Friday, August 31, 2007

Security of Medical Information

eHealthRisk Blog reader Lyndon Dubeau passed on this link to UK Information Security Expert Ross Anderson who is a professor at the University of Cambridge. I've just spent an hour watching his online lecture Searching for Evil, in which he discusses how to find and thwart bad guys on the net.

Anderson's website has a wealth of information and useful links. Its worth a look.

Thursday, August 30, 2007

Community Attitudes to Privacy 2007

The Office of the Privacy Commissioner of Australia has issued a report titled Community Attitudes to Privacy 2007. The study aimed "to understand Australians' changing awareness and opinions about privacy laws, how they apply to government and business and how individuals view a range of emerging issues, in particular, identity fraud and theft and the use of closed circuit television."

Also included in the report was an assessment of consumer attitudes towards health services and privacy including inclusion in a National Health Database, health professionals sharing patient information, Doctors discussing personal medical information in an identifiable way, and disclosure of the fact that a patient has a genetic illness - with and without consent. A brief analysis of the report and its implications for health care can be found on Dr. David More's blog Australian Health Information Technology.

Wednesday, August 29, 2007

What Type of Person Takes Risks?

How do you classify a person who skydives, yet won't stand up to his/her boss? Is he/she a risk-taker? Understanding why we take some risks and yet avoid others is at the heart of risk management. Researchers at the University of Michigan have recently published a paper titled Towards the development of an evolutionary valid domain-specific risk-taking scale - an unwieldy title better explained in an article titled Not all risk is created equal by the University of Michigan News Service.

Thanks to Gila Pyke for passing this link along.

Tuesday, August 28, 2007

AHRQ National Resource Center for Health IT

The Agency for Healthcare Research and Quality (an agency of the US Department of Health and Human Services) has established a National Resource Center for Health Information Technology. While US focused, it contains many articles, resources and toolkits that can be adapted to many jurisdictions. I particularly like their Privacy and Security Toolkit and "Emerging Lessons" pages for CPOE, EMR/EHR, Health Information Exchange, and Health IT in Small and Rural Communities.

Its an excellent site that appears to present a balanced view of many eHealth opportunities and issues.

Monday, August 27, 2007

eHealth Business Risk

Business risk is associated with the business and political environment in which a health care organization operates. It is perhaps the most challenging area of risk because often the organization doesn’t have control over the measures necessary to reduce the impact or likelihood of such events.

Business risks are often at the heart of the risks identified in other domains. For example, many privacy risks arise because of confused business models that don’t clearly define the roles and responsibilities of each of the stakeholders in an eHealth program. Business risk sometimes transcends the organization for regional, provincial, state and national eHealth programs where government or other supra-organizations are responsible for setting and enforcing standards and policy. The issue of eHealth governance is central to the management of business risk.

There are no defined control standards available to specifically address eHealth business risks at the regional, provincial, state and national levels. Each government jurisdiction has its own unique business and regulatory environment. However, anecdotal evidence suggests several significant control measures that should be put in place for such eHealth programs.

1. An eHealth Governance Framework and Authority – A legitimate body that has the authority to establish and enforce policy and standards in an eHealth environment that includes many healthcare organizations, health care providers and other stakeholders.

2. A Comprehensive Business Model – that defines the roles and responsibilities of each stakeholder in an eHealth program. This includes ensuring that all stakeholders benefit from the initiative in a manner and magnitude consistent with their investment.

3. A Contractual Framework – that accurately represents the business model and agreements between all stakeholders participating in the eHealth program. This would include consent forms and processes for patients.

4. Strategic Business and Technical Architectures –that enable the integration of the eHealth program into the larger health system and ensure that it is interoperable with other eHealth programs and systems.

5. A Stakeholder Engagement Model – to ensure that the interests of all stakeholders, and in particular, patients and end-users, are addressed in all aspects of eHealth program design, deployment and support.

In most jurisdictions around the world, governments have significant involvement in the funding and management of health care. This results in a complex political environment that has a direct impact on business risk. Political influence can be exerted by politicians or by the bureaucracy that supports the government. Political decisions affect priorities and in extreme cases can interfere with normal business protocols.

Business risks associated with eHealth include:

• Regulatory and legal liability
• Financial loss
• Political interference
• Procurement challenges
• Rejection by users
• Business interruption

Guidance on business risk assessment and management can be found in the publication Management of Risk: Guidance for Practitioners that is published by the British government’s Office of Government Commerce. This guide addresses risks at the strategic, program, project and operational levels.

Friday, August 24, 2007

eHealth Insider

One of my regular stops on the Internet is eHealth Insider, an online journal published in the United Kingdom. Its focus is on eHealth in Britain, but often its articles are universal in nature. There are lots of lessons to be learned from the UK experience, and this online resource is an excellent source of topical information. They publish eHealth Insider (focusing on the NHS's eHealth initiatives), eHealth Insider Primary Care (what's going on in the physician world), and eHealth Europe (what's going on all over Europe). You can subscribe to their online newsletters so you won't miss a thing!

What caught my eye today is a report on an article published in the British Medical Journal titled Potential of electronic personal health records and EHI's subsequent review and interviews with the authors.

Thursday, August 23, 2007

The Un-Health Record

While scanning the Internet my eye caught an article in GovernmentHealthIT titled The un-health record by Nancy Ferris. It discusses a growing trend by Governments to use health claims data instead of clinical data for a "claims-based EHR". This trend is documented in a report by the US Department of Health and Human Services Office of the Inspector General titled State Medicaid Agencies initiatives on HIT and HIE. Similar initiatives exist in other countries, including Canada, where the Ontario provincial government gives emergency department access to drug claims data for the Ontario Drug Benefit Program.

Its understandable that Governments, with their massive stores of health claims data, would want to put that information to use. However, there is always a risk of using information collected for one purpose (claims adjudication and payment) for another (clinical decision making). Data quality is the issue here.

How good is claims data? From the article:

A 2004 study published in the journal Medical Care found that claim forms showed the correct primary diagnosis slightly more than half the time. For secondary diagnoses, doctor’s offices submitted correct information just 27 percent of the time. Other researchers have come up with comparable findings.

What’s more, claims data lacks some important details and nuance because of the universal coding scheme and the way it is used. For example, the scheme does not distinguish between a severe case of diabetes and one that’s under control, and providers don’t always use the diagnostic codes that indicate the spread of cancers. Furthermore, symptoms such as pain or fever usually don’t show up at all.


So long as health care professionals are fully informed about the limitations of the data, the use of claims data probably brings more benefits than risks. Claims data can be used as one input into the clinical decision-making process. However, in the absence of structured processes for evaluating the quality of the data, and safety risks in eHealth, claims data alone cannot be used as the basis for clinical decision-making.

Wednesday, August 22, 2007

Lessons Learned from Santa Barbara

One of the most celebrated RHIO (Regional Health Information Organization) failures in the United States was the Santa Barbara County Care Data Exchange which ceased operations in December 2006. The California HealthCare Foundation has released an evaluation of the initiative titled The Santa Barbara County Care Data Exchange: Lessons Learned, which documents the issues leading to the failure and lessons learned for similar initiatives. From the Executive Summary:

The Santa Barbara County Care Data Exchange (SBCCDE) was once one of the most ambitious and publicized efforts to develop health information exchange in the United States, and was considered a model for emerging regional health information organizations (RHIOs) elsewhere. Nearly eight years after its inception, and several months after providing some data to clinical end-users, the SBCCDE ceased operations. Although the venture had developed a peer-to-peer technology infrastructure that enabled authorized physicians, health care organizations, and consumers in the region to access some electronic patient information security via the Internet, the once-promising exchange was unable to overcome major hurdles and thrive.

This case study looks at the history of Santa Barbara's RHIO and why it was not successful. It also presents lessons learned from that experience, briefly describes two other exchanges that have been more successful, and discusses the policy implications for nascent RHIOs elsewhere. Reasons why the project did not succeed include the lack of a compelling business case, distorted economic incentives, passive leadership among participants, vendor limitations and software delays, and due to a variety of factors, the venture's poor momentum and credibility.

This case study is required reading for eHealth risk specialists!

Tuesday, August 21, 2007

Requirements for Enhancing Data Quality in EHR Systems

The US Department of Health and Human Services has published a document titled Recommended Requirements for Enhancing Data Quality in Electronic Health Record Systems (EHR-S). The primary purpose of the project was "to identify requirements for EHR-S that can help enhance data protections, such as increased data validity, accuracy and integrity including appropriate fraud management which would prevend fraud from occuring, as well as detect fraud both prospectively and retrospectively."

The fourteen recommended functional requirements include:

Requirement 1: Audit Functions and Features
Requirement 2: Provider Identification
Requirement 3: User Access Authentication
Requirement 4: Documentation Process Issues
Requirement 5: Evaluation and Management (E&M) Coding
Requirement 6: Proxy Authorship
Requirement 7: Record Modification after Signature
Requirement 8: Auditor Access to Patient Record
Requirement 9: EHR Traceability
Requirement 10: Patient Involvement in Anti-Fraud
Requirement 11: Patient Identify-Proofing
Requirement 12: Structured and Coded Data
Requirement 13: Integrity of EHR Transmission
Requirement 14: Accurate Linkage of Claims to Clinical Records

All of these requirements are integral to managing the risks associated with EHRs. A very useful piece of work!

Monday, August 20, 2007

HIMSS PHR Definition and Position Statement

I give a lot of air time to Personal Health Record (PHR) developments on this blog because I believe they represent the wild card in the high stakes game of eHealth. Think of it as the battle between the controlled economy (EHR) and the marketplace (PHR). For all of the privacy legislation and interoperability standards we put in place, the battle will be won by whoever can capture the attention of the kids who are text messaging and sharing information over their iPhones and Boomers who are increasingly concerned about their deteriorating health and want to take control of their destinies.

The Healthcare Information Management and Systems Society (HIMSS) has published a PHR Definition and Position Statement. They define a PHR as:

a universally accessible, layperson comprehensible, lifelong tool for managing relevant health information, promoting health maintenance and assisting with chronic disease management via an interactive, common data set of electronic health information and e-health tools. The ePHR is owned, managed, and shared by the individual or his or her legal proxy(s) and must be secure to protect the privacy and confidentiality of the health information it contains. It is not a legal record unless so defined and is subject to various legal limitations.

The HIMSS Statement of Position is:

HIMSS supports the development of interoperable ePHRs which are interactive and use a common data set of electronic health information and e-health tools. HIMSS envisions ePHRs that are universally accessible and layperson comprehensible, and that may be used as a lifelong tool for managing relevant health information that is owned, managed and shared by the individual or his or her legal proxy(s). The ideal ePHR would receive data from all constituents that participate in the individual’s healthcare; allow patients or proxies to enter their own data (such as journals and diaries); and designate read-only access to the ePHR (or designated portions thereof).

HIMSS supports ePHR applications with the following characteristics:
Provide for unique patient identification
Allow secure access to the information contained in the ePHR
Permit the receipt of email alerts that do not reveal protected health information (PHI);
Allow patient proxy(s) to act on behalf of the patient
Permit the designation of information to be shared electronically;
Provides technical support to ePHR constituents at all times.

HIMSS champions the development of national standards to ease burdens placed on constituents due to variances in state law and the development of national and uniform state standards to address legal concerns raised by ePHRs such as reliability, reimbursement, ownership, access, transfer, and the limitations, rights and responsibilities of patients and providers for the use of e-health and ePHRs.


Similarly, HIMSS encourages the adoption of incentives by payors, providers, pharmaceutical companies, device manufacturers, and the federal and state governments of the United States to reduce the financial barriers to motivate widespread ePHR adoption.


This is a laudable position that seeks to reign in the wild west world of PHRs. Only time will tell whether the controlled economy or the marketplace prevails.