ISMS / ISO・IEC 27001

For healthcare companies

ISMS (ISO/IEC 27001) Certification Support

Your first certification, in 6 months.

Challenges

Do any of these sound familiar?

Healthcare handles highly sensitive information, and partners increasingly require proof of an information security framework. Yet a first-time certification comes with familiar worries.

01

Don't know where to start

The standard's requirements are abstract and hard to operationalize.

02

Not enough resources

No dedicated staff, and unsure you can run it alongside daily work.

03

Documentation is heavy

Building policies, registers, and training from scratch isn't realistic.

04

Unclear how to pick an auditor

Where, at what cost, and how to engage is opaque.

05

Healthcare-specific concerns

Industry requirements like the 3-Ministry guidelines add uncertainty.

Pottech takes all of this on.

We provide templates and project management to minimize your burden and target certification in about 6 months.

About ISMS

What is ISMS — and why healthcare needs it

Overview of ISMS (ISO/IEC 27001)

An ISMS (Information Security Management System) is the framework for managing information assets and continuously maintaining their confidentiality, integrity, and availability. Its international standard is ISO/IEC 27001.

Certification by a third-party audit body provides objective, external proof that your information security framework is properly established.

Why healthcare companies need it

1

A condition of doing business

Certification is increasingly a prerequisite for business with hospitals, pharma, and government bodies.

2

Handling sensitive information

Patient data, clinical information, and PHR carry high breach impact, so proving your framework directly builds trust.

3

Stronger governance

Move from person-dependent operations to rule-based continuous improvement (PDCA).

4

Bridge to industry guidelines

Requirements like the 3-Ministry 2-Guidelines can be addressed efficiently starting from your ISMS documents.

Service

Overview of Pottech's support

We support the full path to certification — from design to audit response. You focus on the decisions; Pottech leads documentation, project management, and communication with the audit body.

Overall design & planning
What Pottech does: Designing scope, structure, and schedule; building the annual plan
What we ask of you: Management buy-in, deciding stakeholders
Documentation
What Pottech does: Drafting policies, registers, and statements from templates
What we ask of you: Reviewing and approving your information
Risk assessment
What Pottech does: Inventorying assets, evaluating risk, and organizing treatment policy
What we ask of you: Providing asset information
Staff training
What Pottech does: Creating and delivering role-based and all-staff materials (included)
What we ask of you: Completing training (to 100%)
Audit-body response
What Pottech does: Obtaining comparative quotes, selection support, attending the audit (option)
What we ask of you: Final choice of audit body
Internal audit
What Pottech does: Planning and running the audit, organizing corrective actions
What we ask of you: Approving audit results
POINT

Training materials can be created by Pottech (included), and Pottech can serve as your internal auditor — so you can proceed even without dedicated in-house staff.

Process

Path to certification (standard 6 months)

We work toward a new certification in about 6 months from kickoff (timing varies by organization size and current state).

1

Goals & planning

~2 weeks

Decide scope, structure, and annual plan; begin auditor selection

2

Risk analysis

~1 month

Inventory assets, run risk assessment, decide treatment policy

3

Rule development

~4 months

Policy and objectives, regulations, statement of applicability, incident flow

4

Controls & training

parallel with ③

Implement technical and operational controls; deliver training (to 100%)

5

Internal audit & fixes

~2 weeks

Run internal audit, correct nonconformities, management review

6

Audit (stage 1 & 2)

~1 month

Stage 1 (1–2 days) → Stage 2 (2–3 days) → certification

From year 2: operations support

We continue to support reviews of roles and scope, risk-assessment updates, internal audits, and surveillance and renewal audits.

Structure

Project structure & roles

ISMS operation requires you to assign the roles the standard calls for. We explain each role and where Pottech can stand in.

Top management
Integrating ISMS into the organization, securing resources, owning risk
Held by management
ISMS lead
Overseeing ISMS build and operation
Appointed in-house
ISMS staff
Supporting ISMS operation in each department
Appointed in-house
Internal audit lead
Planning and improving audits, documenting and communicating results
Pottech can serve
Internal auditor
Conducting internal audits
Pottech can serve

Solving "no dedicated staff"

Pottech can serve as your internal audit lead and internal auditor, so you can focus on appointing management and the ISMS lead and staff.

Deliverables

Documents & deliverables we prepare

Based on Pottech's templates, tailored to your actual situation. There's no need to start from scratch.

Policy, planning & structure

  • Information security policy / objectives table
  • Org chart (roles, responsibilities, authority list)
  • Statement of Applicability (context and scope)

Risk management & operating rules

  • Risk assessment procedure / asset risk-assessment sheet
  • Information security management rules (full internal ruleset)
  • Incident reporting flow and report templates
  • Related-laws list / monitoring scope definition

Outsourcing & continuity

  • Vendor list / checklist
  • Business continuity plan & SLA

Training, audit & improvement

  • Information security training materials (managers / staff)
  • Internal audit plan, checklist, results
  • Corrective-action reports / management review minutes

Audit Body

Audit-body selection support

Certification is granted after an audit by a third-party body. Pottech obtains comparative quotes from multiple bodies and helps you choose one suited to your size and approach (fees vary by headcount, etc.).

BSI Group Japan
ISMS-AC & ANAB
The world's oldest national standards body; original drafter of ISO 27001 with deep experience.
JQA
ISMS-AC & UKAS
A major domestic body; over 70% of registrations are organizations under 100 people — strong startup know-how.
Bureau Veritas Japan
ISMS-AC
Special pricing for referrals; flexible on short timelines and scheduling.
SGS Japan
ISMS-AC
About 140 years of history; experience across sizes, centered on startups.
DQS Japan
ISMS-AC
Active IT-engineer auditors; audits that respect how teams actually work.

* The above are examples. We can also obtain and compare quotes from other bodies such as JUSE, JSA-SOL, and ICMS.

Pricing

Pricing plans

All prices exclude tax. Assumes an organization of up to about 50 people and documentation following our provided templates.

① New certification support (first time)

ISMS new certification support

Delivered using our provided document templates. Assumes up to ~50 people.

¥1.2M/ year~
  • (Option) Stage-1 attendance — full day, 1 day¥100K
  • (Option) Stage-2 attendance — full day, 2 days¥200K

② Operations support (from year 2)

ISMS operations support

Ongoing support for reviewing roles/scope, updating risk assessment, internal audit, and surveillance/renewal audits.

¥800K/ year~

Other options

3-Ministry 2-Guideline support
¥1.5M~
Integrating ISMS documents with 3-Ministry guideline documents (see below)
Security-aware PM support
¥400K
Supporting the project-management process during the engagement
Quality-management process build
¥400K
Building a quality-management process alongside the engagement
Expedited delivery
¥300K
When you need certification faster than standard
Technical implementation support
On request
Technical support including design and development for your product

* Payments to the audit body (audit fees) are not included. We obtain comparative quotes and present them to you.

Why Pottech

Why Pottech — a healthcare-focused track record

Healthcare-focused expertise

We understand clinical workflows and data — online care, PHR, SaMD, trial ePRO, hospital SaaS, and more.

Bridge to industry guidelines

We address industry requirements like the 3-Ministry guidelines with minimal effort, linked to ISMS documents.

Both documentation and engineering

Beyond documents, we can advise on technical controls including product design and development.

Selected engagements

2021
Business and product planning support for a PHR provider's platform build
Pharma & healthcare / PMO
2021
Development support for an ePRO system in clinical trials
Pharma / PMO
2022
COPD treatment-management app project
Pharma / PMO
2023
Digitalizing QMS for a medical-device maker
Medical device / consulting & dev
2024
Building ePRO / eConsent for clinical research use
Research institutes, university hospitals / design & dev

Option

Option: 3-Ministry 2-Guideline support

When providing systems or services to medical institutions, you may be required to comply with the "Guidelines for the Safe Management of Healthcare Information Systems" (3-Ministry 2-Guidelines). Pottech supports efficient compliance integrated with your ISMS.

Common concerns

  • The guidelines are complex — it's unclear how far you must go to count as "compliant."
  • Handling ISMS and the 3-Ministry guidelines separately makes documents and management unwieldy.

Pottech's approach

  • We recommend the optimal, minimal-effort approach for your product and organization.
  • We keep documents to a minimum and link required technical controls to your ISMS.
  • We support communication with medical institutions at rollout (minutes), disclosure documents, and risk-response lists.

Rough timeline: about 4 months from kickoff (risk analysis ▶ defining technical requirements ▶ documentation & operation).

FAQ

Frequently asked questions

Q

How long does certification take?

A

A new certification in about 6 months is standard. It varies by size and current state, and expedited delivery is available as an option.

Q

Is it okay if we have no dedicated security staff?

A

No problem. Pottech leads documentation and project management, and can also serve as your internal audit lead and auditor.

Q

Up to what headcount is the price flat?

A

Up to about 50 people. Beyond that, or for special requirements, we provide an individual quote.

Q

Are payments to the audit body included?

A

No. Audit fees are separate; we obtain comparative quotes and present them to you.

Q

We've already started some security measures. Can we use them?

A

Yes. We review your existing efforts and documents, use what we can, and fill the gaps.

Q

Can we also request 3-Ministry 2-Guideline support at the same time?

A

Yes. Integrating it with your ISMS documents keeps management from becoming unwieldy.

Get in Touch About AI Karte

Ask us anything about AI Karte, our AI-native electronic health record for clinics — key features, pricing plans, or how adoption works. Demo requests are welcome.