Cloud EMRs, remote image interpretation, offsite backup services, outsourced document storage — all of these move clinical records, or information equivalent to them, outside the hospital. These are ordinary choices today. But "records may be held externally" is not the same as "hold them anywhere without thinking."
Hospitals are obliged to retain clinical records for defined periods. Where that retention is electronic, and where it happens outside the hospital, there are requirements to be met. Sign a contract without settling them and, when something goes wrong, the question of who was discharging the retention obligation becomes murky — leaving room for the shortfall to be characterised as the hospital's management failure.
This article sets out what a hospital should verify when medical information is stored externally: the regulatory frame, and then what to secure by contract. For comparing cloud providers see Selecting a Cloud Provider; for internal arrangements, Cloud Security for Healthcare Organisations.
Disclaimer: This article is general information. The authoritative sources for retention obligations and external storage are the Medical Practitioners Act, the Medical Care Act and related law, together with MHLW notifications and the guidelines themselves. Confirm specific cases with the relevant authority and your counsel. Anything marked "confirm against primary sources" must be checked there.
Three Principles That Come First
Where medical information is stored electronically, the MHLW Guidelines for the Safe Management of Medical Information Systems require three things: authenticity, legibility, and preservability. These hold whether or not storage is external, so they precede the external-storage question.
| Principle | Meaning | What is asked in practice |
|---|---|---|
| Authenticity | The record is unaltered and its author is clear | Can you trace who recorded what, when, and what was amended? Design of finalisation and revision history |
| Legibility | It can be retrieved promptly, in readable form, when needed | Is there a way to view records during an outage? Can you meet audit and disclosure requests? |
| Preservability | It remains restorable for the required period | How do you handle media decay, format obsolescence, and a vendor exiting the market? |
Preservability is the one external storage stresses. With an on-premises server it is a question of media and backups. Move offsite and two further questions attach: will the provider stay in business, and can you get the data back when the contract ends? The essential difficulty of external storage is that it turns into a question of business continuity and contract law, not technical reliability.
Legibility also takes on a second face. "Unavailable when the network drops" is a legibility problem. Decide how far you will go — a local cache of recent records, periodic printed output, a documented switch to paper — and put it in the design. See Hospital Incident Response Plans and A BCP for Cyberattacks.
The Conditions for Storing Externally
MHLW has set out the treatment of external storage of clinical records by notification, revised several times. Storage over telecommunications lines — cloud — is possible under stated conditions, and most hospitals now select systems on that basis.
What a hospital must verify reduces to roughly four points.
| Issue | What to verify |
|---|---|
| Location | Whether the storage location falls within what is permitted; confirm the provider's and the data's location in writing |
| Responsibility | Understanding that the retention obligation remains the hospital's even when storage is external |
| Safeguards | Whether the provider's measures follow the METI/MIC provider guidelines |
| Contractual backing | Whether the above appear as contract clauses, not only in a proposal or a verbal assurance |
The second matters most. Storing externally does not transfer the retention obligation to the provider. If records are lost, cannot be retrieved, or their integrity cannot be explained, the hospital answers for it. So you need a means of verifying that retention is actually being performed properly rather than assuming it.
For the detailed conditions, the notifications and the guidelines themselves are authoritative. Any specific judgement about a permitted location or method must rest on the primary sources and confirmation from the relevant authority (confirm against primary sources). This article organises what to treat as an issue when designing the contract and the operation.
What the Contract Must Secure
External storage is as much a contractual question as a technical one. Check that each of the following appears in the agreement or a memorandum, not merely in a proposal.
| Area | What the contract should say |
|---|---|
| Data location | Country/region for production, backups and logs separately |
| Safeguards | The guidelines followed, and a mapping table giving the performing party for each requirement |
| Access | Which of the provider's personnel can reach your data, and how that is recorded |
| Subcontracting | Whether permitted, prior consent or notice, responsibility for subcontractors |
| Preservability | Retention period, generation management, handling of media and format obsolescence |
| Availability | RTO/RPO, and how records can be viewed during a network outage |
| Audit and reporting | Annual reporting obligation; conditions for accepting audit |
| Termination | Return format, coverage, deadline, cost, migration cooperation, deletion and its evidence |
Provider exit is specific to external storage. With an on-premises server, the media stay in your building whatever happens to the vendor. Externally, the provider's continuity is your preservability. Look for a clause such as twelve months' notice of service termination plus an obligation to assist with migration.
Data return also behaves differently here. It is not simply getting the data back; the question is whether the returned data still satisfies the three principles. A CSV export without revision history makes authenticity hard to evidence. Specify at contract stage that audit logs are within the return scope. See Questions to Ask Your Vendor and Security Requirements for EMR Replacement.
Extra Questions Cloud Raises
1. Location is dynamic. Multi-region redundancy is standard. Production may be domestic while backups or logs sit elsewhere. Ask about production, backups and logs separately.
2. Operator location is its own issue. Data held domestically but administered by staff at an overseas site is, in effect, accessible across the border. Round-the-clock monitoring from abroad is common, so ask who touches it.
3. The subcontracting chain is deep. Behind your provider sit the platform, monitoring, a CDN, outsourced development. Without visibility, you cannot locate the cause of an incident. See Supply Chain Risk for Hospitals.
4. Certification scope must be checked. Many providers hold ISO/IEC 27001 or 27017 — but whether the service you buy falls within the certified scope is a separate fact. Proposals presenting a platform's certificate as the provider's own do exist. See What Is an ISMS? and The Shared Responsibility Model for AI EMRs.
Backups and the fee criteria
Level 1 of the FY2026 electronic clinical information coordination system development addition requires backups by multiple methods, part of them held offline. That requirement rests on the hospital even where storage is external.
Official Q&A indicates that backup to a logically separated area within a cloud service, where prompt recovery is possible, also satisfies it — so using cloud is not a barrier. But a copy into another bucket in the same account is lost with the account. Confirm with the provider that the architecture genuinely constitutes a logically separated area. See Backup Design for Hospitals: the 3-2-1 Rule and The FY2026 Fee Revision.
Decisions to Make Internally
- Who verifies that storage is being performed properly — naturally part of the medical information system safety management officer's duties: receiving the provider's annual report, reviewing it, and retaining the record
- How you operate during a network outage — external storage depends on connectivity. Document how care continues offline: printed output of recent records, the switch to paper, and how entries are caught up afterwards
- How you answer disclosure requests and audits — know the procedure and the elapsed days for retrieving externally stored data
The second only works if you rehearse it. Having a runbook and being able to act are different things. See Designing Staff Security Training and Exercises.
Conclusion
- Whether or not storage is external, you must satisfy authenticity, legibility and preservability
- External storage loads the weight onto preservability — a question of the provider's continuity and of contract, not of media
- The retention obligation does not transfer. The hospital answers for it and needs a means of verification
- Check the contract, not the proposal — especially notice of service termination and migration assistance
- Ask whether returned data still satisfies the three principles; include audit logs in the return scope
- Cloud adds residency, operator location, subcontracting depth, and certification scope
- Internally, settle who verifies, how you run during an outage, and how you meet disclosure requests
Judging permissibility involves interpreting the rules, which requires primary sources and the relevant authority. Designing contract terms and the questions you put to providers, however, can be prepared in advance. For a review of existing contracts or requirements ahead of a replacement, contact us.
References and Sources
- Guidelines for the Safe Management of Medical Information Systems | MHLW
- Guidelines, edition 6.0 (PDF) | MHLW
- FY2026 Fee Revision | MHLW
- Personal Information Protection Commission
- Information-technology Promotion Agency (IPA)
Note: retention obligations and the treatment of external storage are governed by the relevant statutes and MHLW notifications and guidelines, and change with revisions. Base any specific judgement on the primary sources and confirmation from the relevant authority.