Back to Columns
EMR9 min read

The Three Ministries' Two Guidelines Explained Simply: Essential Checks When Adopting an EMR

July 2, 2026

The Three Ministries' Two Guidelines Explained Simply: Essential Checks When Adopting an EMR
Share this article

When you consider adopting an EMR or a cloud service, you are certain to come across the term "the Three Ministries' Two Guidelines." However, many find it hard to grasp what exactly they stipulate and what a medical institution should check. This article explains what the Three Ministries' Two Guidelines are in an easy-to-understand way and organizes the points you must check when adopting an EMR.

What Are the Three Ministries' Two Guidelines?

The "Three Ministries' Two Guidelines" is a collective term for two guidelines established by three ministries to handle medical information safely. Their characteristic is that they present the roles of the medical institution side and the system provider side separately for the safe management of medical information systems.

TargetGuidelineJurisdiction
Medical institutionsGuidelines for the Safe Management of Medical Information SystemsMinistry of Health, Labour and Welfare
System/service providersSafety Management Guidelines for Providers of Information Systems and Services Handling Medical InformationMinistry of Economy, Trade and Industry; Ministry of Internal Affairs and Communications

There was a period when the Ministry of Internal Affairs and Communications and the Ministry of Economy, Trade and Industry issued separate guidelines, so it was called "the Three Ministries' Four Guidelines." The two have since been integrated, and the current framework is "the Three Ministries' Two Guidelines."

Why They Matter

An EMR gathers extremely sensitive personal information such as patients' names, diagnoses, and test results. If these are leaked, tampered with, or lost, it harms not only patients but also seriously affects the trust in the medical institution. The Three Ministries' Two Guidelines present the "standards to be observed" for protecting medical information from such risks, and they form the foundation for operating an EMR safely.

Three Basic Principles for the Medical Institution Side

The Ministry of Health, Labour and Welfare's guideline sets out, for electronically stored medical information, meeting the following "three principles of electronic storage" as fundamental:

  • Authenticity: records are created under proper authority, it is clear who created/revised them and when, and they have not been tampered with
  • Readability: content can be displayed or output in a form legible to the naked eye whenever needed
  • Preservability: records are stored in a restorable state throughout the statutory retention period

In addition, operational safety management is required, such as access-permission management, authentication via passwords, backups, and countermeasures against cyberattacks. In recent years, against the backdrop of increasing cyberattacks, the importance of these measures has risen further.

Checkpoints When Adopting an EMR

1. Whether the Product/Provider Complies with the Guidelines

First, confirm that the EMR or cloud service under consideration complies with the provider-side guideline. Ask the vendor to clearly state its "compliance status with the Three Ministries' Two Guidelines."

2. Whether the Point of Responsibility Demarcation (Role Allocation) Is Clear

In the cloud model, the "point of responsibility demarcation"—how far the provider handles security measures and where the medical institution's responsibility begins—is important. Confirm it in the contract and service specifications.

3. Whether the Medical Institution Can Establish Operational Rules

Even if you adopt a guideline-compliant product, it is meaningless without accompanying in-house operational rules such as password management, access permissions, and deleting the accounts of departing staff. Establish your operational structure together with adoption.

4. Backup and Business Continuity

Confirm that there are mechanisms for data backup and recovery to prepare for failures and cyberattacks.

Note That the Guidelines Are Updated

The Three Ministries' Two Guidelines are continuously revised in response to technological progress and new threats. For the medical-institution-facing "Guidelines for the Safe Management of Medical Information Systems," the latest version (Ver. 7.0) has been published. At adoption and during operation, it is important to always refer to the latest version and the official Q&A.

AI Karte's Compliance with the Guidelines

The AI-native EMR "AI Karte" is provided in a cloud environment compliant with the Three Ministries' Two Guidelines, equipped with the mechanisms necessary for safe management, such as access-permission management, authentication, and backups. While consolidating patient information on a single foundation with its integrated receipt computer (rececon), features such as voice input and AI claim checking can also be used safely within the same security standards. We also explain the point of responsibility demarcation and operational structure individually at adoption.

Conclusion

The Three Ministries' Two Guidelines consist of two guidelines—one for medical institutions and one for providers—and present standards for safely protecting medical information. When adopting an EMR, it is essential to check the compliance status of the product/provider, the point of responsibility demarcation, in-house operational rules, and the backup structure, and to refer to the latest version of the guidelines as well. Safe management is not something that ends at adoption; regard it as something to review continuously.

Through providing AI Karte, Pottech aims to be the ideal business partner for clinics—improving the working environment for physicians, nurses, and medical clerical staff, and supporting clinics in fully realizing what they want to achieve.

For more details, please feel free to contact us.

References

Share this article

Related Articles

EMR

How to Avoid EMR Vendor Lock-In: Contracts, Data, and Standards

Many clinics discover only when attempting to switch that data cannot be extracted, migration costs were unbudgeted, or the contract term still runs. We break lock-in into three layers—data, functionality, and contract—then organize what to verify before signing and the role standards play.

August 10, 2026
EMR

What a Hospital-Grade AI-Native EMR Must Deliver

The role an AI-native EMR plays in a hospital differs from a clinic. The goal is not unstaffed operation but trimming peripheral work by profession to create time with patients and room to think. We organize the functions each profession needs, the cross-cutting requirements of permissions, departmental integration, and availability, and how to approach deployment.

August 10, 2026
EMR

Why Hospital and Clinic EMRs Differ So Much: A Comparison of Design Philosophies

Hospital and clinic electronic medical records share a name but are different products. Where does the divergence come from? We trace it to four sources—the correlation with organizational structure described by Conway's law, the differing time axes of outpatient and ward care, the separation of decision-maker from user, and revenue structure.

August 10, 2026
EMR

EMR Data Migration Aligned with Standard Requirements: HL7 FHIR, SS-MIX2, and Standard Codes

EMR data migration changes significantly when data conforms to standards (HL7 FHIR, SS-MIX2, standard codes). Based on EMR information standardization and the standard-type EMR, this article organizes migration methods, steps, and limitations aligned with the standard requirements, referencing official MHLW information.

August 2, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

AI Karte as an Option

Most of the problems covered in this article are what AI Karte, our AI-native EHR for clinics, is built to handle. Start by seeing what it is.