For an overview of "what the guidelines are," see the companion article (The Three Ministries' Two Guidelines Explained Simply). This article goes one step further, organizing the concrete steps a medical institution takes to implement compliance, around accountability boundaries and a risk-based approach. It is written for the practitioners and IT staff who adopt and operate EMRs, AI EMRs, and cloud services.
Disclaimer: This article is general information, not legal or professional advice. Guidelines may be amended; confirm the latest primary sources and consult experts.
The big picture: two responsibilities, risk-based thinking
The framework imposes duties on both the institution and the provider.
- Institution (administrator) responsibility: safe management under MHLW's "Guidelines for the Safe Management of Medical Information Systems, Ver. 6.0" (Governance / Management / Operations volumes).
- Provider responsibility: measures under the METI/MIC "Guidelines for Safe Management by Providers Handling Medical Information."
Crucially, Ver. 6.0 takes a risk-based approach: rather than meeting everything uniformly, assess your assets, threats, and impact, and prioritize. That mindset is the starting point of implementation.
Step 1: Scope and asset inventory
Define "what you are protecting." Map where patient data flows—EMR, billing, booking/intake, imaging, AI EMR, backups, external integrations (systems, devices, network, contractors)—and make it visible as an asset register. Ambiguity here makes everything downstream ambiguous.
Step 2: Risk assessment
For each asset, evaluate threats and vulnerabilities across confidentiality, integrity, and availability, and rate risk by likelihood and impact. Prioritize on "would care stop?" and "could data leak?"
Step 3: Safeguards (four categories)
| Category | Main content |
|---|---|
| Organizational | Roles/structure, policies, inspection/audit, incident response |
| Human | Training, confidentiality, privilege-appropriate operation |
| Physical | Server/device siting, access control, theft/removal prevention |
| Technical | Access control/authentication, encryption, logging, anti-malware, network boundary |
Step 4: The three storage principles
For electronic storage, meet authenticity (prevent tampering/impersonation; clear accountability), legibility (readable on demand), and preservation (recoverable through the retention period). In AI EMRs, distinguishing AI-generated drafts from physician-finalized records, and logging finalization (who, when), are key to authenticity.
Step 5: Network boundary and online eligibility verification
Since April 2023, online eligibility verification became, in principle, mandatory for insured medical institutions, making network-connection security a premise for nearly all facilities. Revisit boundary design (closed networks, VPN, perimeter defense, endpoint measures) per the Operations volume of Ver. 6.0.
Step 6: Vendor selection and contracts (accountability boundary)
When using cloud services, clarify where the provider's duty ends and the institution's operational responsibility begins. Confirm and agree on:
- Guideline compliance and third-party certification (ISMS = ISO/IEC 27001, ISO/IEC 27017, ISMAP)
- Data location (domestic/overseas), encryption, and key management
- Audit rights and audit-log provision; incident notification and response
- SLA (availability, recovery targets) and support scope
- Data return/erasure at contract termination
Step 7: Audit logs, access control, BCP/incident response
Record "who accessed what, when, and did what" in a tamper-evident form and review regularly. Control access with least privilege, and prepare a BCP for disasters/outages/attacks (degraded/offline operation, backups, recovery procedures) plus an incident response structure. Ransomware drills help.
Step 8: Training and continuous review (PDCA)
Safe management is not "set once." Review your risk assessment and controls periodically as guidelines, systems, and threats change. MHLW also publishes checklists useful for annual review.
Integrating with ISMS (ISO/IEC 27001)
Compliance aligns well with ISMS: run risk assessment, safeguards, and PDCA as a shared mechanism to avoid double management while gaining objective certification. Designing compliance as a "continuous system," not a one-off, is efficient in practice.
Conclusion
Implementation is not filling in a checklist; design it as a system that clarifies accountability, prioritizes by risk, and reviews continuously.
Pottech provides ISMS certification support, three-ministry guideline compliance support, and AI-native healthcare system development. See also Designing Security for an AI EMR.
References
- MHLW, "Guidelines for the Safe Management of Medical Information Systems, Ver. 6.0 (Overview)"
- MHLW, "Cybersecurity Checklist for Medical Institutions (FY2025)"
This article is general information, not legal or professional advice. Confirm the latest primary sources and consult experts.
