Ellmers Calls on Sebelius to Address Health IT Safety Concerns: A Responsible Voice in Government on Health IT and HIT Safety

The following press release is very welcome, and speaks for itself.  There is a responsible voice in the government wilderness.  It is perhaps no surprise it comes from a Congresswoman who is also a registered nurse:

Ellmers Calls on Sebelius to Address Health IT Safety Concerns



Safety Risks and Health IT-Related Errors Cited in IOM Recommendations

WASHINGTON – House Small Business Subcommittee on Healthcare and Technology Chairwoman Renee Ellmers (R-NC) today sent a letter to Kathleen Sebelius, Secretary of Health and Human Services (HHS), inquiring about whether the Department has adopted the Institute of Medicine’s (IOM) recommendations for improving the safety of health information technology (IT).
The report, issued in November, recommended several steps to be taken by HHS and called for greater oversight by the public and private sectors. The Secretary was called upon by the IOM to issue a plan within 12 months to minimize patient safety risks associated with health IT and report annually on the progress being made.  The report further recommended that the plan should include a schedule for working with the private sector to assess the impact of health IT on patient safety, and recommended several other steps to help improve the safety of health IT.

Specifically, Chairwoman Ellmers has requested a copy of the Secretary’s plan to minimize patient safety risks, a description of health IT-related errors that have resulted in patient risks, injuries and deaths, and the status of the development of a mechanism for health IT vendors and users to report health IT-related deaths.  She said that because health IT has the promise to improve health care delivery for patients, physicians and other medical professionals, she remains eager to work with the Secretary to ensure that health IT is safe, effective and affordable.

In an August 11, 2011 letter to Secretary Sebelius, Chairwoman Ellmers said that a modern, well-equipped office is critical to the practice of medicine, and asked the Secretary to undertake a study of health IT’s adoption, benefits and cost effectiveness, including medical error rates.

On June 2, 2011, Chairwoman Ellmers’ Subcommittee held a hearing on the barriers to health IT that are encountered by physicians and other health professionals in small and solo practices.   At the hearing, physicians expressed strong concerns about the cost of purchasing and maintaining health IT systems, as well as the staff training and downtime necessary to implement such a system.  Chairwoman Ellmers noted health IT’s great potential to improve health care delivery, decrease medical errors, increase clinical and administrative efficiency and reduce paperwork.

For more than twenty-one years before being elected to Congress, Chairwoman Ellmers served as a registered nurse, focusing on surgical care as Clinical Director of the Trinity Wound Care Center and later helping to manage the family's small medical practice with her husband, Dr. Brent Ellmers, a licensed surgeon. As a registered nurse and the wife of a surgeon, Ellmers understands that a modern, efficient and well-equipped office is critical to the practice of medicine.    

This voice of sanity is quite welcome.  I've spoken with Rep. Ellmers' office, pointing them to my Drexel Univ. writings and materials and recommending Sebelius' reply be gone over with a fine-toothed comb, from the perspective of health IT realities, not merely from the perspective of the Ddulite's good intentions.  (I also introduced her staffer to the concept of the Ddulite, the HIT hyper-enthusiast who ignores all downsides and ethical concerns.)

I also pointed out the ethical lapse in IOM's position of "wait and see" while HIT is pushed nationally under penalty of law, at the cost of hundreds of billions of dollars, when their own report (along with reports from FDA here, JC here and others) admits they don't know the magnitude of benefits, risks and harms:

... While some studies suggest improvements in patient safety can be made, others have found no effect. Instances of health IT–associated harm have been reported. However, little published evidence could be found quantifying the magnitude of the risk.

Several reasons health IT–related safety data are lacking include the absence of measures and a central repository (or linkages among decentralized repositories) to collect, analyze, and act on information related to safety of this technology. Another impediment to gathering safety data is contractual barriers (e.g., nondisclosure, confidentiality clauses) that can prevent users from sharing information about health IT–related adverse events. These barriers limit users’ abilities to share knowledge of risk-prone user interfaces, for instance through screenshots and descriptions of potentially unsafe processes. In addition, some vendors include language in their sales contracts and escape responsibility for errors or defects in their software (i.e., “hold harmless clauses”). The committee believes these types of contractual restrictions limit transparency, which significantly contributes to the gaps in knowledge of health IT–related patient safety risks. These barriers to generating evidence pose unacceptable risks to safety.
[IOM (Institute of Medicine). 2012. Health IT and Patient Safety: Building Safer Systems for Better Care (PDF). Washington, DC: The National Academies Press, pg. S-2.]

As I wrote in my Nov. 2011 post "IOM Report - 'Health IT and Patient Safety: Building Safer Systems for Better Care' - Nix the FDA; Create a New Toothless Agency", the IOM's response to their own study was reckless and unethical (at best):

... The panel also recommends that the HHS secretary publicly report on the progress of health IT safety each year, beginning in 2012. If the secretary determines at any time that adequate safety progress has not been made, only then should the FDA take the regulatory lead and be given the resources to do so, the report recommends, adding that the agency should be developing a framework now to be prepared.

In the meantime, during each year of "watching for safety progress", innumerable patients are exposed to HIT's hazards and costs.  Pharma and other medical device industries are afforded no such special accommodation.

-- SS

University of Miami Lays Off 800, Cuts Research Funding, Builds New Presidential Mansion

Despite the trillions of dollars flowing through the US health care systems, prominent not-for-profit health care organizations seem to be complaining more often that the money going to them is not enough. 

The Lay-Offs and Research Cutbacks

Recently, for example, the University of Miami announced that its medical center would have to tighten its belt.  In April, according to the Miami Herald,
University of Miami President Donna Shalala announced Tuesday that the medical school will take 'difficult and painful but necessary steps' next month to reduce costs, including staff cuts.In a letter to employees, she called the cuts 'significant' but provided no details about how many employees might be laid off.

'The process will take place in stages, and affected employees will be notified during the month of May,' Shalala wrote. 'Reductions will not impact clinical care or our patients and will primarily focus on unfunded research and administrative areas.'

Shalala said the cuts were necessary because of 'unprecedented factors' including the global downturn of 2008, decreased funding for research and clinical care, plus cutbacks in payments from Jackson Health System. The Jackson reductions 'have had a profound effect on our finances,' she wrote.

Placing the blame for the medical school's financial problems on Jackson Health System, the local safety-net health system, did not sit well with that organization's leadership. In another Miami Herald story, its chairman stated that the real problem might be:
'investments that they have made that may or may not have panned out,' including the purchase in 2007 of Cedars Medical Center, across the street from Jackson Memorial, for a price that several experts say was far too high.

In fact, we discussed here allegations that the University of Miami Medical School's purchase of a facility that was renamed the University of Miami Hospital adjacent to Jackson was meant to take insured patients from that already struggling facility.

Nonetheless, the Medical School proceeded with its cuts, which resulted in 800 layoffs (see Miami Herald story here.) The next Miami Herald story suggested that the cuts would disproportionately impact worthy researchers, for example,
When Nobel Laureate Andrew Schally arrived in South Florida six years ago, he was greeted with great fanfare and named a distinguished professor of pathology at the University of Miami medical school. Now he says his work is one of the many casualties of the school’s budget slashing.

Schally says UM told him several weeks ago that his annual funding of $150,000 for research would end May 31, part of widespread cuts in the medical school that could eliminate up to 800 jobs this month and trigger major reductions in research.

'I was shocked... We developed so many drugs for the university,' Schally says. 'They are killing the goose that laid the golden egg.'
The President's New House
The headline of another Miami Herald story last week suggested that things had gotten so bad that the cuts were even going to affect top university leadership's lifestyle:
UM president’s house sells for $9 million

We had posted about University of Miami President Donna Shalala's lavish university funded living conditions a while ago. Now it seems she would be giving up
'tropical ambiance,' 4.6 acres of lush gardens, and a prestigious Gables Estates address.

This "rare piece of Florida history" also had
a guest room created specifically to host the Dalai Lama during His Holiness’ visits to South Florida.

So can we conclude that the University is really tightening its belt when its President is forced to move out of such a lush environment? Not really.

In fact, Ms Shalala may be moving to even more plush surroundings, courtesy the university's supposedly challenged budget:
The 32-acre Pinecrest development, built on land donated to the university by UM law grad-turned-philanthropist Frank Smathers Jr., exclusively houses UM faculty. Shalala will now join their ranks as both boss and neighbor.

Decades ago, the grounds were home to Smathers’ Arabian horses and world-renowned mango collection. The UM-built homes are clustered in the center one-third of the acreage 'to safeguard the botanical integrity of the estate,' according to the university’s website. The remaining land is dominated by lush plants and fruit groves, and is maintained by Fairchild Tropical Botanical Gardens.

In particular,
It’s a very bold house,” Taylor said of Shalala’s new digs. “It’s a dominant house in the neighborhood.”

Taylor said the all-white exterior of the new home is a noticeable contrast to the more-earthy tones of other houses nearby. The university is calling it the 'Ibis House' after UM’s beloved (and also all-white) mascot.

Shalala’s new home will sit on a quarter-acre of land — dramatically less property than she enjoyed before. On the plus side, Shalala, just as in her old home, will enjoy about 9,000 or so square feet of interior space, and an in-home elevator connecting the first and second floors.

The new home is also situated in a unique gated community that offers a community clubhouse, tennis courts and pool, and meticulously landscaped gardens.

Was anyone really expecting that Ms Shalala would have to find her own housing, like the 99 percent have to?

Summary
So here we have another example of how the notion of CEO exceptionalism has filtered down from large for-profit corporations to even non-profit, ostensibly mission-oriented health care institutions. Leaders of health care organizations are now deemed to be so important, at least in the eyes of their hired public relations staff, that they must be given every luxury. Perhaps if housed in any space smaller than 9000 feet, Ms Shalala would be so confined as not be able to think great thoughts anymore, like how many layoffs would be needed to sufficiently cut costs. Worse, maybe without such free housing, she would just decide that the institution would not be showing enough gratitude, and so her amazingly brilliant leadership would have to seek new pastures.

Maybe, on the other hand, Ms Shalala's new house is just another demonstration how health care has become dominated by leadership whose own compensation and privilege seems to come before the mission., and sees no problem in asking for "difficult and painful" cuts from those who do the real work on the ground while building itself new mansions.

So as usual, it is time to say that true health care reform would foster leadership  that upholds the core values of health care, and focuses on and are accountable for the mission, not on secondary responsibilities that conflict with these values and their mission, and not on self-enrichment. Leaders ought to be rewarded reasonably, but not lavishly, for doing what ultimately improves patient care, or when applicable, good education and good research.

Cart Before the Horse, Part 3: AHRQ's "Health IT Hazard Manager"

In a July 2010 post "Meaningful Use Final Rule: Have the Administration and ONC Put the Cart Before the Horse on Health IT?" and an Oct . 2010 post "Cart before the horse, again: IOM to study HIT patient safety for ONC; should HITECH be repealed?" I wrote about the postmodern "ready, fire, aim" approach to health IT:

In the first post, I wrote:

... These "usability" problems require long term solutions. There are no quick fix, plug and play solutions. Years of research are needed, and years of system migrations as well for existing installations.

Yet we now have an HHS Final Rule on "meaningful use" regarding experimental, unregulated medical devices the industry itself admits have major usability problems, along with a growing body of literature on the risks entailed.
For crying out loud, talk about putting the cart before the horse...

Something's very wrong here...

However, this situation is anything but humorous.

How more "cart before the horse" can government get?

In the second post, I wrote:

... So, in the midst of a National Program for Health IT in the United States (NPfIT in the U.S.), with tens of billions of dollars earmarked for health IT already (money we don't really have, but it can be printed quickly, or borrowed from China) the IOM is going to study health IT safety, prevention of health IT-related errors, etc. ... only now?

Here we go yet again.

The problem with the AHRQ (Agency for Healthcare Research and Quality, a division of HHS) announcement below of a webinar about a new tool for identifying, categorizing, and resolving health IT hazards, as I have written before, is putting the "cart before the horse" and throwing medical ethics to the wind.

If we've just developed a tool "for identifying, categorizing, and resolving health IT hazards", the magnitude of which others such as IOM admit are unknown to our detriment (e.g., Health IT and Patient Safety: Building Safer Systems for Better Care, pg. S-2), then health IT is, it follows, an experimental technology.

If it is an experimental technology, AHRQ and others in HHS should probably be raising the issue of a slow down or moratorium on widespread rollout under HITECH until risk management and remediation is better understood.  At the very least they should be calling for patient informed consent that a device that will largely regulate their care is experimental, that a competency "gap" exists among healthcare practitioners within the "health IT environment" (meaning patients are at risk), and that patients should be offered the opportunity for informed consent with opt-out provisions.  The principals should not just be announcing a webinar:

Sent: Tuesday, June 05, 2012 12:23 PM
To: OHITQUSERS@LIST.NIH.GOV
Subject: Register Now! AHRQ Health IT Webinar "Purpose and Demonstration of the Health IT Hazard Manager and Next Steps" June 11, 2:30 PM ET

Agency for Healthcare Research and Quality

Purpose and Demonstration of the Health IT Hazard Manager and Next Steps

June 11, 2012 — 2:30-4 p.m., EST

The Agency for Healthcare Research and Quality (AHRQ) has identified a gap in a health care/public health practitioner’s competency within the health IT environment. This webinar is designed to increase practitioners’ competencies in several areas: improving health care decision making; supporting patient-centered care; and enhancing the quality and safety of medication management by improving the ability to identify, categorize, and resolve health IT hazards.

The Webinar will explore the Health IT Hazard Manager—a tool for identifying, categorizing, and resolving health IT hazards. When implemented, the tool allows health care organizations and software vendors alike to learn about potential hazards and work to resolve them, including the use of data to communicate potential and actual adverse effects. The session will discuss how the Health IT Hazard Manager was tested and refined as well as strategies and implications for deploying it. The target audience includes AHRQ grantees/researchers; health care providers, including physicians and nurses; consumers/patients; and health care policymakers.

... Webinar learning objectives include:

1. Describe the rationale for developing the Health IT Hazard Manager and how it evolved through alpha and beta testing.
2. Explain the process for identifying and categorizing health IT-related hazards.
3. Demonstrate how the Health IT Hazard Manager would be used [i.e., it's not yet in use, despite mandates for HIT rollout with penalties for non-adopters - ed.] within and across care delivery organizations and health IT software vendors.
4. Discuss policy and process implications for deploying the Health IT Hazard Manager via different organizations (i.e., AHRQ; Office of the National Coordinator for Health IT; Patient Safety Organization(s); Accrediting bodies; IT entities).

In effect, HHS seems to be saying "we're working on the HIT risk problem, but roll it out anyway; if you get harmed or killed, tough luck."  This seems a form of negligence.

Have we thrown out all we know about medical research and human subjects protections in face of the magical powers and profits of computers in medicine?

-- SS

More Electronic Medical Record Breaches: You Could Not Do This With Paper

I have written repeatedly on the dangers posed by poorly managed health IT regarding information breaches.  See "2011 Closes on a Note of Electronic Medical Record Privacy Breach Shame" and other posts at this query link:   http://hcrenewal.blogspot.com/search/label/medical%20record%20confidentiality

Now this, from Kaiser Health News and The Washington Post:

As Patients' Records Go Digital, Theft And Hacking Problems Grow 
Jun 03, 2012

As more doctors and hospitals go digital with medical records, the size and frequency of data breaches are alarming privacy advocates and public health officials.

Keeping records secure is a challenge that doctors, public health officials and federal regulators are just beginning to grasp. And, as two recent incidents at Howard University Hospital show, inadequate data security can affect huge numbers of people.  

With paper, you'd need a stream of trucks to accomplish this magnitude of theft:

On May 14, federal prosecutors charged one of the hospital's medical technicians with violating the Health Insurance Portability and Accountability Act, or HIPAA. Prosecutors say that over a 17-month period Laurie Napper used her position at the hospital to gain access to patients' names, addresses and Medicare numbers in order to sell their information. A plea hearing has been set for June 12; Napper's attorney declined comment.

Just a few weeks earlier, the hospital notified more than 34,000 patients that their medical data had been compromised. A contractor working with the hospital had downloaded the patients' files onto a personal laptop, which was stolen from the contractor's car. The data on the laptop was password-protected but unencrypted, which means anyone who guessed the password could have accessed the patient files without a randomly generated key. According to a hospital press release, those files included names, addresses, and Social Security numbers -- and, in a few cases, "diagnosis-related information."

I add that they could also probably have booted the laptop from alternate media, and/or removed the hard drive and inserted into another computer, to access the contents.

Ronald J. Harris, Howard University's top spokesman, said in an e-mail that the two incidents are unrelated, but declined to answer further questions. In its press release about the stolen laptop, the hospital said it will set new requirements for all laptops used by contractors and those issued to hospital personnel to help protect data.

Still it could have been worse. Much worse.

Just days after Howard University contacted its patients about the stolen laptop, the Utah Department of Health announced that hackers based in Eastern Europe had broken into one of its servers and stolen personal medical information for almost 800,000 people -- more than one of every four residents of the state.

How many trucks (and Stargate SG-1 style invisibility cloaks) would it take to inconspicuously steal 800,000 paper charts, I ask?

And last November, TRICARE, which handles health insurance for the military, announced that a trove of its backup computer tapes had been stolen from one of its contractors in Virginia. The tapes contained names, Social Security numbers, home addresses and, in some cases, clinical notes and lab test results for nearly 5 million patients, making it the largest medical data breach since the Department of Health and Human Services began tracking incidents two and a half years ago.

Five million charts in a country of 300 million people...

As recently as five years ago, it's possible no one outside Howard University would have known about the incidents there. But, new reporting rules adopted as part of the 2009 stimulus act insure the public knows far more about medical data breaches than in the past. When a breach occurs that affects 500 or more patients, health care providers now must notify not only HHS, but also the media.

Meaning there were breaches the public does not know about.

Deven McGraw, director of the health privacy project at the Center for Democracy & Technology, a Washington-based Internet advocacy group, said the number of incidents is growing with the increased use of digital health records. The health care industry, she added, has been slow to respond.

A problem is not enough "motivation."

"Many financial companies have used encryption for years and they probably wonder what the heck is going on with the health care industry," McGraw said. "It's much cheaper to deploy safeguards than to suffer a breach."

I offer a one word answer:  complacency.

Now for the "spin control":

This growing problem puts HHS in a tough spot. It is pushing hospitals and doctors to adopt electronic health records, but it's also responsible for punishing health care providers who fail to properly secure their patients' records.

"Mistakes happen, incidents happen, corners get cut from time to time," said Susan McAndrew, deputy director for health information policy at HHS's Office of Civil Rights. "That's where we come in."

"From time to time" is a rather modest description of the millions of breaches mentioned in just this posting.

 But as I've written before, don't worry, your records are safe.

Just don't tell the doctor about that "incident" at that seedy club the other night, and find some other excuse to get the antibiotics you need, and that information will be safe, too.

-- SS