HHS rule would give government everybody’s health records?

I really don't like the sound of this in the Washington Examiner. It contains many warnings of the kind I've written about here at HC Renewal regarding EHR systems, data privacy, confidentiality and security, coding madness, and (especially in the proposed rule) computational alchemy - a belief that one can turn unreliable data into "gold":

HHS rule would give government everybody’s health records
By: Rep. Tim Huelskamp
09/23/11 3:29 PM
OpEd Contributor

It’s been said a thousand times: Congress had to pass President Obama’s health care law in order to find out what’s in it. But, despite the repetitiveness, the level of shock from each new discovery never seems to recede.

This time, America is learning about the federal government’s plan to collect and aggregate confidential patient records for every one of us.

In a proposed rule from Secretary Kathleen Sebelius and the Department of Health and Human Services (HHS), the federal government is demanding insurance companies submit detailed health care information about their patients.

(See Proposed Rule: Patient Protection and Affordable Care Act; Standards Related to Reinsurance, Risk Corridors and Risk Adjustment, Volume 76, page 41930. Proposed rule docket ID is HHS-OS-2011-0022 http://www.gpo.gov/fdsys/pkg/FR-2011-07-15/pdf/2011-17609.pdf)

The HHS has proposed the federal government pursue one of three paths to obtain this sensitive information: A “centralized approach” wherein insurers’ data go directly to Washington; an “intermediate state-level approach” in which insurers give the information to the 50 states; or a “distributed approach” in which health insurance companies crunch the numbers according to federal bureaucrat edict.

It’s par for the course with the federal government, but abstract terms are used to distract from the real objectives of this idea: no matter which “option” is chosen, government bureaucrats would have access to the health records of every American - including you.

There are major problems with any one of these three “options.” First is the obvious breach of patient confidentiality. The federal government does not exactly have a stellar track record when it comes to managing private information about its citizens.

Why should we trust that the federal government would somehow keep all patient records confidential? In one case, a government employee’s laptop containing information about 26.5 million veterans and their spouses was stolen from the employee’s home.

There's also the HHS contractor who lost a laptop containing medical information about nearly 50,000 Medicare beneficiaries. And, we cannot forget when the USDA's computer system was compromised and information and photos of 26,000 employees, contractors, and retirees potentially accessed. [I've written about this issue frequently on this blog - ed.]

The second concern is the government compulsion to seize details about private business practices. Certainly many health insurance companies defended and advocated for the president’s health care law, but they likely did not know this was part of the bargain.

They are being asked to provide proprietary information to governments for purposes that will undermine their competitiveness. Obama and Sebelius made such a big deal about Americans being able to keep the coverage they have under ObamaCare; with these provisions, such private insurance may cease to exist if insurers are required to divulge their business models.

Certainly businesses have lost confidential data like the federal government has, but the power of the market can punish the private sector. A victim can fire a health insurance company; he cannot fire a bureaucrat.

What happens to the federal government if it loses a laptop full of patient data or business information? What recourse do individual citizens have against an inept bureaucrat who leaves the computer unlocked? Imagine a Wikileaks-sized disclosure of every Americans’ health histories. The results could be devastating - embarrassing - even Orwellian.

With its extensive rule-making decrees, ObamaCare has been an exercise in creating authority out of thin air at the expense of individuals’ rights, freedoms, and liberties.

The ability of the federal government to spy on, review, and approve individuals’ private patient-doctor interactions is an excessive power-grab.

Like other discoveries that have occurred since the law’s passage, this one leaves us scratching our heads as to the necessity not just of this provision, but the entire law.

The HHS attempts to justify its proposal on the grounds that it has to be able to compare performance. No matter what the explanation is, however, this type of data collection is an egregious violation of patient-doctor confidentiality and business privacy. It is like J. Edgar Hoover in a lab coat.

And, no matter what assurances Obama, Sebelius and their unelected and unaccountable HHS bureaucrats make about protections and safeguards of data, too many people already know what can result when their confidential information gets into the wrong hands, either intentionally or unintentionally.

Republican Tim Huelskamp represents the first congressional district of Kansas.

While the word "de-identified" is in the proposed rule, I don't have great confidence in such assurances (for instance, see my Oct. 2009 post "Health IT Vendors Trafficking in Patient Data?").

I don't believe additional commentary is needed.

Hat tip - Drudge Report.

-- SS

My doctor will now need to code for when I get bitten by George or Martha Goose

The bureaucrats always seem to find new ways to waste precious medical resources and capital to justify their existence.

Here's the latest twist:

I regularly feed swans, ducks and geese at my local park. In fact, I don't seek them out; the geese in particular come to me when they see me on the trail. They know me for years.

They have tremendous vision, so I can't escape them.

Per the WSJ, medical coding is about to become so hypergranular (could the reason be that bureaucrats needed work to do?) as to be reasonably considered insane:

Walked Into a Lamppost? Hurt While Crocheting? Help Is on the Way

New Medical-Billing System Provides Precision; Nine Codes for Macaw Mishaps


Wall Street Journal
Sept. 13, 2011

... Billing experts who translate doctors' work into codes are gearing up to start using the new system in two years. They say the new detail is welcome in many cases. But a few aspects are also causing some head scratching.

Some codes could seem downright insulting: R46.1 is "bizarre personal appearance (see code)," while R46.0 is "very low level of personal hygiene (see code)."

It's not clear how many klutzes want to notify their insurers that a doctor visit was a W22.02XA, "walked into lamppost, initial encounter" (or, for that matter, a W22.02XD, "walked into lamppost, subsequent encounter").

Why are there codes for injuries received while sewing, ironing, playing a brass instrument, crocheting, doing handcrafts, or knitting—but not while shopping, wonders Rhonda Buckholtz, who does ICD-10 training for the American Academy of Professional Coders, a credentialing organization.

... Much of the new system is based on a World Health Organization code set in use in many countries for more than a decade. Still, the American version, developed by the Centers for Disease Control and Prevention and the Centers for Medicare and Medicaid Services, is considerably more fine-grained.

The WHO, for instance, didn't see the need for 72 codes about injuries tied to birds. But American doctors whose patients run afoul of a duck (see codes), macaw (see codes), parrot (see codes), goose (see codes), turkey (see codes) or chicken (see codes) will be able to select from nine codes for each animal, notes George Alex, an official at the Advisory Board Co., a health-care research firm.

There are 312 animal codes in all
, he says, compared to nine in the international version. There are separate codes for "bitten by turtle" and "struck by turtle." (See codes.)

Examples:

W6151XA Bitten by goose, initial encounter
W6151XD Bitten by goose, subsequent encounter [Killer Goose?]
W6151XS Bitten by goose, sequela
W6152XA Struck by goose, initial encounter
W6152XD Struck by goose, subsequent encounter
W6152XS Struck by goose, sequela
W6159XA Other contact with goose, initial encounter
W6159XD Other contact with goose, subsequent encounter
W6159XS Other contact with goose, sequela

Sometimes my favorite Canada Goose couple, George and Martha, and their annual young'uns will overextend their beaks when being fed and nip my finger. They've never broken my skin (geese have no teeth, just ridges) but if they do ... my doctor is likely to have to code for "bitten by Canada Goose."

I wonder if CDC will then send out the Goose Patrol. George and Martha, be careful, or your goose may be cooked!



George, I'm going to feed you, but don't W6151XD me (bite me) or the Feds will be after you ... (click to enlarge photos)



Young'uns, you better watch out, too!



This guy has already done a W6152XA and W6152XD to me with his wings, leaving me with a W6152XS (bruise on my leg) when I didn't feed him before the Canadas! You can just tell he's looking to create coding mayhem from that expression on his face.



Is there an ICD-10 code for "foot bitten by cute little Mallard duckie?"


What a perverse waste of resources this coding mania represents...


Hat tip: The Galen Institute/Grace-Marie Turner


-- SS

Johnson and Johnson Pleads Guilty - a Reminder of the "Lost Decade" of Nesiritide

It was just a short article in Bloomberg about yet another misstep by Johnson and Johnson....
Johnson & Johnson (JNJ)’s Scios unit agreed to pay an $85 million fine and plead guilty to misbranding the heart drug Natrecor, the U.S. said.

Scios was charged in July with misbranding the medicine because its labeling lacked adequate directions for use. Under a plea agreement reached after months of negotiation with prosecutors, Scios will be placed under organizational probation for three years in addition to paying the fine....

Although the case did involve a guilty plea, the fine actually seemed small compared to some others we have seen lately. The article made it sound like this was just a technical mis-step in labeling.

A Darker History

However, another brief paragraph hinted at a more complex background:
Natrecor, given intravenously, was one of the first drugs for congestive heart failure when it was approved in 2001, and in 2004 it generated $230 million in revenue. Sales plummeted to less than $100 million in 2006 after reviews of its use in less than 1,000 patients tied the medicine to worsening kidney function and higher death rates.

Of course, to a physician, the first sentence makes no sense. Digitalis was probably the first effective drug for heart failure, and its use was described in the 18th century. To the rest we should pay heed.

A Lack of Evidence for Benefit Outweighing Harm

In fact, in 2005, Dr Eric Topol wrote a commentary in the New England Journal that discussed Natrecor's (nesiritide's) troubled history.(1)

Here are the main points:
- Nesiritide was first tested on seriously ill, hospitalized patients with congestive heart failure.
- The drug improved one measure of physiogic function, the pulmonary capillary web pressure. However, patients given nesiritide had a not statistically significant increase in mortality, and a later significant decrease in kidney function.
- Nesiritide was thus only approved for short-term use in acutely ill heart failure patients (in 2001).
- However, its manufacturer, Scios, a Johnson and Johnson subsidiary, vigorously promoted it for out-patient "tune ups," a use for which there was no evidence that its benefits outweighed its harms.
- This use, however, was very lucrative for the company at a price of $500 per dose. So,
outpatient nesiritide use has become widespread, fulfilling sales objectives for the manufacturer and bringing in revenue for physicians. The overall sales figure for nesiritide is projected to be $700 million for 2005, nearly double last year's tally; it represents payment for more than 1.4 million treatments. Given that nearly 10 times as much drug is used for serial administration in outpatients as for the one-time use in hospitalized patients, much of this growth clearly stems from the off-label 'tune-up' application.

At that time, Dr Topol summarized the case thus:
The nesiritide story reflects some recurring themes: in other recent cases, too, major safety problems have been uncovered after a drug has been approved. Nesiritide was approved on the basis of a single trial in which surrogate end points were assessed three hours after administration. In cardiovascular medicine, we learned long ago that therapies directed at surrogate end points — such as the suppression of premature ventricular contractions or, for inotropic agents, an improved ejection fraction — can be associated with excess deaths. With the low threshold set for regulatory approval, the FDA did not demand appropriate warnings on the label regarding an increased risk of death or worsened renal function and did not require the performance of trials that would have provided definitive verification of the safety and efficacy of nesiritide.

We practice medicine in an era in which there is one pharmaceutical-company representative for every five physicians and in which companies will stretch the limits in their marketing of drugs. The boundary lines that previously separated industry from the FDA and academia have unfortunately become blurred.
No Evidence of Benefit in 2011, the End of the "Lost Decade"
Finally, in 2011, a larger study of the drug appeared.(2) It did not show that nesiritide increased mortality at 30 days, but neither did it decrease it. Essentially, it showed that the drug had no clinically important advantage over standard therapy. In an accompanying commentary, Dr Topol used the nesiritide case as an example of a "lost decade" due to "deficient clinical development of certain pharmaceutical agents."(3)
The FDA, without a prospective plan or capability to force the sponsor to perform a fitting trial after approval, unwittingly created a monster. Physicians, who prescribed nesiritide without definitive knowledge of efficacy or safety, particularly for off-label use such as for tune-up clinics, were treating patients without an adequate evidence base. The manufacturer in this case was the chief culprit because it widely promoted nesiritide in the early years after its approval but was unwilling to appropriate the resources to design and execute a compelling trial.

Summary
The sorry nesiritide case now seems to be staggering towards its conclusion with little fanfare (although the Bloomberg article noted that the legal proceedings related to it are not over.  There is a pending civil False Claims suit brought by the US Department of Justice.)

So, 10 years after the drug was widely marketed to patients for whom it would do no good, the "chief culprit" has had a pay a small financial price, relative to the revenue it received, for an offense tangential to the lost decade created for patients and physicians who thought that nesiritide might be worth using. As usual in such cases, no individual who authorized, directed or implemented the "monster" that was the dubious nesiritide marketing campaign has suffered any negative consequences.

This was just the latest in a long series of legal misadventures by the once revered Johnson and Johnson. Its most recent guilty plea for a marketing offense was only a month ago (see post here.) That blog post listed five other recent adverse legal results related to the company's marketing.

Of course, as long as the company's leaders seem immune to any sort of negative consequences for its bad behavior, and as long as its board seems happy to pay millions to the executives who preside over these messes, why should the bad behavior stop? Do we expect multi-millionaire executives to actually worry about the ethics and morals of what they are doing? - not in an era when "greed is good," at least until the whole economy collapses from the aggregated greed of its leaders.

For physicians, the nesiritide case should remind us not to deploy a test or treatment without good evidence that it actually does patients more good than harm, even if we really hope it does, and even if the company that markets it really hopes so too. 

For all of us, the case should remind us that if there are short-term monetary rewards but no penalties for unethical behavior, unethical behavior will continue.
References

1. Topol E. Nesiritide - not verified. N Engl J Med 2005; 353: 113-116. Link here.
2. O'Connor CM, Starling RC, Hernandez AF et al. Effects of nesiritide in patients with acute decompensated heart failure. N Engl J Med 2011; 365: 32-43. Link here.
3. Topol EJ.  The lost decade of nesiritide.  N Engl J Med 2011; 365: 81-82.  Link here.

NPfIT Programme goes "PfffT"

More on the travails of the UK's moribund National Programme for IT in the NHS.

It's officially gone "PffffT"...

NHS told to abandon delayed IT project
Denis Campbell, health correspondent
The Guardian, Wednesday 21 September 2011

£12.7bn computer scheme to create patient record system is to be scrapped after years of delays

The NHS has spent billions of pounds on a computerised patient record and booking system, which has never worked properly.

An ambitious multibillion pound programme to create a computerised patient record system across the entire NHS is being scrapped, ministers have decided.

The £12.7bn National Programme for IT is being ended after years of delays, technical difficulties, contractual disputes and rising costs.

And failure to read and comprehend sites like "Contemporary Issues in Medical Informatics: Common Examples of Healthcare Information Technology Difficulties" (extant since ca. 1999) and this very blog...

Health secretary Andrew Lansley, Cabinet Office minister Francis Maude and NHS chief executive Sir David Nicholson have decided it is better to discontinue the programme rather than put even more money into it. The axe may be wielded , with ministers likely to criticise the last Labour government for initiating the project but doing too little to ensure it delivered its objectives.

An announcement has been expected for months after the National Audit Office cast serious doubt on the wisdom of ploughing further money into the scheme and David Cameron told MPs in May that he was considering that advice. Whitehall sources confirmed the decision had been made because of coalition cost-cutting and the ongoing problems.

"It was meant to be a very helpful thing for NHS staff and patients but instead has become this amazingly top-heavy, hideously expensive programme. The problem is, it didn't deliver", said a Department of Health source.

We, of course, in the United States will learn from all this and our "National Program for IT in the HHS" will go splendidly...

"It was too ambitious, the technology kept changing, and loads and loads of money has been put into it. It's wasted a lot of money that should have been spent on nurses and improving patient care, and not on big international IT companies."

Perhaps they do read Healthcare Renewal after all, because I've written exactly that in numerous posts...

The move comes after ministers received fresh advice from the Cabinet Office's major projects authority, which assesses the value for money of major public spending schemes. It concluded "there can be no confidence that the programme has delivered or can be delivered as originally conceived", recommending ministers "dismember the programme and reconstitute it under new management and organisation arrangements".

How about with leaders with domain-specific expertise, too, as I wrote at my Aug. 2010 post "Are computers in medicine narcotic? Why did the National Programme for IT fail?" At that post I sadly observed that:

... [NPfIT] also failed because of collective ignorance of these domains [e.g., healthcare informatics, social informatics, etc. - ed.] among its leaders, and among those who chose the leaders. For instance, as I wrote here:

The Department of Health has announced the two long-awaited senior management appointments for the National Programme for IT ... The Department announced in February that it was recruiting the two positions as part of a revised governance structure for handling informatics in the Department of Health.

Christine Connelly will be the first Chief Information Officer for Health and will focus on developing and delivering the Department's overall information strategy and integrating leadership across the NHS and associated bodies including NHS Connecting for Health and the NHS Information Centre for Health and Social Care.
Christine Connelly was previously Chief Information Officer at Cadbury Schweppes with direct control of all IT operations and projects. She also spent over 20 years at BP where her roles included Chief of Staff for Gas, Power and Renewables, and Head of IT for both the upstream and downstream business.

Martin Bellamy will be the Director of Programme and System Delivery. He will lead NHS Connecting for Health and focus on enhancing partnerships with and within the NHS. Martin Bellamy has worked for the Department for Work and Pensions since 2003. His main role has been as CIO of the Pension Service.

Excuse me. Cadbury Schweppes (candy and drink?) The Pension Service? As national leaders for healthcare IT?

Instead of sobriety, attitudes about health IT seem to universally be "sure, the experts think you shouldn’t ride a bicycle into the eye of a hurricane, but we have our own theories." (See here and here.)

The domain of health IT needs a very stiff period of detox and rock-solid sobriety before it can achieve the (non-revolutionary) benefits of which it is capable.

Riding bicycles into eyes of hurricanes, I'm sorry to say, really is not a good idea.

Back to the current Guardian article:

Its highly critical verdict said: "The project has not delivered in line with the original intent as targets on dates, functionality, usage and levels of benefit have been delayed and reduced. It is not possible to identify a documented business case for the whole of the programme. Unless the work is refocused, it is hard to see how the perception can ever be shifted from the faults of the past and allowed to progress effectively to support the delivery of effective healthcare."

That is a stark assessment. I think we in the U.S. remain deluded as to the true complexity of a scheme for national health IT, using today's systems.

Health minister Simon Burns, who is responsible for the NHS, said recently: "The nationally imposed system is neither necessary nor appropriate to deliver this. We will allow hospitals to use and develop the IT they already have and add to their environment either by integrating systems purchased through the existing national contracts or elsewhere."

Providers of NHS care such as hospitals and GP surgeries will now be told to strike IT deals locally and regionally to get the best programmes they can afford.

Common sense regarding the need for some degree of local control in healthcare, in a country with socialized medicine yet.

It is still unclear how much money the government has agreed to pay contractors in recent negotiations over cancellation fees for scrapping the project.

Let's just say, the amount will not be peanuts.

Lansley told the the Daily Mail: "Labour's IT programme let down the NHS and wasted taxpayers' money by imposing a top-down IT system on the local NHS, which didn't fit their needs.

"We will be moving to an innovative new system driven by local decision-making. This is the only way to make sure we get value for money from IT systems that better meet the needs of a modernised NHS." Serious doubts about the project's future were confirmed this year when the cross-party House of Commons public accounts committee said it was "unworkable" and that, despite huge investment, had failed to deliver.

Sadly, I knew and predicted this years ago. And I'm not even British, although I have spoken to many G-prefixed ham radio operators over the years.

This is one prediction I am not happy to see come true.

You can guess the next prediction of mine that I hope also doesn't occur.

-- SS