Back to Columns
Healthcare Security13 min read

Building a Security Governance Structure in a Hospital, Including One-Person IT Departments

September 14, 2026

Building a Security Governance Structure in a Hospital, Including One-Person IT Departments
Share this article

Hospitals where security stalls tend to share a conversation: "IT handles it", "the vendor is presumably watching", "we have a committee, but it mostly covers EHR training". None of these is wrong, and yet nobody is looking at the whole.

The structure stays hidden until something happens, because in peacetime it looks as though someone is doing something. When systems actually stop, it surfaces all at once: no one to decide, information not arriving, decisions not reaching the floor.

Japan's FY2026 fee revision made a dedicated medical information system safety manager a common requirement of the new coordinated electronic clinical information add-on. Governance is now being asked about from the regulatory side as well.

This article covers how to build — or rebuild — that structure, with particular attention to what is possible when there is one IT person, or none dedicated at all.

Disclaimer: General information. Reimbursement requirements and guideline obligations are governed by MHLW notices and the Guidelines themselves. Confirm requirements for the safety manager role against primary sources.

Decide Accountability First

It is tempting to start by drawing an organisation chart. It works better to decide who is accountable first, because filling in roles first mass-produces titles without authority.

RoleWhoAccountabilityOutsourceable?
Ultimate accountabilityHospital director / board chairFinal responsibility; investment and disclosure decisionsNo
Medical information system safety managerDeputy director, head of administration or of ITOverall safety management, driving guideline compliance; the add-on requires a dedicated appointmentNo
Operational leadIT staffDay-to-day operations, monitoring, vendor liaisonPartly
Departmental championsOne person per departmentCascading information, surfacing real practiceNo

Confirm how "dedicated" is interpreted against primary sources. Secondary commentary varies on whether the role can be combined with others and on qualification requirements; building a structure on unverified premises means rebuilding it later. See The Medical Information Safety Manager Role.

What matters is giving the safety manager real authority: involvement in procurement and system replacement, involvement in the decision to stop systems, and a reporting line into the executive meeting. Without those three, neither vendors nor departments will act on their requests.

Constituting a Committee

Most hospitals already have a medical information committee. It is more realistic to ask what to add to the existing one than to create another.

ElementWorksBecomes theatre
ChairDirector or deputy directorThe IT staff member
MembershipOne each from medicine, nursing, administration, IT, patient safetyIT only
FrequencyRegular (several times a year) plus ad hocOnce a year, reporting only
AgendaMatters requiring a decisionStatus reports only
MinutesDecisions, owners, deadlinesLoose notes
EscalationRegular reporting to the executive meetingNone

Always put decisions on the agenda. Report-only committees lose attendance with every meeting. What to do about unpatchable equipment, whether to fund something this year, whether to change a rule — real decisions keep a committee alive.

Connecting to the patient safety committee helps: a reporting culture already exists there. The habit of reporting near-misses transfers directly, as does the principle that reporting is not punished (see Phishing Simulations).

A Realistic Design for a One-Person IT Department

A 200-bed hospital with one IT person, who also covers billing or general affairs, is unremarkable. Here is what "build a structure" can realistically mean.

First, decompose what is concentrated in one person.

FunctionConcentrated stateDirection
Day-to-day supportEverything lands hereDistribute first-line to departmental champions
Vendor managementOne person negotiates with all vendorsMove contracting and procurement to administration
Monitoring and log reviewNever gets doneAutomate, or outsource
DecisionsCarried aloneEscalate to the safety manager and committee
DocumentationAlways deferredProvide templates; embed records in the work

Second, separate what can and cannot be outsourced.

FunctionOutsourceableWhy
Being accountableNoAccountability does not transfer
DecidingNoRequires knowledge of the institution
Monitoring and detectionYesRound-the-clock coverage is impractical in-house
Vulnerability intelligence and assessmentYesSpecialised and continuous
Configuration and build workYesHands-on work can move outside
DocumentationYesAdapt templates to your institution
Drill design and facilitationYesExperience matters

Third, decide what you will not do. Attempting everything to the same depth with one person produces uniform mediocrity. Prioritise, and have the committee agree and minute where this year's line falls. That is not negligence; it is documented risk acceptance.

See How to Use the MHLW Security Checklist and Outsourcing Guideline Compliance.

Getting Executives Involved

The decisive factor is whether executives see security as theirs. The Guidelines' separate governance volume exists precisely to be read by this group.

Explanations that land are translated into management terms, not technical ones.

FramingExample
Revenue"Meeting the security requirements qualifies us for the higher tier under the FY2026 revision; otherwise we fall to the lower tier or cannot claim"
Cost of downtime"A day of suspended care costs roughly X. The recovery period cannot be estimated"
Accountability"If this happens, the executive team explains it to patients and the region"
Framing the spend"This is capital investment and also a billing requirement"
Making status visiblePresent the checklist results in two colours: done, not done

The reimbursement angle is the easiest entry. Security shifting from cost to billing requirement changes the decision frame itself. See Key Points of the FY2026 Fee Revision.

Ask executives for three things specifically: receive and approve an annual report; decide explicitly where the authority to stop systems sits; and make the investment decisions rather than leaving them to IT.

Keeping the Structure Alive

WhenActivityRecord
Start of yearAnnual plan, approved by the committeeThe plan
QuarterlyPrivilege review, vulnerability statusReview records
Through the yearTraining and drillsCompletion records
Second halfRestoration test, tabletop exerciseTest records, elapsed times
Year endSummary and report to executivesReport, improvement plan

Records are not only for auditors. They are the only means of handing over when the person changes — which makes them most valuable in exactly the one-person hospitals that find them hardest to keep.

This annual cycle is structurally the same PDCA a supplier runs under an information security management system; knowing that framework helps you see what to ask of them. See What Is an ISMS (ISO/IEC 27001)?.

Conclusion

  1. Decide accountability before drawing the chart
  2. Give the safety manager real authority: procurement, the stop decision, and a line to the executive meeting
  3. Add to the existing committee, put decisions on the agenda, and borrow the patient safety reporting culture
  4. With one IT person, decompose functions, outsource what can move, and decide what you will not do — minuting the acceptance
  5. Translate for executives; the billing requirement is the easiest entry point
  6. Run an annual cycle and record it — records are the only handover mechanism

An outside view speeds this up. Pottech advises on governance and operating rules from the standpoint of building and running medical information systems — contact us. Where you need suppliers to hold certification, see ISMS Certification Support.

References and Sources

Note: requirements for the safety manager role, the meaning of "dedicated", and the add-on criteria are given concrete form by notices and Q&A and are subject to change. Confirm with MHLW publications.

Share this article

Related Articles

Healthcare Security

Access Control and Privileged ID Management: What Is Realistic in a Hospital

Role-based permissions, least privilege, offboarding and transfer reviews, vendor maintenance accounts, and what to do where shared IDs genuinely cannot be eliminated. Access design that actually limits blast radius within the constraints of clinical work.

September 14, 2026
Healthcare Security

Antivirus and EDR: What a Hospital Should Decide Before Buying

How EDR differs from conventional antivirus, why it is not a product that protects you simply by being installed, how to choose an operating model for the alerts it produces, what to do about devices it cannot be installed on, and what to settle before you buy.

September 14, 2026
Healthcare Security

Logging and Audit Trails: Getting Past 'We Collect It but Nobody Looks'

What to log, how long to retain it, and the real problem — logs collected but never read. Which logs actually matter during an incident, and how to make review a sustainable routine in a hospital with limited staff.

September 14, 2026
Healthcare Security

Backup Design for Hospitals: The 3-2-1 Rule and the Tier 1 Requirement

Japan's FY2026 revision makes multi-method backup with part of it held offline a tier 1 requirement. We cover the three methods accepted as meeting it — external media, automated transfer to a permanently detached NAS, and a logically separated area within a cloud service — plus generation management and why an untested backup does not count.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.