Karinoya Learning Room

Qualifications · Healthcare Information Technologist Success Lab

Related Laws and Data Analysis

Read the questions and explanations in English. The lectures (explanatory articles) are available in Japanese only.

View the Japanese version (with lectures) →

Q1 | Authenticity

Which is the correct description of "authenticity" among the 3 criteria for electronic storage of medical records?

  1. Only authorized persons can access the information, and its content is kept from being known to third parties
  2. Recorded information is stored, for the period prescribed by laws and regulations, in a state that maintains authenticity and can be made readable
  3. For records created under legitimate authority, false entry, rewriting, erasure, and mixing are prevented, and responsibility for creating the record is clear to third parties
  4. Content stored on electronic media can, at the request of an authorized person, easily be made readable to the naked eye as needed, and can be printed on paper as needed
AnswerC. For records created under legitimate authority, false entry, rewriting, erasure, and mixing are prevented, and responsibility for creating the record is clear to third parties

Authenticity is the criterion requiring prevention of false entry, rewriting, erasure, and mixing, and clarity about who is responsible for creating the record. The first option is the definition of legibility, the second is preservability, and the last describes confidentiality in information security, which is not among the 3 criteria for electronic storage.

Q2 | Legibility

Which is the correct description of "legibility" among the 3 criteria for electronic storage of medical records?

  1. Content stored on electronic media can, at the request of an authorized person, easily be made readable to the naked eye as needed
  2. Recorded information is stored, for the period prescribed by laws and regulations, in a state that maintains authenticity and remains readable
  3. The system is kept available so that users can use it whenever needed
  4. For records created under legitimate authority, false entry, rewriting, erasure, and mixing are prevented, and responsibility for creation is clear
AnswerA. Content stored on electronic media can, at the request of an authorized person, easily be made readable to the naked eye as needed

Legibility is the criterion requiring that stored content can easily be made readable to the naked eye when needed, meaning it must be promptly displayable and printable in response to clinical and other demands. The second option is the definition of authenticity and the third is preservability, while the last describes availability in information security.

Q3 | Preservability

Which is the correct description of "preservability" among the 3 criteria for electronic storage of medical records?

  1. Recorded information is stored, for the period prescribed by laws and regulations, in a state that maintains authenticity and can be made readable
  2. The information is accurate and complete, with no falsification or omission
  3. Stored content can, at the request of an authorized person, easily be made readable to the naked eye as needed and can also be printed on paper
  4. Responsibility for creating the record is clear to third parties
AnswerA. Recorded information is stored, for the period prescribed by laws and regulations, in a state that maintains authenticity and can be made readable

Preservability is the criterion requiring that records be stored throughout the statutory retention period in a state that maintains authenticity and remains readable; it is ensured through measures against media degradation, backups, and the like. The first option is the definition of authenticity and the second is legibility, while the third describes integrity in information security and is not the name of one of the 3 criteria.

Q4 | Authenticity measures

Which measure in an electronic medical record contributes directly to ensuring authenticity?

  1. Distributing backup data across facilities at remote locations for storage
  2. Shortening screen response times to improve usability
  3. Copying data to new media before the storage media degrades
  4. Saving, as an update history, the user who finalized a record and the date and time
AnswerD. Saving, as an update history, the user who finalized a record and the date and time

Keeping a history (audit trail) of who finalized each record and when helps prevent rewriting and clarifies responsibility for creation, so it is an authenticity measure. Remote storage of backups and media copying (migration) relate to preservability, and improving display response times relates to legibility.

Q5 | Legibility measures

Which is an appropriate measure for ensuring legibility in electronic storage of medical records?

  1. Migrating storage media to a new format before the standard changes
  2. Attaching the responsible creator's digital signature and a timestamp to scanned documents
  3. Prohibiting shared user IDs and authenticating each individual
  4. Preparing alternative means of reading so medical records can be consulted even during system failures
AnswerD. Preparing alternative means of reading so medical records can be consulted even during system failures

Because legibility requires that content can be made readable whenever needed, preparing alternative means of reading during failures (backup servers, alternative terminals, and so on) is a legibility measure. Digital signatures with timestamps and individual authentication are authenticity measures, and migrating media and formats is a preservability measure.

Q6 | Preservability measures

Which is an appropriate measure for ensuring preservability in electronic storage of medical records?

  1. Providing functions to display records on screen and print them on paper at the request of authorized persons
  2. Introducing two-factor authentication to prevent impersonation
  3. Migrating to new media and formats in preparation for media degradation and standard changes during the statutory retention period
  4. Having the finalizing person approve records entered by proxy
AnswerC. Migrating to new media and formats in preparation for media degradation and standard changes during the statutory retention period

Preservability requires that records remain intact and readable throughout the statutory retention period, so migration in preparation for media degradation and standard changes is the measure. Approval of proxy entries and two-factor authentication are authenticity measures, and printing functions relate to legibility.

Q7 | e-Document Act

Which is correct about the relationship between the e-Document Act (e-文書法) and electronic storage of medical records?

  1. With the enforcement of the e-Document Act, creating and storing paper medical records was prohibited
  2. The e-Document Act itself prescribes the specific technical measures and operational criteria for ensuring the authenticity, legibility, and preservability of medical records
  3. The e-Document Act is a law governing electronic storage of books and documents related to national taxes
  4. It is a law that generally permits electromagnetic storage of documents whose paper storage is required by law, and by MHLW ministerial ordinance medical records are also covered
AnswerD. It is a law that generally permits electromagnetic storage of documents whose paper storage is required by law, and by MHLW ministerial ordinance medical records are also covered

The e-Document Act is a Japanese law that generally permits electromagnetic storage of documents whose storage on paper is required by law; by MHLW ministerial ordinance, electronic storage of medical records and digitization by scanner are permitted. Electronic storage of tax-related books is governed by the Electronic Books Preservation Act. Paper medical records were not prohibited, and the concrete requirements are set out in the Guidelines for the Safety Management of Medical Information Systems.

Q8 | External storage

Which is the correct way of thinking when electronic medical record data is stored with an external service provider?

  1. If external storage is outsourced, the duty to store the records and the responsibility transfer to the contractor
  2. In external storage, the 3 criteria of authenticity, legibility, and preservability need not be met
  3. Even when external storage is outsourced, the duty to store the records and the responsibility remain with the healthcare institution
  4. For external storage, only the contractor needs to consider measures to protect personal information
AnswerC. Even when external storage is outsourced, the duty to store the records and the responsibility remain with the healthcare institution

External storage of medical records is permitted, but the duty to store them and the responsibility rest with the healthcare institution and do not transfer to the provider through outsourcing. Even with external storage, the 3 criteria of electronic storage must be ensured and personal information protection must be attended to, and the institution must manage the contractor as part of its own responsibilities.

Q9 | Guideline author

Which body formulates the "Guidelines for the Safety Management of Medical Information Systems"?

  1. The Personal Information Protection Commission
  2. The Ministry of Internal Affairs and Communications
  3. The Ministry of Economy, Trade and Industry
  4. The Ministry of Health, Labour and Welfare
AnswerD. The Ministry of Health, Labour and Welfare

The Guidelines for the Safety Management of Medical Information Systems, aimed at healthcare institutions, are formulated by the Ministry of Health, Labour and Welfare (厚生労働省). The Ministry of Economy, Trade and Industry and the Ministry of Internal Affairs and Communications jointly formulate the safety management guidelines for providers of systems and services handling medical information; together these are called the 3-ministry, 2-guideline framework. The Personal Information Protection Commission is the supervisory body for the Act on the Protection of Personal Information.

Q10 | Version 6.0 structure

Which structure was adopted in version 6.0 of the Guidelines for the Safety Management of Medical Information Systems?

  1. General provisions volume, technology volume, operations volume, audit volume, and forms volume
  2. Management volume, legislation volume, network volume, and cloud volume
  3. Overview volume, physician volume, nurse volume, pharmacist volume, and clerical staff volume
  4. Overview volume, governance volume, planning and management volume, and system operation volume
AnswerD. Overview volume, governance volume, planning and management volume, and system operation volume

Version 6.0 was organized into 4 volumes according to the reader's role: the overview volume, the governance volume, the planning and management volume, and the system operation volume. Its distinguishing feature is separating the volumes to be read by executives, by planning and management staff, and by system operation staff. Volume structures by profession or by technical field, as in the other options, were not adopted.

Q11 | Planning volume

In the Guidelines for the Safety Management of Medical Information Systems (version 6.0 and later), which volume is aimed mainly at staff who plan and manage the practical work of safety management, covering preparation of operating management regulations, risk assessment, and contractor management?

  1. The system operation volume
  2. The planning and management volume
  3. The overview volume
  4. The governance volume
AnswerB. The planning and management volume

The planning and management volume addresses staff who plan and manage the practical work of safety management, covering preparation of operating management regulations, risk assessment, contractor management, and the like. The overview volume covers the purpose and philosophy of the guidelines as a whole, the governance volume covers executives' decision-making, resource allocation, and accountability, and the system operation volume is for staff who implement and operate technical measures.

Q12 | 3-ministry guidelines

Which is the correct combination making up the so-called 3-ministry, 2-guideline framework for handling medical information?

  1. The MHLW's Guidelines for the Safety Management of Medical Information Systems, and the METI-MIC Safety Management Guidelines for Providers of Information Systems and Services Handling Medical Information
  2. The MIC's guidelines for cloud service providers handling medical information, and the METI guidelines for contracted information processing providers
  3. The Personal Information Protection Commission's guidelines and the Japan Medical Association's clinical information handling guidance
  4. The MHLW's Guidelines for the Safety Management of Medical Information Systems, and the Ministry of Education's research ethics guidelines
AnswerA. The MHLW's Guidelines for the Safety Management of Medical Information Systems, and the METI-MIC Safety Management Guidelines for Providers of Information Systems and Services Handling Medical Information

The 3-ministry, 2-guideline framework refers to the MHLW guidelines for healthcare institutions and the joint METI-MIC guidelines for service providers. The former separate provider guidelines of the MIC and METI (the 3-ministry, 4-guideline framework) were consolidated into the current provider guidelines. Research ethics guidelines and the medical association's guidance are not part of this framework.

Q13 | Responsibility when outsourcing

Which is correct about responsibility when a healthcare institution outsources operation of its medical information system to a service provider?

  1. If stipulated in the contract, the institution can be fully released from its responsibility to patients
  2. Because the contractor performs safety management, there is no need to define the demarcation of responsibility in the contract
  3. Even when outsourcing, the institution bears the ultimate responsibility to patients
  4. Once outsourced, accountability to patients for information leaks transfers to the contractor
AnswerC. Even when outsourcing, the institution bears the ultimate responsibility to patients

The safety management guidelines state that even when system operation and maintenance are outsourced, the ultimate responsibilities to patients — accountability, management responsibility, and so on — remain with the healthcare institution. That is precisely why the outsourcing contract must define the demarcation of responsibility and the institution must supervise the contractor. Accountability does not transfer to the provider, and a contract cannot release the institution from its responsibility to patients.

Q14 | Ransomware backups

Which is the appropriate approach to backups as a ransomware countermeasure in healthcare institutions?

  1. Keep multiple generations of backups offline or in areas that cannot be rewritten
  2. To speed up recovery, keep only 1 generation of backups in the same area as the production server, permanently connected
  3. Systems not connected to external networks need no backups
  4. As long as backups exist, investigating the infection route and preventing recurrence are unnecessary
AnswerA. Keep multiple generations of backups offline or in areas that cannot be rewritten

A permanently connected backup risks being encrypted by ransomware along with the production data, so keeping multiple generations offline or in non-rewritable areas is appropriate. Network isolation alone does not prevent infection via maintenance lines or USB memory, so backups are still needed, and after recovery the cause must be investigated and recurrence prevented.

Q15 | Contingency planning

Which is the appropriate approach to contingency response (BCP) for a healthcare institution's information systems?

  1. When a system failure occurs, keep no records about care until recovery
  2. Define the procedures for switching to paper operation in advance and drill them in normal times
  3. As long as backups are taken, recovery procedures need not be documented
  4. The BCP covers only natural disasters and does not include cyberattacks
AnswerB. Define the procedures for switching to paper operation in advance and drill them in normal times

To continue care in emergencies, the procedures for switching to paper operation and for recovery must be defined in advance and their effectiveness confirmed through drills. The BCP covers not only disasters but also system outages caused by cyberattacks such as ransomware, and recovery procedures must be prepared even when backups exist. Records of care are continued on paper or by other means during the outage.

Q16 | Version 7.0 addition

Which volume was newly added in version 7.0 of the Guidelines for the Safety Management of Medical Information Systems, issued in June 2026 (Reiwa 8)?

  1. An audit volume
  2. A maintenance contractor volume
  3. A patient volume
  4. A cloud services volume
AnswerB. A maintenance contractor volume

In version 7.0, a maintenance contractor volume — addressed to providers contracted by healthcare institutions to maintain their systems — was added to the 4 volumes of version 6.0 (overview, governance, planning and management, and system operation), making a 5-volume structure. No cloud services, audit, or patient volume was created.

Q17 | Sensitive personal information

Which of the following falls under special care-required personal information (要配慮個人情報) in the Act on the Protection of Personal Information?

  1. The patient's medical history
  2. The patient's income
  3. The patient's nationality
  4. The patient's telephone number
AnswerA. The patient's medical history

Special care-required personal information is information demanding particular care to prevent unjust discrimination or prejudice; besides medical history it includes race, creed, social status, and criminal record, and by cabinet order the results of health checkups and information on care and dispensing are also included. A telephone number, nationality, and income can be personal information but are not special care-required personal information.

Q18 | Handling sensitive data

Which is correct about handling special care-required personal information?

  1. When handled by healthcare institutions, it is exempt from the Act on the Protection of Personal Information
  2. It can be provided to third parties by opt-out if notified to the Personal Information Protection Commission
  3. Obtaining it requires, in principle, the person's prior consent
  4. It cannot be obtained even with the person's consent
AnswerC. Obtaining it requires, in principle, the person's prior consent

Obtaining special care-required personal information requires, in principle, the person's prior consent, and opt-out provision to third parties is not permitted even with notification. Healthcare institutions are also subject to the Act as personal information handling businesses. Acquisition is possible with the person's consent, and for the scope normally needed for care, the official guidance also sets out the concept of implied consent.

Q19 | Anonymized vs. pseudonymized

Which is correct about anonymized information and pseudonymized information under the Act on the Protection of Personal Information?

  1. Anonymized information may remain in a state where a specific individual can be identified by matching it against other information
  2. Pseudonymized information is information processed so that restoring the original personal information is technically impossible even by matching against other information
  3. Anonymized information is processed so that no specific individual can be identified or restored, and can be provided to third parties without consent, subject to duties such as public disclosure
  4. Pseudonymized information can be provided freely to third parties without the person's consent
AnswerC. Anonymized information is processed so that no specific individual can be identified or restored, and can be provided to third parties without consent, subject to duties such as public disclosure

Anonymized information is processed so that individuals cannot be identified or the data restored, and it can be provided to third parties without consent if duties such as disclosing the data items are met. Pseudonymized information is processed so that individuals cannot be identified unless matched against other information; irreversibility is not required, but in exchange it cannot, in principle, be provided to third parties and is intended for internal analysis.

Q20 | Individual identification codes

Which of the following falls under individual identification codes in the Act on the Protection of Personal Information?

  1. The patient's name and address
  2. The symbol and number on a public health insurance card
  3. The patient's date of birth and sex
  4. The patient's mobile phone number and email address
AnswerB. The symbol and number on a public health insurance card

Individual identification codes are designated by cabinet order as codes that can identify a specific individual on their own; they include the symbol and number of a public health insurance card, codes digitizing physical characteristics such as DNA base sequences, the My Number, and passport numbers. Names and dates of birth are descriptions that may identify a person but, like mobile numbers and email addresses, are not designated as individual identification codes.

Q21 | Next-Generation Act

Which is a correct description of the Next-Generation Medical Infrastructure Act (次世代医療基盤法)?

  1. A law stipulating that healthcare institutions must always obtain the person's written consent to provide medical information for research
  2. A law that abolished the Act on the Protection of Personal Information and unified protection of personal information in healthcare
  3. A law establishing a mechanism in which government-certified businesses collect medical information from healthcare institutions, anonymize it, and provide it for research and development
  4. A law stipulating that any private company can run an anonymized medical information business simply by filing a notification
AnswerC. A law establishing a mechanism in which government-certified businesses collect medical information from healthcare institutions, anonymize it, and provide it for research and development

The Next-Generation Medical Infrastructure Act establishes a mechanism in which certified anonymized medical information producers — businesses that meet standards such as high safety management capability and are certified by the government — anonymize medical information and provide it for research and development. Provision from institutions can be by notice with opt-out, so written consent is not always required. It does not replace the Act on the Protection of Personal Information, and businesses need certification, not mere notification.

Q22 | Provision method

Which is correct about how healthcare institutions provide medical information to certified anonymized medical information producers under the Next-Generation Medical Infrastructure Act?

  1. Provision is possible after notifying the person in advance, unless the person or a bereaved family member requests that it stop
  2. Provision is possible only after the institution itself has anonymized the information
  3. Once deemed to have consented, the person cannot stop the provision even on request
  4. Because medical information includes special care-required personal information, provision to certified businesses is entirely impossible
AnswerA. Provision is possible after notifying the person in advance, unless the person or a bereaved family member requests that it stop

The Next-Generation Medical Infrastructure Act permits an opt-out method: after notifying the person in advance, medical information can be provided to certified businesses unless the person (or a bereaved family member) requests a stop — a special exception to the Act on the Protection of Personal Information, which prohibits opt-out provision of special care-required personal information. The person can request a stop at any time. Anonymization is performed by the certified business, not by the institution before providing.

Q23 | Publishing purposes

Which reflects the thinking of the "Guidance on the Proper Handling of Personal Information by Medical and Long-term Care Businesses"?

  1. If the purposes of use are published, for example by posting in the facility, implied consent can be assumed for uses within the scope normally needed for care
  2. Even where based on laws and regulations, provision to third parties always requires the person's consent
  3. The purposes of use of personal information need be explained only when a patient asks
  4. Even for uses within the scope normally needed for care, such as outsourcing tests, written consent must be obtained for each use
AnswerA. If the purposes of use are published, for example by posting in the facility, implied consent can be assumed for uses within the scope normally needed for care

The guidance holds that when the purposes of use are published clearly, for example by posting in the facility, and the person raises no objection, implied consent can be assumed for uses and provision within the scope normally needed, such as care and insurance claims. Purposes must be published without waiting for questions, and item-by-item written consent is not required within the normal scope. Cases based on laws and regulations are exceptions where third-party provision is possible without consent.

Q24 | DWH advantages

Which is an advantage of using a data warehouse (DWH) when analyzing hospital information system data?

  1. The DWH becomes the original medical record, fulfilling the statutory storage duty
  2. Data for analysis can be extracted without putting load on the operational databases
  3. Screen responses in daily work such as order entry become faster
  4. Using a DWH eliminates the need to preprocess missing values and outliers
AnswerB. Data for analysis can be extracted without putting load on the operational databases

A DWH is an analysis platform that replicates data from operational systems and accumulates it in time series; its advantage is that extraction and aggregation put no load on the operational databases. It does not speed up the operational systems, nor does it serve as the original medical record for statutory storage. Even for data in a DWH, preprocessing such as handling missing values and outliers is still necessary.

Q25 | Missing values

Which is the appropriate handling of missing values in analyzing medical data?

  1. Check why the values are missing and decide the handling — exclusion, imputation, and so on — according to the purpose of the analysis
  2. Always exclude items containing missing values from the analysis, regardless of the reason
  3. Missing values occur at random, so they can simply be ignored in aggregation
  4. Treat all missing values as 0 and aggregate as-is
AnswerA. Check why the values are missing and decide the handling — exclusion, imputation, and so on — according to the purpose of the analysis

Missing values arise for various reasons — data not entered, tests not performed — and their occurrence is not necessarily random (for example, some tests are more likely to be measured in sicker patients). It is appropriate to check the reason and then decide on exclusion, imputation, or other handling according to the purpose. Mechanical treatments such as counting them as 0, always excluding, or ignoring them risk distorting the results.

Q26 | Outliers

Which is the appropriate handling of outliers in analyzing medical data?

  1. A dataset containing even 1 outlier cannot be used for analysis
  2. Check whether each is an input error or a genuine abnormal value, and then decide the handling
  3. Replace outliers with the mean automatically, without checking
  4. Outliers are always input errors, so delete them all when found
AnswerB. Check whether each is an input error or a genuine abnormal value, and then decide the handling

Outliers can be input errors, such as mixed-up units, or genuinely occurring abnormal values. In medical data, true abnormal values can carry important clinical meaning, so the cause is checked before deciding to correct, exclude, or keep them. Assuming they are always mistakes and deleting them, or mechanically replacing them with the mean, leads to wrong results. Analysis is possible even with outliers if they are handled properly.

Q27 | Record linkage

Which is a correct description of "nayose" (record linkage) in preprocessing medical data?

  1. Filling in missing values using statistical methods
  2. When the same person has multiple patient IDs or records with inconsistent spellings, matching and merging them into that person's data
  3. Deleting or replacing identifiers such as names and addresses so that no specific individual can be identified
  4. Sorting the patient list into Japanese syllabary order
AnswerB. When the same person has multiple patient IDs or records with inconsistent spellings, matching and merging them into that person's data

Record linkage (名寄せ, nayose) is the task of matching and merging one person's records that have been split by duplicate patient IDs, spelling variations of names, and the like; it determines the accuracy of per-patient analysis. Deleting identifiers is anonymization or pseudonymization, rearranging is mere sorting, and imputing missing values is a different preprocessing step.

Q28 | DWH

Which is the correct description of a hospital data warehouse (DWH)?

  1. A core operational system that directly handles data entry in daily clinical work
  2. A database that consolidates and accumulates data from each system for analysis and holds it in time series
  3. A system for staff payroll and attendance management
  4. A system for storing medical images and viewing them from terminals in the hospital
AnswerB. A database that consolidates and accumulates data from each system for analysis and holds it in time series

A DWH (data warehouse) is a database that consolidates and accumulates data from systems such as the electronic medical record and billing systems, holding it in time series for analysis. Daily data entry is done by the core operational systems, image storage is PACS, and payroll is the HR and payroll system; none of these describes a DWH. A subset extracted for a specific purpose is called a data mart.

Q29 | Data characteristics

Which shows a correct understanding of the characteristics of hospital information system data when used for management analysis or quality-of-care evaluation?

  1. Claims data contains the numerical results of every laboratory test
  2. Disease names on insurance claims include names assigned for billing purposes and do not necessarily match the confirmed diagnosis
  3. DPC data is research-only data collected with no relation to the medical fee system
  4. Hospital information system data is designed for analysis, so extracts can be used for analysis as-is
AnswerB. Disease names on insurance claims include names assigned for billing purposes and do not necessarily match the confirmed diagnosis

Claim disease names include names assigned for billing purposes, so they do not necessarily match confirmed diagnoses, and care is needed when counting diseases. Claims record that tests were performed but not the result values. DPC data comes from the discharge patient survey tied to the DPC/PDPS payment system, and hospital information system data is recorded for operational purposes, so preprocessing and quality checks are indispensable.

Q30 | Secondary use cautions

Which of the following is not an appropriate point of care when putting data accumulated in a hospital information system to secondary use in clinical research?

  1. When using it for research, follow the relevant frameworks such as personal information protection law and research ethics guidelines
  2. Take into account the history of master and code revisions accompanying medical fee schedule revisions
  3. Extract data after clearly defining the target patients, target period, and exclusion criteria
  4. Electronic medical record data is designed for research, so extracted data can be used for analysis as-is
AnswerD. Electronic medical record data is designed for research, so extracted data can be used for analysis as-is

Electronic medical record data is real-world data recorded for the work of clinical care, not designed for research, so it cannot be analyzed as-is without preprocessing — missing values, outliers, record linkage — and quality checks. Compliance with personal information law and research ethics, clear extraction criteria, and attention to code revision history are all necessary points of care in secondary use.

Practice: answer the questions on this page

This practice tool asks questions in random order (it works when JavaScript is enabled). You can still read all the questions and explanations above without it.

* The explanations are information for study purposes. Exam scope and systems change from year to year, so always check the official announcements of the organization that administers the exam.

This page is a translation of the Japanese original. If the translation and the original differ, the Japanese version takes precedence. View the Japanese original