When the electronic health record will not open one morning, who decides to take the system offline? Who calls the public health centre and the regional referral hospital, who decides to stop outpatient reception, and who answers the phone when a reporter calls? A surprising number of providers, of every size, cannot answer these questions immediately.
Security discussions gravitate toward the perimeter — how to keep attackers out. But if you have not decided how the organisation moves once the perimeter fails, the disruption caused by confusion outlasts the incident itself. What published cases have in common is that the gap in decision-making and the breakdown of communication stretch the timeline far more than the technical recovery does.
With Japan's FY2026 fee revision, this moved from good practice to a billing requirement. The newly created coordinated electronic clinical information add-on states, at its higher tier, that a business continuity plan for cyberattacks must be developed and drilled.
This article is the blueprint for building an incident response plan from scratch, or rebuilding one that has become a shelf document.
Disclaimer: This article is general information. The authoritative sources are the Ministry of Health, Labour and Welfare's notices and Q&A on reimbursement requirements, and the text of the Guidelines for the Safe Management of Medical Information Systems. Base actual decisions on those.
Why a Plan Is Now Required
The FY2026 revision abolished and merged two earlier add-ons into a new coordinated electronic clinical information add-on, folding cybersecurity evaluation into it.
| Tier | Points | Requirements |
|---|---|---|
| Tier 1 | 160 | The common requirements below, plus backups by multiple methods (some held offline) and a cyberattack BCP that has been developed and drilled |
| Tier 2 | 80 | Conformance with the Guidelines for the Safe Management of Medical Information Systems, and a dedicated medical information system safety manager |
The point is not the difference in reimbursement but the fact that the system now evaluates planning and drills. The question is no longer what you bought but whether the organisation can move. See Key Points of the FY2026 Fee Revision and The Medical Information Safety Manager Role. For the guideline background, see The Three-Ministry Guidelines.
What the Plan Must Contain
A plan is not judged by thickness. The test is whether a night-shift lead can open it at 2am and act. At minimum, six things must be written down.
| Item | What to write | Common omission |
|---|---|---|
| Scope and activation criteria | What counts as an incident, and who declares activation | "In serious cases" with no criteria |
| Roles and authority | Who can decide what, and the order of deputies | No deputy order; everything stalls without the director |
| Communication | Internal and external contacts, and the order to use them | The contact list exists only inside the affected system |
| First response | What to do in the first hour, and what not to do | "Respond promptly" and nothing more |
| Clinical continuity | Paper fallback and clinical priorities | No printed forms exist |
| Records and reporting | What to record, and where and when to report | No list of reporting destinations |
First response is covered in First Response to Ransomware, continuity in A BCP for Cyberattacks, and reporting duties in Reporting a Personal Data Breach.
Write activation criteria as observable events. "The same file extension change observed on multiple endpoints" or "no staff member can log in to the core system" is the granularity a duty officer can act on without hesitation.
Who Decides What
Response is delayed less often by a lack of technical skill than by nobody knowing who decides. For each decision, name a first-line decision-maker and a final approver.
| Decision | First line | Final approver | Target timing |
|---|---|---|---|
| Declaring an incident | Duty lead / IT staff | Medical information safety manager | Within 30 min of detection |
| Disconnecting from the network | IT staff | Safety manager (design for after-the-fact reporting) | Within 1 hour of detection |
| Restricting admissions and outpatient intake | Department head | Hospital director | Within 2 hours of activation |
| Requesting outside help (specialist firms, authorities) | Safety manager | Hospital director | Same day |
| Public disclosure and press handling | Communications lead | Director / board chair | After facts are confirmed |
| Reporting to the Personal Information Protection Commission | Data protection lead | Hospital director | Within the statutory window |
Delegating the disconnection decision downward matters most in practice. Waiting for approval lets damage spread; disconnecting wrongly stops clinical care. Pre-authorising staff to disconnect under stated conditions, with reporting afterwards, is the workable design.
How to assign these roles and constitute a committee is covered in Building a Security Governance Structure.
Build Communication on the Assumption It Fails
A recurring failure in published cases is that the contact list lived only inside the system that was encrypted. Intranet portals, shared folders, notes in the EHR — all lost at once.
Design communication in three layers.
- A paper call tree — staff, key vendors, the public health centre, police, partner hospitals. Held under lock in more than one location
- Channels that do not depend on the hospital network — mobile phones or a separate messaging route, tested in peacetime
- A single point of contact — enquiries, press, and patient questions routed to one place so accounts do not diverge
For external contacts, record the contractual number and the number that actually answers separately. A maintenance contract's main line frequently goes unanswered at night. List out-of-hours procedures and contractual response times alongside. See Writing SLAs and Demarcating Responsibility.
Keeping Care Going
The purpose of the plan is not to fix the system but to keep treating patients. This is where it resembles a disaster BCP — and where it differs, because after a cyberattack the time to recovery cannot be estimated.
Include:
- Clinical priorities — emergency, surgery, dialysis, obstetrics: identify what cannot stop
- Paper forms — prescriptions, orders, test requests, consent. Printed and stored. Files alone are useless
- The minimum information you must still be able to read — inpatient list, allergies and contraindications, the day's surgical and test schedule
- Reconciliation after recovery — how paper records get back into the EHR. Skipping this creates a second wave of disruption
Knowing how many days you can run on paper is what separates a real plan from a document. Three days and two weeks imply very different stockpiles and very different investment decisions. See A BCP for Cyberattacks and Backup Design: the 3-2-1 Rule.
Keeping the Plan Usable
Plans decay from the day they are written: staff rotate, systems are replaced. Three maintenance activities are the minimum.
| Activity | How to set frequency | Records to keep |
|---|---|---|
| Updating the call tree | Tie it to staff rotation dates | Update date, distribution list |
| Tabletop walkthrough | On revision and on structural change | Scenario, participants, issues raised |
| Live drill of degraded operation | Built into the annual plan | Record, elapsed times, improvements |
| Plan review | After drills and after real incidents | Revision history |
The value of a drill is discovering what you could not do. A drill that runs smoothly was probably too easy. Add constraints — the approver is unreachable, the call tree is unavailable — and the gaps appear.
See Designing Staff Training and Drills and Phishing Simulations. For reconciling your plan against the checklist MHLW published on 14 May 2025, see How to Use the MHLW Security Checklist.
Conclusion
- The FY2026 coordinated electronic clinical information add-on makes a drilled cyberattack BCP a tier-1 requirement. Planning is now a billing condition
- The plan's skeleton is six items: scope and activation, roles and authority, communication, first response, clinical continuity, records and reporting
- Separate first-line decision-makers from final approvers for each decision, and pre-authorise disconnection
- Keep contact lists outside the affected systems — on paper, in more than one place
- Continuity planning is only real once you know how many days you can run on paper
- Drills exist to surface what you could not do; a smooth drill was under-loaded
Building the skeleton is usually within reach in-house; writing decision criteria at a usable granularity and designing drill scenarios is where teams stall without prior experience. Pottech works on the design and operation of medical information systems and advises on governance and guideline compliance. If going it alone is difficult, contact us. For the supplier side of the equation, What Is an ISMS (ISO/IEC 27001)? is a useful companion.
References and Sources
- Guidelines for the Safe Management of Medical Information Systems | MHLW
- FY2026 Medical Fee Revision | MHLW
- Personal Information Protection Commission
- Information-technology Promotion Agency (IPA)
- National center of Incident readiness and Strategy for Cybersecurity (NISC)
Note: reimbursement requirements are given concrete form by notices and Q&A and are subject to revision. Confirm the current text with MHLW publications.