• JP
  • EN
  • CH
MENU

ASOURCE Times

SPECIAL INTERVIEW

Cybersecurity for medical institutions is essential for ensuring business continuity and reliability.

Learn about the support measures provided by the Ministry of Health, Labor and Welfare and the Japan Medical Association and actively utilize them.

Japan Medical Association Executive Director
Director of Nagashima Orthopedics

Kimiyuki Nagashima

Graduated from Shimane Medical University School of Medicine. Obtained Doctor of Medicine degree from Jichi Medical University Graduate School. After working at a university hospital, he opened Nagashima Orthopedics in 1992 in Mibu-cho, Shimotsuga-gun, Tochigi Prefecture. He has been a member of the Japan Medical Association Medical IT Committee since 2010, a permanent director of the Tochigi Prefectural Medical Association since 2012, and a permanent director of the Japan Medical Association since 2018.

In recent years, Japanese medical institutions have been damaged by cyber attacks. In response to this, the government and the Japan Medical Association have recently launched a series of support measures for cybersecurity at medical institutions. We will ask Kimiyuki Nagashima, executive director of the Japan Medical Association, a clinician and expert in IT and medical systems, about the latest cyberattacks surrounding medical institutions and the Japan Medical Association's efforts in response.

Medical institution systems are connected to the outside world,
Cybersecurity is becoming increasingly important

Originally, medical institutions maintained the security of medical information by not connecting to external networks. However, with the introduction of cloud-based electronic medical records, participation in regional medical information collaboration networks, remote maintenance of in-hospital systems, and even online qualification confirmation that will become mandatory from April 2023, connections with external systems have become increasingly important in recent years. has become essential. As a result, the importance of cybersecurity is increasing.

 厚生労働省(以下「厚労省」)は、電子カルテなどの医療情報の適切な管理のために「医療情報システムの安全管理に関するガイドライン」を定めています。このガイドラインは適宜見直しが行われており、2023年5月には第6.0版が公表されました。今回の見直しの特徴は、オンライン資格確認の原則義務化を背景に、概説編、経営管理編、企画管理編、システム運用編とに分けて、また、医療機関の情報システムを類型化して、医療情報の安全に関する遵守事項や考え方を示した点です。

 ただ、ガイドラインを見るだけでは、医療機関や介護事業者が何から始めればいいかがわかりにくいため、日本医師会協力のもと、厚労省が「医療機関におけるサイバーセキュリティ対策チェックリスト」(以下「チェックリスト」)を作成し、2023年6月に公表しました。このチェックリストに対応するためのマニュアルも併せて示されています。

“Japan Medical Association Cybersecurity Support System”
make use of

The Japan Medical Association began operating the "Japan Medical Association Cybersecurity Support System" in June 2022. Three points are available: a contact point for consultation in emergencies, a call to use the free site "Tokio Cyber Port" to strengthen security measures, and a temporary support system for medical institutions whose members have suffered a cyber attack or had their personal information leaked. It is a measure. In addition to Nichiyo A① members, other doctors and clerks of A① member medical institutions, nursing care service facilities, and business offices, as well as the secretariats of prefectural medical associations and medical associations in districts, cities, and districts, etc., can also use the service.

The consultation center has received more than 60 inquiries in the one year since its establishment, including ``My electronic medical record was encrypted by ransomware,'' ``What should I do to deal with a virus infection?'' and ``My website was attacked by a cyberattack.'' I received a consultation.

Furthermore, starting in October of this year, we plan to provide materials and videos explaining the Medical Information System Safety Management Guidelines, and also open a consultation desk regarding the guidelines.

Adding cybersecurity to the medical safety system

The first important thing for medical institutions to do is to follow the checklist above to understand how all systems, including computers and medical equipment, both inside and outside the institution, are connected and where they are at risk. This requires the cooperation of vendors related to the supply chain.

We will also review and thoroughly enforce rules within medical institutions regarding information leaks caused by "people" such as leaving behind a laptop or taking out a USB drive.

It is also necessary to decide who will be responsible for managing the security of medical information systems, but many medical institutions cannot afford to hire a specialist. What I would like to propose is not to create a new department for cybersecurity, but to add cybersecurity work to the department responsible for medical safety, such as near-miss incidents. For example, we organize a communication network in the event of an incident such as ``unusual characters appear on the computer screen'' or ``the printer won't stop printing'', create a manual, and conduct training. The operation is exactly the same as medical safety.

I would like medical and nursing care professionals, especially those in management, to first check the items on this checklist. We also hope that you will take advantage of the Japan Medical Association's support system. At the consultation desk, we not only respond to actual cyber-attacks, but also provide detailed consultations such as questions about how to respond to checklists.

Medical institutions lack the knowledge, human resources, and financial resources to address cybersecurity. The Japan Medical Association will continue to request that the government move forward with support such as subsidies and human resource development.

The widespread use of online qualification confirmation will lead to the era of personal health records, where individuals carry medical information on their smartphones. The Japan Medical Association will continue to research and propose future-oriented cybersecurity.

Cybersecurity countermeasure checklist for medical institutions
https://www.mhlw.go.jp/content/10808000/001139055.pdf

Cybersecurity countermeasure checklist manual for medical institutions
https://www.mhlw.go.jp/content/10808000/001105752.pdf

Executive Director, Japan Medical Association Director, Nagashima Orthopedics Kimiyuki Nagashima

Japan Medical Association Executive Director
Director of Nagashima Orthopedics

Kimiyuki Nagashima

Graduated from Shimane Medical University School of Medicine. Obtained Doctor of Medicine degree from Jichi Medical University Graduate School. After working at a university hospital, he opened Nagashima Orthopedics in 1992 in Mibu-cho, Shimotsuga-gun, Tochigi Prefecture. He has been a member of the Japan Medical Association Medical IT Committee since 2010, a permanent director of the Tochigi Prefectural Medical Association since 2012, and a permanent director of the Japan Medical Association since 2018.

Listen to the best-in-class

2024年度診療報酬改定と急性期病院 病棟再編の道筋が示された今こそ 地域における役割と...

MM Office Co., Ltd. Representative Director Takashi Kudo

Medical DX in acute care hospitals: After establishing the direction of the hospital, we use AI technology that is highly practical and convenient...

Cybersecurity for medical institutions is essential for ensuring business continuity and reliability. Support measures from the Ministry of Health, Labor and Welfare and the Japan Medical Association...

一覧を見る
ASOURCE Times latest article

Full-time employment of people with medical information management qualifications promotes task shifts within the hospital and reduces turnover rate.

Shiori Hirashima, Director of Medical Information Office, Medical Affairs Division, Miyazaki University Hospital

Points for implementing rules regarding taking photos and videos at medical institutions

一覧を見る
Recommended articles

Japan's proud medical technologies (2) CT and MRI

Japan's proud medical technology (1) Endoscope

How to deal with drug resistance