Thursday, October 21, 2010

History Repeats, and Repeats: McKesson Settles

Here a settlement, there a settlement, everywhere a settlement....  And the march continues, as reported by the New London (CT) Day,
Pharmaceutical distributor McKesson Corp. will pay Connecticut $15 million for 'illegal and deceptive practices' that inflated drug costs for both individual consumers and state-funded programs, Attorney General Richard Blumenthal announced Tuesday.

The settlement calls for $9 million to be used for reimbursing Connecticut's Medicaid program and $3 million for ConnPace, a state program that provides drug coverage for seniors. In addition, $2.3 million will be paid as a civil penalty and $700,000 will go into the state's drug-assistance program for AIDS patients.

Blumenthal had charged in a lawsuit that San Francisco-based McKesson conspired with First DataBank - which publishes average wholesale prices of drugs - to increase the amounts Connecticut paid for brand-name remedies by about 25 percent over usual wholesale costs. Previously, the prices had been 20 percent above wholesale.

McKesson used the increase to sweeten the 'spread' - the amount of profit - that could be taken by pharmacies, thereby increasing its share of the market, he said.

'McKesson manipulated the drug market - conspiring to inflate costs for hundreds of drugs and exploiting public programs that serve our most vulnerable citizens,' Blumenthal said in a statement.

Having been posting on this blog for nearly five years, it is interesting that viewed over time, patterns emerge suggesting that certain organizations have chronic problems with bad behavior. Last year, we noted that a former McKesson Chairman of the Board was convicted of five counts of securities fraud arising from actions occurring in the early part of the 21st century. Five former McKesson executives had already pleaded guilty to related crimes. Last year, Bloomberg called this scandal "one of the largest white-collar crimes."

This pattern may go back a lot longer that the turn of the last century.  Amazingly, the same company, McKesson, was involved in one of the biggest frauds of the great depression era. From the Wikipedia entry,
The McKesson & Robbins, Inc. scandal of 1938 was one of the major financial scandals of the 20th century. The company McKesson & Robbins, Inc. (now McKesson Corporation) had been taken over in 1925 by Phillip Musica, who had previously used Adelphia Pharmaceutical Manufacturing Company as a front for bootlegging operations. Musica, a twice-convicted felon, used assumed names to conceal his true identity in taking control of the two companies: Frank D. Costa at Adelphia Pharmaceutical and F. Donald Coster at McKesson & Robbins. Although he was successful in expanding the company’s legitimate business operations, Musica recruited three of his brothers, also working under assumed names, one outside the company and two inside it, to generate bogus sales documentation and to pay commissions to a shell distribution company under their control. Eventually, McKesson & Robbins treasurer Julian Thompson discovered the distribution company was bogus. It was eventually determined that about $20 million of the $87 million in assets on the company’s balance sheet were phony.

In December 1938, the Securities and Exchange Commission (SEC) opened an investigation and Musica was arrested. Only after he was booked, fingerprinted and released on bond did the authorities realize that 'Coster' was in reality Musica. His bond was revoked and he committed suicide before he could be rearrested.

The McKesson & Robbins scandal led to major corporate governance and auditing reforms. The SEC required that public companies have audit committees of 'outside' directors and that the appointment of auditors be approved by the shareholders. The American Institute of Accountants (now the American Institute of Certified Public Accountants) adopted audit standards requiring that auditors verify accounts receivable and inventory.

So I guess in some ways it should not be a surprise that a company involved in one of the biggest financial scandals of the depression era, and then one of the biggest white-collar crime of the early 21st century, should now be involved in a comparatively small settlement involving allegations of over-charges for drugs.

Given that in this latest case, the settlement was small, and there were no negative consequences for any individual who authorized, directed, or implemented the alleged market manipulation, it seems doubtful that it will have any lasting effect on corporate leadership of the corporate culture.

McKesson's long and chequered history suggests some sort of chronic affliction of its corporate culture.  It also suggests a rationale for requiring heath care organizations to have ongoing, active organizational ethics policies.  

Medical data breach of the week - but your EMR data is secure, trust us, we're IT experts

I have written frequently about the pipe dream of secure national electronic medical records, such as in February 2010 at my post "Networked EMR's and Healthcare Information Security: Practical When Massive IT Security Breaches Continue?", my post "Networked, Interoperable, Secure National Medical Records a Castle in the Sky?", as well as "Operation Aurora And a Widespread Reluctance to Discuss IT Flaws: Is Universal Healthcare IT Really a Good Idea in 2010?" and others.

I was also quoted on July 30, 2010, in a Philadelphia Inquirer story about the theft of a laptop computer with data on 21,000 patients from Thomas Jefferson University Hospital here, and also interviewed August 2 by local NPR station WHYY-91FM, where I stated:

"There is almost no excuse for unencrypted data to be sitting on any computer at a hospital or any organization," said Scot Silverstein, a Drexel University expert on health-information technology.

In the latest health-data-on-computer-theft-of-the-week, the Inquirer ran this story today about a local theft ten times as large as July's:

Medical-data breach said to be major
A computer flash drive containing the names, addresses, and personal health information of 280,000 people is missing - one of the largest recent security breaches of personal health data in the nation.

"We deeply regret this unfortunate incident," said Jay Feldstein, the president of the two affiliated Philadelphia companies, Keystone Mercy Health Plan and AmeriHealth Mercy Health Plan.

The breach, which involves the records of Medicaid recipients, is the first such Medicaid data breach in Pennsylvania since at least 1997, according to the state's Department of Welfare, which has oversight.

There is little more I can add to my prior postings on this issue except the words of privacy advocate, psychiatrist Dr. Deborah Peel:

The security failure, one of the several largest in nearly two years, involves nearly two-thirds of the insurers' subscribers. It became known only after The Inquirer requested information Tuesday evening. The insurers said the drive was missing from the corporate offices on Stevens Drive in Southwest Philadelphia. It noted that the same flash drive was used at community health fairs.

"That seems grossly irresponsible," said Dr. Deborah Peel, a Texas psychiatrist who heads Patient Privacy Rights, an advocacy group.

"Why would you be hauling around private patient information to a health fair," she said. "I can't imagine what they were thinking, taking this data out of a locked room at company headquarters.

"What's tragic is that this is a particularly vulnerable group of people," Peel said. "They tend to be vulnerable to identity theft, vulnerable to discrimination." Medicaid recipients are low-income people.


As to encryption (a built-in feature of the upper tier versions of Windows and of Mac OS X):

They [the companies] would not comment on the riskiness of taking the drive to health fairs, nor would they say whether the data on the drive was encrypted.

Highly likely translation: no.

The companies issued an apology:

"At Keystone Mercy Health Plan and AmeriHealth Mercy Health Plan, our number one priority is our members. Since reporting this unfortunate incident to the Department of Public Welfare, we have actively and responsibly executed a multifaceted plan to inform those affected, while also evaluating and enhancing our security measures to ensure this does not happen again."

[Did any employee have their "privileges revoked" -- the medical term of art for a physician who is 'fired' -- I wonder? - ed.]

Perhaps the executives in charge of this data, as well as the IT department, should read stories like the aforementioned July 30, 2010 story.

However, I fear there are those who are ineducable or hopelessly irresponsible when it comes to acting cautiously and responsibly regarding computer-based medical information, in the poorly bounded, complex, unpredictable world of healthcare.

That is not to even mention deliberate theft for personal gain.

This is why the dream of
secure national electronic medical records seems a pipe dream for the foreseeable future.

-- SS

10/23 Addendum

in an updated story, the Inquirer reports the data was indeed unencrypted, although the companies claimed an encryption project was in progress.