Hello, this is Ryuta Hamamoto from TIMEWELL.
Until quite recently, "economic security" meant semiconductors, rare earths, or defense equipment. If you told a hospital administrator or a pharmaceutical company's quality-assurance staff, "this is an economic security issue for your organization," you would usually be met with a blank stare. Then, in June 2026, the mood shifted. The Cabinet Office formally added "healthcare" to the critical infrastructure regime under the Economic Security Promotion Act, writing the word "healthcare" onto the list of infrastructure the state must protect, alongside electricity, gas, and finance.
This was a symbolic event. Surgeries postponed because antibiotics run short. Electronic medical records encrypted by ransomware, forcing outpatient clinics to shut down. Most APIs depending on a single country. Each of these had long been a source of unease that people on the ground felt in their bones, but the significance lies in the fact that they were now named as "security issues" from the institutional side. In this article, we organize economic security in healthcare into three layers—"pharmaceutical supply chains," "medical DX and cybersecurity," and "healthcare joining critical infrastructure"—based on the government's primary-source information. If you want to get an early read on whether your medical devices, APIs, or manufacturing equipment might be caught by export controls, working through the Export Control Compliance Check before you read on will make the rest of this feel personal.
Let me summarize the key points in three lines first. First, antibiotics (antibacterial preparations) and ventilators are designated as "specified critical materials" under the Economic Security Promotion Act, and support for domestic production and API stockpiling is advancing. Second, since April 2023, hospital and clinic administrators have been legally obligated to ensure cybersecurity, and safety management is strongly required as a precondition for medical DX. Third, in June 2026 healthcare was added to the critical infrastructure regime, and core medical institutions are moving toward prior screening of critical equipment procurement and outsourcing. Healthcare is now becoming a main battlefield of economic security from both the supply-chain and the infrastructure sides.
Economic security in healthcare is advancing across three layers at once
If we draw economic security in healthcare as a single map, three overlapping layers come into view. At the foundation lies a statute called the Economic Security Promotion Act. Its formal name is the "Act on the Promotion of Ensuring Security by Taking Integrated Economic Measures" (Act No. 43 of 2022), enacted in May 2022. This law bundles four distinct regimes into a single statute: ensuring the stable supply of critical materials, ensuring the stable provision of critical infrastructure services, supporting the development of advanced critical technologies, and keeping certain patent applications confidential. The two most deeply relevant to healthcare are the first two—the supply-chain regime and the infrastructure regime. If you want to grasp the overall picture first, reading Economic Security Promotion Act Basics alongside this article will help you see where healthcare sits within the framework.
That said, economic security in healthcare does not end with the Economic Security Promotion Act alone. The cybersecurity protecting the vast volumes of clinical data handled in medical DX and telemedicine is governed by a separate legal system—the Medical Care Act and its enforcement regulations. In other words, the starting point is understanding that economic security in healthcare is composed of "the security of goods and equipment" carried by the Economic Security Promotion Act combined with "the security of information and care continuity" carried by the Medical Care Act system.
To organize the three layers covered in this article: the first layer is the supply chain of materials such as pharmaceuticals and medical devices; the second is the cybersecurity of medical DX and clinical data; and the third is healthcare's newly added status in 2026 as critical infrastructure. Jurisdiction is also split by layer. The Cabinet Office bundles the regime as a whole, but the point of contact for antibiotics, hospital security, and medical DX is the Health Policy Bureau of the Ministry of Health, Labour and Welfare (MHLW); for semiconductors and export control it is the Ministry of Economy, Trade and Industry (METI); and for the My Number infrastructure and platform development it is the Digital Agency. Several ministries are intertwined. From a medical institution's point of view, because there is no single counterpart, it is an area where you can easily get lost unless you assemble the overall picture yourself.
Pharmaceutical supply chains—why antibiotics became a "specified critical material"
The first thing to understand in healthcare economic security is the pharmaceutical supply chain. Article 1 of the enforcement order of the Economic Security Promotion Act (Cabinet Order No. 394 of 2022) designates materials whose supply disruption would seriously impair national life or the economy as "specified critical materials." As of July 2026, a total of 16 materials are designated, and two of them are directly tied to healthcare: "antibacterial preparations" and "ventilators." The designation of specified critical materials started with 11 materials in December 2022 and was expanded thereafter. Antibiotics have been on the list from that first round.
Why antibiotics? Antibiotics are indispensable for preventing post-surgical infections and treating serious infectious diseases—the very foundation supporting medical care. Yet their APIs (the source of a drug's active ingredient) have relied heavily on production overseas, particularly in a specific country. In fact, there have been periods when a mainstay antibiotic fell into short supply, forcing the use of alternatives or the rescheduling of surgeries. A single API factory going offline can affect operating rooms in hospitals across Japan. It was this structure that came to be recognized as a "security issue."
The targets are the class of antibiotics known as β-lactams—specifically cefazolin sodium, cefmetazole sodium, ampicillin/sulbactam, and piperacillin/tazobactam. The MHLW's policy sets the goal of building, by 2030, a system that can continuously and stably supply the necessary volumes of β-lactam antibiotics on the front lines even when supply is disrupted. In concrete terms, this means developing manufacturing facilities capable of producing from the API stage domestically, and building stockpiling facilities to hold raw materials and APIs in advance. The idea is to shift from dependence on a single overseas company to a state in which a minimum can be produced domestically.
This policy has not remained a mere pipe dream. Under the scheme, a company that draws up a "supply-assurance plan" and has it certified by the competent minister can receive subsidies and support, and certifications are indeed progressing for antibiotics. For cefazolin sodium and cefmetazole sodium, Shionogi Pharma and Pharmira were certified on July 28, 2023; for ampicillin/sulbactam and piperacillin/tazobactam, Meiji Seika Pharma and others were certified on July 7, 2023, and they have begun domestic manufacturing of antibiotic APIs—so-called domestic production. The point of contact is the Pharmaceutical Industry Promotion and Medical Information Planning Division of the MHLW's Health Policy Bureau.
Let us also look at the scale of the funding. According to the Cabinet Office, across the entire stable-supply-assurance regime for critical materials, a combined budget of roughly ¥2.56 trillion has been secured, and 151 supply-assurance plans with a combined maximum subsidy of roughly ¥1.68 trillion have been certified (as of July 14, 2026). What to note here is that these figures are the total across all 16 materials. How much has been invested in antibiotics alone cannot be read from these numbers. When discussing budgets related to healthcare, it is important not to conflate "the amount for the regime as a whole" with "the amount for an individual material such as antibiotics." For a deeper dive into specified critical materials, including pharmaceuticals, our guide to specified critical materials is a useful reference.
Replace siloed classification work with AI.
METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.
Medical devices are also within scope—ventilators and the blind spot of semiconductor dependence
The story of materials is not only about drugs. Ventilators are also designated as specified critical materials. This measure reflects the experience during the COVID-19 pandemic, when ventilators essential for treating critically ill patients were fought over worldwide, and whether the necessary number of units could be secured meant the difference between life and death for the medical system. Ensuring that life-critical equipment can be secured domestically when the time comes—the same philosophy flows through here as well.
An easily overlooked point with medical devices is dependence not only on the equipment itself but on the components built into it. Modern medical devices use semiconductors for control and run on the premise of power and communications. Semiconductors, critical minerals, and storage batteries are also designated as specified critical materials, and these are firmly embedded, indirectly, in the healthcare field as core components and power sources for medical devices. Ventilators, CT and MRI scanners, and patient monitors run because behind them the supply chains for semiconductors and electronic components are functioning. If you look only at "obviously medical" materials such as antibiotics, you will miss the blind spot of supply-chain risk for the components that support the equipment. For medical procurement staff, a perspective that treats drugs, devices, and components as a single continuous supply chain is becoming necessary.
Medical DX and cybersecurity—an era in which hospitals become "attack targets"
Let us move to the second of the three layers: medical DX and cybersecurity. This is an area governed not by the Economic Security Promotion Act but by the Medical Care Act system. Japanese healthcare is now in the midst of a major wave of digitalization. The command tower is the Medical DX Promotion Headquarters established within the Cabinet Secretariat, headed by the Prime Minister. On June 2, 2023, this headquarters decided on the "Roadmap for Promoting Medical DX." It has three pillars: the nationwide medical information platform, the standardization of electronic medical record information, and DX of medical fee revisions. The MHLW, the Digital Agency, the Ministry of Internal Affairs and Communications, and METI are advancing it in coordination.
Concrete mechanisms are coming online one after another. Online eligibility verification at insurance-covered medical institutions and pharmacies became mandatory in principle from April 1, 2023, under Ordinance No. 124 of 2022 of the MHLW and related rules. Home-visit nursing stations and the like came within scope from December 2, 2024. On that same day, December 2, 2024, the issuance of new health insurance cards was halted, advancing consolidation into the My Number insurance card. As one function of the nationwide medical information platform, an Electronic Medical Record Information Sharing Service has also begun, allowing medical institutions and patients themselves to view and share referral letters, discharge summaries, health checkup results, and patient summaries. The Social Insurance Medical Fee Payment Fund (Shakai Hoken Shinryo Hoshu Shiharai Kikin) operates this service, and a standard electronic medical record system for medical clinics is scheduled for completion during fiscal 2026. Electronic prescriptions, which reference prescription and dispensing information across multiple medical institutions and pharmacies to check for duplicate medication and contraindicated combinations, are also a component of this platform.
While things become more convenient, the more clinical data is aggregated, the more attractive a target it becomes for attackers. Over the past several years, there have been multiple reported cases in Japan of hospitals being infected with ransomware (malware that encrypts data and demands a ransom), rendering electronic medical records unusable and forcing them to halt outpatient and emergency admissions for extended periods. A halt in care directly affects patients' lives. That is precisely why the state raised medical institutions' cybersecurity from an "effort target" to an "obligation." The ministerial ordinance partially revising the Enforcement Regulations of the Medical Care Act (Ordinance No. 20 of 2023 of the MHLW) was promulgated on March 10, 2023, took effect on April 1 of the same year, and obligated the administrators of hospitals, clinics, and birthing centers to take measures to ensure cybersecurity.
The practical standard is the MHLW's "Guidelines on Safety Management of Medical Information Systems." The current version is 7.0 (June 2026), organized into three parts: management, planning and administration, and system operation. It covers a wide range, from responses to personal information protection and the e-Document Act, to safety management when outsourcing or using the cloud, to technical requirements such as networks, authentication, and backups. In recent times, an advisory on measures against attacks targeting VPN devices and the like (March 2026) and an advisory on measures against the risk of abuse of high-performance AI (May 2026) have been issued in succession. Should a cyber incident occur, the practice is to report it promptly to the Medical Information Counselor's Office of the Health Policy Bureau.
This layer also includes telemedicine. Online medical care is conducted based on the MHLW's "Guidelines for the Appropriate Implementation of Online Medical Care," which require attention to the communication environment, identity verification, information security, and the management of clinical information. Clinical data transmitted and received remotely is, of course, subject to this safety management guideline as well. What tends to be overlooked here is the reliability of the communication devices, cloud services, and software themselves. Which country's control is the cloud storing clinical data under? Where do the components of telemedicine devices originate? This is information security and, at the same time, an economic security issue of supply-chain reliability. In medical DX, protecting data and scrutinizing the provenance of the equipment and services that support it are seamlessly connected.
[June 2026] Healthcare was added to the critical infrastructure regime
And so we come to the third layer, the newest development: healthcare joining critical infrastructure. On June 17, 2026, the Cabinet Office updated its overview materials for the critical infrastructure regime in connection with "the addition of the healthcare sector to specified critical infrastructure operations." The critical infrastructure regime is a mechanism under which, for businesses that support the foundations of society, an operator must notify the state and undergo screening in advance before introducing critical equipment or outsourcing maintenance to third parties. Until now, specified critical infrastructure operations comprised 15 sectors: electricity, gas, oil, water supply, railways, freight motor transport, oceangoing shipping, aviation, airports, port transport, telecommunications, broadcasting, postal services, finance, and credit cards. "Healthcare" has now been added, bringing the total to 16 sectors. The MHLW's discussion materials, "On the Addition of the Healthcare Sector to the Critical Infrastructure Regime," confirm the same direction.
What does this mean? Core medical institutions are moving toward being subject to prior notification and screening for the introduction of critical equipment and the outsourcing of critical maintenance and management. For example, when a large hospital newly introduces a core system, or entrusts maintenance and operation to an outside vendor, the image is that the state will check in advance whether that equipment or that contractor poses any security concern. The single biggest significance of this change is that healthcare has now become an entity spanning both the supply-chain regime (specified critical materials) and the infrastructure regime (specified critical infrastructure operations).
That said, this is also a part where we should avoid making definitive claims. Which scale of medical institution will be covered (specific thresholds such as the number of beds), how far the equipment subject to prior screening extends, and when application will actually begin—these details will be finalized in the Cabinet Office's overview materials and forthcoming cabinet and ministerial ordinances. What can be said with certainty at this point is only that "on June 17, 2026, the Cabinet Office updated its overview materials, and the healthcare sector was added to the critical infrastructure regime." Core hospitals, and the system vendors and maintenance contractors that support them, would do well to begin taking inventory of their equipment and outsourcing relationships before the details firm up, to avoid scrambling later. For those who want to follow the substance of the regime in more detail, please see our guide to the critical infrastructure prior-screening system.
Practical steps medical institutions and pharmaceutical companies should start now
Taking the three layers together, what medical institutions and pharmaceutical companies should do comes down not to an abstract "awareness" but to a concrete inventory. Personally, I think the realistic place to start is to "make visible" your own supply chain's foreign dependence. Which APIs do you source from which factory in which country? Where do your equipment's core components originate? To whom do you entrust system maintenance? Simply putting this into a single list will surface where you are weak if supply is disrupted. Whether in the prior screening for critical infrastructure or in the supply-assurance plans for specified critical materials, in the end what is asked is whether you "can explain the reliability of your counterparties."
The next thing to tackle is screening your counterparties and contractors. Are your overseas API manufacturers, equipment vendors, and system contractors on any country's sanctions lists or watch lists? If you trace their capital relationships, do they connect to any company of concern? Unless you confirm this, you may find yourself at the notification or screening stage unable to "explain that counterparty." The types of sanctions and watch lists and how to use them are compiled in our complete guide to sanctions lists.
An often-overlooked point is the interface with export control (the Foreign Exchange Act). Healthcare carries a strong image of being "the importing side," but the Foreign Exchange Act actually comes into play in export and technology-provision situations. Manufacturing equipment for pharmaceutical APIs—such as fermenters, freeze-dryers, and bioreactors—certain reagents and pathogen-related items, and advanced medical devices can fall within the scope of the Foreign Exchange Act's Export Trade Control Order and Foreign Exchange Order. Before exporting overseas or providing technology, a "classification assessment (gaihi-hantei)" of whether the item falls under the regulations is indispensable. For the overall picture of classification assessment, our commentary on METI's classification-assessment guidelines is a useful reference.
University hospitals and research institutions have one more issue of their own: deemed exports. Providing sensitive technical information to researchers or foreign students from abroad can be regarded as an "export" and fall within the scope of the Foreign Exchange Act even when provided domestically. In infectious-disease research, biotechnology, and advanced medical device research, this issue becomes very real. For details, please check our commentary on deemed-export risk. My view is that economic security in healthcare, when pushed to its core, comes down to "the practical work of regulatory compliance."
Streamline classification assessment and counterparty screening with TRAFEED
Even so, running all the practical work described above by hand alone is, frankly, quite a burden. There are countless API manufacturers and equipment vendors, and each country's regulations and lists are updated frequently. TRAFEED (formerly ZEROCK ExCHECK, an export control AI agent compliant with METI standards), which we provide, was built precisely to lighten this burden. Let me organize how it helps with economic security compliance in healthcare across three scenarios.
The first is classification assessment. As noted earlier, manufacturing equipment for pharmaceutical APIs, certain reagents, and advanced medical devices can fall within the scope of the Foreign Exchange Act, and TRAFEED supports the initial assessment of whether an item falls under the regulations in line with METI standards. The aim is to shorten the time an assessment takes and to prevent it from becoming dependent on a single individual. The second is counterparty screening. It cross-checks overseas API manufacturers, equipment vendors, and contractors against each country's sanctions and watch lists, making visible the risks of a counterparty's country of origin and capital relationships. This makes it easier to continuously maintain the "state of being able to explain your counterparties" required for supply-assurance plans for specified critical materials and for prior screening of critical infrastructure.
The third is the operation of economic security compliance as a whole. Now that healthcare has joined critical infrastructure, core hospitals and pharmaceutical companies need to periodically take inventory of their supply chains' foreign dependence and maintain a structure that can withstand notification and screening. With TRAFEED, you can run supply-chain visualization and screening as an ongoing operation rather than a one-off. It also supports deemed-export management for university hospitals and research institutions. TRAFEED's AI assessment accuracy has been confirmed at 95% or higher based on a joint demonstration with Okayama University and approximately 30,000 past assessment records (in-house survey). That said, the premise is that the final classification assessment is made by your company's export control officer. AI is a tool to speed up the groundwork of judgment—it does not take on the responsibility in your place. I want to emphasize this point.
Conclusion
Economic security in healthcare is not a distant policy debate; it has worked its way into the daily operations of hospitals and pharmaceutical companies. Let me organize the key points at the end.
- Economic security in healthcare is advancing simultaneously across three layers: "pharmaceutical supply chains," "medical DX and cybersecurity," and "healthcare joining critical infrastructure."
- Antibacterial preparations (β-lactam antibiotics) and ventilators are designated as specified critical materials, and toward building a stable-supply system by 2030, certified operators are moving to domesticate API production.
- Since April 2023, the administrators of hospitals and similar facilities have been obligated to ensure cybersecurity, and in practice the standard is the Safety Management Guidelines Version 7.0.
- On June 17, 2026, healthcare was added to the critical infrastructure regime. The details of scope and timing of application will be finalized in forthcoming cabinet and ministerial ordinances.
- What companies should do is concrete practical work: making foreign dependence in the supply chain visible, screening counterparties, classification assessment under the Foreign Exchange Act, and deemed-export management.
Carrying all of these issues by hand alone is not realistic. First, try writing out—however small—where the risks lie in your own supply chain. Then, if you are unsure how to systematize classification assessment and counterparty screening, bring your specific use cases to a personal consultation on TRAFEED, and we will work out an approach tailored to your situation together. Precisely because healthcare is a field entrusted with people's lives, supply-chain security is a theme we do not want to leave to "by the time you notice, it's already too late."
