Japan’s health and long-term care systems support older people through an extensive network of hospitals, primary-care practices, pharmacies, municipal services, care managers, rehabilitation teams, home-care providers and residential settings.
This breadth creates choice and specialist capability, but it can also divide information across multiple organizations.
An older person may be assessed repeatedly, explain the same history to several professionals and receive support from teams that cannot see each other’s current plans.
The Japan Aging, Long-Term Care & Community Support Knowledge Hub explores how Japan can build a more integrated, preventive and sustainable response to population aging.
Interoperable digital care records are essential to that transformation.
They could help professionals understand the person’s medication, diagnoses, functional ability, long-term care arrangements, rehabilitation goals, communication needs and personal preferences without relying on fragmented paper documents or repeated telephone calls.
However, interoperability is not achieved simply by connecting databases.
Information must be accurate, relevant, understandable and available to the people responsible for acting upon it.
Older people also need confidence that sensitive information will not circulate without clear purpose or meaningful safeguards.
The central challenge is therefore not how much data Japan can connect.
It is how effectively information can support safer decisions, stronger continuity and more person-centred care.
What Interoperability Means in Long-Term Care
Interoperability is the ability of different people, organizations and digital systems to exchange and use information safely.
It includes several connected dimensions.
Technical Interoperability
Systems can transmit and receive information through compatible formats, standards and interfaces.
Semantic Interoperability
The receiving organization understands the information in the same way as the organization that created it.
Operational Interoperability
Professionals know how exchanged information should influence assessment, planning, escalation and follow-up.
Organizational Interoperability
Health, long-term care, housing and community organizations have agreements defining accountability, access and information-sharing.
Person-Centred Interoperability
The older person can understand, contribute to and influence the information used in their care.
A technically connected system may still fail if professionals use different terminology, records are not updated or no one acts on new information.
Japan’s Care Pathways Generate Information Across Many Settings
An older person may have relevant information held by:
- acute hospitals;
- specialist outpatient services;
- primary-care physicians;
- dentists;
- community pharmacies;
- municipal long-term care teams;
- care managers;
- home-care providers;
- home nursing services;
- rehabilitation professionals;
- day services;
- residential long-term care facilities;
- mental health services;
- housing organizations;
- emergency services;
- technology and remote-monitoring platforms; and
- family caregivers.
Each organization may hold only one part of the person’s story.
The hospital may understand the acute diagnosis but know little about the home environment.
The care manager may understand daily routines but lack current clinical information.
The pharmacist may identify medication risk without seeing changes in functional ability.
Interoperability should connect these perspectives around defined care decisions.
Fragmented Information Creates Practical Risk
Information gaps may contribute to:
- duplicate assessment;
- conflicting care plans;
- medication discrepancies;
- missed allergies;
- delayed home support;
- unsafe hospital discharge;
- repeated diagnostic tests;
- poor recognition of deterioration;
- unnecessary emergency attendance;
- failure to respect communication needs;
- caregiver confusion;
- duplicated professional effort; and
- loss of trust.
These problems are not caused only by the absence of technology.
They may also result from unclear responsibilities, inconsistent documentation and organizations that do not routinely coordinate.
Digital records should strengthen integrated working rather than automate existing fragmentation.
Operational Example: Information Lost During a Hospital Transition
An older person living alone is admitted to hospital following a fall and dehydration.
The hospital records the acute treatment but has limited information about the person’s usual mobility, home-care visits and communication needs.
A five-stage interoperable pathway could operate as follows:
- Retrieve the shared profile: The admitting team accesses current medication, long-term care involvement, emergency contacts and communication preferences.
- Confirm information: Hospital staff verify the record with the person, family caregiver and municipal care manager.
- Update changing needs: Reduced mobility, new medication and rehabilitation recommendations are added during admission.
- Coordinate discharge: The care manager, pharmacy, home-support provider and rehabilitation team receive the relevant plan before the person returns home.
- Confirm implementation: The shared record shows whether medication, equipment, visits and follow-up have started.
The digital record does not replace communication.
It creates a common source of information around which professionals can coordinate.
A Shared Care Record Should Provide a Usable Overview
Professionals do not always need access to every item held by every organization.
A shared care record might include:
- identity and contact information;
- preferred name and communication method;
- language and accessibility needs;
- current diagnoses;
- allergies;
- current medication;
- significant clinical risks;
- mobility and functional ability;
- cognitive and communication needs;
- long-term care certification and support level;
- current providers;
- care-plan goals;
- family and informal support;
- recent hospital admissions;
- advance-care preferences;
- equipment and assistive technology;
- emergency arrangements;
- named coordinators; and
- outstanding actions.
The record should identify when each item was reviewed and who remains responsible for maintaining it.
Too Much Information Can Be as Harmful as Too Little
Large volumes of unstructured information may make important details harder to find.
Professionals may encounter:
- duplicate documents;
- outdated plans;
- contradictory medication lists;
- copied notes;
- unclear abbreviations;
- irrelevant historical information;
- unverified automated summaries;
- alerts without priority;
- documents stored in the wrong section; and
- actions without named owners.
A safe shared record should distinguish current information from history.
It should present critical information clearly while allowing professionals to examine additional detail where required.
Data Quality Is a Care Quality Issue
Digital systems may exchange inaccurate information efficiently.
Poor-quality data can lead to incorrect decisions at greater speed and scale.
Common data-quality problems include:
- misspelled names;
- duplicate records;
- incorrect dates;
- outdated medication;
- missing allergies;
- unrecorded changes in capacity;
- incorrect care-provider details;
- ambiguous risk descriptions;
- outdated emergency contacts;
- copy-and-paste errors;
- unverified device readings; and
- actions recorded as complete when they remain outstanding.
Organizations should not treat data cleansing as a one-time technical project.
Accuracy depends on everyday professional practice, clear ownership and regular review.
Every Critical Data Item Needs an Accountable Owner
Governance should determine who is responsible for maintaining information such as:
- medication;
- diagnoses;
- allergies;
- care goals;
- functional ability;
- communication needs;
- emergency contacts;
- advance-care preferences;
- current services;
- risk-management plans; and
- hospital discharge actions.
Responsibility may vary according to the information.
A physician may remain accountable for a diagnosis, while a care manager maintains the current long-term care plan and a pharmacist verifies medication reconciliation.
The system should show the source, date and status of information rather than presenting every entry as equally current and authoritative.
Medication Information Is a Priority for Interoperability
Older people may receive prescriptions from several clinicians and collect medication from different settings.
Risk increases during:
- hospital admission;
- hospital discharge;
- transfer between care settings;
- changes in diagnosis;
- acute illness;
- temporary respite;
- change of pharmacy;
- caregiver transition;
- home-care commencement; and
- end-of-life care.
An interoperable medication record could help professionals identify:
- the current prescription;
- recent additions and discontinuations;
- who authorized each change;
- known allergies;
- duplicate medicines;
- high-risk combinations;
- medicines associated with falls;
- adherence concerns;
- administration support;
- side effects; and
- the person’s own understanding and preferences.
Medication reconciliation should remain a professional task.
A shared list is useful only when it has been checked against what the person is actually taking.
Operational Example: Preventing a Medication Error After Discharge
An older person is discharged after treatment for infection and heart failure.
The hospital has stopped one medicine, changed another dose and introduced a temporary prescription.
The interoperable pathway follows five stages:
- Publish the verified discharge list: The hospital records each medication change and the reason for it.
- Alert relevant professionals: Primary care, the pharmacy, care manager and home nursing service receive the update.
- Reconcile at home: A nurse compares the shared list with medication physically present in the home.
- Resolve discrepancies: An old medicine remains in the person’s dispenser and is removed following clinical confirmation.
- Confirm understanding: The person and caregiver receive an accessible explanation and know whom to contact with concerns.
The pathway prevents a harmful combination that may not have been identified through separate records.
Hospital Discharge Requires More Than a Clinical Summary
A discharge record should support the next stage of daily life.
Relevant information may include:
- reason for admission;
- treatment provided;
- new diagnoses;
- medication changes;
- mobility status;
- cognitive or communication change;
- nutrition and hydration needs;
- wound care;
- rehabilitation goals;
- equipment required;
- personal care needs;
- warning signs;
- scheduled follow-up;
- responsible professionals;
- caregiver concerns; and
- unresolved actions.
The record should be available before or at the time of discharge rather than several days later.
Information received after the person has returned home may be too late to prevent failure.
Discharge Actions Should Be Trackable
Shared records can move beyond sending documents by showing whether key actions have occurred.
These may include:
- medication delivered;
- home-care visits started;
- equipment installed;
- primary-care review booked;
- rehabilitation commenced;
- community nursing contact completed;
- home hazards assessed;
- family caregiver informed;
- transport arranged; and
- follow-up results reviewed.
An action should have a named owner and deadline.
Digital visibility should prevent professionals from assuming that another organization has completed the task.
Long-Term Care Assessments Should Be Available Across the Pathway
Municipal long-term care assessments contain valuable information about:
- daily living ability;
- mobility;
- cognition;
- communication;
- personal care;
- household tasks;
- caregiver involvement;
- housing conditions;
- current services;
- risks;
- personal goals; and
- changes over time.
Relevant information should be available to health professionals when it affects treatment and discharge.
Similarly, care managers need timely information about changes identified by hospitals and primary care.
This connects with health integration and care coordination.
Care Plans Should Reflect One Coherent Direction
An older person may have separate plans for:
- medical treatment;
- long-term care;
- rehabilitation;
- medication;
- nutrition;
- dementia support;
- falls prevention;
- mental health;
- housing adaptation;
- emergency response; and
- family-caregiver support.
These plans may contain different goals and instructions.
Interoperability should help teams identify conflict and duplication.
A shared summary should explain the person’s priorities and how each professional contribution supports them.
Personal Goals Should Be Visible Alongside Clinical Information
Digital records often prioritize diagnoses, risks and service activity.
A person-centred record should also include what the person wants to achieve or preserve.
Goals might include:
- remaining within a familiar home;
- continuing to prepare meals;
- visiting a spouse;
- attending a local group;
- walking safely outdoors;
- managing medication independently;
- reducing pain;
- regaining strength after illness;
- maintaining privacy;
- supporting a family relationship;
- continuing religious or cultural routines; and
- avoiding unwanted hospital admission.
Professionals should be able to see whether planned interventions support or undermine these outcomes.
Risk Information Must Be Specific and Actionable
Labels such as “falls risk,” “dementia” or “non-compliant” provide limited practical guidance.
Useful risk information should explain:
- what may happen;
- which circumstances increase the likelihood;
- how the person understands the risk;
- which preventive actions are effective;
- what support the person accepts;
- which early warning signs matter;
- who should respond;
- when escalation is required; and
- how the plan balances safety with autonomy.
The Positive Risk Enablement Planner can help teams document proportionate support that protects choice while clarifying foreseeable risks and agreed safeguards.
Shared risk information should not create permanent restrictive labels that follow the person across every service.
Advance-Care Preferences Should Be Accessible When Needed
Older people may express preferences about future treatment, hospitalization, resuscitation, place of care and who should participate in decisions.
These wishes may be recorded in different formats and stored by separate organizations.
An interoperable system should help authorized professionals locate:
- the person’s current preferences;
- the date of the discussion;
- the people involved;
- relevant legal documentation;
- clinical context;
- preferred decision-making support;
- the nominated family or trusted person;
- preferred place of care;
- situations requiring further discussion; and
- whether the plan has been reviewed after a significant change.
Availability should not be confused with automatic application.
Professionals must consider current circumstances and confirm the person’s wishes wherever possible.
Emergency Services Need Concise, Reliable Information
During an emergency, professionals may need rapid access to:
- current medication;
- allergies;
- significant diagnoses;
- communication needs;
- baseline cognition;
- mobility support;
- recent deterioration;
- advance-care preferences;
- home oxygen or equipment;
- emergency contacts; and
- the person’s usual providers.
The emergency view should remain concise and current.
Outdated or excessive information can delay decisions and create false confidence.
Care Homes Need Two-Way Information Exchange
Residential long-term care facilities may send residents to hospital with paper summaries that are incomplete or unavailable.
Hospitals may return residents with limited information about treatment and follow-up.
Two-way interoperability should support:
- baseline function and cognition;
- current medication;
- communication needs;
- reason for transfer;
- recent observations;
- advance-care preferences;
- treatment provided;
- medication changes;
- new risks;
- infection-control requirements;
- rehabilitation needs;
- follow-up appointments; and
- warning signs requiring escalation.
The receiving team should know which information has changed and which actions remain outstanding.
Home-Care Workers Need Access to Relevant Information
Home-care workers may observe important changes in daily life but have limited access to clinical or care-management information.
Relevant access may include:
- current support tasks;
- mobility guidance;
- communication preferences;
- nutrition and hydration plans;
- medication-support responsibilities;
- skin-integrity guidance;
- early warning signs;
- infection-control requirements;
- emergency contacts;
- recent hospital discharge information; and
- changes requiring reporting.
Workers do not need unrestricted access to the person’s complete medical history.
Role-based access should provide the information required for safe support while protecting unnecessary personal detail.
Frontline Observations Should Flow Back Into the Shared Record
Home-care and community workers may notice:
- reduced appetite;
- increased confusion;
- difficulty walking;
- medication left untaken;
- changes in mood;
- unsafe home conditions;
- caregiver exhaustion;
- new pain;
- social withdrawal;
- weight loss;
- breathlessness; and
- decline in personal care.
These observations should reach the professionals responsible for assessment and response.
A shared system should make it easy to record concise, relevant change without expecting frontline workers to produce lengthy clinical documentation.
Operational Example: Turning Home-Care Observations Into Early Intervention
A home-care worker notices that an older person is leaving meals untouched and appears less steady over several visits.
The shared pathway follows five stages:
- Record the change: The worker documents the observation using a structured deterioration entry.
- Notify the coordinator: The care manager and community nurse receive an alert because two indicators have changed together.
- Review the wider record: The nurse identifies recent medication adjustment and weight loss documented by the pharmacy and family.
- Complete assessment: A home visit identifies dehydration and adverse medication effects.
- Update the plan: Treatment, meal support and monitoring are revised across the shared record.
Interoperability allows several small pieces of information to form a meaningful pattern before a crisis develops.
Rehabilitation Information Should Follow the Person
Rehabilitation goals and guidance may be lost when people move between hospital, home and long-term care.
A shared rehabilitation record could include:
- baseline ability;
- personally meaningful goals;
- safe transfer guidance;
- walking aids;
- exercise plans;
- pain and fatigue considerations;
- progress achieved;
- support required from care workers;
- environmental barriers;
- review dates;
- reasons for stopping an intervention; and
- future progression.
Care workers and family caregivers should receive information in practical language.
Technical rehabilitation reports alone may not explain how to support daily activity safely.
Interoperability Can Strengthen Dementia Care
People living with dementia may find repeated questioning distressing and may be unable to explain their history during unfamiliar situations.
A person-centred dementia profile may include:
- preferred name;
- communication style;
- important relationships;
- usual routines;
- interests;
- sources of comfort;
- known causes of distress;
- baseline cognition;
- how pain is expressed;
- mobility;
- eating and drinking preferences;
- sensory needs;
- decision-making support;
- successful approaches; and
- information about the home environment.
This information can help hospitals, emergency services and temporary-care providers avoid preventable distress.
The record should be reviewed with the person and those who know them well.
Safeguarding Information Requires Proportionate Access
Some records may contain information about abuse, neglect, financial exploitation, coercion or family conflict.
Safeguarding information must be available to professionals who need it while remaining protected from inappropriate access.
Governance should define:
- which information is shared;
- who may view it;
- how access is restricted;
- when the person is informed;
- how immediate risk is escalated;
- how unverified concerns are described;
- how records are corrected;
- how family access is managed;
- when information may be shared without consent; and
- how decisions are documented.
This aligns with safeguarding, abuse, neglect and exploitation.
Systems should avoid exposing sensitive information to an alleged abuser who also has family portal access.
Family Access Must Be Based on the Older Person’s Choice
Family portals may help relatives understand appointments, medication and care plans.
They can also create privacy and control concerns.
The person should be able to decide:
- which relatives receive access;
- which parts of the record they can see;
- whether they can add information;
- whether they receive alerts;
- how long access continues;
- whether different relatives receive different permissions; and
- how access can be withdrawn.
Family involvement should not become automatic because an older person needs support.
Some people may want assistance with technology while retaining privacy about particular aspects of health or personal life.
Older People Need Direct Access to Their Own Information
A person-centred digital record should allow older people to:
- see current care information;
- check medication;
- understand upcoming appointments;
- review agreed goals;
- identify responsible professionals;
- see outstanding actions;
- add personal information;
- request correction;
- control family access;
- record communication needs;
- review consent; and
- obtain information in an accessible format.
Access should not depend entirely on smartphone ownership or advanced digital confidence.
Printed summaries, supported access and alternative formats should remain available.
Information Must Be Understandable
Clinical records often contain terminology that is difficult for non-professionals to interpret.
Accessible records may require:
- plain-language summaries;
- translation;
- large print;
- audio formats;
- visual information;
- explanations of abbreviations;
- clear distinction between confirmed and suspected information;
- support to understand test results;
- contact details for questions; and
- assistance from an advocate or trusted person.
Providing access without supporting understanding may create anxiety rather than control.
People Must Be Able to Challenge Inaccurate Records
Incorrect information can influence future assessment and treatment.
People should have a clear process to:
- identify an error;
- request correction;
- add their perspective;
- understand who will review the request;
- receive a response within a defined period;
- see whether connected systems were updated;
- escalate unresolved disagreement; and
- record that information remains disputed.
Organizations should not repeatedly copy a contested statement into new records without review.
Consent Should Be Meaningful and Specific
People need clear information about:
- which organizations contribute to the record;
- which professionals may access it;
- what information is included;
- why information is shared;
- whether access is recorded;
- how family members are involved;
- whether data is used for research or planning;
- how long information is retained;
- how access can be restricted; and
- which information may be shared without consent for legal or safety reasons.
Consent should not be reduced to a lengthy document that few people can understand.
It should be supported through clear explanation, accessible formats and opportunities to ask questions.
Supported Decision-Making Should Guide Digital Consent
Some older people may need help understanding information-sharing choices.
Support may include:
- plain language;
- visual explanation;
- discussion over several meetings;
- examples of how information will be used;
- involvement of a trusted person;
- communication aids;
- interpretation;
- checking understanding;
- review when circumstances change; and
- separate decisions about different types of information.
Difficulty understanding technology should not be assumed to mean that the person has no ability to make decisions about their information.
Privacy Controls Should Reflect Different Levels of Sensitivity
Not every professional requires access to every part of the record.
Role-based access may distinguish between:
- emergency information;
- current medication;
- care tasks;
- mental health records;
- safeguarding information;
- sexual health;
- family relationships;
- financial information;
- legal documentation;
- advance-care planning;
- professional notes; and
- information contributed by the person.
Access should reflect professional responsibility and current involvement.
Permissions should be removed when workers change roles or organizations cease providing support.
Access Logs Can Strengthen Accountability
People should be able to know that access to their information is controlled and reviewable.
Audit logs can record:
- who viewed the record;
- which organization they represented;
- what information they accessed;
- when access occurred;
- whether information was changed;
- whether information was exported;
- whether emergency access was used;
- which automated systems processed the record; and
- whether unusual access patterns were identified.
Organizations should monitor logs rather than retain them only for investigation after a breach.
Repeated access unrelated to a professional’s role should trigger review.
Emergency Access Requires Additional Safeguards
There may be circumstances in which emergency clinicians need immediate access to information beyond their normal permissions.
Emergency access arrangements should require:
- a defined clinical or safety reason;
- clear identification of the professional;
- automatic recording of the access;
- notification to the responsible organization;
- retrospective review;
- proportionate access to relevant information;
- sanctions for misuse; and
- clear explanation to the person where appropriate.
Emergency access should not become a convenient way to bypass normal information-governance controls.
Cybersecurity Is Fundamental to Safe Interoperability
Connecting systems can increase the number of routes through which sensitive information may be accessed or disrupted.
Cybersecurity risks may include:
- stolen credentials;
- ransomware;
- malware;
- unauthorized exports;
- compromised supplier systems;
- insecure interfaces;
- misconfigured access permissions;
- unpatched software;
- lost devices;
- phishing;
- insider misuse;
- denial-of-service attacks; and
- corruption or loss of shared records.
Cybersecurity controls should include:
- multi-factor authentication;
- role-based access;
- encryption;
- device management;
- regular patching;
- supplier assurance;
- network monitoring;
- incident response;
- secure backup;
- staff training;
- access review;
- penetration testing; and
- business continuity planning.
A cyber incident affecting shared records is not only an information-security problem.
It can become a direct care-quality and patient-safety risk.
Business Continuity Must Include Record Unavailability
Professionals may become dependent on connected records and lose confidence in operating when systems are unavailable.
Continuity plans should address:
- temporary loss of network access;
- regional outages;
- cyberattack;
- supplier failure;
- power interruption;
- corrupted data;
- failed system updates;
- loss of mobile connectivity;
- inability to verify identity; and
- delayed synchronization between systems.
Fallback arrangements may include:
- read-only emergency summaries;
- secure offline access;
- printed critical-information packs;
- telephone verification;
- manual medication reconciliation;
- local emergency contact lists;
- paper documentation;
- priority restoration plans;
- post-outage data reconciliation; and
- clear communication with people and families.
Continuity arrangements should be tested through practical exercises rather than assumed to work.
Operational Example: Maintaining Care During a Regional Outage
A regional shared-care platform becomes unavailable following a major system failure.
The partnership uses a five-stage continuity process:
- Activate priority access: Hospitals, pharmacies, care homes and home-care teams use locally stored emergency summaries for people with the highest risk.
- Verify critical information: Medication and allergy details are confirmed directly with the person, family, pharmacy and responsible clinician.
- Use temporary documentation: Teams record decisions through approved offline or paper processes.
- Reconcile after restoration: Temporary records are reviewed and entered into the shared system without duplication.
- Review the incident: Leaders assess delayed care, information gaps, staff response and improvements required.
The system failure does not remove professional responsibility for safe assessment and communication.
It tests whether organizations can maintain continuity without their usual digital infrastructure.
Interoperability Requires Common Standards
Organizations cannot exchange information reliably when each system uses different structures and definitions.
Common standards may be needed for:
- identity;
- medication;
- allergies;
- diagnoses;
- functional ability;
- care goals;
- risk;
- communication needs;
- provider details;
- discharge actions;
- consent;
- advance-care preferences;
- equipment;
- alert severity;
- incident reporting; and
- outcomes.
Standards should support consistent meaning without forcing every organization to use identical operational systems.
Local services may retain different workflows while exchanging a common core of understandable information.
Terminology Must Be Consistent Across Health and Long-Term Care
The same word may carry different meanings across clinical, municipal and social-care settings.
Terms such as independence, risk, dependency, rehabilitation, crisis and deterioration may be interpreted differently.
Semantic alignment should establish:
- clear definitions;
- agreed coding systems;
- mapping between existing terminology;
- guidance for free-text information;
- distinction between observed and reported information;
- clear status markers;
- consistent date and time standards;
- version control;
- review arrangements; and
- processes for updating national definitions.
Shared language should improve understanding without removing professional nuance.
Free Text Remains Important
Structured data supports searching, comparison and automated exchange.
It cannot fully capture the complexity of a person’s life.
Free-text documentation may be needed to explain:
- how the person communicates;
- why a particular risk matters;
- what daily routines are important;
- how symptoms present unusually;
- which support approaches are effective;
- how family relationships affect care;
- why a person declined an intervention;
- what professionals remain uncertain about; and
- how personal priorities influence decisions.
Systems should combine structured fields with concise narrative rather than forcing every aspect of care into predefined categories.
Structured Data Should Not Encourage Oversimplification
Drop-down menus and coded fields may improve consistency but can also reduce complex situations to simplistic labels.
Examples include:
- recording cognition as impaired without describing communication strengths;
- recording non-adherence without explaining side effects or personal choice;
- recording high risk without identifying the specific circumstances;
- recording caregiver available without assessing capacity;
- recording independent without describing fluctuating support needs; and
- recording no concern when the person was unable to participate fully.
Documentation design should encourage explanation where a coded response may be misleading.
Identity Matching Must Be Reliable
Interoperability depends on linking information to the correct person.
Identity errors may arise from:
- similar names;
- changes in address;
- different name formats;
- inaccurate dates of birth;
- duplicate records;
- temporary identifiers;
- transcription errors;
- migration between systems;
- language and character variation; and
- records created during emergencies.
Identity matching should use several verified attributes rather than relying on one field.
Systems should flag uncertainty instead of automatically merging records.
Duplicate Records Require Controlled Resolution
Merging two records incorrectly can be as harmful as leaving duplicates unresolved.
A duplicate-record process should include:
- verification by trained staff;
- comparison of several identity fields;
- review of conflicting clinical information;
- preservation of audit history;
- notification to connected organizations;
- correction of downstream systems;
- review of actions taken using incorrect information; and
- communication with the person where appropriate.
Automated matching may identify potential duplicates, but human verification should remain available for uncertain cases.
Interoperability Must Include Smaller Providers
Large hospitals and municipal systems may have greater technical capacity than small home-care agencies, community organizations or rural providers.
A national strategy should prevent smaller organizations from being excluded because they cannot afford complex integration.
Support may include:
- national technical standards;
- shared procurement;
- subsidized interfaces;
- secure web portals;
- standardized templates;
- technical assistance;
- training;
- regional integration hubs;
- minimum supplier requirements; and
- phased implementation.
Interoperability that connects only major institutions will leave important parts of daily care outside the shared system.
Community Organizations Need Proportionate Participation
Community groups may support meals, transport, social connection, exercise, welfare checks and caregiver respite.
They may need limited information to coordinate safely, but they should not receive unrestricted access to health records.
Proportionate information-sharing could include:
- preferred communication method;
- mobility or accessibility needs;
- transport requirements;
- dietary information;
- emergency contact arrangements;
- relevant risk precautions;
- attendance plans;
- consent for coordination; and
- who to contact if concerns arise.
The level of access should reflect the organization’s role and safeguarding responsibilities.
Interoperability Can Improve Rural Care Coordination
Rural areas may rely on small teams covering wide geographical areas.
Shared information can help them:
- reduce repeated travel;
- coordinate visits;
- access specialist advice;
- identify emerging deterioration;
- plan medication delivery;
- support emergency transfer;
- coordinate family involvement;
- share rehabilitation guidance;
- maintain continuity during workforce shortages; and
- understand unmet community need.
Rural interoperability should be designed for low-bandwidth environments and periods of disrupted connectivity.
A system that depends on continuous high-speed access may perform poorly in the communities intended to benefit.
Mobile Access Can Support Community Work
Professionals working in homes and community settings may need secure mobile access to relevant records.
Mobile systems should support:
- role-based information;
- offline capability;
- secure authentication;
- rapid entry of observations;
- photograph controls;
- time-stamped updates;
- voice-to-text with verification;
- accessible interfaces;
- remote device management; and
- automatic removal of cached information.
Mobile documentation should reduce duplication rather than require staff to record the same information in several systems.
Bring-Your-Own-Device Arrangements Create Additional Risk
Allowing staff to access care records through personal devices may improve convenience but introduces concerns involving:
- shared household access;
- unapproved applications;
- insecure networks;
- device loss;
- automatic cloud backup;
- screen capture;
- outdated software;
- mixing personal and professional communication;
- difficulty removing access; and
- unclear ownership of stored information.
Organizations should define whether personal devices are permitted and apply consistent technical and employment controls.
Supplier Ecosystems Must Not Create Data Lock-In
Providers may become dependent on one software supplier because records cannot be exported or transferred easily.
Contracts should require:
- open standards;
- documented interfaces;
- structured data export;
- readable archive formats;
- migration support;
- continued access during transition;
- clear data ownership;
- retention and deletion rules;
- subcontractor transparency;
- security obligations;
- service-level commitments; and
- exit assistance.
Organizations should retain control of their information even when suppliers host or process it.
Procurement Should Test Interoperability Claims
Suppliers may describe systems as interoperable when they can exchange only limited files or require costly custom development.
Procurement should test:
- which standards are supported;
- which systems already connect;
- whether information is exchanged in real time;
- whether data remains understandable after transfer;
- how duplicate records are managed;
- whether consent controls are preserved;
- how audit logs operate;
- whether structured export is available;
- what additional charges apply;
- how upgrades affect interfaces;
- how outages are managed; and
- how the supplier supports contract exit.
The Regulatory Readiness Gap Analyzer can help organizations assess weaknesses in data governance, supplier assurance, cybersecurity, consent and interoperability before procurement or expansion.
Interfaces Require Ongoing Maintenance
An interface that works at launch may fail after a software update, coding change or supplier modification.
Organizations should monitor:
- message failure rates;
- delayed transfers;
- missing fields;
- changed terminology;
- duplicate entries;
- authentication failures;
- data truncation;
- incorrect time stamps;
- system-version compatibility; and
- unresolved technical incidents.
Interoperability should be treated as an operational service requiring maintenance, testing and accountable ownership.
Operational Example: Detecting a Failed Data Interface
A municipal care-management system appears to send discharge notifications to local home-care providers.
An audit finds that some messages have not transferred after a software update.
The partnership follows five stages:
- Identify affected records: Technical logs are compared with hospital discharges and provider receipt confirmations.
- Protect current users: Teams contact affected providers and verify medication, visits and follow-up manually.
- Repair the interface: Suppliers correct the changed data field and complete controlled testing.
- Reconcile missed information: All delayed updates are reviewed before entering provider records.
- Strengthen assurance: Future interface changes require pre-release testing, monitoring and named approval.
The incident shows that successful transmission should be evidenced rather than assumed.
Automated Alerts Need Careful Design
Interoperable systems may generate alerts when new information enters the shared record.
Alerts may relate to:
- hospital admission;
- hospital discharge;
- medication change;
- allergy;
- new safeguarding concern;
- missed follow-up;
- rapid functional decline;
- repeated falls;
- caregiver breakdown;
- new emergency-plan information; and
- significant risk escalation.
Alerts should identify:
- why the notification matters;
- which professional should respond;
- the required timescale;
- what information changed;
- whether the alert has been acknowledged; and
- what happens if no response occurs.
Sending information to a shared inbox without accountable follow-up does not create a safe escalation system.
Alert Fatigue Can Hide Important Change
Professionals may receive so many notifications that they struggle to distinguish urgent risk from routine updates.
Services should monitor:
- alert volume;
- alert severity;
- response time;
- acknowledgment rates;
- duplicate alerts;
- false positives;
- actions generated;
- alerts repeatedly overridden;
- staff feedback; and
- incidents involving missed notifications.
Rules should be refined according to evidence rather than allowing alert volume to increase continuously.
Artificial Intelligence May Help Organize Shared Information
AI may assist by:
- summarizing lengthy records;
- identifying conflicting medication lists;
- detecting missing information;
- highlighting recent change;
- prioritizing alerts;
- linking related observations;
- identifying duplicate records;
- translating terminology;
- predicting transition risk;
- supporting coding; and
- generating accessible summaries.
These uses may reduce administrative burden and make important information easier to find.
AI-generated content should be clearly identified and checked before it influences care.
Automated Summaries Can Distort the Record
An AI summary may omit context, treat old information as current or give excessive weight to repeated documentation.
Risks include:
- missing a recent medication change;
- presenting an unverified concern as fact;
- omitting the person’s preferences;
- misinterpreting abbreviations;
- confusing two family members;
- overstating risk;
- underrepresenting uncertainty;
- failing to distinguish direct observation from reported information; and
- reproducing inaccurate historical labels.
Professionals should verify the source information and remain responsible for the final interpretation.
AI Should Not Determine Access Permissions Automatically
Automated systems may propose who should access particular information based on role, location or previous activity.
Access decisions should remain governed by approved policies and accountable human oversight.
AI should not independently expand access because it predicts that information may be useful.
Privacy controls must remain deliberate, transparent and auditable.
Population Intelligence Requires Separate Governance
Aggregated shared-care data could help Japan understand:
- patterns of hospital admission;
- medication risk;
- unmet long-term care need;
- regional workforce pressure;
- failed discharge;
- rehabilitation gaps;
- caregiver strain;
- rural access;
- inequalities in service use;
- emergency demand;
- housing-related risk; and
- changes in population health.
This intelligence may support planning, commissioning and prevention.
Information collected for individual care should not automatically be reused for research or system planning without appropriate legal, ethical and governance arrangements.
De-Identification Does Not Remove Every Privacy Risk
Data may still be re-identifiable when it includes:
- rare conditions;
- small rural locations;
- unusual service combinations;
- precise dates;
- detailed household information;
- unique care pathways;
- linked demographic characteristics; and
- small population groups.
Population-data governance should consider the likelihood of re-identification and reduce detail where it is not necessary.
Research Access Should Be Transparent
People should be able to understand:
- which data may be used for research;
- who approves access;
- whether commercial organizations are involved;
- how data is protected;
- whether results will be published;
- how communities will benefit;
- whether consent is required;
- how objections are handled; and
- what happens when research ends.
Public confidence will depend on whether data use produces visible social value and remains subject to credible oversight.
Quality Dashboards Can Connect Information Across the System
Interoperable data may support assurance across health and long-term care.
A balanced dashboard could include:
- discharge information received on time;
- medication discrepancies;
- duplicate records;
- unacknowledged alerts;
- failed interfaces;
- accessibility needs recorded;
- care-plan review completion;
- outstanding actions;
- privacy incidents;
- cybersecurity events;
- user correction requests;
- record-access complaints;
- supplier performance;
- staff documentation burden; and
- outcomes following care transitions.
The Quality Dashboard Builder can help organizations combine safety, timeliness, data quality, workforce and outcome measures within one assurance framework.
Quality Measurement Should Examine Whether Information Was Used
Recording that a document was transmitted does not show that it influenced care.
Organizations should assess:
- whether the receiving team viewed the information;
- whether required actions were completed;
- whether conflicting information was resolved;
- whether the person understood the revised plan;
- whether duplication reduced;
- whether medication errors declined;
- whether discharge became safer;
- whether emergency teams found information useful;
- whether staff saved time; and
- whether outcomes improved.
Interoperability should be evaluated through the decisions it enables rather than the volume of data exchanged.
Incidents Must Include Information Failures
Organizations should recognize incidents involving:
- information sent to the wrong person;
- incorrect record matching;
- missing discharge information;
- outdated medication;
- unauthorized access;
- failed interface transmission;
- incorrect automated summary;
- unreviewed alert;
- lost consent restrictions;
- inappropriate family access;
- record unavailability;
- incorrect data migration;
- failure to update connected systems; and
- care decisions based on inaccurate information.
The Quality Improvement Action Plan Builder can help teams convert repeated information failures into accountable corrective actions with named owners, deadlines and completion evidence.
Incident Review Should Examine the Whole Pathway
An information-related incident may involve several contributing factors.
Review should consider:
- record design;
- data-entry practice;
- workload;
- training;
- access permissions;
- interface failure;
- supplier change;
- unclear responsibility;
- poor terminology;
- alert design;
- business continuity;
- communication between organizations; and
- whether the person had an opportunity to correct information.
Blaming the professional who entered the final incorrect field may overlook deeper system weaknesses.
Complaints Can Reveal Loss of Control
People may complain that:
- incorrect information follows them across services;
- too many professionals can view their record;
- family members received access without agreement;
- they cannot correct an error;
- information was shared without explanation;
- staff rely on the record rather than listening;
- different systems show conflicting information;
- important preferences are missing;
- the portal is inaccessible; or
- they do not understand how their data is being used.
Complaints should be treated as evidence about trust, usability and governance rather than only as customer-service issues.
Frontline Staff Should Influence Record Design
Systems developed without frontline input may create unnecessary fields, duplicate work and difficult navigation.
Workers should help test:
- how quickly critical information can be found;
- whether terminology reflects practice;
- whether alerts are meaningful;
- how information is entered during home visits;
- whether documentation is duplicated;
- how corrections are made;
- how tasks are assigned;
- whether access works in low-connectivity locations;
- how handovers are completed; and
- which information supports safe decisions.
A technically sophisticated record may fail if staff need workarounds to complete routine tasks.
Documentation Burden Must Be Measured
Interoperability should reduce repeated entry, but poorly designed systems may require professionals to:
- enter the same information in several applications;
- copy data manually;
- scan documents;
- reconcile conflicting fields;
- respond to excessive alerts;
- maintain separate local notes;
- check whether transfers succeeded;
- manage repeated login processes;
- correct automated summaries; and
- support people who cannot access portals.
Leaders should measure time spent on documentation before and after implementation.
Efficiency claims should include the full workforce experience.
Training Must Extend Beyond Software Navigation
Staff need competence in:
- accurate documentation;
- data quality;
- role-based access;
- consent;
- privacy;
- cybersecurity;
- identity verification;
- information-sharing;
- record correction;
- alert response;
- business continuity;
- safeguarding;
- accessible communication;
- supplier incident reporting; and
- professional accountability.
Training should use realistic scenarios involving discharge, medication, family access and disputed information.
Competence should be refreshed when systems, policies or responsibilities change.
New Roles May Be Needed
Integrated digital records may require roles such as:
- clinical information leads;
- long-term care interoperability coordinators;
- data-quality specialists;
- information-governance leads;
- cybersecurity specialists;
- interface managers;
- digital inclusion coordinators;
- record-correction officers;
- supplier-assurance leads;
- clinical safety officers;
- analytics specialists; and
- lived-experience advisers.
These roles should support frontline practice rather than create a separate digital bureaucracy.
Professional Accountability Must Remain Clear
A shared record can make information visible to many professionals, but visibility does not automatically transfer responsibility.
Organizations should define:
- who verifies medication;
- who updates the care plan;
- who responds to alerts;
- who confirms discharge actions;
- who corrects identity errors;
- who reviews disputed information;
- who monitors supplier performance;
- who informs the person about a breach;
- who acts during system failure; and
- who provides final clinical interpretation.
Shared access should strengthen coordination without creating collective ambiguity.
Governance Must Connect Technology, Practice and Accountability
Interoperability programmes often begin as technology initiatives.
Their success ultimately depends on governance across clinical care, long-term care, municipal services, information security, workforce practice and supplier management.
Leaders should be able to explain:
- which organizations contribute information;
- which systems exchange data;
- which standards are used;
- who owns each critical information item;
- how access is authorized;
- how consent and restrictions are recorded;
- who responds to alerts;
- how inaccurate information is corrected;
- how interface failures are detected;
- how incidents are investigated;
- how suppliers are held accountable;
- how people participate in governance; and
- how outcomes are evaluated.
The governance framework should cover the full information journey from creation and sharing to use, correction, retention and eventual deletion.
Boards Need Evidence About Care Impact
Senior leaders may receive reports showing the number of connected systems, shared records or data transactions.
These measures demonstrate activity, but not whether interoperability improves care.
Board assurance should examine:
- medication discrepancies;
- delayed discharge information;
- duplicate records;
- failed interfaces;
- unacknowledged alerts;
- inaccurate information;
- unauthorized access;
- record correction times;
- cyber incidents;
- staff documentation burden;
- user complaints;
- inequality in access;
- supplier performance;
- continuity during outages; and
- outcomes following transitions.
The Governance Maturity Assessment can help organizations determine whether digital-record oversight remains fragmented or has become embedded within strategic, operational and quality governance.
Boards should ask whether connected information has prevented harm, reduced duplication and improved coordination.
Operational Example: Creating System-Wide Information Governance
A regional partnership connects hospital, municipal, pharmacy and long-term care records, but each organization applies different access and correction rules.
The partnership introduces a five-stage governance model:
- Map accountability: Every data source, interface, supplier and responsible organization is documented.
- Agree common controls: Partners establish shared standards for identity, access, consent, correction, alerts and incident escalation.
- Create joint assurance: Data quality, interface performance, privacy incidents and care outcomes are reviewed through one regional forum.
- Include public representation: Older people and caregivers review portal design, access controls and information-sharing explanations.
- Act on evidence: Persistent failures lead to revised workflows, supplier action or suspension of unsafe data exchange.
The partnership moves from separate organizational policies to a coherent system of shared accountability.
Older People Should Participate in Record Design
Digital records are often designed around professional documentation and reporting requirements.
Older people should help shape:
- which information appears in the shared summary;
- how personal goals are displayed;
- how consent choices are explained;
- how family access is managed;
- how errors are challenged;
- which accessibility features are required;
- how alerts and notifications are communicated;
- how emergency information is presented;
- how personal contributions are distinguished from professional notes; and
- how people can see who accessed their record.
This aligns with co-production and lived experience.
Design groups should include people with limited digital confidence, sensory impairment, cognitive change and varied family circumstances.
A Personal Health and Care Record Could Strengthen Control
Future systems may give older people a unified personal view across health and long-term care.
A personal record could allow someone to:
- review medication;
- see current professionals and providers;
- check appointments;
- review personal goals;
- see hospital discharge actions;
- record preferences;
- add information about daily life;
- manage family permissions;
- request corrections;
- download an emergency summary;
- review consent choices; and
- see how their information has been accessed.
The personal record should not become the only route through which people can understand their care.
Supported access, paper summaries and direct professional explanation must remain available.
Personal Contributions Should Be Treated as Valuable Evidence
Older people may identify information that formal records overlook.
They may contribute:
- daily symptoms;
- medication side effects;
- changes in appetite;
- sleep patterns;
- mobility concerns;
- personal goals;
- communication preferences;
- caregiver availability;
- home-environment changes;
- reasons for declining treatment;
- what helps during distress; and
- questions for upcoming appointments.
Systems should identify the source of information clearly while ensuring that personal contributions can influence professional assessment.
Information should not be treated as less important simply because it originated with the person rather than a clinician.
Family Caregivers Need Defined and Flexible Permissions
Family caregivers may support appointment coordination, medication, transport and communication.
Access arrangements should allow the older person to decide:
- which relative may view information;
- which parts they may access;
- whether they can add observations;
- whether they receive alerts;
- whether they can communicate with professionals;
- how long access continues;
- whether access changes during illness;
- how permissions are reviewed; and
- how access is withdrawn.
Systems should also support situations in which family relationships are difficult, unsafe or changing.
One relative should not automatically receive control because they provide occasional support.
Digital Portals Must Be Accessible
Portal design should account for:
- visual impairment;
- hearing impairment;
- cognitive change;
- limited literacy;
- language differences;
- motor difficulty;
- older devices;
- limited connectivity;
- password difficulty; and
- the need for supported access.
Useful features may include:
- large text;
- high contrast;
- screen-reader compatibility;
- voice control;
- plain-language summaries;
- translation;
- simple navigation;
- telephone support;
- trusted-person access; and
- printable information.
Accessibility should be tested directly with older users.
Interoperability Can Support More Preventive Care
Connected information may help teams identify gradual change before crisis develops.
Patterns may emerge across:
- repeated falls;
- weight loss;
- medication changes;
- missed appointments;
- increasing home-care hours;
- reduced rehabilitation progress;
- repeated emergency contacts;
- caregiver strain;
- declining social participation;
- changes in cognition;
- housing concerns; and
- increased use of urgent services.
No single entry may appear urgent.
Interoperability can help combine these signals into a more complete understanding of emerging risk.
Predictive Models Must Not Exclude People With Sparse Data
Connected data may support algorithms that estimate risk of admission, deterioration or failed discharge.
These models may perform poorly for people who:
- rarely use formal services;
- live in rural areas;
- receive most support from family;
- have records across unconnected systems;
- cannot use digital tools;
- move between municipalities;
- use community services not included in the dataset; or
- belong to small population groups.
Limited data should not be interpreted as low need.
Predictive systems require equity testing, professional challenge and routes for adding contextual information.
Population Intelligence Could Improve Planning
Aggregated interoperable data could help municipalities and national leaders understand:
- where long-term care demand is increasing;
- which communities experience repeated failed discharge;
- where medication risk is concentrated;
- which populations lack rehabilitation;
- where caregiver breakdown is increasing;
- which rural areas experience access gaps;
- where workforce shortages affect continuity;
- which housing conditions contribute to crisis;
- where emergency demand is rising; and
- which preventive interventions improve outcomes.
This aligns with data and intelligence.
Population insight should guide investment while remaining subject to strong privacy and ethical safeguards.
Commissioning Can Reward Information Continuity
Commissioners and municipalities can strengthen interoperability by requiring providers to demonstrate:
- timely record updates;
- accurate medication information;
- participation in shared-care systems;
- role-based access controls;
- response to alerts;
- safe discharge communication;
- data-quality assurance;
- cybersecurity controls;
- record correction processes;
- business continuity;
- staff competence; and
- evidence that information improves outcomes.
This connects with commissioning, funding and system design.
Contracts should avoid placing technical requirements on small providers without funding and support to meet them.
Funding Should Cover Integration, Not Only Software
Interoperability requires investment in:
- system interfaces;
- data cleansing;
- identity matching;
- workflow redesign;
- training;
- cybersecurity;
- technical support;
- digital inclusion;
- supplier management;
- quality assurance;
- record correction;
- business continuity;
- public involvement; and
- evaluation.
Funding only the central platform can leave organizations without the capacity to use it safely.
Whole-life costs should include maintenance, interface updates, supplier transition and workforce time.
National Infrastructure Could Reduce Local Duplication
Japan could support municipalities and providers through national services such as:
- common data standards;
- national identity services;
- secure authentication;
- consent frameworks;
- interoperability specifications;
- approved supplier requirements;
- cybersecurity guidance;
- standard emergency summaries;
- shared terminology;
- testing environments;
- technical support for smaller providers;
- national incident reporting; and
- independent evaluation.
National infrastructure should establish a reliable foundation without removing local responsibility for service design and accountability.
National Standards Should Protect Local Innovation
Consistency is needed for safety-critical information, but organizations should retain flexibility to improve local workflows.
National standards could define:
- minimum information sets;
- technical formats;
- identity requirements;
- access principles;
- consent controls;
- audit logging;
- data-quality expectations;
- cybersecurity;
- interface monitoring;
- record correction;
- business continuity;
- supplier exit; and
- quality reporting.
Local systems could then build additional functionality around community needs while retaining national compatibility.
Certification Could Strengthen Supplier Accountability
Technology suppliers could be required to demonstrate:
- conformity with interoperability standards;
- secure development;
- accessible design;
- data-export capability;
- audit logging;
- identity controls;
- interface reliability;
- incident reporting;
- business continuity;
- subcontractor transparency;
- performance monitoring; and
- safe contract exit.
Certification should include ongoing surveillance rather than one approval before market entry.
Major software changes should trigger renewed testing where they affect safety or data exchange.
Independent Assurance Can Build Public Trust
People may be more willing to support connected records when they know that systems are independently reviewed.
Assurance may examine:
- privacy controls;
- cybersecurity;
- data quality;
- access logs;
- record correction;
- supplier compliance;
- algorithmic fairness;
- incident response;
- business continuity;
- user accessibility;
- public communication; and
- evidence of care benefit.
Assurance findings should be communicated in language that the public can understand.
Transparency Should Extend to System Failure
Organizations should communicate openly when interoperability fails.
People may need to know:
- what happened;
- which information was affected;
- whether care decisions may have been influenced;
- whether unauthorized access occurred;
- what immediate protections were introduced;
- how records will be corrected;
- who they can contact;
- how the incident is being investigated; and
- what will prevent recurrence.
Transparency should avoid technical language that minimizes the potential impact on care.
Common Weaknesses in Interoperability Programmes
Interoperability initiatives may appear successful while important operational problems remain unresolved.
Common weaknesses include:
- connecting systems without redesigning workflows;
- sharing excessive information;
- failing to identify accountable data owners;
- assuming information is accurate because it is digital;
- using inconsistent terminology;
- allowing duplicate records to persist;
- providing broad rather than role-based access;
- failing to monitor interface errors;
- creating alerts without response ownership;
- excluding small providers;
- ignoring documentation burden;
- relying on supplier claims;
- providing inaccessible portals;
- making correction difficult;
- assuming family access is always appropriate;
- collecting data without clear purpose;
- failing to prepare for outages; and
- measuring data exchange instead of care outcomes.
Mature programmes treat interoperability as continuous organizational improvement rather than a completed technology installation.
What Other Countries Can Learn From Japan
1. Connect Information Around the Person
Interoperability should support one coherent care journey rather than simply link institutional databases.
2. Prioritize Transitions
Hospital admission, discharge and movement between care settings are high-value starting points.
3. Treat Data Quality as a Safety Issue
Inaccurate shared information can spread harm rapidly across connected services.
4. Give Every Critical Item an Owner
Medication, care plans, alerts and discharge actions require accountable maintenance.
5. Provide Role-Based Access
Professionals need relevant information, not unrestricted access to complete records.
6. Include Smaller Providers
National integration fails when home-care and community organizations remain disconnected.
7. Preserve Personal Control
Older people should be able to access, understand and challenge their information.
8. Plan for System Failure
Care must continue safely when digital records are temporarily unavailable.
9. Test Supplier Claims
Interoperability should be demonstrated through real exchange, usability and safe contract exit.
10. Measure Decisions and Outcomes
The purpose of connected records is better care, not greater data volume.
The Future of Connected Care Records in Japan
Future digital records may combine:
- health information;
- long-term care plans;
- medication;
- rehabilitation;
- remote-monitoring data;
- smart-home information;
- personal goals;
- caregiver observations;
- housing needs;
- community participation;
- emergency plans;
- advance-care preferences;
- predictive risk indicators; and
- personal access and consent controls.
The challenge will be maintaining relevance and proportionality as more data sources become available.
Connected care should not become continuous surveillance or an unmanageable accumulation of information.
Digital Identity Could Simplify Access
Secure digital identity may allow older people and professionals to access records across organizations without repeated registration.
A national identity model would need safeguards for:
- identity verification;
- fraud prevention;
- delegated access;
- people unable to use digital credentials;
- lost devices;
- emergency access;
- changes in family support;
- record correction;
- access revocation; and
- offline alternatives.
Digital identity should simplify access without becoming a barrier for people who need non-digital support.
Portable Care Summaries Could Support Mobility
Older people may move temporarily or permanently between municipalities, hospitals, family homes and care settings.
A portable summary could include:
- current medication;
- allergies;
- diagnoses;
- functional ability;
- communication needs;
- current support;
- personal priorities;
- advance-care preferences;
- emergency contacts;
- recent treatment;
- equipment; and
- outstanding actions.
The summary should remain synchronized with source systems and clearly show when it was last verified.
Digital Twins May Support More Coordinated Planning
Future systems may create dynamic digital representations of an individual’s health, function, care environment and support network.
A personal digital twin could potentially combine:
- clinical history;
- medication;
- daily function;
- mobility;
- home environment;
- remote observations;
- rehabilitation progress;
- caregiver capacity;
- service use;
- personal goals; and
- predicted response to different interventions.
Such systems could help teams test alternative care plans and anticipate future needs.
They would also create significant questions about accuracy, consent, explainability, bias and the right not to be continuously modeled.
Federated Data Models May Protect Local Control
Rather than transferring every record into one national database, future systems may allow approved queries across information held locally.
A federated model could:
- reduce unnecessary central storage;
- allow organizations to retain source records;
- support national analysis;
- limit the movement of identifiable data;
- apply consistent access controls;
- improve resilience; and
- support regional innovation.
Federated systems still require common standards, reliable identity matching and transparent governance.
Blockchain Is Not a Substitute for Governance
Distributed-ledger technology is sometimes proposed as a way to protect record integrity and track access.
Potential uses may include:
- consent records;
- access logs;
- credential verification;
- document version history;
- supplier accountability; and
- proof of data exchange.
Blockchain cannot determine whether information is accurate, whether access is appropriate or whether professionals act upon it.
Technology should be selected according to defined need rather than novelty.
Generative AI May Change How Records Are Used
Generative AI may help professionals:
- summarize complex histories;
- prepare multidisciplinary reviews;
- identify unresolved actions;
- translate technical information;
- produce person-friendly summaries;
- compare conflicting plans;
- draft referral information;
- identify missing data;
- organize chronology; and
- highlight emerging patterns.
AI should identify its sources and clearly communicate uncertainty.
Professionals must verify outputs before they affect diagnosis, treatment or support.
The Right to Human Review Must Be Protected
People should be able to challenge decisions influenced by automated analysis.
Human review is particularly important where systems affect:
- access to long-term care;
- risk classification;
- service prioritization;
- hospital discharge;
- safeguarding;
- caregiver assessment;
- funding;
- housing support;
- emergency response; and
- restrictions on personal choice.
Automated recommendations should not become unchallengeable because they draw upon a large volume of connected data.
A Human-Centred Vision for Interoperability
The most advanced connected-care system will not be the one that centralizes the greatest volume of data.
It will be the one that makes the right information available to the right person at the right time for a clear and legitimate purpose.
A human-centred model would prioritize:
- care purpose before data collection;
- accuracy before speed;
- relevance before volume;
- personal goals alongside clinical risk;
- role-based access before unrestricted sharing;
- understanding before technical availability;
- correction before repeated copying;
- accountability before automation;
- continuity before organizational ownership; and
- outcomes before transaction counts.
Interoperability should help professionals listen more effectively, not encourage them to rely on records instead of the person.
Conclusion
Digital care records and interoperability could become foundational infrastructure for Japan’s response to population aging.
Connected information can reduce repeated assessment, strengthen medication safety, improve hospital discharge and allow health, long-term care and community services to work from a more coherent understanding of the person.
The opportunity is significant, but technical connection alone will not produce integrated care.
Information must be accurate, current, relevant and understandable.
Every critical item requires accountable ownership, and every alert or shared action requires a clear response.
Older people need meaningful access to their own information, genuine control over family permissions and reliable routes for correcting mistakes.
Smaller providers, rural services and community organizations must be included through proportionate and affordable access.
Cybersecurity, business continuity and supplier accountability should be treated as direct care-quality responsibilities.
Japan should therefore approach interoperability not as a national database project, but as a transformation of relationships, decisions and accountability across the care system.
The strongest connected record will not replace professional communication or personal knowledge.
It will make them more reliable, timely and coordinated.
Built around trust, proportionality and shared purpose, interoperability can help Japan create a care system in which older people experience one connected pathway rather than a succession of disconnected organizations.