Fundamentals|Published

A History of Hospital Information Systems, Part 3|Toward Medical DX and AI-Native Systems (2018–)

Part 1 traced billing through order entry; Part 2 the birth and spread of the EHR. This final article addresses the era of "medical DX" beginning around 2018, in which the national government made standardization and nationwide information exchange pillars of policy while new technologies and challenges — cybersecurity, cloud, generative AI — are transforming hospital information systems. It organizes the path to the present and the outlook ahead.

Policies and programs related to medical DX are still in progress and their names and timelines may change. This article reflects published information as of 2026; confirm the latest status with the MHLW and related agencies.

Around 2018: the turn toward data utilization

In May 2018, the Act on Anonymized Medical Data for R&D, commonly the Next-Generation Medical Infrastructure Act, took effect. It allows certified entities to anonymize clinical information held by institutions and provide it for research, institutionally opening the way to use data accumulated in EHRs across society. Around the same time, the government launched "Data Health Reform," aiming to build an infrastructure through which individuals can use their health information across their lifetimes.

On the hospital side, data utilization practice also spread. Aggregating DPC and EHR data into data warehouses to visualize management indicators became common in large hospitals. In the fee schedule, the data submission add-on introduced in 2014 gradually expanded its scope, making data submission a requirement for recovery rehabilitation, long-term care, and psychiatric wards as well. Being a hospital that can produce data became a precondition for billing inpatient fees.

  • 2018 Next-Generation Medical Infrastructure Act: anonymized data for R&D
  • Data Health Reform: lifelong personal health information infrastructure
  • Data warehouse management visualization becomes common in large hospitals
  • Expanding data submission requirements make data output a precondition for fees

Online eligibility verification and e-prescriptions: national infrastructure goes live

The physical foundation of medical DX is the online eligibility verification system. Full operation began in October 2021, allowing the My Number card to be used as a health insurance card with instant eligibility checks. In April 2023, adoption became mandatory in principle for insured institutions and pharmacies, achieving a state in which nearly all institutions connect to the national network. In December 2024, issuance of conventional insurance cards ended, shifting to a system based on the My Number insurance card.

On this national network, e-prescriptions began operation in January 2023. Issuing and receiving prescription information electronically enables checks for duplicate medication and contraindications across multiple institutions and pharmacies. Mechanisms allowing institutions to view medication, health checkup, and clinical information with patient consent have also expanded, creating a premise different from the traditional in-house hospital system: patient information leaves the institution and is referenced nationwide.

  • Oct 2021 online eligibility verification launches; Apr 2023 mandatory in principle
  • Dec 2024 conventional insurance card issuance ends; shift to My Number card
  • Jan 2023 e-prescriptions begin
  • Shift to a premise where patient information is referenced outside the institution

The Medical DX headquarters and roadmap: standardization, sharing, and revision DX

In October 2022, the government established the Medical DX Promotion Headquarters in the Cabinet, and in June 2023 adopted the "Roadmap for Promoting Medical DX." The roadmap sets three pillars — building a national medical information platform, standardizing EHR information, and DX of fee schedule revisions — with fiscal-year targets for each. This was the first time in the history of medical information systems that the government presented a whole picture with such concrete milestones.

For standardizing EHR information, the international HL7 FHIR standard was adopted, beginning with the "3 documents and 6 items": referral letters, discharge summaries, and health checkup reports, plus diagnoses, allergies, infections, drug contraindications, tests, and prescriptions, exchanged in standard form. The "EHR information sharing service" shares these nationwide, launched from FY2025 following pilot projects. The FY2024 fee revision created the Medical DX Promotion System add-on to reward readiness for this infrastructure.

For small hospitals and clinics where adoption lags, the government also proposed a "standard EHR" it would lead in developing. Development began in FY2024, pilot operation started at some institutions in FY2025, and the goal is EHR adoption at virtually all institutions by 2030. In revision DX, the government provides a "common calculation module" reflecting revision content to reduce vendor-specific modification burden, and from the FY2024 revision the effective date was moved from April to June.

  • 2022 headquarters, 2023 roadmap: platform, standardization, revision DX
  • HL7 FHIR standardization of 3 documents/6 items and the EHR sharing service
  • Standard EHR: adoption at virtually all institutions by 2030
  • Common calculation module and June effective dates (from FY2024)

Cybersecurity: the reality ransomware forced on hospitals

As medical DX advanced, the 2020s also became an era in which hospitals were targets of cyberattacks. In October 2021, a municipal hospital in Tokushima was infected with ransomware, rendering its EHR unusable and restricting normal care for about two months. In October 2022, a large acute hospital in Osaka suffered similar damage, with prolonged suspension of outpatient care and restrictions on emergency admissions. Both were attributed to intrusion via devices connected to the internal network or via business partners, shattering the assumption that hospitals were safe because their networks were closed.

These incidents prompted rapid institutional responses. In April 2023, the Medical Care Act enforcement regulations were amended to require hospital administrators to ensure cybersecurity measures. The security management guidelines were revised to version 6.0 in May 2023, restructured by role — executives, planning managers, and system operators — and now call for concrete measures such as the 3-2-1 backup rule, network perimeter defense, and business continuity planning. Submission of a cybersecurity checklist for medical institutions was added to on-site inspection items.

Cybersecurity has become a key criterion in selecting and operating hospital systems. There is growing recognition that keeping servers on-premises is not inherently safe and that entrusting operations to cloud providers with specialized operations can be more robust. At the same time, external storage and cloud use require compliance with the "three-ministry, two-guideline" framework, including the guideline for providers of systems and services handling medical information, and contractual practice that clarifies the division of responsibility between hospitals and vendors has grown in importance.

  • 2021 and 2022: major care suspensions from ransomware
  • Apr 2023: cybersecurity measures made mandatory under the Medical Care Act regulations
  • Security guidelines v6.0: role-based structure, concrete backup and BCP measures
  • Compliance with the three-ministry two-guideline framework and clear responsibility boundaries

Cloud and generative AI: the next form of hospital systems

Technologically, the spread of cloud-based EHRs is the major trend of the 2020s. Using systems in data centers via network rather than in-house servers offers lower initial investment, data protection in disasters, specialized security operations, and frequent feature updates; adoption spread first in clinics and small hospitals and is beginning in large hospitals as well. Maturing security guidelines and faster networks support this trend.

The rapid evolution of generative AI from late 2022 has fundamentally re-posed the question of what hospital systems should be. Recording consultations by speech recognition and automatically generating draft notes, discharge summaries, and referral letters from them directly addresses the long-standing "documentation burden" discussed in Part 2. Extracting nursing-need evaluation items from nursing records and flagging possible billing omissions are also spreading applications.

At the end of this trajectory lie the "AI-native EHR," which places AI at the core of design rather than bolting it on, and the concept of "AI agents" that autonomously advance processing across multiple tasks. Data is structured from the moment of entry; recording, search, summarization, and decision support operate as one; and agents handle routine administrative and billing work. This marks a turning point at which the hospital information system that began sixty years ago with computerized billing changes its role from a box for records to a platform that generates value from records.

  • Cloud EHRs: lower initial cost, disaster resilience, specialized security operations
  • Generative AI: speech recognition and document generation directly address documentation burden
  • AI for nursing-need extraction and billing omission detection
  • AI-native EHRs and AI agents: from box to platform

What history suggests about hospital systems ahead

Looking back over sixty years, consistent patterns emerge. First, policy has been the trigger for change: universal insurance created claims work, the 1999 notice made EHRs possible, DPC demanded structured data, and the medical DX roadmap drives standardization. Reading policy direction is decisive in system investment decisions.

Second, there has always been tension between frontline burden and data value. Order entry asked physicians to enter data; EHRs increased documentation burden. Yet that data has generated value in DPC analysis, management improvement, and research. Generative AI and AI-native design are positioned as the first technologies with the potential to fundamentally ease this tension.

Third, accumulated local optimization becomes long-term debt. Department- and vendor-specific connections produced lock-in and update burden. In selecting future systems, hospitals should evaluate as one whole: support for standards such as HL7 FHIR, reduced operational load via cloud, AI support for documentation and billing, and cybersecurity posture. Selection informed by history will be the foundation for hospital operations in the coming decade.

  • Policy triggers change: reading direction is key to investment decisions
  • AI-native design may ease the tension between burden and data value
  • Local optimization becomes debt: evaluate standards, cloud, AI, and security together