The medical information system security manager has, in many institutions, been a name on an organisation chart. The administrator's name appears in the procedure; in practice the IT person runs things on personal judgement. That arrangement is common.
Japan's FY2026 fee revision changed it. The common requirements of the new electronic clinical information coordination add-on include the appointment of a dedicated medical information system security manager. Writing a name is no longer enough: that person's time has to be carved out, which is a staffing decision.
The practical questions start there. Who should be appointed? Does it have to be a physician? Can the role be combined with others? Who carries it in a small clinic? This article works through them. For the add-on and the four-part structure of the guidelines, see Key Points of Edition 6.0.
Disclaimer: This article is general information. The authoritative sources are the MHLW's published text, notices, and Q&A. Base filing decisions on current notices and confirmation from your Regional Bureau of Health and Welfare.
Why "Dedicated" Entered the Requirement
The FY2026 revision abolished the medical information acquisition add-on and the healthcare DX promotion structure add-on, merging them into the new add-on, and transferred in the cybersecurity requirements previously attached to medical records management structure add-on 1. For the shape of the revision, see FY2026 Fee Revision: Cross-Specialty Changes.
The inpatient tiers:
| Tier | Points | Requirements |
|---|---|---|
| Tier 1 | 160 | Common requirements + multi-method backups (some offline) + a cyberattack BCP with drills |
| Tier 2 | 80 | Common requirements only |
The common requirements are two:
- Compliance with the Guidelines for the Safe Management of Medical Information Systems
- A dedicated medical information system security manager
Their pairing is the point. Compliance means documents and operations are in order — but without someone maintaining that continuously, an institution simply gets itself in order for the filing date and then drifts. Read plainly, "dedicated" is a demand that the institution resource the maintenance.
Specific qualification requirements and any transitional deadlines circulate in secondary explanations but could not be confirmed against primary material here (verify against the primary text).
What the Role Actually Does
The title suggests a technical role. In practice most of the work is coordination and record-keeping. Vendors carry much of the technology; the manager's value lies in getting decisions made internally, keeping them running, and keeping the institution able to explain itself.
Across a year:
| Cadence | Work | Output |
|---|---|---|
| Ongoing | Approving account issuance and suspension; vendor liaison | Request and approval records |
| Ongoing | Receiving incidents and near-misses; first-line judgement | Response records |
| Monthly–quarterly | Confirming backup results and log review findings | Review records |
| Annual | Updating the asset register; reviewing access rights | Updated register, review results |
| Annual | Revisiting the risk assessment; organising untreated risks | Risk table, draft acceptance decisions |
| Annual | Running staff training and tracking completion | Per-person training records |
| Annual | Checking suppliers (contracts, certification validity and scope) | Supplier list and verification records |
| At least annual | Reporting to the executive | Minutes |
| At least annual | BCP drills (where claiming tier 1) | Drill records and improvements |
Little of this requires deep specialist knowledge. Most of it is "do the agreed thing, by the due date, leaving a record" — which means someone with the habit of deadlines and documentation suits the role.
There is one thing that must not be handed to the manager: the final decision to accept an untreated risk. That belongs to the executive; the manager's job ends at presenting it in a form that can be decided. Blurring this creates a structure where the manager quietly shelves controls for lack of budget and is personally blamed after an incident. See The Governance Part.
Who to Appoint
| Candidate | Strengths | Weaknesses | Mitigation |
|---|---|---|---|
| Administrator / head of administration | Internal standing; short reporting line to the board | Limited technical judgement; heavily loaded, so hard to make dedicated | Build a route for technical questions to vendors or outside advisers |
| IT / medical informatics staff | Knows what is actually running | Often lacks authority over clinical departments | Put the authority in writing and make executive backing visible |
| A physician with informatics interest | Can judge clinical impact; persuasive internally | Clinical duties make time hard to secure | Put an operational deputy underneath; keep the manager on judgement |
| Health information manager | Records expertise; fits logging and access control naturally | Infrastructure knowledge needed separately | Define the vendor interface for infrastructure |
| External hire | Secures the expertise | Takes time to learn the institution and its relationships | Pair with the administrator for the first months |
The condition common to every candidate is authority. If the manager says "change this setting" or "stop doing this" and it does not happen, the role does not exist. Put the following in writing at the point of appointment:
- The manager's scope of authority — what they can halt, what they can require
- The reporting line — who they can report to directly, and how many layers intervene
- The duties lifted — if the role is dedicated, who absorbs the current workload
- The deputy — who judges when the manager is absent
The fourth is treated lightly but matters: incidents do not wait for the manager to be at their desk. Without a named first-line judge for nights and weekends, the initial response stalls. See The System Operations Part and Building an Incident Response Plan.
How to Treat Dual-Hatting
The most frequent question. Two separate issues sit inside it.
Issue 1: under the guidelines
The guidelines require the role to exist, while allowing a structure proportionate to the size of the facility. A small practice where the administrator also carries the role is not, in itself, ruled out. What matters is whether the role is actually being discharged.
Issue 2: "dedicated" as a billing requirement
The word "dedicated" in the add-on's common requirements must be read more strictly. To claim it, you need to be able to show that safety management is positioned as that person's work, with time secured for it.
A workable way to sort this by situation:
| Your situation | Approach |
|---|---|
| Claiming the add-on (inpatient) | Plan on a staffing arrangement that satisfies "dedicated"; the decision sits with the executive |
| Not planning to claim | The guideline role must still exist; a combined role can work if duties and time are explicit |
| Considering claiming later | Stand the role up as a combined role first, measure the actual workload, then decide on dedication |
The third path fits many institutions. Measuring what the role actually involves is better input to a staffing decision than a guess. Run the annual work list above for six months and record the hours.
How "dedicated" is judged in practice — how much other work is tolerated — is the kind of point clarified through official Q&A. Confirm current notices and check with your Regional Bureau before filing.
Making It Work in a Small Clinic
A ten-person clinic often cannot realistically staff a dedicated manager. But the role is needed regardless of size: the guidelines apply to "all those involved in the introduction, operation, use, maintenance, and disposal of medical information systems," whatever the size or type of facility.
Three ways to make it work.
1. Break the role apart and share it
Imagining one omnicompetent person guarantees failure. Decomposed, the work distributes.
| Work | Who carries it in a small practice |
|---|---|
| Deciding (policy, risk acceptance, budget) | The director — not delegable |
| Running (register updates, reviews, training, records) | The administrator or lead administrative staff |
| Technical execution (backup configuration, patching, equipment refresh) | The vendor — settled in the contract |
| Confirming technical adequacy | The vendor or an outside third party |
That leaves two people needed internally: someone to decide and someone to run. Appointing the director or administrator as manager and distributing the execution is the realistic shape.
2. Narrow what you take on
Trying to fix everything at once stalls. The first two things for a small practice are backups and access control — the two most directly tied to outcomes when something goes wrong. See Guideline Compliance for Small Clinics: How Far to Go.
3. Put what the vendor carries into the contract
In a small practice, technical work is almost entirely vendor-dependent. The problem is not the dependence but that it is not written down. Converting "backups are presumably handled" into "taking, retaining, and restore-testing backups is the provider's responsibility, reported monthly" changes the quality of the arrangement on its own. See Demarcating Responsibility and Security Check Sheets for Vendors.
Still, and it bears repeating: outsourcing does not transfer the institution's responsibility. Vendor compliance with the METI/MIC guidelines is a precondition, not a defence. See The Three Ministries' Two Guidelines Explained and, for the vendor-side certification regime, What Is an ISMS (ISO/IEC 27001)?.
Conclusion
- FY2026 made a dedicated medical information system security manager a common requirement of the new add-on. A name on a chart is no longer enough
- Most of the role is coordination and record-keeping. The habit of deadlines and documentation matters more than deep expertise
- Do not hand the manager the decision to accept untreated risk. That is executive work; the manager prepares it for decision
- At appointment, put authority, reporting line, duties lifted, and deputy in writing. A manager without authority writes reports
- Separate the guideline role from "dedicated" as a billing requirement. Without a claim in view, a combined role can work
- In a small practice, split the role into decider, runner, and vendor. Start with backups and access control
- The practical test for "dedicated," qualification requirements, and any transitional measures require verification against primary sources before filing
Who to appoint and how much to delegate depends heavily on your institution. If you would like to talk through role design or structuring ahead of filing, get in touch. For the practitioner side, see The Planning and Management Part and The System Operations Part.
References and Sources
- Guidelines for the Safe Management of Medical Information Systems | MHLW
- Edition 6.0 full text (PDF) | MHLW
- On the FY2026 medical fee revision | MHLW
- Personal Information Protection Commission
- Information-technology Promotion Agency (IPA)
Note: the guidelines are revised and fee requirements clarified through official Q&A. This article reflects material published at the time of writing.