Hospitals where security stalls tend to share a conversation: "IT handles it", "the vendor is presumably watching", "we have a committee, but it mostly covers EHR training". None of these is wrong, and yet nobody is looking at the whole.
The structure stays hidden until something happens, because in peacetime it looks as though someone is doing something. When systems actually stop, it surfaces all at once: no one to decide, information not arriving, decisions not reaching the floor.
Japan's FY2026 fee revision made a dedicated medical information system safety manager a common requirement of the new coordinated electronic clinical information add-on. Governance is now being asked about from the regulatory side as well.
This article covers how to build — or rebuild — that structure, with particular attention to what is possible when there is one IT person, or none dedicated at all.
Disclaimer: General information. Reimbursement requirements and guideline obligations are governed by MHLW notices and the Guidelines themselves. Confirm requirements for the safety manager role against primary sources.
Decide Accountability First
It is tempting to start by drawing an organisation chart. It works better to decide who is accountable first, because filling in roles first mass-produces titles without authority.
| Role | Who | Accountability | Outsourceable? |
|---|---|---|---|
| Ultimate accountability | Hospital director / board chair | Final responsibility; investment and disclosure decisions | No |
| Medical information system safety manager | Deputy director, head of administration or of IT | Overall safety management, driving guideline compliance; the add-on requires a dedicated appointment | No |
| Operational lead | IT staff | Day-to-day operations, monitoring, vendor liaison | Partly |
| Departmental champions | One person per department | Cascading information, surfacing real practice | No |
Confirm how "dedicated" is interpreted against primary sources. Secondary commentary varies on whether the role can be combined with others and on qualification requirements; building a structure on unverified premises means rebuilding it later. See The Medical Information Safety Manager Role.
What matters is giving the safety manager real authority: involvement in procurement and system replacement, involvement in the decision to stop systems, and a reporting line into the executive meeting. Without those three, neither vendors nor departments will act on their requests.
Constituting a Committee
Most hospitals already have a medical information committee. It is more realistic to ask what to add to the existing one than to create another.
| Element | Works | Becomes theatre |
|---|---|---|
| Chair | Director or deputy director | The IT staff member |
| Membership | One each from medicine, nursing, administration, IT, patient safety | IT only |
| Frequency | Regular (several times a year) plus ad hoc | Once a year, reporting only |
| Agenda | Matters requiring a decision | Status reports only |
| Minutes | Decisions, owners, deadlines | Loose notes |
| Escalation | Regular reporting to the executive meeting | None |
Always put decisions on the agenda. Report-only committees lose attendance with every meeting. What to do about unpatchable equipment, whether to fund something this year, whether to change a rule — real decisions keep a committee alive.
Connecting to the patient safety committee helps: a reporting culture already exists there. The habit of reporting near-misses transfers directly, as does the principle that reporting is not punished (see Phishing Simulations).
A Realistic Design for a One-Person IT Department
A 200-bed hospital with one IT person, who also covers billing or general affairs, is unremarkable. Here is what "build a structure" can realistically mean.
First, decompose what is concentrated in one person.
| Function | Concentrated state | Direction |
|---|---|---|
| Day-to-day support | Everything lands here | Distribute first-line to departmental champions |
| Vendor management | One person negotiates with all vendors | Move contracting and procurement to administration |
| Monitoring and log review | Never gets done | Automate, or outsource |
| Decisions | Carried alone | Escalate to the safety manager and committee |
| Documentation | Always deferred | Provide templates; embed records in the work |
Second, separate what can and cannot be outsourced.
| Function | Outsourceable | Why |
|---|---|---|
| Being accountable | No | Accountability does not transfer |
| Deciding | No | Requires knowledge of the institution |
| Monitoring and detection | Yes | Round-the-clock coverage is impractical in-house |
| Vulnerability intelligence and assessment | Yes | Specialised and continuous |
| Configuration and build work | Yes | Hands-on work can move outside |
| Documentation | Yes | Adapt templates to your institution |
| Drill design and facilitation | Yes | Experience matters |
Third, decide what you will not do. Attempting everything to the same depth with one person produces uniform mediocrity. Prioritise, and have the committee agree and minute where this year's line falls. That is not negligence; it is documented risk acceptance.
See How to Use the MHLW Security Checklist and Outsourcing Guideline Compliance.
Getting Executives Involved
The decisive factor is whether executives see security as theirs. The Guidelines' separate governance volume exists precisely to be read by this group.
Explanations that land are translated into management terms, not technical ones.
| Framing | Example |
|---|---|
| Revenue | "Meeting the security requirements qualifies us for the higher tier under the FY2026 revision; otherwise we fall to the lower tier or cannot claim" |
| Cost of downtime | "A day of suspended care costs roughly X. The recovery period cannot be estimated" |
| Accountability | "If this happens, the executive team explains it to patients and the region" |
| Framing the spend | "This is capital investment and also a billing requirement" |
| Making status visible | Present the checklist results in two colours: done, not done |
The reimbursement angle is the easiest entry. Security shifting from cost to billing requirement changes the decision frame itself. See Key Points of the FY2026 Fee Revision.
Ask executives for three things specifically: receive and approve an annual report; decide explicitly where the authority to stop systems sits; and make the investment decisions rather than leaving them to IT.
Keeping the Structure Alive
| When | Activity | Record |
|---|---|---|
| Start of year | Annual plan, approved by the committee | The plan |
| Quarterly | Privilege review, vulnerability status | Review records |
| Through the year | Training and drills | Completion records |
| Second half | Restoration test, tabletop exercise | Test records, elapsed times |
| Year end | Summary and report to executives | Report, improvement plan |
Records are not only for auditors. They are the only means of handing over when the person changes — which makes them most valuable in exactly the one-person hospitals that find them hardest to keep.
This annual cycle is structurally the same PDCA a supplier runs under an information security management system; knowing that framework helps you see what to ask of them. See What Is an ISMS (ISO/IEC 27001)?.
Conclusion
- Decide accountability before drawing the chart
- Give the safety manager real authority: procurement, the stop decision, and a line to the executive meeting
- Add to the existing committee, put decisions on the agenda, and borrow the patient safety reporting culture
- With one IT person, decompose functions, outsource what can move, and decide what you will not do — minuting the acceptance
- Translate for executives; the billing requirement is the easiest entry point
- Run an annual cycle and record it — records are the only handover mechanism
An outside view speeds this up. Pottech advises on governance and operating rules from the standpoint of building and running medical information systems — contact us. Where you need suppliers to hold certification, see ISMS Certification Support.
References and Sources
- Guidelines for the Safe Management of Medical Information Systems | MHLW
- FY2026 Medical Fee Revision | MHLW
- Information-technology Promotion Agency (IPA)
- Personal Information Protection Commission
Note: requirements for the safety manager role, the meaning of "dedicated", and the add-on criteria are given concrete form by notices and Q&A and are subject to change. Confirm with MHLW publications.