- A list of all links featured on the eHealthRisk Blog including all documents referenced on the blog and in the reference section of the eHealth Risk Report Card Methodology. I also indicate whether the materials are free or must be purchased (eHealth Risk Links).
- Downloads of the eHealthRisk Report Card Methodology and any supplementary materials, PowerPoint presentations given on the subject (Home page).
- Educational opportunities (Training page)
Saturday, June 30, 2007
eHealthRisk.com
Friday, June 29, 2007
Identity Theft
There is however the matter of identity theft. No one wants my lab tests, but they might be motivated by the opportunity to take over my bank accounts, credit cards and home mortgage. Health care databases are a rich source of data for identity thieves who are more interested in the state of my finances than the state of my health.
We must also recognize that health care is a valuable service that doesn't cover everyone, especially those living in the United States who might be motivated to scam some free health services. Stealing the identity of an insured person is one way of gaining access to free health care.
Gordon Atherley has written a white paper on identity theft in health care. I'll also point you to the article Diagnosis: Identity Theft from an earlier post on this blog. The World Privacy Forum has published a report titled Medical Identity Theft: The Information Crime that Can Kill You. Download and read these papers. Someone out there will be motivated to go after your databases not because they intend to misuse the health data, but because they want to rob us blind.
Thursday, June 28, 2007
Knowledge Centre
Its worth a look.
The Burden of eDiscovery
The American Health Information Management Association (AHIMA) has published a summary of the Electronic Discovery Civil Rule and how it applies to healthcare organizations. While this applies to organizations in the United States, one will expect that similar issues will arise in all national jurisdictions. From the summary:
"As electronic health record (EHR) technology advances, sophisticated litigators are gaining a better understanding of the information they can obtain from e-mail messages, databases, software applications, computer logs, and metadata. Electronic discovery (e-discovery) is becoming a critical part in gathering and using evidence in legal proceedings, complementing traditional methods such as photocopies, printouts, and digital images of patient medical records.
New changes to the Federal Rules of Civil Procedure related to e-discovery will greatly affect how healthcare organizations manage their electronic records. This practice brief provides an overview of pretrial requirements in the e-discovery civil rule and reviews the relevance and application of each section of the rule to healthcare organizations. Additionally, it identifies the steps HIM professionals can take to prepare their departments and organizations for the challenges associated with e-discovery."
Wednesday, June 27, 2007
Health IT Horror Stories
Tuesday, June 26, 2007
EHR Information Governance
The paper raises many issues that need to be resolved before an interoperable EHR can become a reality. For example it acknowledges what I believe to be the biggest problem in privacy risk management - the problem of what to do with the results of privacy impact assessments.
“Although substantial expertise exists across Canada in the conduct of PIAs, few best practices or policies have been developed to monitor the implementation of privacy risk mitigation strategies and to integrate privacy monitoring and PIA revisions into the change management process. Developing programs to ensure continuous privacy management is an issue that will need to be addressed as part of effective EHR information governance.” (page 15)
The paper doesn't have all the answers, but it does ask the right questions. This is a must read.
Monday, June 25, 2007
eHealth Safety Issues - Focus on CPOE
J. Ash, M. Berg, E. Coiera, Some Unintended Consequences of Information Technology in Health Care: The Nature of Patient Care Information System-related Errors, JAMIA Mar/Apr 2004
Y. Han, J. Carcillo, S. Venkataraman, R. Clark, R. Scott Watson, T Nguyen, H. Bayir, R. Orr, Unexpected Increased Mortality After Implementation of a Commercially Sold Computerized Physician Order Entry System, Pediatrics Dec 2005
R. Koppel, J. Metlay, A. Cohen, B. Abaluck, A.R. Localio, S. Kimmel, B. Strom, Role of Computerized Physician Order Entry Systems in Facilitating Medication Errors, JAMA Mar. 9 2005
R. Berger, J.P. Kichak, Computerized Physician Order Entry: Helpful or Harmful? JAMIA, Mar./Apr. 2004
G. Kuperman, R. Gibson, Computer Physican Order Entry: Benefits, Costs and Issues, Annals of Internal Medicine, July 2003
A few thoughts after reading these articles:
- CPOE is undoubtedly a good thing... if implemented well.
- CPOE is not a magic bullet. Simple implementation of a CPOE system will not automatically result in reduced errors. In fact it may increase errors.
- All CPOE systems are not created equal. Some commercial products are better than others... which also means that some commercial products are worse than others.
- Software implemented badly, no matter how good it is, will result in a bad system that can hurt people.
Friday, June 22, 2007
FOI Request and Appeal for PIAs
The Ministry released redacted copies of the Steering Committee minutes but denied access to the PIA's and Strategic eHealth Plan.
Reasons for denying access to the PIA's included:
For OLIS - Section 12(1)(a) of FIPPA - Cabinet Records
For ODBDPV - Section 14(1)(i) of FIPPA - Law Enforcement, and 17(1)(a)(b)(c) of FIPPA - Third Party
For iPHIS - 12(1)(c)&(e) of FIPPA - Cabinet Records, and 14(1)(i) of FIPPA - Law Enforcement.
The Ministry found a 2004 eHealth Strategy document and denied access under Section 12 (Cabinet Records) of FIPPA.
I have appealed the denial of access to the PIA's to the Information and Privacy Commissioner for Ontario. I decided not to pursue the matter of the Strategic Plan as it appears that the Ministry does not have a current eHealth Strategic Plan.
The IPC has acknowledged receipt of my appeal.
I'll post updates on the Blog concerning the progress of this request.
Wednesday, April 25, 2007
Positive Feedback on eHealth Risk - Opportunity Workshop
A thank you to the participants who were fully engaged and who offered a great deal of constructive criticism and advice for the next version of the report card.
Monday, April 23, 2007
Comments on eHealth Risk Opportunity Report Card Paper
- In general, I think that you have put together a well-thought out paper.
- I like Page 5 where you have indicated that each eHealth program can apply flexible weights to the report card. Risk management tools need to be flexible to address different situations.
- The opportunity-risk matrix in Table 5 is also a nifty idea.
- I am very interested in seeing the paper put into real practice. In fact, application of the paper is a theme for me. Applying this to a pilot area of eHealth will be the true test of what works, what does not work and what needs to be refined a bit.
- The biggest potential obstacle that you may face is with the definition of risk.
- There are many competing definitions of the word risk out there. You have defined risk as the possibility that a threat will be realized resulting in harm or loss.
- The risk management world is slowly moving towards more of a risk definition that is uncertainty of outcome, with an outcome potentially having both positive and negative elements.
- I like the uncertainty definition much better because it inherently contains both the positive and negative definition of risk. It also forces the risk assessor / manager to focus on events and scenarios that have not occurred yet as opposed to issues that have already materialized.
I may seem to be quibbling but I have come to the epiphany that when I talk about risk management, often everyone in the room has different definitions of risk (a bad thing, uncertainty, an impact, a possibility, etc.). If you agreed with the semantics change, the language would change slightly in the paper. For example, in the title:
The eHealth Risk Report Card:
A practical approach to realizing opportunities in eHealth from understanding and managing risk
- Many in the audience for this paper could potentially have little understanding of risk management methodology. Hopefully that is not the case too often as a CIO should have at least a rough understanding of risk management. Still, you may want to have a brief primer on risk management in your back pocket or in an Appendix.
- Much of the material that was brought over to SSHA to help define the risk management framework came from the brilliant Australian Risk Management Standard AS/NZS 4360:2004 RISK MANAGEMENT. You will want to cite the framework in your end notes.