Showing posts with label electronic medical records. Show all posts
Showing posts with label electronic medical records. Show all posts

Thursday, November 29, 2012

Cybernetik Über Alles Again: HHS and Sebelius - Hospitals And Their Computers Have More Rights Than Patients

A Nov. 29, 2012 New York Times article by Reed Abelson entitled "Medicare Is Faulted on Shift to Electronic Records" observes that:

The conversion to electronic medical records — a critical piece of the Obama administration’s plan for health care reform — is “vulnerable” to fraud and abuse because of the failure of Medicare officials to develop appropriate safeguards, according to a sharply critical report to be issued Thursday by federal investigators [the report from HHS OIG is here - ed.] ... Medicare, which is charged with managing the incentive program that encourages the adoption of electronic records, has failed to put in place adequate safeguards to ensure that information being provided by hospitals and doctors about their electronic records systems is accurate. To qualify for the incentive payments, doctors and hospitals must demonstrate that the systems lead to better patient care, meeting a so-called meaningful use standard by, for example, checking for harmful drug interactions. [I note that meeting EHR "meaningful use" standards does not necessarily signify better care; the "standards" are experimental - ed.]

Hospitals and doctors are lying about their EHR efforts, in order to gain incentive payments, it seems.

In an article "IG says program is 'vulnerable' to abuse, better oversight needed", Fred Schulte at the Center for Public Integrity notes:

... the Centers for Medicare and Medicaid Services has since paid out more than $3.6 billion to medical professionals who made the switch without verifying they are meeting the required quality goals, according to a new federal audit to be released today

Observes the CEO of the American Health Information Management Association:

“We’ve gone from the horse and buggy to the Model T, and we don’t know the rules of the road. Now we’ve had a big car pileup,” said Lynne Thomas Gordon, the chief executive of the American Health Information Management Association, a trade group in Chicago. 

More Horse and Buggy than Model T.  At least the Model T was reasonably dependable. 

Also mentioned is this:

House Republicans echoed these concerns in early October in a letter to Kathleen Sebelius, secretary of health and human services. Citing the Times article, they called for suspending the incentive program until concerns about standardization had been resolved. “The top House policy makers on health care are concerned that H.H.S. is squandering taxpayer dollars by asking little of providers in return for incentive payments,” said a statement issued at the same time by the Republicans, who are likely to seize on the latest inspector general report as further evidence of lax oversight. Republicans have said they will continue to monitor the program.

In her letter in response, which has not been made public, Ms. Sebelius dismissed the idea of suspending the incentive program, arguing that it “would be profoundly unfair to the hospitals and eligible professionals that have invested billions of dollars and devoted countless hours of work to purchase and install systems and educate staff.”


I was taught "first, do no harm."  Fairness to patients injured and killed by this technology in its present "Horse and Buggy" state (buggy being a particularly apropos term) seems not a matter of particularly high concern to HHS.   A suspension of incentives would slow the adoption rate down, necessary in order to "get the bugs" out of the technology before mass deployment and develop safety, validation and surveillance standards (currently non-existent), as I wrote in my Oct. 24, 2012 "Letter To U.S. Senators and Representatives Who've Sought HHS Input On EHR Problems."

This is despite the fact that FDA, IOM and others have indicated the level of harm is not known, due to systematic impediments to diffusion of that knowledge (see IOM statements in the midsection of my post on health information technology hyper-enthusiasm at this link, and an internal FDA memo on HIT safety at this link). 

HHS seems to care not about health and human services, or at best to be severely misguided.  "Cybernetik Über Alles" seems their current credo.

-- SS

Tuesday, June 5, 2012

Cart Before the Horse, Part 3: AHRQ's "Health IT Hazard Manager"

In a July 2010 post "Meaningful Use Final Rule: Have the Administration and ONC Put the Cart Before the Horse on Health IT?" and an Oct . 2010 post "Cart before the horse, again: IOM to study HIT patient safety for ONC; should HITECH be repealed?" I wrote about the postmodern "ready, fire, aim" approach to health IT:

In the first post, I wrote:

... These "usability" problems require long term solutions. There are no quick fix, plug and play solutions. Years of research are needed, and years of system migrations as well for existing installations.

Yet we now have an HHS Final Rule on "meaningful use" regarding experimental, unregulated medical devices the industry itself admits have major usability problems, along with a growing body of literature on the risks entailed.
For crying out loud, talk about putting the cart before the horse...

Something's very wrong here...

However, this situation is anything but humorous.

How more "cart before the horse" can government get?

In the second post, I wrote:

... So, in the midst of a National Program for Health IT in the United States (NPfIT in the U.S.), with tens of billions of dollars earmarked for health IT already (money we don't really have, but it can be printed quickly, or borrowed from China) the IOM is going to study health IT safety, prevention of health IT-related errors, etc. ... only now?

Here we go yet again.

The problem with the AHRQ (Agency for Healthcare Research and Quality, a division of HHS) announcement below of a webinar about a new tool for identifying, categorizing, and resolving health IT hazards, as I have written before, is putting the "cart before the horse" and throwing medical ethics to the wind.

If we've just developed a tool "for identifying, categorizing, and resolving health IT hazards", the magnitude of which others such as IOM admit are unknown to our detriment (e.g., Health IT and Patient Safety: Building Safer Systems for Better Care, pg. S-2), then health IT is, it follows, an experimental technology.

If it is an experimental technology, AHRQ and others in HHS should probably be raising the issue of a slow down or moratorium on widespread rollout under HITECH until risk management and remediation is better understood.  At the very least they should be calling for patient informed consent that a device that will largely regulate their care is experimental, that a competency "gap" exists among healthcare practitioners within the "health IT environment" (meaning patients are at risk), and that patients should be offered the opportunity for informed consent with opt-out provisions.  The principals should not just be announcing a webinar:

Sent: Tuesday, June 05, 2012 12:23 PM
To: OHITQUSERS@LIST.NIH.GOV
Subject: Register Now! AHRQ Health IT Webinar "Purpose and Demonstration of the Health IT Hazard Manager and Next Steps" June 11, 2:30 PM ET

Agency for Healthcare Research and Quality

Purpose and Demonstration of the Health IT Hazard Manager and Next Steps

June 11, 2012 — 2:30-4 p.m., EST

The Agency for Healthcare Research and Quality (AHRQ) has identified a gap in a health care/public health practitioner’s competency within the health IT environment. This webinar is designed to increase practitioners’ competencies in several areas: improving health care decision making; supporting patient-centered care; and enhancing the quality and safety of medication management by improving the ability to identify, categorize, and resolve health IT hazards.

The Webinar will explore the Health IT Hazard Manager—a tool for identifying, categorizing, and resolving health IT hazards. When implemented, the tool allows health care organizations and software vendors alike to learn about potential hazards and work to resolve them, including the use of data to communicate potential and actual adverse effects. The session will discuss how the Health IT Hazard Manager was tested and refined as well as strategies and implications for deploying it. The target audience includes AHRQ grantees/researchers; health care providers, including physicians and nurses; consumers/patients; and health care policymakers.

... Webinar learning objectives include:

1. Describe the rationale for developing the Health IT Hazard Manager and how it evolved through alpha and beta testing.
2. Explain the process for identifying and categorizing health IT-related hazards.
3. Demonstrate how the Health IT Hazard Manager would be used [i.e., it's not yet in use, despite mandates for HIT rollout with penalties for non-adopters - ed.] within and across care delivery organizations and health IT software vendors.
4. Discuss policy and process implications for deploying the Health IT Hazard Manager via different organizations (i.e., AHRQ; Office of the National Coordinator for Health IT; Patient Safety Organization(s); Accrediting bodies; IT entities).

In effect, HHS seems to be saying "we're working on the HIT risk problem, but roll it out anyway; if you get harmed or killed, tough luck."  This seems a form of negligence.

Have we thrown out all we know about medical research and human subjects protections in face of the magical powers and profits of computers in medicine?

-- SS

Sunday, June 3, 2012

WSJ "There's a Medical App for That—Or Not" - Misinformation on Health IT Safety Regulation?

There's a health IT meme that just won't die (patients may, but not the meme).

It's the meme that health IT "certification" is a certification of safety.

I expressed concern about the term "certification" being misunderstood even before the meme formally appeared, when the term was adopted by HHS with regard to evaluation of health IT for adherence to the "meaningful use" pre-flight features checklist.  See my mid-2009 post "CCHIT Has Company" where I observed:

HIT "certification." ... is a term I put in quotes since it really is "features qualification" at this point, not certification such as a physician receives after passing Specialty Boards.

The "features qualification" is an assurance that the EHR functions in way that could enable an eligible provider or eligible hospital to meet the Center for Medicare & Medicaid Services' (CMS) requirements of "Meaningful Use."  No rigorous safety testing in any meaningful sense is done, and no testing under real-world conditions is done at all.

I've seen the meme in various publications and venues.  I've even seen it in legal documents in medical malpractice cases where EHR's were involved, as an attempted defense.

Now the WSJ has fallen for the health IT Certification meme.

An article "There's a Medical App for That—Or Not" was published on May 29, 2012.  Its theme is special regulatory accommodation for health IT in the form of opposition to FDA regulation of devices such as "portable health records and programs that let doctors and patients keep track of data on iPads."

In the article, this assertion about health IT "certification" is made:

... The FDA's approach to health-information technology risks snuffing out activity at a critical frontier of health care. Poor, slow regulation would encourage programmers to move on, leaving health care to roil away for yet another generation, fragmented, disconnected and choking on paperwork.

The process already exists for safeguarding the public for computers in health care. It's not FDA premarket review but the health information technology certification program, established under President George W. Bush and still working fine under the Obama Health and Human Services Department. The government sets the standards and an independent nonprofit [ATCB, i.e., ONC Authorized Testing and Certification Bodies - ed.] ensures that apps meet those standards. It's a regulatory process as nimble as the breakout industry it's meant to monitor. That is where and how these apps should be regulated.

It's a wonderful meme.  Unfortunately, it's wrong.  Dead wrong.

Certification by an ATCB does not "safeguard the public."   Two ONC Authorized Testing and Certification Bodies (ATCB's) admitted this in email, as in my Feb. 2012 post "Hospitals and Doctors Use Health IT at Their Own Risk - Even if Certified".  I had asked them, point-blank:

"Is EHR certification by an ATCB a certification of EHR safety, effectiveness, and a legal indemnification, i.e., certifying freedom from liability for EHR use of clinical users or organizations? Or does it signify less than that?"

I received two replies from major ONC ATCB's indicating that "certification" is merely assurance that HIT meets a minimal set of "meaningful use" guidelines, not that it's been vetted for safety.  For instance:

From: Joani Hughes (Drummond Group)
Sent: Monday, March 05, 2012 1:06 PM
To: Scot Silverstein
Subject: RE: EHR certification question

Per our testing team:

It is less than that. It does not address indemnification although a certification could be used as a conditional part of some other form of indemnification function, such as a waiver or TOA, but that is ultimately out of the scope of the certification itself. Certification in this sense is an assurance that the EHR functions in way that could enable an eligible provider or eligible hospital to meet the CMS requirements of Meaningful Use Stage 1. Or to restate it more directly, CMS is expecting eligible providers or eligible hospitals to use their EHR in “meaningful way” quantified by various quantitative measure metrics and eligible providers or eligible hospitals can only be assured they can do this if they obtain a certified EHR technology.

Please let me know if you have any questions.

Thank you,
Joani.

Joani Hughes
Client Services Coordinator
Drummond Group Inc.

The other ATCB, ICSA Labs, stated that:

... Certification by an ATCB signifies that the product or system tested has the capabilities to meet specific criteria published by NIST and approved by the Office of the National Coordinator. In this case the criteria are designed to support providers and hospitals achieve "Meaningful Use." A subset of the criteria deal with the security and patient privacy capabilities of the system.

Here is a list of the specific criteria involved in our testing:
http://healthcare.nist.gov/use_testing/effective_requirements.html

In a nutshell, ONC-ATCB Certification deals with testing the capabilities of a system, some of them relate to patient safety, privacy and security functions (audit logging, encryption, emergency access, etc.).

What was suggested in the email below (freedom from liability for users of the system, etc.) would be out of scope for ONC-ATCB testing based on the given criteria. [I.e., certification criteria - ed.] I hope that helps to answer your question.

I had noted that:

... My question was certainly answered [by the ATCB responses]. ONC certification is not a safety validation, such as in a document from NASA on aerospace software safety certification, "Certification Processes for Safety-Critical and Mission-Critical Aerospace Software" (PDF) which specifies at pg. 6-7:
In order to meet most regulatory guidelines, developers must build a safety case as a means of documenting the safety justification of a system. The safety case is a record of all safety activities associated with a system throughout its life. Items contained in a safety case include the following:

• Description of the system/software
• Evidence of competence of personnel involved in development of safety-critical software and any
safety activity
• Specification of safety requirements
• Results of hazard and risk analysis
• Details of risk reduction techniques employed
• Results of design analysis showing that the system design meets all required safety targets
• Verification and validation strategy
• Results of all verification and validation activities
• Records of safety reviews
• Records of any incidents which occur throughout the life of the system
• Records of all changes to the system and justification of its continued safety

A CCHIT ATCB juror, a physician informatics specialist, has also done a guest post in Jan. 2012 on HC Renewal about the certification process, reproducing his testimony to HHS on the issue.  That post is "Interesting HIT Testimony to HHS Standards Committee, Jan. 11, 2011, by Dr. Monteith."  Dr. Monteith testified (emphases mine):

... I’m “pro-HIT.” For all intents and purposes, I haven’t handwritten a prescription since 1999.

That said and with all due respect to the capable people who have worked hard to try to improve health care through HIT, here’s my frank message:

ONC’s strategy has put the cart before the horse. HIT is not ready for widespread implementation. 

... ONC has promoted HIT as if there are clear evidence-based products and processes supporting widespread HIT implementation.

But what’s clear is that we are experimenting…with lives, privacy and careers.

... I have documented scores of error types with our certified EHR, and literally hundreds of EHR-generated errors, including consistently incorrect diagnoses, ambiguous eRxs, etc.

As a CCHIT Juror, I’ve seen an inadequate process. Don’t get me wrong, the problem is not CCHIT. The problem stems from MU.

EHRs are being certified even though they take 20 minutes to do a simple task that should take about 20 seconds to do in the field.  [Which can contribute to mistakes and "use error" - ed.] Certification is an “open book” test. How can so many do so poorly?

For example, our EHR is certified, even though it cannot generate eRxs from within the EHR, as required by MU.

To CCHIT’s credit, our EHR vendor did not pass certification. Sadly, our vendor went to another certification body, and now they’re certified.

MU does not address many important issues. Usability has received little more than lip-service. What about safety problems and reporting safety problems? What about computer generated alerts, almost all of which are known to be ignored or overridden (usually for good reason)?
 
The concept of “unintended consequences” comes to mind.

All that said, the problem really isn’t MU and its gross shortcomings, it is ONC trying to do the impossible:

ONC is trying to artificially force a cure for cancer, basically trying to promote one into being, when in fact we need to let one evolve through an evidence-based, disciplined process of scientific discovery and the marketplace.

Needless to say, as was learned at great cost in past decades, a "disciplined process" in medicine includes meaningful safety regulation by objective outside experts.

Further, the certifiers have no authority to do important things such as forcibly remove dangerous software from the market.  An example is the forced Class 1 recall of a defective system as I wrote about in my Dec. 2011 post "FDA Recalls Draeger Health IT Device Because This Product May Cause Serious Adverse Health Consequences, Including Death".   Class 1 recalls are the most serious type of recall and involve situations in which there is a reasonable probability that use of these products will cause serious adverse health consequences or death.

In that situation, the producer had been simply advising users (in critical care environments, no less) to "work around the defects" that could indicate incorrect recommended dosage values of critical meds, including a drug dosage up to ten times the indicated dosage, as well as corrupt critical cardiovascular monitoring data.  As I observed:

... I find a software company advising clinicians to make sure to "work around" blatant IT defects in "acute care environments" the height of arrogance and contempt for patient safety.

Without formal regulatory authority to take actions such as this FDA recall, "safeguarding the public" is a meaningless platitude.

It's also likely the ATCB's, which are private businesses, would not want the responsibility of "safeguarding the public."  That responsibility would open them up to litigation when patient injuries or death were caused, or were contributed to, by "certified" health IT.

I have in the past also noted that the use of the term "certification" might have been deliberate, to mislead potential buyers exactly into thinking that "certification" is akin to a UL certification of an electrical appliance for safety, or an FAA approval of a new aircraft's flight-worthiness.

The WSJ needs to clarify and/or retract its statement, as the statement is misinformation.

At my Feb. 2012 post "Health IT Ddulites and Disregard for the Rights of Others" I observed:

Ddulites [HIT hyper-enthusiasts - ed.] ... ignore the downsides (patient harms) of health IT.

This is despite being already aware of, or informed of patient harms, even by reputable sources such as FDA (Internal FDA memo on H-IT risks), The Joint Commission (Sentinel Events Alert on health IT), the NHS (Examples of potential harm presented by health software - Annex A starting at p. 38), and the ECRI Institute (Top ten healthcare technology risks), to name just a few.

In fact, the hyper-enthusiastic health IT technophiles will go out of their way to incorrectly dismiss risk management-valuable case reports as "anecdotes" not worthy of consideration (see "Anecdotes and medicine" essay at this link).

They will also make unsubstantiated, often hysterical-sounding claims that health IT systems are necessary to, or simply will "transform" (into what, exactly, is usually left a mystery) or even "revolutionize" medicine (whatever that means).

Health IT is a potentially dangerous technology.   It requires meaningful regulation to "safeguard the public."  How many incidents like this and this will it take before that is understood by the hyper-enthusiasts?

I've emailed the ATCB's that had responded to my aforementioned query for clarification on the WSJ assertion about their role, being that the statement is in contradiction to their earlier replies to me.  I also advised them of the potential liability issues.

However, if it turns out to be true that the ONC-ATCB's do intend themselves as the ultimate watchdog and assurer of public safety related to EHR's, that needs to be known by the public and their representatives.

-- SS

Saturday, April 28, 2012

Don't Worry, Your Records are Safe - Part IV

At past posts "Don't Worry, Your Electronic Medical Records Are Getting Safer With Every Passing Day", "Another Episode of "But Don't Worry, Your Records are Safe..." and "Still More Electronic Medical Data Chaos, Pandemonium, Bedlam, Tumult and Maelstrom: But Don't Worry, Your Data is Secure", I wrote on the issue of medical record security.

Security from prying eyes, that is.

I didn't include security of data from placement into /dev/null (that is, destruction).

There's this email, received by East coast physicians not long ago from a claims processing company (identities redacted):

Dear Provider,

As you may be aware, we experienced a significant problem with our computer system during a software maintenance function on XX/XX/2010.

In addition to the network issue, we discovered that the redundant back-up systems were not operating as reported.  ["Reported" when, and by whom, one wonders? - ed.]

We had two on-site back-up systems that were monitored daily and which were historically reported as successful.  We have since learned that these internal back-up functions were not operating as reported and the on-site back-ups were not entirely successful. [Meaning, they were not successful, period - ed.]

Also, our software vendor, [major EHR vendor], was providing two additional remote back-ups on servers located in [city, state] and [city, state]. [EHR vendor] has informed us that these remote back-ups were not initiated as represented.  [Meaning, they screwed up - ed.]  Therefore, when our computer network system malfunctioned, there was no readily available back-up data on-site or at the remote redundant back-up servers.

Please be aware that we have replaced hardware components and were able to recreate the data bases and we are billing.  However, we are still unable to access data that was stored on our servers prior to XX/XX/2010.

[EHR vendor] is diligently working to retrieve the data from the hard drives, back-up tapes, and through other means.  Please be assured that all files will be restored, if the files cannot be fully restored electronically, then they will be fully restored manually.

At [our claims processing company], we are truly saddened by the fact that we have disappointed clients and we sincerely apologize for any inconvenience experienced by you, your staff, or your patients.

We have always appreciated your loyalty as a valued client and will continue to keep you informed of the progress.

The levels of information technology and data management incompetence exhibited in this message are stunning. 

The confidence it imparts regarding the safety of our critical medical data from destruction, and its availability when truly needed, is less than stellar.

A major problem is that the health IT industry has no accountability. 

I believe the Food, Drug and Cosmetic Act needs to be amended to become the "Food, Drug, Cosmetic, and Cybernetic" Act.

-- SS

Tuesday, March 20, 2012

Human Subjects Experimentation Directives Ignored in the Grand Health IT Experiment?

The following represents some very inconvenient truths that have long been ignored.

Health IT is an experimental technology. The literature in 2012 remains conflicting on benefits and risks (the latter which is acknowledged, but whose magnitude is uncertain).

At NIH study sections, for example, research proposals that involve health IT (even modifications to existing applications) are subjected to far more scrutiny around human subjects protections, of both patients and investigators, than the typical wide-scale hospital implementation of enterprise health IT systems. The latter are validated and approved by - nobody.

How many of these directives are ignored in the Grand Health IT Experiment?

I've bolded the issues that I believe are ignored.

See "Reading list on health IT" for more information on conflicts in the literature:

---------------------------------------------

Directives for Human Experimentation

NUREMBERG CODE

  1. The voluntary consent of the human subject is absolutely essential. This means that the person involved should have legal capacity to give consent; should be so situated as to be able to exercise free power of choice [that is, to opt-out - ed.], without the intervention of any element of force, fraud, deceit, duress, over-reaching, or other ulterior form of constraint or coercion; and should have sufficient knowledge and comprehension of the elements of the subject matter involved as to enable him to make an understanding and enlightened decision. This latter element requires that before the acceptance of an affirmative decision by the experimental subject there should be made known to him the nature, duration, and purpose of the experiment; the method and means by which it is to be conducted; all inconveniences and hazards reasonable to be expected; and the effects upon his health or person [information on HIT risk exists, such as on this blog - ed.] which may possibly come from his participation in the experiment. The duty and responsibility for ascertaining the quality of the consent rests upon each individual who initiates, directs or engages in the experiment. It is a personal duty and responsibility which may not be delegated to another with impunity.
  2. The experiment should be such as to yield fruitful results for the good of society, unprocurable by other methods or means of study [such as small scale controlled clinical trials with full informed consent and opt-out provisions- ed.], and not random and unnecessary in nature.
  3. The experiment should be so designed and based on the results of animal experimentation and a knowledge of the natural history of the disease or other problem under study that the anticipated results will justify the performance of the experiment.
  4. The experiment should be so conducted as to avoid all unnecessary physical and mental suffering and injury.
  5. No experiment should be conducted where there is an a priori reason to believe that death or disabling injury will occur; except, perhaps, in those experiments where the experimental physicians also serve as subjects.
  6. The degree of risk to be taken should never exceed that determined by the humanitarian importance of the problem to be solved by the experiment. [The magnitude of HIT risks are unknown - ed.]
  7. Proper preparations should be made and adequate facilities provided to protect the experimental subject against even remote possibilities of injury, disability, or death.
  8. The experiment should be conducted only by scientifically qualified persons. [Yet the HIT field is filled with amateurs - ed.] The highest degree of skill and care should be required through all stages of the experiment of those who conduct or engage in the experiment.
  9. During the course of the experiment the human subject should be at liberty to bring the experiment to an end [go back to paper - ed.] if he has reached the physical or mental state where continuation of the experiment seems to him to be impossible.
  10. During the course of the experiment the scientist in charge must be prepared to terminate the experiment at any stage [go back to paper - ed.], if he has probable cause to believe, in the exercise of the good faith, superior skill and careful judgment required of him that a continuation of the experiment is likely to result in injury, disability, or death to the experimental subject.

Reprinted from Trials of War Criminals before the Nuremberg Military Tribunals under Control Council Law No. 10, Vol. 2, pp. 181-182.. Washington, D.C.: U.S. Government Printing Office, 1949.

I'd thought these issues were settled after WW2, but apparently not.

-- SS

Tuesday, December 20, 2011

Health Care Policy of the Insiders, by the Insiders, for the Insiders - the Newt Gingrich Case Files

Newt Gingrich's rise to the top of the pack of Republican contenders for the US presidency has earned him increased scrutiny.  The resulting investigative reporting has provided a revealing set of case studies showing how insiders have come to dominate US health care policy.

Below I have reorganized the information presented in a series of news articles from mid-November to mid-December, 2011.

Mr Gingrich's Consulting Empire

A general description of Mr Gingrich's health care "think tank" appeared in the Washington Post.(1)
A think tank founded by GOP presidential candidate Newt Gingrich collected at least $37 million over the past eight years from major health-care companies and industry groups, offering special access to the former House speaker and other perks, according to records and interviews.

The Center for Health Transformation, which opened in 2003, brought in dues of as much as $200,000 per year from insurers and other health-care firms, offering some of them 'access to Newt Gingrich' and 'direct Newt interaction,' according to promotional materials.

Despite its name, the CHT was for-profit. Much of its actual workings are confidential, per the Post,(1)
Susan Meyers, a center spokeswoman, declined to comment on the think tank’s income or staffing levels because it is a private-sector organization.

Despite its pretentious name, the CHT was apparently a vehicle for its wealthy corporate clients to influence health policy to favor their business interests.  A NY Times article(2) reported that:
His consultancy practice was centered around his ability to help big corporate interests speak the language of Republicans and navigate the corridors of Capitol Hill on issues vital to their businesses.

According to a Bloomberg article(3), the work was quite lucrative:
Two companies founded by Newt Gingrich announced yesterday that they had grossed $55 million between 2001 and 2010, part of an effort to quiet questions about how the former U.S. House speaker earned millions since he resigned from Congress in 1999.

That revenue supports the Center for Health Transformation and The Gingrich Group LLC, which have a staff of as many as 30 people, stage health-care policy events, and provide advice to clients, Nancy Desmond, the chairman and chief executive officer of the firms, said in a written statement.

The CHT was linked to a small corporate empire, as described by the Washington Post,(4)
Former House speaker Newt Gingrich transfigured himself from a political flameout into a thriving business conglomerate. The power of the Gingrich brand fueled a for-profit collection of enterprises that generated close to $100 million in revenue over the past decade, said his longtime attorney Randy Evans.

Among Gingrich’s moneymaking ventures: a health-care think tank financed by six-figure dues from corporations; a consulting business; a communications firm that handled his speeches of up to $60,000 a pop, media appearances and books; a historical documentary production company; a separate operation to administer the royalties for the historical fiction that Gingrich writes with two co-authors; even an in-house literary agency that has counted among its clients a presidential campaign rival, former senator Rick Santorum (R-Pa.).

Separate from all of that was his nonprofit political operation, American Solutions for Winning the Future.

Relationships with Big Health Care Corporations

The Center for Health Transformation was largely funded by big health care corporations. The Post first noted,(1)
The biggest funders, ... [included] firms such as AstraZeneca, Blue Cross Blue Shield and Novo Nordisk,...

Also,(1)
The center has listed scores of firms and industry groups as members over the years, amounting to a Who’s Who of the medical field, from GE Healthcare to the American Hospital Association to Wellpoint, the nation’s largest health insurer.

Other clients were listed in a Bloomberg article,(5)
Among the member companies were drugmaker Johnson & Johnson (JNJ) and health insurer Blue Cross and Blue Shield Association....

Also,(5)
Pfizer Inc. (PFE), the world’s largest drugmaker, had consulting contracts with Gingrich, according to two people familiar with the arrangements. Pfizer spokesman Ray Kerins didn’t respond to requests for comment.

The Pharmaceutical Research and Manufacturers of America, the industry’s trade group, was also a client. His firm 'was retained by the PhRMA general counsel’s office at one time to provide advice on a positioning project,' the group said.
In addition, as noted below, clients included important firms in the health care information technology (IT) sector, including GE, IBM, Microsoft, Allscripts, and Siemens.

Below, we present several cases in which Mr Gingrich apparently intervened on behalf of his clients to promote their business interests in the guise of promoting his views on health policy solutions.  In some cases, the views he promoted did not fit with what is generally regarded as his political philosophy, suggesting that the interests of his paying clients overrode his political views.

Case: End of Life Care

The New York Times reported,(2)
Writing on the Web site of the Washington Post, Mr Gingrich praised Gundersen Lutheran Health System of LaCrosse, Wis., for its successful efforts to persuade most patients to have 'advance directives,' saying if Medicare had followed Gundersen's lead on end-of-life care and other practices, it would 'save more than $33 billion a year.'

Note that
Gundersen was one of the paying clients of Mr. Gingrich's Center for Health Transformation....

However,
within weeks, Mr. Gingrich would find himself on the wrong end of what some Republicans labeled the 'death panel' issue.

At that point, Mr Gingrich abruptly changed his tune,
As it happens, shortly after Mr. Gingrich wrote his article praising Gundersen, he joined the conservative critics of the provision. 'You are asking us to trust turning power over to the government,' Mr Gingrich told George Stephanopoulos of ABC News that August 'when there are clearly people in America who believe in establishing euthanasia, including selective standards.'

This suggested that Mr Gingrich took up the cause of end-of-life decision making not be cause he deeply believed in it, but because it was expeditious given the wishes of his clients, despite the assertion made by his spokesperson,(2)
Mr. Hammond said that Mr. Gingrich did not take policy positions for pay; rather, he said, clients sought him out because of the views he already held and his expertise in communicating ideas.

Case: Medicare Prescription Coverage Sans Negotiations about Drug Prices

As reported by Bloomberg,(5)
When U.S. House Republican leaders in 2003 were short of votes to pass a $395 billion Medicare prescription drug benefit, they recruited former House Speaker Newt Gingrich for help.

In a hushed room on Capitol Hill, Gingrich told his former Republican colleagues that if he could endorse the measure, they should be comfortable with it, too, said two former senior House aides who attended the closed-door session.

Two days later, after a vote was held open for three hours as leaders corralled the final ayes, the measure passed and was eventually signed into law by President George W. Bush.

What Gingrich didn’t mention during the Republican caucus meeting was that he was also building a for-profit, health-care research company and seeking financing from drugmakers, which were investing $128.6 million in lobbying for passage of the new benefit for seniors.

Note that the legislation that provided Medicare drug coverage forbade the government from negotiating prices with drugmakers.  This was unprecedented, because drug coverage from the US Veterans Administration and Medicaid did not come with the obligation to pay whatever the drug-makers charged.  The inability of Medicare to negotiate the prices it paid for drugs certainly helped the companies' revenues while driving up the costs of Medicare, the federal deficit and the costs of health care in general.

Case: Promoting Expensive Diabetes Care

The Washington Post reported,(4)
Novo Nordisk, a Denmark-based drug firm that specializes in diabetes treatments.... paid a total of $1.2 million to Gingrich’s foundation over six years as a 'founding charter member.'

'It was strictly a business, nonpolitical relationship,' Novo Nordisk spokesman Ken Inchausti said. 'We admired his leadership on issues related to health-care delivery systems. We thought the CHT brought something to the table to us in terms of finding ways to help people prevent diabetes.'

Gingrich loaned his celebrity to causes that, whatever their other merits, could also be good for Novo Nordisk’s bottom line. For instance, he was the keynote speaker at Novo Nordisk’s 'diabetes summit' in 2005 and joined the company in issuing a 'call to action' to fight diabetes in Texas and Georgia.
One wonders how many of the widely promoted "summits" and other star-studded conferences on health care featuring corporate  and political leaders as speakers are just stealth health policy advocacy or stealth marketing.

Case: Irrational Exuberance for Electronic Health Records

My fellow Health Care Renewal blogger has often discussed the "irrational exuberance" for electronic health records (EHRs) despite scant information about their benefits, and increasing data suggesting their harms.  It now appears that Mr Gingrich, sponsored by copious funds from the health care IT sector, has been a major source of such exuberance. 

Mr Gingrich had a complex relationship with the health care information technology (IT) industry. It began to come out first in a NY Times story,(6)
When the center [for Health Transformation] sponsored a 'health transformation summit' at the Florida State Capitol in March 2006, lawmakers who attended Mr. Gingrich's keynote speech inside the House chamber received a booklet promoting not just ideas but also the specific services of two dozen of his clients. Executives from some of those companies sat on panels for discussions that lawmakers were encouraged to attend after Mr. Gingrich's address.

Gerard White, president of Clearwave, which paid about $50,000 to become a center member, used the occasion to pitch his company's system for managing patient data.

This had all began earlier,
Two years before the Florida 'summit,' Mr. Gingrich made a presentation to Republican lawmakers in Georgia, promoting the work of his member companies by citing specific benefits if they were hired. For example, 'VitalSpring could save the State Employee Program over $20 million a year.'

Minutes of the members-only conference call from March 2004 said the center had 'arranged joint meetings' for members to present their work on electronic health records to top federal officials, noting that Mr. Gingrich 'reported very positive feedback overall from these meetings.'

He also pressed for passage of a federal bill to increase the use of electronic health records, collaborating with one of its co-sponsors, Representative Patrick J. Kennedy of Rhode Island, and Senator Hillary Rodham Clinton of New York, both Democrats.

Furthermore,
Many of the ideas he has pushed involve the increased use of information technology, and companies specializing in that are well represented in the center's roster. They also figured prominently in an early center initiative, teaming up in 2003 with the conservative Georgia Public Policy Foundation to promote changes in health care in Mr. Gingrich's home state.

At his discussion with Georgia House Republicans in 2004, Mr. Gingrich gave examples of companies whose services could 'both improve health and start saving money,' according to the center's summary of his presentation.

And there is more,
In Washington, Mr. Gingrich's push for electronic health records illustrated how his own policy advocacy and ties to former Congressional colleagues made him a sought-out consultant for companies like Astra Zeneca and Siemens. Mr. Gingrich hailed HealthTrio, one of the center's 'founding charter members,' during a hearing held in 2003 by Senator Larry Craig, Republican of Ohio. Telling the senator that HealthTrio's chief executive had helped design the electronic records program in the United Kingdon, Mr. Gingrich said the company 'estimates we could have an electronic health record for American for about 10 cents per month, per person.'

The center later arranged for HealthTrio and I.B.M to meet with senior federal health officials and congressional leaders 'to review the U.K. approach and how it might be applied in the U.S.,' according to center records.

Some of the ideas promoted by the center found their way into the electronic health records legislation proposed by Mr. Kennedy, which was prepared with input from Mr. Gingrich.
This is especially ironic, given that the UK NHS electronic health record initiative has become a crashing failure (for example, see this post).

Even more involvement with the push for electronic health records (EHRs) appeared in a Boston Globe article,(7)
Newt Gingrich seized the TV airwaves in 2009 to bash President Obama’s stimulus package, calling it 'entirely a pork-barrel bill' that would do little to solve the recession.

Later, in a separate web video, the former House speaker stepped back from his blanket criticism. He explained that he strongly supported spending $27 billion of stimulus funds to encourage doctors and hospitals to create electronic medical records for their patients. Left unsaid was that the Gingrich Group, his consulting business in Washington, received large payments from medical technology companies that stand to profit from the federal money.

In particular,
The stimulus infusion Gingrich supported is expected to benefit health care technology companies, including those who have been clients such as GE Healthcare and Allscripts.

GE Healthcare said it pays Gingrich’s center to act as a 'collaborator and facilitator' among a diverse group of health care interests.

'We work with the Center for Health Transformation in an effort to improve the effectiveness of the health system through the use of information technology,' said GE Healthcare spokesman Corey Miller.

Allscripts spokeswoman Ariana Nikitas said the company ended its relationship with Gingrich’s center two years ago but considered the venture 'a think-tank to advance health care efforts.'

It does not stop there. Per the NY Times,(8)
Mr. Gingrich was cheering a $19 billion part of the [Obama stimulus] package that promoted the use of electronic health records, something that benefited clients of his consulting business. 'I am delighted that President Obama has picked this as a key part of the stimulus package,' he told health care executives in a January 2009 conference call.

After the bill was passed a month later, Mr. Gingrich's consultancy, the Center for Health Transformation, joined two of his clients, Allscripts and Microsoft, in an 'Electronic Health Records Stimulus Tour' that traveled the country, encouraging doctors and hospitals to buy their products with billions in federal subsidies.
We, particularly InformaticsMD, have frequently commented on how health care information technology has been promoted not just by enthusiasts in the field, and by companies that manufacture such devices, but by the government.  The bandwagon has gone down the road despite little clinical evidence that such technology is beneficial, and increasing evidence of its harms.  Now it appears that an important reason for this ruch to promote expensive, but unproven devices comes from the sort of stealth health care policy advocacy on behalf of corporate vested interests described above.
Summary

So Newt Gingrich parlayed his political track record into a lucrative "consultancy" which enthusiastically promoted the health policy objectives of its clients, who included some of the biggest US health care corporations.  Some of the policy positions the consultancy promoted seemed to run counter to Mr Gingrich's political record.  Worse, some of the initiative he successfully promoted seem to have contributed to US health care dysfunction.

These stories, some of which are many years old, only came out after Mr Gingrich became the front runner for the Republican nomination for US President.  Had he not chosen to re-enter politics, it is not clear when reporters would have had time to due the required investigations.  One wonders how many similar stories have not been made public because they do not involve prominent presidential candidates.

The bottom line seems to be that there are myriad ways corporate and political insiders push health policy agendas because of self-interest, regardless of their effects on patients' and the public's health.  Health policy in the US has become an insiders' game.  Unless it is redirected to reflect patients' and the public's health, facilitated by the knowledge of unbiased clinical and policy experts rather than corporate public relations, expect our efforts at health care reform to just increase health care dysfunction. 

Physicians, public health advocates, whatever unbiased health policy experts remain must educate the public about how health policy has been turned into a corporate sandbox.  We must try to somehow activate the public to call for health care policy of the people, by the people, and for the people.

References


1.  Eggen D. Gingrich think tank collected millions from health-care industry.  Washington Post.  November 17, 2011.  Link here.
2. Rutenberg J. Gingrich faces more scrutiny over corporate clients. NY Times, November, 17, 2011. Link here.
3. Benson C, Lerer L. Gingrich health center and group paid $55M. Bloomberg, November 22, 2011. Link here.
4. Tumulty K, Eggen D. Newt Gingrich Inc.: how the GOP hopeful went from political flameout to fortune. Washington Post, November 26, 2011. Link here.
5. Davis JH, Jensen K. Gingrich campaigning as change agent profited as an insider. Bloomberg, November 18, 2011. Link here.
6. McIntire M, Rutenberg J. Gingrich gave push to clients, not just ideas. NY Times, November 29, 2011. Link here.
7. Rowland C. Newt Gingrich supported $27 billion of President Obama's stimulus for electronic medical records, helping his consulting clients. Boston Globe, December 16, 2011. Link here.
8. Rutenberg J, McIntire M. Gingrich push on health care appears at odds with G.O.P. NY Times, December 16, 2011. Link here.

Saturday, December 17, 2011

As U.S. Presidential Campaign Ramps Up, Newt Gingrich Plays Down Support for Health IT

Presidential candidate Newt Gingrich, who I recall hearing in person as an an invited speaker at a health IT meeting some years ago (AMIA, I believe), has been pushing health IT rather uncritically in recent years.

However, he seems to have backed off that position at the election cycle heats up:

As Campaign Ramps Up, Gingrich Plays Down Support for Health IT

iHealthbeat.org

Friday, December 16, 2011

Now that he is a frontrunner in the race for the Republican presidential nomination, former House Speaker Newt Gingrich (R-Ga.) is downplaying his previous support for health IT adoption, The Hill's "Healthwatch" reports (Pecquet, "Healthwatch," The Hill, 12/15).

History of Supporting Health IT

During the George W. Bush administration, Gingrich worked with former CMS administrator Mark McClellan and former National Coordinator for Health IT David Brailer on federal efforts to promote health IT, according to the New York Times (Rutenberg/McIntire, New York Times, 12/16).

Gingrich also worked with former Senate Majority Leader Tom Daschle (D-S.D.) to co-author the forward of a book titled, "Paper Kills 2.0," which gives examples of how federal funds for health IT could be used in pilot projects to improve health care (Rowland, Boston Globe, 12/16).

Shortly before the passage of the 2009 federal economic stimulus package, Gingrich criticized the legislation as a "big politician, big bureaucracy, pork-laden bill." However, at the same time, Gingrich praised a provision of the stimulus package that allocated $19 billion to promote the use of health IT. He said, "I am delighted that President Obama has picked this as a key part of the stimulus package."

His views have apparently changed somewhat:

... Campaign Plays Down Health IT Support

On Wednesday, Gingrich unveiled a new brain science initiative that does not include any mention of EHRs, even though the technology was a major component of the brain science proposals he discussed over the summer.


Politics aside (it is probably not too far from the truth to say that all politicians hold out their fingers to see what direction the wind is blowing, although Mr. Gingrich is probably becoming more aware of HIT downsides thanks to lobbying of both sides of the aisle by people such as myself and like-minded experts [1]), I cannot disagree with this:

In August, Gingrich said he aimed to bolster brain science research in part by modernizing FDA through the use of EHRs. Gingrich said EHRs would allow for "much faster [FDA] approval times because you can monitor in real time everyone who uses the drug. And if you start getting inappropriate responses, you can change within weeks" ("Healthwatch," The Hill, 12/15).


In fact, I was championing exactly this idea ca. 2001 when I was employed at Merck Research Labs in the Research Information Systems division. Unfortunately, the answer from more senior personnel was that doing so would be "impossible" due to inability to blind, to control the data quality, etc., responses I considered unreasonable at the time but did not argue with to avoid getting on the Short List early in my employment there.

I also tried to present the idea to Merck as a former employee in Nov. 2006, at an invited presentation to the Clinical Risk Management & Safety Surveillance department of MRL entitled “Medical Informatics Perspectives on Leveraging the EMR in Pharma" (PPT). Also see my 2007 paper "A Medical Informatics Grand Challenge: the EMR and Post-Marketing Drug Surveillance" where I address a number of issues related to using EHR's in this fashion (PDF).

Using EHR's (e.g., with special screens and training) for well-defined Phase IV post-marketing surveillance studies would be one of the best uses for the technology [2].

Finally, I note that we need post-marketing surveillance of EHR's, CPOE's and other clinical IT systems themselves, not just drugs. Information technology cannot improve healthcare until it itself is improved significantly regarding its current deficiencies (see "reading list" here for illustrations).

-- SS

Notes:

[1] Health IT risks are a non-partisan issue.


[2] I should note that while I believe EHR's could facilitate postmarketing surveillance of drugs and devices, I take a dim view of more grandiose proposed uses of EMR's such as for comparative effectiveness research (CER). See my essay in the Journal of the American Association of Physicians and Surgeons (AAPS) entitled "The Syndrome of Inappropriate Overconfidence in Computing: An Invasion of Medicine by the Information Technology Industry?" here (PDF).


Thursday, January 7, 2010

Two New Challenges to a Healthcare Cybernetic Utopia: Yet More Hurdles Exposed

At "2009: a Pivotal Year in Healthcare IT" I concluded that 2009 had proven to be a critical year in HIT, due to authoritative publications on HIT difficulties and related issues that appeared that year.

It was good to see the critical thought processes and the scientific methods inherent in modern medicine applied to the irrational exuberance and marketing-dominated field of healthcare IT.

It seems in 2010 the trend may continue.

Two new very interesting publications have recently come to my attention regarding the complications that can, and are, introduced by HIT.

These complications are worsened by the "boatload of cash," as one author expressed it, that is helping fuel what I term an irrational exuberance, or purchased exuberance, in this technology and its use in social re-engineering in medicine.

-----------------------

The first publication of note is a newsletter "Medical Risk Management Advisor" from ProAssurance Indemnity Company, Inc. and affiliates, a provider of medical insurance for clinicians. It can be downloaded here (PDF). It advises:

On choosing an EHR system:

Be sure to obtain physician input and review of the software prior to purchase to ensure it meets the needs of your practice. Consider talking to other medical practices already using the software, not only to assist in your decision, but to anticipate flaws or errors existing users may have encountered. Lastly, establish a process to address problems discovered after implementation.

"Anticipating flaws or errors existing users may have encountered" seems to be at odds with nondisclosure clauses in heathcare IT contracts, but this insurer seems to have gotten the message that HIT is not a perfected technology by a long shot.

On Alert fatigue:

Physicians may ignore e-prescribing alerts for a variety of reasons (e.g., excessive alerts or alerts that are not clinically useful). Again, input from physicians prior to implementation can help prioritize and choose alerts appropriate to the practice.

That the advice has to be given by an insurance company to healthcare organizations that "input from physicians prior to implementation" is crucial reflects a pathology, whose root is within the paternalistic and patronizing IT culture.

This culture and occupation has invaded medicine and supplied endless predictions of utopia for at least the past thirty years, in a domain it generally understands at the level of a layperson.

On "additional features" creating risk: [HIT incurs risk? How can the tool touted to revolutionize medicine incur risk? - ed.]

For example, some software programs require a diagnosis listed with each prescription. Consider the following: a patient is on Depakote for bipolar and seizure disorders, but the e-prescribing system only notes bipolar disorder because of its one-diagnosis limitation by design.

Subsequently, the patient becomes manic and the on-call psychiatrist starts the patient on lithium for the bipolar disorder. Checking the e-prescribing system, he notes Depakote was prescribed for bipolar disorder so he titrates the Depakote to discontinuation.

The patient has a seizure during the titration which leads to death.

The on-call psychiatrist assumed the patient was on Depakote solely for bipolar disorder and not seizures. If the diagnosis feature had been more extensive or had not been used with the software, the on-call psychiatrist might have explored further before discontinuing the Depakote.

Again, input from physicians prior to implementation may help prevent potential risks.

(According to Socky the Meditech Sockpuppet, such events are impossible.)

On Interoperability:

Another issue is whether your e-prescribing system fully integrates with pharmacy systems. Using the previous example, what if the diagnosis was changed in the psychiatrists’ system, but the pharmacy system did not automatically update this information? Be sure to investigate the compatibility of your system with others in your area. Not all pharmacies have e-prescribing capabilities. Many rural areas do not have the broadband internet access required.

It is unfortunate that the HIT vendor community is based on a business-computing model. That culture is extremely territorial. Seamless interoperability will be a long time in coming in HIT.

On Medication Reconciliation:

Physicians and pharmacies may find it difficult to trust the completeness and currency of the medication history and reconciliation, since medication histories often derive from multiple sources. Continue to verify medication histories with patients, and update records accordingly.

What? Actually not rely on the computer? What kind of extremist anti-health IT Luddite advice is this insurer proffering?

On Indemnity or "Hold Harmless" agreements:

Finally, be cautious about entering into hold harmless agreements with software vendors. Your ProAssurance policy excludes from coverage liability assumed under any contract or agreement, unless the liability would be imposed by law in the absence of the contract or agreement. It covers only the insured’s professional liability and not the liability of another party that the insured may assume through an indemnity agreement. If you are asked to sign such an agreement, you should have your attorney carefully review the agreement and your insurance policy.

I did not think of this issue when I wrote my July 2009 JAMA letter to the editor and a fuller posting on this issue at my Drexel HIT difficulties website here.

In addition to violating their fiduciary responsibilities and Joint Commission Safety Standard obligations, hospital executives signing nondisclosure and hold harmless agreements may be putting their organizations under undue financial risk if a HIT-related catastrophe occurs.

-----------------------

The second publication of note is an article from the IEEE (Institute of Electrical and Electronics Engineers). A Jan. 6, 2010 IEEE Spectrum article entitled "More Hurdles Appear in U.S. Electronic Health Record Adoption" has been published. I would actually have entitled it "More Hurdles Exposed in U.S. EHR Adoption", but that's not important now.

What is important, once again, is the Management Information Systems (business computing) approach to healthcare IT. The typical convoluted licensing arrangements for this software (really a virtual clinical tool that happens to reside on a computer) has created this fine mess:

The first was a story from a few months back that [the IEEE author] ran across recently from the Washington State Spokesman-Review about Inland Northwest Health Services suing the owner of Deaconess Medical Center, which the paper said alleged breach of "contracts and bad faith dealings that imperil the region's acclaimed electronic medical records network.

It is a bit complicated, but in essence, in 1994, Spokane's Deaconess Medical Center, Providence Holy Family Hospital, Providence Sacred Heart Medical Center & Children's Hospital and Valley Hospital & Medical Center established the non-profit Inland Northwest Health Services (INHS) as a way to merge competing lines of business and to oversee them. One of the things INHS did was to invest in electronic medical records using MEDITECH's technology. [You mean this Meditech? - ed.]

Apparently, Community Health Systems, a Tennessee company that bought Spokane's Deaconess Medical Center and Valley Hospital & Medical Center in 2007 decided that it was going to start charging INHS $150,000 a month to use the MEDITECH license, claiming that Deaconess Medical Center was owner of the license. INHS says that Deaconess transferred ownership to it years ago.

The Spokesman says some 38 hospitals along with many private practices and clinics are affected by the dispute.

The upshot of all this is that license ownership of the underlying EHR technology will likely be a big issue in the future as more regional health information networks are started, as will be technology lock-in (INHS has been using MEDITECH technology for 13-years, and it moving to another EHR is unlikely to be an easy or inexpensive proposition). Neither issue has appeared much in the EHR literature.


Yes, indeed, except once again I would have written:

The upshot of all this is that license ownership of the underlying EHR technology will likely be a big disaster in the future...

... as the HIT vendors will likely only allow their profitable licensing practices to be pried from their cold, dead fingers (metaphorically speaking, of course).

Then, this on EHR patient data trafficking:

... there was also a story in the American Medical News in late November about the Cleveland Clinic giving $1 million to a start-up company called Explorys to "commercializing the patient database search system Cleveland Clinic developed." The Cleveland Clinic has a very extensive EHR system and data base of patient information that it now wishes to exploit.

As I mentioned last month, there was a report by PricewaterhouseCoopers LLP that found 76% of healthcare executives surveyed felt that all the data being collected in their EHR systems was going to be their organization's greatest asset over the next five years. It also found that the executives only felt they could recoup their investments if they could exploit that information in some way.


The IEEE author largely addresses health IT failure as an impediment to such EHR patient data trafficking. In my Oct. 2009 post "Health IT Vendors Trafficking in Patient Data?" I came at the issue from an ethical and legal angle. I wrote:

This practice [trafficking in EHR patient data] raises numerous questions:

  • Meaningful informed consent issues: as an example, of 1000 patients at one of the facilities using this vendor's HIT products, what percentage would be able to tell me they know their data is being trafficked to pharmaceutical companies and other organizations for profit?
  • Healthcare data ownership and stewardship issues: who, exactly, extracts the data for aggregation and sale? Hospital employees properly trained and bonded (i.e., Healthcare Information Management professionals) regarding privacy of patient data? IT personnel lacking such credentials and experience? HIT vendor employees?
  • De-identification issues: what processes are being used to de-identify data? Who is performing it? At some point before the data is de-identified, it is protected information in identifiable form. Is access to the data during de-identification audited in any way, and if so, by whom? If not, why not? (Also see article on re-identification below.)
  • Legal issues: who is, by contract, liable for data breaches that occur in the transfer process?
  • Pharma integrity issues: with the many stories on this blog and others about ethically questionable pharma practices such as ghostwriting, manipulation of clinical research, suppression of research, pushing drugs on physicians and patients for unapproved off-label uses, etc., what are these organizations going to do with the data? Who will have access to it, and will their access be audited? Are they going to resell it? Might they try to re-identify data to locate individuals of interest? And so forth.

Serious consideration of these issues in vendor-led healthcare data trafficking becomes more imperative in the face of just how easy it is to "re-identify" data:

Ohm, Paul: "Broken Promises of Privacy: Responding to the Surprising Failure of Anonymization" (August 13, 2009). University of Colorado Law Legal Studies Research Paper No. 09-12. Available at SSRN: http://ssrn.com/abstract=1450006

In Dec. 2007 I'd also presented to the IEEE Medical Technology Policy Committee on some of these issues in "To the Moon in a Hot Air Balloon: Why is Clinical IT Difficult?". In response, they introduced me to the term "resilience engineering" in the sense that healthcare IT was lacking in that particular characteristic:

The term Resilience Engineering represents a new way of thinking about safety. Whereas conventional risk management approaches are based on hindsight and emphasise error tabulation and calculation of failure probabilities, Resilience Engineering looks for ways to enhance the ability of organisations to create processes that are robust yet flexible, to monitor and revise risk models, and to use resources proactively in the face of disruptions or ongoing production and economic pressures.


Health IT as a cybernetic miracle? As I've stated before, healthcare is a harsh environment for cybernetics, talent to accomplish the needed IT and medical culture changes essential to successful computerization in medicine is grossly mismanaged by the HIT and hospital industries, and reality is a harsh mistress.

-- SS

Sunday, October 25, 2009

Clinic's medical files vanish

At "Data Malpractice on T-Mobile Sidekick: But Don't Worry, Your Medical Data is Safe", on Oct. 16 I wrote:

One of the promises made about healthcare IT is that your medical data is "safer" in electronic form than in paper form. The Hurricane Katrina example of paper records being destroyed is often used as a poster example of the dangers of paper records.

However, the risk of electronic storage of information, especially the talk of national EMR's stored on the "cloud" (an amorphous term meaning distributed storage "out there" whose physical sites and boundaries are supposedly irrelevant from the user's perspective) has also been under-reported.

Personal customer data had been "lost" from many of T-Mobile USA's Sidekick devices due to a computer malfunction, although the data was apparently recovered eventually, apparently through luck rather than good engineering.

I expressed concern that such mishaps could affect clinical IT. I did not have to wait long for such a case to appear. Less than one week.

Below is a story of a Canadian clinic that lost two years of electronic health records:

Clinic's medical files vanish

By Ryan Cormier, Edmonton Journal

October 21, 2009

During a recent investigation into whether a patient's confidentiality had been breached at the Fairview Medical Clinic, an investigator asked for a log of who had accessed the complainant's file. When the clinic responded that it had automated his records in 2004 but only had files from 2006 on, alarm bells rang.

"That raised a lot of questions," said Leahann McElveen, an investigator with the office of the information and privacy commissioner.

The clinic had permanently lost two years worth of health files that include patient information on visits, prescriptions, lab reports, doctor's notes and other information. The loss happened when the clinic switched from one electronic medical records system to another.

"They were two similar systems intended to do the same thing," McElveen said. "However, they weren't coded the same way behind the scenes. It's not that the records fall into the wrong hands, they just don't exist anymore."


*POOF*.

Deinstallation of one system in favor of another is not uncommon. EHR data may become unavailable due to lack of data portability and the expense of data migration, or in this case apparently due to preventable technical problems.

It is essential for clinical IT users to have robust disaster recovery and business continuity solutions, and take great care when performing actions that can lose large amounts of data very fast. This adds to clinical IT cost, and a concern is that some users might skimp on these capabilities.

This must be discouraged.

(To the reader: do you back up your own PC or Mac reliably?)

-- SS

Tuesday, October 20, 2009

Private medical records offered for sale

Private medical records have been offered for sale in the U.K.

And quite cheaply, too...

e-Health Insider (Europe)
Private Medical Records Offered for Sale
Oct. 20, 2009

Medical records of patients treated at a private British hospital, The London Clinic, have been illegally sold to undercover investigators.

The revelations were made in ITV’s Tonight Programme report, Health Records For Sale, broadcast last night.

The programme reported that hundreds of files containing details of patients’ conditions, home addresses and dates of birth were offered to undercover reporters for just £4 each by sales executives from India, contacted online.


That's about $6.56 U.S. each. A genuine bargain for those intrepid medical identity thieves, and pesky government death panels ...


The records offered for sale appear to have been medical records that consultants working at the London Clinic, the hospital processes its own records internally, who contracted with a firm called DGL (DGL) Information Technologies UK to digitise their records.

DGL is then claimed to have sub-contracted to another firm, Scanning and Data Solutions (SDS), which scanned them into computers in the UK. SDS in turn is said to have sub-contracted further work on the files to a company in Pune, India, which had signed tight confidentiality agreements.


With all this contracting and subcontracting - four layers? - adding potential security breach possibilities, and if this is not an uncommon practice, perhaps paper is safer than electronic health records?


... The reporters bought more than 100 records belonging to UK patients but were told they could obtain up to 30,000 more on demand. Confidential records were offered by condition such as particular cancers.

Of 116 files bought by ITV, 100 of which were confirmed as genuine, were for patients who had been treated in private hospitals. Although not NHS records they did contain some NHS data, including referral letters from GPs.


The potential abuses resulting from such sales are of great concern. If it happened in the UK, it can happen in the U.S.


One patient whose record was affected by the security breach said in the documentary that the data breach was ‘one step up from grave-robbing’.


I agree with that assessment.

These practices call for the most severe penalties, and if the authorities lack the will, confidence in EMR privacy, confidentiality and security will suffer, along with the physician-patient relationship.

The old ST:TOS line "Sometimes a man will tell his bartender things he'll never tell his doctor" could become too applicable for comfort.


Sometimes a man will tell his bartender things he'll never tell his doctor ... especially if they suspect their data is for sale to the Talosians, Captain ...

-- SS

Friday, October 16, 2009

Data Malpractice on T-Mobile Sidekick: But Don't Worry, Your Medical Data is Safe

One of the promises made about healthcare IT is that your medical data is "safer" in electronic form than in paper form. The Hurricane Katrina example of paper records being destroyed is often used as a poster example of the dangers of paper records.

However, the risk of electronic storage of information, especially the talk of national EMR's stored on the "cloud" (an amorphous term meaning distributed storage "out there" whose physical sites and boundaries are supposedly irrelevant from the user's perspective) has also been under-reported. Excluding frequent reports of data confidentiality breaches, we also have this:

Wall Street Journal, Oct. 15, 2009
Microsoft Recovers Lost Sidekick Data
By ROGER CHENG

Microsoft Corp. said Thursday that it has been able to recover the personal customer data lost from many of T-Mobile USA's Sidekick devices.

The Redmond, Wash., software giant said that most, if not all, customer data was recovered, and that the company would begin restoring data as soon as it has validated it. The company said it will start with personal contacts, and move on to the lost calendar, notes, tasks and pictures as quickly as possible.

The fix comes as Microsoft suffers through a public backlash after mishandling the information found on the Sidekick line of messaging phones, which are popular with teenagers ... Over the weekend, T-Mobile and Microsoft initially warned that the recovery of data would be unlikely, but upgraded their prospects on Tuesday.

They got lucky.

Microsoft blamed a system failure [i.e., an IT system - ed.] for the data loss in the core database and backup system. Microsoft said it had taken steps to strengthen the stability of the Sidekick service and started a more resilient backup process. [More resilient compared to ... what? - ed.]

In IT it's always an apersonal "system failure", not "data malpractice." When medical malpractice occurs, it's the doctor's fault, even if that malpractice occurred secondary to the failure or misdesign of an EMR or other clinical IT by dyscompetent software engineers. When data malpractice occurs, the motto is "We always blame the computer." How about some names of those responsible for this debacle?

... The Sidekick service, run by Microsoft unit Danger [talk about ironic names - ed.], is supposed to be more secure in storing data because it is kept in the "cloud," which involves storing information on the Internet and not one physically vulnerable location, making the temporary loss of data striking.

"Cloud" is a new buzzword du jour to make more appealing a basically bad idea for many fields. Distributing data also distributes risk that some incompetent or careless person or person(s) will cause data corruption or loss (yes, computers are run by people, and either they're in control of their systems, or their systems are in control of them). It also puts organizations storing data on the "internet cloud" at risk of being victims of a network "rainy day" when internet connections might prove unreliable (accidents, sabotage, natural disasters all come to mind).

In healthcare, using the "cloud" for data storage seems to be a bad idea, especially in an era of $99 (retail) terabyte hard drive storage, and corresponding economies in mission critical-grade local mass storage, backup, business continuity and disaster recovery capabilities.

In summary, is electronic medical data more secure when stored electronically than on paper? Only if the underlying CIO's, information stewards, technicians and system administrators are at least as competent and careful as the trained health information management (HIM) personnel in hospital medical records departments and doctors' offices.

Time will tell if that is the case. One mistake, and thousands or millions of records can go *POOF*.

Microsoft and T-Mobile were lucky ... this time.

-- SS

10/26 addendum:

Sometimes, EHR data simply disappears too. At this link is a story of a Canadian clinic that lost two years of electronic health records:


Clinic's medical files vanish

By Ryan Cormier, Edmonton Journal

October 21, 2009

During a recent investigation into whether a patient's confidentiality had been breached at the Fairview Medical Clinic, an investigator asked for a log of who had accessed the complainant's file. When the clinic responded that it had automated his records in 2004 but only had files from 2006 on, alarm bells rang.

"That raised a lot of questions," said Leahann McElveen, an investigator with the office of the information and privacy commissioner.

The clinic had permanently lost two years worth of health files that include patient information on visits, prescriptions, lab reports, doctor's notes and other information. The loss happened when the clinic switched from one electronic medical records system to another.

"They were two similar systems intended to do the same thing," McElveen said. "However, they weren't coded the same way behind the scenes. It's not that the records fall into the wrong hands, they just don't exist anymore."


*POOF* again.

-- SS