Back to Columns
Healthcare Security12 min read

The Medical Information System Security Manager: Role and Appointment

September 14, 2026

The Medical Information System Security Manager: Role and Appointment
Share this article

The medical information system security manager has, in many institutions, been a name on an organisation chart. The administrator's name appears in the procedure; in practice the IT person runs things on personal judgement. That arrangement is common.

Japan's FY2026 fee revision changed it. The common requirements of the new electronic clinical information coordination add-on include the appointment of a dedicated medical information system security manager. Writing a name is no longer enough: that person's time has to be carved out, which is a staffing decision.

The practical questions start there. Who should be appointed? Does it have to be a physician? Can the role be combined with others? Who carries it in a small clinic? This article works through them. For the add-on and the four-part structure of the guidelines, see Key Points of Edition 6.0.

Disclaimer: This article is general information. The authoritative sources are the MHLW's published text, notices, and Q&A. Base filing decisions on current notices and confirmation from your Regional Bureau of Health and Welfare.

Why "Dedicated" Entered the Requirement

The FY2026 revision abolished the medical information acquisition add-on and the healthcare DX promotion structure add-on, merging them into the new add-on, and transferred in the cybersecurity requirements previously attached to medical records management structure add-on 1. For the shape of the revision, see FY2026 Fee Revision: Cross-Specialty Changes.

The inpatient tiers:

TierPointsRequirements
Tier 1160Common requirements + multi-method backups (some offline) + a cyberattack BCP with drills
Tier 280Common requirements only

The common requirements are two:

  • Compliance with the Guidelines for the Safe Management of Medical Information Systems
  • A dedicated medical information system security manager

Their pairing is the point. Compliance means documents and operations are in order — but without someone maintaining that continuously, an institution simply gets itself in order for the filing date and then drifts. Read plainly, "dedicated" is a demand that the institution resource the maintenance.

Specific qualification requirements and any transitional deadlines circulate in secondary explanations but could not be confirmed against primary material here (verify against the primary text).

What the Role Actually Does

The title suggests a technical role. In practice most of the work is coordination and record-keeping. Vendors carry much of the technology; the manager's value lies in getting decisions made internally, keeping them running, and keeping the institution able to explain itself.

Across a year:

CadenceWorkOutput
OngoingApproving account issuance and suspension; vendor liaisonRequest and approval records
OngoingReceiving incidents and near-misses; first-line judgementResponse records
Monthly–quarterlyConfirming backup results and log review findingsReview records
AnnualUpdating the asset register; reviewing access rightsUpdated register, review results
AnnualRevisiting the risk assessment; organising untreated risksRisk table, draft acceptance decisions
AnnualRunning staff training and tracking completionPer-person training records
AnnualChecking suppliers (contracts, certification validity and scope)Supplier list and verification records
At least annualReporting to the executiveMinutes
At least annualBCP drills (where claiming tier 1)Drill records and improvements

Little of this requires deep specialist knowledge. Most of it is "do the agreed thing, by the due date, leaving a record" — which means someone with the habit of deadlines and documentation suits the role.

There is one thing that must not be handed to the manager: the final decision to accept an untreated risk. That belongs to the executive; the manager's job ends at presenting it in a form that can be decided. Blurring this creates a structure where the manager quietly shelves controls for lack of budget and is personally blamed after an incident. See The Governance Part.

Who to Appoint

CandidateStrengthsWeaknessesMitigation
Administrator / head of administrationInternal standing; short reporting line to the boardLimited technical judgement; heavily loaded, so hard to make dedicatedBuild a route for technical questions to vendors or outside advisers
IT / medical informatics staffKnows what is actually runningOften lacks authority over clinical departmentsPut the authority in writing and make executive backing visible
A physician with informatics interestCan judge clinical impact; persuasive internallyClinical duties make time hard to securePut an operational deputy underneath; keep the manager on judgement
Health information managerRecords expertise; fits logging and access control naturallyInfrastructure knowledge needed separatelyDefine the vendor interface for infrastructure
External hireSecures the expertiseTakes time to learn the institution and its relationshipsPair with the administrator for the first months

The condition common to every candidate is authority. If the manager says "change this setting" or "stop doing this" and it does not happen, the role does not exist. Put the following in writing at the point of appointment:

  1. The manager's scope of authority — what they can halt, what they can require
  2. The reporting line — who they can report to directly, and how many layers intervene
  3. The duties lifted — if the role is dedicated, who absorbs the current workload
  4. The deputy — who judges when the manager is absent

The fourth is treated lightly but matters: incidents do not wait for the manager to be at their desk. Without a named first-line judge for nights and weekends, the initial response stalls. See The System Operations Part and Building an Incident Response Plan.

How to Treat Dual-Hatting

The most frequent question. Two separate issues sit inside it.

Issue 1: under the guidelines

The guidelines require the role to exist, while allowing a structure proportionate to the size of the facility. A small practice where the administrator also carries the role is not, in itself, ruled out. What matters is whether the role is actually being discharged.

Issue 2: "dedicated" as a billing requirement

The word "dedicated" in the add-on's common requirements must be read more strictly. To claim it, you need to be able to show that safety management is positioned as that person's work, with time secured for it.

A workable way to sort this by situation:

Your situationApproach
Claiming the add-on (inpatient)Plan on a staffing arrangement that satisfies "dedicated"; the decision sits with the executive
Not planning to claimThe guideline role must still exist; a combined role can work if duties and time are explicit
Considering claiming laterStand the role up as a combined role first, measure the actual workload, then decide on dedication

The third path fits many institutions. Measuring what the role actually involves is better input to a staffing decision than a guess. Run the annual work list above for six months and record the hours.

How "dedicated" is judged in practice — how much other work is tolerated — is the kind of point clarified through official Q&A. Confirm current notices and check with your Regional Bureau before filing.

Making It Work in a Small Clinic

A ten-person clinic often cannot realistically staff a dedicated manager. But the role is needed regardless of size: the guidelines apply to "all those involved in the introduction, operation, use, maintenance, and disposal of medical information systems," whatever the size or type of facility.

Three ways to make it work.

1. Break the role apart and share it

Imagining one omnicompetent person guarantees failure. Decomposed, the work distributes.

WorkWho carries it in a small practice
Deciding (policy, risk acceptance, budget)The director — not delegable
Running (register updates, reviews, training, records)The administrator or lead administrative staff
Technical execution (backup configuration, patching, equipment refresh)The vendor — settled in the contract
Confirming technical adequacyThe vendor or an outside third party

That leaves two people needed internally: someone to decide and someone to run. Appointing the director or administrator as manager and distributing the execution is the realistic shape.

2. Narrow what you take on

Trying to fix everything at once stalls. The first two things for a small practice are backups and access control — the two most directly tied to outcomes when something goes wrong. See Guideline Compliance for Small Clinics: How Far to Go.

3. Put what the vendor carries into the contract

In a small practice, technical work is almost entirely vendor-dependent. The problem is not the dependence but that it is not written down. Converting "backups are presumably handled" into "taking, retaining, and restore-testing backups is the provider's responsibility, reported monthly" changes the quality of the arrangement on its own. See Demarcating Responsibility and Security Check Sheets for Vendors.

Still, and it bears repeating: outsourcing does not transfer the institution's responsibility. Vendor compliance with the METI/MIC guidelines is a precondition, not a defence. See The Three Ministries' Two Guidelines Explained and, for the vendor-side certification regime, What Is an ISMS (ISO/IEC 27001)?.

Conclusion

  1. FY2026 made a dedicated medical information system security manager a common requirement of the new add-on. A name on a chart is no longer enough
  2. Most of the role is coordination and record-keeping. The habit of deadlines and documentation matters more than deep expertise
  3. Do not hand the manager the decision to accept untreated risk. That is executive work; the manager prepares it for decision
  4. At appointment, put authority, reporting line, duties lifted, and deputy in writing. A manager without authority writes reports
  5. Separate the guideline role from "dedicated" as a billing requirement. Without a claim in view, a combined role can work
  6. In a small practice, split the role into decider, runner, and vendor. Start with backups and access control
  7. The practical test for "dedicated," qualification requirements, and any transitional measures require verification against primary sources before filing

Who to appoint and how much to delegate depends heavily on your institution. If you would like to talk through role design or structuring ahead of filing, get in touch. For the practitioner side, see The Planning and Management Part and The System Operations Part.

References and Sources

Note: the guidelines are revised and fee requirements clarified through official Q&A. This article reflects material published at the time of writing.

Share this article

Related Articles

Healthcare Security

Access Control and Privileged ID Management: What Is Realistic in a Hospital

Role-based permissions, least privilege, offboarding and transfer reviews, vendor maintenance accounts, and what to do where shared IDs genuinely cannot be eliminated. Access design that actually limits blast radius within the constraints of clinical work.

September 14, 2026
Healthcare Security

Antivirus and EDR: What a Hospital Should Decide Before Buying

How EDR differs from conventional antivirus, why it is not a product that protects you simply by being installed, how to choose an operating model for the alerts it produces, what to do about devices it cannot be installed on, and what to settle before you buy.

September 14, 2026
Healthcare Security

Logging and Audit Trails: Getting Past 'We Collect It but Nobody Looks'

What to log, how long to retain it, and the real problem — logs collected but never read. Which logs actually matter during an incident, and how to make review a sustainable routine in a hospital with limited staff.

September 14, 2026
Healthcare Security

Backup Design for Hospitals: The 3-2-1 Rule and the Tier 1 Requirement

Japan's FY2026 revision makes multi-method backup with part of it held offline a tier 1 requirement. We cover the three methods accepted as meeting it — external media, automated transfer to a permanently detached NAS, and a logically separated area within a cloud service — plus generation management and why an untested backup does not count.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.