Cybersecurity and Data Privacy in Japan’s Long-Term Care System: Protecting Trust in Connected Aging

Japan’s response to population aging is becoming increasingly dependent on digital infrastructure.

Electronic care records, telehealth, remote monitoring, smart-home technology, robotics, mobile applications and artificial intelligence can help older people remain independent while allowing health and long-term care services to coordinate more effectively.

These technologies also increase the amount of sensitive information collected, exchanged and processed across homes, hospitals, municipalities, pharmacies, care providers and technology suppliers.

The Japan Aging, Long-Term Care & Community Support Knowledge Hub explores how Japan can develop a sustainable, connected and person-centred aging society.

Cybersecurity and privacy will be fundamental to that future.

A connected care system can improve safety only when people trust it, professionals can rely on it and essential services remain available during disruption.

A cyberattack affecting a long-term care provider is therefore not simply an information-technology incident.

It may prevent workers from accessing medication information, interrupt remote monitoring, disable building systems, delay hospital discharge or leave older people unable to call for assistance.

Privacy failures can be equally damaging.

Excessive monitoring, inappropriate family access, inaccurate records and hidden secondary use of personal data can reduce dignity and control even when no criminal breach occurs.

Japan’s challenge is to create a digital care ecosystem that is secure without becoming inaccessible, connected without becoming intrusive and innovative without weakening human accountability.

Cybersecurity and Privacy Are Related but Different

Cybersecurity focuses on protecting systems, networks, devices and information from unauthorized access, disruption, alteration or destruction.

Privacy focuses on whether personal information is collected, used and shared appropriately.

A system may be technically secure but still undermine privacy by collecting excessive information or sharing it with too many organizations.

Conversely, a service may have a clear privacy policy but remain vulnerable to ransomware, stolen passwords or insecure devices.

Strong digital governance must address both.

Cybersecurity Is a Direct Care-Quality Responsibility

Long-term care organizations may once have viewed cybersecurity as a specialist technical concern.

That distinction is no longer sustainable.

Digital systems may now control or support:

  • medication administration;
  • care plans;
  • staff scheduling;
  • emergency contacts;
  • remote monitoring;
  • door-access systems;
  • call bells;
  • environmental controls;
  • telehealth;
  • clinical communication;
  • family updates;
  • billing;
  • payroll;
  • supplier ordering; and
  • regulatory evidence.

A failure in any of these systems can affect continuity, safety and personal wellbeing.

Cybersecurity should therefore be integrated into quality management, clinical governance, emergency preparedness and organizational leadership.

Japan’s Aging-Care Ecosystem Creates a Wide Attack Surface

The digital care environment may include:

  • national and municipal systems;
  • hospital records;
  • long-term care management platforms;
  • pharmacy systems;
  • home-care applications;
  • care-home networks;
  • mobile devices;
  • remote-monitoring sensors;
  • smart-home equipment;
  • wearable devices;
  • video-consultation platforms;
  • robotic systems;
  • cloud services;
  • supplier portals;
  • family applications; and
  • research databases.

Every connected device, supplier and user account can become a potential route into the wider system.

Security must therefore extend beyond large hospitals and government platforms.

Small home-care agencies, community organizations and individual households are also part of the digital care infrastructure.

Older People May Face Distinct Digital Risks

Older adults may be targeted because criminals believe they are more likely to:

  • trust official-looking messages;
  • respond to urgent requests;
  • have limited digital confidence;
  • reuse passwords;
  • depend on family or support workers;
  • hold financial assets;
  • experience cognitive change;
  • feel reluctant to report mistakes; or
  • be socially isolated.

These assumptions should not become stereotypes.

Many older people manage digital security confidently, while younger relatives or professionals may also create significant risk.

Protection should be based on actual circumstances, system design and support needs rather than age alone.

Common Cyber Threats in Long-Term Care

Threats may include:

  • phishing;
  • ransomware;
  • malware;
  • credential theft;
  • business-email compromise;
  • unauthorized remote access;
  • supplier compromise;
  • data extraction;
  • denial-of-service attacks;
  • device theft;
  • insider misuse;
  • fraudulent payment requests;
  • identity theft;
  • manipulation of records; and
  • destruction or encryption of backups.

The potential consequences extend beyond loss of confidentiality.

Attackers may disrupt service delivery, alter information, redirect payments or use stolen data for coercion and fraud.

Phishing Remains a Major Human and Organizational Risk

Phishing messages may imitate:

  • municipal authorities;
  • health insurers;
  • hospitals;
  • technology suppliers;
  • senior managers;
  • banks;
  • pharmacies;
  • family members;
  • delivery companies;
  • tax authorities; or
  • emergency services.

Messages may ask the recipient to:

  • open an attachment;
  • click a link;
  • reset a password;
  • confirm identity;
  • transfer money;
  • provide a verification code;
  • install software;
  • approve a new supplier account; or
  • respond urgently to a supposed care emergency.

Security awareness should focus on practical recognition and verification rather than generic warnings.

Care-Related Messages Can Create Particular Urgency

Criminals may exploit concern for an older person by claiming that:

  • a hospital payment is required;
  • a care appointment will be cancelled;
  • a relative has experienced an emergency;
  • a medication order has failed;
  • a long-term care benefit must be renewed;
  • a monitoring device requires urgent access;
  • a professional needs identity confirmation; or
  • a family member must provide banking details.

Care organizations should make legitimate communication recognizable and provide simple routes for verification.

People should never be asked to disclose passwords, passcodes or banking credentials through an unexpected message.

Operational Example: Responding to a Fraudulent Care Message

An older person receives a message claiming to come from a municipal long-term care office.

The message states that their services will stop unless they confirm personal and banking information immediately.

A five-stage protective response could operate as follows:

  1. Verify safely: The person contacts the municipality through a previously known telephone number rather than using the message link.
  2. Protect accounts: Where information has been disclosed, banking, email and care-system credentials are secured promptly.
  3. Report the incident: The fraudulent message is shared with the municipality, relevant provider and law-enforcement or fraud-reporting channels.
  4. Check wider harm: Teams review whether appointments, care arrangements or family contacts have been altered.
  5. Restore confidence: The person receives practical support to continue using legitimate digital services without blame or embarrassment.

The response protects the person while recognizing that fraud may affect care continuity as well as finances.

Ransomware Can Interrupt Essential Care

Ransomware may encrypt data or disable access to systems until payment is demanded.

A long-term care provider affected by ransomware may lose access to:

  • medication records;
  • care plans;
  • risk assessments;
  • staff rotas;
  • family contacts;
  • clinical correspondence;
  • incident records;
  • building-access systems;
  • remote-monitoring dashboards;
  • financial systems; and
  • supplier information.

Even when backups exist, restoration may take days or weeks.

Organizations need practical arrangements for safe care during prolonged system unavailability.

Paying a Ransom Does Not Guarantee Recovery

Payment may not result in:

  • complete data restoration;
  • removal of malicious access;
  • deletion of stolen information;
  • protection from repeated attack;
  • working systems;
  • accurate records; or
  • continued confidentiality.

Ransomware planning should focus on prevention, containment, restoration and continuity rather than assuming payment will resolve the incident.

Backups Must Be Protected From the Same Attack

Backups may fail when they are:

  • permanently connected to the live network;
  • protected by the same credentials;
  • incomplete;
  • untested;
  • corrupted;
  • poorly documented;
  • dependent on one supplier;
  • stored in one location; or
  • unable to restore individual systems.

Organizations should maintain protected, tested and recoverable backups.

Restoration testing should include care-critical systems rather than only office files.

Recovery Priorities Should Reflect Care Risk

Not every system can be restored at the same time.

Priority may need to be given to:

  • medication information;
  • emergency contacts;
  • care plans;
  • high-risk alerts;
  • staff scheduling;
  • remote-monitoring response;
  • building safety systems;
  • clinical communication;
  • hospital discharge coordination; and
  • payroll where workforce continuity is threatened.

Recovery plans should be based on the consequences of unavailability rather than technical convenience.

Cyberattacks Can Manipulate Information

Confidentiality breaches receive significant attention, but information integrity is equally important.

An attacker or unauthorized user may change:

  • medication doses;
  • allergy information;
  • contact details;
  • banking information;
  • staff credentials;
  • care-plan instructions;
  • appointment times;
  • supplier accounts;
  • risk ratings;
  • family permissions; or
  • monitoring thresholds.

Changes may be difficult to detect when they appear to come from a legitimate account.

Systems need audit trails, change alerts and verification of high-risk amendments.

Data Integrity Should Be Treated as a Safety Control

Organizations should be able to determine:

  • who entered or changed information;
  • when the change occurred;
  • which device was used;
  • what the previous information stated;
  • whether approval was required;
  • whether connected systems were updated;
  • whether unusual activity occurred; and
  • whether care decisions were affected.

Critical information should not be overwritten without retaining version history.

Identity Theft Can Affect Care as Well as Finance

Stolen identity information may be used to:

  • open financial accounts;
  • obtain services fraudulently;
  • redirect benefits;
  • access health records;
  • impersonate a family member;
  • change contact details;
  • intercept appointments;
  • obtain prescriptions;
  • submit false claims; or
  • create conflicting care records.

Identity recovery may require coordination across banks, municipalities, health providers, insurers and care organizations.

The person should receive support to correct both financial and care-related consequences.

Unauthorized Family Access Is a Privacy Risk

Family members may provide valuable support, but access should not be assumed.

Privacy concerns may arise when relatives:

  • use the person’s password;
  • read clinical information without agreement;
  • change appointments;
  • control contact details;
  • access financial information;
  • receive alerts automatically;
  • monitor location;
  • communicate with professionals as if they were the person; or
  • continue accessing information after relationships change.

Systems should provide separate delegated credentials with permissions defined by the older person wherever possible.

Delegated Access Should Be Specific and Reviewable

An older person may choose to allow a relative or trusted supporter to:

  • view appointments;
  • receive reminders;
  • read medication information;
  • join virtual consultations;
  • upload observations;
  • communicate with professionals;
  • manage equipment;
  • view selected records; or
  • act only during a temporary period.

Permissions should be reviewed when circumstances change.

Shared passwords should not be the standard method of providing family support.

Insider Risk Must Be Addressed Proportionately

Workers and contractors require access to information to perform their roles.

Insider risk may involve:

  • curiosity-driven access;
  • looking at records of acquaintances;
  • inappropriate disclosure;
  • fraud;
  • retaining data after employment;
  • copying records to personal devices;
  • using information to exploit a person;
  • sharing credentials;
  • unauthorized research; or
  • deliberate sabotage.

Most workers act responsibly.

Controls should protect people without creating a culture in which every employee is treated as inherently untrustworthy.

Role-Based Access Reduces Unnecessary Exposure

Professionals should see the information required for their role.

A home-care worker may need:

  • current support instructions;
  • medication tasks;
  • mobility information;
  • communication preferences;
  • known risks;
  • emergency contacts;
  • daily observations; and
  • escalation routes.

They may not need unrestricted access to:

  • historic clinical records;
  • financial information;
  • unrelated family information;
  • complete psychiatric history;
  • research participation;
  • legal documents; or
  • every previous incident.

Access should be proportionate, time-limited where appropriate and reviewed regularly.

Privileged Accounts Require Additional Protection

System administrators and senior users may have access to large volumes of information or the ability to change settings.

Privileged-account controls should include:

  • multi-factor authentication;
  • separate administrator accounts;
  • approval for high-risk changes;
  • detailed audit logging;
  • session monitoring;
  • time-limited access;
  • rapid removal after role change;
  • restricted remote access;
  • regular access review; and
  • investigation of unusual activity.

Administrative convenience should not override security.

Access Must Be Removed Promptly When Roles Change

Access may remain active after:

  • employment ends;
  • a worker moves teams;
  • a temporary contract finishes;
  • a student placement ends;
  • a supplier changes;
  • a family permission is withdrawn;
  • a volunteer role ends; or
  • a professional relationship with the person concludes.

Organizations should connect access management with human resources, contracting and care-planning processes.

Dormant accounts should be identified and disabled.

Mobile Working Creates Additional Exposure

Home-care workers, nurses, therapists and care managers may access records through phones, tablets and laptops.

Risks may include:

  • device loss;
  • shoulder surfing;
  • use of public Wi-Fi;
  • shared vehicles;
  • unattended equipment;
  • personal applications;
  • screen capture;
  • automatic cloud backup;
  • weak device passwords;
  • outdated software; and
  • family members using the device.

Mobile security should support practical community work rather than impose controls that workers routinely bypass.

Secure Mobile Working Requires Organizational Support

Controls may include:

  • managed devices;
  • encryption;
  • multi-factor authentication;
  • remote locking and deletion;
  • automatic timeout;
  • restricted downloads;
  • approved applications;
  • secure connectivity;
  • privacy screens;
  • rapid reporting of loss;
  • replacement arrangements; and
  • training based on real working conditions.

Workers should not have to choose between completing care safely and following impractical security rules.

Bring-Your-Own-Device Models Require Careful Governance

Personal-device use may appear affordable and convenient.

It can create uncertainty involving:

  • ownership of information;
  • device security;
  • remote deletion;
  • privacy of personal data;
  • software updates;
  • family access;
  • photographs;
  • messaging applications;
  • employment boundaries;
  • staff costs;
  • device loss; and
  • removal of access when employment ends.

Organizations should define clearly whether personal devices may be used and under which technical and employment conditions.

Messaging Applications Can Become Informal Care Records

Workers and families may use familiar messaging platforms to share:

  • care updates;
  • photographs;
  • medication information;
  • staffing arrangements;
  • appointment details;
  • safeguarding concerns;
  • personal preferences;
  • location information; and
  • urgent requests.

This may improve speed but create risks involving:

  • unapproved platforms;
  • personal telephone numbers;
  • missing records;
  • unclear consent;
  • group membership;
  • information retained after employment;
  • automatic backups;
  • poor escalation; and
  • lack of professional boundaries.

Organizations need approved communication routes that are usable enough to prevent unsafe workarounds.

Personal Email Should Not Become a Substitute for Secure Systems

Workers may send information to personal accounts when official systems are difficult to access.

This can lead to:

  • uncontrolled storage;
  • incorrect recipients;
  • weak passwords;
  • family access;
  • loss of audit history;
  • inability to delete information;
  • continued access after employment; and
  • data being processed in unknown locations.

Leaders should investigate why workarounds occur and improve official systems rather than relying only on disciplinary warnings.

Smart Homes Expand Cybersecurity Into the Person’s Living Environment

Connected homes may include:

  • movement sensors;
  • voice assistants;
  • smart locks;
  • video doorbells;
  • environmental controls;
  • medication dispensers;
  • fall detectors;
  • wearables;
  • connected appliances;
  • location technology;
  • emergency alarms; and
  • remote family-access applications.

A compromise may reveal daily routines, location, health information or periods when the person is alone.

It may also allow unauthorized control of devices.

Home Technology Should Be Secure by Default

Security should not depend on the older person changing complex settings.

Devices should include:

  • unique credentials;
  • secure initial setup;
  • automatic updates;
  • encrypted communication;
  • clear privacy controls;
  • limited data collection;
  • visible recording indicators;
  • safe reset processes;
  • supplier support;
  • defined support periods;
  • secure decommissioning; and
  • manual alternatives where appropriate.

Default settings should protect privacy rather than maximize data collection.

Installation Must Include a Security Conversation

People should understand:

  • what the device records;
  • when it is active;
  • who receives information;
  • whether family members have access;
  • how alerts are generated;
  • how the device is updated;
  • what happens during an outage;
  • how access can be withdrawn;
  • how information is deleted;
  • how to report a fault; and
  • how to identify legitimate supplier contact.

Installation should not be treated solely as a technical task.

Operational Example: Securing a Connected Home-Care Package

An older person receives a package containing movement sensors, a smart medication dispenser and a family monitoring application.

A five-stage security process could be used:

  1. Map the data: The provider explains what each device collects, where information goes and who can access it.
  2. Configure securely: Default passwords are replaced, unnecessary functions disabled and family permissions limited.
  3. Test continuity: The person and care team practice what to do if the internet, power or device fails.
  4. Monitor safely: Access logs, missed transmissions and software updates are reviewed.
  5. Reassess regularly: Consent, usefulness, family access and security are reconsidered as circumstances change.

The technology supports independence without giving unlimited access to the person’s home and routines.

Wearables Collect Highly Personal Information

Wearable devices may capture:

  • heart rate;
  • sleep;
  • movement;
  • location;
  • falls;
  • temperature;
  • oxygen levels;
  • stress indicators;
  • daily routines; and
  • social activity.

Combined over time, these data can reveal intimate patterns about health, behavior and lifestyle.

Collection should be limited to information needed for an agreed care purpose.

Location Tracking Requires Particular Caution

Location technology may support safety for some people living with cognitive impairment or risk of becoming lost.

It may also create continuous surveillance.

Assessment should consider:

  • the person’s wishes;
  • decision-making support;
  • the specific risk;
  • less intrusive alternatives;
  • who can view location;
  • when tracking is active;
  • how alerts operate;
  • accuracy limitations;
  • risk of family misuse;
  • review dates;
  • device removal; and
  • what happens when tracking fails.

The Positive Risk Enablement Planner can help teams balance personal freedom, foreseeable harm, privacy and proportionate safeguards when considering monitoring technologies.

Video Monitoring Is Especially Intrusive

Cameras may be proposed for fall detection, security, remote care or safeguarding.

They may record:

  • personal care;
  • family conversations;
  • visitors;
  • workers;
  • daily routines;
  • health events;
  • religious activity;
  • private relationships; and
  • periods of distress.

Video should not be used when a less intrusive technology can meet the same purpose.

Where cameras are used, their location, recording status, access, retention and review should be tightly controlled.

Monitoring Workers Raises Additional Ethical Questions

Home-monitoring systems may capture staff activity during care visits.

This can affect:

  • privacy;
  • employment rights;
  • professional relationships;
  • trust;
  • staff behavior;
  • evidence in complaints;
  • family expectations; and
  • retention of recordings.

Workers should know when monitoring is present and how information may be used.

Monitoring should not replace supervision, training and fair investigation.

Robotic Systems Require Cybersecurity Controls

Care robots may support lifting, mobility, communication, prompting or companionship.

Cybersecurity risks may include:

  • unauthorized remote control;
  • microphone or camera access;
  • manipulation of instructions;
  • unsafe movement;
  • extraction of personal information;
  • supplier access;
  • failed software updates;
  • loss of connectivity;
  • inaccurate identity recognition; and
  • continued operation after support ends.

Robotic safety should combine physical, software and information-security assurance.

Remote Supplier Access Must Be Controlled

Suppliers may need remote access to diagnose faults or update devices.

This access should be:

  • authorized;
  • time-limited;
  • logged;
  • restricted to necessary systems;
  • protected by strong authentication;
  • reviewed after use;
  • covered by contract; and
  • removed when no longer required.

Permanent supplier accounts with broad access create avoidable risk.

Telehealth Platforms Must Protect Confidentiality

Virtual consultations may involve:

  • video;
  • audio;
  • chat;
  • screen sharing;
  • clinical documents;
  • identity information;
  • family participation;
  • interpretation;
  • recording; and
  • supplier processing.

Services should confirm:

  • whether sessions are encrypted;
  • whether recordings are created;
  • where data is stored;
  • how participants are authenticated;
  • how unauthorized entry is prevented;
  • how interpreters join securely;
  • how links expire;
  • how technical support accesses sessions; and
  • how incidents are reported.

Privacy Also Depends on the Physical Environment

A technically secure consultation may still be overheard in:

  • a shared care-home room;
  • a family living area;
  • a community center;
  • a pharmacy;
  • a workplace;
  • a hospital corridor;
  • a staff vehicle; or
  • a crowded home.

Professionals should confirm who is present and whether the person can speak privately.

Alternative arrangements should be available where confidentiality cannot be protected.

Recording Virtual Consultations Requires Clear Rules

Recordings may be useful for:

  • clinical review;
  • communication support;
  • training;
  • quality assurance;
  • complaint investigation; or
  • allowing the person to revisit information.

They also create additional risk.

People should understand:

  • whether recording occurs;
  • why it is needed;
  • who can access it;
  • how long it is retained;
  • whether they can refuse;
  • whether a written summary is available instead;
  • how recordings are protected; and
  • how deletion is managed.

Electronic Records Can Spread Errors Rapidly

Connected records may distribute inaccurate information across multiple organizations.

Examples include:

  • incorrect diagnosis;
  • outdated medication;
  • wrong family contact;
  • misstated decision-making ability;
  • incorrect safeguarding information;
  • historic risk presented as current;
  • wrong address;
  • duplicate identity;
  • unverified allegation; or
  • misinterpreted personal preference.

Privacy includes the right not to be defined indefinitely by inaccurate or irrelevant information.

People Need Effective Routes to Correct Records

A correction process should explain:

  • how the person can identify an error;
  • which organization is responsible;
  • how evidence is reviewed;
  • how disagreement is recorded;
  • how connected systems are updated;
  • how urgent safety errors are prioritized;
  • how previous decisions are reviewed;
  • how the person is informed; and
  • how long correction should take.

Correction should not depend on the person navigating several organizations independently.

Data Minimization Reduces Privacy and Security Risk

Organizations should collect and retain only information needed for a clear purpose.

Excessive data may increase:

  • breach impact;
  • storage costs;
  • staff confusion;
  • unnecessary access;
  • supplier dependence;
  • risk of inappropriate secondary use;
  • difficulty correcting records;
  • identity theft exposure; and
  • public mistrust.

The availability of technology to collect information does not establish a legitimate need to do so.

Purpose Limitation Should Be Visible

Information collected for one reason should not automatically be reused for another.

For example, data collected for fall prevention should not automatically be used for:

  • employment decisions;
  • insurance pricing;
  • commercial advertising;
  • unrelated research;
  • family surveillance;
  • housing enforcement;
  • eligibility restriction; or
  • automated judgments about lifestyle.

New uses require appropriate authority, transparency and review.

Consent Is Not the Only Privacy Safeguard

Consent may be important, but it can become weak when:

  • the service is essential;
  • terms are complex;
  • the person fears losing support;
  • several data uses are bundled together;
  • future uses are unclear;
  • technology changes over time;
  • the person cannot negotiate supplier terms; or
  • withdrawal is difficult.

Organizations remain responsible for fairness, proportionality, security and lawful use even when a consent box has been selected.

Privacy Notices Must Be Understandable

People should be able to understand:

  • what information is collected;
  • why it is needed;
  • who receives it;
  • which suppliers are involved;
  • whether information leaves Japan;
  • whether automated analysis is used;
  • how long information is kept;
  • how access can be restricted;
  • how errors can be corrected;
  • how concerns can be raised; and
  • what happens when the service ends.

This connects with data governance, privacy and interoperability.

Privacy information should be available in plain language, accessible formats and non-digital forms.

Data Retention Should Reflect Care and Legal Need

Keeping information indefinitely may appear safe but creates long-term exposure.

Retention decisions should consider:

  • clinical need;
  • continuity of care;
  • legal obligations;
  • safeguarding;
  • complaint and incident review;
  • research approval;
  • the age and relevance of information;
  • supplier contracts;
  • archiving security;
  • the person’s rights; and
  • secure deletion capability.

Retention schedules should apply to backups, recordings, exported files and supplier copies as well as active records.

Secure Deletion Must Be Planned

Information may remain on:

  • old devices;
  • cloud backups;
  • supplier systems;
  • email accounts;
  • portable storage;
  • printed documents;
  • test systems;
  • replaced sensors;
  • returned tablets; and
  • staff personal devices.

Organizations need processes to confirm that information is removed or rendered inaccessible when no longer required.

Decommissioning Connected Devices Is a Privacy Event

When equipment is replaced, returned or transferred, teams should address:

  • stored personal information;
  • account credentials;
  • family access;
  • supplier connections;
  • remote-control permissions;
  • recording history;
  • device identifiers;
  • reuse;
  • physical destruction; and
  • evidence of secure deletion.

Removing a device from the home does not automatically remove the information associated with it.

Supplier Risk Extends Across the Care Ecosystem

Long-term care organizations may rely on technology suppliers for:

  • electronic records;
  • remote monitoring;
  • telehealth;
  • cloud hosting;
  • mobile applications;
  • care scheduling;
  • smart-home devices;
  • robotics;
  • artificial intelligence;
  • payment systems;
  • identity services;
  • cybersecurity monitoring;
  • data analytics; and
  • technical support.

A supplier compromise can therefore affect several organizations and thousands of older people at once.

Organizations remain accountable for understanding and managing supplier risk even when technical activity is outsourced.

Contracts Should Define Security Responsibilities Clearly

Supplier contracts should address:

  • security standards;
  • access controls;
  • encryption;
  • vulnerability management;
  • software updates;
  • incident notification;
  • subcontractors;
  • data location;
  • business continuity;
  • backup and restoration;
  • penetration testing;
  • audit rights;
  • insurance;
  • data return;
  • secure deletion; and
  • support during contract exit.

General statements that a supplier follows good practice are not sufficient for care-critical systems.

Subcontractors Can Create Hidden Dependencies

A primary supplier may depend on other organizations for:

  • cloud infrastructure;
  • software development;
  • technical support;
  • analytics;
  • translation;
  • identity verification;
  • payment processing;
  • device manufacture;
  • telecommunications;
  • data storage; and
  • artificial intelligence models.

Organizations should know which subcontractors process information or support essential functions.

Contractual controls should extend through the full supply chain.

Supplier Concentration Creates Systemic Risk

Several municipalities or providers may depend on the same platform, cloud service or device manufacturer.

A single failure could then disrupt a large part of the care system.

Leaders should examine:

  • market concentration;
  • common infrastructure;
  • shared software components;
  • single points of failure;
  • availability of alternative suppliers;
  • data portability;
  • transition time;
  • specialist workforce dependence; and
  • the consequences of supplier insolvency.

Resilience planning should consider regional and national dependencies rather than only individual contracts.

Software Supply Chains Require Ongoing Oversight

Modern applications may contain components developed by several organizations.

Risks can arise through:

  • outdated software libraries;
  • unpatched vulnerabilities;
  • malicious updates;
  • compromised development tools;
  • poorly controlled code repositories;
  • unknown third-party components;
  • weak testing;
  • expired certificates;
  • insecure application interfaces; and
  • unsupported operating systems.

Suppliers should maintain an accurate understanding of the components within their products and respond quickly when vulnerabilities are identified.

Unsupported Technology Creates Accumulating Risk

Care organizations may continue using older systems because replacement is expensive or operationally difficult.

Unsupported systems may no longer receive:

  • security patches;
  • technical assistance;
  • compatibility updates;
  • vulnerability monitoring;
  • hardware replacement;
  • certificate renewal;
  • application support; or
  • compliance assurance.

Organizations should maintain an inventory showing support dates, known risks and replacement plans.

Where immediate replacement is not possible, additional safeguards and isolation may be required.

Procurement Should Test Cybersecurity Claims

Technology procurement should require evidence of:

  • secure development practices;
  • independent testing;
  • vulnerability management;
  • patching timescales;
  • multi-factor authentication;
  • data encryption;
  • access logging;
  • incident response;
  • backup and recovery;
  • business continuity;
  • subcontractor oversight;
  • secure configuration;
  • privacy by design;
  • accessibility;
  • data portability; and
  • secure contract exit.

Demonstrations should include failure, recovery and emergency scenarios rather than only normal operation.

Security Requirements Must Remain Usable

Overly complex controls may encourage unsafe workarounds.

Examples include:

  • staff sharing accounts;
  • writing passwords beside devices;
  • using personal messaging applications;
  • copying information to paper;
  • leaving sessions open;
  • avoiding system updates;
  • using one administrator account for several workers;
  • sending records to personal email; and
  • disabling controls that interrupt care.

Security design should reflect real workflows, time pressure, accessibility and workforce capability.

Frontline workers should help test whether controls are practical.

Security Culture Matters More Than Annual Training Alone

Annual e-learning may provide basic awareness but cannot create a resilient security culture by itself.

A stronger culture includes:

  • visible leadership;
  • regular discussion of current threats;
  • safe reporting of mistakes;
  • practical simulations;
  • rapid feedback;
  • clear escalation;
  • learning from incidents;
  • role-specific training;
  • support for new staff;
  • supplier participation;
  • recognition of positive practice; and
  • continuous improvement.

Workers should feel able to report a suspicious message or mistaken click immediately without fear of automatic punishment.

Blame Can Delay Incident Reporting

Workers may conceal or delay reporting when they believe they will be disciplined for:

  • clicking a malicious link;
  • sending information to the wrong person;
  • losing a device;
  • sharing a password;
  • using an unauthorized application;
  • failing to install an update;
  • leaving a record open;
  • disclosing information accidentally; or
  • being deceived by a sophisticated fraud.

Delays allow harm to spread.

Organizations should distinguish honest error, weak system design, reckless behavior and deliberate misuse.

Operational Example: Creating a Just Cybersecurity Culture

A home-care worker clicks a fraudulent link that imitates the organization’s scheduling system.

The worker immediately reports the incident rather than attempting to hide it.

A five-stage response follows:

  1. Contain the risk: The account is secured, active sessions closed and suspicious activity reviewed.
  2. Protect care: Teams check whether schedules, addresses or care instructions were accessed or altered.
  3. Support the worker: The worker receives practical guidance without automatic blame.
  4. Investigate the system: Leaders examine why the message was convincing and whether technical controls could have blocked it.
  5. Share learning: Staff receive a brief, anonymized alert showing how to recognize similar attacks.

The organization improves security because the worker felt safe to report quickly.

Training Should Reflect Different Roles

A care worker, system administrator, board member and family support volunteer face different risks.

Role-specific training may address:

  • secure mobile working;
  • record access;
  • phishing recognition;
  • care-related fraud;
  • privileged accounts;
  • supplier access;
  • incident escalation;
  • remote monitoring;
  • privacy conversations;
  • family permissions;
  • device installation;
  • business continuity; and
  • safe use of artificial intelligence.

Training should include realistic scenarios drawn from the organization’s own systems and services.

Temporary and Agency Workers Must Be Included

Temporary workers may require rapid access to systems during staffing shortages.

Risks can arise when:

  • identity checks are incomplete;
  • accounts are shared;
  • training is abbreviated;
  • access is broader than needed;
  • credentials remain active after the shift;
  • workers use personal devices;
  • local processes are unfamiliar; or
  • incident reporting routes are unclear.

Security arrangements should support urgent staffing while maintaining individual accountability.

Volunteers and Community Partners Need Appropriate Controls

Community organizations may support:

  • digital inclusion;
  • transport;
  • welfare checks;
  • social participation;
  • emergency response;
  • caregiver support;
  • meal delivery;
  • technology setup; and
  • community navigation.

They may need limited access to personal information.

Access should be based on defined purpose, confidentiality, training, supervision and clear deletion arrangements.

Community value should not be undermined by transferring unnecessary data.

Security Testing Should Include Social Engineering

Technical testing may identify software vulnerabilities but overlook manipulation of people.

Social-engineering testing may examine attempts to:

  • obtain passwords;
  • impersonate senior managers;
  • change supplier bank details;
  • gain entry to facilities;
  • persuade staff to install software;
  • obtain resident information;
  • reset accounts fraudulently;
  • access records through family impersonation;
  • exploit emergency procedures; or
  • retrieve information from discarded documents.

Testing should be proportionate, ethically governed and used for learning rather than humiliation.

Physical Security Remains Part of Cybersecurity

Digital systems depend on physical assets such as:

  • servers;
  • routers;
  • network cabinets;
  • staff devices;
  • backup media;
  • smart-home hubs;
  • care-home terminals;
  • robotic equipment;
  • security tokens;
  • printed recovery codes; and
  • portable storage.

Unauthorized physical access may allow theft, tampering or connection of malicious equipment.

Security plans should cover homes, community locations, care facilities and offices.

Paper Records Still Create Privacy Risk

During system outages or mobile working, organizations may use paper.

Risks may include:

  • documents left in vehicles;
  • records visible in homes;
  • incorrect disposal;
  • uncontrolled copying;
  • missing pages;
  • poor version control;
  • information not transferred back to the digital record;
  • unreadable handwriting;
  • incorrect filing; and
  • continued use after systems recover.

Paper continuity procedures should include secure storage, collection, reconciliation and destruction.

Printing Should Be Controlled but Not Prohibited Unrealistically

Some workers may need printed information for:

  • outage continuity;
  • home visits with poor connectivity;
  • accessible communication;
  • emergency evacuation;
  • medication support;
  • family discussion; or
  • legal requirements.

Organizations should define when printing is appropriate and how documents are secured, updated and destroyed.

Cybersecurity Incidents Require Care-Focused Triage

Initial incident assessment should consider:

  • which systems are unavailable;
  • whether information was altered;
  • whether data was extracted;
  • which people are affected;
  • whether medication information is accessible;
  • whether monitoring has stopped;
  • whether staffing can be coordinated;
  • whether family contacts are available;
  • whether building systems are affected;
  • whether hospital discharge should pause;
  • whether manual processes are safe; and
  • whether emergency services or regulators need notification.

Technical severity and care severity may differ.

A small system failure can be high risk when it affects one person with complex medication or communication needs.

Incident Response Teams Need Multidisciplinary Membership

A cyber incident may require input from:

  • information technology;
  • information governance;
  • clinical leadership;
  • long-term care operations;
  • safeguarding;
  • human resources;
  • communications;
  • legal advisers;
  • facilities management;
  • supplier management;
  • municipal leadership;
  • emergency planning; and
  • senior executives.

Technical teams cannot determine care priorities alone.

Roles and Decision Authority Must Be Clear

During an incident, leaders should know who may:

  • disconnect systems;
  • activate manual procedures;
  • contact law enforcement;
  • notify regulators;
  • communicate with families;
  • pause admissions;
  • cancel digital appointments;
  • authorize emergency spending;
  • engage specialist responders;
  • restore systems;
  • approve public statements; and
  • declare recovery complete.

Unclear authority can delay containment and care decisions.

Communication During a Cyber Incident Must Be Trusted

Normal email and messaging systems may be unavailable or compromised.

Organizations need alternative routes such as:

  • verified telephone trees;
  • secure emergency messaging;
  • offline contact lists;
  • pre-agreed regional channels;
  • radio or public information;
  • face-to-face briefings;
  • supplier hotlines;
  • emergency websites; and
  • community partner networks.

Staff should know which communications are authentic during disruption.

Public Communication Should Be Honest and Proportionate

Older people and families may need information about:

  • which services are affected;
  • whether appointments will continue;
  • how to obtain medication advice;
  • whether remote monitoring is functioning;
  • whether personal information may have been accessed;
  • which fraud risks to watch for;
  • how to contact the organization;
  • what alternative arrangements are available;
  • how long disruption may continue; and
  • what support will be provided.

Organizations should avoid both unnecessary alarm and misleading reassurance.

People Should Be Warned About Secondary Fraud

After a data breach, criminals may use stolen information to create convincing messages.

They may know:

  • the person’s name;
  • provider;
  • health condition;
  • family contact;
  • address;
  • appointment details;
  • device type;
  • care-worker name;
  • municipality; or
  • financial information.

People should receive clear guidance about how legitimate organizations will communicate and what information they will never request.

Operational Example: Maintaining Care During a Regional Cyberattack

A regional cloud platform used by hospitals, pharmacies and long-term care providers becomes unavailable following a cyberattack.

A five-stage continuity response is activated:

  1. Prioritize high-risk people: Providers identify individuals dependent on medication administration, monitoring or time-critical support.
  2. Activate verified summaries: Protected offline care and medication information is made available to authorized teams.
  3. Use alternative communication: Hospitals, pharmacies and providers coordinate through pre-agreed emergency channels.
  4. Reconcile decisions: Every manual change is recorded for later transfer into restored systems.
  5. Restore safely: Systems return in stages after security testing, data-integrity checks and operational approval.

The region protects care continuity while avoiding uncontrolled use of outdated information.

Business Continuity Must Cover Extended Disruption

Cyber incidents may last longer than power outages or routine technical failures.

Plans should consider disruption lasting:

  • several hours;
  • several days;
  • several weeks; or
  • an uncertain period.

Extended continuity requires arrangements for:

  • staffing;
  • paper supplies;
  • medication records;
  • manual scheduling;
  • financial payments;
  • supplier ordering;
  • equipment maintenance;
  • family communication;
  • regulatory reporting;
  • staff wellbeing;
  • regional mutual aid; and
  • secure storage of temporary records.

Offline Information Must Be Current and Protected

Organizations may maintain emergency copies of:

  • medication summaries;
  • care plans;
  • risk information;
  • emergency contacts;
  • staff contact lists;
  • supplier details;
  • continuity procedures;
  • facility plans;
  • critical passwords or recovery instructions; and
  • high-risk resident lists.

Offline information should be updated, encrypted where appropriate and accessible only to authorized people.

Old emergency copies can create serious safety risk.

Manual Processes Need Clear Limits

During disruption, manual processes may be necessary for:

  • medication administration;
  • care notes;
  • staff allocation;
  • incident recording;
  • monitoring observations;
  • hospital communication;
  • supplier orders;
  • family contact;
  • appointment management; and
  • financial transactions.

Teams should know which activities can continue manually and which require specialist approval or suspension.

Recovery Requires More Than Switching Systems Back On

Before restored systems return to full use, organizations should confirm:

  • the threat has been contained;
  • credentials have been secured;
  • malicious access has been removed;
  • software is patched;
  • data is accurate;
  • backups are trustworthy;
  • manual records are reconciled;
  • interfaces are functioning;
  • alerts are reaching the correct teams;
  • staff understand revised processes;
  • suppliers are safe to reconnect; and
  • continued monitoring is in place.

Premature restoration may reintroduce attackers or spread corrupted information.

Data Reconciliation Is a Major Recovery Task

During an outage, care decisions may be recorded on paper, spreadsheets or temporary systems.

Recovery should ensure that:

  • medication changes are transferred;
  • new risks are recorded;
  • hospital admissions and discharges are updated;
  • appointments are reconciled;
  • staff notes are entered;
  • incidents are recorded;
  • family-contact changes are updated;
  • temporary records are securely destroyed; and
  • duplicate or conflicting entries are resolved.

Reconciliation requires protected workforce time and quality checks.

Post-Incident Review Should Examine Care Consequences

Technical reports may focus on the attack route, malware and restoration.

Care-focused review should also examine:

  • delayed medication;
  • missed visits;
  • failed monitoring;
  • hospital discharge delays;
  • emergency admissions;
  • staffing disruption;
  • family distress;
  • privacy harm;
  • financial loss;
  • safeguarding concerns;
  • documentation gaps;
  • inequality in access;
  • worker fatigue; and
  • loss of public trust.

The Quality Improvement Action Plan Builder can help organizations convert cyber-incident findings into named actions, deadlines, evidence requirements and executive oversight.

Near Misses Should Also Inform Improvement

Organizations should learn from events such as:

  • blocked phishing attempts;
  • lost devices recovered quickly;
  • supplier vulnerabilities identified before exploitation;
  • incorrect recipients detected before disclosure;
  • unusual account activity stopped;
  • failed backup tests;
  • weak emergency communication;
  • unauthorized access attempts;
  • outdated devices found during audit; and
  • unsafe staff workarounds.

Near misses reveal weaknesses while there is still time to intervene.

Cybersecurity Metrics Should Support Decision-Making

Leaders may monitor:

  • phishing reports;
  • account compromises;
  • patching times;
  • unsupported systems;
  • multi-factor authentication coverage;
  • privileged-account reviews;
  • supplier risks;
  • backup success;
  • restoration testing;
  • device loss;
  • incident response times;
  • training completion;
  • repeat vulnerabilities;
  • care disruption;
  • privacy complaints; and
  • corrective-action completion.

The Quality Dashboard Builder can help organizations combine cybersecurity, privacy, care continuity, supplier and workforce indicators within one assurance view.

Training Completion Is Not Proof of Security

A report showing that all staff completed training does not demonstrate that:

  • phishing is recognized;
  • mistakes are reported promptly;
  • password practices are safe;
  • mobile devices are secure;
  • continuity plans work;
  • supplier access is controlled;
  • staff understand privacy choices;
  • high-risk changes are verified; or
  • leaders respond effectively.

Metrics should test behavior, controls and outcomes.

Board Reporting Should Connect Cyber Risk to Care Risk

Boards should understand:

  • which services depend on digital systems;
  • where single points of failure exist;
  • which suppliers create high dependency;
  • how long care can continue offline;
  • which systems are unsupported;
  • whether backups have been restored successfully;
  • how cyber incidents affect older people;
  • how privacy harms are addressed;
  • where investment is insufficient;
  • how regional partners coordinate; and
  • whether improvement actions are completed.

Cybersecurity should not be reduced to a technical traffic-light report.

Risk Registers Should Reflect Real Dependencies

Cyber risks may be understated when they are described only as general threats.

More useful risk statements identify:

  • the system or dependency;
  • the threat;
  • the vulnerability;
  • the affected population;
  • the care consequence;
  • existing controls;
  • control weaknesses;
  • recovery capability;
  • accountable owner; and
  • planned improvement.

The Regulatory Readiness Gap Analyzer can help providers identify weaknesses in cybersecurity, privacy, business continuity, supplier assurance, record governance and organizational oversight.

Privacy Impact Assessment Should Begin Early

New technology should be assessed before procurement or deployment.

A privacy impact assessment may examine:

  • the care purpose;
  • the information collected;
  • necessity and proportionality;
  • who receives the information;
  • supplier involvement;
  • automated processing;
  • family access;
  • international data transfer;
  • retention;
  • security;
  • accessibility;
  • withdrawal;
  • potential discrimination;
  • less intrusive alternatives; and
  • the views of older people.

Assessment after implementation may be too late to redesign fundamental features.

Privacy by Design Should Shape the Default Service

A privacy-protective service may:

  • collect less information;
  • restrict default access;
  • separate optional functions;
  • limit retention;
  • provide clear controls;
  • avoid unnecessary recording;
  • minimize supplier access;
  • use local processing where appropriate;
  • support anonymous or pseudonymous use;
  • make withdrawal simple; and
  • provide non-digital alternatives.

People should not have to locate hidden settings to obtain basic privacy.

Data Sharing Requires More Than a Written Agreement

Organizations may sign information-sharing agreements but still lack operational clarity.

They should also define:

  • which information is shared;
  • for which purpose;
  • through which system;
  • who may access it;
  • how accuracy is maintained;
  • how corrections are communicated;
  • how incidents are reported;
  • how consent or objection is recorded;
  • how records are retained;
  • how suppliers participate;
  • how sharing ends; and
  • how people receive explanations.

Information governance must operate in daily practice, not only in policy documents.

Emergency Sharing Should Be Proportionate

During emergencies, organizations may need to share information rapidly.

This may include:

  • identity;
  • location;
  • medication;
  • mobility;
  • communication needs;
  • medical equipment;
  • caregiver availability;
  • evacuation support;
  • emergency contacts; and
  • immediate risk.

Emergency authority should not become a permanent justification for unrestricted data sharing.

Access should be logged, reviewed and reduced when the emergency ends.

Research Use Requires Separate Governance

Connected care data may support research into:

  • healthy longevity;
  • dementia;
  • falls;
  • medication;
  • care pathways;
  • workforce;
  • remote monitoring;
  • robotics;
  • artificial intelligence;
  • health inequality;
  • caregiver support; and
  • service outcomes.

Research potential does not remove the need for transparency, ethical review, security and proportionate use.

De-Identification Does Not Remove Every Privacy Risk

People may sometimes be re-identified when datasets contain combinations of:

  • age;
  • location;
  • rare conditions;
  • service patterns;
  • dates;
  • household information;
  • device identifiers;
  • genetic information;
  • movement data; or
  • linked public information.

Risk increases when several datasets are combined.

De-identification should be supported by access controls, contractual restrictions and monitoring of use.

Commercial Use Can Undermine Trust

Older people may be concerned that care data will be used for:

  • advertising;
  • insurance decisions;
  • product development;
  • credit assessment;
  • employment decisions;
  • targeted sales;
  • pricing;
  • commercial profiling; or
  • sale to data intermediaries.

Organizations should be transparent about commercial partnerships and distinguish care delivery from optional secondary use.

Artificial Intelligence Creates New Security and Privacy Risks

AI systems may process:

  • care records;
  • clinical notes;
  • voice recordings;
  • video;
  • sensor data;
  • location;
  • family information;
  • staff activity;
  • incident reports;
  • communication history; and
  • population datasets.

Risks may involve:

  • unauthorized training use;
  • data leakage;
  • inaccurate outputs;
  • model manipulation;
  • supplier access;
  • hidden profiling;
  • weak explainability;
  • re-identification;
  • cyberattack; and
  • dependence on external platforms.

Public AI Tools Should Not Receive Sensitive Care Information

Workers may be tempted to enter information into general AI tools to:

  • summarize records;
  • draft care plans;
  • translate notes;
  • prepare reports;
  • write family communications;
  • analyze incidents;
  • create training materials; or
  • organize meeting notes.

This may expose personal information to systems not approved for care use.

Organizations need clear guidance, secure alternatives and monitoring of unauthorized AI use.

AI Access Should Be Limited to Necessary Data

An AI system designed to support appointment scheduling may not need complete clinical records.

A fall-risk model may not need financial information or unrelated family history.

Data access should be matched to the defined purpose.

Broad access increases breach impact and may introduce irrelevant bias into automated outputs.

Model Security Requires Specialist Oversight

AI systems may be vulnerable to:

  • malicious inputs;
  • manipulated training data;
  • prompt attacks;
  • model extraction;
  • unauthorized changes;
  • insecure interfaces;
  • adversarial examples;
  • data leakage through outputs;
  • supplier compromise; and
  • uncontrolled model updates.

Security assurance should cover the model, data, infrastructure, interfaces and human workflow.

AI Outputs Can Reveal Sensitive Information Indirectly

An automated summary or risk score may disclose:

  • suspected dementia;
  • mental health concerns;
  • family conflict;
  • safeguarding information;
  • substance use;
  • financial vulnerability;
  • predicted mortality;
  • location patterns;
  • caregiver strain; or
  • future service needs.

Access to AI outputs should be controlled as carefully as access to source records.

People Need Transparency About Automated Use

Older people should understand when AI is used to:

  • summarize records;
  • prioritize referrals;
  • predict deterioration;
  • identify safeguarding risk;
  • recommend services;
  • monitor behavior;
  • allocate resources;
  • detect fraud;
  • generate care communications; or
  • support professional decisions.

Human review and challenge should remain available where automated processing may affect rights, access or care.

Cybersecurity Must Be Included in AI Governance

AI governance should address:

  • approved use;
  • data protection;
  • access controls;
  • supplier assurance;
  • model security;
  • output verification;
  • bias;
  • explainability;
  • incident response;
  • version control;
  • human oversight;
  • monitoring;
  • withdrawal; and
  • safe decommissioning.

Innovation governance should not treat security as a later technical check.

Privacy-Preserving Technologies May Support Safer Analysis

Future approaches may include:

  • federated learning;
  • secure data environments;
  • pseudonymization;
  • differential privacy;
  • confidential computing;
  • local device processing;
  • role-based analytical access;
  • synthetic data;
  • controlled research environments; and
  • auditable query systems.

These approaches may reduce unnecessary movement or exposure of identifiable information.

They do not remove the need for governance, transparency and purpose limitation.

Federated Models Can Reduce Centralized Exposure

A federated system may allow approved analysis across data held by different organizations without transferring every record into one central database.

Potential benefits include:

  • greater local control;
  • reduced data movement;
  • limited central storage;
  • regional resilience;
  • more proportionate research access;
  • support for national planning; and
  • clearer source accountability.

Federated systems still require secure identity, common standards, strong endpoints and transparent governance.

Encryption Protects Data but Is Not a Complete Solution

Encryption can help protect information during storage and transmission.

It does not prevent:

  • authorized users misusing information;
  • phishing;
  • poor consent;
  • excessive collection;
  • weak access controls;
  • inaccurate records;
  • malware operating after login;
  • screen capture;
  • unsafe printed copies; or
  • data exposure through compromised applications.

Encryption should form part of a wider control framework.

Authentication Must Balance Security and Accessibility

Strong authentication may involve:

  • passwords;
  • passkeys;
  • biometrics;
  • security tokens;
  • device recognition;
  • one-time codes;
  • smart cards; or
  • multi-factor authentication.

Some methods may be difficult for people with cognitive, visual, hearing or dexterity needs.

Services should provide secure, accessible options and supported recovery.

Biometric Security Requires Careful Governance

Biometric systems may use:

  • fingerprints;
  • facial recognition;
  • voice patterns;
  • iris scans;
  • gait;
  • behavioral patterns; or
  • other biological characteristics.

Biometric data cannot be changed easily if compromised.

Organizations should consider:

  • necessity;
  • accuracy;
  • bias;
  • accessibility;
  • storage;
  • supplier use;
  • fallback methods;
  • consent;
  • security;
  • retention; and
  • what happens when recognition fails.

Account Recovery Must Be Secure and Human-Centred

People may lose access after:

  • forgetting credentials;
  • changing telephone numbers;
  • replacing devices;
  • bereavement;
  • cognitive change;
  • moving home;
  • family conflict;
  • fraud;
  • account lockout; or
  • loss of identity documents.

Recovery should not depend entirely on digital steps that the person cannot complete.

Human verification and supported access should remain available.

Security Controls Should Not Enable Family Takeover

When a person struggles with authentication, services may default to allowing a relative to control the account.

This can remove:

  • privacy;
  • direct communication;
  • control over appointments;
  • access to records;
  • financial autonomy;
  • the ability to change permissions; and
  • the opportunity to report abuse.

Supported access should preserve the person’s authority wherever possible.

Privacy Must Include People With Impaired Decision-Making

Cognitive impairment does not remove a person’s right to dignity, confidentiality and participation.

Support may involve:

  • simple explanations;
  • visual information;
  • repetition;
  • familiar communication;
  • trial periods;
  • trusted support;
  • review of preferences;
  • limited permissions;
  • least-intrusive options; and
  • independent advocacy.

Decisions should distinguish between inability to manage one digital task and inability to make broader choices about privacy.

Safeguarding and Privacy Must Work Together

Information may need to be shared to protect someone from abuse, neglect or exploitation.

At the same time, excessive or poorly controlled sharing can create further harm.

Professionals should consider:

  • the nature and immediacy of risk;
  • the person’s wishes;
  • decision-making support;
  • who may be causing harm;
  • which information is necessary;
  • safe contact routes;
  • family access;
  • technology-facilitated abuse;
  • documentation;
  • review; and
  • how the person will be informed.

This connects with safeguarding, abuse, neglect and exploitation.

Technology-Facilitated Abuse May Be Difficult to Detect

Abuse may involve:

  • device surveillance;
  • location tracking;
  • password control;
  • interception of appointments;
  • record access;
  • online financial coercion;
  • impersonation;
  • restriction of communication;
  • manipulation of smart-home controls;
  • threats involving private information; and
  • fraudulent changes to delegated access.

Professionals need confidential ways to ask about digital control and provide safer alternatives.

Operational Example: Protecting a Person From Digital Coercion

A care manager notices that all portal messages are answered by a relative and that the older person appears unaware of changes to appointments.

A five-stage safeguarding response is used:

  1. Create a private opportunity: The care manager speaks with the person without the relative present.
  2. Assess digital control: Access, passwords, devices, financial activity and monitoring arrangements are reviewed.
  3. Secure communication: A separate safe contact method and supported account recovery are arranged.
  4. Restrict unauthorized access: Delegated permissions are reviewed and changed according to the person’s wishes and safeguarding needs.
  5. Coordinate protection: Relevant safeguarding, financial and care services develop an ongoing plan.

The response treats digital access as part of personal safety and autonomy.

Cybersecurity Can Affect Workforce Wellbeing

Cyber incidents may create:

  • long working hours;
  • manual documentation burden;
  • uncertainty;
  • fear of blame;
  • aggressive public contact;
  • repeated system failure;
  • pressure to improvise;
  • delayed payroll;
  • moral distress;
  • exposure to disturbing stolen information; and
  • fatigue during recovery.

Incident plans should include staff support, rest, communication and workload management.

Cybersecurity Specialists Need Care-System Understanding

Technical experts should understand:

  • medication risk;
  • care continuity;
  • hospital discharge;
  • remote monitoring;
  • dementia support;
  • home-care workflows;
  • care-home operations;
  • safeguarding;
  • family involvement;
  • rural service delivery;
  • accessibility; and
  • the consequences of system downtime.

Security decisions should be made with operational and clinical partners.

Care Leaders Need Sufficient Cyber Literacy

Senior leaders do not need to become technical specialists.

They should be able to ask:

  • Which services are most dependent on technology?
  • Which systems are unsupported?
  • Which suppliers create concentration risk?
  • How quickly are serious vulnerabilities corrected?
  • Can backups be restored?
  • How long can care continue offline?
  • Who controls privileged access?
  • How are older people informed after breaches?
  • How are privacy choices protected?
  • What evidence shows that controls work?

Leadership literacy is essential for meaningful challenge and investment decisions.

Investment Should Be Based on Risk, Not Visibility

Organizations may prioritize visible new technology while underfunding:

  • legacy-system replacement;
  • identity management;
  • backup testing;
  • staff training;
  • incident response;
  • supplier assurance;
  • network segmentation;
  • device management;
  • privacy support;
  • technical resilience;
  • business continuity; and
  • specialist workforce capacity.

Cybersecurity investment should reflect the potential impact on care and public trust.

Smaller Providers Need Proportionate Support

Small long-term care and home-care organizations may lack:

  • specialist security staff;
  • procurement expertise;
  • legal advice;
  • incident-response capability;
  • negotiating power with suppliers;
  • backup infrastructure;
  • training capacity;
  • continuous monitoring;
  • funding for replacement systems; and
  • access to technical assurance.

National and regional support could provide shared services, templates, training, incident assistance and procurement frameworks.

Shared Security Services Could Improve System Resilience

Regional or national support might include:

  • threat intelligence;
  • security monitoring;
  • incident-response teams;
  • approved supplier frameworks;
  • vulnerability alerts;
  • backup guidance;
  • phishing simulations;
  • technical standards;
  • emergency communication;
  • legal and regulatory support;
  • forensic investigation; and
  • recovery assistance.

Shared services should strengthen rather than replace local accountability.

Community Organizations Should Not Be Excluded by Security Requirements

Small voluntary and neighbourhood groups may contribute significantly to aging support.

Security expectations should be proportionate to:

  • the information accessed;
  • the purpose;
  • the number of people involved;
  • the systems used;
  • the potential harm;
  • the duration of access; and
  • the organization’s capability.

Where access to sensitive data is necessary, commissioners should provide funding, guidance and secure tools.

Cybersecurity Should Support Interoperability

Connected care requires information to move safely between organizations.

Security should enable trusted exchange through:

  • verified identities;
  • role-based access;
  • encrypted interfaces;
  • common standards;
  • audit logging;
  • data validation;
  • supplier assurance;
  • incident coordination;
  • secure correction; and
  • continuity arrangements.

Security should not become a justification for withholding information that is genuinely necessary for safe care.

Zero-Trust Principles May Support Connected Care

A zero-trust approach assumes that no user, device or system should be trusted automatically because it is inside a network.

Controls may include:

  • continuous identity verification;
  • least-privilege access;
  • device checks;
  • network segmentation;
  • behavior monitoring;
  • time-limited sessions;
  • strong authentication;
  • rapid access removal;
  • restricted supplier connections; and
  • verification of every sensitive transaction.

Implementation should remain usable for care workers and accessible to older people.

Network Segmentation Can Limit Incident Spread

Organizations may separate:

  • clinical and care records;
  • guest Wi-Fi;
  • building systems;
  • smart-home devices;
  • robotics;
  • administrative systems;
  • supplier access;
  • backup infrastructure;
  • research environments; and
  • personal devices.

Segmentation can prevent one compromised device from providing unrestricted access to the wider environment.

Device Inventories Are Essential

Organizations cannot secure equipment they do not know exists.

An inventory should record:

  • device type;
  • location;
  • owner;
  • user;
  • operating system;
  • software version;
  • support status;
  • network connection;
  • information processed;
  • supplier;
  • update arrangements;
  • security configuration;
  • maintenance history; and
  • decommissioning status.

Inventories should include equipment installed in private homes as part of commissioned care.

Vulnerability Management Must Prioritize Care Consequences

Not every vulnerability carries the same operational risk.

Prioritization should consider:

  • likelihood of exploitation;
  • internet exposure;
  • availability of patches;
  • system criticality;
  • data sensitivity;
  • number of affected people;
  • ability to isolate the system;
  • impact of downtime;
  • supplier support;
  • existing controls; and
  • potential care harm.

High-risk vulnerabilities should have named owners and defined remediation timescales.

Patching Requires Operational Coordination

Updates may interrupt:

  • care records;
  • monitoring;
  • telehealth;
  • staff scheduling;
  • smart-home systems;
  • robotic equipment;
  • building controls;
  • pharmacy interfaces; and
  • family portals.

Patching plans should include testing, downtime communication, rollback arrangements and care continuity.

Delaying updates indefinitely because systems are operationally important can create greater future risk.

Penetration Testing Should Reflect Real Care Environments

Testing may examine:

  • external systems;
  • internal networks;
  • mobile applications;
  • cloud platforms;
  • remote access;
  • smart-home devices;
  • robotics;
  • telehealth;
  • supplier interfaces;
  • wireless networks;
  • identity systems; and
  • physical access.

Testing should be coordinated carefully so that essential care systems are not disrupted.

Security Monitoring Must Respect Privacy

Organizations may monitor network activity, logins, device behavior and staff access to identify threats.

Monitoring should be:

  • necessary;
  • proportionate;
  • transparent;
  • restricted to defined purposes;
  • subject to access controls;
  • retained for an appropriate period;
  • reviewed for false positives;
  • protected from misuse; and
  • connected to fair investigation.

Security monitoring should not become unrestricted surveillance of workers or older people.

Anomaly Detection Can Support Early Intervention

Systems may identify unusual activity such as:

  • access at unexpected times;
  • large record downloads;
  • logins from unfamiliar locations;
  • rapid access to many records;
  • unusual changes to contact details;
  • failed authentication attempts;
  • new supplier accounts;
  • unexpected data transfer;
  • disabled security tools; or
  • access after employment ends.

Automated alerts should be reviewed by trained people before conclusions are drawn.

Alert Fatigue Can Weaken Cybersecurity

Security teams may receive large numbers of low-value alerts.

This can lead to:

  • delayed investigation;
  • important signals being missed;
  • routine dismissal;
  • staff fatigue;
  • poor prioritization;
  • unclear accountability; and
  • overdependence on automated scoring.

Alerts should be tuned according to risk, context and available response capacity.

Security Operations Need Care Escalation Routes

A technical alert may require operational action when it affects:

  • medication;
  • remote monitoring;
  • emergency contacts;
  • staff scheduling;
  • building access;
  • hospital discharge;
  • family communication;
  • personal alarms;
  • robotic equipment; or
  • high-risk records.

Security teams should know which care leaders to contact and how urgently.

National Threat Intelligence Could Protect the Sector

Japan could strengthen long-term care resilience through timely sharing of information about:

  • active phishing campaigns;
  • ransomware groups;
  • supplier vulnerabilities;
  • fraud patterns;
  • malicious domains;
  • compromised software;
  • device weaknesses;
  • attack techniques;
  • recommended mitigations; and
  • lessons from incidents.

Information should be translated into practical actions suitable for providers of different sizes.

Incident Reporting Should Support National Learning

A national reporting model could help identify:

  • repeated supplier failures;
  • common phishing methods;
  • unsupported technology;
  • care-disruption patterns;
  • privacy weaknesses;
  • regional dependencies;
  • fraud targeting older people;
  • AI-related incidents;
  • smart-home vulnerabilities; and
  • effective recovery practices.

Reporting should encourage openness and avoid unnecessary duplication across agencies.

International Cooperation Is Increasingly Important

Technology suppliers, cloud services and cybercriminal groups operate across borders.

International cooperation may support:

  • threat intelligence;
  • law-enforcement action;
  • supplier assurance;
  • vulnerability disclosure;
  • incident coordination;
  • research;
  • common standards;
  • cross-border data protection;
  • ransomware disruption; and
  • learning from attacks on health and care systems.

Japan’s aging-care cybersecurity strategy should connect with wider national and international cyber resilience.

Cyber Insurance May Provide Support but Not Prevention

Insurance may assist with:

  • forensic investigation;
  • legal advice;
  • notification costs;
  • public communication;
  • business interruption;
  • recovery services;
  • identity-protection support; and
  • specialist incident response.

Coverage may be limited by exclusions, security requirements, notification delays or changing market conditions.

Insurance should not replace investment in controls and continuity.

Organizations Should Understand Their Insurance Conditions

Policies may require:

  • multi-factor authentication;
  • regular backups;
  • patching;
  • incident notification within defined timescales;
  • approved response suppliers;
  • staff training;
  • access controls;
  • security monitoring;
  • documented continuity; and
  • cooperation with investigation.

Leaders should know whether actual practice meets these conditions before an incident occurs.

Cybersecurity Audits Should Examine Operational Reality

Audit should test:

  • whether access matches roles;
  • whether inactive accounts are removed;
  • whether backups restore successfully;
  • whether continuity plans work;
  • whether staff report incidents;
  • whether supplier access is controlled;
  • whether devices are supported;
  • whether privacy choices are reflected in systems;
  • whether emergency records are current;
  • whether vulnerabilities are corrected;
  • whether AI tools are approved; and
  • whether improvement actions are sustained.

Document review should be combined with observation, testing and staff interviews.

Simulation Exercises Can Reveal Hidden Weaknesses

Exercises may test scenarios involving:

  • ransomware;
  • cloud failure;
  • supplier compromise;
  • loss of medication records;
  • failure of remote monitoring;
  • stolen devices;
  • fraudulent payment changes;
  • smart-home disruption;
  • data theft;
  • AI-system manipulation;
  • regional outage; and
  • public misinformation.

Exercises should involve operational teams, senior leaders, suppliers and partner organizations.

Operational Example: Testing a Care-Home Cyber Continuity Plan

A care home runs an exercise in which its electronic records, call-bell dashboard and staff-scheduling system become unavailable.

The exercise follows five stages:

  1. Activate manual care: Teams access protected emergency summaries and paper medication procedures.
  2. Maintain staffing: Managers use offline contact lists and confirm shifts directly.
  3. Protect residents: High-risk people receive additional observation while digital alerts are unavailable.
  4. Communicate clearly: Staff, families, suppliers and health partners receive verified updates.
  5. Review performance: Leaders identify missing records, unclear authority and inadequate paper supplies.

The exercise produces practical improvements before a real incident occurs.

Exercises Should Include Ethical and Privacy Decisions

Teams may need to decide:

  • how much information to share;
  • whether to notify people before facts are complete;
  • when to suspend a service;
  • how to prioritize limited resources;
  • whether emergency access should be expanded;
  • how to protect people experiencing abuse;
  • how to preserve consent during disruption;
  • when manual monitoring becomes too unsafe; and
  • how to communicate uncertainty.

Cyber resilience involves judgment as well as technical procedure.

Regulatory Oversight Should Connect Security and Care Quality

Oversight bodies may examine whether organizations:

  • identify digital dependencies;
  • protect personal information;
  • manage suppliers;
  • control access;
  • maintain supported systems;
  • test backups;
  • plan for outages;
  • report incidents;
  • communicate with affected people;
  • learn from harm;
  • protect accessibility; and
  • maintain care during disruption.

Cybersecurity should be assessed as part of safe, effective and well-governed care.

Compliance Should Not Become a Ceiling

Organizations may meet formal requirements while remaining vulnerable because:

  • controls exist only on paper;
  • training is superficial;
  • backups are untested;
  • supplier assurances are not verified;
  • legacy systems remain unsupported;
  • frontline workarounds are ignored;
  • incidents are underreported;
  • privacy notices are unreadable;
  • boards receive weak information; or
  • continuity plans do not reflect care reality.

Mature assurance focuses on whether controls work under pressure.

Boards Should Treat Cybersecurity as a Strategic Governance Issue

Cybersecurity should be discussed alongside quality, safeguarding, workforce, finance and operational resilience rather than being isolated within information technology.

Board members should understand:

  • which services are digitally dependent;
  • which cyber risks present the greatest threat to people receiving care;
  • whether investment matches operational risk;
  • how supplier assurance is monitored;
  • whether recovery capability has been tested;
  • how privacy concerns are addressed;
  • how incidents affect service users;
  • how improvement actions are tracked;
  • whether emerging technologies introduce new risks; and
  • how organizational learning is shared.

Cyber resilience should become a routine element of governance rather than a discussion that follows major incidents.

Governance Should Balance Security, Privacy and Care

Strong governance recognizes that cybersecurity decisions influence everyday care.

Leaders should avoid approaches that:

  • make systems so restrictive that staff create unsafe workarounds;
  • collect excessive personal information;
  • reduce accessibility for older people;
  • limit clinical decision-making unnecessarily;
  • delay emergency care;
  • remove personal choice;
  • discourage innovation; or
  • shift responsibility onto individuals without appropriate support.

Security should enable safe, trusted and person-centred care rather than obstruct it.

Operational Example: Board-Level Cyber Governance

A regional long-term care provider introduces connected monitoring, AI-assisted documentation and expanded telehealth across multiple services.

The board adopts a five-stage governance framework.

  1. Understand critical dependencies: Leaders map every care service that depends upon digital technology.
  2. Review strategic risks: Cybersecurity, privacy, supplier resilience and business continuity are incorporated into corporate risk management.
  3. Measure performance: Executive dashboards include security, privacy, resilience and care-continuity indicators.
  4. Test preparedness: Cyber exercises are conducted annually with operational, clinical and executive teams.
  5. Monitor improvement: Audit findings, incidents and lessons learned are reviewed until actions are fully implemented.

Cybersecurity becomes a visible element of organizational leadership rather than an isolated technical programme.

Public Trust Depends Upon Transparency

People are more likely to embrace digital care when organizations communicate openly about:

  • how information is protected;
  • who can access records;
  • how incidents are managed;
  • how privacy choices are respected;
  • how technologies are evaluated;
  • how AI supports decisions;
  • how data contributes to service improvement;
  • how concerns can be raised;
  • how organizations learn from mistakes; and
  • how people remain in control of their own information.

Trust grows through consistent behaviour rather than reassurance alone.

People Should Remain Active Participants

Older people should be encouraged to participate in protecting their own information without placing unrealistic responsibility upon them.

Organizations can support this by providing:

  • clear explanations;
  • simple reporting routes;
  • digital safety education;
  • accessible privacy controls;
  • supported authentication;
  • fraud awareness;
  • regular review of delegated access;
  • easy correction of inaccurate records;
  • technical assistance; and
  • accessible communication.

Cyber resilience improves when people understand how the system works and where support is available.

Future Technologies Will Require Continuous Adaptation

Japan's care system will increasingly incorporate:

  • ambient intelligent homes;
  • predictive AI;
  • digital twins;
  • robotic assistance;
  • wearable diagnostics;
  • voice-enabled care;
  • automated care coordination;
  • population analytics;
  • advanced interoperability; and
  • personalized digital support.

Every innovation creates new opportunities alongside new cyber risks.

Security governance must therefore evolve continuously rather than relying upon one-time implementation projects.

Cybersecurity Supports Innovation Rather Than Restricts It

Some organizations view cybersecurity as an obstacle to innovation.

In reality, secure systems encourage adoption because professionals, families and older people are more willing to use technologies they trust.

Well-designed security therefore enables:

  • greater digital confidence;
  • broader participation;
  • safer information sharing;
  • responsible AI deployment;
  • expanded home-based care;
  • remote clinical support;
  • research collaboration;
  • innovation partnerships;
  • public confidence; and
  • long-term sustainability.

Common Weaknesses in Cybersecurity Strategies

Organizations often weaken resilience by:

  • viewing cybersecurity as purely technical;
  • underestimating supplier risk;
  • neglecting privacy conversations;
  • overlooking smart-home devices;
  • failing to rehearse cyber incidents;
  • depending on unsupported systems;
  • providing generic rather than practical staff training;
  • measuring compliance instead of resilience;
  • underinvesting in recovery capability;
  • ignoring digital safeguarding;
  • assuming technology suppliers manage every risk;
  • collecting unnecessary information;
  • providing weak board oversight;
  • overlooking human factors;
  • using AI without governance; and
  • treating cyber incidents separately from care quality.

Most significant failures arise through combinations of organizational, human and technical weaknesses rather than a single vulnerability.

Lessons for Other Aging Nations

1. Treat Cybersecurity as Care Quality

Protecting digital systems protects continuity, dignity and safety.

2. Build Security Into Every Innovation

Privacy and resilience should be designed from the beginning rather than added later.

3. Protect the Entire Ecosystem

Home-care agencies, municipalities, suppliers, hospitals and families all contribute to overall resilience.

4. Support Smaller Providers

Shared guidance, procurement and technical expertise improve national resilience.

5. Combine Technical and Human Controls

Technology alone cannot prevent cyber incidents.

6. Encourage Rapid Reporting

Learning cultures identify and contain threats earlier.

7. Prepare for Long-Term Disruption

Business continuity should assume prolonged outages rather than brief interruptions.

8. Keep Older People in Control

Privacy should strengthen independence rather than reduce participation.

9. Govern Artificial Intelligence Carefully

Innovation requires transparency, accountability and secure data management.

10. Earn Public Trust Every Day

Confidence develops through reliable governance, openness and demonstrated protection.

A National Vision for Trusted Digital Care

Japan has the opportunity to become an international leader in secure digital aging.

This vision could include:

  • national cybersecurity standards for long-term care;
  • privacy-by-design procurement;
  • shared threat intelligence;
  • regional cyber support services;
  • supplier certification;
  • secure interoperability;
  • AI governance frameworks;
  • digital safeguarding standards;
  • accessible authentication;
  • community cyber education;
  • continuous workforce development;
  • board-level assurance;
  • regular resilience exercises; and
  • public participation in digital governance.

Such an approach would strengthen both technological innovation and social confidence.

A Human-Centred Test for Every Connected Care System

Before introducing any new digital technology, leaders should ask:

  • Does this improve people's lives?
  • What new cyber risks are introduced?
  • What personal information is actually required?
  • Can older people understand how it works?
  • How are privacy choices respected?
  • How is business continuity maintained?
  • What happens when the technology fails?
  • Who remains accountable?
  • Can people challenge automated decisions?
  • How will trust be maintained over time?

These questions ensure technology remains accountable to people rather than expecting people to adapt to technology.

Conclusion

Japan's long-term care system is entering an era in which digital infrastructure will become as important as physical infrastructure.

Cybersecurity therefore becomes inseparable from care quality, operational resilience, safeguarding, governance and public confidence.

The greatest challenge is not preventing every cyber incident, because no connected system can eliminate risk completely.

The real objective is building organizations that anticipate threats, respond rapidly, recover safely and continue delivering compassionate care throughout disruption.

Older people should never be forced to choose between digital innovation and personal privacy.

They deserve technologies that enhance independence while protecting dignity, choice and trust.

Families should feel confident that information is used responsibly.

Professionals should work within secure systems that support rather than obstruct care.

Leaders should recognize that cybersecurity is no longer simply about protecting computers.

It is about protecting people.

As Japan continues developing one of the world's most advanced digitally enabled aging societies, cybersecurity and privacy will become defining foundations of sustainable long-term care.

The countries that succeed will not necessarily be those deploying the greatest amount of technology, but those building digital systems that people trust enough to use with confidence for decades to come.