Japan’s response to population aging is becoming increasingly dependent on digital infrastructure. Electronic care records, telehealth, remote monitoring, smart-home technology, robotics, mobile applications and artificial intelligence can help older people remain independent while allowing hospitals, municipalities, pharmacies and long-term care providers to coordinate more effectively.
The Japan Aging, Long-Term Care & Community Support Knowledge Hub examines how Japan can build a sustainable, connected and person-centred aging society. Cybersecurity and privacy must sit at the centre of that development because a connected care system can improve safety only when people trust it, professionals can rely upon it and essential services remain available during disruption.
The consequences of digital failure in long-term care extend far beyond lost files or unavailable office systems. A cyberattack may prevent workers from accessing medication instructions, interrupt remote monitoring, disable call systems, delay hospital discharge, disrupt staff scheduling or leave an older person unable to request assistance. A privacy failure can be equally harmful when monitoring becomes excessive, family access is granted without clear authority, inaccurate information follows a person across services or care data are reused for purposes they never reasonably expected.
Japan therefore needs a digital care ecosystem that is secure without becoming inaccessible, connected without becoming intrusive and innovative without weakening human accountability. This requires cybersecurity to be governed as part of care quality, safeguarding, operational resilience and public trust rather than treated as a narrow information-technology responsibility.
Cybersecurity and Privacy Are Different but Interdependent
Cybersecurity is concerned with protecting systems, networks, devices and information from unauthorized access, disruption, alteration or destruction. Privacy is concerned with whether personal information is collected, used, retained and shared appropriately.
A platform may be technically secure while still undermining privacy because it collects more information than the care purpose requires, gives too many people access or retains intimate records indefinitely. Conversely, an organization may publish a clear privacy notice while remaining vulnerable to ransomware, stolen credentials, insecure mobile devices or unsupported software.
Strong digital governance must therefore address confidentiality, integrity and availability alongside necessity, proportionality and personal control. Information must remain confidential, records must remain accurate and care-critical systems must remain available. At the same time, older people should be able to understand what information is being used, why it is required and who can see it.
This broader approach connects cybersecurity with data governance, privacy and interoperability. Secure technology is not enough when the underlying data are inaccurate, excessive, poorly shared or difficult for the person to correct.
Cybersecurity Is Now a Direct Care-Quality Responsibility
Digital systems increasingly support medication administration, care planning, workforce deployment, emergency contacts, remote monitoring, telehealth, family communication, building access, environmental controls, supplier ordering and regulatory evidence. When those systems fail, the effects may be immediate and personal.
A scheduling outage can become a missed-visit risk. An unavailable medication record can become a clinical safety risk. A compromised smart lock can become a physical-security risk. A disabled monitoring platform can remove oversight from people whose health or mobility requires a rapid response.
Cybersecurity should therefore be incorporated into quality management, clinical governance, safeguarding, emergency preparedness and executive decision-making. Technology teams remain essential, but they cannot determine the care consequences of an incident alone. Operational and clinical leaders must understand which systems support critical functions, which people would be affected by failure and how long services could operate safely without digital access.
Boards and senior leaders should be able to answer practical questions. They need to know which systems are indispensable, where single points of failure exist, whether backups can actually be restored, which suppliers hold privileged access and what manual arrangements would protect people during a prolonged outage.
The Governance Maturity Assessment can help organizations examine whether leadership, accountability, assurance and improvement arrangements are sufficiently developed to govern connected care safely.
A Wide and Interdependent Attack Surface
Japan’s digital aging-care environment may include national and municipal platforms, hospital and pharmacy records, long-term care management systems, mobile applications, cloud infrastructure, telehealth services, wearable devices, smart-home equipment, robotic systems, family portals and research databases.
Each connected device, supplier interface and user account creates potential exposure. Security therefore cannot focus only on large hospitals or government networks. Small home-care agencies, community organizations, care homes and individual households are also part of the national care infrastructure.
A small provider may hold less information than a major hospital, but disruption can still be severe when it depends upon one scheduling platform, one cloud supplier or one administrator account. Equally, a household device may appear low risk until it reveals when a person is alone, records intimate routines or provides remote access to doors, cameras or medication equipment.
Resilience requires an ecosystem perspective. Municipalities need assurance about provider systems, providers need assurance about suppliers and technology companies need clear responsibilities for updates, incident notification, support and secure decommissioning. Weakness in one part of the chain can affect many organizations at once.
Older People May Face Distinct but Varied Risks
Criminals may target older adults because they expect urgent official-looking messages to be trusted, believe financial assets are available or assume that limited digital confidence will reduce the likelihood of detection. Social isolation, cognitive change or dependence upon family support may increase vulnerability in some circumstances.
These risks should not become stereotypes. Many older people manage digital security confidently, while younger relatives, care workers, managers and suppliers may create equally serious exposure through shared passwords, insecure devices or inappropriate access.
Protection should therefore be based upon actual circumstances rather than age alone. Services should consider digital confidence, communication needs, cognitive change, family relationships, financial vulnerability and access to trusted support. Security information should be available in plain language, accessible formats and non-digital forms.
People also need safe routes for reporting mistakes or suspicious activity without embarrassment. Fraud frequently succeeds because victims fear blame or believe they should have recognized the deception. A supportive response can prevent further loss and help the person continue using legitimate digital services with confidence.
Phishing and Care-Related Fraud
Phishing remains one of the most common routes into organizations and personal accounts. Messages may imitate municipal authorities, hospitals, banks, pharmacies, technology suppliers, senior managers or family members. They may ask the recipient to reset a password, open an attachment, confirm identity, provide a verification code, install software or approve a payment urgently.
Care-related messages can be particularly persuasive because they exploit concern. A criminal may claim that a long-term care benefit will stop, a medication order has failed, an appointment will be cancelled or a relative has experienced an emergency. The emotional pressure created by these messages can override normal caution.
Organizations should make legitimate communication recognizable and provide simple verification routes. People should be encouraged to contact the organization through a previously known telephone number or official portal rather than using contact details contained within an unexpected message.
Operational Example: Responding to a Fraudulent Care Message
An older person receives a message claiming to come from a municipal long-term care office. It states that services will stop unless personal and banking information are confirmed immediately.
Instead of following the link, the person contacts the municipality using a number from previous correspondence. Staff confirm that the message is fraudulent and help secure the person’s email and care-portal credentials. Because some financial information has already been disclosed, the bank is contacted and relevant accounts are protected.
The municipality also checks whether appointments, contact details or care arrangements have been altered. The provider informs other people receiving services about the fraudulent campaign without identifying the individual. Practical support is then offered so the person can continue using legitimate digital services without blame or loss of confidence.
The incident is treated not only as attempted financial fraud but also as a potential threat to care continuity and personal safety.
Ransomware Can Disrupt Essential Care
Ransomware may encrypt information, disable systems or steal data before payment is demanded. A long-term care provider affected by ransomware may lose access to care plans, medication records, staff rotas, emergency contacts, incident information, family communications and remote-monitoring dashboards.
Even where backups exist, restoration can take days or weeks. Organizations therefore need practical arrangements for safe care during prolonged system unavailability rather than assuming that technical recovery will be immediate.
Paying a ransom does not guarantee complete restoration, deletion of stolen information or removal of malicious access. Attackers may provide unreliable decryption tools, retain copies of personal data or return later through the same vulnerability. Planning should focus on prevention, containment, continuity and trusted recovery.
Backups Must Be Protected and Tested
Backups may fail because they remain permanently connected to the live network, use the same compromised credentials, contain incomplete information or have never been tested under realistic conditions. A backup that cannot restore care-critical functions provides only false reassurance.
Organizations should identify which information must be available first during recovery. Medication instructions, current care plans, emergency contacts, high-risk alerts, staff scheduling and clinical communication may take priority over routine administrative files.
Recovery priorities should reflect care consequences rather than technical convenience. A relatively small database may require urgent restoration when it supports a person with complex medication, while a much larger administrative system may be able to remain unavailable temporarily without immediate harm.
Information Integrity Is as Important as Confidentiality
Cybersecurity discussions often focus on stolen data, but altered information may create even greater immediate risk. An attacker or unauthorized user could change a medication dose, allergy status, emergency contact, bank account, care-plan instruction, monitoring threshold or family permission.
Changes may be difficult to detect when they appear to come from a legitimate account. Systems therefore need audit trails, version history and additional verification for high-risk amendments.
Organizations should be able to establish who entered or changed information, when the change occurred, which device was used, what the previous record stated and whether connected systems were updated. Critical information should not be overwritten without preserving its history.
Where unusual activity is detected, technical investigation must be accompanied by a care review. Teams should establish whether decisions were made using inaccurate information and whether medication, appointments, family communication or safeguarding arrangements were affected.
Identity Theft Can Create Conflicting Care Records
Stolen personal information may be used to redirect benefits, access health records, obtain prescriptions, impersonate a family member or change contact details. These activities can create fragmented or conflicting records across banks, municipalities, health providers and care organizations.
Identity recovery should therefore include both financial and care-related consequences. The person may need help correcting records, restoring portal access, reviewing delegated permissions and confirming that genuine appointments and medication arrangements remain intact.
Family Support Must Not Become Uncontrolled Access
Family members may provide essential assistance with appointments, medication, communication and technology. Their involvement should be enabled through transparent, reviewable permissions rather than shared passwords or assumed entitlement.
An older person may want a relative to receive reminders or join virtual consultations without granting access to their complete clinical history. Another person may want temporary support following hospital discharge but wish to withdraw that access after recovery.
Digital systems should therefore provide granular delegated access. Permissions should specify what the supporter can see or do, remain separate from the older person’s own credentials and be reviewed when relationships or circumstances change.
This is particularly important where family conflict, financial control or safeguarding concerns exist. A relative should not be able to change contact details, intercept appointments or monitor location simply because they previously helped create an account.
Role-Based Access Should Reflect Real Care Responsibilities
Professionals need sufficient information to provide safe care, but unrestricted access creates unnecessary exposure. A home-care worker may need current support instructions, medication tasks, mobility information, communication preferences, known risks and escalation routes. They may not need access to complete historical records, unrelated family information or financial data.
Access should be based upon role, location, duration and current involvement. Temporary workers, students, contractors and volunteers should receive only the permissions required for the defined task, and those permissions should end promptly when the role concludes.
Privileged administrator accounts require additional protection because they can change settings, create users and access large volumes of information. Multi-factor authentication, separate administrator credentials, detailed logging and review of unusual activity should be standard for high-risk access.
Mobile Working Must Be Secure and Practical
Home-care workers, nurses, therapists and care managers increasingly access information through mobile phones, tablets and laptops. Device loss, public Wi-Fi, shared vehicles, personal applications, outdated software and automatic cloud backups can all create risk.
Controls may include managed devices, encryption, multi-factor authentication, automatic timeout, remote locking, restricted downloads and approved applications. However, security must reflect the realities of community work.
Workers should not have to choose between following impractical rules and completing care safely. When official systems are slow, inaccessible or poorly designed, staff may turn to personal email, messaging applications or paper notes. Leaders should investigate why these workarounds occur and improve the approved pathway rather than relying solely on disciplinary warnings.
Secure systems are most effective when frontline staff help design and test them. Usability is not separate from cybersecurity; it is one of the conditions that determines whether controls will be followed in practice.
Smart Homes Extend Cybersecurity Into the Person’s Living Environment
Connected care increasingly reaches beyond organizational systems and into private homes. Movement sensors, voice assistants, smart locks, video doorbells, medication dispensers, fall detectors, wearables, connected appliances and emergency alarms can help older people remain independent while allowing earlier intervention when circumstances change.
These technologies also create new routes into highly personal environments. A compromised device may reveal when a person is asleep, away from home, receiving care or living alone. In more serious cases, unauthorized users may gain access to cameras, microphones, doors, environmental controls or medication equipment.
Security should therefore be considered at the point of care planning, procurement and installation. Home technology must not be treated as harmless consumer equipment simply because it is located outside a hospital or care organization.
Secure by Default Should Be the Standard
Older people should not be expected to configure complex security settings before a device becomes safe to use. Equipment commissioned for care should arrive with unique credentials, encrypted communication, automatic security updates and unnecessary functions disabled.
Default settings should minimize data collection rather than maximize it. Recording, continuous location tracking, supplier analytics and family access should not be activated automatically when they are not required for the agreed purpose.
Manufacturers should define how long software and security support will continue. Providers and municipalities should know what happens when the device becomes unsupported, the supplier exits the market or a serious vulnerability cannot be corrected.
Installation Is a Privacy and Care Conversation
Installation should include more than connecting equipment to a network. The person should understand what information the device records, when it is active, who receives alerts and whether relatives or suppliers can access the data.
Teams should also explain what happens during internet or power failure, how faults are reported, how access can be withdrawn and how information will be deleted when the equipment is removed.
These discussions should be revisited when circumstances change. Technology that was proportionate during recovery from illness may become unnecessarily intrusive once independence improves. A family member who previously held access may no longer need it. A device may also stop delivering meaningful benefit even though data collection continues.
Operational Example: Securing a Connected Home-Care Package
An older person receives movement sensors, a smart medication dispenser and a family-monitoring application following hospital discharge.
The provider begins by mapping what each device collects, where the information is processed and who can access it. Default passwords are replaced, unnecessary functions are disabled and family permissions are limited to medication alerts and missed-contact notifications.
The person and care team then practice what to do if the internet, power or device fails. A non-digital medication plan and emergency contact route are retained. Access logs, missed transmissions and software updates are reviewed during the first weeks of use.
At the scheduled review, the person confirms that the equipment remains helpful but no longer wants continuous activity monitoring. That function is removed while the medication support continues.
The package supports independence because security, privacy and usefulness are reviewed together rather than treated as separate issues.
Wearables Reveal Intimate Patterns Over Time
Wearable devices may capture heart rate, sleep, movement, falls, oxygen levels, location and daily routines. Each data point may appear limited, but combined over time they can reveal highly personal patterns about health, lifestyle, social activity and vulnerability.
Collection should remain linked to a defined care purpose. A device introduced to detect falls should not automatically become a platform for continuous location analysis, commercial profiling or unrelated research.
People should understand whether data are processed locally, stored in the cloud or shared with suppliers. They should also know whether the device continues collecting information when they are not receiving formal care.
Location Tracking Requires Particular Caution
Location technology may support some people living with cognitive impairment or a risk of becoming lost. It may also create continuous surveillance and allow relatives or professionals to monitor movement beyond what is necessary.
Assessment should consider the person’s wishes, the specific risk, less intrusive alternatives, who can view the location and what happens when the device is inaccurate or unavailable. Review dates should be agreed from the beginning.
The Positive Risk Enablement Planner can help teams balance personal freedom, foreseeable harm, privacy and proportionate safeguards when considering tracking or other monitoring technologies.
Technology should support safer independence rather than become an automatic substitute for conversation, community support or individualized risk planning.
Video Monitoring Is Especially Intrusive
Cameras may be proposed for fall detection, security, remote support or safeguarding. They may also record personal care, family conversations, visitors, periods of distress and workers completing intimate tasks.
Video should not be used when a less intrusive technology can meet the same purpose. Where cameras are considered necessary, their location, recording status, retention and access should be tightly controlled.
People should know when recording is active and who can view live or stored footage. Audio capture should be considered separately because it may record conversations that are unrelated to the stated purpose.
Video systems should also include safe removal and deletion arrangements. Turning off a camera does not necessarily delete historical recordings held by suppliers or family applications.
Monitoring Workers Raises Additional Ethical Questions
Home-monitoring systems may also capture staff activity during visits. This can provide evidence where concerns arise, but it may affect privacy, professional relationships, employment rights and workforce trust.
Workers should be informed when monitoring is present and how information may be used. Recordings should not become a routine substitute for supervision, training and fair investigation.
Organizations should distinguish between monitoring intended to support the person and monitoring introduced primarily to measure staff productivity. The latter may create a different purpose, different access requirements and different governance obligations.
Robotic Systems Combine Physical and Digital Risk
Care robots may support mobility, lifting, prompting, communication or companionship. Their safety depends not only on mechanical reliability but also on secure software, controlled remote access and accurate identity recognition.
A compromised robotic system could allow unauthorized control, manipulation of instructions, microphone or camera access or unsafe movement. Failed updates and loss of connectivity may also affect safe operation.
Robotic assurance should therefore combine physical safety, cybersecurity, data protection and care governance. Services should know how the equipment behaves when connectivity is lost, when updates fail or when the supplier’s remote support is unavailable.
Remote Supplier Access Must Be Restricted
Suppliers may need remote access to diagnose faults or install updates. This access should be authorized, time-limited, logged and restricted to the systems required for the task.
Permanent supplier accounts with broad privileges create avoidable risk. Access should be removed after use unless there is a clearly defined operational need for it to remain active.
Contracts should require strong authentication, incident notification and evidence of who accessed the system. Providers should also understand whether supplier personnel, subcontractors or offshore support teams can view personal information during technical work.
Telehealth Must Protect Both Digital and Physical Confidentiality
Virtual consultations may involve video, audio, chat, clinical documents, family participation and interpretation. Services should establish whether sessions are encrypted, whether recordings are created, how participants are authenticated and where information is stored.
Privacy also depends upon the physical environment. A technically secure consultation may still be overheard in a shared room, family living area, community centre or staff vehicle.
Professionals should confirm who is present and whether the person can speak privately. Where confidentiality cannot be protected, alternative arrangements should be offered rather than assuming that a virtual consultation remains appropriate.
Recording Virtual Consultations Requires Clear Rules
Recordings may support communication, clinical review, quality assurance or complaint investigation. They also create additional exposure because video and audio may reveal sensitive health, family and personal information.
People should understand whether recording is optional, who can access it, how long it will be retained and whether a written summary is available instead. Recordings should not be created automatically simply because the platform allows it.
Where professionals or family members make their own recordings, expectations should be discussed openly. Hidden recording can damage trust and may create difficult questions about consent, storage and later use.
Electronic Records Can Spread Errors Rapidly
Connected records improve continuity only when information is accurate. An incorrect diagnosis, outdated medication, wrong family contact or historic risk presented as current can be copied across several organizations and influence decisions long after the original error occurred.
Privacy includes the right not to be defined indefinitely by inaccurate, irrelevant or unverified information. A mistaken record about decision-making ability, safeguarding or family involvement can alter how professionals communicate with the person and who receives access.
Organizations should therefore provide clear and accessible correction routes. Urgent safety errors should be prioritized, disagreement should be recorded fairly and connected systems should be updated rather than leaving the person to contact several organizations independently.
Record Correction Is a System Responsibility
When an error is identified, teams should establish which organization owns the record, which systems received the inaccurate information and whether decisions were made using it.
Correction may require more than changing one field. Staff may need to update care plans, medication records, portal permissions, hospital correspondence and family notifications. Where the original information cannot be deleted for legal reasons, the correction or disagreement should remain clearly visible.
People should be informed when the process is complete and told who to contact if the error continues to appear elsewhere.
Data Minimization Reduces Both Privacy and Cyber Risk
Organizations should collect and retain only the information needed for a clear and legitimate purpose. Excessive data increase breach impact, staff confusion, storage cost and the likelihood of inappropriate access or secondary use.
The availability of technology to collect movement, voice, video or behavioural information does not establish a need to do so. Every additional dataset creates responsibilities for access, accuracy, security, retention and deletion.
Data minimization is therefore both a privacy principle and a practical resilience strategy. Organizations cannot lose, misuse or struggle to correct information they never needed to collect.
Purpose Limitation Must Be Visible in Practice
Information collected for fall prevention should not automatically be reused for insurance pricing, marketing, unrelated research, family surveillance or decisions about eligibility.
New uses require separate consideration of authority, necessity, fairness and transparency. Older people should not discover after deployment that a monitoring system has become a source of commercial analytics or organizational performance measurement.
System design should separate mandatory care functions from optional uses. Declining a secondary purpose should not remove access to essential support.
Consent Is Important but Not Sufficient
Consent can become weak when the service is essential, terms are complex or several data uses are bundled together. A person may technically agree because they fear losing support or lack a realistic alternative.
Organizations remain responsible for fairness, security and proportionality even when a consent box has been selected. They should not rely on lengthy terms to justify unnecessary collection or indefinite retention.
Consent also needs to remain current. Technology, suppliers and data uses may change over time. People should be told when material changes occur and given meaningful opportunities to reconsider participation.
Privacy Information Must Be Understandable
Older people should be able to understand what information is collected, why it is needed, who receives it, which suppliers are involved and whether automated analysis is used.
They should also know how long information is retained, how access can be restricted, how records can be corrected and what happens when the service ends.
Privacy notices should be available in plain language, accessible formats and non-digital forms. Key information should be explained at the point of decision rather than hidden within a lengthy general notice.
Retention Should Reflect Actual Need
Keeping information indefinitely may appear cautious, but it creates long-term exposure. Retention decisions should consider continuity of care, legal obligations, safeguarding, complaint investigation and the relevance of older information.
Schedules should apply to backups, recordings, exported files, paper documents and supplier copies as well as active databases. Deleting a record from a user interface may not remove it from cloud archives or subcontractor systems.
Organizations should be able to explain why information is still required and how it will be destroyed or rendered inaccessible when that need ends.
Decommissioning Is a Privacy Event
When connected equipment is returned, replaced or transferred, teams should address stored data, account credentials, supplier connections, family permissions and recording history.
Removing a device from a home does not automatically remove the information associated with it. The supplier may continue holding data, relatives may retain access and the equipment may still be linked to an active account.
Secure decommissioning should include evidence of deletion, account closure and removal of remote access. Devices intended for reuse should be reset and verified before being allocated to another person.
Supplier Risk Extends Across the Entire Ecosystem
Long-term care organizations may depend upon suppliers for electronic records, remote monitoring, cloud hosting, telehealth, mobile applications, smart-home devices, robotics, artificial intelligence, payment systems and technical support.
A single supplier compromise can therefore affect several organizations and large numbers of older people at once. Outsourcing technical activity does not outsource accountability for care continuity or privacy.
Organizations should understand which suppliers process personal information, which services depend upon them and how quickly alternative arrangements could be established if they failed.
Contracts Must Define Security Responsibilities Clearly
Care-critical contracts should address access controls, encryption, software updates, vulnerability management, backup, incident notification, subcontractors, business continuity, audit rights, data return and secure deletion.
General claims that a supplier follows good practice are not enough. Providers need evidence that controls operate in reality and that support will remain available during a serious incident.
Contracts should also define what happens at exit. Data portability, continued access to historical records and removal of supplier accounts should be planned before the relationship begins.
Subcontractors Create Hidden Dependencies
A primary supplier may rely upon cloud infrastructure, software developers, identity services, analytics providers, telecommunications companies and external support teams.
Organizations should know which subcontractors support essential functions or process information. Contractual controls should extend through the full chain rather than ending with the visible supplier.
This matters particularly where information is processed outside Japan or where several suppliers depend upon the same underlying platform.
Supplier Concentration Creates Systemic Risk
Several municipalities or providers may depend on the same cloud service, scheduling platform or device manufacturer. A single failure can therefore disrupt a large part of the care system.
Leaders should examine market concentration, common infrastructure, data portability and the availability of alternatives. They should also consider the consequences of supplier insolvency, withdrawal from the market or loss of specialist staff.
Resilience planning should include regional and national dependencies rather than focusing only on the organization’s own contract.
Unsupported Technology Accumulates Risk
Care organizations may continue using older systems because replacement is expensive, disruptive or difficult to procure. Over time, unsupported equipment may stop receiving security patches, technical assistance and compatibility updates.
Organizations should maintain an inventory showing each system’s support status, known vulnerabilities and replacement plan. Where immediate replacement is impossible, additional isolation, access restrictions and monitoring may be required.
Unsupported technology should remain visible within strategic risk reporting rather than being accepted as an indefinite operational reality.
Procurement Should Test Security Claims
Technology procurement should require evidence of secure development, independent testing, patching timescales, multi-factor authentication, access logging, incident response and business continuity.
Demonstrations should include failure and recovery scenarios rather than only normal operation. Suppliers should be asked to show what happens when connectivity is lost, a device becomes compromised, information is corrupted or several customers require support at the same time.
The Regulatory Readiness Gap Analyzer can help organizations identify weaknesses in cybersecurity, privacy, supplier assurance, record governance and continuity before deployment or contract renewal.
Security Controls Must Remain Usable
Overly complex controls can encourage staff to share accounts, leave sessions open, use personal messaging applications or write passwords beside equipment. These behaviours may be unsafe, but they often reveal that official processes do not reflect real work.
Security design should consider time pressure, mobile working, poor connectivity, accessibility and staffing arrangements. Frontline workers should participate in testing because they understand where workarounds are most likely to occur.
A secure system that professionals cannot use safely is not genuinely secure.
A Just Security Culture Encourages Early Reporting
Workers may delay reporting when they fear automatic punishment for clicking a malicious link, sending information to the wrong recipient or losing a device.
Delay allows harm to spread. Organizations should distinguish honest error, poor system design, reckless behaviour and deliberate misuse.
Staff should receive rapid support when an incident is reported. Accounts can be secured, recipients contacted and devices disabled before the full investigation is complete.
A learning culture does not remove accountability. It creates a fairer and faster route to containment while allowing leaders to address repeated disregard or intentional misuse appropriately.
Operational Example: Responding Without Automatic Blame
A home-care worker clicks a fraudulent link that imitates the organization’s scheduling system. The worker reports the incident immediately.
The account is secured, active sessions are closed and unusual activity is reviewed. Operational teams check whether addresses, visit schedules or care instructions were accessed or altered.
The worker receives practical guidance, while leaders examine why the message appeared credible and whether stronger technical filtering or clearer verification could have prevented the event.
An anonymized warning is then shared with colleagues, showing the indicators of the attack and the correct reporting route.
The organization reduces harm because rapid disclosure is treated as responsible behaviour rather than automatic failure.
Training Should Reflect Different Roles
A board member, care worker, system administrator, volunteer and family supporter face different risks. Training should therefore be role-specific rather than limited to generic annual e-learning.
Frontline staff may need practical guidance on mobile working, phishing, record access and family permissions. Administrators require stronger training on privileged accounts, audit logs and supplier access. Leaders need sufficient cyber literacy to challenge investment, continuity and risk decisions.
Temporary and agency workers should not be excluded because of short assignments. They still require individual accounts, clear reporting routes and access limited to the work they are undertaking.
Community Partners Need Proportionate Controls
Community organizations may support welfare checks, social participation, meal delivery, technology setup and emergency response. They may need limited information to perform these roles safely.
Access should be based on a defined purpose, appropriate training and clear deletion arrangements. Community value should not be undermined by transferring complete care records when a name, address and agreed support instruction would be sufficient.
Commissioners should provide secure tools and practical guidance rather than expecting small organizations to create complex infrastructure alone.
Cybersecurity Testing Should Include Human Manipulation
Technical testing may identify software vulnerabilities while missing social engineering. Criminals may impersonate senior managers, family members, suppliers or emergency services to obtain passwords, change bank details or gain physical access.
Proportionate simulations can help organizations understand how staff respond to realistic pressure. These exercises should be ethically governed and used for learning rather than humiliation.
Testing should also consider discarded documents, unlocked cabinets, shared reception areas and unattended devices. Physical security remains part of cybersecurity because access to equipment or paper can bypass digital controls.
Paper Records Still Require Strong Governance
Paper may be necessary during outages, poor connectivity or emergency evacuation. Risks include documents left in vehicles, outdated care plans, uncontrolled copying and information that is never transferred back into the digital record.
Continuity procedures should cover secure storage, collection, version control, reconciliation and destruction. Teams should know which paper summaries are authoritative and how often they are updated.
Printing should not be prohibited unrealistically when it is necessary for safe care. Instead, organizations should define when printing is appropriate and how the document will be secured and replaced when circumstances change.
Cyber Incidents Require Care-Focused Triage
Technical severity and care severity are not always the same. A relatively small system failure may create high risk when it affects medication, monitoring or communication for one person with complex needs.
Initial assessment should therefore establish which systems are unavailable, whether information was altered, which people are affected and whether manual processes remain safe.
Teams should determine whether hospital discharges need to pause, whether remote monitoring has stopped and whether staff can still access emergency contacts and current instructions.
This approach connects cyber response with emergency preparedness and business continuity rather than allowing technical teams to assess impact in isolation.
Incident Response Requires Multidisciplinary Leadership
A serious cyber incident may require input from information technology, information governance, clinical leadership, long-term care operations, safeguarding, human resources, communications, legal advisers, facilities teams, suppliers and municipal authorities.
Technical specialists can identify malicious activity and secure infrastructure, but they may not know which unavailable record creates the greatest medication risk or which monitoring failure requires an immediate welfare visit. Care leaders must translate technical disruption into practical priorities for older people, families and frontline workers.
Roles and authority should be agreed before an incident occurs. Organizations need to know who can disconnect systems, activate manual procedures, pause admissions, authorize emergency expenditure, notify affected people and approve restoration.
Unclear authority can delay both containment and care decisions. A response structure should therefore distinguish technical command, operational coordination, executive accountability and external communication while maintaining a shared understanding of personal risk.
Communication Must Remain Trusted During Disruption
Normal email, telephony or messaging systems may be unavailable or compromised. Organizations need alternative routes such as verified telephone trees, offline contact lists, secure emergency messaging, supplier hotlines and pre-agreed regional communication channels.
Staff must know which communications are authentic. Cybercriminals may exploit the confusion surrounding a real incident by sending false password-reset instructions or impersonating incident responders.
Older people and families may need clear information about which services are affected, whether appointments and visits will continue, whether remote monitoring remains operational and how urgent medication or care concerns should be raised.
Communication should be honest without creating unnecessary alarm. Early messages may need to acknowledge uncertainty while explaining what is known, what protective action has been taken and when the next update will be provided.
Secondary Fraud May Follow a Data Breach
Stolen records can make later fraud unusually convincing. Criminals may know the person’s provider, condition, municipality, device type, appointment schedule or care-worker name.
A fraudulent caller may therefore appear to possess information that only a legitimate organization should know. Following a breach, affected people should receive practical warnings explaining how genuine providers will communicate and what information they will never request unexpectedly.
Support may also be required to review banking arrangements, change account credentials and restore trusted contact methods. Privacy harm should not be assessed only by whether information was published. The possibility of future coercion, impersonation and targeted exploitation also matters.
Operational Example: Maintaining Care During a Regional Cyberattack
A regional cloud platform used by hospitals, pharmacies and long-term care providers becomes unavailable following a cyberattack.
Providers first identify people dependent upon time-critical medication, remote monitoring, complex support or regular clinical communication. Protected offline care summaries are released to authorized teams, and hospitals, pharmacies and community providers begin using pre-agreed emergency channels.
Every medication change, hospital discharge and care-plan amendment made during the outage is recorded through controlled manual processes. Staff are instructed not to rely on older printed information without checking its date and current relevance.
Systems are restored in stages only after technical testing, data-integrity checks and operational approval. Temporary records are reconciled before normal workflows resume.
The response protects continuity while reducing the risk that outdated or conflicting information becomes embedded in the restored system.
Business Continuity Must Prepare for Extended Outages
Cyber disruption may last much longer than a routine technical failure. Organizations should consider how care would continue for several days or weeks rather than planning only for a brief interruption.
Extended continuity may require manual scheduling, alternative medication documentation, offline contact lists, paper supplies, supplier ordering, staff payment arrangements and regional mutual aid. Workforce fatigue and management capacity can become significant risks as temporary processes continue.
Offline information must remain current and protected. Emergency copies of medication summaries, care plans and contact lists can support continuity, but outdated copies may create serious harm. Organizations should define how often emergency information is refreshed, who may access it and how superseded copies are destroyed.
Manual processes also require clear limits. Some activity can continue safely with paper records and direct communication, while other functions may need to pause until specialist oversight or reliable information becomes available.
Recovery Is More Than Reconnecting Technology
Systems should not return to full operation simply because they appear accessible. Before restoration, organizations should confirm that malicious access has been removed, credentials secured, vulnerabilities corrected and backups verified.
Operational testing should establish whether interfaces, alerts, medication information, schedules and family permissions are accurate. A technically restored platform may still be unsafe if it contains corrupted or outdated data.
During an outage, decisions may have been recorded on paper, spreadsheets or temporary systems. Recovery therefore includes transferring medication changes, hospital admissions, new risks, appointments, incidents and family-contact amendments into the authoritative record.
Reconciliation requires protected workforce time and quality checks. Rushing teams back into routine work can leave gaps, duplication and conflicting instructions unresolved.
Post-Incident Review Must Examine Human Consequences
A technical report may explain how attackers entered the network and which systems were encrypted. A care-focused review must also examine whether visits were missed, medication was delayed, monitoring failed or hospital discharge was disrupted.
Leaders should consider the effects on privacy, safeguarding, family distress, staff fatigue, financial loss and public confidence. They should identify whether some groups experienced greater harm because they lacked digital alternatives, lived in rural areas or depended more heavily upon connected equipment.
The review should distinguish immediate causes from deeper weaknesses. A phishing email may trigger an incident, but the scale of harm may reflect unsupported systems, weak access controls, untested backups or poor continuity planning.
The Quality Improvement Action Plan Builder can help organizations convert findings into named actions, deadlines, evidence requirements and executive oversight.
Near Misses Are Valuable Sources of Intelligence
Organizations should learn not only from major breaches but also from blocked phishing attempts, failed backup tests, lost devices recovered quickly and supplier vulnerabilities identified before exploitation.
Near misses reveal weaknesses while there is still time to intervene. A worker who reports that a family member can still access an old portal account may prevent future misuse. A failed restoration exercise may expose the need for stronger backup design before a ransomware event occurs.
Learning should be shared across teams and, where appropriate, across municipalities and providers. Repeated local failures may reveal a wider supplier, training or infrastructure problem.
Cybersecurity Metrics Must Show Whether Controls Work
Useful measures may include patching times, unsupported systems, multi-factor authentication coverage, privileged-account reviews, backup success, restoration testing, supplier risks, device loss and incident response times.
Organizations should also monitor care disruption, privacy complaints, delayed reporting and completion of improvement actions. A technically strong dashboard can still provide false assurance when it does not connect controls with personal outcomes.
The Quality Dashboard Builder can support a combined view of cybersecurity, privacy, continuity, supplier performance, workforce capability and care quality.
Training completion should not be treated as proof of safe practice. Leaders need evidence that suspicious messages are reported, lost devices can be disabled, backups restore successfully and workers know how to continue care during disruption.
Risk Registers Should Describe Real Dependencies
General statements such as “risk of cyberattack” provide limited support for decision-making. Stronger risk descriptions identify the system, threat, vulnerability, affected population, care consequence and current control weakness.
A provider might identify that its remote-monitoring service depends upon one unsupported gateway used across several municipalities. Another may recognize that medication records can be accessed offline but only through a process known by one manager.
Specific risk statements allow investment and accountability to be directed where they matter most. They also make it easier for boards to understand whether risk is being reduced or merely described repeatedly.
Privacy Impact Assessment Should Begin Before Procurement
New technology should be assessed before contracts are signed or devices installed. Privacy and security weaknesses can be difficult and expensive to correct once a system has become embedded within care delivery.
Assessment should examine the care purpose, information collected, necessity, proportionality, supplier involvement, family access, automated processing, international transfer, retention, accessibility and less intrusive alternatives.
The views of older people and frontline workers should inform this process. They may identify practical risks that are invisible within technical specifications, including difficulty withdrawing consent, unclear recording indicators or family access that is too broad.
Privacy by design means that protective choices shape the normal service. People should not have to search through hidden settings to prevent unnecessary recording, commercial use or indefinite retention.
Data Sharing Agreements Must Operate in Daily Practice
Written agreements are important, but they do not guarantee that information is shared safely. Organizations should define which information is exchanged, for what purpose, through which system and who may access it.
They also need practical processes for corrections, objections, incidents and termination of sharing. Where several organizations hold the same information, each should understand how an error or changed permission will be communicated to the others.
Emergency sharing may be necessary during evacuation, disaster response or urgent clinical deterioration. Information about medication, mobility, communication and medical equipment may need to move rapidly.
Emergency authority should remain proportionate. Expanded access should be logged, reviewed and reduced when the emergency ends. Temporary need should not become permanent unrestricted sharing.
Research and Commercial Use Require Separate Governance
Connected care data may support valuable research into dementia, falls, medication, healthy longevity, workforce and service outcomes. The potential public benefit does not remove the need for transparency, ethical review and secure access.
De-identification can reduce risk but may not prevent re-identification where datasets contain rare conditions, detailed location, device identifiers or unusual service patterns. Combining several datasets can make individuals more identifiable even when names have been removed.
Commercial use requires particular clarity. Older people may accept monitoring for care but object to the same information being used for advertising, insurance decisions, product development or commercial profiling.
Care delivery should be separated from optional secondary use. Refusing a commercial or research purpose should not normally remove access to essential support.
Artificial Intelligence Introduces New Security and Privacy Risks
AI systems may process care records, clinical notes, voice recordings, sensor information, incident reports and family communication. Risks include unauthorized training use, data leakage, model manipulation, inaccurate outputs, hidden profiling and dependence upon external platforms.
Workers may be tempted to enter sensitive information into general public AI tools to summarize records, translate notes or draft care plans. This can expose personal information to platforms that have not been approved for care use.
Organizations need clear rules, secure alternatives and practical training. A prohibition without usable tools may simply drive activity out of sight.
AI access should also remain proportionate. A scheduling tool does not need a person’s complete clinical history, while a fall-risk model does not require financial information or unrelated family records.
Model Security Needs Specialist Oversight
AI systems may be vulnerable to malicious inputs, insecure interfaces, manipulated training data and uncontrolled updates. Security assurance should cover the model, source data, infrastructure, supplier access and the workflow through which outputs influence care.
An AI-generated summary or risk score may reveal suspected dementia, family conflict, safeguarding information or predicted service need. Access to these outputs should therefore be controlled as carefully as access to the original record.
Older people should understand when AI is used to summarize information, prioritize referrals, predict deterioration or support resource decisions. Human review and challenge should remain available whenever automated processing may affect rights, access or care.
Cybersecurity must be incorporated into AI governance from the beginning, including approved use, access controls, supplier assurance, version control, incident response and safe withdrawal.
Privacy-Preserving Technologies May Support Safer Analysis
Future approaches such as federated learning, secure data environments, pseudonymization and local device processing may reduce unnecessary movement of identifiable information.
A federated model may allow approved analysis across several organizations without transferring every record into one central database. This can support local control and national learning while limiting central exposure.
These technologies do not remove governance responsibilities. Secure identity, common definitions, endpoint protection and transparent decision-making remain necessary. Population analysis may still influence funding or service design even when individuals are not directly identified.
Authentication Must Balance Security and Accessibility
Multi-factor authentication, passkeys and biometric methods can strengthen protection, but some approaches may be difficult for people with cognitive, visual, hearing or dexterity needs.
Services should provide accessible options and supported recovery. Account recovery should not depend entirely upon digital steps that the person cannot complete, nor should difficulty using authentication automatically result in a relative taking permanent control.
Biometric information requires careful governance because it cannot be changed easily if compromised. Organizations should consider accuracy, bias, storage, supplier use, fallback methods and what happens when recognition fails.
Supported access should preserve the older person’s authority wherever possible. Assistance with one digital task should not automatically remove control over communication, appointments, records and permissions.
Safeguarding and Privacy Must Work Together
Information may need to be shared to protect someone from abuse, neglect or exploitation. Excessive or poorly controlled sharing can also create harm, particularly where the person causing concern is a relative with portal, device or financial access.
Professionals should consider the immediacy of risk, the person’s wishes, safe communication routes and the minimum information needed. They should also examine whether technology is being used to monitor, impersonate or isolate the person.
This links directly with safeguarding, abuse, neglect and exploitation. Digital access, account control and location monitoring should be considered within safeguarding assessment rather than treated as separate technical issues.
Operational Example: Responding to Digital Coercion
A care manager notices that every portal message is answered by a relative and that the older person appears unaware of repeated appointment changes.
The care manager creates a private opportunity to speak with the person and discovers that the relative controls the account, email address and telephone linked to care services.
A separate safe contact route is established, account recovery is completed and delegated permissions are reviewed. The person chooses to remove access to appointments and records while retaining limited support for medication reminders.
Safeguarding and financial services then coordinate further action because the relative has also attempted to redirect payments.
The response recognizes that digital control can become a form of coercion affecting safety, autonomy and access to care.
Workforce Wellbeing Is Part of Cyber Resilience
Cyber incidents may create long hours, manual documentation, delayed payroll, public frustration and pressure to improvise. Staff may also experience anxiety about blame or distress after learning that sensitive information has been stolen.
Incident plans should include rest, workload management, psychological support and clear communication. Exhausted workers are more likely to make errors during recovery, particularly when reconciling records or managing unfamiliar manual processes.
Cybersecurity specialists also need an understanding of care delivery. Decisions about disconnecting systems or delaying restoration should be made with professionals who understand medication, home-care workflows, dementia support and safeguarding.
Care leaders do not need to become technical specialists, but they require sufficient cyber literacy to challenge assurance, investment and continuity decisions.
Smaller Providers Need Proportionate National and Regional Support
Small home-care agencies and community providers may lack specialist security staff, procurement expertise and incident-response capability. Their limited resources do not reduce the potential consequences of failure.
Regional or national arrangements could provide threat intelligence, approved procurement frameworks, shared security monitoring, incident assistance, training and recovery support.
Shared services should strengthen rather than replace local accountability. Providers must still understand their systems, maintain continuity plans and report concerns promptly.
Community organizations should not be excluded by security requirements that are disproportionate to their role. Commissioners should provide secure tools and support when small partners need access to sensitive information for defined purposes.
Interoperability and Security Must Support Each Other
Connected care requires information to move safely between hospitals, pharmacies, municipalities and long-term care providers. Security should enable trusted exchange through verified identities, role-based access, encrypted interfaces, audit logging and common standards.
It should not become a blanket justification for withholding information that is genuinely necessary for safe care. Equally, interoperability should not mean that every connected organization gains unrestricted access to complete records.
A zero-trust approach can support this balance by requiring identity, device and purpose to be checked rather than assuming that users or systems are safe because they sit within a trusted network.
Network segmentation can also limit incident spread by separating care records, guest Wi-Fi, building systems, smart-home devices, robotics, supplier access and backup infrastructure.
Organizations Need Accurate Technology Inventories
Providers cannot secure devices and software they do not know exist. An inventory should record equipment type, location, owner, user, support status, information processed, supplier and update arrangements.
This includes equipment installed in private homes as part of commissioned care. A sensor or smart-home hub may remain active after formal support ends unless decommissioning is tracked properly.
Inventories should connect with vulnerability management. Risks should be prioritized according to likelihood of exploitation, system criticality, data sensitivity, number of people affected and the consequences of downtime.
Patching requires operational coordination because updates may interrupt records, monitoring, telehealth or building systems. Testing, communication and rollback arrangements should form part of the change process.
Security Monitoring Must Remain Proportionate
Organizations may monitor logins, network activity and device behaviour to identify unusual access or data movement. This can support early intervention when an account downloads large numbers of records or accesses information after employment ends.
Monitoring should remain necessary, transparent and restricted to defined security purposes. It should not become unrestricted surveillance of workers or older people.
Automated alerts also require careful design. Excessive low-value notifications can create fatigue and delay investigation of serious concerns. Alert thresholds should reflect risk, context and available response capacity.
Security teams should have clear operational escalation routes when technical activity affects medication, monitoring, staffing, hospital discharge or personal alarms.
National Threat Intelligence Could Strengthen the Sector
Japan could support providers by sharing timely information about active phishing campaigns, ransomware groups, supplier vulnerabilities, fraud patterns and compromised software.
Information should be translated into practical actions suitable for organizations of different sizes. A small home-care provider needs clear steps rather than highly technical intelligence that it cannot interpret.
National incident reporting could identify repeated supplier failure, common privacy weaknesses, smart-home vulnerabilities and effective recovery practices.
Reporting should support learning and avoid unnecessary duplication. Providers are less likely to report openly when systems are punitive, fragmented or administratively burdensome.
Exercises Must Test Real Care Consequences
Simulation exercises may test ransomware, cloud failure, stolen devices, smart-home disruption, supplier compromise or loss of medication records.
Exercises should involve operational teams, senior leaders, suppliers and partner organizations. They should test communication, manual care, restoration and decision authority rather than focusing only on technical containment.
Teams should also practise ethical and privacy decisions, including how much information to share, when to notify people and when emergency access should be expanded or withdrawn.
Operational Example: Testing a Care-Home Continuity Plan
A care home runs an exercise in which electronic records, call-bell monitoring and staff scheduling become unavailable.
Teams access protected emergency summaries and activate paper medication procedures. Managers use offline contact lists to confirm staffing, while residents at highest risk receive additional observation during the loss of digital alerts.
Families, health partners and suppliers receive verified updates through alternative channels. When the exercise ends, leaders identify that several emergency summaries are outdated and that responsibility for authorizing restoration is unclear.
The home updates its procedures, increases paper supplies and introduces a clearer executive decision route before the next exercise.
The test improves resilience because it examines how people would actually be protected rather than simply confirming that a continuity document exists.
Regulatory Oversight Should Connect Security and Care Quality
Oversight should examine whether organizations understand digital dependencies, protect information, control access, manage suppliers and maintain care during disruption.
Evidence should extend beyond policies and training records. Regulators and commissioners may need assurance that backups have been restored successfully, unsupported systems are being replaced and continuity plans have been exercised.
Compliance should not become a ceiling. An organization may meet formal requirements while remaining vulnerable because controls exist only on paper, privacy notices are unreadable or frontline workarounds are ignored.
Mature assurance tests whether systems and leadership arrangements work under pressure.
Board Governance Must Connect Cyber Risk With Strategic Decisions
Boards should discuss cybersecurity alongside quality, safeguarding, workforce, finance and operational resilience. They need to understand which services are digitally dependent, where supplier concentration exists and whether investment reflects actual care risk.
Board reporting should show whether restoration capability has been tested, privacy concerns are addressed and improvement actions remain outstanding. Cybersecurity should not be reduced to a technical traffic-light report that provides little insight into consequences for older people.
Governance must also balance security with accessibility and care. Controls that are so restrictive that staff create workarounds or older people lose direct access may introduce different forms of risk.
Operational Example: Board-Level Cyber Governance
A regional long-term care provider introduces connected monitoring, AI-assisted documentation and expanded telehealth across several services.
The board first maps every care process that depends upon digital technology. Cybersecurity, privacy, supplier resilience and continuity are then incorporated into corporate risk management rather than held only within the technology department.
Executive dashboards combine technical controls with service disruption, privacy complaints and recovery testing. Annual exercises involve care, clinical, technical and executive teams.
Audit findings and incidents remain on the board action log until there is evidence that improvements have been implemented and tested.
Cybersecurity becomes a visible component of organizational leadership rather than an isolated technical programme.
Public Trust Depends Upon Consistent Transparency
People are more likely to embrace digital care when organizations explain how information is protected, who can access it and how incidents will be managed.
They should also understand how AI supports decisions, how privacy choices are respected and how concerns can be raised. Transparency should continue throughout the life of a service rather than appearing only at the point of initial consent.
Trust grows through consistent behaviour. Organizations must demonstrate that they correct records, restrict unnecessary access, notify people honestly after incidents and withdraw technology that no longer provides proportionate benefit.
Cybersecurity Enables Responsible Innovation
Security is sometimes presented as an obstacle to innovation. In reality, trustworthy systems encourage adoption because older people, families and professionals are more willing to use technology when risks are understood and controlled.
Well-designed security can support broader participation, safer information sharing, remote care, responsible AI and long-term sustainability.
Weak governance creates the greater barrier. A serious breach or intrusive monitoring programme can damage confidence across an entire class of technology, including systems that may offer genuine benefit.
A National Vision for Trusted Digital Aging
Japan has the opportunity to become an international leader in secure and human-centred digital aging.
A national approach could bring together long-term care cybersecurity standards, privacy-by-design procurement, shared threat intelligence, regional support services, supplier assurance, accessible authentication, AI governance and regular resilience exercises.
National learning should help smaller providers and municipalities avoid repeating the same failures independently. It should also identify systemic dependencies that no single organization can resolve alone.
Public participation will be essential. Older people, caregivers and professionals should influence what monitoring is considered acceptable, which data uses require stronger safeguards and how automated systems can be challenged.
A Human-Centred Test for Connected Care
Before introducing new technology, leaders should ask whether it improves people’s lives, what information is genuinely required and what new risks are introduced.
They should consider whether older people can understand the system, whether privacy choices are meaningful and whether care can continue when the technology fails.
They should also establish who remains accountable, how people can challenge automated decisions and what evidence will show that the service continues to provide benefit.
These questions keep technology accountable to people rather than expecting people to adapt unquestioningly to technology.
Conclusion
Japan’s long-term care system is entering an era in which digital infrastructure will become as important as physical infrastructure. Cybersecurity is therefore inseparable from care quality, safeguarding, operational resilience and public confidence.
The objective cannot be to eliminate every cyber risk because no connected system can guarantee complete protection. The stronger ambition is to build organizations that anticipate threats, detect problems early, respond rapidly and continue providing compassionate care during disruption.
Older people should never be forced to choose between innovation and privacy. They deserve technology that enhances independence while protecting dignity, choice and personal control.
Families should be confident that access is limited and reviewable. Professionals should be supported by systems that are secure, practical and reliable. Leaders should understand that protecting digital infrastructure ultimately means protecting the people whose care depends upon it.
Japan’s international leadership will not be determined by the volume of technology deployed. It will be shaped by whether connected care remains trustworthy, proportionate and resilient as technologies and risks continue to evolve.
Explore further analysis of Japan’s emerging care system through the Japan Aging, Long-Term Care & Community Support Knowledge Hub.