Back to Columns
Healthcare Security13 min read

Requirements for External Storage of Medical Information: What Can Leave the Hospital

September 14, 2026

Requirements for External Storage of Medical Information: What Can Leave the Hospital
Share this article

Cloud EMRs, remote image interpretation, offsite backup services, outsourced document storage — all of these move clinical records, or information equivalent to them, outside the hospital. These are ordinary choices today. But "records may be held externally" is not the same as "hold them anywhere without thinking."

Hospitals are obliged to retain clinical records for defined periods. Where that retention is electronic, and where it happens outside the hospital, there are requirements to be met. Sign a contract without settling them and, when something goes wrong, the question of who was discharging the retention obligation becomes murky — leaving room for the shortfall to be characterised as the hospital's management failure.

This article sets out what a hospital should verify when medical information is stored externally: the regulatory frame, and then what to secure by contract. For comparing cloud providers see Selecting a Cloud Provider; for internal arrangements, Cloud Security for Healthcare Organisations.

Disclaimer: This article is general information. The authoritative sources for retention obligations and external storage are the Medical Practitioners Act, the Medical Care Act and related law, together with MHLW notifications and the guidelines themselves. Confirm specific cases with the relevant authority and your counsel. Anything marked "confirm against primary sources" must be checked there.

Three Principles That Come First

Where medical information is stored electronically, the MHLW Guidelines for the Safe Management of Medical Information Systems require three things: authenticity, legibility, and preservability. These hold whether or not storage is external, so they precede the external-storage question.

PrincipleMeaningWhat is asked in practice
AuthenticityThe record is unaltered and its author is clearCan you trace who recorded what, when, and what was amended? Design of finalisation and revision history
LegibilityIt can be retrieved promptly, in readable form, when neededIs there a way to view records during an outage? Can you meet audit and disclosure requests?
PreservabilityIt remains restorable for the required periodHow do you handle media decay, format obsolescence, and a vendor exiting the market?

Preservability is the one external storage stresses. With an on-premises server it is a question of media and backups. Move offsite and two further questions attach: will the provider stay in business, and can you get the data back when the contract ends? The essential difficulty of external storage is that it turns into a question of business continuity and contract law, not technical reliability.

Legibility also takes on a second face. "Unavailable when the network drops" is a legibility problem. Decide how far you will go — a local cache of recent records, periodic printed output, a documented switch to paper — and put it in the design. See Hospital Incident Response Plans and A BCP for Cyberattacks.

The Conditions for Storing Externally

MHLW has set out the treatment of external storage of clinical records by notification, revised several times. Storage over telecommunications lines — cloud — is possible under stated conditions, and most hospitals now select systems on that basis.

What a hospital must verify reduces to roughly four points.

IssueWhat to verify
LocationWhether the storage location falls within what is permitted; confirm the provider's and the data's location in writing
ResponsibilityUnderstanding that the retention obligation remains the hospital's even when storage is external
SafeguardsWhether the provider's measures follow the METI/MIC provider guidelines
Contractual backingWhether the above appear as contract clauses, not only in a proposal or a verbal assurance

The second matters most. Storing externally does not transfer the retention obligation to the provider. If records are lost, cannot be retrieved, or their integrity cannot be explained, the hospital answers for it. So you need a means of verifying that retention is actually being performed properly rather than assuming it.

For the detailed conditions, the notifications and the guidelines themselves are authoritative. Any specific judgement about a permitted location or method must rest on the primary sources and confirmation from the relevant authority (confirm against primary sources). This article organises what to treat as an issue when designing the contract and the operation.

What the Contract Must Secure

External storage is as much a contractual question as a technical one. Check that each of the following appears in the agreement or a memorandum, not merely in a proposal.

AreaWhat the contract should say
Data locationCountry/region for production, backups and logs separately
SafeguardsThe guidelines followed, and a mapping table giving the performing party for each requirement
AccessWhich of the provider's personnel can reach your data, and how that is recorded
SubcontractingWhether permitted, prior consent or notice, responsibility for subcontractors
PreservabilityRetention period, generation management, handling of media and format obsolescence
AvailabilityRTO/RPO, and how records can be viewed during a network outage
Audit and reportingAnnual reporting obligation; conditions for accepting audit
TerminationReturn format, coverage, deadline, cost, migration cooperation, deletion and its evidence

Provider exit is specific to external storage. With an on-premises server, the media stay in your building whatever happens to the vendor. Externally, the provider's continuity is your preservability. Look for a clause such as twelve months' notice of service termination plus an obligation to assist with migration.

Data return also behaves differently here. It is not simply getting the data back; the question is whether the returned data still satisfies the three principles. A CSV export without revision history makes authenticity hard to evidence. Specify at contract stage that audit logs are within the return scope. See Questions to Ask Your Vendor and Security Requirements for EMR Replacement.

Extra Questions Cloud Raises

1. Location is dynamic. Multi-region redundancy is standard. Production may be domestic while backups or logs sit elsewhere. Ask about production, backups and logs separately.

2. Operator location is its own issue. Data held domestically but administered by staff at an overseas site is, in effect, accessible across the border. Round-the-clock monitoring from abroad is common, so ask who touches it.

3. The subcontracting chain is deep. Behind your provider sit the platform, monitoring, a CDN, outsourced development. Without visibility, you cannot locate the cause of an incident. See Supply Chain Risk for Hospitals.

4. Certification scope must be checked. Many providers hold ISO/IEC 27001 or 27017 — but whether the service you buy falls within the certified scope is a separate fact. Proposals presenting a platform's certificate as the provider's own do exist. See What Is an ISMS? and The Shared Responsibility Model for AI EMRs.

Backups and the fee criteria

Level 1 of the FY2026 electronic clinical information coordination system development addition requires backups by multiple methods, part of them held offline. That requirement rests on the hospital even where storage is external.

Official Q&A indicates that backup to a logically separated area within a cloud service, where prompt recovery is possible, also satisfies it — so using cloud is not a barrier. But a copy into another bucket in the same account is lost with the account. Confirm with the provider that the architecture genuinely constitutes a logically separated area. See Backup Design for Hospitals: the 3-2-1 Rule and The FY2026 Fee Revision.

Decisions to Make Internally

  1. Who verifies that storage is being performed properly — naturally part of the medical information system safety management officer's duties: receiving the provider's annual report, reviewing it, and retaining the record
  2. How you operate during a network outage — external storage depends on connectivity. Document how care continues offline: printed output of recent records, the switch to paper, and how entries are caught up afterwards
  3. How you answer disclosure requests and audits — know the procedure and the elapsed days for retrieving externally stored data

The second only works if you rehearse it. Having a runbook and being able to act are different things. See Designing Staff Security Training and Exercises.

Conclusion

  1. Whether or not storage is external, you must satisfy authenticity, legibility and preservability
  2. External storage loads the weight onto preservability — a question of the provider's continuity and of contract, not of media
  3. The retention obligation does not transfer. The hospital answers for it and needs a means of verification
  4. Check the contract, not the proposal — especially notice of service termination and migration assistance
  5. Ask whether returned data still satisfies the three principles; include audit logs in the return scope
  6. Cloud adds residency, operator location, subcontracting depth, and certification scope
  7. Internally, settle who verifies, how you run during an outage, and how you meet disclosure requests

Judging permissibility involves interpreting the rules, which requires primary sources and the relevant authority. Designing contract terms and the questions you put to providers, however, can be prepared in advance. For a review of existing contracts or requirements ahead of a replacement, contact us.

References and Sources

Note: retention obligations and the treatment of external storage are governed by the relevant statutes and MHLW notifications and guidelines, and change with revisions. Base any specific judgement on the primary sources and confirmation from the relevant authority.

Share this article

Related Articles

Healthcare Security

Access Control and Privileged ID Management: What Is Realistic in a Hospital

Role-based permissions, least privilege, offboarding and transfer reviews, vendor maintenance accounts, and what to do where shared IDs genuinely cannot be eliminated. Access design that actually limits blast radius within the constraints of clinical work.

September 14, 2026
Healthcare Security

Antivirus and EDR: What a Hospital Should Decide Before Buying

How EDR differs from conventional antivirus, why it is not a product that protects you simply by being installed, how to choose an operating model for the alerts it produces, what to do about devices it cannot be installed on, and what to settle before you buy.

September 14, 2026
Healthcare Security

Logging and Audit Trails: Getting Past 'We Collect It but Nobody Looks'

What to log, how long to retain it, and the real problem — logs collected but never read. Which logs actually matter during an incident, and how to make review a sustainable routine in a hospital with limited staff.

September 14, 2026
Healthcare Security

Backup Design for Hospitals: The 3-2-1 Rule and the Tier 1 Requirement

Japan's FY2026 revision makes multi-method backup with part of it held offline a tier 1 requirement. We cover the three methods accepted as meeting it — external media, automated transfer to a permanently detached NAS, and a logically separated area within a cloud service — plus generation management and why an untested backup does not count.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.