診療業務との整合
Clinical workflow alignment
紹介、画像共有、治験、研究連携ごとに、誰が何をいつ閲覧・記録できるかを共同定義します。
Define who can view and record what, and when, for referrals, imaging, trials, and research collaboration.
将来の医療モデル · 共同開発構想
Future healthcare model · collaboration brief
Arc Medical Modelは、大学病院・研究機関・医療データ基盤事業者とともに、機微な医療情報の転送、組織・端末認可、期限管理、監査可能性を一つの運用モデルへ統合するための将来構想です。
Arc Medical Model is a future collaboration concept for integrating sensitive-data transfer, organizational and device authorization, lifecycle controls, and auditability into one healthcare-specific operating model.
一般向けArcとは別仕様の将来計画です。 現在提供中の医療サービス、医療機器、電子カルテ、診断支援機能ではありません。医療機関・専門家との共同設計、規制評価、実証実験を経て提供可否を判断します。
This is a future healthcare-specific specification, separate from the consumer Arc product. It is not a currently available medical service, medical device, electronic health record, or diagnostic tool. Availability will be determined only after joint design, regulatory evaluation, and validation with healthcare partners.
01 · なぜ別仕様なのか
01 · Why a separate specification
医療情報には、診療録の保存義務、職務に基づくアクセス制御、患者同意、緊急時の例外、監査、越境移転、インシデント対応が同時に関わります。暗号化だけでなく、組織運用と法務判断を含む別のsystem boundaryが必要です。
Healthcare information involves record-retention duties, role-based access, patient consent, emergency exceptions, auditing, cross-border transfer, and incident response. Encryption is necessary, but a separate system boundary covering clinical operations and legal accountability is essential.
紹介、画像共有、治験、研究連携ごとに、誰が何をいつ閲覧・記録できるかを共同定義します。
Define who can view and record what, and when, for referrals, imaging, trials, and research collaboration.
医療機関、委託先、クラウド事業者、Atlas Associatesの責任分界を契約とtechnical controlの両方で閉じます。
Close accountability boundaries among institutions, processors, cloud providers, and Atlas Associates through contracts and technical controls.
脅威モデル、独立評価、実環境の運用試験、障害復旧、法務レビューが揃うまで医療用途として提供しません。
No healthcare release before threat modeling, independent assessment, operational testing, recovery evidence, and legal review are complete.
02 · 共同設計する基盤
02 · Architecture to co-design
以下は医療モデルで採用を検討する設計項目です。一般向けArcの提供状況を示すものではなく、医療機関との要件定義と検証によって最終仕様を固定します。
These are proposed design areas for the healthcare model. They do not represent current consumer-product availability; the final specification will be frozen through requirements work and validation with healthcare institutions.
所属、職務、委任、端末登録、失効、再認証を別々の権威として扱い、退職・端末紛失・異動時に旧権限を残しません。
Treat affiliation, role, delegation, device enrollment, revocation, and re-verification as distinct authorities so stale access does not survive personnel or device changes.
QRは移行元・移行先端末、組織identity、端末名簿revision、有効期限へ束縛する1回限りの認可であり、暗号鍵そのものではありません。新端末でtransferのcommitとread-backが検証できてから旧端末を失効し、期限切れ・消滅済み・削除済み情報を移行対象から除外します。
The QR code is a one-time authorization bound to source and target devices, organizational identity, roster revision, and expiry—not an encryption key. The old device is revoked only after the transfer commit and read-back are verified on the new device; expired, burned, and deleted information remains excluded.
監査済みライブラリを前提に、標準化ML-KEM-1024と古典鍵合意を組み合わせるPQXDH、Double Ratchet、端末単位の鍵失効を評価します。独自暗号primitiveは設計しません。
Evaluate standardized ML-KEM-1024 hybrid PQXDH, Double Ratchet, and per-device revocation using audited libraries. No custom cryptographic primitives will be designed.
連絡用メッセージ、診療録へ転記すべき情報、研究データを分離します。IGF型の期限管理は保存義務・litigation hold・監査要件と整合する範囲でのみ利用し、診療録廃棄の代替にはしません。
Separate transient coordination, material that belongs in the clinical record, and research data. IGF-style expiry controls may be used only where compatible with retention, legal-hold, and audit duties; they do not replace record management.
データ標準、同意、provenance、参照先システムの責任を明確にし、チャットを電子カルテや画像保管システムの非公式な代替にしません。
Define standards, consent, provenance, and source-system responsibility so messaging never becomes an unofficial substitute for EHR or imaging repositories.
本文をログへ出さず、必要最小限のsecurity eventを監査可能にします。鍵失効、誤送信、障害、端末紛失を想定した訓練とread-back証拠を設計します。
Keep message content out of logs while preserving the minimum security-event evidence required for accountability, revocation, misdelivery response, recovery, and device-loss exercises.
オンライン通信、院内ネットワーク、災害時の限定経路を同一視せず、暗号モード・到達性・OS制約・電波条件ごとの保証範囲を明示します。
Do not conflate online, institutional-network, and disaster pathways. State the exact guarantees for each cryptographic mode, operating-system state, and radio condition.
技術的境界: E2EEを採用しても、宛先、通信時刻、IPアドレス、message size、push provider由来のmetadataが自動的に消えるわけではありません。相手が保存・複製・撮影した情報を遠隔から完全削除することも保証できません。
Technical boundary: E2EE does not automatically hide recipients, timing, IP addresses, message size, or push-provider metadata. It also cannot guarantee remote deletion of information a recipient has saved, copied, or photographed.
03 · 規制と標準
03 · Regulation and standards
適用法令はデータの種類、当事者、地域、契約、運用によって変わります。下記は評価対象であり、認証取得や法令準拠を現在保証する一覧ではありません。
Applicable obligations depend on the data, parties, geography, contracts, and operating model. The list below defines evaluation scope; it is not a current certification or compliance guarantee.
| 地域・領域 | Region / domain | 評価対象 | Evaluation scope | 必要な証拠 | Required evidence |
|---|---|---|---|---|---|
| 日本 | Japan | 個人情報保護法、医療情報システム安全管理ガイドライン、三省2ガイドライン | APPI, MHLW safety-management guidance, and service-provider guidance | 情報区分、委託関係、control対応表、運用規程、第三者評価 | Data classification, processor roles, control mapping, procedures, independent assessment |
| 米国 | United States | HIPAA / HITECH, BAA, state privacy and breach rules | covered entity / business associate判定、risk analysis、契約、監査 | Entity-role analysis, risk assessment, contracts, and audit evidence | |
| 欧州・越境 | Europe / cross-border | GDPR, data residency, SCC / transfer mechanisms | 処理根拠、DPIA、data flow、保管場所、移転影響評価 | Lawful basis, DPIA, data flow, residency, and transfer-impact assessment | |
| 医療相互運用 | Healthcare interoperability | HL7 FHIR, DICOM, IHE profiles where applicable | 適合性試験、provenance、同意、patient matching、異常系 | Conformance testing, provenance, consent, patient matching, and failure cases |
04 · 実証Gate
04 · Validation gates
05 · 対象外
05 · Explicit non-goals
医療行為、診断、治療方針、緊急度判定を自動化する製品として設計しません。
The model is not designed to automate medical practice, diagnosis, treatment, or urgency decisions.
記録すべき情報は正規の電子カルテ・研究システムへprovenance付きで確定します。
Information that belongs in the record must be committed with provenance to the authorized clinical or research system.
force-stop、圏外、停電、radio制約があるため、緊急連絡の唯一の経路にはしません。
Force-stop, coverage, power, and radio constraints prevent this from being the sole emergency communication channel.
期限管理はcontrolled storageへ適用します。受信者が別途保存したcopyやscreenshotまで消せるとは表現しません。
Lifecycle controls apply to managed storage; they are not represented as erasing separately saved copies or screenshots.
06 · 協業・実証パートナー募集
06 · Collaboration and validation partners
大学病院、研究機関、医療データ基盤事業者、EHR/PACSベンダー、privacy・security・医事法務の専門家を募集しています。特に、国際セカンドオピニオン、臨床研究、画像・文書の院外連携、災害時の限定情報連携について、実データを使わない初期検証から共同設計できる組織を歓迎します。
We welcome university hospitals, research institutions, healthcare data platforms, EHR/PACS vendors, and privacy, security, and healthcare-law specialists. Priority collaboration areas include international second opinions, clinical research, cross-institution imaging and document exchange, and bounded information sharing during disasters—beginning with non-production data.
お問い合わせ時点で医療サービスの提供、適合性、導入時期を保証するものではありません。秘密情報・個人情報・実患者データは初回連絡へ記載しないでください。
An inquiry does not guarantee service availability, compliance, or deployment timing. Do not include confidential information, personal data, or real patient data in the initial message.