Back to Columns
AI & DX13 min read

Implementing the Three-Ministry Guidelines: Practical Steps, Accountability, and Risk Assessment

July 28, 2026

Implementing the Three-Ministry Guidelines: Practical Steps, Accountability, and Risk Assessment
Share this article

For an overview of "what the guidelines are," see the companion article (The Three Ministries' Two Guidelines Explained Simply). This article goes one step further, organizing the concrete steps a medical institution takes to implement compliance, around accountability boundaries and a risk-based approach. It is written for the practitioners and IT staff who adopt and operate EMRs, AI EMRs, and cloud services.

Disclaimer: This article is general information, not legal or professional advice. Guidelines may be amended; confirm the latest primary sources and consult experts.

The big picture: two responsibilities, risk-based thinking

The framework imposes duties on both the institution and the provider.

  • Institution (administrator) responsibility: safe management under MHLW's "Guidelines for the Safe Management of Medical Information Systems, Ver. 6.0" (Governance / Management / Operations volumes).
  • Provider responsibility: measures under the METI/MIC "Guidelines for Safe Management by Providers Handling Medical Information."

Crucially, Ver. 6.0 takes a risk-based approach: rather than meeting everything uniformly, assess your assets, threats, and impact, and prioritize. That mindset is the starting point of implementation.

Step 1: Scope and asset inventory

Define "what you are protecting." Map where patient data flows—EMR, billing, booking/intake, imaging, AI EMR, backups, external integrations (systems, devices, network, contractors)—and make it visible as an asset register. Ambiguity here makes everything downstream ambiguous.

Step 2: Risk assessment

For each asset, evaluate threats and vulnerabilities across confidentiality, integrity, and availability, and rate risk by likelihood and impact. Prioritize on "would care stop?" and "could data leak?"

Step 3: Safeguards (four categories)

CategoryMain content
OrganizationalRoles/structure, policies, inspection/audit, incident response
HumanTraining, confidentiality, privilege-appropriate operation
PhysicalServer/device siting, access control, theft/removal prevention
TechnicalAccess control/authentication, encryption, logging, anti-malware, network boundary

Step 4: The three storage principles

For electronic storage, meet authenticity (prevent tampering/impersonation; clear accountability), legibility (readable on demand), and preservation (recoverable through the retention period). In AI EMRs, distinguishing AI-generated drafts from physician-finalized records, and logging finalization (who, when), are key to authenticity.

Step 5: Network boundary and online eligibility verification

Since April 2023, online eligibility verification became, in principle, mandatory for insured medical institutions, making network-connection security a premise for nearly all facilities. Revisit boundary design (closed networks, VPN, perimeter defense, endpoint measures) per the Operations volume of Ver. 6.0.

Step 6: Vendor selection and contracts (accountability boundary)

When using cloud services, clarify where the provider's duty ends and the institution's operational responsibility begins. Confirm and agree on:

  • Guideline compliance and third-party certification (ISMS = ISO/IEC 27001, ISO/IEC 27017, ISMAP)
  • Data location (domestic/overseas), encryption, and key management
  • Audit rights and audit-log provision; incident notification and response
  • SLA (availability, recovery targets) and support scope
  • Data return/erasure at contract termination

Step 7: Audit logs, access control, BCP/incident response

Record "who accessed what, when, and did what" in a tamper-evident form and review regularly. Control access with least privilege, and prepare a BCP for disasters/outages/attacks (degraded/offline operation, backups, recovery procedures) plus an incident response structure. Ransomware drills help.

Step 8: Training and continuous review (PDCA)

Safe management is not "set once." Review your risk assessment and controls periodically as guidelines, systems, and threats change. MHLW also publishes checklists useful for annual review.

Integrating with ISMS (ISO/IEC 27001)

Compliance aligns well with ISMS: run risk assessment, safeguards, and PDCA as a shared mechanism to avoid double management while gaining objective certification. Designing compliance as a "continuous system," not a one-off, is efficient in practice.

Conclusion

Implementation is not filling in a checklist; design it as a system that clarifies accountability, prioritizes by risk, and reviews continuously.

Pottech provides ISMS certification support, three-ministry guideline compliance support, and AI-native healthcare system development. See also Designing Security for an AI EMR.

References

This article is general information, not legal or professional advice. Confirm the latest primary sources and consult experts.

Share this article

Related Articles

AI & DX

AI Tools That Support Physicians: Voice Input, Summarization, Literature Search, and Chart Creation

Voice input during consultations, drafting referral letters and certificates, literature search, patient explanation materials. What AI can take on in a physician's work sits around documentation and research. We organize the division of roles between general-purpose AI and healthcare-specific AI (the AI EMR), representative tools, and the line on patient information.

September 7, 2026
AI & DX

AI Tools for Clinic Marketing and Website Operations: Review Replies, Column Drafts, and Image Creation

Replying to reviews, drafting website columns, making signage and social images, writing patient FAQs—the writing and making side of attracting patients is where generative AI can take the first draft. We cover representative tools, how to use them, and the clinic-specific cautions: medical advertising rules and fact-checking.

September 7, 2026
AI & DX

AI Tools for Clinic Back-Office Work: Documents, Meeting Minutes, Email, and Translation in Practice

The fastest wins from AI in a clinic come from back-office work that contains no patient information. For each task—drafting internal documents, meeting minutes, patient-facing notices, foreign-language signage, monthly tallies—we cover which tools to use, how to use them, and where the line falls on what must never be entered.

September 7, 2026
AI & DX

AI Tools for Clinic Reception and Patient Contact: AI Phone, Chatbots, Web Intake, and Multilingual Support

Reception is where calls, inquiries, intake, and payment all arrive at once—and where AI's effect shows up most clearly in numbers. We cover five areas—AI phone answering, chatbots such as LINE, AI intake, translation devices and apps, and booking guidance—explaining where the burden actually falls, an adoption order that protects the patient experience, and how to handle personal information.

September 7, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

AI Karte as an Option

Most of the problems covered in this article are what AI Karte, our AI-native EHR for clinics, is built to handle. Start by seeing what it is.