When you consider adopting an EMR or a cloud service, you are certain to come across the term "the Three Ministries' Two Guidelines." However, many find it hard to grasp what exactly they stipulate and what a medical institution should check. This article explains what the Three Ministries' Two Guidelines are in an easy-to-understand way and organizes the points you must check when adopting an EMR.
What Are the Three Ministries' Two Guidelines?
The "Three Ministries' Two Guidelines" is a collective term for two guidelines established by three ministries to handle medical information safely. Their characteristic is that they present the roles of the medical institution side and the system provider side separately for the safe management of medical information systems.
| Target | Guideline | Jurisdiction |
|---|---|---|
| Medical institutions | Guidelines for the Safe Management of Medical Information Systems | Ministry of Health, Labour and Welfare |
| System/service providers | Safety Management Guidelines for Providers of Information Systems and Services Handling Medical Information | Ministry of Economy, Trade and Industry; Ministry of Internal Affairs and Communications |
There was a period when the Ministry of Internal Affairs and Communications and the Ministry of Economy, Trade and Industry issued separate guidelines, so it was called "the Three Ministries' Four Guidelines." The two have since been integrated, and the current framework is "the Three Ministries' Two Guidelines."
Why They Matter
An EMR gathers extremely sensitive personal information such as patients' names, diagnoses, and test results. If these are leaked, tampered with, or lost, it harms not only patients but also seriously affects the trust in the medical institution. The Three Ministries' Two Guidelines present the "standards to be observed" for protecting medical information from such risks, and they form the foundation for operating an EMR safely.
Three Basic Principles for the Medical Institution Side
The Ministry of Health, Labour and Welfare's guideline sets out, for electronically stored medical information, meeting the following "three principles of electronic storage" as fundamental:
- Authenticity: records are created under proper authority, it is clear who created/revised them and when, and they have not been tampered with
- Readability: content can be displayed or output in a form legible to the naked eye whenever needed
- Preservability: records are stored in a restorable state throughout the statutory retention period
In addition, operational safety management is required, such as access-permission management, authentication via passwords, backups, and countermeasures against cyberattacks. In recent years, against the backdrop of increasing cyberattacks, the importance of these measures has risen further.
Checkpoints When Adopting an EMR
1. Whether the Product/Provider Complies with the Guidelines
First, confirm that the EMR or cloud service under consideration complies with the provider-side guideline. Ask the vendor to clearly state its "compliance status with the Three Ministries' Two Guidelines."
2. Whether the Point of Responsibility Demarcation (Role Allocation) Is Clear
In the cloud model, the "point of responsibility demarcation"—how far the provider handles security measures and where the medical institution's responsibility begins—is important. Confirm it in the contract and service specifications.
3. Whether the Medical Institution Can Establish Operational Rules
Even if you adopt a guideline-compliant product, it is meaningless without accompanying in-house operational rules such as password management, access permissions, and deleting the accounts of departing staff. Establish your operational structure together with adoption.
4. Backup and Business Continuity
Confirm that there are mechanisms for data backup and recovery to prepare for failures and cyberattacks.
Note That the Guidelines Are Updated
The Three Ministries' Two Guidelines are continuously revised in response to technological progress and new threats. For the medical-institution-facing "Guidelines for the Safe Management of Medical Information Systems," the latest version (Ver. 7.0) has been published. At adoption and during operation, it is important to always refer to the latest version and the official Q&A.
AI Karte's Compliance with the Guidelines
The AI-native EMR "AI Karte" is provided in a cloud environment compliant with the Three Ministries' Two Guidelines, equipped with the mechanisms necessary for safe management, such as access-permission management, authentication, and backups. While consolidating patient information on a single foundation with its integrated receipt computer (rececon), features such as voice input and AI claim checking can also be used safely within the same security standards. We also explain the point of responsibility demarcation and operational structure individually at adoption.
Conclusion
The Three Ministries' Two Guidelines consist of two guidelines—one for medical institutions and one for providers—and present standards for safely protecting medical information. When adopting an EMR, it is essential to check the compliance status of the product/provider, the point of responsibility demarcation, in-house operational rules, and the backup structure, and to refer to the latest version of the guidelines as well. Safe management is not something that ends at adoption; regard it as something to review continuously.
Through providing AI Karte, Pottech aims to be the ideal business partner for clinics—improving the working environment for physicians, nurses, and medical clerical staff, and supporting clinics in fully realizing what they want to achieve.
For more details, please feel free to contact us.
References
- Guidelines for the Safe Management of Medical Information Systems, Ver. 7.0 (Ministry of Health, Labour and Welfare)
- Safety Management Guidelines for Providers of Information Systems and Services Handling Medical Information, Ver. 2.0 (Ministry of Economy, Trade and Industry; Ministry of Internal Affairs and Communications)
