Showing posts with label healthcare IT safety. Show all posts
Showing posts with label healthcare IT safety. Show all posts

Tuesday, January 15, 2013

New York Times: "In Second Look, Few Savings From Digital Health Records", and AMA Med News on EHR Harms

This post should perhaps be entitled "I told you so."

A letter I wrote in response to the Wall Street Journal's "A Health-Tech Monopoly", Feb. 11, 2009 was published Feb. 18, 2009 under the header Digitizing Medical Records May Help, but It's Complex.

I wrote:

Dear Wall Street Journal,

You observe that the true political goal is socialized medicine facilitated by health care information technology. You note that the public is being deceived, as the rules behind this takeover were stealthily inserted in the stimulus bill.

I have a different view on who is deceiving whom. In fact, it is the government that has been deceived by the HIT industry and its pundits. Stated directly, the administration is deluded about the true difficulty of making large-scale health IT work. The beneficiaries will largely be the IT industry and IT management consultants.

For £12.7 billion the U.K., which already has socialized medicine, still does not have a working national HIT system, but instead has a major IT quagmire, some of it caused by U.S. HIT vendors.

HIT (with a few exceptions) is largely a disaster. I'm far more concerned about a mega-expensive IT misadventure than an IT-empowered takeover of medicine.

The stimulus bill, to its credit, recognizes the need for research on improving HIT. However this is a tool to facilitate clinical care, not a cybernetic miracle to revolutionize medicine. The government has bought the IT magic bullet exuberance hook, line and sinker.

I can only hope patients get something worthwhile for the $20 billion.

Scot Silverstein, M.D.
Faculty, Biomedical Informatics
Drexel University Institute for Healthcare Informatics
Philadelphia

I also had penned essays on the need for a moratorium on HITECH (Nov. 2008, "Should The U.S. Call A Moratorium On Ambitious National Electronic Health Records Plans?" and Jan. 2009, "I Ask Again: Should The U.S. Call A Moratorium On Ambitious National Electronic Health Records Plans?").  My theme was that the issues with implementation of good health IT and elimination of bad health IT, and the issue of how to implement most efficiently, needed to be better understood before a national rollout.  Hold off multi-billion dollar national initiatives "until we know how to get HIT right", I wrote.

Now the New York Times has this, citing a new RAND paper:

In Second Look, Few Savings From Digital Health Records
By REED ABELSON and JULIE CRESWELL

January 10, 2013

The conversion to electronic health records has failed so far to produce the hoped-for savings in health care costs and has had mixed results, at best, in improving efficiency and patient care, according to a new analysis by the influential RAND Corporation.

Optimistic predictions by RAND in 2005 helped drive explosive growth in the electronic records industry and encouraged the federal government to give billions of dollars in financial incentives to hospitals and doctors that put the systems in place.

“We’ve not achieved the productivity and quality benefits that are unquestionably ["unquestionably?" why?- ed.]  there for the taking,” said Dr. Arthur L. Kellermann, one of the authors of a reassessment by RAND that was published in this month’s edition of Health Affairs, an academic journal.

Noted is the provenance of the 2005 report that created the windfall for the electronic records industry:

RAND’s 2005 report was paid for by a group of companies, including General Electric and Cerner Corporation, that have profited by developing and selling electronic records systems to hospitals and physician practices. Cerner’s revenue has nearly tripled since the report was released, to a projected $3 billion in 2013, from $1 billion in 2005.

A retraction:

The report predicted that widespread use of electronic records could save the United States health care system at least $81 billion a year, a figure RAND now says was overstated. The study was widely praised within the technology industry and helped persuade Congress and the Obama administration to authorize billions of dollars in federal stimulus money in 2009 to help hospitals and doctors pay for the installation of electronic records systems ... But evidence of significant savings is scant, and there is increasing concern that electronic records have actually added to costs by making it easier to bill more for some services.

In my Feb. 2009 WSJ letter, I'd written that "it is the government that has been deceived by the HIT industry and its pundits. Stated directly, the administration is deluded about the true difficulty of making large-scale health IT work. The beneficiaries will largely be the IT industry and IT management consultants."  It appears I was correct.

Officials at RAND said their new analysis did not try to put a dollar figure on how much electronic record-keeping had helped or hurt efforts to reduce costs. But the firm’s acknowledgment that its earlier analysis was overly optimistic adds to a chorus of concern about the cost of the new systems and the haste with which they have been adopted.

Not mentioned are harms that bad health IT is creating.

The recent analysis was sharply critical of the commercial systems now in place, many of which are hard to use and do not allow doctors and patients to share medical information across systems. “We could be getting much more if we could take the time to do a little more planning and to set more standards,” said Marc Probst, chief information officer for Intermountain Healthcare, a large health system in Salt Lake City that developed its own electronic records system

A "little more" planning?  How about several years' worth, to ensure the technologies are safe, effective and properly vetted, along with a system for post-market surveillance as exists in other healthcare sectors?

Technology “is only a tool,” said Dr. David Blumenthal, who helped oversee the federal push for the adoption of electronic records under President Obama and is now president of the Commonwealth Fund, a nonprofit health group. “Like any tool, it can be used well or poorly.” While there is strong evidence that electronic records can contribute to better care and more efficiency, Dr. Blumenthal said, the systems in place do not always work in ways that help achieve those benefits.

Dr. Blumenthal seems to be triangulating from his earlier 2010 NEJM statement that:

... The widespread use of electronic health records (EHRs) in the United States is inevitable. EHRs will improve caregivers’ decisions and patients’ outcomes. Once patients experience the benefits of this technology, they will demand nothing less from their providers. Hundreds of thousands of physicians have already seen these benefits in their clinical practice.

Meantime, in the real world signs of my expressed concerns about a quagmire are appearing:

... Late last year, a physician practice in Panama City, Fla., filed a lawsuit against the health care technology firm Allscripts after the company stopped supporting an electronic records system called MyWay that it had sold to 5,000 small-group physicians at a cost of $40,000 per physician. The lawsuit said that the system had problems and that the physician group was unable to meet the criteria for federal incentive money. A spokeswoman for Allscripts said it would defend itself vigorously.

A clue as to the candidness of the new report:

... The new analysis was not sponsored by any corporations, said Dr. Kellermann, who added that some members of RAND’s health advisory board wanted to revisit the earlier analysis.

Finally, this from the horse's mouth:

Dr. David J. Brailer, who was the nation’s first health information czar under President George W. Bush, said he still believed tens of billions of dollars could eventually be squeezed out of the health care system through the use of electronic records. In his view, the “colossal strategic error” that occurred was a result of the Obama administration’s incentive program.

I repeat my admonition from 2009 that I can only hope patients get something worthwhile for the $20 billion, which by now is probably many times that amount.

Finally, I note the American Medical News cites me in a Jan. 14, 2013 article as follows:

... Other experts on health IT said the Pennsylvania [PA Patient Safety Authority] study probably underestimates the extent of health IT safety problems. They say that is because the research is based on voluntary reports and that health professionals are unaware that a patient safety incident was caused by an EHR failure.

“These systems are incredibly complex,” said Scot M. Silverstein, MD, a consultant in medical informatics at Drexel University in Philadelphia. “They’re not just huge filing cabinets, they are enterprise resource management systems. There are many ways that things can go wrong that may not be seen as the computer having caused the mess-up in the first place.”

For example, he said, it would be difficult for a practicing physician to detect when data are missing from a record or that an alert failed to pop up.

Yet the title of the article is "EHR-related errors soar, but few harm patients" with a table at the bottom labeled "How rarely EHR problems harm patients." More evidence that EHRs always receive special accommodation. 

I was an invited reviewer of the PA Patient Safety Authority report, and wrote about the major deficiencies of its dataset at my posts Dec. 13, 2012 post "Pennsylvania Patient Safety Authority: The Role of the Electronic Health Record in Patient Safety Events" and a follow-up Dec. 19 post "A Significant Additional Observation on the PA Patient Safety Authority Report -- Risk."

My major point was that one simply cannot know what one cannot know, when using a very incomplete dataset gathered in a setting of systematic impediments to accuracy and completeness.  For instance, as I wrote in those earlier posts, through my work I personally know of cases of harms up to and including death that should have been in the PA database, but apparently are not - and I'm just one person.

We simply don't know in 2013 how many EHR errors harm patients, and the effects of increasing adoption by organizations and physicians less technology-able than current adopters.  I hope the magnitude of harms is truly small, but hope is not enough; this study and report was just a 'dipping of the toes into the water' towards understanding the realities.

Incidentally, we also don't know how severely the known toxic effects of bad health IT might affect care in times of duress, e.g., an epidemic.  However, I am certainly not sanguine about EHRs in their present state as robustly facilitating national emergency preparedness.

My dreaded prediction for the future?  A 2016 AMA News story entitled "Known EHR-related harms soar."

-- SS

Saturday, January 5, 2013

ONC and "Health IT Patient Safety Action & Surveillance Plan": When Sociologists Uphold the Hippocratic Oath While Physicians Pay Respect to the Lords of Kobol, We Are in a Dark Place, Ethically

[Note: this essay contains many hyperlinks. They can be right-clicked and opened in a separate tab or window.]

I've been meaning to write more on the just-before-Christmas, Friday afternoon, minimal-visibility release of the ONC report I'd written about in my Dec. 23, 2012 post "ONC's Christmas Confessional on Health IT Safety: HIT Patient Safety Action & Surveillance Plan for Public Comment."   (The ONC report itself is available at this link in PDF.)

The Boston Globe and Globe staff writer Chelsea Conaboy, however, have beaten me to the punch in the Jan. 3, 2013 article "Federal government releases patient safety plan for electronic health records", link below.

('Lords of Kobol', of course, is a pun.  They were fictional gods in a sci-fi series from the 1970's and a remake a few years ago, but in my circles the term is used satirically and derisively to reflect people expressing inappropriate overconfidence in - and perhaps worship of - computers.   Cobol, the COmmon Business-Oriented Language, is one of the oldest programming languages and was the major programming language of the merchant computing sector, including business, finance, and administrative systems for companies and governments.)

First, I do want to reiterate what I'd mentioned in my earlier post:  the new ONC report is a sign of progress, in terms of a government body explicitly recognizing the social responsibilities incurred by conducting the mass human subjects experiment of national health IT.  However, I also wrote:

... [The ONC report] is still a bit weak in acknowledging the likely magnitude of under-reporting of medical errors, including HIT-related, in the available data, and the issue of risk vs. 'confirmed body counts' as I wrote at my recent post "A Significant Additional Observation on the PA Patient Safety Authority Report -- Risk".

The Globe quoted a number of people involved the health IT debate, and I am now commenting on their Jan. 3 article:

Federal government releases patient safety plan for electronic health records
Boston Globe
01/03/2013 11:16 AM   

By Chelsea Conaboy, Globe Staff

The federal office in charge of a massive rollout of electronic health records has issued a plan aimed at making those systems safer by encouraging providers to report problems to patient safety organizations.

Though some in the field say it doesn’t go far enough, others said the plan is an important step for an office whose primary role has been cheerleader for a technology that has the potential to dramatically improve health care in the United States but that may come with significant risks.

A major issue at the heart of the controversy is the fact that, admittedly, nobody knows the magnitude of the risks - in large part due to systematic impediments to knowing.  This has been admitted by organizations including the Joint Commission (link), U.S. FDA (link; albeit in an "internal memo" never intended for public view, and discovered only through the hard work of Center for Public Integrity investigative reporter Fred Schulte when he was at the Huffington Post Investigative Fund), Institute of Medicine of the U.S. National Academies (link, quoted at midsection of post), and others. 

I have made the claim that when you don't know the level of harm of an intervention in healthcare, and there are risk management-relevant case reports of dangers, you don't go gung-ho and start a national-scale implementation with penalties for non-adopters, and then decide to study safety, quality, usability etc.  You determine safety first in more controllable and constrained environments.  Anything else is, as I wrote, putting the cart before the horse (link).


Things are a bit out of order here.


You also certainly don't dismiss risk management-relevant case reports from credible observers as "anecdotal", the common refrain of hyperenthusiasts and (incompetent) scientists who conflate scientific research with risk management - as a researcher from Down Under eloquently observed in the Aug. 2011 guest post "From a Senior Clinician Down Under: Anecdotes and Medicine, We are Actually Talking About Two Different Things."

 Back to the Globe:

A year ago, the Institute of Medicine issued a report urging the federal government to do more to ensure the safety of electronic health records. It highlighted instances in which the systems were linked to patient injury, deaths, or other unsafe conditions.

The report suggested creating an independent body to investigate problems with electronic records and to recommend fixes, similar to how the National Transportation Safety Board investigates aviation accidents.

Instead, the Office of the National Coordinator for Health Information Technology delegated various monitoring and data collection duties to existing federal offices, including the Agency for Healthcare Research and Quality [AHRQ].

The problem is that AHRQ is a research agency (as its name suggests), has no regulatory authority nor any experience in regulation, and most clinicians have never heard of it.  In effect, this ONC recommendation is lacking teeth, even compared to the relatively milquetoast recommendations of IOM itself (as I wrote about in a Nov. 2011 post "IOM Report - 'Health IT and Patient Safety: Building Safer Systems for Better Care' - Nix the FDA; Create a New Toothless Agency").


The [ONC] office has asked patient safety organizations, which work with doctors and hospitals to monitor and analyze medical errors, to add health IT to their agendas. Data from the organizations would be aggregated by the agency, but reporting by doctors and hospitals is completely voluntary.  [A prime example of what I term an extraordinary regulatory accommodation afforded the health IT industry - ed.]

Now we're into septic shock blood pressure-level weakness. Here is PA Patient Safety Authority Board Member Cliff Rieders, Esq. on mandatory, let alone voluntary reporting. From “Hospitals Are Not Reporting Errors as Required by Law", Philadelphia Inquirer, pg. 4, http://articles.philly.com/2008-09-12/news/24991423_1_report-medical-mistakes-new-jersey-hospital-association-medication-safety:
  


... Hospitals don’t report serious events if patients have been warned of the possibility of them in consent forms, said Clifford Rieders, a trial lawyer and member of the Patient Safety Authority’s board.

He said he thought one reason many hospitals don’t want to report serious events is that the law also requires that patients be informed in writing within a week of such problems. So, if a hospital doesn’t report a problem, it doesn’t have to send the patient that letter. [Thus reducing risk of litigation, and, incidentally, potentially infringing on patients' rights to legal recourse - ed.]


Rieders says the agency has allowed hospitals to determine for themselves what constitutes a serious event and the agency has failed to come up with a solid definition in six years.

Fixing this “is not a priority,” he added.

To expect hospitals to voluntarily report even a relevant fraction of mistakes and near-misses out of pure altruism, or permit their clinicians to do so, with the inherent risks to organizational interests such reporting entails, is risible.

The near-lack of reporting by most health IT sellers and hospitals in the already-existing FDA Manufacturer and User Facility Device Experience (MAUDE) database is substantial confirmation of that; the fraction of reports in MAUDE, however, are hair-raising.  See my Jan. 2011 post "MAUDE and HIT Risks: What in God's Name is Going on Here?" for more on that issue.

Here's an example of what happens to 'whistleblowers', even those responsible for system development and safety: "A Lawsuit Over Healthcare IT Whistleblowing and Wrongful Discharge."

ONC's recommendations thus in my opinion reflect bureaucratic window dressing, designed to create progress - but progress that can probably be measured in microns.

“There was no evidence that a mandatory program was necessary,” Jodi Daniel, the [ONC] office’s director of policy and planning, said in an interview.

Really?  See the aforementioned Philadelphia Inquirer article Hospitals Are Not Reporting Errors as Required by Law", as well as numerous articles on pharma and medical device industry reporting deficits such as starting at page 5 in my paper "A Medical Informatics Grand Challenge: the EMR and Post-Marketing Drug Surveillance" at this link in PDF.

There is no evidence mandatory reporting is necessary ... to someone who's either naïve, incompetent - or persuaded, e.g. with money, to not find evidence or rationale.

The [ONC] office has been under pressure to roll out the electronic health records systems quickly while protecting patient data and making sure that the systems don’t cause problems in medical care, said Dr. John Halamka, chief information officer at Beth Israel Deaconess Medical Center. 

Under pressure by the health IT lobby, perhaps; but nobody else that I can think of.

“It’s this challenging chicken-and-egg problem,” he said.

No, actually, it isn't.  Patient safety must come first. This becomes clear when one considers the late 5th century BC ethical principle Primum non nocere ("first, do no harm" or "abstain from doing harm") versus the late 20th and early 21st century IT-hyperenthusiast credo I've expressed as "Cybernetik Über Alles"  ("Computers above all"). Under CÜA, the computer has more rights than the patients, and the IT industry receives extraordinary regulatory accommodation to sloppy practices that no other healthcare or mission-critical non-healthcare sector enjoys.

I sent Dr. Halamka a set of arguments such as I make here, and a picture of a health IT 'chicken', my deceased mother in her death robes.

I received back a "thank you for the views" message - but no condolences.  (It occurs that I have rarely if ever received condolences from any senior HIT-hyperenthusiast Medical Informatics academic or government official to whom I've mentioned my mother.  Not to play amateur psychologist, but I believe it reflects the level of disdain or even hatred felt by these people towards health IT iconoclasts/patient's rights advocates.)

The plan, which is subject to public comment through Feb. 4, “is a reasonable start,” in part because it puts more pressure on hospitals and doctors to monitor safety, Halamka said.

As I expressed to Dr. Halamka, we are in agreement on that point.

The government would have risked stifling innovation in the industry if it had opted instead to require the kinds of tests and review by the Food and Drug Administration that new medical devices and drugs must go through, he said.

To that, I mention here (as I did in my email to him) my response to this industry meme, as I had expressed it at Q&A after my August 2012 keynote address to the Health Informatics Society of Australia:

... I had a question from the audience [after my talk], from fellow blogger Matthew Holt of the Health Care Blog.  (I've had some online debate with him before, such as in the comment thread at my April 2012 post here.)

Matthew asked me a somewhat hostile question (perhaps in retaliation for the thrashing he received at the end of my May 2009 post on the WaPo's HIT Lobby article here), that I was well prepared for, expecting a question along these lines from the seller community, actually.  The question was preceded by a bit of a soliloquy of the "You're trying to stop innovation through regulation" type, with a tad of Merck/VIOXX ad hominem thrown in (I ran Merck Research Labs' Biomedical libraries and IT group in 2000-2003).

His question was along the lines of - you were at Merck; VIOXX was bad; health IT allowed discovery of the VIOXX problem by Kaiser several years before anyone else; you're trying to halt IT innovation via demanding regulation of the technology thus harming such capabilities and other innovations.

The audience was visibly unsettled.  Someone even hollered out their disapproval of the question.

My response was along the lines that:

  • VIOXX was certainly not Merck at its best, but regulation didn't stop Merck from "revolutionizing" asthma and osteoporosis via Singulair and Fosamax;
  • That I'm certainly not against innovation; I'm highly pro-innovation;
  • That our definitions of "innovation" in medicine might differ, in that innovation without adherence to medical ethics is not really innovation.  It is exploitation.

I stand by that assessment.

More from the Globe article:

There is little good research into how the systems improve health care and there are big obstacles to fixing even the known problems, said Ross Koppel, a professor of sociology at the University of Pennsylvania who studies hospital culture and medication errors.

Some developers require providers to sign nondisclosure agreements before using their systems, and the safety plan does not prohibit such gag clauses.  [Note: I wrote on this issue here, and in a published July 2009 JAMA letter to the editor "Health Care Information Technology, Hospital Responsibilities, and Joint Commission Standards" here - ed.]  While the plan addresses reporting of known problems, Koppel said it will not help researchers and developers understand problems that go unnoticed but that may be causing real patient harm. 

“We only know the tip of the iceberg” about how electronic health records affect patient care, said Koppel, who was an official reviewer for the Institute of Medicine report.

As per the title of this blog post, we are in a dark place, ethically, when a PhD sociologist who's never taken the Oath of Hippocrates (to my knowledge) appears to express more concern for patient safety and patient's rights than a Harvard physician-informatics Key Opinion Leader such as Dr. Halamka.

Koppel said the mantra of the Office of the National Coordinator has been that more health IT leads to better health care. “It probably is better than paper,” he said, “but it could be so much better than it is.”

I agree, but with caveats.  I opine that bad health IT is likely worse for patients than a good, well-staffed paper based system.  For instance, the former can cause systematic dangers that even a bad paper system cannot, such as tens of thousands of prescription errors (see my Nov, 2011 post "Lifespan Rhode Island: Yet another health IT 'glitch' affecting thousands - that, of course, caused no patient harm that they know of - yet") or mass privacy breaches (see the current 30 or so posts on that issue at this blog query link: http://hcrenewal.blogspot.com/search/label/medical record privacy).

On good health IT and bad health IT from my teaching site "Contemporary Issues in Medical Informatics: Good Health IT, Bad Health IT, and Common Examples of Healthcare IT Difficulties" at http://www.ischool.drexel.edu/faculty/ssilverstein/cases/:

Good Health IT ("GHIT") is IT that provides a good user experience, enhances cognitive function, puts essential information as effortlessly as possible into the physician’s hands, keeps eHealthinformation secure, protects patient privacy and facilitates better practice of medicine and better outcomes. 

Bad Health IT ("BHIT") is IT that is ill-suited to purpose, hard to use, unreliable, loses data or provides incorrect data, causes cognitive overload, slows rather than facilitates users, lacks appropriate alerts, creates the need for hypervigilance (i.e., towards avoiding IT-related mishaps) that increases stress, is lacking in security, compromises patient privacy or otherwise demonstrates suboptimal design and/or implementation.
 

The Boston Globe article concludes:

Ashish Jha, associate professor of health policy at Harvard School of Public Health and a member of the panel that drafted the Institute of Medicine report, said he wants doctors to be able to report problems -- errors in medication lists, for example -- in real-time so they can be found and fixed quickly. The safety plan does not require systems to have that capability, but Daniel said her office could soon add such a requirement for products that receive federal certification.

The bigger problem is that health care as a whole needs a better way of tracking patient safety, Jha said. Monitoring issues caused by electronic health records “should be a part of it, and then we can actually know if this is a small, medium or large contributor to patient safety issues,” he said. “But we don’t know that.”

I agree with Dr. Jha, but the IT sellers and healthcare organizations will (legitimately) claim that adding real-time error reporting/forwarding to their products will be extremely resource-intensive.

I have an alternate approach that will require little effort on the part of the sellers and user organizations.

  • Post a message at the sign-in screen of all health IT along the lines that "This technology is experimental, adopted willingly by [organization] although not rigorously vetted for safety, reliability, usability, nor fitness for purpose, and thus you use it at your own risk.  If problems occur, report them to the following" ...

"The following" could include a list of alternatives such as I wrote in my Aug. 2012 post "Clinicians: How to Document the EHR Screens You Encounter That Cause Concern."


... When a physician or other clinician observes health IT problems, defects, malfunctions, mission hostility (e.g., poor user interfaces), significant downtimes, lost data, erroneous data, misidentified data, and so forth ... and most certainly, patient 'close calls' or actual injuries ... they should (anonymously if necessary if in a hostile management setting):

  • Inform their facility's senior management, if deemed safe and not likely to result in retaliation such as being slandered as a "disruptive physician" and/or or being subjected to sham peer review (link).
  • Inform their personal and organizational insurance carriers, in writing. Insurance carriers do not enjoy paying out for preventable IT-related medical mistakes. They have begun to become aware of HIT risks. See, for example, the essay on Norcal Mutual Insurance Company's newsletter on HIT risks at this link. (Note - many medical malpractice insurance policies can be interpreted as requiring this reporting, observed occasional guest blogger Dr. Scott Monteith in a comment to me about this post.)
  • Inform the State Medical Society and local Medical Society of your locale.
  • Inform the appropriate Board of Health for your locale.
  • If applicable (and it often is), inform the Medicare Quality Improvement Organization (QIO) of your state or region. Example: in Pennsylvania, the QIO is "Quality Insights of PA."
  • Inform a personal attorney.
  • Inform local, state and national representatives such as congressional representatives. Sen. Grassley of Iowa is aware of these issues, for example.


See the actual post for an idea about clinicians seeking indemnification when forced by healthcare organizations to use bad health IT.  I can attest to actually seeing HIT policies that call for "human resources actions" if clinicians refuse to use HIT, or cannot learn to use it at a sufficient pace.

(Left out of this reiteration is the demonstration on photographing problematic EHR screens.  See the post for the details - it is easy to do, even with a commodity cellphone.)

HHS should be promoting laws on protection from retaliation upon clinicians reporting problems in good faith.

Thus, physicians, nurses and other clinicians can create needed health IT transparency and help our society discover the true level of risks of bad health IT.  They simply need the right information on what to do and where to report, bypassing the ONC office and, in the spirit of medicine, taking such matters into their own hands in the interests of patient care and medical ethics.

I also made recommendations to the Pennsylvania Patient Safety Authority on how known taxonomies of health IT-related medical error can be used, and need to be used, to promote error reporting in common formats.  Slides from my presentation to the Authority entitled "Asking the Right Questions:  Using Known HIT Safety Issues to Improve Risk Reporting and Analysis", given in July 2012 at their invitation, are at http://www.ischool.drexel.edu/faculty/ssilverstein/PA_patient_safety_Jul2012.ppt

Finally, another sign of progress:  unlike the HITECH Act, this new ONC plan is open to public comment.

-- SS

Addendum Jan. 8., 2012:

Dr. Halamka has put more details regarding his views in his blog.  The entry is entitled "Electronic Health Record Safety" at this link:  http://geekdoctor.blogspot.com/2013/01/electronic-health-record-safety.html .

He writes:

... Some have questioned the wisdom of moving forward with EHRs before we are confident that they are 100% safe and secure.   [That, of course, is not my argument - nothing is ever 100% safe and secure.  However, we don't yet know just how safe and secure - or unsafe and insecure - HIT is.  That is the issue I am concerned about - ed.] I believe we need to continue our current implementation efforts.

I realize it is a controversial statement for me to make, but let me use an analogy.

When cars were first invented, seat belts, air bags, and anti-lock brakes did not exist.    Manufacturers tried to create very functional cars, learned from experience how to make them better, then innovated to create new safety technologies. many of which are now required by regulation.

Writing regulation to require seat belts depended on experience with early cars.

My grandmother was killed by a medication error caused by lack of an EHR.  My mother was incapacitated by medication issues resulting from lack of health information exchange between professionals and hospitals.   My wife experienced disconnected cancer care because of the lack of incentives to share information.     Meaningful Use Stage 2 requires the functionality in EHRs which could have prevented all three events.

I express my condolences on those events.

I disagree, however, with continuing national implementation efforts at the current rate, with penalties for non-adopters.  I opine from the perspective of believing health IT has not reached a stage where it is ready for national rollout and remains experimental, its magnitude of harms admittedly unknown and information flows systematically impaired.  I recommend and prefer great caution under those circumstances, and remediation of those circumstances before full-bore national implementation.

I will leave it to the reader ponder the two views.

-- SS

Sunday, December 23, 2012

ONC's Christmas Confessional on Health IT Safety: "HIT Patient Safety Action & Surveillance Plan for Public Comment"

This time of year is certainly appropriate for a confessional on the health IT industry and hyperenthusiasts' sins.

In the first report I've seen that seems genuinely imbued with a  basic level of recognition of social responsibility incurred by conducting the grand human subjects experiment known as national health IT, ONC has issued a Dec. 21, 2012 report "Health Information Technology Patient Safety Action & Surveillance Plan for Public Comment." It is available at this link in PDF.

Statements are made that have appeared repeatedly since 2004 at this blog, and my health IT difficulties site that went online years before this blog (1998 to be exact); it is possible through my early writing and that of like-minded colleagues that we were the origin of most of these memes.  We wrote them with the result of bringing much scorn upon ourselves. After all, "how could health IT possibly not be a panacea?" was the "you are an apostate" attitude I certainly experienced (e.g., as in my Sept. 2012 post "The Dangers of Critical Thinking in A Politicized, Irrational Culture").

Observations echoed in the new ONC report:

  • "Just as health IT can create new opportunities to improve patient care and safety, it can also create new potentials for harm."
  • Health IT will only fulfill its enormous potential to improve patient safety if the risks associated with its use are identified, if there is a coordinated effort to mitigate those risks, and if it is used to make care safer.
  • Because health IT is so tightly integrated into care delivery today, it is difficult to interpret this initial research [such as the PA Patient Safety Authority study  - ed.], which would seem to suggest that health IT is a modest cause of medical errors. However, it is difficult to say whether a medical error is health IT-related. [Not emphasized, as I wrote here, is the issue of risk when, say, tens of thousands of prescriptions are erroneous due to one software bug, a feat impossible with paper - ed.]
  • The proper steps to improve the safety of health IT can only be taken if there is better information regarding health IT’s risks, harms, and impact on patient safety.

Suggested steps to be taken include:

  • Make it easier for clinicians to report patient safety events and risks using EHR technology.
  • Engage health IT developers to embrace their shared responsibility for patient safety and promote reporting of patient safety events and risks. [I am frankly amazed to see this admission.  In the past, that sector excused itself entirely on the basis of the "learned intermediary" doctrine and "hold harmless" clauses; where the clinician is an all-knowing Deity between computer and patient.  I've been writing for years, however, that the computer is now the intermediary between clinician and patient since all care 'transactions' have to traverse what is now an enterprise clinical resource and clinician control system - ed.]
  • Provide support to Patient Safety Organizations (PSOs) to identify, aggregate, and analyze health IT safety event and hazard reports.
  • Incorporate health IT safety in post-market surveillance of certified EHR technology
  • Align CMS health and safety standards with the safety of health IT, and train surveyors.
  • Collect data on health IT safety events through the Quality & Safety Review System (QSRS).
  • Monitor health IT adverse event reports to the Manufacturer and User Facility Device Experience (MAUDE) database. [I've been promoting the use of MAUDE for just that purpose, and much more regarding documenting and reporting on mission-hostile health IT; see this post - ed.]

These steps are to be taken in order to "Inspire Confidence and Trust in Health IT and Health Information Exchange."

The title of my keynote address to the Health Informatics Society of Australia this summer was, in fact, "Critical Thinking on Building Trusted, Transformative Medical Information:  Improving Health IT as the First Step".

My thoughts on this report:

  • It is at least two decades overdue.
  • It was produced largely if not solely due to the pressure of the "HIT apostates", finally overcoming industry memes and control of information flows through great perseverance.
  • It is indeed a confessional of the sins committed by the health IT industry over those decades.  Creating, implementing and maintaining mission critical software in a safety-cognizant way is not, and was not, a mystery.  It's been done in numerous industries for decades.
  • It is still a bit weak in acknowledging the likely magnitude of under-reporting of medical errors, including HIT-related, in the available data, and the issue of risk vs. 'confirmed body counts' as I wrote at my recent post "A Significant Additional Observation on the PA Patient Safety Authority Report -- Risk".
  • It is unfortunate that this report did not come from the informatics academic community in the United States, i.e., the American Medical Informatics Association (AMIA).  AMIA's academics have done well in advancing the theoretical aspects of the technologies, and how to create "good health IT" and not "bad health IT."  However, they have largely abrogated their social responsibilities and obligations, including but not limited to those of physicians, in ensuring the theories were followed in practice by an industry all too eager to ignore academic research (which, in order to follow, utilizes money and resources and reduces margins).
(On the latter point, just last week did the American College of Medical Informatics [ACMI] refuse to permit me to be a speaker at their early 2013 annual retreat despite support from some of its members.)

And this:

  • If the industry and the academics had been doing their job responsibly, I might be spending this Christmas and New Years's holiday with my mother, rather than visiting her in the cemetery.

All that said, the report is welcome.

Finally, it is hoped - and expected - that public comments will indeed be "public", and that any irregularities in such comments (such as appeared in the public comments period for MU2 due to industry ghostwriting as in my Aug. 2012 post "Health IT Vendor EPIC Caught Red-Handed: Ghostwriting And Using Customers as Stealth Lobbyists - Did ONC Ignore This?" and Sept. 2012 post "Was EPIC successful in watering down the Meaningful Use Stage 2 Final Rule?") will be reported and acted upon in an aggressive manner.

And finally, from the Healthcare Renewal blog, Merry Christmas.

-- SS

Thursday, June 14, 2012

Ellmers Calls on Sebelius to Address Health IT Safety Concerns: A Responsible Voice in Government on Health IT and HIT Safety

The following press release is very welcome, and speaks for itself.  There is a responsible voice in the government wilderness.  It is perhaps no surprise it comes from a Congresswoman who is also a registered nurse:

Ellmers Calls on Sebelius to Address Health IT Safety Concerns



Safety Risks and Health IT-Related Errors Cited in IOM Recommendations

WASHINGTON – House Small Business Subcommittee on Healthcare and Technology Chairwoman Renee Ellmers (R-NC) today sent a letter to Kathleen Sebelius, Secretary of Health and Human Services (HHS), inquiring about whether the Department has adopted the Institute of Medicine’s (IOM) recommendations for improving the safety of health information technology (IT).
The report, issued in November, recommended several steps to be taken by HHS and called for greater oversight by the public and private sectors. The Secretary was called upon by the IOM to issue a plan within 12 months to minimize patient safety risks associated with health IT and report annually on the progress being made.  The report further recommended that the plan should include a schedule for working with the private sector to assess the impact of health IT on patient safety, and recommended several other steps to help improve the safety of health IT.

Specifically, Chairwoman Ellmers has requested a copy of the Secretary’s plan to minimize patient safety risks, a description of health IT-related errors that have resulted in patient risks, injuries and deaths, and the status of the development of a mechanism for health IT vendors and users to report health IT-related deaths.  She said that because health IT has the promise to improve health care delivery for patients, physicians and other medical professionals, she remains eager to work with the Secretary to ensure that health IT is safe, effective and affordable.

In an August 11, 2011 letter to Secretary Sebelius, Chairwoman Ellmers said that a modern, well-equipped office is critical to the practice of medicine, and asked the Secretary to undertake a study of health IT’s adoption, benefits and cost effectiveness, including medical error rates.

On June 2, 2011, Chairwoman Ellmers’ Subcommittee held a hearing on the barriers to health IT that are encountered by physicians and other health professionals in small and solo practices.   At the hearing, physicians expressed strong concerns about the cost of purchasing and maintaining health IT systems, as well as the staff training and downtime necessary to implement such a system.  Chairwoman Ellmers noted health IT’s great potential to improve health care delivery, decrease medical errors, increase clinical and administrative efficiency and reduce paperwork.

For more than twenty-one years before being elected to Congress, Chairwoman Ellmers served as a registered nurse, focusing on surgical care as Clinical Director of the Trinity Wound Care Center and later helping to manage the family's small medical practice with her husband, Dr. Brent Ellmers, a licensed surgeon. As a registered nurse and the wife of a surgeon, Ellmers understands that a modern, efficient and well-equipped office is critical to the practice of medicine.    

This voice of sanity is quite welcome.  I've spoken with Rep. Ellmers' office, pointing them to my Drexel Univ. writings and materials and recommending Sebelius' reply be gone over with a fine-toothed comb, from the perspective of health IT realities, not merely from the perspective of the Ddulite's good intentions.  (I also introduced her staffer to the concept of the Ddulite, the HIT hyper-enthusiast who ignores all downsides and ethical concerns.)

I also pointed out the ethical lapse in IOM's position of "wait and see" while HIT is pushed nationally under penalty of law, at the cost of hundreds of billions of dollars, when their own report (along with reports from FDA here, JC here and others) admits they don't know the magnitude of benefits, risks and harms:

... While some studies suggest improvements in patient safety can be made, others have found no effect. Instances of health IT–associated harm have been reported. However, little published evidence could be found quantifying the magnitude of the risk.

Several reasons health IT–related safety data are lacking include the absence of measures and a central repository (or linkages among decentralized repositories) to collect, analyze, and act on information related to safety of this technology. Another impediment to gathering safety data is contractual barriers (e.g., nondisclosure, confidentiality clauses) that can prevent users from sharing information about health IT–related adverse events. These barriers limit users’ abilities to share knowledge of risk-prone user interfaces, for instance through screenshots and descriptions of potentially unsafe processes. In addition, some vendors include language in their sales contracts and escape responsibility for errors or defects in their software (i.e., “hold harmless clauses”). The committee believes these types of contractual restrictions limit transparency, which significantly contributes to the gaps in knowledge of health IT–related patient safety risks. These barriers to generating evidence pose unacceptable risks to safety.
[IOM (Institute of Medicine). 2012. Health IT and Patient Safety: Building Safer Systems for Better Care (PDF). Washington, DC: The National Academies Press, pg. S-2.]

As I wrote in my Nov. 2011 post "IOM Report - 'Health IT and Patient Safety: Building Safer Systems for Better Care' - Nix the FDA; Create a New Toothless Agency", the IOM's response to their own study was reckless and unethical (at best):

... The panel also recommends that the HHS secretary publicly report on the progress of health IT safety each year, beginning in 2012. If the secretary determines at any time that adequate safety progress has not been made, only then should the FDA take the regulatory lead and be given the resources to do so, the report recommends, adding that the agency should be developing a framework now to be prepared.

In the meantime, during each year of "watching for safety progress", innumerable patients are exposed to HIT's hazards and costs.  Pharma and other medical device industries are afforded no such special accommodation.

-- SS

Sunday, June 3, 2012

WSJ "There's a Medical App for That—Or Not" - Misinformation on Health IT Safety Regulation?

There's a health IT meme that just won't die (patients may, but not the meme).

It's the meme that health IT "certification" is a certification of safety.

I expressed concern about the term "certification" being misunderstood even before the meme formally appeared, when the term was adopted by HHS with regard to evaluation of health IT for adherence to the "meaningful use" pre-flight features checklist.  See my mid-2009 post "CCHIT Has Company" where I observed:

HIT "certification." ... is a term I put in quotes since it really is "features qualification" at this point, not certification such as a physician receives after passing Specialty Boards.

The "features qualification" is an assurance that the EHR functions in way that could enable an eligible provider or eligible hospital to meet the Center for Medicare & Medicaid Services' (CMS) requirements of "Meaningful Use."  No rigorous safety testing in any meaningful sense is done, and no testing under real-world conditions is done at all.

I've seen the meme in various publications and venues.  I've even seen it in legal documents in medical malpractice cases where EHR's were involved, as an attempted defense.

Now the WSJ has fallen for the health IT Certification meme.

An article "There's a Medical App for That—Or Not" was published on May 29, 2012.  Its theme is special regulatory accommodation for health IT in the form of opposition to FDA regulation of devices such as "portable health records and programs that let doctors and patients keep track of data on iPads."

In the article, this assertion about health IT "certification" is made:

... The FDA's approach to health-information technology risks snuffing out activity at a critical frontier of health care. Poor, slow regulation would encourage programmers to move on, leaving health care to roil away for yet another generation, fragmented, disconnected and choking on paperwork.

The process already exists for safeguarding the public for computers in health care. It's not FDA premarket review but the health information technology certification program, established under President George W. Bush and still working fine under the Obama Health and Human Services Department. The government sets the standards and an independent nonprofit [ATCB, i.e., ONC Authorized Testing and Certification Bodies - ed.] ensures that apps meet those standards. It's a regulatory process as nimble as the breakout industry it's meant to monitor. That is where and how these apps should be regulated.

It's a wonderful meme.  Unfortunately, it's wrong.  Dead wrong.

Certification by an ATCB does not "safeguard the public."   Two ONC Authorized Testing and Certification Bodies (ATCB's) admitted this in email, as in my Feb. 2012 post "Hospitals and Doctors Use Health IT at Their Own Risk - Even if Certified".  I had asked them, point-blank:

"Is EHR certification by an ATCB a certification of EHR safety, effectiveness, and a legal indemnification, i.e., certifying freedom from liability for EHR use of clinical users or organizations? Or does it signify less than that?"

I received two replies from major ONC ATCB's indicating that "certification" is merely assurance that HIT meets a minimal set of "meaningful use" guidelines, not that it's been vetted for safety.  For instance:

From: Joani Hughes (Drummond Group)
Sent: Monday, March 05, 2012 1:06 PM
To: Scot Silverstein
Subject: RE: EHR certification question

Per our testing team:

It is less than that. It does not address indemnification although a certification could be used as a conditional part of some other form of indemnification function, such as a waiver or TOA, but that is ultimately out of the scope of the certification itself. Certification in this sense is an assurance that the EHR functions in way that could enable an eligible provider or eligible hospital to meet the CMS requirements of Meaningful Use Stage 1. Or to restate it more directly, CMS is expecting eligible providers or eligible hospitals to use their EHR in “meaningful way” quantified by various quantitative measure metrics and eligible providers or eligible hospitals can only be assured they can do this if they obtain a certified EHR technology.

Please let me know if you have any questions.

Thank you,
Joani.

Joani Hughes
Client Services Coordinator
Drummond Group Inc.

The other ATCB, ICSA Labs, stated that:

... Certification by an ATCB signifies that the product or system tested has the capabilities to meet specific criteria published by NIST and approved by the Office of the National Coordinator. In this case the criteria are designed to support providers and hospitals achieve "Meaningful Use." A subset of the criteria deal with the security and patient privacy capabilities of the system.

Here is a list of the specific criteria involved in our testing:
http://healthcare.nist.gov/use_testing/effective_requirements.html

In a nutshell, ONC-ATCB Certification deals with testing the capabilities of a system, some of them relate to patient safety, privacy and security functions (audit logging, encryption, emergency access, etc.).

What was suggested in the email below (freedom from liability for users of the system, etc.) would be out of scope for ONC-ATCB testing based on the given criteria. [I.e., certification criteria - ed.] I hope that helps to answer your question.

I had noted that:

... My question was certainly answered [by the ATCB responses]. ONC certification is not a safety validation, such as in a document from NASA on aerospace software safety certification, "Certification Processes for Safety-Critical and Mission-Critical Aerospace Software" (PDF) which specifies at pg. 6-7:
In order to meet most regulatory guidelines, developers must build a safety case as a means of documenting the safety justification of a system. The safety case is a record of all safety activities associated with a system throughout its life. Items contained in a safety case include the following:

• Description of the system/software
• Evidence of competence of personnel involved in development of safety-critical software and any
safety activity
• Specification of safety requirements
• Results of hazard and risk analysis
• Details of risk reduction techniques employed
• Results of design analysis showing that the system design meets all required safety targets
Verification and validation strategy
• Results of all verification and validation activities
• Records of safety reviews
• Records of any incidents which occur throughout the life of the system
• Records of all changes to the system and justification of its continued safety

A CCHIT ATCB juror, a physician informatics specialist, has also done a guest post in Jan. 2012 on HC Renewal about the certification process, reproducing his testimony to HHS on the issue.  That post is "Interesting HIT Testimony to HHS Standards Committee, Jan. 11, 2011, by Dr. Monteith."  Dr. Monteith testified (emphases mine):

... I’m “pro-HIT.” For all intents and purposes, I haven’t handwritten a prescription since 1999.

That said and with all due respect to the capable people who have worked hard to try to improve health care through HIT, here’s my frank message:

ONC’s strategy has put the cart before the horse. HIT is not ready for widespread implementation. 

... ONC has promoted HIT as if there are clear evidence-based products and processes supporting widespread HIT implementation.

But what’s clear is that we are experimenting…with lives, privacy and careers.

... I have documented scores of error types with our certified EHR, and literally hundreds of EHR-generated errors, including consistently incorrect diagnoses, ambiguous eRxs, etc.

As a CCHIT Juror, I’ve seen an inadequate process. Don’t get me wrong, the problem is not CCHIT. The problem stems from MU.

EHRs are being certified even though they take 20 minutes to do a simple task that should take about 20 seconds to do in the field.  [Which can contribute to mistakes and "use error" - ed.] Certification is an “open book” test. How can so many do so poorly?

For example, our EHR is certified, even though it cannot generate eRxs from within the EHR, as required by MU.

To CCHIT’s credit, our EHR vendor did not pass certification. Sadly, our vendor went to another certification body, and now they’re certified.

MU does not address many important issues. Usability has received little more than lip-service. What about safety problems and reporting safety problems? What about computer generated alerts, almost all of which are known to be ignored or overridden (usually for good reason)?
 
The concept of “unintended consequences” comes to mind.

All that said, the problem really isn’t MU and its gross shortcomings, it is ONC trying to do the impossible:

ONC is trying to artificially force a cure for cancer, basically trying to promote one into being, when in fact we need to let one evolve through an evidence-based, disciplined process of scientific discovery and the marketplace.

Needless to say, as was learned at great cost in past decades, a "disciplined process" in medicine includes meaningful safety regulation by objective outside experts.

Further, the certifiers have no authority to do important things such as forcibly remove dangerous software from the market.  An example is the forced Class 1 recall of a defective system as I wrote about in my Dec. 2011 post "FDA Recalls Draeger Health IT Device Because This Product May Cause Serious Adverse Health Consequences, Including Death".   Class 1 recalls are the most serious type of recall and involve situations in which there is a reasonable probability that use of these products will cause serious adverse health consequences or death.

In that situation, the producer had been simply advising users (in critical care environments, no less) to "work around the defects" that could indicate incorrect recommended dosage values of critical meds, including a drug dosage up to ten times the indicated dosage, as well as corrupt critical cardiovascular monitoring data.  As I observed:

... I find a software company advising clinicians to make sure to "work around" blatant IT defects in "acute care environments" the height of arrogance and contempt for patient safety.

Without formal regulatory authority to take actions such as this FDA recall, "safeguarding the public" is a meaningless platitude.

It's also likely the ATCB's, which are private businesses, would not want the responsibility of "safeguarding the public."  That responsibility would open them up to litigation when patient injuries or death were caused, or were contributed to, by "certified" health IT.

I have in the past also noted that the use of the term "certification" might have been deliberate, to mislead potential buyers exactly into thinking that "certification" is akin to a UL certification of an electrical appliance for safety, or an FAA approval of a new aircraft's flight-worthiness.

The WSJ needs to clarify and/or retract its statement, as the statement is misinformation.

At my Feb. 2012 post "Health IT Ddulites and Disregard for the Rights of Others" I observed:

Ddulites [HIT hyper-enthusiasts - ed.] ... ignore the downsides (patient harms) of health IT.

This is despite being already aware of, or informed of patient harms, even by reputable sources such as FDA (Internal FDA memo on H-IT risks), The Joint Commission (Sentinel Events Alert on health IT), the NHS (Examples of potential harm presented by health software - Annex A starting at p. 38), and the ECRI Institute (Top ten healthcare technology risks), to name just a few.

In fact, the hyper-enthusiastic health IT technophiles will go out of their way to incorrectly dismiss risk management-valuable case reports as "anecdotes" not worthy of consideration (see "Anecdotes and medicine" essay at this link).

They will also make unsubstantiated, often hysterical-sounding claims that health IT systems are necessary to, or simply will "transform" (into what, exactly, is usually left a mystery) or even "revolutionize" medicine (whatever that means).

Health IT is a potentially dangerous technology.   It requires meaningful regulation to "safeguard the public."  How many incidents like this and this will it take before that is understood by the hyper-enthusiasts?

I've emailed the ATCB's that had responded to my aforementioned query for clarification on the WSJ assertion about their role, being that the statement is in contradiction to their earlier replies to me.  I also advised them of the potential liability issues.

However, if it turns out to be true that the ONC-ATCB's do intend themselves as the ultimate watchdog and assurer of public safety related to EHR's, that needs to be known by the public and their representatives.

-- SS

Friday, June 1, 2012

Upcoming Keynote Presentation to Health Informatics Society of Australia: Health IT Must First Do No Harm

Pulse+IT Magazine (http://www.pulseitmagazine.com.au/) is Australasia's first, and they claim only, eHealth and Health IT periodical.

In a May 30, 2012 article entitled "Patient and safety advocates a highlight at HIC2012" at this link, writer Kate McDonald describes my upcoming panel participation and Keynote Presentation at the annual Health Informatics Conference (HIC) of the Health Informatics Society of Australia (HISA) in Sydney.

The focus of the HIC2012 meeting is "Building a Healthcare Future through Trusted Information."

Ms. McDonald had called me from Down Under to discuss my upcoming talk.  She writes:

 ... Also on the panel [one of the conference's annual Q&A panels - ed.] will be NEHTA CEO Peter Fleming, HISA board director and well-known consultant David Rowlands, and Scot Silverstein, an adjunct professor of health informatics at Drexel University in the US.

Dr Silverstein also has a personal story to tell that brings home the importance of what exactly is 'trusted' information. A qualified medical doctor and medical informatics researcher, Dr Silverstein is a strong advocate for safety in health IT systems, having been personally involved in what he believes was a case of medical misadventure caused by an electronic health record that resulted in harm to a close relative.

He will also deliver a keynote speech on the topic of improving health IT systems as a first step towards evidence-based medicine and better clinical outcomes.

Dr Silverstein told Pulse+IT that there is a “syndrome of over-confidence” in computer output that he finds puzzling.

“In other fields people, when they start getting incorrect bills or they keep coming and they can't stop them, it is always blamed on a computer system,” he said. “And yet in medicine, it seems to have evolved a culture around computing that machines in healthcare must deterministically create improvement and are purely beneficent and can't be capable of creating harm.

“It is a strange philosophy because in the same breath, people say healthcare information technology is capable of great benefit, that is a very powerful technology and when it is done well, it is. [As I've written before, "doing HIT well" is a challenge of 'wicked' complexity - ed.]  But anything that is a potential source for great good can also have a downside. There seems to be a cognitive gap in connecting computing in healthcare to its possible risk.”

She summarizes the views expressed in our phone conversation well.  My theme will be that health IT and the information it generates cannot be trusted until the technology itself is trustworthy, and earns our trust, through better engineering and implementation practices.

Ironically, I was invited to 2011's meeting.  I would have attended, but was tending to the injuries of my relative caused by the aforementioned medical misadventure. That relative is no longer with us and is hopefully resting in peace.

HISA was kind enough to re-invite me for 2012, for which I am grateful.

I will also be spending some time with several Medical Informatics professors in Australian universities, which should provide an excellent opportunity for sharing of views.


Sydney, Australia

I look forward to being in Sydney, never having been physically present in Australia, although being a ham radio operator, my single sideband (voice) and Morse code shortwave signals have been there on many occasions over the years.  This is a mere ~ 10,000-mile path.  No Internet or phone lines needed!  (I hope I get the opportunity to operate an Amateur radio station from "Down Under.")

More here after my presentation.

-- SS

Tuesday, February 21, 2012

Is ONC Stonewalling on the issue of HIT Certification, Safety and Liability?

At my Feb. 16, 2012 post "Hospitals and Doctors Use Health IT at Their Own Risk - Even if Certified" I wrote that an ONC-ATCB (Authorized Testing and Certification Body) replied to my email inquiry about health IT certification, safety and liability indemnification by stating that:

What was suggested in the email below (freedom from liability for users of the system, etc.) would be out of scope for ONC-ATCB testing based on the given criteria.

[That is, the criteria used in testing
here - ed.]

What I did not include in that post was the fact that some months ago, I had emailed ONC directly with the same questions, and then called them on the phone with those questions at about the same time as I inquired of the ATCB.

ONC itself never responded.

There are several possibilities:

  • They don't know the answer.
  • They don't want to respond.
  • They don't care to respond.


Dismissing possibility #1, these civil servants appear to be stonewalling on the issue.

It would be nice to hear ONC itself admit the term "certification" is a gossamer guarantee of health IT safety, efficacy and indemnification of purchasers, implementers and users from potential EHR-related liability.

I am not holding my breath.

-- SS

Addendum:

An ONC representative did get back to me on Feb. 27, but I told them my question had already been answered by ONC ATCB's.

Sunday, March 6, 2011

What to do about the state of the ED EHR's in NSW?

At my post yesterday "On an EMR Forensic Evaluation by Professor Jon Patrick from Down Under: More Thoughts", I've come down pretty hard on internal and external (i.e., human interface) sloppiness in mission critical IT systems.

In my view, the flaws that create randomly-occurring errors, combined with a mission hostile user experience highly and especially inappropriate in the hectic and unpredictable ED environment, turn these systems into slot machines. The jackpot, however, is not wealth. It's injury or death.

I've been asked, "So - what to do about the state of the ED EHR in NSW?"

Here are some simple initial suggestions:

A. For the time being: securing and implementing a paper backup (pen & paper) with scanning and document imaging retrieval system (integrated or standalone) as an 'EHR supplement", in order that really critical info can be steered in that direction.

Clinicians are already avoiding the EHR system and not entering or minimizing data, or using other "workarounds." Therefore, informationally and safety-wise, a document imaging/retrieval system for paper would probably be a net plus.

ED charts are not Tolstoy novel-length, as a matter of fact. There would not be many pages per patient, but even small morsels of key information collected easily and quickly, then retrieved easily, and presented clearly, cleanly and rapidly, as on a sheet or three of physical, then virtual parchment, can have enormous value.

B. Clinicians and responsible executives and officials should start demanding that the ED EHR vendor release its full conceptual and logical data models so that others can, competitively (including the original vendor if they wish), cleanse it and redo a user interface that meets the needs of NSW ED's. The latter should be determined collaboratively with the key stakeholders, and developed using agile, iterative and incremental methodologies, not the usual stale Management Information Systems approach. (I.e., the mercantile, manufacturing and management computing paradigms that are ill-fitting to healthcare informatics as further explained at my post here.)

That way moving data over to the "redone" new system would not be a nightmare. Or perhaps less of a nightmare than an entirely new extant system from another vendor (which would likely have similar flaws anyway and need similar rework).

The closed-system, locked-in-to-one-vendor paradigm that's apparently holding the ED's of an entire state of the fine country of Australia hostage must end. Let the best organization win.

As I also observed in the aforementioned post, the UK, having their own HIT issues (see my Aug. 2010 "Battle of Britain" post at this link), apparently learned something, as evidenced in:

Health Informatics — Application of clinical risk management to the manufacture of health software. UK National Health Service, DSCN14 (2009), formerly ISO/TS 29321:2008(E).

and

Health informatics — Guidance on the management of clinical risk relating to the deployment and use of health software. UK National Health Service, DSCN18 (2009), formerly ISO/TR 29322:2008(E).

Perhaps those in the U.S. and in VK-land (amateur-radio speak for Australia; I am KU3E here in the U.S.) can also heed these documents and their recommendations.

-- SS

Mar. 8, 2011 addendum:

Prof. Patrick has added a new section to his report, entitled "The Future Pathways for e-Health in NSW." It is available at this link (PDF).

It inoculates against most of the 'Ten Plagues' that bedevil health IT projects (such as the IT-clinical leadership inversion, magical thinking about the technology, and lack of accountability):

More on the Pathways at my post here.

The de facto "National Program for IT in the HHS" here in the United States needs a similar inoculation.

--SS

Wednesday, January 5, 2011

Institute of Medicine Committee on Patient Safety and Health Information Technology, and Thoughts on Social Aspects of Health IT Evaluation

March 2011 addendum: also see my thoughts on Meeting two of the Committee on Patient Safety and Health Information Technology at this link.

The U.S. National Research Council of the National Academy of Sciences issued a report in early 2009 on the state of health IT.

That study's report, led in part by pioneers in Medical Informatics G. Octo Barnett and William Stead, was entitled "Computational Technology for Effective Health Care: Immediate Steps and Strategic Directions" (pre-publication PDF available free at this link). The report was announced under the following header:

CURRENT APPROACHES TO U.S. HEALTH CARE INFORMATION TECHNOLOGY ARE INSUFFICIENT

The insufficiencies were largely in the areas of difficulties with data sharing and integration, deployment of new IT capabilities, large-scale data management, and lack of cognitive support by health IT for busy clinicians.

One might reasonably conclude such deficits could affect patient safety.

Recently the Institute of Medicine (the health arm of the National Academy of Sciences) formed a Committee to study health IT safety. It held its first meeting on Dec. 14, 2010 (quite a few years late in my opinion, and only after tens of billions of dollars have been earmarked for health IT, but better late than never):

The Institute of Medicine Committee on Patient Safety and Health Information Technology is holding its first meeting on December 14-15, 2010. The first day, December 14, 2010 beginning at 10:30 am, is open to the public to observe the committee proceedings. The committee will hear presentations by the Office of the National Coordinator and other invited guests. There will also be an opportunity for members of the public and representatives of interested organizations to make a brief statement before the committee. Prior registration is requested for attendees and required for those wishing to make a statement.

Participant lists and materials from that first meeting are available at this link.

This brings to mind some thoughts on the social aspects of health IT evaluation.

At a website by Dr. David Healy (link) on mass over-promotion and clinical trial data irregularities regarding SSRI's, academic abuses towards critical thinkers, and related affairs, I note an interesting observation in the preface. The author states:

"On the face of it, the investigation of possible hazards posed by SSRIs does not seem to have followed the conventional dynamics of science, where anomalies in the data are supposed to spur further investigation. In this case, debate has been closed down rather than opened up. Journals that might have been thought to be independent of pharmaceutical company influence have “managed” not to publish articles and the appropriate scientific forums have “managed” not to debate the issues."

This sounds eerily familiar with regard to another domain in biomedicine - health IT.

Allow me to substitute a few words:

"On the face of it, the investigation of possible hazards posed by clinical information technology does not seem to have followed the conventional dynamics of science, where anomalies in the data are supposed to spur further investigation. In this case, debate has been closed down rather than opened up. Journals that might have been thought to be independent of information technology company influence have “managed” not to publish articles and the appropriate scientific forums have “managed” not to debate the issues."


Only recently do I note this phenomenon starting to lift. I've aggregated a number of reports and articles of recent years that take a critical-thinking attitude about health IT safety, efficacy, and sociopolitical matters such as here and here. I intend to broaden and deepen this aggregation to make it more comprehensive in the coming months.

This is a somewhat personal exercise as my relative was severely injured in 2010 by health IT interference with clinician communications.

However, it's also a professional endeavor. I will be presenting at a regional health care attorney's meeting in a few months on health IT risks. In my talk I will undoubtedly recommend aggressive litigation when HIT is implicated in patient injury, and investigations of potential contributions of health IT to medical malpractice when not readily apparent. I am not alone in this stance.

Several weeks ago I also asked the IOM Committee on Patient Safety and Health Information Technology to be allowed to present my mother's case at some point, a tragic and ironic example of a family member of a physician and Medical Informatics specialist (not just a layperson) injured as a result of health IT. I have not yet received a reply.

Evaluation of health IT will likely become more than an academic endeavor in the next few years. Those engaged in it might find themselves called as expert witnesses - or as defendants.

I see a legal storm approaching in health IT. This is a domain I am somewhat familiar with, as pre-informatics I was a medical officer in public transit making safety-related medical decisions on transit authority/DOT-related matters, at a time when nationally-mandated random drug testing in the industry had recently begun. The legal implications of such work can be quite unexpected - and profound, especially when interfered with by outside sources with conflict of interest (e.g., labor unions). Train wrecks - literally, accompanied by litigation through the roof.

To those involved in health IT, this is not a scientific opinion, and thus feel free to ignore it.

At your own peril IMO.

-- SS