Showing posts with label computer security. Show all posts
Showing posts with label computer security. Show all posts

Manipulation of 12,000 Medical Records Made Easy by EHR

This from a hospital in Canberra, Australia using a common ED EHR in that part of the world, iSOFT:

Canberra Hospital embroiled in data scandal
SBI Magazine (Secure Business Intelligence)
Jul 5, 2012 

A Canberra Hospital executive has admitted to manipulating Emergency Department records to make wait times and stays appear shorter than they were.

The executive told the Director-General of the Health Directorate they had made "approximately 20 to 30 changes to hospital records" a day from "late 2010" onwards.

ABC [Australian Broadcasting Corp.] News reported that the matter has been referred to police, while the executive has been suspended without pay.

Though the data manipulation was initially said to be motivated by concerns over job security, changes in 2011 and early 2012 were said to have been made due to "managerial pressure" to improve publicly-reported performance statistics.

This raises the issue that data manipulation might have been performed not just to improve reported statistics, but to cover up medical error, computer related or not, and thus deny injured patients or their heirs the right to legal redress.

"The only thing that worked to achieve benchmark targets was to alter the data," the executive later told investigators at PricewaterhouseCoopers (PwC), which was engaged by Health to perform a forensics analysis. The analysis is detailed in a new Auditor-General report (pdf).

In total, PwC found 11,700 performance records - about six percent of all records stored in the hospital's iSOFT emergency department information solution (EDIS) - had been altered.

It is believed more staff at Canberra Hospital altered records than the executive that has so far admitted responsibility.  "While an executive has admitted to changing EDIS records, it is probable that EDIS records have also been manipulated by other persons with access to the system," the federal auditor-general noted overnight.

This is another area where electronic records make possible tasks that are probably impossible with paper.  Altering 11,000+ records would be hard in paper charts, as the alterations would likely stick out in a pronounced manner.

"The executive’s admission to Audit does not appear to account for all of the changes to EDIS records that have been made to improve timeliness performance."

For example, changes to EDIS records, albeit a much smaller number, appear to have been made on days when the executive was on leave (seven days in total in 2010-11 and early 2011-12). 

I am saddened to note, a proper term for this activity might indeed be "conspiracy":  a conspiracy is an agreement between two or more persons to break the law at some time in the future.

User access control, IT security failures

Poor controls such as generic logins and inadequate user and password security made it easy for insiders to game the data.

While EDIS was on approximately 259 workstations across the hospital and 253 users had permission to run the software, there were only 23 user accounts.

Of these user accounts, only eight were in regular use, including four named administrator accounts (specific to administrative staff) and four generic user accounts: CLERK, NURSE, DOCTOR and BEDMAN.

The generic accounts could be used by personnel across the hospital, not just within the Emergency Department.

Passwords for the four generic user accounts were "very poor" and had "never been changed". Password expiry was set at a default 999 days.

Audit logs were equally poor, not proactively checked and unreliable.

The proper term for these arrangements might be "gross mismanagement" of clinical information technology.

"A feature of the logging record is that it logs the changed field in EDIS and a number of other fields simultaneously, while not identifying which field was changed and what its original value was," auditors noted.

"Audit also notes that the logging record is also ineffective, because every entry in EDIS is logged from “Workstation 14”.  

"Although EDIS has been disseminated widely throughout the Canberra Hospital each of these users logs into EDIS using the common “Workstation 14”.

"This practice, combined with the use of generic user accounts, makes the EDIS logging information useless for investigations of unauthorised activity."

Furthermore, it was possible to edit EDIS records up to 72 hours after a patient’s treatment, providing a generous window for later unauthorised changes to the records.

These "features" sound like seller misdesign with regard to the metadata (logging records).

Noticing anomalies

It was only in April this year that a full inquiry was commissioned after "anomalies" in performance figures were spotted by the Australian Institute of Health and Welfare (AIHW).

The AIHW found an unusually high number of emergency patients that were reported to have been seen at exactly within the required time for their illness category.

For example, there was an unusually high number of patients who were reported to have been seen at exactly 30 minutes or 60 minutes.

In addition, an unusually high number of people checked out of the Emergency Department precisely 240 minutes after their recorded arrival.

If you're going to engage in this type of activity, at least be competent at it...instead of setting up a red flag bigger than the flag that used to fly over the Kremlin.

The records that were manipulated mean that publicly reported information relating to the timeliness of access to the Emergency Department and overall length of stay in the Emergency Department have been inaccurately reported.

The report could not ascertain the level of over‐estimation due to the lack of a clear audit trail identifying what were legitimate and what were fabricated entries in patients’ records.  

Timelines can be critical to proving medical negligence in court.  Further, if time data could have been manipulated, it seems clinical data could have been manipulated as well.

EHR data manipulation is of unknown magnitude worldwide, but I can imagine if it's easy to do and the benefits potentially substantial, electronic records could possibly be less trustworthy than paper records.

-- SS

Addendum:  while on the topic of clinical IT Down Under, there's also this:

Coast medical records system 'dangerous'
Stephanie Bedo
Goldcoast.com.au


Doctors have complained about the system, saying some patient documents are missing, it has log-in problems and 10-minute delays in accessing critical information.

Gold Coast Health was the first region in the state to move to electronic record-keeping, rolled out progressively from October last year.

Queensland Health spent about $200 million on the electronic medical record roll-out last year, which was delayed by 12 months because of problems with the software provider.

... Hospital cardiologist Dr Greg Aroney raised concerns about the system at a Griffith University forum on the future of health on the Gold Coast this week.

"Our system is totally inadequate and dangerous," Dr Aroney said.


Read the whole story at this link:   http://www.goldcoast.com.au/article/2012/07/06/429621_gold-coast-news.html

A similar story from the states where the doctors' complaints were actually ignored is at my Sept. 2011 post "Blake Medical Center (Bradenton, Fla.) Ignores Health IT Warning Letter From 100 Staff Physicians." 

Let's hope the Australian physicians' complaints are taken more seriously.

-- SS

Banking as the Standard Healthcare Should Look Up To On Medical Information Security?

At past posts "Don't Worry, Your Electronic Medical Records Are Getting Safer With Every Passing Day", "Another Episode of "But Don't Worry, Your Records are Safe..." and "Still More Electronic Medical Data Chaos, Pandemonium, Bedlam, Tumult and Maelstrom: But Don't Worry, Your Data is Secure", "Don't Worry, Your Records are Safe - Part IV" and others, I wrote on the issue of medical record security.

Banking has been held as the standard as to which medicine has been compared, with medicine being called archaic and behind the times for its reliance on paper.  Banking security is cited as a reason why electronic medical records can also be secured.

There's this:

Fraud Ring In Hacking Attack On 60 Banks 

June 27, 2012

Some 60m euro is stolen from bank accounts in a massive cyber raid, after fraudsters raid dozens of banks around the world.

By Pete Norman, Sky News Online


Sixty million euro has been stolen from bank accounts in a massive cyber bank raid after fraudsters raided dozens of financial institutions around the world.

According to a joint report by software security firm McAfee and Guardian Analytics, more than 60 firms have suffered from what it has called an "insider level of understanding".

"The fraudsters' objective in these attacks is to siphon large amounts from high balance accounts, hence the name chosen for this research - Operation High Roller," the report said.

"If all of the attempted fraud campaigns were as successful as the Netherlands example we describe in this report, the total attempted fraud could be as high as 2bn euro (£1.6bn)."

The automated malicious software programme was discovered to use servers to process thousands of attempted thefts from both commercial firms and private individuals.

The stolen money was then sent to so-called mule accounts in caches of a few hundreds and 100,000 euro (£80,000) at a time.

Credit unions, large multinational banks and regional banks have all been attacked.

Sky News defence and security editor Sam Kiley said: "It does include British financial institutions and has jumped over to North America and South America.

"What they have done differently from routine attacks is that they have got into the bank servers and constructed software that is automated.

"It can get around some of the mechanisms that alert the banking system to abnormal activity."

The details of the global fraud come just a day after the MI5 boss warned of the new cyber security threat to UK business.

McAfee researchers have been able to track the global fraud, which still continues, across countries and continents.

"They have identified 60 different servers, many of them in Russia, and they have identified one alone that has been used to steal 60m euro," Kiley said.

"There are dozens of servers still grinding away at this fraud – in effect stealing money."

That's all very reassuring.   Let's put all of our personal medical secrets online ASAP.  Don't worry, your information's safe and secure.

-- SS


Don't Worry, Your Electronic Medical Records Are Getting Safer With Every Passing Day

At my Oct. 2011 post "Still More Electronic Medical Data Chaos, Pandemonium, Bedlam, Tumult and Maelstrom: But Don't Worry, Your Data is Secure" and others in this query link on medical record privacy, http://hcrenewal.blogspot.com/search/label/medical%20record%20privacy I wrote:

"Don't worry, your medical data's safe."

In Jan 2012 I then posted about Joseph Conn of ModernHealthcare.com's article "2011 Closes on a Note of Electronic Medical Record Privacy Breach Shame."

Don't worry, though; the IT industry's leader, finance, to which medicine is always compared, has gotten closer to getting the situation under control:

From MSNBC:

MasterCard, Visa confirm credit card data theft described as 'massive'
March 30, 2012
By Bob Sullivan

Law enforcement officials are investigating what appears to be a massive theft of U.S. consumers' credit card data, MasterCard and Visa confirmed Friday. The computer security expert who first reported the theft said it might involve as many as 10 million MasterCard and Visa accounts, making it one of the largest known credit card heists.

"MasterCard is currently investigating a potential account data compromise event of a U.S.-based entity and, as a result, we have alerted payment card issuers regarding certain MasterCard accounts that are potentially at risk," that association said in a statement. "Law enforcement has been notified of this matter and the incident is currently the subject of an ongoing forensic review by an independent data security organization."

The theft was first reported by well-known computer security journalist Brian Krebs on his blog, KrebsonSecurity.com. Krebs said the crime involves compromise of a credit card payment processor — a "middle man" that handles transactions between retailers and banks [like these middlemen in medicine? - ed.]

The name of that institution is unknown, but processors have long been a target of identity thieves because of the enormous amounts of data they control. In 2008, Princeton, N.J.,-based Heartland Systems was hacked, exposing tens of millions of credit card account numbers to theft.

Krebs reported that hackers had access to the unknown processors data from Jan 21 through Feb 25, and were able to siphon off enough data to easily create counterfeit cards. His sources called the leak "massive."

...
Gartner security expert Avivah Litan said she's been told that the stolen data is already being used on the street by identity thieves.

"I’ve spoken with folks in the card business who are seeing signs of this breach mushroom. Looks like the hackers have started using the stolen card data more recently," she said.


Read the whole article at the link.

Don't let this trouble you, however. The problem is getting closer to a solution with each mega-break in.

They'll have it fixed any day now, so have no fear telling your EHR-equipped doctor all your private and most sensitive medical business.

-- SS

Proposed new Consumer Privacy Bill of Rights: Is It Too Late For Healthcare?

From the White House:
http://www.whitehouse.gov/the-press-office/2012/02/23/fact-sheet-plan-protect-privacy-internet-age-adopting-consumer-privacy-b

The White House
Office of the Press Secretary
For Immediate Release
February 23, 2012

Plan to Protect Privacy in the Internet Age by Adopting a Consumer Privacy Bill of Rights

CONSUMER PRIVACY BILL OF RIGHTS

The Consumer Privacy Bill of Rights applies to personal data, which means any data, including aggregations of data, that is linkable to a specific individual. Personal data may include data that is linked to a specific computer or other device. The Administration supports Federal legislation that adopts the principles of the Consumer Privacy Bill of Rights. Even without legislation, the Administration will convene multi-stakeholder processes that use these rights as a template for codes of conduct that are enforceable by the Federal Trade Commission. These elements—the Consumer Privacy Bill of Rights, codes of conduct, and strong enforcement—will increase interoperability between the U.S. consumer data privacy framework and those of our international partners.

  1. INDIVIDUAL CONTROL: Consumers have a right to exercise control over what personal data companies collect from them and how they use it. Companies should provide consumers appropriate control over the personal data that consumers share with others and over how companies collect, use, or disclose personal data. Companies should enable these choices by providing consumers with easily used and accessible mechanisms that reflect the scale, scope, and sensitivity of the personal data that they collect, use, or disclose, as well as the sensitivity of the uses they make of personal data. Companies should offer consumers clear and simple choices, presented at times and in ways that enable consumers to make meaningful decisions about personal data collection, use, and disclosure. Companies should offer consumers means to withdraw or limit consent that are as accessible and easily used as the methods for granting consent in the first place.
  2. TRANSPARENCY: Consumers have a right to easily understandable and accessible information about privacy and security practices. At times and in places that are most useful to enabling consumers to gain a meaningful understanding of privacy risks and the ability to exercise Individual Control, companies should provide clear descriptions of what personal data they collect, why they need the data, how they will use it, when they will delete the data or de-identify it from consumers, and whether and for what purposes they may share personal data with third parties.
  3. RESPECT FOR CONTEXT: Consumers have a right to expect that companies will collect, use, and disclose personal data in ways that are consistent with the context in which consumers provide the data. Companies should limit their use and disclosure of personal data to those purposes that are consistent with both the relationship that they have with consumers and the context in which consumers originally disclosed the data, unless required by law to do otherwise. If companies will use or disclose personal data for other purposes, they should provide heightened Transparency and Individual Control by disclosing these other purposes in a manner that is prominent and easily actionable by consumers at the time of data collection. If, subsequent to collection, companies decide to use or disclose personal data for purposes that are inconsistent with the context in which the data was disclosed, they must provide heightened measures of Transparency and Individual Choice. Finally, the age and familiarity with technology of consumers who engage with a company are important elements of context. Companies should fulfill the obligations under this principle in ways that are appropriate for the age and sophistication of consumers. In particular, the principles in the Consumer Privacy Bill of Rights may require greater protections for personal data obtained from children and teenagers than for adults.
  4. SECURITY: Consumers have a right to secure and responsible handling of personal data. Companies should assess the privacy and security risks associated with their personal data practices and maintain reasonable safeguards to control risks such as loss; unauthorized access, use, destruction, or modification; and improper disclosure.
  5. ACCESS AND ACCURACY: Consumers have a right to access and correct personal data in usable formats, in a manner that is appropriate to the sensitivity of the data and the risk of adverse consequences to consumers if the data is inaccurate. Companies should use reasonable measures to ensure they maintain accurate personal data. Companies also should provide consumers with reasonable access to personal data that they collect or maintain about them, as well as the appropriate means and opportunity to correct inaccurate data or request its deletion or use limitation. Companies that handle personal data should construe this principle in a manner consistent with freedom of expression and freedom of the press. In determining what measures they may use to maintain accuracy and to provide access, correction, deletion, or suppression capabilities to consumers, companies may also consider the scale, scope, and sensitivity of the personal data that they collect or maintain and the likelihood that its use may expose consumers to financial, physical, or other material harm.
  6. FOCUSED COLLECTION: Consumers have a right to reasonable limits on the personal data that companies collect and retain. Companies should collect only as much personal data as they need to accomplish purposes specified under the Respect for Context principle. Companies should securely dispose of or de-identify personal data once they no longer need it, unless they are under a legal obligation to do otherwise.
  7. ACCOUNTABILITY: Consumers have a right to have personal data handled by companies with appropriate measures in place to assure they adhere to the Consumer Privacy Bill of Rights. Companies should be accountable to enforcement authorities and consumers for adhering to these principles. Companies also should hold employees responsible for adhering to these principles. To achieve this end, companies should train their employees as appropriate to handle personal data consistently with these principles and regularly evaluate their performance in this regard. Where appropriate, companies should conduct full audits. Companies that disclose personal data to third parties should at a minimum ensure that the recipients are under enforceable contractual obligations to adhere to these principles, unless they are required by law to do otherwise.

For an example of some of the major problems with healthcare data, see my Oct. 2009 post "Health IT Vendors Trafficking in Patient Data?"

I like the proposals.

The question is, regarding electronic health data: are these Federal proposals too little, too late?

Complex systems such as massive computer networks (with myriad stakeholders seeking to 'game' the system, skirt the boundaries of the law, and make handsome profits) can become uncontrollable.

-- SS

2011 Closes on a Note of Electronic Medical Record Privacy Breach Shame

At my Oct. 2011 post "Still More Electronic Medical Data Chaos, Pandemonium, Bedlam, Tumult and Maelstrom: But Don't Worry, Your Data is Secure" and others in this query link on medical record privacy, http://hcrenewal.blogspot.com/search/label/medical%20record%20privacy I wrote:

"Don't worry, your medical data's safe."

Joseph Conn of ModernHealthcare.com apparently disagrees (with my sarcasm, that is) and states the obvious outright. I post his story with few comments and several emphases which are mine:

Year closes on a note of breach shame
Modern Healthcare
Dec. 2012

Three-eighty. Three-eighty. Do I hear four hundred?

With 2011 winding down, there are now 380 major data breaches involving 500 or more patients' records listed on the "wall of shame" website kept by HHS' Office for Civil Rights.

So far, from the first wall postings in September 2009 through the latest on Dec. 8 this year, there have been 18,059,831 "individuals affected," and even that massive number is an undercount of the breach problem.

First, the civil rights office hasn't yet released the records of tens of thousands of breaches it has received under a federal reporting mandate on breaches affecting fewer than 500 patients per incident. I've been asking for electronic copies of those records since June. I hope to hear soon on an appeal of a decision last fall by HHS, claiming that the civil rights office can hide those reports while it "investigates" an estimated 30,000 or more breaches they describe.

Second, even the OCR's posted numbers are low.

A Nov. 4 public notice on a breach reported by the UCLA Health System states that "some personal information on 16,288 patients" was stolen, but the wall of shame lists the "individuals affected" in the UCLA incident as 2,761.

UCLA spokeswoman Dale Tate said in an e-mail that the nearly six-times-larger number in its notice "represents the number of individuals who had some information on the hard drive," while the 2,761 figure sent to the OCR "represents the number of people that met the specific criteria" under the federal breach notification rule.

Under the federal rule, Tate says, "the information for these individuals could possibly cause more than a minimal amount of financial, reputational or other harm." Information on the rest of the individuals, Tate said, did not meet the criteria.

Not to get too harpy, but this breach stuff is long past being ridiculous.

The lawyers are already all over it, and maybe that's what it will take for the industry to finally start addressing the problem. Brian Kabateck, a California lawyer, thinks so.

In the past three months, his Los Angeles law firm has filed a pair class-action breach suits against two of the most highly regarded healthcare systems in the state, University of California, Los Angeles and Stanford, as well as one of the latter's business associates, Multi-Specialty Collection Services.

"I think this is a short blip on the radar," Kabateck said. As the settlement costs pile up, he said, "I think big institutions are going to learn—five years from now, these lawsuits are going to be obsolete."

Class-action lawsuits are needed as much for health IT risk and safety issues causing near-misses, injuries and death as for security breaches, I note.

I think five years is highly overoptimistic as well on the breach issue, considering the degree of "institutional learning" that's occurred on how to do health IT "right" over the past ~ three decades, and considering that the breaches that are increasing, not decreasing, in intensity and severity across all industry sectors. That includes industry sectors far better equipped to manage IT security than hospitals.

Right now, though, Kabateck says, "This is not to the level of being an epidemic, but it's close."

I think it is epidemic.

Rather than being a miracle that will revolutionize medicine, health IT is like any other information and communication technology (ICT): it has unintended consequences (UC's) that can dilute or even negate its advantages. The issue of damaged medical record privacy, confidentiality and security is but one UC of health IT.

-- SS

Still More Electronic Medical Data Chaos, Pandemonium, Bedlam, Tumult and Maelstrom: But Don't Worry, Your Data is Secure

Case 1. Tumult
October 5, 2011
New York Times
Patient Data Landed Online After a Series of Missteps

By KEVIN SACK

Private medical data for nearly 20,000 emergency room patients at California’s prestigious Stanford Hospital were exposed to public view for nearly a year because a billing contractor’s marketing agent sent the electronic spreadsheet to a job prospect as part of a skills test, the hospital and contractors confirmed this week. The applicant then sought help by unwittingly posting the confidential data on a tutoring Web site. [Got all that? - ed.]

In an e-mail sent to a victim of the breach, the billing contractor, Joe Anthony Reyna, president of Multi-Specialty Collection Services in Los Angeles, explained that his marketing vendor, Frank Corcino, had received the data directly from Stanford Hospital, converted it to a new spreadsheet and then forwarded it to a woman he was considering for a short-term job.

The position was with Mr. Corcino’s one-man shop, Corcino & Associates, Mr. Reyna wrote in the e-mail, which was authenticated by his lawyer, Ellyn L. Sternfield. The job applicant apparently was challenged to convert the spreadsheet — which included names, admission dates, diagnosis codes and billing charges — into a bar graph and charts, Stanford Hospital officials said.

Not knowing that she had been given real patient data, the applicant posted it as an attachment to a request for help on studentoffortune.com [I wrote about that earlier here - ed.], which allows students to solicit paid assistance with their work. First posted on Sept. 9, 2010, the spreadsheet remained on the site until a patient discovered it on Aug. 22 and notified Stanford.

My, how electronic data can travel when mishandled. Try that trick with 20,000 paper charts ...

The hospital, located on the campus of Stanford University in Palo Alto, demanded that the spreadsheet be removed, and the Web site quickly complied. Pressed for time, the job prospect wound up completing the assignment herself and, in the end, did not get hired, Ms. Sternfield said.

Ironically, this was all for naught.

Mr. Corcino, in his first public statement, attributed the breach to “a chain of mistakes which are far too easy to make when handling electronic data.”

Far too easy to make - especially by the dyscompetent.

... Breaches of private medical data have become distressingly commonplace, with two substantial ones disclosed in the last week alone. [We don't know the details of those yet; that's for next week - ed.]

Case 2: Pandemonium
(from same NYT article)

In Orlando, officials with Florida Hospital reported that three employees had improperly combed through emergency department records of 2,252 patients, apparently to forward information about accident victims to lawyers. The employees were fired, and law enforcement officials are investigating.

Trolling for Torts - is this a new EMR TV game contestant show? Perhaps it could be followed by "Trolling for Tarts?"


Case 3: Bedlam (from the same NYT article)

Meanwhile, Science Applications International Corporation disclosed that computer backup tapes containing medical data for 4.9 million military patients [that number also amounts to almost 2% of the total U.S. population - ed.] had been stolen from an employee’s car in San Antonio. The data included Social Security numbers, clinical notes, laboratory test results and prescriptions. The company said the risk of harm was low because retrieving data from the tapes would require specialized knowledge, software and hardware. [Who's to say the theft was not by someone with that specialization, or someone paid by same to steal the tapes? - ed.]

The Texas breach is by far the largest since September 2009, when a new federal law began requiring disclosures of medical privacy violations involving at least 500 people. Some 330 such episodes have been tallied, including four others that affected more than one million people each.

We'd all be buried in stray clinical paper by now if it weren't for computers. Thank god for them!

Officials at the Department of Health and Human Services said the new reporting requirements had exposed deep vulnerabilities and encouraged renewed vigilance.

Exposed to whom? The blind, deaf and dumb?

“We’re moving in the right direction in terms of a culture of compliance,” said Leon Rodriguez, director of the department’s Office for Civil Rights, which investigates medical privacy cases. “Are there still a lot of problems out there? Yeah, my sense is there are still a lot of problems.”

The Titanic was moving in the right direction - towards New York Harbor, in fact, when it met a little unexpected obstacle. Perhaps a culture of brains would be better than a culture of compliance...

The Stanford breach was notable for the duration of public exposure, and for spotlighting the vulnerability created by a medical provider’s business relationships with outside parties.

Last week, lawyers filed suit in state court in Los Angeles, seeking certification as a class action and $20 million in damages from Stanford Hospital & Clinics and Multi-Specialty Collection Services, which is known as MSCS.

$20 million might hurt a bit, and might help motivate the organization to hire better and/or more appropriate clinical information management expertise - in house where it belongs (see below).

The threat of liability set off a predictable round of finger-pointing.

In written responses to questions, Lisa Lapin, Stanford University’s assistant vice president for university communications, said, “MSCS bears the complete and sole responsibility for the breach.”

It's their fault, not ours.

Ms. Lapin said the hospital had sent the data in encrypted form to Mr. Corcino, who requested it on behalf of MSCS to analyze a strategy for improving billing collections. She said Mr. Corcino had regularly represented himself as MSCS’s executive vice president and had been Stanford’s “primary contact” during a seven-year relationship. MSCS, a five-person firm that audits hospital accounts to maximize reimbursement, possessed the passwords to unencrypt the data, she said.

It was all about money and outsourcing.

“This mishandling of private patient information was in complete contravention of the law and of the requirements of MSCS’s contract and is shockingly irresponsible,” the hospital said in a statement.

It is foolish to believe that someone else can run critical aspects of your business, and it is even more foolish to believe that it is OK for someone else to run critical aspects of your business.

Ms. Sternfield, Mr. Reyna’s lawyer, said Mr. Corcino had never been an MSCS employee, but rather was paid a monthly fee to drum up business, typically in face-to-face meetings with health care executives. Mr. Reyna, she said, had no knowledge that the Stanford data had been sent to Mr. Corcino, or that he had passed it on.

Mr. Corcino was not authorized to use an MSCS title, Ms. Sternfield said, but she declined to say whether Mr. Reyna was aware of the practice. She acknowledged that Mr. Corcino sometimes used an MSCS e-mail account.

In his e-mail to the breach victim, who shared it with The Times, Mr. Reyna wrote that Stanford had sent the file to Mr. Corcino “for a potential MSCS project that would audit paid accounts to verify that the reimbursement was correct.”

For his part, Mr. Corcino said in a statement that he was an independent contractor but was “the marketing face of the company,” and that MSCS “allowed me to use the title of executive vice president.” He wrote: “Stanford sent the file to me at MSCS, and I imported the data into a spreadsheet that was forwarded to the job applicant as part of a skills test. I did not intend to provide any personal health information in the file. This was a marketing project.”

Without explaining how or why he sent the data to the applicant, Mr. Corcino said MSCS had not trained him properly and faulted Stanford for sending him private information that he did not need. That, he said, was the “first link in a chain of mistakes.”

“I regret that Stanford released a file containing unnecessary information,” Mr. Corcino said, “that MSCS did not have an appropriate training and audit system for the handling of electronic data and that I was not more careful with the file. While Stanford and MSCS left the information in the file I received, it was my mistake to not catch its inclusion and remove the data.” ... The hospital has terminated its relationship with MSCS, and Mr. Reyna has done the same with Mr. Corcino.

Even I can't follow all that. This will be one convoluted court case...

Stanford Hospital has reassured affected patients that the posted spreadsheet did not contain Social Security numbers, birthdates or credit card numbers, and has offered free identity theft protection services. The hospital said it had not uncovered any misuse of the exposed data.

Yet, that is. (Is it no wonder that sedatives are among the most highly-prescribed medications?)

Moving from the NYT article:

Case 4: Tumult (I'm running out of descriptors)

A large class action lawsuit again Health Net and IBM:

California Legal
Westlaw Journal Insurance Coverage

Health Net’s, IBM’s negligence compromised medical data, suit says

June 7 (Westlaw Journals) - Health Net Inc. and IBM face a class-action lawsuit seeking $5 million in damages over the loss of computer storage devices that held the medical histories, financial data and Social Security numbers of 2 million people.

Health Net Policyholder Alana Bournas’ class-action complaint in the U.S. District Court for the Eastern District of California alleges that the insurer and IBM breached their duty of confidentiality and negligently allowed the release of highly personal and confidential information of millions of Health Net employees and policyholders.

The complaint alleges violation of California’s Confidentiality of Medical Information Act, Cal. Civ. Code § 56; Cal. Civ. Code § 1798.2, which concerns the unauthorized disclosure of customer records; Cal. Bus. & Prof. Code § 17200, the state’s unfair-competition law; and public disclosure of private facts.

Companies will either pay the going price for competent employees, or pay for the mistakes of incompetent ones. It would probably be better for society, however, to do the former habitually.

The suit says IBM agreed to manage Health Net’s information technology database for five years beginning in 2008.

IBM informed Health Net Jan. 21 that it had lost nine disk drives containing the confidential information of 2 million people, including Health Net policyholders and employees.

Health Net failed to alert the victims of the breach until March 14, the complaint says.

IBM allegedly also failed to encrypt the data, thereby enabling anyone who possesses the hard drives to easily access the confidential information. This puts the victims at an increased risk of identity theft and “other unauthorized uses of plaintiff and class members’ personal information” the suit says.

Encryption, a feature now built into mainstream OS's by Microsoft and Apple? (Oh wait...IBM...)

Health Net’s attempt to compensate the victims by providing two years of free credit monitoring services through TransUnion is an inadequate remedy for the defendant’s conduct, Bournas says. This “remedy” fails to address unauthorized disclosures of medical information, and the monitoring services only protect against new account fraud but do not address fraudulent activity with existing accounts, the suit says.

These executives apparently can't even get the fix straight.

Moreover, the complaint says, Health Net has previously been accused of a similar breach of confidential information. In 2009 it lost the same types of records of nearly 1.5 million people and waited six months before notifying the victims. In settling the state of Connecticut’s lawsuit stemming from that security breach, the company promised “to enhance security procedures and training,” the suit says.

What can I say?

The current breach could have been avoided had Health Net and IBM taken proper precautions and implemented security policies to maintain consumers’ confidential data, according to Bournas. Therefore, the protections granted under California law require that Health Net be penalized for its negligence, she says.

The plaintiff notes that millions of people entrusted Health Net with their private data.

“At best, defendants’ actions allowed this private information to go astray. At worst, the private information is being viewed, sold, resold, and used for illegitimate and illegal purposes,” the complaint says.

The suit is seeking injunctive relief, compensatory damages, declaratory relief, and attorney fees and costs.

Bournas v. Health Net Inc., No. 2_11-CV-01262, complaint filed (E.D. Cal. May 11, 2011).

I would revise that to say "The current breach could have been avoided had Health Net and IBM hired personnel in adequate numbers with the qualifications and true gravitas (and not laid them off, of course) to maintain consumers’ confidential data."

Case 5: Maelstrom (I am reaching to the bottom of the barrel for such descriptors).

Wellpoint recently settled class-action suit in CA.

AMA news
By Pamela Lewis Dolan, amednews staff.
Posted Aug. 1, 2011.

WellPoint reaches tentative accord in data breach suit

It is the second settlement to come from lawsuits claiming that the company failed to protect the privacy of individual insurance applicants online.

WellPoint has reached a preliminary settlement that will, if approved, bring an end to a class-action lawsuit filed more than a year ago.

The lawsuit, filed in the Superior Court of the State of California, involves the potential exposure of data belonging to more than 600,000 individual health insurance applicants on a company-run website that allowed insurance applicants to track their applications.

The situation came to light when an applicant to WellPoint-owned Anthem Blue Cross of California sued the company in March 2010. The applicant was able to manipulate the web address within the site to gain access to other applicants' information, including names, addresses, dates of birth, Social Security numbers and health and financial information.

In other words, probably changing a simple number in the URL brought up someone else's records. Good going there, Wellpoint. What were the programmers thinking? (Were they thinking?)

When the suit was filed, the company said an upgrade to the system caused the information to become exposed. The company said a third-party vendor validated that all security measures were in place when, in fact, they were not. Changes were made to the system soon after the situation was discovered.

Blame someone else, yet again.

In addition to the class-action suit, the company was sued by Indiana Attorney General Greg Zoeller in July 2010. The suit, filed in Marion County Civil Superior Court, alleged that the company violated the Indiana Disclosure of Security Breach Act by failing to notify Zoeller, and the 32,051 Indiana residents affected by the incident, in a timely manner. That suit was settled in early July, when WellPoint agreed to pay a $100,000 fine. As part of the settlement, WellPoint admitted it had a security breach and failed to properly notify the attorney general's office as required by law.

Gevalt.

Under the preliminary settlement in the California class-action matter, WellPoint agreed to offer credit monitoring for two years to all affected individuals. Class members are eligible to receive reimbursement for identity theft losses of up to $50,000 per incident, as well as additional time to file identity theft claims until May 31, 2016. Those making identity theft claims are eligible for an additional five years of credit monitoring. The company also will donate a total of $250,000 to two nonprofit organizations whose efforts are directed at protecting consumers' privacy on the Internet.

It might have been cheaper and better for goodwill not to outsource a vital function...those third-party vendors can really hurt you. (I'd really like to know - was this "third party vendor" domestic, or overseas?)

WellPoint did not admit wrongdoing in the case, nor was it found guilty. A fairness hearing is scheduled for November, and the courts then will decide whether to approve the settlement.

Large corporations are immune from such formalities as admitting wrongdoing or being found guilty.

-----------------------

But don't worry. Your medical data's safe.

Sort of. See also:


-- SS

Another Episode of "But Don't Worry, Your Records are Safe..."

Oops!

NHS trust sends data CD to landfill

By Wesley Johnson

Friday, 16 September 2011

The personal information of 1.6 million people has been put at risk after a CD was sent to a landfill site by an NHS trust by mistake, a watchdog said.

The Eastern and Coastal Kent Primary Care Trust put the CD, which contained the name, address, date of birth, NHS number and GP of about 1.6 million people, in a filing cabinet during an office move.

But no one told staff who sent the cabinet to the landfill site and it has not been recovered, the Information Commissioner's Office said.

... An undertaking signed by the trust's chief executive Ann Sutton read: "The Information Commissioner was provided with a report by the data controller informing that a filing cabinet containing personal data had been sent to landfill during a move of office premises.

"The filing cabinet contained a CD holding the address, date of birth, NHS number and GP practice code of approximately 1.6 million individuals.


Read the whole article. They promise to be more careful - next time.

The trust said it would now take action to bring in clear policies and procedures for when moving office, improve staff training and boost security against unauthorised and unlawful processing, accidental loss, destruction and damage of personal records.

That is reassuring - I guess.

-- SS

New way to get kids interested in medicine: post confidential medical records on a homework site?

Was this a new way to get kids interested in medical careers?

Or was it an accident due to the highest levels of negligence associated with lowest/cheapest standards in hiring for mission critical roles?

Patient Data Posted Online in Major Breach of Privacy
New York Times
Sept. 8, 2011
Kevin Sack

A medical privacy breach at Stanford University’s hospital in Palo Alto, Calif., led to the public posting of medical records for 20,000 emergency room patients, including names and diagnosis codes, on a commercial Web site for nearly a year, the hospital has confirmed.

Since discovering the breach last month, the hospital has been investigating how a detailed spreadsheet made its way from one of its vendors, a billing contractor identified as Multi-Specialty Collection Services, to a Web site called “Student of Fortune,” which allows students to solicit paid assistance with their school work. Gary Migdol, a spokesman for Stanford Hospital and Clinics, said the spreadsheet first appeared on the site on Sept. 9, 2010, as an attachment to a question about how to convert the data into a bar graph.


To teach the kids to be medical bean counters at an early age, perhaps?


Even as government regulators strengthen oversight by requiring public reporting of breaches and imposing heavy fines, experts on medical security said the Stanford incident spotlights the persistent vulnerability posed by legions of outside contractors who gain access to private data.


In the Oct. 2009 post "Private medical records offered for sale" I wrote about how such data was for sale by onion-like layers contractors - cheap.


The spreadsheet contained names, diagnosis codes, account numbers, admission and discharge dates, and billing charges for patients seen at Stanford Hospital’s emergency room during a six-month period in 2009, Mr. Migdol said. It did not include Social Security numbers, birthdates, credit-card accounts or other information used to perpetrate identity theft, he said, but the hospital is offering free identity protection services to affected patients.


(Partial) luck prevailed - this time.


The breach was discovered by a patient and reported to the hospital on Aug. 22, according to a letter written four days later to affected patients by Diane Meyer, Stanford Hospital’s chief privacy officer. The hospital took “aggressive steps,” [i.e., its CIO made a quick, panicky phone call - ed.] and the Web site removed the post the next day, Ms. Meyer wrote. It also notified state and federal agencies, Mr. Migdol said.


Perhaps "aggressive steps" should have been taken before private medical data was published on a kid's homework site?


“It is clearly disturbing when this information gets public,” he said. “It is our intent 100 percent of the time to keep this information confidential and private, and we work hard every day to ensure that.”

Would "Master of the Obvious" (a favorite line of my early medical mentor, cardiothoracic surgeon/polymath Dr. Victor P. Satinsky, be too kind a response to this statement?


Diane Dobson, of Santa Clara, Calif., said her “jaw dropped” on Saturday when she intercepted the letter from Ms. Meyer addressed to her 21-year-old son, who she said received emergency psychiatric treatment at Stanford in 2009. Ms. Dobson said it could have been disastrous if her son, who lives at home, had learned that his name was linked online to a diagnosis for psychosis.

“My son, I can tell you, is fragile and confused enough that this would have sent him over the edge,” Ms. Dobson said. “Everyone with an electronic medical record is at risk, and that means everyone.”


My sympathies go out to this mother and her son. Her concerns show that cavalier attitudes towards EMR's can lead to catastrophe beyond identity theft or career damage.


The incident at Stanford, while egregious in its details, is far from rare. Records compiled by the Department of Health and Human Services reveal that personal medical data for more than 11 million people has been improperly exposed during the last two years alone ... The major breaches — a disconcerting log of stolen laptops, hacked networks, unencrypted records, misdirected mailings, missing files and wayward e-mails — took place in 44 states.


I'm certain there is an increasing amount of critical medical data being withheld by patients as publicity about these breaches become more well-known.


The breaches at Stanford reinforce that even the most prestigious medical centers are not immune to risk.

Massachusetts General Hospital in Boston, which trains Harvard medical students, agreed this year to pay a $1 million federal fine after an employee left paper medical records on a subway train while commuting to work. The pages contained the names of 192 patients, and diagnoses for about a third of them, including for H.I.V./AIDS. They were never recovered.


I note these are both pioneers in electronic health records. Imagine what might be happening at Podunk Hollow General Hospital...


Mr. Migdol said the hospital had concluded that “there is no employee from Stanford Hospital who has done anything impermissible.” He said he expected the federal Department of Health and Human Services to conduct its own investigation. Susan McAndrew, deputy director of health information privacy for the department’s Office of Civil Rights, said she could not discuss whether an investigation was in progress ... Bryan Cline, a vice president with the Health Information Trust Alliance, a nonprofit company that establishes privacy guidelines for health care providers, said that nearly 20 percent of breaches were perpetrated by outside contractors, accounting for more than half of all the records exposed.


When you start to outsource mission critical data, you should probably be prepared to take responsibility for whomever you outsource it to.


The vendor, identified by Mr. Migdol as Multi-Specialty Collection Services LLC, based in Los Angeles, could not be reached for comment. Mr. Migdol said the company created the spreadsheet as part of a billing-and-payment analysis for the hospital. He said the hospital immediately suspended its relationship with the contractor and received written certification that previous files would be destroyed or returned securely.


Apparently someone there with access to the spreadsheet was less than careful about keeping it away from children. One wonders if they would have been more careful with pornography...


“We’re still kind of caught in the pre-high-tech trust model instead of the insurance model,” Mr. Cline said. “Health care providers say, ‘I’m going to have some contract language and then just trust that you’ll protect my data because if you don’t I’m going to sue you.’ That just doesn’t work, as we can see. You have to do due diligence, something to assure yourself that the people you’re giving your data to can be trusted.”


I'd say we're still in the stone age with respect to our irrational exuberance about health IT. See my series of articles on these issues at these query links: computer security, medical record privacy, medical record confidentiality.

A fundamental set of rules in today's hire-on-the-cheap, keep-staffing-minimal environment is this:

1. If you want information to be kept secure, don't place it on a computer.
2. If you place the information on a computer, don't place the computer on a network.
3. If you place the computer on a network, the information is no longer secure.

In our current culture I do not believe these issues to be easily remediable, but hiring the truly best and brightest (after satisfactory scores in a very hard test in critical thinking skills) into IT roles - including design, implementation, and management - might be a start.

-- SS

Blogscan: UK unencrypted laptop health breach affects more than 8.6 million records

From the blog "Australian Health Information Technology":

Who Needs Hackers When There Are Accidents Like This? The PCEHR [Personally Controlled Electronic Health Record - ed.] Won’t Avoid Hacker Attention I Suspect.

The following popped up a little while ago.

By Dom Nicastro

Think the United States has its problems with securing patient health information?

We’re not alone.

London Health Programmes, a medical research organization based at the NHS North Central London health authority, has reported missing an unencrypted laptop containing information of 8.63 million patients and 18 million hospital visits, operations and procedures, according to today’s issue of The Sun.

The data does not include names, “but patients could be identified from postcodes and details such as gender, age and ethnic origin,” according to the newspaper. Information on the laptop included records of cancer, HIV, mental illness and abortions.

The computer was one of 20 lost, and officials have since recovered eight. The research organization “only just” reported the missing laptops to police although they went missing three weeks ago, according to the newspaper.

The Information Commissioner’s Office, Great Britain’s independent authority that promotes data privacy for individuals, has issued a statement regarding the laptop theft:

“Any allegation that sensitive personal information has been compromised is concerning and we will now make inquiries to establish the full facts of this alleged data breach.”

More here with a gruesome list of UK breaches.

http://blogs.hcpro.com/hipaa/2011/06/unencrypted-laptop-health-breach-affects-more-than-8-million-records/

Clearly this sort of incident is made more significant when material like this is appearing regularly.


We've posted numerous times at Healthcare Renewal on the impossible dream of electronic medical record privacy, security and confidentiality. See blog query links here and here.

-- SS

Another Blow to the Health IT Idealists: Sony CEO Howard Stringer, and HHS OIG, on Information Security

In a series of Healthcare Renewal posts such as those linked below, I pointed out that healthcare IT information security was largely a pipe dream, and that plans to create a national network of health information, while a seductive idea dating to the beginnings of computer networking, is not a good idea now.


Now you can hear it from another source: The CEO of one of the world's largest electronic companies, Sony.

Emphases mine:

Sony CEO Warns of 'Bad New World'
Wall Street Journal
May 8, 2011

TOKYO—After spending weeks to resolve a massive Internet security breach, Sony Corp. Chief Executive Howard Stringer said he can't guarantee the security of the company's videogame network or any other Web system in the "bad new world" of cybercrime.

Mr. Stringer's comments in a phone interview Tuesday, ahead of a New York roundtable discussion with reporters, come on the heels of a trying month for Sony. The company partially restored two of its online game systems and a streaming movie and music service over the weekend after shutting the services for several weeks when a breach compromised the personal information of more than 100 million account holders.

While Sony has restored part of the PlayStation Network—an online game system for its PlayStation 3 videogame console—in the U.S. and Europe and bolstered security measures, Mr. Stringer, 69 years old, said maintaining the service's security is a "never-ending process" and he doesn't know if anyone is "100% secure."

He said the security breach at PSN, Sony Online Entertainment, an online game service for personal-computer users, and its Qriocity streaming video and music network his company could lead the way to bigger problems well beyond Sony, or the gaming industry. He warned hackers may one day target the global financial system, the power grid or air-traffic control systems. [And healthcare, where identity theft, data alteration, and data destruction might occur - ed.]


I really don't think this is the time to be setting up a national health information network.

Beyond that, I offer no additional comments, other than that regarding the impossibility of keeping healthcare information secure on a national or even regional network, you may have heard it first here at Healthcare Renewal.

It would be prudent and consistent with the Hippocratic Oath to tone down our grandiose expectations and grandiose plans for these technologies in healthcare.

If you feel insecure yet, just wait a moment.

Going from very, very bad to very much worse:


An independent audit of ONC's and CMS's security programs by the HHS OIG (Office of the Inspector General) produced concerning if not alarming results to say the least:

Federal Audits Find HIT Security Problems at CMS, ONC
John Commins, for HealthLeaders Media
May 18, 2011

Audits of the federal agencies charged with implementing and monitoring security measures for healthcare information technology identified this week lax oversight and insufficient standards for healthcare providers.


The audits were conducted by the Department of Health and Human Services' Office of Inspector General, and targeted HIT security standards, privacy protection under HIPAA, and other security measures at the Centers for Medicare & Medicaid Services, and the Office of the National Coordinator. "
These two reports are being issued simultaneously because OIG found weaknesses in the two HHS agencies entrusted with keeping sensitive patient records private and secure," OIG said in a media release.

The CMS audit,
Nationwide Rollup Review of the Centers for Medicare & Medicaid Services Health Insurance Portability and Accountability Act of 1996 Oversight, examined seven hospitals across the country and found 151 "vulnerabilities" in systems and controls that are designed to safeguard electronic protected health information.

Those lapses included 124 "high impact vulnerabilities" such as
unencrypted laptops and portable drives containing sensitive personal health information, outdated antivirus software and patches, unsecured networks, and the failure to detect rogue devices intruding on wireless networks, the OIG audit said.

"These vulnerabilities placed the confidentiality, integrity, and availability of ePHI at risk. Outsiders or employees at some hospitals could have accessed, and at one hospital did access, systems and beneficiaries' personal data and performed unauthorized acts without the hospitals' knowledge," the OIG audit said. "As a result, CMS had limited assurance that controls were in place and operating as intended to protect electronic protected health information, thereby leaving ePHI vulnerable to attack and compromise.


OIG's Audit of Information Technology Security Included in Health Information Technology Standards examined ONC's mandate under the HITECH Act to develop HIT security as part of a national HIT interoperability infrastructure. The audit found "no HIT standards that included general information IT security controls … which provide the structure, policies, and procedures that apply to a healthcare provider's overall computer operations, ensure the proper operation of information systems [which obviously also impacts patient safety - ed.], and create a secure environment for application systems and controls.


That's not very reassuring. In fact, it is downright frightening. ONC has to learn such lessons from HHS OIG? Read the whole thing.

I somewhat mordantly note that organizations such as ONC and CMS would probably never hire a person like me, who might actually kick-start true critical thinking on these issues. This is due to my non-bien pensant "bad attitudes", and lack of faith in cybernetic idols.


Click to enlarge. A well-known idol of gold. Computer circuits use gold, no?

-- SS


Medical Data Breach of the Month Department: Health Net Once Again a Star in the Healthcare Renewal Theatre

I have written frequently about the breaches of electronic information security, such as at my posts:

"Networked EMR's and Healthcare Information Security: Practical When Massive IT Security Breaches Continue?"

"Networked, Interoperable, Secure National Medical Records a Castle in the Sky?"

"Operation Aurora And a Widespread Reluctance to Discuss IT Flaws: Is Universal Healthcare IT Really a Good Idea in 2010?"

Medical data breach of the week - but your EMR data is secure, trust us, we're IT experts

and others.

This latest medical information breach only affected a mere 2 million people this time.

Perhaps we should go for 20 million next time?

And then - there were substantial delays in notification (to give identity thieves time to get rich?)

Health Net Delays Notification of Data Breach Involving 2 Million People

By: Brian T. Horowitz
2011-03-16

Insurer Health Net waited until March 14 to disclose a data breach discovered on Jan. 21 involving the loss of nine server drives and the data of 2 million customers, employees and health care providers.

Health Net, a provider of health insurance to about 6 million people across the United States, has come under fire for reporting the loss of nine server drives at its data center in Rancho Cordova, Calif., nearly two months after it occurred.

More than 2 million Health Net members, employees and health care providers may have been affected by the data breach, including about 845,000 California policyholders, according to The San Francisco Chronicle. California regulators are investigating the breach, the newspaper reports.

How did this happen?

The insurer found out about the security lapse on Jan. 21, when IBM, which manages the company's IT infrastructure, informed Health Net that it was unable to locate server drives, according to a recording on Health Net's data breach hotline (855-434-8081).

These drives perhaps are of a new technology, with motorized robotic legs that allow them to walk away.

Or perhaps the drives were like this, where the round drive platter stacks perform double duty as wheels:


A "mobile" hard drive. Click to enlarge.


The drives just rolled away - to the tune of Steppenwolf's "Born to be Wild" ...


These drives were just Born to be Wild! Click to play.


Get your motor runnin' ... head out on the highway ...

The health benefits provider began its investigation at that time and learned that the nine drives included personal information for former and current Health Net members, employees and health care providers. The company didn't report the breach to the public until March 14.

Gee, thanks.

Health Net spokesman Brad Kieffer declined eWEEK's request for additional information on the breach but said, "We continue investigating unaccounted for server drives, and out of an abundance of caution we are notifying our members."

"Abundance of caution" and an almost 2-month delay do not belong in the same news story.

... "Given the size and type of data lost, this is a serious breach, and those affected should have been notified and protected immediately when IBM notified Health Net of the loss," Rob Enderle, principal analyst for the Enderle Group, wrote in an e-mail to eWEEK.

Indeed.

"While the delay was likely due to the belief that these drives were either misplaced or reused and not logged and the hope they would turn up on a maintenance rotation, the exposure to those that may have been compromised is excessive, and for an insurance company not to immediately mitigate this exposure—unforgivable," Enderle said.

"Hope/keeping your fingers crossed" and "due diligence/corporate responsibility" also do not belong in the same paragraph.

Information included names, addresses, health information, Social Security numbers and/or financial information, Health Net reports. .

All the news that's fit to print.


The Health Net breach could be the most serious health care data breach since 2008, when incidents affected 2.2 million people at the University of Utah and 2.1 million people at the University of Miami, according to the San Francisco Chronicle report.

Since 2008, eh, way back when, ancient history, when dinosaurs ruled the earth?

In May 2009, Health Net suffered another security breach in which a portable disk drive holding the medical and financial data on 1.5 million members disappeared from its Connecticut headquarters.

The portable disk drives must have robotic legs, too.

Data breach penalties for Health Net could be severe, according to Enderle.

Perhaps that's why they were crossing their fingers hoping the drives would turn up somehow?

Finally, I note that this company has also been busy in recent years making a name for themselves in the Healthcare Renewal Theatre in other ways. They're stars! See http://hcrenewal.blogspot.com/search/label/Health%20Net

-- SS

Windows 7 Service Pack 1 "Glitches": Why Personal Computers are Problematic, and Perhaps Should Not Be Mission Critical Components in Hospitals

A technical note on computer unreliability, and a series of followup critical questions relative to health IT:

I run Windows 7 Professional on one of my computers, a very unspecial 4-5 year old Micro Center machine, the PowerSpec 6001, using conventional components. The machine was upgraded with 2 Gb RAM and an ATI Radeon 9600 series video card, to run the Aero "eye candy."

It has run satisfactorily since I installed Windows 7 Professional (32-bit version) on it last year.

I am not a computer amateur. [I do, however, admit to being a Radio Amateur - Extra class - ed.] Further, I meticulously keep the machine current with Microsoft security patches, use Symantec anti-virus which I also keep updated, check my disk for errors, and only visit major well-known, nationally prominent websites using the machine.

So yesterday, Windows 7 Service Pack 1 appeared in my "Software updates" list from Microsoft, after being released to the general public.

It was explained that this Service Pack improves performance, reliability and security [i.e., it is intended to update all the many, many bugs, unreliabilities and security holes of the operating system since its inception - ed.]

I confirmed my machine met the specs for it, and allowed the computer to download and install Service Pack 1.

That was my mistake.

After installation, the machine could no longer reboot Windows.

The flying color patches of the first screen appeared ... and then the machine suffered a hard reboot (going back to the BIOS-initiated memory checks and screens, etc.), as if I'd pressed the front panel hardware RESET button this machine has.

An automated "wizard" that came up and tried to figure out why the machine would not restart failed to do so.

I asked the machine, therefore, to roll back to the state it was in prior to the Service Pack 1 (SP1) "upgrade" via a "Restore Point", a feature Windows permits using the "system restore" capability. The SP1 installation automatically creates a Restore Point (image of the prior state of the OS) on the machine just before installing itself.

The machine works again, but ... (and that is a big "but"):

  • The Service Pack is not installed. Therefore I am not running the latest protections, and do not know what will happen in the future with respect to patches and upgrades. Maybe the Service Pack will get its own Service Pack at some point to fix it, so it can fix my computer;
  • The Service pack installation, without warning and rather rudely, erased my prior computer Restore Points of the past few weeks, leaving only the Restore Point it created just before inflicting itself on my machine. Just to thumb its nose at me, it also left two Restore Points from back in November, which would require me to then re-install a lot of software and updates at the very least. I cannot even try a Restore Point of, say, last week after other updates;
  • I attempted to view the system error logs to determine what caused the failed Service Pack Install. Surprise! The Event Viewer and Task Scheduler management consoles I use to review system operation no longer operated, instead producing this lovely, extremely explanatory message: "MMC cannot initialize the snap-in", followed by hexadecimal gibberish that any doctor or citizen can easily decipher:

Such explanatory error messages! "MMC cannot initialize the snap-in. The snap-in might not have been installed correctly. Name: Event viewer. CLSID: FX: {b05566ad-fe9c-4363-be05-7a4cbb7cb510}." Click to enlarge.

  • Attempts to look up the error on the Web produce gobs and gobs of amateurish "legible gibberish", indirection, misdirection, guesswork, and speculation, some of it from Microsoft itself;
  • To add insult to injury, typical of poor user interaction design, I could not copy-and-paste the error, but had to type it (partially, fortunately, thanks to Google);
  • Much of the material was in very broken English (where's those language translators promised to us for some 50 years now by computer scientists?)
  • My attempts at repairing the damage by running the command "SFC /scannow" (system file check) to check and repair critical windows files showed that the Service Pack "Upgrade" also corrupted a number of critical Windows system files - despite the "Restore Point" rollback. Great Scott!
  • SFC repaired the files and produced a log of gibberish that's thousands of pages long for me to ferret out what got damaged (ironically, just like the records from a few weeks of a relative's EMR-error-related hospitalization, at appx. 2,900 pages of legible gibberish);
  • The repair did not restore the missing functionality;
  • Attempts to reinstall supporting packages such as .Net framework also do not restore the functionality;
  • Attempts to reinstall the Service Pack produce the same results, a crash on initial restart after the installation and need to roll back, erasure of several Restore Points I manually created, along with re-corruption of the critical system files previously repaired by the SFC /scannow command.
  • I have no way of knowing what else is broken or may malfunction;

Russian Roulette, anyone?

All this was after many months of Microsoft "Beta testing" the Service Pack. (Perhaps it was really "Alpha testing?")

Similar issues occurred with the former Microsoft OS, Windows XP (now in its third major service pack since its release in 2002, with patches still coming on an almost weekly basis).

Fortunately, I have backup images of my entire disk, but the inconvenience and time wasted is quite irritating - and I will still not have the latest security patches after I roll back my machine to my latest disk image.


One should note that these "glitches" are just in the Operating System (OS) itself. Third-party applications (such as EMR and CPOE sytems, middleware, interfaces, etc.) suffer the same type of problems...for instance, the life-and-limb-threatening "glitches" that occurred at Trinity Healthcare after an EMR "upgrade."

Further, OS "glitches" can cause unexpected application "glitches", and vice versa. Complexity on top of complexity...

Note that machines running similar software are on the "servers" that are the heart of major enterprise systems such as EMR's and CPOE's, that communicate with enduser workstations.

Now, several simple questions:

  • Who knows what other "glitches" the Service Pack introduced to my machine, that will "bite me" (or patients) later?
  • Are these the machines we want our doctors and nurses to depend upon, since they increasingly regulate every medical transaction that occurs?
  • Has the software become too complex to be entirely reliable, maintainable and secure?
  • Does the average hospital have the staff to effectively deal with issues such as the above?
  • Do these "glitches" raise the risk and the cost - therefore reducing the ROI, already low (see reading list) - of experimental health IT to even more unsatisfactory levels?

Finally:

  • Would the average person tolerate such behavior from their car? In their aircraft? (Oops, the brakes don't work properly in 13.5% of cars after the parts upgrade, and that altimeter is simply crazy ...)
-- SS

Feb. 24 late night addendum:

Deciding to play with this mayhem, and knowing I was going to be wasting a lot of time, I first backed up my deranged machine to an external disk (~ half an hour) to preserve my files. I then restored my machine from an external disk backup image to its condition in mid-Nov. 2010 [thinking perhaps something more recent caused the SP1 to fail]. That took another half an hour. I then attempted to install the SP1 again. That took another hour or more.

Same results - machine crash after the "circling window panes" display.

I let the "Startup Repair" wizard run. It failed with the following informative messages. In a superb example of poor user design, I had to jot the messages down on paper, as it made no offer to print them, or load them into a thumb drive, etc. - although it did offer to send the error messages to Microsoft, a neat trick as the software components to drive the computer's wireless network adapter were not loaded:

Problem details - System Repair
Problem signature:

1- 6.1.7600.16385
2- 6.1.7600.16385
3 - unknown
4 - 21201077
5- AutoFailure
6 - 3
7 - BadPatch

OS version - 6.1.7600.2.0.0
Local ID - 1033256.1
Root cause - a patch is preventing the system from starting [no fooling - ed.]
Repair Action
System file integrity check and repair
Result = Failed.
Error code = 0xa

Then for added fun, I started the machine up in 'Safe Mode' (using the F8 key at startup). It came up, but told me it was doing a System Restore due to the failure to configure the Service Pack. After about 20 minutes of frantic disk activity, the machine rebooted - and immediately crashed as before.

I am rerunning the Startup Repair wizard again, asking it to restore my system, but I predict it will do so with the original remaining problems of non-functioning components that started this whole mess - if it works at all.

This is all absurd. It is a massive waste of time, a result of poor programming, uninformative, cryptic error messages (what? computers don't have enough storage for useful error messages?), poor (nonexistent) documentation, inadequate attention to the user experience, condescension of the user, inability to report the problems back to HQ automatically due to lack of forethought about a compromised machine's ability to access the network, software unreliability, and probably a host of other issues I haven't thought of yet because I'm tired after all this fritter.

Not to mention, it is potentially destructive of data to those who suffer this problem but did not keep backups. They warn you beforehand - but the installation agreement you "sign" is of the Ross Koppel/David Kreda "hold the vendor harmless" variety.

This experience is a metaphor for the state of health IT (with "glitches", "workarounds", unexplained errors, etc.), and of the dangers of computer worship.

-- SS

Feb 25 addendum - further experimentation based on web comments about SP1, such as running a pre-SP1 readiness checking utility by Microsoft, emptying the /temp folders, renaming the "software distribution" folder, clean booting, etc. all produce the same result: crash of the machine on reboot.

And there's no computer doctor to call for an appointment to fix the problem.

-- SS