For healthcare companies
ISMS (ISO/IEC 27001) Certification Support
Challenges
Do any of these sound familiar?
Healthcare handles highly sensitive information, and partners increasingly require proof of an information security framework. Yet a first-time certification comes with familiar worries.
Don't know where to start
The standard's requirements are abstract and hard to operationalize.
Not enough resources
No dedicated staff, and unsure you can run it alongside daily work.
Documentation is heavy
Building policies, registers, and training from scratch isn't realistic.
Unclear how to pick an auditor
Where, at what cost, and how to engage is opaque.
Healthcare-specific concerns
Industry requirements like the 3-Ministry guidelines add uncertainty.
Pottech takes all of this on.
We provide templates and project management to minimize your burden and target certification in about 6 months.
About ISMS
What is ISMS — and why healthcare needs it
Overview of ISMS (ISO/IEC 27001)
An ISMS (Information Security Management System) is the framework for managing information assets and continuously maintaining their confidentiality, integrity, and availability. Its international standard is ISO/IEC 27001.
Certification by a third-party audit body provides objective, external proof that your information security framework is properly established.
Why healthcare companies need it
A condition of doing business
Certification is increasingly a prerequisite for business with hospitals, pharma, and government bodies.
Handling sensitive information
Patient data, clinical information, and PHR carry high breach impact, so proving your framework directly builds trust.
Stronger governance
Move from person-dependent operations to rule-based continuous improvement (PDCA).
Bridge to industry guidelines
Requirements like the 3-Ministry 2-Guidelines can be addressed efficiently starting from your ISMS documents.
Service
Overview of Pottech's support
We support the full path to certification — from design to audit response. You focus on the decisions; Pottech leads documentation, project management, and communication with the audit body.
Training materials can be created by Pottech (included), and Pottech can serve as your internal auditor — so you can proceed even without dedicated in-house staff.
Process
Path to certification (standard 6 months)
We work toward a new certification in about 6 months from kickoff (timing varies by organization size and current state).
Goals & planning
~2 weeksDecide scope, structure, and annual plan; begin auditor selection
Risk analysis
~1 monthInventory assets, run risk assessment, decide treatment policy
Rule development
~4 monthsPolicy and objectives, regulations, statement of applicability, incident flow
Controls & training
parallel with ③Implement technical and operational controls; deliver training (to 100%)
Internal audit & fixes
~2 weeksRun internal audit, correct nonconformities, management review
Audit (stage 1 & 2)
~1 monthStage 1 (1–2 days) → Stage 2 (2–3 days) → certification
From year 2: operations support
We continue to support reviews of roles and scope, risk-assessment updates, internal audits, and surveillance and renewal audits.
Structure
Project structure & roles
ISMS operation requires you to assign the roles the standard calls for. We explain each role and where Pottech can stand in.
Solving "no dedicated staff"
Pottech can serve as your internal audit lead and internal auditor, so you can focus on appointing management and the ISMS lead and staff.
Deliverables
Documents & deliverables we prepare
Based on Pottech's templates, tailored to your actual situation. There's no need to start from scratch.
Policy, planning & structure
- ›Information security policy / objectives table
- ›Org chart (roles, responsibilities, authority list)
- ›Statement of Applicability (context and scope)
Risk management & operating rules
- ›Risk assessment procedure / asset risk-assessment sheet
- ›Information security management rules (full internal ruleset)
- ›Incident reporting flow and report templates
- ›Related-laws list / monitoring scope definition
Outsourcing & continuity
- ›Vendor list / checklist
- ›Business continuity plan & SLA
Training, audit & improvement
- ›Information security training materials (managers / staff)
- ›Internal audit plan, checklist, results
- ›Corrective-action reports / management review minutes
Audit Body
Audit-body selection support
Certification is granted after an audit by a third-party body. Pottech obtains comparative quotes from multiple bodies and helps you choose one suited to your size and approach (fees vary by headcount, etc.).
* The above are examples. We can also obtain and compare quotes from other bodies such as JUSE, JSA-SOL, and ICMS.
Pricing
Pricing plans
All prices exclude tax. Assumes an organization of up to about 50 people and documentation following our provided templates.
① New certification support (first time)
ISMS new certification support
Delivered using our provided document templates. Assumes up to ~50 people.
- (Option) Stage-1 attendance — full day, 1 day¥100K
- (Option) Stage-2 attendance — full day, 2 days¥200K
② Operations support (from year 2)
ISMS operations support
Ongoing support for reviewing roles/scope, updating risk assessment, internal audit, and surveillance/renewal audits.
Other options
* Payments to the audit body (audit fees) are not included. We obtain comparative quotes and present them to you.
Why Pottech
Why Pottech — a healthcare-focused track record
Healthcare-focused expertise
We understand clinical workflows and data — online care, PHR, SaMD, trial ePRO, hospital SaaS, and more.
Bridge to industry guidelines
We address industry requirements like the 3-Ministry guidelines with minimal effort, linked to ISMS documents.
Both documentation and engineering
Beyond documents, we can advise on technical controls including product design and development.
Selected engagements
Option
Option: 3-Ministry 2-Guideline support
When providing systems or services to medical institutions, you may be required to comply with the "Guidelines for the Safe Management of Healthcare Information Systems" (3-Ministry 2-Guidelines). Pottech supports efficient compliance integrated with your ISMS.
Common concerns
- ›The guidelines are complex — it's unclear how far you must go to count as "compliant."
- ›Handling ISMS and the 3-Ministry guidelines separately makes documents and management unwieldy.
Pottech's approach
- We recommend the optimal, minimal-effort approach for your product and organization.
- We keep documents to a minimum and link required technical controls to your ISMS.
- We support communication with medical institutions at rollout (minutes), disclosure documents, and risk-response lists.
Rough timeline: about 4 months from kickoff (risk analysis ▶ defining technical requirements ▶ documentation & operation).
FAQ
Frequently asked questions
How long does certification take?
A new certification in about 6 months is standard. It varies by size and current state, and expedited delivery is available as an option.
Is it okay if we have no dedicated security staff?
No problem. Pottech leads documentation and project management, and can also serve as your internal audit lead and auditor.
Up to what headcount is the price flat?
Up to about 50 people. Beyond that, or for special requirements, we provide an individual quote.
Are payments to the audit body included?
No. Audit fees are separate; we obtain comparative quotes and present them to you.
We've already started some security measures. Can we use them?
Yes. We review your existing efforts and documents, use what we can, and fill the gaps.
Can we also request 3-Ministry 2-Guideline support at the same time?
Yes. Integrating it with your ISMS documents keeps management from becoming unwieldy.
Get in Touch About AI Karte
Ask us anything about AI Karte, our AI-native electronic health record for clinics — key features, pricing plans, or how adoption works. Demo requests are welcome.