Showing posts with label healthcare IT risks. Show all posts
Showing posts with label healthcare IT risks. Show all posts

Pennsylvania Patient Safety Authority: The Role of the Electronic Health Record in Patient Safety Events

The Pennsylvania Patient Safety Authority has released a report "The Role of the Electronic Health Record in Patient Safety Events."  A press release is at this link, and the full report in PDF is at this link.  In the report, the Pennsylvania Patient Safety Authority analyzed reports of EHR-related events from a state database of reported medical errors and identified several major themes.

The report was prepared with the assistance of Erin Sparnon, Senior Patient Safety Analyst the ECRI Institute near Philadelphia.  The ECRI Institute is an independent organization renowned for its safety testing of medical technologies and reporting on same, and that "researches the best approaches to improving the safety, quality, and cost-effectiveness of patient care."  I've mentioned it and its bylaws in this blog in the past as a model for independent, unbiased testing and reporting of healthcare techonlogies.

Regarding the Patient Safety Authority:


The Pennsylvania Patient Safety Authority was established under Act 13 of 2002, the Medical Care Availability and Reduction of Error ("Mcare") Act, as an independent state agency. It operates under an 11-member Board of Directors, six appointed by the Governor and four appointed by the Senate and House leadership. The eleventh member is a physician appointed by the Governor as Board Chair.  Current membership includes three physicians, three attorneys, three nurses, a pharmacist and a non-healthcare worker.

The Authority is charged with taking steps to reduce and eliminate medical errors by identifying problems and recommending solutions that promote patient safety in hospitals, ambulatory surgical facilities, birthing centers and certain abortion facilities. Under Act 13 of 2002, these facilities  must report what the Act defines as "Serious Events" and "Incidents" to the Authority.

The Authority maintains a database of serious events and incidents:

Consistent with Act 13 of 2002, the Authority developed the Pennsylvania Patient Safety Reporting System (PA-PSRS, pronounced "PAY-sirs"), a confidential web-based system that both receives and analyzes reports of what the Act calls Serious Events (actual occurrences) and Incidents (so-called "near-misses").

Cutting right to the chase, the paper's summary:

As adoption of health information technology solutions like electronic health records (EHRs) has increased across the United States, increasing attention is being paid to the safety and risk profile of these technologies. However, several groups have called out a lack of available safety data as a major challenge to assessing EHR safety, and this study was performed to inform the field about the types of EHR-related errors and problems reported to the Pennsylvania Patient Safety Authority and to serve as a basis for further study. Authority analysts queried the Pennsylvania Patient Safety Reporting System for reports related to EHR technologies and performed an exploratory analysis of 3,099 reports using a previously published classification structure specific to health information technology. The majority of EHR-related reports involved errors in human data entry, such as entry of “wrong” data or the failure to enter data, and a few reports indicated technical failures on the part of the EHR system. This may reflect the clinical mindset of frontline caregivers who report events to the Authority.

Results:

... Reported events were categorized by their reporter-selected harm score (see Table 1). Of the 3,099 EHR-related events, 2,763 (89%) were reported as “event, no harm” (e.g., an error did occur but there was no adverse outcome for the patient) [a risk best avoided to start with, because luck runs out eventually - ed.], and 320 (10%) were reported as “unsafe conditions,” which did not result in a harmful event. Fifteen reports involved temporary harm to the patient due to the following: entering wrong medication data (n = 6), administering the wrong medication (n = 3), ignoring a documented allergy (n = 2), failure to enter lab tests (n = 2), and failure to document (n = 2). Only one event report, related to a failure to properly document an allergy, involved significant harm.

A significant "study limitations" section was included that addressed: 

  • Issues regarding reporting statutes of the PA-PSRS errors database; 
  • lack of awareness of EHRs as a potential contributing factor to an error;
  • limitations of narrative reporting affecting both the types of reports queried and the tags applied (the study used textual data mining methodolgies);
  • query design of the study; and
  • the need for further refinement of the machine learning tool used in creating the working dataset, which may have missed relevant cases.

Some of these impediments to knowing the magnitude of extant HIT issues are also present in the 2008 Joint Commission Sentinel Events Alert on HIT, the 2010 FDA internal memorandum on HIT Safety, and the 2011 IOM report on the same topic.

(The IOM report specifically observed that the "barriers to generating evidence pose unacceptable risks to safety.") 

The major obstacle to this study in my view, though, was the nature of the dataset.  The database is for general reporting of medical errors, and it contains no specific fields or reminders about EHRs or the known ways in which they can contribute to, or cause, medical mistakes.  

The attempt was made, as acknowledged in the study, to glean information about EHR-related events from, in large part, textual analysis of narrative in the hopes that the reporter recognized the role of IT, and reported it using terms that could be detected by the search algorithms.  In other words, the data was not "purposed" for this type of study.  

It is axiomatic that one cannot find data that is simply not present, no matter how fancy the search algorithm.  Further, passive analysis of clinical IT risk/harms data in an industry where lack of knowledge of causation and misconceptions abound will produce only partial results that suggest further study is needed, and not give an indicator of just how incomplete the results are.

Thus, this cautionary statement was made in the new PA Patient Safety Authority report:

"Although the vast majority of EHR-related reports did not document actual harm to the patient, analysts believe that further study of EHR-related near misses and close calls is warranted as a proactive measure." 

My comments:

The report is welcome.

The most important part of the paper, I point out, is the “Limitations” section. FDA, IOM and others have made similar observations – we don’t know the true magnitude of the problem due to systematic limitations of the available data. 

Therefore, at best what is available must be deemed as risk management-relevant case reports, a “red flag” that could represent (using the words of FDA CDRH director Jeffrey Shuren regarding HIT safety), the tip of the iceberg.

It is imperative far more work be done in post-market surveillance as this technology is deployed nationally and internationally.  This is to ensure that good health IT (GHIT) prevails and bad health IT (BHIT) is either remediated or removed from the marketplace.  I had defined those in other writings as follows:

Good Health IT ("GHIT") is defined as IT that provides a good user experience, enhances cognitive function, puts essential information as effortlessly as possible into the physician’s hands, keeps eHealthinformation secure, protects patient privacy and facilitates better practice of medicine and better outcomes. 

Bad Health IT ("BHIT") is defined as IT that is ill-suited to purpose, hard to use, unreliable, loses data or provides incorrect data, causes cognitive overload, slows rather than facilitates users, lacks appropriate alerts, creates the need for hypervigilance (i.e., towards avoiding IT-related mishaps) that increases stress, is lacking in security, compromises patient privacy or otherwise demonstrates suboptimal design and/or implementation. 

An additional major factor that also contributes to lack of knowledge of EHR-related adverse events is hospital reporting non-compliance. For instance, I know of cases from my own legal consulting work and personal experience that I would have expected to appear in the database, but apparently do not.

But don’t take it from me alone. Here is PA Patient Safety Authority Board Member Cliff Rieders, Esq. on this.

From “Hospitals Are Not Reporting Errors as Required by Law, Phila. Inquirer”, pg. 4,http://articles.philly.com/2008-09-12/news/24991423_1_report-medical-mistakes-new-jersey-hospital-association-medication-safety:
  

... Hospitals don’t report serious events if patients have been warned of the possibility of them in consent forms, said Clifford Rieders, a trial lawyer and member of the Patient Safety Authority’s board.

He said he thought one reason many hospitals don’t want to report serious events is that the law also requires that patients be informed in writing within a week of such problems. So, if a hospital doesn’t report a problem, it doesn’t have to send the patient that letter. [Thus reducing risk of litigation, and, incidentally, potentially infringing on patients' rights to legal recourse - ed.]

Rieders says the agency has allowed hospitals to determine for themselves what constitutes a serious event and the agency has failed to come up with a solid definition in six years.

Fixing this “is not a priority,” he added.

This coincides with my own personal experience precisely.  In a case where my relative was permanently injured as a result of EHR-related medication error, and then died of the injuries, I never received the required report in writing from the hospital.  I also do not believe the case was reported to the Safety Authority, at least not as IT-related.

I suspect the true rates of EHR-related close calls, reversible injuries, permanent injuries and deaths is significantly higher than the limited data available suggests. That data is merely a red flag that much more education, stringent reporting requirements,  templates of known causes of error, and enforcement are needed.  (An April 2010  "thought experiment" on this issue I wrote about at "If The Benefits Of Healthcare IT Can Be Guesstimated, So Can And Should The Dangers" certainly suggested as much.)

Slides where I made those types of recommendations to the Patient Safety Authority, at a presentation I gave in July 2012 at their invitation, are at http://www.ischool.drexel.edu/faculty/ssilverstein/PA_patient_safety_Jul2012.ppt

A major concern I have is that the HIT industry will use this new report in a manner that ignores its limitations.

(Disclosure: I was an invited reviewer of this new PPSA report.)

-- SS 

Addendum Dec. 13:   

Also worth review is "Patient Safety Problems Associated with Heathcare Information Technology: an Analysis of Adverse Events Reported to the US Food and Drug Administration", Magrabi, Ong, Runciman, and Coiera, AMIA Annu Symp Proc. 2011.  

Data here came from FDA's voluntary (i.e., also tip of the iceberg) Manufacturer and User Facility Device Experience (MAUDE) database.  Ironically, the study was done in Australia using Australian grant funds.

-- SS

Cybernetik Über Alles Again: HHS and Sebelius - Hospitals And Their Computers Have More Rights Than Patients

A Nov. 29, 2012 New York Times article by Reed Abelson entitled "Medicare Is Faulted on Shift to Electronic Records" observes that:

The conversion to electronic medical records — a critical piece of the Obama administration’s plan for health care reform — is “vulnerable” to fraud and abuse because of the failure of Medicare officials to develop appropriate safeguards, according to a sharply critical report to be issued Thursday by federal investigators [the report from HHS OIG is here - ed.] ... Medicare, which is charged with managing the incentive program that encourages the adoption of electronic records, has failed to put in place adequate safeguards to ensure that information being provided by hospitals and doctors about their electronic records systems is accurate. To qualify for the incentive payments, doctors and hospitals must demonstrate that the systems lead to better patient care, meeting a so-called meaningful use standard by, for example, checking for harmful drug interactions. [I note that meeting EHR "meaningful use" standards does not necessarily signify better care; the "standards" are experimental - ed.]

Hospitals and doctors are lying about their EHR efforts, in order to gain incentive payments, it seems.

In an article "IG says program is 'vulnerable' to abuse, better oversight needed", Fred Schulte at the Center for Public Integrity notes:

... the Centers for Medicare and Medicaid Services has since paid out more than $3.6 billion to medical professionals who made the switch without verifying they are meeting the required quality goals, according to a new federal audit to be released today

Observes the CEO of the American Health Information Management Association:

“We’ve gone from the horse and buggy to the Model T, and we don’t know the rules of the road. Now we’ve had a big car pileup,” said Lynne Thomas Gordon, the chief executive of the American Health Information Management Association, a trade group in Chicago. 

More Horse and Buggy than Model T.  At least the Model T was reasonably dependable. 

Also mentioned is this:

House Republicans echoed these concerns in early October in a letter to Kathleen Sebelius, secretary of health and human services. Citing the Times article, they called for suspending the incentive program until concerns about standardization had been resolved. “The top House policy makers on health care are concerned that H.H.S. is squandering taxpayer dollars by asking little of providers in return for incentive payments,” said a statement issued at the same time by the Republicans, who are likely to seize on the latest inspector general report as further evidence of lax oversight. Republicans have said they will continue to monitor the program.

In her letter in response, which has not been made public, Ms. Sebelius dismissed the idea of suspending the incentive program, arguing that it “would be profoundly unfair to the hospitals and eligible professionals that have invested billions of dollars and devoted countless hours of work to purchase and install systems and educate staff.”


I was taught "first, do no harm."  Fairness to patients injured and killed by this technology in its present "Horse and Buggy" state (buggy being a particularly apropos term) seems not a matter of particularly high concern to HHS.   A suspension of incentives would slow the adoption rate down, necessary in order to "get the bugs" out of the technology before mass deployment and develop safety, validation and surveillance standards (currently non-existent), as I wrote in my Oct. 24, 2012 "Letter To U.S. Senators and Representatives Who've Sought HHS Input On EHR Problems."

This is despite the fact that FDA, IOM and others have indicated the level of harm is not known, due to systematic impediments to diffusion of that knowledge (see IOM statements in the midsection of my post on health information technology hyper-enthusiasm at this link, and an internal FDA memo on HIT safety at this link). 

HHS seems to care not about health and human services, or at best to be severely misguided.  "Cybernetik Über Alles" seems their current credo.

-- SS

Bad Health IT -Yet Another Health IT 'Glitch' - Potential Image Loss in GE Centricity PACS; ECRI Again Reports Health IT a Top Ten Hospital Risk

From my definition of bad health IT (BHIT) at this link:

Bad Health IT ("BHIT") is defined as IT that is ill-suited to purpose, hard to use, unreliable, loses data or provides incorrect data, causes cognitive overload, slows rather than facilitates users, lacks appropriate alerts, creates the need for hypervigilance (i.e., towards avoiding IT-related mishaps) that increases stress, is lacking in security, compromises patient privacy or otherwise demonstrates suboptimal design and/or implementation.  

Considering the problem of lost data (lost x-rays) that affects not one, but two versions ("versions 3.x and 4.x and higher") of a common GE PACS (radiology image management) system, as in the attached memo to hospital radiology and IT executives, one might ask:

  • How long has this been going on before this 'glitch' was discovered? 
  • What validation and safety testing does GE use before releasing its health IT to production? 
  • Why was it discovered in several successive versions of PACS systems being used on live patients, instead of in laboratory testing?
      • How many delayed diagnoses, injuries and/or deaths might have occurred as a result of this "disappearing image" bug?
      • What is the likelihood this "workaround" will be uniformly adopted in short order?  
      • What levels of hypervigilance, stress and increased likelihood of error will this temporary "workaround" engender?
      • When will it be fixed in all implementations worldwide?


         Beware disappearing x-rays.  Make sure every system user performs this workaround, too (click to enlarge).


        Page 2 (click to enlarge)

        It's not as if missing x-rays are a trivial matter.  One routine x-ray lost to followup resulted in the needless and rather horrible death of an infant, and a $1.5 million settlement, as at the June 2011 link "Babies' deaths spotlight safety risks linked to computerized systems" (case #2).

        Patient safety is being compromised.

        Lack of regulation of health IT, and lack of reporting and accountability, needless to say, are major contributors to the prevalence of BHIT.

        I also note for several years running, including in the latest report of 2013, the ECRI Institute (an independent tester of healthcare technology) reports health IT-related problems as among the top ten technology problems in hospitals (link to report):

        ...Five of the top 10 hazards explained in ECRI Institute’s [2013] report are:

            1.  Alarm hazards
            2.  Medication administration errors using infusion pumps
            3.  Unnecessary radiation exposures and radiation burns during diagnostic radiology
                 procedures
            4.  Patient/data mismatches in EHRs and other health IT (HIT) systems
            5.  Interoperability failures with medical devices and health IT systems

        Three of the ten topics on the 2013 list are directly associated with the still-maturing [i.e., experimental - ed.] health IT field where the interplay between complexity and effectiveness and potential harm is most evident; several of the other topics are peripherally related to HIT issues.

        “The inherent complexity of HIT-related medical technologies, their potential to introduce new failure modes, and the possibility that such failures will affect many patients before being noticed—combined with federal incentives to meet Meaningful Use requirements—leads us to encourage healthcare facilities to pay particular attention to health IT when prioritizing their safety initiatives for 2013,” says James P. Keller, Jr., vice president, health technology evaluation and safety, ECRI Institute.

        The hazards included in the 2013 list, published in the November 2012 issue of ECRI Institute’s Health Devices journal, met one or all of the following criteria: it has resulted in injury or death; it has occurred frequently; it can affect a large number of individuals; it is difficult to recognize; it’s had high-profile, widespread news coverage.

        -- SS

        Healthcare IT Transparency Could Stand Some Improvement

        Transparency in the health IT sector is akin to the transparency of Pb (lead).

        The following report comes from the FDA Maude (Manufacturer and User Facility Device Experience) voluntary-reporting database, reported by a (likely unhappy) biomedical engineer a month after the "incident" - the nature of which is deliberately kept hidden.  This is regarding the PICIS "Pulsecheck" EHR for emergency departments:

        Report Date     05/14/2010

        PICIS INC. CARESUITE ED PULSECHECK S/W, TRANSMISSION & STORAGE PATIENT DATA
        Event Type:  Other
        Patient Outcome:  Required Intervention

        Event Description

        The customer has reported a patient incident that has prompted a review of their internal process and possible issues surrounding the incident. The customer report alleges the involvement of picis' ed (emergency dept. ) electronic health record application, whereby, duplicate results were received by the picis ehr application from an enterprise info system, which, when displayed in their entirety may have contributed to some degree of confusion for the treating physician - the context of which the customer has declined to clarify any further.  [What in the world? -ed.] At this time, we have been informed by the customer that they are restricted by senior leadership from disclosing any specific details regarding the patient's status, the specific type of result or evidence of application performance to support picis' investigation.

        "Restricted by senior leadership from disclosing any specific details regarding the patient's status, the specific type of result or evidence of application performance to support Picis' investigation?"

        That is perverse on its face, and probably in violation of Joint Commission safety standards on reporting of incidents that could affect other organizations.


        Manufacturer Narrative

        Picis' investigation into the reported incident is based on a limited exchange of info with the customer, as well as our internal review of the application design and current configuration in use at the reporting site. Review of configuration files, existing system build at the client site, interface specification documents and previous customer communications demonstrate that the customer implemented and accepted the picis edis in 2008. During this process, the picis edis system was configured to display all results sent from the customer's enterprise system rather than configuring the results display in 'overwrite' mode. Prior to acceptance, an investigation by picis and the client revealed that it was the sending system, sending multiple duplicate results messages [great quality - ed.] and a request was made by the customer of that enterprise vendor [I can only wonder who that was - ed.] to investigate. However, due to the enterprise system's protocol for 'add on' tests, it was not possible to utilize the 'overwrite' configuration due to the risk of filtering out unique results and subsequently not presenting the clinicians with important info. Therefore, the customer elected to have all results displayed.

        A workaround that apparently, from the limited information provided, led to physician confusion..."the context of which the customer had", not very helpfully, "declined to clarify any further."

        Hospitals also are required to have add'l safeguards in place for the handling of critical results including expedited reporting of critical results with a licensed responsible caregiver rather than relying solely on standard results reporting processes (joint commission national patient safety goal 02. 03. 01).

        This is not a resounding statement of confidence in health IT...

        The customer is currently working with a 3rd party integration consultant to improve the handling of results sent to picis' electronic health record application. We are providing support as it is requested. At this time, no corrective action is needed. 

        The "senior leadership" that withheld details was protecting what, exactly?  Money and contracts, perhaps; conflicts of interest, possibly ... but not patients.

        All I can say is:

        Imagine if this was a report on a new drug suspected of harming people. 

        What in heaven's name was going on here?

        As I've written many times, and as illustrated by this MAUDE report, the health IT industry must first be transformed into one of evidence-driven IT practices and transparency before anyone touting its products has any business even speaking about the technology "transforming medicine."

        -- SS

        Good HIT, Bad HIT, HIMSS And Reckless Technology Advocacy: Will This Hurt President Obama?

        HIMSS, the Health Information Systems Management Society, is the large vendor trade group representing healthcare IT sellers.

        At the HIMSS blog entitled "Health IT is an essential element to transform the Nation’s healthcare system" (link), writes this with regard to the House  letter to HHS Secretary Sebelius asking her to suspend payments for the EHR Incentive Payments authorized in the American Recovery & Reinvestment Act of 2009:

        HIMSS opposes halting the Meaningful Use EHR Incentive Program. Health IT is an essential, foundational element of any meaningful transformation of the Nation’s healthcare delivery system. 

        (Of course, not mentioned is "transformed" into what, exactly; this utopian ideation is a topic for another time.)

        A chart is then presented as to "how US civilian hospitals have, since the first incentive payments were made in second quarter, 2011, matured in their use of health IT."  Then this statement is made:

        Healthcare providers are adopting certified EHRs and using them for meaningful purposes; thus, achieving Congressional intent to improve the quality, safety, and cost-effectiveness of care in U.S.

        Really?  (See my Feb. 2012 post "Hospitals and Doctors Use Health IT at Their Own Risk - Even if Certified.")

        This non-evidence based, amoral advocacy by HIMSS for health IT may cost the President the November election.  HIMSS has beguiled the president into similar unquestioning advocacy for the technology in its present form, which his opponents are now (rightfully) seizing upon as in the House letter.

        The reckless mistakes made by HIMSS and their advocates include these two:

        1.   The unquestioned belief that this expensive technology would save billions of dollars in healthcare costs, instead of depleting precious healthcare resources better spent on, say, improvement of healthcare services for the poor.

        2.  More importantly, the appallingly naïve belief that any health IT is good health IT, and that any health IT is only capable of good, not bad.

        HIMSS has thus failed to recognize - or perhaps worse, recognized but recklessly ignored - the profound difference between good health IT (GHIT) and bad health IT (BHIT).

        As I defined at my teaching site on Medical Informatics:

        Good Health IT ("GHIT") is defined as IT that provides a good user experience, enhances cognitive function, puts essential information as effortlessly as possible into the physician’s hands, keeps eHealth information secure, protects patient privacy and facilitates better practice of medicine and better outcomes.

        Ba
        d Health IT ("BHIT") is defined as IT that is ill-suited to purpose, hard to use, unreliable, loses data or provides incorrect data, causes cognitive overload, slows rather than facilitates users, lacks appropriate alerts, creates the need for hypervigilance (i.e., towards avoiding IT-related mishaps) that increases stress, is lacking in security, compromises patient privacy or otherwise demonstrates suboptimal design and/or implementation.  

        I am an advocate of the former, and an opponent of the latter.

        Bad health IT is prevalent in 2012 due to lack of meaningful quality control, software validation, usability standards and testing, and regulation of any type - a situation HIMSS long favored.   (The failed National Programme for HIT [NPfIT] in the NHS learned this the hard way, as will Australians needing emergency care, I predict.)

        Put bluntly, in the end BHIT maims and kills patients, squanders precious healthcare resources, and drains the treasury into IT industry pockets (see my Oct. 3, 2012 post "Honesty and Good Sense on Electronic Medical Records From Down Under" and this query link on health IT risks). 

        Further, the failure to recognize that the technology's downsides need to be understood and remediated before national deployment occurs and under controlled conditions, not after (which uses patients as non-consenting experimental subjects for software debugging), speaks to gross corporate negligence on the part of HIMSS.  It's not as if they did not have advance warning of all of healthcare IT's deficiencies. 

        BHIT also permits record alterations after the fact that may be to conceal medical error.  I am aware of numerous instances of such alterations, fortunately caught by critical-thinking, detail-minded attorneys.  However, like health IT harms, the incidences of known alteration attempts likely reflect the "tip of the iceberg."

        HIMSS and its fellow travelers have thus led this administration down the Garden Path of health IT perdition.

        I warned of this in a Feb. 18, 2009 Wall Street Journal letter to the editor:

        Dear Wall Street Journal:

        You observe that the true political goal is socialized medicine facilitated by health care information technology. You note that the public is being deceived, as the rules behind this takeover were stealthily inserted in the stimulus bill.

        I have a different view on who is deceiving whom. In fact, it is the government that has been deceived by the HIT industry and its pundits. Stated directly, the administration is deluded about the true difficulty of making large-scale health IT work. The beneficiaries will largely be the IT industry and IT management consultants.

        For £12.7 billion the U.K., which already has socialized medicine, still does not have a working national HIT system, but instead has a major IT quagmire, some of it caused by U.S. HIT vendors. [That project, the NPfIT in the NHS, has now been abandoned - ed.]

        HIT (with a few exceptions) is largely a disaster. I'm far more concerned about a mega-expensive IT misadventure than an IT-empowered takeover of medicine.

        The stimulus bill, to its credit, recognizes the need for research on improving HIT. However this is a tool to facilitate clinical care, not a cybernetic miracle to revolutionize medicine. The government has bought the IT magic bullet exuberance hook, line and sinker.

        I can only hope patients get something worthwhile for the $20 billion.


        Scot Silverstein, MD

        Mr. President, again, quite bluntly, the health IT industry took you for a ride, and the damage is done and is continuing due to lack of any meaningful health IT post market surveillance.   (As I wrote here, the untoward results have already been used against the current administration, with more perhaps to follow.)

        In the U.S. we have the 1938 Federal Food, Drug, and Cosmetic Act (FD&C Act) in place:

        The introduction of this act was influenced by the death of more than 100 patients due to a sulfanilamide medication where diethylene glycol was used to dissolve the drug and make a liquid form.  See Elixir Sulfanilamide disaster. It replaced the earlier Pure Food and Drug Act of 1906.

        It should be honored, not ignored via special accommodation to the health IT industry and its trade group.

        HITECH also needs to be put in dormancy until the problems with these unregulated medical devices get worked out in relatively small, controlled settings to minimize risk, with patient informed consent.  This is in accord with human rights documents dating at least to the Nuremberg Code, as in any new, experimental or partly-experimental medical device, pharmaceutical, or therapy.

        -- SS
         

        House Ways And Means, and Energy and Commerce, Note EHRs Not What They Were Made Out To Be, Calls For HITECH Moratorium

        I have called numerous times for a moratorium on ambitious national health IT programs.  See 2008 and 2009 posts here and here for example.  My calls are due to the prevalence of bad health IT (BHIT) in 2012, hopelessly deficient if not deranged talent management practices (especially when compared to clinical medicine) in the health IT industry, and complete lack of regulation, validation and quality control of these potentially harmful medical devices. 

        I also called the HITECH stimulus act in its present form social policy malpractice.  (See my Sept. 2012 post "At Risk in the Computerized Hospital: The HITECH Act as Social Policy Malpractice, and Passivity of Medical Professional".)

        Congress is starting to catch on:


        Letter from House Ways and Means, and Energy & Commerce, to Secretary Sebelius of HHS.  Click here to download.

        The letter to HHS secretary Sebelius is from Congressmen Dave Camp (Chairman, Ways and Means), Wally Herger (Chariman, Ways and Means Subcommittee on Health), Fred Upton (Chairman, Energy and Commerce) and Joe Pitts (Chairman, Energy and Commerce Subcommittee on Health).

        In the letter the following is noted:

        Dear Secretary Sebelius:

        We are writing to express serious concerns about the final Electronic Health Record (EHR) Stage 2 Meaningful Use rules recently issued by HHS and ONC.  We believe the Stage 2 rules are, in some respects, weaker than the proposed Stage 1 regulation released in 2009.  The results will be a less efficient system that squanders taxpayer dollars and does little, if anything, to improve outcomes for Medicare.

        The letter then notes that the "Stage 2 rules ask less of providers and do less for program efficiency" and that the Stage 2 rules fail to achieve comprehensive interoperability in the face of
        warnings that:

        ..".failure to set a date for certain interoperable standards would put as much as $35 billion in Medicare and taxpayer funds in the hands of providrrs who purchase and use EHR systems that are not interoperable."

        They note the Stage 2 rules fail to achieve interoperability in a timely manner and that "more than four and a half years and two final MU rules later, it is safe to say that we are no closer to interoperability in spite of the nearly $10 billion spent."

        A major reason for this, I believe, is regulatory capture by the IT industry as I outlined in my somewhat rhetorically-entitled posts "Health IT Vendor EPIC Caught Red-Handed: Ghostwriting And Using Customers as Stealth Lobbyists - Did ONC Ignore This?" and "Was EPIC successful in watering down the Meaningful Use Stage 2 Final Rule?"

        The House letter also notes:

        It is highly counterproductive for providers to have purchased EHR systems that "cannot talk with one another" and cannot perform basic functions because of the insufficient standards set by your agency.

        One of the critical "basic functions" is the note search capability upon which the vendors used their influence during the "public comments" period to have written out of existence, as in the above posts.  The influence became apparent due to serious public comment editing mistakes by customers.  One wonders what other episodes of vendor influence did not make it into the public spotlight.

        The house committee members also note:

        Perhaps not surprisingly, your EHR inventive program appears to be doing more harm than good.  A recent analysis of Medicare data by the New York Times explains the costly consequences.

        Unfortunately, the letter did not spotlight the excellent analysis done by the Center for Public Integrity and published before the NYT article ("Cracking the Codes" by Fred Schulte et al.)

        Finally, the letter calls for HHS to:

        ... Immediately suspend the distribution of incentive payments until your agency promulgates universal interoperable standards.  Such a move would also require a commensurate delay of penalties for providers who choose not to integrate HIT into their practice"  and to "significantly increase what's expected of Meaningful Users."


        It is unfortunate the letter seems to make the assumption that health IT in its present form, and the industry in its present state of anarchy, can produce good health IT (GHIT) that is safe and effective.  (As I've written, we need ease-of-use, reliability and safety - basic "operability" - before interoperability.)  Perhaps the congresspeople need to read my recent post "Honesty and Good Sense on Electronic Medical Records From Down Under".

        Financial issues are one major concern, but patient harm and death due to the disruptive influences of BHIT are, in fact in many respects more important.

        Finally, to those who would suggest a political angle to this letter (I note comments on sites such as on the Histalk blog that the authors are Republicans), I note that ONC was started in 2004 by George W. Bush, and that health IT has always had broad bi-partisan support.

        Reality in healthcare is more often than not apolitical, and injured and dead patients really don't care much about ideology.

        -- SS

        Honesty and Good Sense on Electronic Medical Records From Down Under

        Australians seem to not be as seduced by the Siren Song of cybernetic miracles as health IT leaders in the United States.

        It took an Australian computer scientist at U. Sydney to dissect and perform a detailed analysis of the internals of an American EHR system, the results of which were disturbing to say the least.  This was a task the American members of the American Medical Informatics Association (AMIA) should have taken on.  It's not as if they're unaware of clinical IT problems.

        It also seems to take a group of Australian researchers at the Univ. of New South Wales, the Australian Patient Safety Foundation, and the University of South Australia to perform a forensic analysis on U.S. data in the FDA's Manufacturer and User Facility Device Experience (MAUDE) database, instead of Americans themselves. 

        At least AMIA allowed the Australians the opportunuty to present their findings.

        In "Patient Safety Problems Associated with Heathcare Information Technology: an Analysis of Adverse Events Reported to the US Food and Drug Administration" (free fulltext at this link), AMIA Annual Symposium Proceedings 2011;2011:853-7 the Australian researchers including Medical Informaticist and critical thinker Dr. Enrico Coiera (see here) analyzed healthcare information technology (HIT) events associated with patient harm submitted to the MAUDE database:

        We downloaded all 899,768 reports that were submitted to MAUDE from January 2008 to July 2010 and searched for events using a broad definition of HIT as “hardware or software that is used to electronically create, maintain, analyse, store, receive, or otherwise aid in the diagnosis, cure, mitigation, treatment, or prevention of disease, and that is not an integral part of (1) an implantable device or (2) medical equipment.” We retrieved and classified 678 reports describing 436 unique events using a previously published methodology. Of the 436 HIT-related events that we examined, 11% (n=46) were associated with patient harm [this excludes the "near misses" - ed.] ... In this paper we specifically focus on examining the 46 events where HIT problems were associated with patient harm.

        These submissions are voluntary, and due to systematic, severe impediments to submissions as below, this data likely represents a very small fraction ("tip of the iceberg" per FDA itself, link) of the true incidence of these events.  See the addendum to this post "Systematic impediments to voluntary reporting of health IT risks."

        Summarizing the Australian researchers' findings (read the entire paper at the link above):


        Medication problems represented 41% of the events of these types:

        • Wrong patient
        • Wrong dose or overdose
        • Missed and delayed doses

        Clinical process problems
        represented 33% of the events:
        • Use errors in entering information ("use error" is an error due to poor and confusing design, as opposed to "user errors")
        • Poor functionality of CPOE and PACS

        Exposure to radiation occurred in 15% of the events

        Surgery problems occurred in 11% of the events.

        The authors recommended that "strategies to improve the safety of HIT should focus on designing safe user interfaces, integrated checks of key identifiers and decision support, and engineering safer clinical processes."

        Unfortunately, that does not appear to be occurring in the U.S. to any significant degree.  "Certification" of health IT to meet government criteria for financial incentives is unrelated to such measures and is in my view symptomatic of industry regulatory capture (see here and here).  The IOM itself has instituted a "watch and wait" policy, a likely unique special accommodation in current regulation of medical devices (see here).

        I reiterate this MAUDE data is voluntary and the impediments to its reporting systematic and severe.  See addendum to this post.

        In the category of good sense on electronic medical records, I note the following articles:

        Victoria aims for more open ICT strategy 

        Pulse+IT Magazine
        Kate McDonald
        02 October 2012

        The newly formed Victorian Information and Communications Technology Advisory Committee (VITAC) has released a draft strategy (PDF) describing how the state government should manage and use ICT to better provide government services.

        The strategy recommends that the government engage more closely with the ICT sector and move away from customised products in favour of existing market offerings.

        ... It recommends that the government engage with the ICT market early in the procurement lifecycle. “We will avoid being locked into single suppliers by favouring open standards and will be open to any qualified ICT provider regardless of size. Procurement of ICT services will be made more efficient.”

        The strategy should also provide guidance to agencies to move away from customised major ICT developments and use existing market offerings with little or no customisation instead.

        What this means is abandoning the approach of large, single-source (monolithic), proprietary clinical information systems from large health IT vendors that try to cover everything, in favor of smaller, open standards-based "best-of-breed" applications (from vendors of all sizes) that can be woven together to meet users' needs:

        The subsequent fallout from the Ombudsman's report led to the Victorian government cancelling several programs, including the $323 million HealthSMART program, an ambitious project to roll out common eHealth infrastructure throughout Victoria's public health services.

        This included implementing iSOFT's (now CSC) i.PM patient administration system and Cerner's clinical information system in its hospitals, as well as InterSystems' TrakCare platform for community health agencies.

        I note that another article in eHealth Insider mentions the same strategy in the UK, "Winchester switches off Cerner in ED":

        The Royal Hampshire County Hospital in Winchester has switched off Cerner Millennium in A&E and moved to Patient First.  The electronic patient record system will also be switched off for theatres and order communications at the old Winchester and Eastleigh Healthcare NHS Trust ... Basingstoke and North Hampshire was pursuing an alternative IT strategy, built around a 'best of breed' approach to building on its existing systems.

        The U.S. has yet to learn these lessons, and will likely repeat the same mistakes at the cost of hundreds of billions of dollars.

        Unfortunately, I have no answers.  I see no way to avoid it, considering the HITECH momentum that favors the large-vendor monolithic product model.

        -- SS

        --------------------------------------

        Addendum.  Systematic impediments to voluntary reporting of health IT risks:

        From the 2010 FDA internal memo on health IT risks:

        Limitations of the MAUDE search and final subset of MDRs include the following:

        1.  Not all H-IT safety issue MDRs can be captured due to limitations of reporting practices including:

        ... (a) Vast number of H-IT systems that interface with multiple medical devices currently assigned to multiple procodes making it difficult to identify specific procodes for H-IT safety issues;
        ... (b) Procode assignments are also affected by the ability of the reporter/contractor to correctly identify the event as a H-IT safety issue;
        ... (c) Correct identification by the reporter of the suspect device brand name is challenged by difficulties discerning the actual H-IT system versus the device it supports.

        2.  Due to incomplete information in the MDRs, it is difficult to unduplicate similar reports, potentially resulting in a higher number of reports than actual events.

        3.  Reported death and injury events may only be associated with the reported device but not necessarily attributed to the device.

        4.  Correct identification by the reporter of the manufacturer name is convoluted by the inability to discern the manufacturer of the actual H-IT system versus the device it supports.

        5.  The volume of MDR reporting to MAUDE may be impacted by a lack of understanding the reportability of H-IT safety issues and enforcement of such reporting.

        From the 2012 IOM report on health IT safety:

        ... While some studies suggest improvements in patient safety can be made, others have found no effect. Instances of health IT–associated harm have been reported. However, little published evidence could be found quantifying the magnitude of the risk.

        Several reasons health IT–related safety data are lacking include the
        absence of measures and a central repository (or linkages among decentralized repositories) to collect, analyze, and act on information related to safety of this technology. Another impediment to gathering safety data is contractual barriers (e.g., nondisclosure, confidentiality clauses) that can prevent users from sharing information about health IT–related adverse events. These barriers limit users’ abilities to share knowledge of risk-prone user interfaces, for instance through screenshots and descriptions of potentially unsafe processes. In addition, some vendors include language in their sales contracts and escape responsibility for errors or defects in their software (i.e., “hold harmless clauses”). The committee believes these types of contractual restrictions limit transparency, which significantly contributes to the gaps in knowledge of health IT–related patient safety risks. These barriers to generating evidence pose unacceptable risks to safety.
        … “For example, the number of patients who receive the correct medication in hospitals increases when these hospitals implement well-planned, robust computerized prescribing mechanisms and use barcoding systems. But even in these instances, the ability to generalize the results across the health care system may be limited. For other products— including electronic health records, which are being employed with more and more frequency— some studies find improvements in patient safety, while other studies find no effect.

        More worrisome, some case reports suggest that poorly designed health IT can create new hazards
        in the already complex delivery of care. Although the magnitude of the risk associated with health IT is not known, some examples illustrate the concerns. Dosing errors, failure to detect life-threatening illnesses, and delaying treatment due to poor human–computer interactions or loss of data have led to serious injury and death.”

        Not knowing the magnitude of the risks is an effect of the impediments, and does not represent a good environment for national implementation in my view.

        I also add "fear of medical malpractice litigation" to the lists above.

        -- SS

        HIMSS Senior Vice President on Medical Ethics: Ignore Health IT Downsides for the Greater Good

        The Health Information Management Systems Society (HIMSS) is the large health IT vendor trade group in the U.S.  At a Sept. 21, 2012 HIMSS blog post, John Casillas, Senior Vice President of HIMSS Financial-Centered Systems and HIMSS Medical Banking Project dismisses concerns about health IT with the refrain:

        ... To argue that the existence of something good for healthcare in many other ways, such as having the right information at the point of care when it’s needed, is actually bad because outliers use it to misrepresent claims activity is deeply flawed.

        Through the best use of health IT and management systems, we have the opportunity to improve the quality of care, reduce medical errors and increase patient safety. Don’t let the arguments of some cast a cloud over the critical importance and achievement of digitizing patient health records.

        Surely, no one can argue paper records are the path forward. Name one other industry where this is the case. I can’t.

        Let’s not let the errors of a few become the enemy of good.

        The ethics of these statements from a non-clinician are particularly perverse.

        The statement "Don’t let the arguments of some cast a cloud over the critical importance and achievement of digitizing patient health records" is particularly troubling.

        When those "some" include organizations such as FDA (see FDA Internal 2010 memo on HIT risks, link) and IOM's Committee on Patient Safety and Health Information Technology (see 2012 report on health IT safety, link) both stating that harms are definite but magnitude unknown due to systematic impediments to collecting the data, and the ECRI Institute having had health IT in its "top ten healthcare technology risks" for several years running, link, the dismissal of "clouds" is unethical on its face.

        These reports indicate that nobody knows if today's EHRs improve or worsen outcomes over good paper record systems or not.  The evidence is certainly conflicting (see here).

        It also means that the current hyper-enthusiasm to roll out this software nationwide in its present state could very likely be at the expense of the unfortunate patients who find themselves as roadkill on the way to the unregulated health IT utopia.

        That's not medicine, that's perverse human subjects experimentation without safeguards or consent.

        As a HC Renewal reader noted:

        Astounding hubris, although it does seem to be effective.  Such is PC hubris.  Who could ever call for reducing the budget of the NIH that is intended to improve health.  Has health improved?  No.

        So why does a group with spotty successes if not outright failure never get cut?  It’s not the results, it’s the mission that deserves the funding.  So it’s not the reality of HIT, it’s the promise, the mission, that gets the support.  Never mind the outcome, it’s bound to improve with the continued support of the mission.

        Is this HIMSS VP aware of these reports?  Does he even care?

        Does he believe patients harmed or killed as a result of bad health IT (and I know of a number of cases personally through my advocacy work, including, horribly, infants and the elderly) are gladly sacrificing themselves for the greater good of IT progress?

        It's difficult to draw any other conclusion from health IT excuses such as proffered, other than he and HIMSS simply don't care about unintended consequences of health IT.

        Regarding "Surely, no one can argue paper records are the path forward" - well, yes, I can.  (Not the path 'forward', but the path for now, at least, until health IT is debugged and its adoption and effects better understood).  And I did so argue, at my recent posts "Good Health IT v. Bad Health IT: Paper is Better Than The Latter" and "A Good Reason to Refuse Use of Today's EHR's in Your Health Care, and Demand Paper".  I wrote:

        I opine that the elephant in the living room of health IT discussions is that bad health IT is infrequently, if ever, made a major issue in healthcare policy discussions.

        I also opine that bad health IT is far worse, in terms of diluting and decreasing the quality and privacy of healthcare, than a very good or even average paper-based record-keeping and ordering system.  


        This is a simple concept, but I believe it needs to be stated explicitly. 

        A "path forward" that does not take into account these issues is the path forward of the hyper-enthusiastic technophile who either deliberately ignores or is blinded to technology's downsides, ethical issues, and repeated local and mass failures.

        If today's health IT is not ready for national rollout, e.g., causes harms of unknown magnitude (e.g., see this query link), results in massive breaches of security as the "Good Reason" post above, and mayhem such as at this link, then:

        The best - and most ethical - option is to slow down HIT implementation and allow paper-based organizations and clinicians to continue to resort to paper until these issues are resolved.  Resolution needs to occur in lab or experimental clinical settings without putting patients at risk - and with their informed consent.

        Anything else is akin to the medical experimentation abuses of the past that led to current research subjects protections such as the "Ethical Guidelines & Regulations" used by NIH.

        -- SS

        Good Health IT (GHIT) v. Bad Health IT (BHIT): Paper is Better Than The Latter

        An unspoken running assumption of the health IT enthusiast crowd seems to be that any health IT is better than no health IT, because using paper results in mistakes.

        I offer a different view.

        At the introduction to my Medical Informatics teaching site I've defined good health IT and bad health IT as follows:

        Good Health IT ("GHIT") is defined as IT that provides a good user experience, enhances cognitive function, puts essential information as effortlessly as possible into the physician’s hands, keeps eHealth information secure, protects patient privacy and facilitates better practice of medicine and better outcomes. 

        Bad Health IT ("BHIT")
        is defined as IT that is ill-suited to purpose, hard to use, unreliable, loses data or provides incorrect data, causes cognitive overload, slows rather than facilitates users, lacks appropriate alerts, creates the need for hypervigilance (i.e., towards avoiding IT-related mishaps) that increases stress, is lacking in security, compromises patient privacy or otherwise demonstrates suboptimal design and/or implementation.  . 
          

        There are also good paper systems and bad paper systems.

        I opine that the elephant in the living room of health IT discussions is that BHIT is infrequently, if ever, made a major issue in healthcare policy discussions.

        I also opine that BHIT is far worse, in terms of diluting and decreasing the quality and privacy of healthcare, than a very good or even average paper-based record-keeping and ordering system.  

        This is a simple concept, but I believe it needs to be stated explicitly. 

        In today's healthcare world, where health IT is dominated by hyper-enthusiasts of one motive or another, such an axiomatic statement will probably be viewed as controversial if not heretical. 

        This blog has numerous postings about health IT debacles, e.g., query links here and here, that could not occur with paper systems.  The defects of just one company's products, the only one that publicly reports them to FDA (link) are frightening in terms of potential consequences.

        GHIT needs to be promoted and BHIT needs to be eliminated.  That implies a major transformation of the health IT industry and its oversight.

        -- SS

        Another unsolicited email from a physician describing EHR-caused chaos in the clinic

        I periodically receive unsolicited stories of EHR difficulties (mayhem, really) as a result of clinicians or others locating my materials online, via web searches, social networking sites, or word of mouth.

        Another unsolicited email from a physician describing EHR-caused chaos in the clinic, reposted with permission, is at my Health IT academic site at this link.

        -- SS

        A Good Reason to Refuse Use of Today's EHR's in Your Health Care, and Demand Paper

        I've written before that health IT, including the technology and the social infrastructure in which it resides, is not ready for widespread diffusion.  Its widespread dissemination (on largely economic grounds) at this point in its development is premature, and is destructive.

        So much, in fact, that I am considering demanding that any physician I see or hospital I visit use paper records, not any EHR they have available.

        Think that extreme?  In the real world as it exists today, perhaps the notion that one should freely spill one's deepest confidences into an insecure EHR system is the extreme view.

        The reason (aside from the risk today's clinical information technology presents):  yet another addition to my series of posts on health IT privacy breaches at this query link, this time from ABC News:

        Your Medical Records May Not Be Private: ABC News Investigation

        BY JIM AVILA (@JimAvilaABC) AND SERENA MARSHALL (@SerenaMarsh)

        Sept. 13, 2012

        Psychiatric Therapy Notes Get Shared Within One Health Care System; and Other Info Spreads on a Black Market

        You walk into the doctor's office. They lead you to a private room and shut the door. The nurse enters writes on a chart (or maybe an iPad) and shuts the door. A doctor enters and shuts the door.

        It all screams of privacy -- privacy you expect.

        But what if you were to find out those medical records containing your private history, family history and medication history weren't so private after all?

        Considering electronic breaches in other sectors, and the fact that hospitals' core competencies do not include computing or computer security, why would anyone expect privacy?

        Julie, a lawyer from Boston, discovered that her sensitive health information was available to anyone who worked at the hospital.  (See video of Julie at this link).

        For an attorney who might be involved in nasty litigation, that is not a career-enhancing prospect.

        "My expectation was that my records were going to be private, especially my therapy records," Julie said. "And if another doctor wanted to see my records, they'd ask me and then I'd give my authorization for them to view my records if they needed to see them."

        In an ideal world not pervaded by inappropriate leadership of health IT and incompetence, perhaps.

        Julie, who requested her last name not be used, was diagnosed with in her late teens and began seeing a psychiatrist in 2002 after speaking with her primary care physician.

        She, like millions of Americans, thought her conversations with her psychiatrist were confidential.

        "I thought I had protection under HIPAA (the Health Insurance Portability and Accountability Act) for my psychotherapy notes to be private and I thought only my psychiatrist could see those," the 42-year-old said, adding that she noticed over the years her physician started entering them electronically.

        A law is only as good as the technology and people behind it, and technology and the people may not be so good:

        According to the HHS Health Information Privacy Tool, there were at least 78 breaches so far this year affecting 500 or more individuals, many affecting thousands, some tens of thousands.

        Known to those in the health IT world as the "Wall of Shame," the HHS site lists more than 21 million individuals who have been victims to date.

        The Privacy Rights Clearinghouse found more than 130 breaches so far in 2012 -- breaches affecting any number of individuals.

        Try that with paper...how many 18-wheel trucks would it take to haul 21 million charts?

        What she didn't realize was that her physician's notes could be accessed by doctors and other health-care providers who worked in the same health-care system (6,000 doctors and nine affiliated hospitals) to have access -- information she learned after going to see an on-call physician for a stomach issue and realizing he knew about intimate relationship information only disclosed to her psychiatrist.

        Concerned, she requested a copy of her medical records from the health care system.

        Within those records she saw every note, every meeting, every conversation she had with her psychiatrist.

        "It was pretty traumatic because I felt that, you know, this man read without -- against my wishes -- without my consent," Julie said. "He read private information that I disclosed to a therapist that I didn't even tell my best friends about."

        There are supposed to be multiple levels of access security in EHR's, but that has to 1) work properly out of the box, 2) be implemented properly, and 3) be enforced.  That's three very large assumptions...

        And while most hospitals have rules about who may access medical records, compliance for the most part is not strictly regulated.

        Indeed.

        In fact, an ABC News investigation found that often medical information is so unprotected, millions of records can be bought online. Because so many people have access, the entire system is vulnerable to theft, experts told ABC News.

        These are an on-their-face reasons to refuse entry of your data in EMR systems.

        To see exactly how easy it was to find medical records online, ABC News enlisted the help of IT specialist Greg Porter, a consultant with Allegheny Digital.

        "This isn't very sophisticated," Porter said. "If you can use a Web browser and you can search to www.google.com, you can begin to try and obtain some of this information."

        With two clicks of a mouse, Porter found somebody willing to sell a data dump of diabetic patients with information including their names, birth dates and who their insurance provider was, among other details. Another seller offered 100,000 records of customers who purchased health insurance in the last three to 12 months.

        "Typically, what we find are things like first name, last name, address, medical condition, whether they were a smoker, diabetic patient, perhaps even as intensive as, or invasive as whether they are HIV-positive or not," Porter said. "Some of the most intimate information about all of us potentially could be revealed if appropriate safeguards aren't put in place.

        Putting appropriate "safeguards" into place hurts healthcare organizations' bottom lines.

        Security professionals are seeing an increase in theft via the "insider threat," Porter said.

        "It's a depressed global economy," Porter added. Thieves might approach medical staff and offer upward of $500 per week for providing 20 to 25 insurance claim forms, medical records or health financing records, Porter said. Those documents fall under HIPAA security rules and are considered protected health information.

        Could never happen, right?

        In June, a hospital medical technician at Howard University pleaded guilty to selling patient information, including names, birth dates and Medicare numbers, for $500 to $800 per transaction for more than a year.

        In August, a hospital employee at Florida Hospital Celebration was arrested for accessing more than 700,000 patient records in two years.

        According to the FBI, Dale Munroe accessed car accident victims' date and sold it to someone who passed it on to chiropractors and attorneys.

        And this week, the University of Miami Health System said that two workers had "inappropriately" accessed patient data and "may have sold the information to a third party."

        On the black market, "health information is far more valuable than Social Security numbers," said Dr. Deborah Peel, founder and chairwoman of Patient Privacy Rights.

        I stand corrected.

        ABC News' searches found one seller offering database dumps for $14 to $25 per person. After a quick email inquiry into the sale of records, ABC News was sent, unsolicited, 40 individuals' private health information, including their names, addresses and body mass index.

        Another inquiry yielded an offer of more than 100 records that, if purchased, would have included everything from Social Security numbers to whether someone suffered from anxiety or hypertension, or even their HIV status.

        ABC News contacted patients from one of the lists to see if they knew their information was being sold over the Internet and if they had consented.

        One victim named Rafael said he had not "recalled" giving anyone permission to sell his information.

        "I'm appalled, I'm disgusted and I'm very much concerned," Rafael said. "Who's giving out my personal information like that? I thought there were security and safeguards for these things. I thought … your medical records are confidential."


        So, in addition to the risks to good care posed by today's EHRs, now one has to be concerned about risks to one's privacy, damage to one's career, and to one's financial health as well.

        ... [Privacy advocate Dr. Deborah] Peel believes ways to fix the privacy vulnerabilities are available. "Technologies exist today to allow you to selectively share parts of your record that are relevant on a need-to-know basis with your other physicians and no one else, but we don't have those technologies in wide use," she said.

        Not in the short term, unfortunately.

        For Julie, privacy is a battle she continues to fight.

        "I asked … please restrict the records and of course they said 'No,'" she said.

        Great.  How reassuring.

        "Let me also assure you that our physicians and other staff access information on a strictly 'need to know' basis and as such, we do not restrict access to clinical information from any department or physician," the hospital told her. "I take your concerns very seriously and understand your need for privacy with your psychiatric records. Sometimes it can be a challenge to balance access to records for patient care purposes with the need for privacy."

        Bullsh*t, I say, having led EMR implementations at large hospitals where these exact issues were considered.

        Since discovering her records were available to the whole health system, Julie has stopped seeking care out of concerns for her privacy.

        That. of course, destroys the whole purpose of electronic records to "improve access" to "accurate medical information."

        ... In sharing her story, Julie wanted to come forward for those who couldn't.

        "The difference in this situation is I actually chose to come here and I actually chose what I'm gonna say and what I'm not gonna say; but when my medical information is available to everybody, I don't have that decision," she said. "Somebody else is making that decision for me and that really makes me feel violated. So that's why I'm here: Because I think it's a really big problem and I wanted to do something about it. "

        The people who in essence are "making that decision for me" are technologists, or technology hyper-enthusiasts, who ignore technology's downsides and ethical considerations.  I defined that defective character type at this post.

        The systemic technological and attitudinal problems (further) exposed by this ABC investigation cannot reasonably be expected to be fixed, and probably cannot be fixed, in a short time frame.

        Thus, I suggest patients who do not desire to be guinea pigs on health information security, privacy and confidentiality consider refusing use of EHR's to record and diffuse their confidential medical information. A person should not be coerced to risk their privacy and financial security while the health IT industry "gets its act together."

        On a pragmatic basis alone in 2012, the risk-to-benefit ratio may simply be too high.  For instance, what are the odds that you'll be found unconscious and without contact information in some distant land, vs. privacy breach or ID theft from an EHR?

        Further, there is no legal requirement that electronic records be used for rendering of medical care.  There is also no legal requirement that live patients consent to be used as test subjects for hospitals and software companies in refining their IT systems ("beta testing") to make them secure.

        If a physician or hospital refuses to honor the request, and/or refuses to provide care, litigation should be pursued.

        -- SS

        A Message for Xerox: Americans Not 'Resistant to Change'; They Are Resistant to Reckless Change That Endangers Them

        A press release from Xerox Healthcare Provider Solutions:


        Only 26 Percent of Americans Want Electronic Medical Records, Says Xerox Survey

        The subtitle is a rhetorical question:

        When it comes to healthcare, are Americans resistant to change?



        ROCHESTER, N.Y. – Americans routinely use electronic files to manage their finances, communicate with friends and family and even take college courses – but when it comes to medical records – only 26 percent want them digital. The findings come from the third annual Electronic Health Records (EHR) online survey of 2,147 U.S. adults, conducted for Xerox (NYSE: XRX) by Harris Interactive in May 2012. 

        According to the survey, only 40 percent of respondents believe digital records will deliver better, more efficient care. That response fell two percent from last year’s survey, and matches the response reported in 2010. Overall, 85 percent of respondents this year expressed concern about digital medical records.

        Americans have a healthy skepticism of putting their private information online to be hacked, of the disruptive effects of today's commercial health IT on their clinicians, and the costs of doing so.  This likely comes from common sense, reading and observation.

        As one reader of this blog wrote:

        Xerox kindly shared all three years of their annual Electronic Health Records (EHR) online surveys by Harris Interactive. The media, industry and government unrelentingly promote health technology as the latest, greatest best stuff. But the public ain’t buying it. They want smart phones, but they don’t want EHRs.

        The Xerox article paternalistically continues:

        “We continue to see a resistance to change from consumers – meaning providers need to continue to educate Americans on the value of EHRs,” said Chad Harris, group president, Xerox Healthcare Provider Solutions.

        (Note the use of the 'EHR' acronym.  As I've written, the acronyms 'EHR' and 'EMR' are anachronisms used to describe what are no longer innocuous filing systems, but greatly intrusive enterprise clinical resource and workflow control systems.  I think the public increasingly understands that.)

        This patriarchal statement by Chad Harris about "resistance to change" by "healthcare consumers" needing re-education is, in a word, depraved, because I think the person uttering the sentence knows better.  Let's define depraved:

        Depraved (adj.):  morally bad or debased; corrupt; perverted

        This statement implies is that health IT is a perfected technology without significant flaws, whose benefits are well-proven and whose drawbacks and risks are well understood.

        Unfortunately, none of those are true.  From my May 2012 post on ONC's embarrassing "Health Data Palooza", worth repeating here, with hyperlinks:

        • There is a markedly unscientific "irrational exuberance" pushing clinical IT into wide use at a dangerously rapid pace. This exuberance is contradicted by a growing body of literature that shows the benefits are likely far less than stated, e.g., by way of example, the ad-hoc set at http://www.ischool.drexel.edu/faculty/ssilverstein/cases/?loc=cases&sloc=readinglist;
        • The technology remains experimental, its rollout is a human subjects experiment on a massive scale lacking nearly all the protections of other human subjects experimentation and for IT in mission critical settings (e.g., informed consent, formal quality control/validation/regulation, formal postmarket surveillance and reporting) due to extraordinary legal and regulatory special accommodations afforded the technology and its purveyors;
        • Defects of in-use systems are rampant, inappropriately turning patients and clinicians into software alpha and beta testers (e.g., as in the voluntary FDA MAUDE database, http://hcrenewal.blogspot.com/2011/01/maude-and-hit-risk-mother-mary-what-in.html which contains information for just one HIT vendor, Cerner, who voluntarily reports such issues);
        • The technology is unsupportive of clinician cognitive needs (2009 National Research Council study, which also stated that accelerating interdisciplinary research in biomedical informatics, computer science, social science, and health care engineering will be essential to perfect this technology);
        • The roles of scientific discovery and anecdote have been turned on their heads. RCT's of clinical IT are nearly non-existent and lower-level evidence (e.g., weak observational, pre-post, qualitative, and other study types) are cited as "scientific proof" of efficacy and safety justifying hundreds of billions of dollars of taxpayer (or is it Chinese loan?) expenditures.  Yet, risk management-relevant case reports of harmful events and near misses, crucial to help organizations and regulatory agencies understand risks are dismissed as "anecdotal" (e.g., Blumenthal: "The [ONC] committee [investigating FDA reports of HIT endangement] said that nothing it had found would give them any pause that a policy of introducing EMR's could impede patient safety," he said, while ONC issued an article based on questionable research methods entitled "The Benefits Of Health Information Technology: A Review Of The Recent Literature Shows Predominantly Positive Results" extolling the virtues of HIT, written about at http://hcrenewal.blogspot.com/2011/03/benefits-of-health-information.html).
        • Risks are definite, with known patient injury and death, but the magnitude is admittedly unknown as admitted by JC (2008 Sentinel Event Alert), FDA (2010 Internal memo on HIT risks and statements of Jeffrey Shuren MD JD about known harms likely being "the tip of the iceberg"), IOM (2011 report on HIT risk), ECRI Institute (Top ten healthcare technology hazards for 2011 and 2012), NORCAL Mutual Insurance Company 2009 report on EHR risks, others;
        • Existence of severe impediments to information diffusion about risks explicitly admitted by FDA (2010 memo), IOM (2011 report), others;
        • Usability of commercial products in real world settings is often poor (e.g., NIST 2011 study on usability), promoting "use error" (user interface designs that engender users to make errors of commission or omission, where many errors are due not to user error per se but due to designs that are flawed, e.g., poorly written messaging, misuse of color-coding conventions, omission of information, etc.)
        • These systems promote capture and display of clinically irrelevant information in the interest of charge capture, and result in reams of "legible gibberish" with many negative characteristics that make it difficult for other clinicians and reviewers to establish a cohesive, definitive narrative of clinical events and timelines.

        The article continues:

        Despite consumers’ misgivings of the value of EHRs, caregivers [largely hospitals and healthcare systems who force it on their staffs and owned physician practices - ed.] are quick to adopt digital technology.  [Thanks to incentives and looming penalties - ed.] When asked how their healthcare provider recorded medical information during their last visit to a doctor or hospital, 60 percent of respondents – who have visited a doctor or hospital – reported that the information was entered directly into a tablet, laptop or in-room computer station versus 28 percent who reported the information was taken via handwritten notes. 

        As the numbers don't justify the practice, even if the numbers as stated are valid, my response is:

        So what?

        To help caregivers do more with this patient information, Xerox is working with researchers at PARC, A Xerox Company, to explore EHRs as a gateway to a variety of healthcare innovation possibilities. The resulting technology tools will simplify back-office and front-line processes, reduce errors, and free up caregivers to spend more time and attention on day-to-day patient care.

        The "possibilities" will accomplish all these things?  

        Not only does that not follow logically, but where's the data, or is this simply wishful thinking? 

        The latter "possibility that will come true" - "free up caregivers to spend more time and attention on day-to-day patient care" - is the most laughable.   These systems do anything but, as for example here regarding the the time costs of data acquisition and the time costs of data input.  I have yet to see serious studies that consistently demonstrate any time savings at all for clinicians.  Quite the reverse, actually.

        Of course, the mandatory marketing puffery:

        “A big part of PARC’s healthcare work for Xerox is using ethnography and other social science methods to observe and analyze actual work practices – not just what people say they do,” said Steve Hoover, CEO, PARC, A Xerox Company. “If there’s one thing that this survey tells us, coupled with our own experiences, it’s that you should never develop or deploy technology outside of the human context.”

        Precisely what is being done now, and on a national scale in the 'National Program for IT in the HHS.'

        Xerox, either you're part of the solution or part of the problem.

        Which is it?

        -- SS
        womens health ,health articles ,health information ,health benefits ,free health insurance ,health plus ,child health insurance ,health insurance plans ,insurance health ,online health insurance ,health insurance companies ,best health insurance ,health insurance ,health plan ,health ins ,family health insurance ,health plans ,health insurance coverage ,health magazine ,health insurance providers ,health news ,health insurance online ,health current events ,health insurance company ,womens health magazine ,health and wellness ,current health articles ,good health insurance ,health insurances ,health news articles ,health insurance plan ,current health events ,health related articles ,health insurance options ,recent health articles ,health facts ,health.com ,get health insurance ,health topics ,articles on health ,articles about health ,health current event ,health concerns ,holistic health ,global health ,health magazines ,health news today ,current health issues ,heart health ,current health news womens health ,health articles ,health information ,health benefits ,free health insurance ,health plus ,child health insurance ,health insurance plans ,insurance health ,online health insurance ,health insurance companies ,best health insurance ,health insurance ,health plan ,health ins ,family health insurance ,health plans ,health insurance coverage ,health magazine ,health insurance providers ,health news ,health insurance online ,health current events ,health insurance company ,womens health magazine ,health and wellness ,current health articles ,good health insurance ,health insurances ,health news articles ,health insurance plan ,current health events ,health related articles ,health insurance options ,recent health articles ,health facts ,health.com ,get health insurance ,health topics ,articles on health ,articles about health ,health current event ,health concerns ,holistic health ,global health ,health magazines ,health news today ,current health issues ,heart health ,current health news