Arc MEDICAL MODEL

将来の医療モデル · 共同開発構想

Future healthcare model · collaboration brief

医療情報の通信を、
医療の現場と設計する。

Designing secure healthcare communication with the people who deliver care.

Arc Medical Modelは、大学病院・研究機関・医療データ基盤事業者とともに、機微な医療情報の転送、組織・端末認可、期限管理、監査可能性を一つの運用モデルへ統合するための将来構想です。

Arc Medical Model is a future collaboration concept for integrating sensitive-data transfer, organizational and device authorization, lifecycle controls, and auditability into one healthcare-specific operating model.

重要な位置づけImportant status

一般向けArcとは別仕様の将来計画です。 現在提供中の医療サービス、医療機器、電子カルテ、診断支援機能ではありません。医療機関・専門家との共同設計、規制評価、実証実験を経て提供可否を判断します。

This is a future healthcare-specific specification, separate from the consumer Arc product. It is not a currently available medical service, medical device, electronic health record, or diagnostic tool. Availability will be determined only after joint design, regulatory evaluation, and validation with healthcare partners.

対象Audience
大学病院、研究機関、医療データ基盤事業者
University hospitals, research institutions, healthcare data platforms
段階Stage
共同要件定義・実証パートナー募集
Joint requirements and validation partner recruitment
更新Updated
2026.08.26 · Atlas Associates Inc.

01 · なぜ別仕様なのか

01 · Why a separate specification

医療は、一般向けチャットの機能追加では成立しない。

Healthcare cannot be addressed by adding features to a consumer messenger.

医療情報には、診療録の保存義務、職務に基づくアクセス制御、患者同意、緊急時の例外、監査、越境移転、インシデント対応が同時に関わります。暗号化だけでなく、組織運用と法務判断を含む別のsystem boundaryが必要です。

Healthcare information involves record-retention duties, role-based access, patient consent, emergency exceptions, auditing, cross-border transfer, and incident response. Encryption is necessary, but a separate system boundary covering clinical operations and legal accountability is essential.

CARE WORKFLOW

診療業務との整合

Clinical workflow alignment

紹介、画像共有、治験、研究連携ごとに、誰が何をいつ閲覧・記録できるかを共同定義します。

Define who can view and record what, and when, for referrals, imaging, trials, and research collaboration.

GOVERNANCE

組織と責任の境界

Organizational accountability

医療機関、委託先、クラウド事業者、Atlas Associatesの責任分界を契約とtechnical controlの両方で閉じます。

Close accountability boundaries among institutions, processors, cloud providers, and Atlas Associates through contracts and technical controls.

EVIDENCE

証拠に基づく提供判断

Evidence-based release decision

脅威モデル、独立評価、実環境の運用試験、障害復旧、法務レビューが揃うまで医療用途として提供しません。

No healthcare release before threat modeling, independent assessment, operational testing, recovery evidence, and legal review are complete.

02 · 共同設計する基盤

02 · Architecture to co-design

暗号、認可、記録、期限を一つの信頼モデルへ。

One trust model for cryptography, authorization, records, and lifecycle.

以下は医療モデルで採用を検討する設計項目です。一般向けArcの提供状況を示すものではなく、医療機関との要件定義と検証によって最終仕様を固定します。

These are proposed design areas for the healthcare model. They do not represent current consumer-product availability; the final specification will be frozen through requirements work and validation with healthcare institutions.

01 · IDENTITY

組織・利用者・端末の分離

Separate organization, user, and device identity

所属、職務、委任、端末登録、失効、再認証を別々の権威として扱い、退職・端末紛失・異動時に旧権限を残しません。

Treat affiliation, role, delegation, device enrollment, revocation, and re-verification as distinct authorities so stale access does not survive personnel or device changes.

02 · KEY SYNC

安全な端末移行と旧端末失効

Secure device transfer and old-device revocation

QRは移行元・移行先端末、組織identity、端末名簿revision、有効期限へ束縛する1回限りの認可であり、暗号鍵そのものではありません。新端末でtransferのcommitとread-backが検証できてから旧端末を失効し、期限切れ・消滅済み・削除済み情報を移行対象から除外します。

The QR code is a one-time authorization bound to source and target devices, organizational identity, roster revision, and expiry—not an encryption key. The old device is revoked only after the transfer commit and read-back are verified on the new device; expired, burned, and deleted information remains excluded.

03 · E2EE TARGET

Signal Protocol · PQXDH · ML-KEM-1024

監査済みライブラリを前提に、標準化ML-KEM-1024と古典鍵合意を組み合わせるPQXDH、Double Ratchet、端末単位の鍵失効を評価します。独自暗号primitiveは設計しません。

Evaluate standardized ML-KEM-1024 hybrid PQXDH, Double Ratchet, and per-device revocation using audited libraries. No custom cryptographic primitives will be designed.

04 · DATA LIFECYCLE

用途別の保存・失効・削除

Purpose-bound retention and retirement

連絡用メッセージ、診療録へ転記すべき情報、研究データを分離します。IGF型の期限管理は保存義務・litigation hold・監査要件と整合する範囲でのみ利用し、診療録廃棄の代替にはしません。

Separate transient coordination, material that belongs in the clinical record, and research data. IGF-style expiry controls may be used only where compatible with retention, legal-hold, and audit duties; they do not replace record management.

05 · INTEROPERABILITY

FHIR・DICOM連携の境界

FHIR and DICOM integration boundaries

データ標準、同意、provenance、参照先システムの責任を明確にし、チャットを電子カルテや画像保管システムの非公式な代替にしません。

Define standards, consent, provenance, and source-system responsibility so messaging never becomes an unofficial substitute for EHR or imaging repositories.

06 · OPERATIONS

監査・復旧・インシデント対応

Audit, recovery, and incident response

本文をログへ出さず、必要最小限のsecurity eventを監査可能にします。鍵失効、誤送信、障害、端末紛失を想定した訓練とread-back証拠を設計します。

Keep message content out of logs while preserving the minimum security-event evidence required for accountability, revocation, misdelivery response, recovery, and device-loss exercises.

07 · RESILIENCE

通常時と災害時の経路分離

Separate routine and disaster pathways

オンライン通信、院内ネットワーク、災害時の限定経路を同一視せず、暗号モード・到達性・OS制約・電波条件ごとの保証範囲を明示します。

Do not conflate online, institutional-network, and disaster pathways. State the exact guarantees for each cryptographic mode, operating-system state, and radio condition.

技術的境界: E2EEを採用しても、宛先、通信時刻、IPアドレス、message size、push provider由来のmetadataが自動的に消えるわけではありません。相手が保存・複製・撮影した情報を遠隔から完全削除することも保証できません。

Technical boundary: E2EE does not automatically hide recipients, timing, IP addresses, message size, or push-provider metadata. It also cannot guarantee remote deletion of information a recipient has saved, copied, or photographed.

03 · 規制と標準

03 · Regulation and standards

「準拠」を先に宣言せず、control mappingから始める。

Start with control mapping—not a premature compliance claim.

適用法令はデータの種類、当事者、地域、契約、運用によって変わります。下記は評価対象であり、認証取得や法令準拠を現在保証する一覧ではありません。

Applicable obligations depend on the data, parties, geography, contracts, and operating model. The list below defines evaluation scope; it is not a current certification or compliance guarantee.

地域・領域Region / domain評価対象Evaluation scope必要な証拠Required evidence
日本Japan個人情報保護法、医療情報システム安全管理ガイドライン、三省2ガイドラインAPPI, MHLW safety-management guidance, and service-provider guidance情報区分、委託関係、control対応表、運用規程、第三者評価Data classification, processor roles, control mapping, procedures, independent assessment
米国United StatesHIPAA / HITECH, BAA, state privacy and breach rulescovered entity / business associate判定、risk analysis、契約、監査Entity-role analysis, risk assessment, contracts, and audit evidence
欧州・越境Europe / cross-borderGDPR, data residency, SCC / transfer mechanisms処理根拠、DPIA、data flow、保管場所、移転影響評価Lawful basis, DPIA, data flow, residency, and transfer-impact assessment
医療相互運用Healthcare interoperabilityHL7 FHIR, DICOM, IHE profiles where applicable適合性試験、provenance、同意、patient matching、異常系Conformance testing, provenance, consent, patient matching, and failure cases

04 · 実証Gate

04 · Validation gates

医療提供を判断する前に、満たすべき証拠。

Evidence required before any healthcare release decision.

病院・研究機関とユースケース、情報区分、責任分界を固定
Freeze use cases, data classification, and accountability with institutions
identity、端末、鍵、権限、緊急例外のthreat modelを第三者レビュー
Independent review of identity, device, key, authorization, and emergency-exception threats
PQXDH / ML-KEM-1024、端末失効、retry、process deathの相互運用試験
Interoperability tests for PQXDH / ML-KEM-1024, revocation, retries, and process death
実データを使わないpilotから開始し、誤配送・欠落・復活を0件で検証
Begin with non-production data and verify zero controlled misdeliveries, loss, or resurrection
インシデント、BCP、鍵失効、account削除、監査証跡の運用訓練
Operational exercises for incidents, continuity, revocation, account deletion, and audit evidence
法務・privacy・security・臨床運用の各責任者がrelease判断に署名
Release sign-off from legal, privacy, security, and clinical operations owners

05 · 対象外

05 · Explicit non-goals

安全のため、しないことも先に決める。

Safety begins by defining what the system will not do.

診断・治療判断をしない

No diagnosis or treatment decision

医療行為、診断、治療方針、緊急度判定を自動化する製品として設計しません。

The model is not designed to automate medical practice, diagnosis, treatment, or urgency decisions.

診療録を置き換えない

No replacement for the clinical record

記録すべき情報は正規の電子カルテ・研究システムへprovenance付きで確定します。

Information that belongs in the record must be committed with provenance to the authorized clinical or research system.

緊急通信を単独保証しない

No sole-channel emergency guarantee

force-stop、圏外、停電、radio制約があるため、緊急連絡の唯一の経路にはしません。

Force-stop, coverage, power, and radio constraints prevent this from being the sole emergency communication channel.

消去を誇張しない

No exaggerated deletion claim

期限管理はcontrolled storageへ適用します。受信者が別途保存したcopyやscreenshotまで消せるとは表現しません。

Lifecycle controls apply to managed storage; they are not represented as erasing separately saved copies or screenshots.

06 · 協業・実証パートナー募集

06 · Collaboration and validation partners

医療の現場と、要件から一緒につくる。

Build from real healthcare requirements—together.

大学病院、研究機関、医療データ基盤事業者、EHR/PACSベンダー、privacy・security・医事法務の専門家を募集しています。特に、国際セカンドオピニオン、臨床研究、画像・文書の院外連携、災害時の限定情報連携について、実データを使わない初期検証から共同設計できる組織を歓迎します。

We welcome university hospitals, research institutions, healthcare data platforms, EHR/PACS vendors, and privacy, security, and healthcare-law specialists. Priority collaboration areas include international second opinions, clinical research, cross-institution imaging and document exchange, and bounded information sharing during disasters—beginning with non-production data.

お問い合わせ時点で医療サービスの提供、適合性、導入時期を保証するものではありません。秘密情報・個人情報・実患者データは初回連絡へ記載しないでください。

An inquiry does not guarantee service availability, compliance, or deployment timing. Do not include confidential information, personal data, or real patient data in the initial message.