Showing posts with label healthcare IT regulation. Show all posts
Showing posts with label healthcare IT regulation. Show all posts

FDA Safety and Innovation Act: To contain an "Appropriate, risk-based regulatory framework pertaining to health information technology"

Congress has just released an an Act "to amend the Federal Food, Drug, and Cosmetic (FD&C) Act to revise and extend the user-fee programs for prescription drugs and medical devices, to establish userfee programs for generic drugs and biosimilars, and for other purposes."  Health IT provisions are included.

This Act, S. 3187, is entitled the ‘‘Food and Drug Administration Safety and Innovation Act.’’  PDF fulltext is located at this link:  http://www.gpo.gov/fdsys/pkg/BILLS-112s3187enr/pdf/BILLS-112s3187enr.pdf

With regard to health IT, the Act states the following.  A risk-based regulatory framework pertaining to health IT is to be developed (emphases mine):



SEC. 618. HEALTH INFORMATION TECHNOLOGY.


(a) REPORT.—Not later than 18 months after the date of enactment of this Act, the Secretary of Health and Human Services (referred to in this section as the ‘‘Secretary’’), acting through the Commissioner of Food and Drugs, and in consultation with the National Coordinator for Health Information Technology and the Chairman of the Federal Communications Commission, shall post on the Internet Web sites of the Food and Drug Administration, the Federal Communications Commission, and the Office of the National Coordinator for Health Information Technology, a report that contains a proposed strategy and recommendations on an appropriate, risk-based regulatory framework pertaining to health information technology, including mobile medical applications, that promotes innovation, protects patient safety, and avoids regulatory duplication.


(b) WORKING GROUP.—
(1) IN GENERAL.—In carrying out subsection (a), the Secretary may convene a working group of external stakeholders and experts to provide appropriate input on the strategy and recommendations required for the report under subsection (a).

(2) REPRESENTATIVES.—If the Secretary convenes the working group under paragraph (1), the Secretary, in consultation with the Commissioner of Food and Drugs, the National Coordinator for Health Information Technology, and the Chairman of the Federal Communications Commission, shall determine the number of representatives participating in the working group, and shall, to the extent practicable, ensure that the working group is geographically diverse and includes representatives of patients, consumers, health care providers, startup companies, health plans or other third-party payers, venture capital investors, information technology vendors, health information technology vendors, small businesses, purchasers, employers, and other stakeholders with relevant expertise, as determined by the Secretary.


While a welcome development, it is to be determined if the Working Group representatives will include critical thinkers without conflict of interest, whose contributions to the health IT debate in this country are needed a lot more than the traditional hyper-enthusiasts, industry courtiers and opportunists.

I am actually not hopeful.

The "promotes innovation" and "avoids regulatory duplication" phrases are of especially great concern.  As I've written before, "innovation" that involves non-consented experimentation is not innovation at all, it is exploitation, and "regulatory duplication" can become an excuse for milquetoast regulation by the conflicted (e.g., regulatory capture) or poorly qualified.

I also note that this Act, while welcome, is long overdue - another example of putting the cart before the horse (link), with a national project (including CMS penalties for non-adopters) now several years underway.

Final thought:  if health IT were safe as has been claimed now for decades, or had been made safe through proper development and clinical trials-based testing, we would not need health IT provisions in a  "Food and Drug Administration Safety and Innovation Act" in 2012.

-- SS

WSJ "There's a Medical App for That—Or Not" - Misinformation on Health IT Safety Regulation?

There's a health IT meme that just won't die (patients may, but not the meme).

It's the meme that health IT "certification" is a certification of safety.

I expressed concern about the term "certification" being misunderstood even before the meme formally appeared, when the term was adopted by HHS with regard to evaluation of health IT for adherence to the "meaningful use" pre-flight features checklist.  See my mid-2009 post "CCHIT Has Company" where I observed:

HIT "certification." ... is a term I put in quotes since it really is "features qualification" at this point, not certification such as a physician receives after passing Specialty Boards.

The "features qualification" is an assurance that the EHR functions in way that could enable an eligible provider or eligible hospital to meet the Center for Medicare & Medicaid Services' (CMS) requirements of "Meaningful Use."  No rigorous safety testing in any meaningful sense is done, and no testing under real-world conditions is done at all.

I've seen the meme in various publications and venues.  I've even seen it in legal documents in medical malpractice cases where EHR's were involved, as an attempted defense.

Now the WSJ has fallen for the health IT Certification meme.

An article "There's a Medical App for That—Or Not" was published on May 29, 2012.  Its theme is special regulatory accommodation for health IT in the form of opposition to FDA regulation of devices such as "portable health records and programs that let doctors and patients keep track of data on iPads."

In the article, this assertion about health IT "certification" is made:

... The FDA's approach to health-information technology risks snuffing out activity at a critical frontier of health care. Poor, slow regulation would encourage programmers to move on, leaving health care to roil away for yet another generation, fragmented, disconnected and choking on paperwork.

The process already exists for safeguarding the public for computers in health care. It's not FDA premarket review but the health information technology certification program, established under President George W. Bush and still working fine under the Obama Health and Human Services Department. The government sets the standards and an independent nonprofit [ATCB, i.e., ONC Authorized Testing and Certification Bodies - ed.] ensures that apps meet those standards. It's a regulatory process as nimble as the breakout industry it's meant to monitor. That is where and how these apps should be regulated.

It's a wonderful meme.  Unfortunately, it's wrong.  Dead wrong.

Certification by an ATCB does not "safeguard the public."   Two ONC Authorized Testing and Certification Bodies (ATCB's) admitted this in email, as in my Feb. 2012 post "Hospitals and Doctors Use Health IT at Their Own Risk - Even if Certified".  I had asked them, point-blank:

"Is EHR certification by an ATCB a certification of EHR safety, effectiveness, and a legal indemnification, i.e., certifying freedom from liability for EHR use of clinical users or organizations? Or does it signify less than that?"

I received two replies from major ONC ATCB's indicating that "certification" is merely assurance that HIT meets a minimal set of "meaningful use" guidelines, not that it's been vetted for safety.  For instance:

From: Joani Hughes (Drummond Group)
Sent: Monday, March 05, 2012 1:06 PM
To: Scot Silverstein
Subject: RE: EHR certification question

Per our testing team:

It is less than that. It does not address indemnification although a certification could be used as a conditional part of some other form of indemnification function, such as a waiver or TOA, but that is ultimately out of the scope of the certification itself. Certification in this sense is an assurance that the EHR functions in way that could enable an eligible provider or eligible hospital to meet the CMS requirements of Meaningful Use Stage 1. Or to restate it more directly, CMS is expecting eligible providers or eligible hospitals to use their EHR in “meaningful way” quantified by various quantitative measure metrics and eligible providers or eligible hospitals can only be assured they can do this if they obtain a certified EHR technology.

Please let me know if you have any questions.

Thank you,
Joani.

Joani Hughes
Client Services Coordinator
Drummond Group Inc.

The other ATCB, ICSA Labs, stated that:

... Certification by an ATCB signifies that the product or system tested has the capabilities to meet specific criteria published by NIST and approved by the Office of the National Coordinator. In this case the criteria are designed to support providers and hospitals achieve "Meaningful Use." A subset of the criteria deal with the security and patient privacy capabilities of the system.

Here is a list of the specific criteria involved in our testing:
http://healthcare.nist.gov/use_testing/effective_requirements.html

In a nutshell, ONC-ATCB Certification deals with testing the capabilities of a system, some of them relate to patient safety, privacy and security functions (audit logging, encryption, emergency access, etc.).

What was suggested in the email below (freedom from liability for users of the system, etc.) would be out of scope for ONC-ATCB testing based on the given criteria. [I.e., certification criteria - ed.] I hope that helps to answer your question.

I had noted that:

... My question was certainly answered [by the ATCB responses]. ONC certification is not a safety validation, such as in a document from NASA on aerospace software safety certification, "Certification Processes for Safety-Critical and Mission-Critical Aerospace Software" (PDF) which specifies at pg. 6-7:
In order to meet most regulatory guidelines, developers must build a safety case as a means of documenting the safety justification of a system. The safety case is a record of all safety activities associated with a system throughout its life. Items contained in a safety case include the following:

• Description of the system/software
• Evidence of competence of personnel involved in development of safety-critical software and any
safety activity
• Specification of safety requirements
• Results of hazard and risk analysis
• Details of risk reduction techniques employed
• Results of design analysis showing that the system design meets all required safety targets
Verification and validation strategy
• Results of all verification and validation activities
• Records of safety reviews
• Records of any incidents which occur throughout the life of the system
• Records of all changes to the system and justification of its continued safety

A CCHIT ATCB juror, a physician informatics specialist, has also done a guest post in Jan. 2012 on HC Renewal about the certification process, reproducing his testimony to HHS on the issue.  That post is "Interesting HIT Testimony to HHS Standards Committee, Jan. 11, 2011, by Dr. Monteith."  Dr. Monteith testified (emphases mine):

... I’m “pro-HIT.” For all intents and purposes, I haven’t handwritten a prescription since 1999.

That said and with all due respect to the capable people who have worked hard to try to improve health care through HIT, here’s my frank message:

ONC’s strategy has put the cart before the horse. HIT is not ready for widespread implementation. 

... ONC has promoted HIT as if there are clear evidence-based products and processes supporting widespread HIT implementation.

But what’s clear is that we are experimenting…with lives, privacy and careers.

... I have documented scores of error types with our certified EHR, and literally hundreds of EHR-generated errors, including consistently incorrect diagnoses, ambiguous eRxs, etc.

As a CCHIT Juror, I’ve seen an inadequate process. Don’t get me wrong, the problem is not CCHIT. The problem stems from MU.

EHRs are being certified even though they take 20 minutes to do a simple task that should take about 20 seconds to do in the field.  [Which can contribute to mistakes and "use error" - ed.] Certification is an “open book” test. How can so many do so poorly?

For example, our EHR is certified, even though it cannot generate eRxs from within the EHR, as required by MU.

To CCHIT’s credit, our EHR vendor did not pass certification. Sadly, our vendor went to another certification body, and now they’re certified.

MU does not address many important issues. Usability has received little more than lip-service. What about safety problems and reporting safety problems? What about computer generated alerts, almost all of which are known to be ignored or overridden (usually for good reason)?
 
The concept of “unintended consequences” comes to mind.

All that said, the problem really isn’t MU and its gross shortcomings, it is ONC trying to do the impossible:

ONC is trying to artificially force a cure for cancer, basically trying to promote one into being, when in fact we need to let one evolve through an evidence-based, disciplined process of scientific discovery and the marketplace.

Needless to say, as was learned at great cost in past decades, a "disciplined process" in medicine includes meaningful safety regulation by objective outside experts.

Further, the certifiers have no authority to do important things such as forcibly remove dangerous software from the market.  An example is the forced Class 1 recall of a defective system as I wrote about in my Dec. 2011 post "FDA Recalls Draeger Health IT Device Because This Product May Cause Serious Adverse Health Consequences, Including Death".   Class 1 recalls are the most serious type of recall and involve situations in which there is a reasonable probability that use of these products will cause serious adverse health consequences or death.

In that situation, the producer had been simply advising users (in critical care environments, no less) to "work around the defects" that could indicate incorrect recommended dosage values of critical meds, including a drug dosage up to ten times the indicated dosage, as well as corrupt critical cardiovascular monitoring data.  As I observed:

... I find a software company advising clinicians to make sure to "work around" blatant IT defects in "acute care environments" the height of arrogance and contempt for patient safety.

Without formal regulatory authority to take actions such as this FDA recall, "safeguarding the public" is a meaningless platitude.

It's also likely the ATCB's, which are private businesses, would not want the responsibility of "safeguarding the public."  That responsibility would open them up to litigation when patient injuries or death were caused, or were contributed to, by "certified" health IT.

I have in the past also noted that the use of the term "certification" might have been deliberate, to mislead potential buyers exactly into thinking that "certification" is akin to a UL certification of an electrical appliance for safety, or an FAA approval of a new aircraft's flight-worthiness.

The WSJ needs to clarify and/or retract its statement, as the statement is misinformation.

At my Feb. 2012 post "Health IT Ddulites and Disregard for the Rights of Others" I observed:

Ddulites [HIT hyper-enthusiasts - ed.] ... ignore the downsides (patient harms) of health IT.

This is despite being already aware of, or informed of patient harms, even by reputable sources such as FDA (Internal FDA memo on H-IT risks), The Joint Commission (Sentinel Events Alert on health IT), the NHS (Examples of potential harm presented by health software - Annex A starting at p. 38), and the ECRI Institute (Top ten healthcare technology risks), to name just a few.

In fact, the hyper-enthusiastic health IT technophiles will go out of their way to incorrectly dismiss risk management-valuable case reports as "anecdotes" not worthy of consideration (see "Anecdotes and medicine" essay at this link).

They will also make unsubstantiated, often hysterical-sounding claims that health IT systems are necessary to, or simply will "transform" (into what, exactly, is usually left a mystery) or even "revolutionize" medicine (whatever that means).

Health IT is a potentially dangerous technology.   It requires meaningful regulation to "safeguard the public."  How many incidents like this and this will it take before that is understood by the hyper-enthusiasts?

I've emailed the ATCB's that had responded to my aforementioned query for clarification on the WSJ assertion about their role, being that the statement is in contradiction to their earlier replies to me.  I also advised them of the potential liability issues.

However, if it turns out to be true that the ONC-ATCB's do intend themselves as the ultimate watchdog and assurer of public safety related to EHR's, that needs to be known by the public and their representatives.

-- SS

EHR: "The Dangerous Decade"

A new perspective piece has appeared in the Journal of the American Medical Informatics Association. Although it is not freely available, I thought posting the abstract and the opening would be of interest:


The dangerous decade
JAMIA
Published Online First 24 November 2011
Enrico Coiera, Jos Aarts, Casimir Kulikowski

Abstract

Over the next 10 years, more information and communication technology (ICT) will be deployed in the health system than in its entire previous history. Systems will be larger in scope, more complex, and move from regional to national and supranational scale. Yet we are at roughly the same place the aviation industry was in the 1950s with respect to system safety. Even if ICT harm rates do not increase, increased ICT use will increase the absolute number of ICT related harms. Factors that could diminish ICT harm include adoption of common standards, technology maturity, better system development, testing, implementation and end user training. Factors that will increase harm rates include complexity and heterogeneity of systems and their interfaces, rapid implementation and poor training of users. Mitigating these harms will not be easy, as organizational inertia is likely to generate a hysteresis-like lag, where the paths to increase and decrease harm are not identical.


The perspective piece then opens with this:

There is a paradox in the relationship between information and communication technology (ICT) and patient safety. ICT can improve the quality, safety and effectiveness of clinical services and patient outcomes,1 although the evidence base for this is sometimes weak.2 As a consequence, the rapid deployment of ICT on a national scale is a priority for many nations faced with a diminishing clinical workforce, increasing workloads, and resource constraints. 3 4
However, ICT use can also lead to patient harm.5 Many commentators have raised concerns that ICT has yet to deliver on its promises,6 or that the rapid adoption of ICT is a risk.7 7a Errors persist in clinical practice even after ICT is introduced,8 because manual processes co-exist with the automated, and the interfaces between the two are seldom perfect. Others counter that such overemphasis on ICT-related harm only delays the implementation of a crucial technology that will save lives.9
It appears that we are caught in a bind. The demands for health system reform are now so compelling that there appears no choice but to implement complex ICT on a large, often national, scale. Yet these ICT systems appear less mature than we would like and our understanding about how to implement and use them safely remains in its infancy. As such, we are faced with a pressing policy challenge on both the national and international stages.10

They raise these rhetorical questions:

... Where is the ‘kill switch’ in our health ICT systems when large-scale privacy breaches are occurring, or large volumes of critical patient data are being corrupted? Who is authorized to activate such a switch?

The answers to these questions are, quite frankly: nowhere, and nobody. What we have instead is an environment of 'irrational exuberance' -- as well as 'rational exuberance', i.e., opportunism, often of a pecuniary nature.

To the authors' other observations I would add that:

1) "Organizational inertia" is probably too narrow a concern. I would broaden it to "cultural inertia", especially since the health IT "ecosystem" is grossly lacking of a culture of safety and accountability;

2) The authors note that "Predicting the actual harm rate and total patient harms that we will see through the use of ICT in healthcare over the next decade is currently not possible."

While I agree, and agree this inability needs to be remediated, extrapolations can be performed to achieve estimates. Regarding increased ICT use increasing the absolute number of related harms, that number could already be quite substantial as I wrote in an April 16, 2010 thought experiment at "If The Benefits Of Healthcare IT Can Be Guesstimated, So Can And Should The Dangers."

Ironically and tragically, that post was written just five days before I wrote a confidential warning letter to a hospital about EHR deficiencies I'd noted in my mother's care there, and just one month before she was severely injured at that hospital by an EHR-related error of a nature as identified in the letter. Thus, the numbers in the thought experiment should be incremented accordingly;

3) I would say regarding safety that the health IT sector is roughly in the same place as aviation was in the 1920's (e.g., unregulated, experimental technology abounding), not the 1950's, and as the maritime passenger service was in ca. 1912 (April to be precise); and

4) The authors observe that "There is however caution in the [2011 IOM] report [on health IT safety here, PDF] that safety regulations would impede industry innovation, an argument which would literally not fly in the aviation industry ... the caution toward recommending regulation may however be misplaced. Simply put, if healthcare wants the benefits of ICT then it must actively manage its risks."

I strongly agree that the IOM's cautions on regulation are misplaced, as I wrote here. Robust regulation could diminish ICT harm as in pharmaceuticals and medical devices (and aviation).

Innovation will not be harmed, and the IT industry needs to -- and can afford to -- accept the responsibilities and obligations of being involved in healthcare. See for example "No More Soft Landings For Software: Liability for Defects in an Industry That Has Come of Age" (PDF), Zollers, McMullin et al., Santa Clara Computer & High Technology Law Journal, Vol. 21 No. 4, 2005.

-- SS

Novel Idea on Healthcare IT: Worth a Billion Dollars!

From an AMIA announcement:

CMS Innovation Center Announces $1 Billion Funding Opportunity:

CMS announced a new initiative, the Health Care Innovation Challenge, which will provide grants for new ideas to improve care and lower costs for those in Medicare, Medicaid and CHIP. CMS will award up to $1 billion in grants for a 3 year period and is encouraging providers, payers, local government, public-private partnerships and multi-payer collaboratives to develop new and innovative ways to improve care. To learn more about the grants and application process, check out the CMS Innovation Center website and be sure to register for the CMS webinar on Thursday.

CMS, I have an idea!

It's a really, really novel idea!

"Let's regulate HIT to improve its safety, usability, usefulness, fitness for purpose, effectiveness, etc."

That will lower healthcare costs! Save lives, too!

----------------------------------

Can I have my Billion Dollars now?

You can do a lot in health IT with a billion dollars - if you're not the HIT industry, that is, that has squandered a large wad of these over the past several decades.

-- SS

FDA Decides Regulating Implantable Defibrillator Medical Devices a "Political Hot Potato"; Demurs

Well, not exactly, but they have decided regulation of another medical device is a political hot potato, and demurred on enforcing regulation:

Health IT.

Health IT are medical devices.


FDA's Chair of the Center for Device and Radiological Health, Jeffrey Shuren, MD JD, stated this explicitly on Feb. 25, 2010 (see testimony to the HHS Health Information Technology HIT Policy Committee at this PDF) that:

... Under the Federal, Food, Drug, and Cosmetic Act, [that regulates all drug, medical devices, etc. in the United States - ed.] HIT software is a medical device. Currently, the FDA mandates that manufacturers of other types of software devices comply with the laws and regulations that apply to more traditional medical device firms. These products include devices that contain one or more software components, parts, or accessories (such as electrocardiographic (ECG) systems used to monitor patient activity), as well as devices that are composed solely of software (such as laboratory information management systems).

That leaves no doubt that these are medical devices. However, he also stated:

To date, FDA has largely refrained from enforcing our regulatory requirements with respect to HIT devices.

In other words, this medical device receives special accommodation over all others,such as heart stents, defibrillators, spine and knee implants, etc., all of which have been in the news in recent years for major defects and malfunctions, up to and including causing patient deaths. The extent would have likely been far, far worse had these gadgets been unregulated.

One should ask: why the special accommodation for health IT medical devices? What are the underlying politics, and who is behind them? Especially when FDA is aware of potential risks that may only be the "tip of the iceberg?"

The selective reluctance to enforce the FD&C Act persists to this day. See for example this link regarding his statements just a few days ago here in Philadelphia: Will FDA Regulate EHR's? :

Speaking at the first annual PharmEHR Summit in Philadelphia on April 7, Jeffrey Shuren, M.D., J.D., director of the Center for Devices and Radiological Health at the FDA, said his agency could change its traditional hands-off approach to EHRs, but he acknowledged that the potential of FDA regulation raises serious clinical issues [the only clinical issues I can think of are in holding vendors accountable for patient injury - ed.] and is a “political hot potato.” As of right now we’re not regulating EHRs, and it may turn out that we won’t,” he said.

Likely translation: FDA regulation of health IT will never happen.

One implication is that health IT quality, safety, efficacy, privacy, security, and other issues about these systems will remain subject to HHS and industry caprice.

While we're at it, let's deregulate knee implants too...

-- SS

Addendum April 19, 2011:

Roy Poses observes that:

Here is a great example of regulatory capture. The health care IT industry has amassed such political clout that it now has impunity to regulation. Once again, combined economic and political power trumps patients' and the public's health and safety. We will not be able to really reform health care until we can provide for honest, independent health care regulation to uphold patients' and the public's health.

-- SS

New York Times: Panel Set to Study Safety of Electronic Patient Data

New York Times author Milt Freudenheim has published an interesting article on health IT:

"Panel Set to Study Safety of Electronic Patient Data" (Dec. 13, 2010, link)

In the article Mr. Freudenheim presents various viewpoints on health IT safety and usability, and reports on an upcoming Institute of Medicine (IOM) Committee on Healthcare IT safety.

In general, the expressed viewpoints reported upon are consistent with the position in the Healthcare IT Ecosystem of those quoted. I wish to add some commentary to a number of those stated positions.

Mr. Freudenheim observes:

Taking a fresh look at such concerns, the Institute of Medicine created the Committee on Patient Safety and Health Information Technology to run a yearlong study and issue recommendations. The 16-member panel is meeting for the first time on Tuesday in Washington.


(This new IOM Committee is in addition to a 2009 study by the National Academies/National Research Council that concluded that "Current Approaches to U.S. Health Care Information Technology are Insufficient", which has largely been invisible. The IOM is the health arm of the National Academies.)

I would add that this Committee is at least a decade late. That it is occurring at all seems to be at the behest of a multitude of complaints and "blows of the whistle" from clinicians who increasingly depend (either voluntarily or by coercion) on this technology to provide safe care.

I would also add that it is my hope the IOM committee with not be overly politicized, considering the stated unconditional exuberance of the past two administrations towards health IT, and that a wide variety of stakeholders will be heard. (For instance, as a medical informatics specialist whose relative was injured as a result of HIT interference with care continuity, will I be allowed to testify?)

Mr. Freudenheim then relates the points of view of stakeholders.

In February, the F.D.A. said it had received 260 reports of malfunctions related to health information technology “with the potential for patient harm,” including 44 reported injuries and six reported deaths in 2008 and 2009. The malfunctions were reported voluntarily to the agency, mainly by hospitals.

“Because these reports are purely voluntary, they may represent only the tip of the iceberg,” said Dr. Jeffrey Shuren, a senior F.D.A. policy and enforcement official.


I'd written about this at "FDA on Health IT Adverse Consequences: 44 Reported Injuries and 6 Deaths, Probably Just Tip of Iceberg" where I noted:

This is a technology almost universally touted as inherently beneficial, right up to our most senior elected leaders, who are now pushing this unproven technology under threat of penalty for non-adopters.

Healthcare IT irrational exuberance can perhaps be illustrated in statements such as this:

“We have the capacity to transform health with one thunderous click of a mouse after another,” said (former) HHS Secretary Michael Leavitt - 2005 HIMSS Summit

I also opined at "If The Benefits Of Healthcare IT Can Be Guesstimated, So Can And Should The Dangers" that one could, as a type of thought experiment, extrapolate from these numbers to guesstimate the effects of universal health IT in the US. The results were startling, even if just an experiment:

[We might have] 880,000 injuries per year, 120,000 deaths when universal HIT use is achieved ... While this is a mere thought experiment, the result certainly suggests we need to know the actual rates of HIT-related patient harm, and act to understand and minimize these events.

In setting national healthcare policy, we should not rely on thought experiments - but even more importantly, we should not be relying on guesswork and wishful thinking as we are currently.

Unfortunately, national policy has been set up to now on wishful thinking. As I stated, the IOM meeting is coming none too soon.

The NYT article then reports on a statement made by ONC Chair David Blumenthal:

“All options for assuring safety are on the table,” said Dr. David Blumenthal, the Obama administration’s national coordinator for health information technology.


Yet Dr. Blumenthal is clearly an adherent to unbridled exuberance about health IT. At "Science or Politics? The New England Journal and the 'Meaningful Use' Regulation for Electronic Health Records" I wrote:

... In the NEJM article "The 'Meaningful Use' Regulation for Electronic Health Records", David Blumenthal, M.D., M.P.P. (ONC Chair) and Marilyn Tavenner, R.N., M.H.A. (10.1056/NEJMp1006114, July 13, 2010) available at this link, the opening statement is (emphases mine):

The widespread use of electronic health records (EHRs) in the United States is inevitable. EHRs will improve caregivers’ decisions and patients’ outcomes. Once patients experience the benefits of this technology, they will demand nothing less from their providers. Hundreds of thousands of physicians have already seen these benefits in their clinical practice.

I think it fair to say those are grandiose statements and predictions presented with a tone of utmost certainty in one of the world's most respected scientific medical journals.


Even though it is a "perspectives" article, I once long ago learned that in writing in esteemed scientific journals of worldwide impact, statements of certainty were at best avoided, or if made should be exceptionally well referenced.

I note the lack of footnotes showing the source(s) of these statements.

I also note the lack of mention of literature refuting or potentially refuting these statements of certainty. [Followed by a list of such literature just off the top of my head - ed.]

Dr. Blumenthal then appeals to authority:

Dr. Blumenthal said health information experts like Dr. Donald M. Berwick, the Medicare and Medicaid administrator, and Dr. Brent James, of Intermountain Healthcare, based in Salt Lake City, “agree that electronic health records will improve the safety of care.”

I am unaware of the expertise of Dr. Berwick and Dr. James in this domain, and the peer reviewed literature they've written that supports such a statement while soundly refuting literature written by other experts that indicates otherwise.

(Perhaps at Intermountain, custom systems that took decades to develop utilizing their Medical Informatics expertise do show safety gains, but such systems and the lessons learned building them are not easily portable to a country's worth of organizations and practitioners, especially under HITECH timeframes.)

Freudenheim then quotes Blumenthal as stating:

“At the same time, any time you change the world you create risks,” Dr. Blumenthal said in a telephone interview last weekend.


This sounds typical of utopian ideology. Yes, any time you change the world you create risks, but you should not attempt to change the world cavalierly and blindly to those risks. (That's the path the National Program for Health IT in the United States has been on, until the IOM meeting was called.) Idealists tend to believe the collateral damage that is caused by utopian experiments (e.g., communism) are a necessary sacrifice to achieve the utopia. Such values are both abhorrent and alien to medicine.

“We want to make sure that implementation is as safe as it can be and all safety benefits are realized.”


Blumenthal's been painted into a corner by tons of complaints on HIT safety; ONC must act, even if just putting on a show about safety considerations. If there were true concern for safety he'd recommend slowing down HITECH timelines until the industry gets its act together and our understanding of HIT usability, safety, and other issues is resolved; cf.: statements of HIMSS leaders on 'needing to be patient' for the industry to get healthcare IT right:

As I'd written about HIMSS admissions of health IT unsuitability to task at "NIST Provides Healthcare IT Industry with Remedial Undergraduate Computer Science Education":

... What have been their product design and development practices, such that leaders of their own trade group HIMSS (as I pointed out in other posts) opine we should be "patient" for them to figure it all out about how to do health IT better and they need more time, and that the technology does not support its users properly due to lack of efficiency and usability of EMRs currently available? (As at my July 2010 post "The National Program for Healthcare IT in the U.S., and the Elephant in the Living Room".)

Further, from the NYT article:

He [Blumenthal] said that if the Institute of Medicine “concludes that regulation is an important part of this fabric of assuring safety, we will want to balance regulation and innovation as we do in every marketplace.”


That he even needs to make such a statement is likely revealing of biases on regulation, which seem aligned to the industry. To wit:

“The policing of design by a third party or agency, however well intended, will likely stifle innovation and inhibit the growth and development of electronic health records in the future,” said Carl Dvorak, executive vice president of Epic Systems, which has built electronic records systems for Kaiser Permanente and other large health care and hospital groups.


There is a lack of evidence supporting such a statement (e.g., pharma has been regulated for decades, as is its clinical IT). The fact that NIST has just delivered Computer Science 101-level usability guidelines to the HIT industry in its recent report “NIST Guide to the Processes Approach for Improving the Usability of Electronic Health Records” to help solve the HIT unusability crisis also suggests that 30+ years of un-regulation did not facilitate ‘innovation.’

In fact 'unregulation' appears to have led to prima facie innovation failure and paralysis as far as usability is concerned.

Unusable health IT might as well not exist as far as clinicians are concerned. It is a menace to the safe practice of medicine. This is a first principle.

Per the NYT, the industry trade group HIMSS has gone mum:

The industry has recently avoided speaking out on a role for the F.D.A. In a statement for this article, the Healthcare Information and Management Systems Society, a Washington-based industry group, said only that it “supports the administration’s decision to ask the Institute of Medicine to study this complex issue and report back over the next 12 months.”


They are certainly not taking a leadership role on this issue. In my humble opinion they will allow regulation, only kicking and screaming and being dragged into it by force. Patients come second to profits - the only factor that will be "stifled" as vendors are coerced to make better products.

The NYT article goes on:

Last month, in protest of one common industry practice, the American Medical Informatics Association said “hold harmless” clauses in many purchasing contracts were unethical. The clauses typically absolve manufacturers of responsibility for any errors or misuse.

“We said we value innovation, but we don’t value it more than safety,” said Kenneth W. Goodman, a University of Miami bioethicist who headed an association advisory group on patient safety.


It took a lot of writing and politicking to get AMIA to this point as well, at least to express it openly (cf.: my efforts here).

Finally, with regard to the IOM meetings on HIT safety, there will be industry stakeholders in attendance such as CCHIT and EPIC.

I believe they should be held to scientific standards of delivery. If they deliver marketing-based spin, they should be called to present scientific evidence for their stance – and not just “positive” evidence. They should be made to refute “negative” evidence as well, not ignore it.

In summary, I welcome the New York Times bringing these issues to the public.

I also welcome IOM's entry into studying HIT safety. While a "Committee on Patient Safety and Health Information Technology" should have been convened years ago, it's better late than never. (Except for patients already injured or killed, of course.)

The results may remain as invisible as the aforementioned National Research Council study. I also doubt the Committee's findings will change hearts and minds. Idealism, profit motive, and irrational exuberance are hard to rectify.

But their effects on people's behaviors can - and should - be regulated.

-- SS

NIST Provides Healthcare IT Industry with Remedial Undergraduate Computer Science Education

The National Institute of Standards & Technology (NIST) has published a guide entitled:

NIST Guide to the Processes Approach for Improving the Usability of Electronic Health Records

It is available free at this link in PDF: http://www.nist.gov/itl/hit/upload/Guide_Final_Publication_Version.pdf (hat tip to an AMIA colleague for posting the URL on an AMIA mailing list.)

The NIST was commissioned by HHS/ONC to study Health IT issues such as usability and report on them.

I find the publication both welcome, and pitiable.

As I started to read ch. 6, for example, I observed material that is suitable for undergraduate computer science instruction:

6. User-Centered Design Process in EHRs

User-centered design is a bedrock principle for creating usable systems and devices. [You don't say? - ed.] One of the most common reasons why systems are poorly designed is that designers and developers fail to engage users in appropriate ways at appropriate times. [Hear that, my young Paduan learners? - ed.] At its core UCD is a process that relies on systematic understanding of users and their environments, and iterative design and testing based on user performance objectives. (Details on usability testing are provided in Section 9.)

UCD has been shown to be effective in many fields. In aviation, for example, this method has been used to develop cockpit navigation displays for low-visibility surface operations. [22] By taking the limitations and capabilities of the flight crew into account, navigation errors have decreased by almost 100%. The adoption of UCD has also been shown to be effective in the design of personal computers. When working on a redesign of the laptop computer, a UCD process was employed. Users were asked to offer feedback about the current model and to offer input about ways to improve the current design. User-centered design was successful in increasing market share, brand equity, and customer satisfaction. [23] In fact, user-centered design has been elevated to an ISO standard. [24] UCD serves to engineer improved human performance into a system or device, and has been crystallizing for several decades as a design philosophy. [25]

While there is no singular model of UCD, the instantiations embody the following principles:

  • Understand user needs, workflows and work environments
  • Engage users early and often
  • Set user performance objectives
  • Design the user interface from known human behavior principles and familiar user interface models
  • Conduct usability tests to measure how well the interface meets user needs
  • Adapt the design and iteratively test with users until performance objectives are met

[HHS needs ONC to commission NIST to provide schooling for the HIT industry on these bons mots? - ed.]

As an iterative process, UCD is a cycle that serves to continually improve the application. For each iteration, critical points and issues are uncovered which can be improved upon and implemented in subsequent releases. An illustration of the UCD process is included in Figure 1.



"User centered design process in EHR's." Undergraduate-level computer science 101 instruction from NIST for the healthcare IT industry? (click to enlarge)


Here is Figure 1:

User centered design 101 (click to enlarge)


I might even have used this in teaching high school students about computer programming.

Readers can download the entire report at the above URL.

I find this publication, or, rather, the need for it to exist at all in 2010, remarkable. Absurd and an embarrassment, in fact. Master of the Obvious [1] material that apparently was not so obvious to this industry.

This is after all a multi-billion dollar industry making claims its products will "revolutionize medicine" and other exceptional claims (but without exceptional evidence). These claims have been pushed so hard that many tens of billions of dollars (with penalties) have been earmarked to either entice -- or coerce -- physicians and hospitals to use these products.

What has this industry, including vendors and highly paid management consultants and contractors, been doing, exactly, for the past thirty+ years?

What have been their product design and development practices, such that leaders of their own trade group HIMSS (as I pointed out in other posts) opine we should be "patient" for them to figure it all out about how to do health IT better and they need more time, and that the technology does not support its users properly due to lack of efficiency and usability of EMRs currently available? (As at my July 2010 post "The National Program for Healthcare IT in the U.S., and the Elephant in the Living Room".)

That HHS needs NIST to provide undergraduate level remedial teaching to the multibillion dollar health IT industry is a very poignant commentary indeed on the priorities of that industry regarding engineering rigor, talent management, attention to safety, and other factors affecting human lives.

These observations speak strongly to the need for regulation for this industry, for a talent management and trade association shakeup of major proportions, and most especially for an awakening of our government servants to exactly what the real situation is with respect to HIT on the ground.

12/14/10 addendum: it struck me that the Guide might need another chapter. I suggest a chapter entitled:

"Listening to informatics experts when they say your product will kill people, instead of firing them."

-- SS

[1] This was another pithy line from my early medical mentor, pioneering cardiothoracic surgeon Victor Satinsky, MD at Hahnemann Medical College.