which page, how often. Twice a year is enough if it is actually assigned. Simply watching MHLW's guideline page on a schedule changes things
- Record your decisions together with the reasoning. You can only identify what a revision affects if the reasoning survives. Documents without it force a full re-read every time
- Layer your documents. Policy (rarely changes) / procedures (revisited on revision) / work instructions (change with operations). Keeping them separate limits the blast radius. One monolithic document means a small revision triggers a full rewrite
- Require suppliers to track too. Contract for a duty to explain their approach when the guidelines change. Some areas you cannot follow alone
These four are less about revisions specifically than about making compliance sustainable. See Implementation Steps and The Three Ministries' Two Guidelines Explained. Providers building a continuous management mechanism may find What Is an ISMS (ISO/IEC 27001)? useful.
Conclusion
- Revisions continue, but most accumulate specificity rather than change the skeleton
- The current version is 6.0 (May 2023), restructured into four volumes by reader, making explicit what executives should read
- 2025 brought the Q&A (May) and the checklist and manual (14 May) — translation into executable form, not a higher bar
- The FY2026 fee revision built guideline compliance into a claiming requirement. Its standing changed
- Generative AI, supply chain, the bar for small facilities, and incident information sharing are under discussion — not settled as revisions
- Prepare through assigned tracking, recorded reasoning, layered documents, and supplier tracking duties
For help building a structure that survives each revision, or organising your document hierarchy, contact us.
References and Sources
- Guidelines for the Safe Management of Medical Information Systems | MHLW
- Version 6.0 full text (PDF) | MHLW
- On the FY2026 fee revision | MHLW
- Ministry of Economy, Trade and Industry
- Ministry of Internal Affairs and Communications
- National center of Incident readiness and Strategy for Cybersecurity (NISC)
Note: version numbers, revision dates, and requirement detail are governed by each ministry's publications. References to topics "under discussion" do not guarantee any future revision. Confirm reimbursement requirements against the official notices and Q&A.