March 1, 2020
Life Data Initiative, a general incorporated association
Regarding inappropriate acquisition of information in certified projects based on the Next-Generation Medical Infrastructure Act
Regarding the recurrence prevention measures implemented based on guidance from the relevant government ministries and agencies and the Personal Information Protection Commission:
Life Data Initiative (hereinafter referred to as LDI) and NTT DATA Corporation (hereinafter referred to as NTT DATA) will reliably implement the measures to prevent recurrence that were established based on the guidance received from the relevant government ministries and agencies and the Personal Information Protection Commission, following the Personal Information Protection Commission's meeting on January 18, 2023, and the Expert and Practitioners' Meeting on Certification under the Next Generation Medical Infrastructure Act on February 6, 2023, in connection with the inappropriate acquisition of information in a certified project under the Next Generation Medical Infrastructure Act (hereinafter referred to as "this incident").
■Regarding the response
• Software bugs have been fixed. Additionally, patient medical information that was mistakenly transferred has been deleted.
We have explained this incident and measures to prevent recurrence to the medical institution, and we are carrying out the notification to the affected patients on their behalf.
We have sent a document ( here ) to eligible patients. If you have any questions, please contact our inquiry desk by phone or email.
We have explained this matter to our users and are asking for their cooperation in retrieving, deleting, and re-providing the anonymized or statistically processed data they have provided to us.
■ Measures to prevent recurrence
We have implemented a system to re-verify, immediately before importing medical information from medical institutions, etc., that the target data does not include data of unnotified patients or patients who have requested to opt out.
To prevent future software malfunctions, we have implemented improvements to our software development and operation processes.
We have reviewed our security management measures (measures against unauthorized access, data leaks, etc.) as a whole.
We have improved our rules to ensure that security incidents are quickly escalated to all relevant parties.
In light of this incident, we have reviewed our education and training policies, plans, and content, and have provided retraining to relevant personnel.
We deeply regret the inconvenience caused to everyone by this incident, and we will not only thoroughly implement measures to prevent recurrence, but also comply with all relevant laws and regulations, and continue to take necessary measures for all stakeholders, including patients, medical institutions, and data users, in order to regain your trust.
We sincerely apologize for the great concern and inconvenience caused to our patients, medical institutions, data users, and all other related parties.
Life Data Initiative Secretariat (General Incorporated Association)