Showing posts with label medical record privacy. Show all posts
Showing posts with label medical record privacy. Show all posts

Friday, February 18, 2011

EHR as Molestation Candidate Selector: What was this Resident looking for in the EHR before "examining" female patients?

As I was the Director of Clinical Informatics/CMIO (Chief Medical Informatics Officer) at Christiana Care Health System in Delaware back in the mid to late 1990's, and was the physician-architect of their EHR systems then, I find this story particularly disturbing:

First-Year Resident Accused Of Fondling 6 Patients
FoxPhilly.com, Feb. 18, 2011

Warrants Issued, Police Searching For Suspect

NEWARK, Del. - Delaware State Police are trying to find a former first-year resident at Christiana Hospital who they have identified as a suspect in alleged sexual contact with six patients.

According to state police, [the former Medical Resident] has been charged with six counts each of third-degree unlawful sexual contact and abuse, mistreatment or neglect of a patient or resident of a facility.

... The incidents were reported between Oct. 1 and Nov. 15 at the hospital in Newark.

The female patients were between the ages of 20 and 32, police said.

Authorities interviewed victims and hospital staff, reviewed patient charts, and audited access to computer records, which led to the identification of [the Resident] as a suspect, according to state police.

... State police said investigators found [the Resident] accessed the computerized hospital records of the six victims prior to the incidents
, performed "physical exams" on the victims and failed to provide clinical documentation of the examinations in the victims' hospital charts. Scheduling records also indicated that [the Resident] was working when the incidents occurred.

... In three of the incidents, it was determined that the victims were identified as "non- teaching" patients for whom [the Resident] had no direct patient care responsibilities and had no authority to conduct physical exams or access their hospital records.

Also noted in another account of the story in the Delaware News Journal (a newspaper) is this:

... State police initially released details about three of the assaults on Nov. 12 and said at the time that they were investigating why hospital officials did not report the incidents to police until after the third assault, some two weeks after the first victim reported the incident to hospital staff.

During the subsequent police investigation, three additional women contacted state police to report similar incidents.

One could ask, then, why the Medical Resident was able to access these medical records, and why the unauthorized accesses apparently took some time to discover by "investigators" (presumably law enforcement officers), only after complaints were made.

It is also reasonable to assume this Resident did not abuse the first woman's records he found in a search. There was likely a larger series of unauthorized chart accesses as he searched the EMR system. In other words, I don't think he was peeking at an individual record, and then going in to a room to do his nasty work, one at a time. He was likely looking at a number of potential "candidates" before each incident; i.e., he was likely "trolling around" for potential victims.

It would be interesting to see the electronic "footprint" he left.

I had horrifying firsthand experience with abuse of electronic medical information in an earlier role in the public sector.

Specifically, I had observed the events in John Doe vs. the Southeastern Pennsylvania Transportation Authority (link). In this situation a gay co-worker, the SEPTA Employee Assistance Program liaison John Eakes (now deceased of AIDS) with whom I had worked extensively in the SEPTA Medical Department, was discriminated against by administration after peeks at his prescription records. His medications included those used in treating HIV-positive patients:

...[After the disclosure to SEPTA Chief Administrative Officer (and Deputy General Manager - ed.) Judith Pierce, Doe - a.k.a. Eakes] testified that he felt as though he were being treated differently. A proposal he had made for an in-house employee assistance program met with scant interest; he felt that this was because of his HIV condition. In addition, an administrator who reported to Pierce did not call on Doe to assist in the same way that he had called on Doe earlier. Doe testified that he felt as though there was less social chitchat, co-workers ate less of the baked goods he brought to the office to share, and that his work space seemed more lonely than before. He also became fearful of Pierce, who never told Doe that she knew of his illness. Doe alleges that he became depressed and requested a prescription for Zoloft, an antidepressant, from his physician. Later, another antidepressant called Elavil was added to the medications Doe was taking.

John Eakes was a good and conscientious employee and deserved none of this, in these relatively early years of HIV+ intolerance.

Therefore, when I was CMIO at Christiana Care Health System just a few years later, and as Chair of the committee on compliance with the then-new Health Insurance Portability and Accountability Act of 1996 (HIPAA), I recommended strongly that chart audits for unauthorized access be performed on a regular basis by a dedicated person or team, and rapid action taken if it occurred. (Then again, my counsel on healthcare IT was not infrequently ignored.)

Multiple accesses by a resident (trainee) to EHR records of non-teaching (private) patients should have sent up a very large and immediate cybernetic red flag.

Ding! Ding! Ding! Warning! Unauthorized accesses detected...

I am also concerned about the characteristics this former trainee was seeking in reviewing the EHR. A history of gynecological or breast disease to serve as a ploy for performing an intrusive exam? Was he looking for a psychiatric history? A history of prior sexual abuse?

While the EHR proved helpful in post hoc forensics, are we now seeing another potential abuse of EHR's for the identification of patients who may be preyed upon by the disturbed?

It would be helpful to know if there was a common medical theme regarding the patients affected in this rather shocking affair.

-- SS

Feb. 19 Addendum:

This affair reminds me of a saying that became news in the election of President Barack Obama:

"The Chickens Have Come Home To Roost" - Rev. Jeremiah Wright

Feb. 21 Addendum:

It appears that the corporate PR folks are monitoring the airwaves in planning their responses to this scandal. From the blog viewing logs:

IP Address 167.112.160.# (Christiana Care Health Services)
ISP Christiana Care Health Services
Time of Visit Feb 21 2011 9:36:32 am
Last Page View Feb 21 2011 9:42:03 am
Visit Length 5 minutes 31 seconds
Page Views 5
Referring URL http://us.cisionpoint.com/NewsItemDetail.aspx?id=1671771040
Visit Entry Page http://hcrenewal.blogspot.com/2011/02/what-was-this-medical-resident-looking.html
Visit Exit Page http://hcrenewal.blogspot.com/2011/02/what-was-this-medical-resident-looking.html

On the "Cisionpoint" company, us.cisionpoint.com, the "referring" URL that led to this post:

CisionPoint brings together - in one integrated customized dashboard - the on-demand tools you need to create, execute and evaluate superior campaigns from start to finish.

Log in to plan your campaign, connect with the media directly, monitor news coverage and analyze campaign results.


It will be interesting to see how this horrifying episode is "managed" by the corporate spin doctors.

-- SS

Feb. 21 addendum #2:

Here is a message posted by the organization:

Message from the chief operating officer

Posted today

Christiana Care is steadfast in our commitment to the safety and well-being of our patients, employees and all visitors to our campuses.

The Delaware State Police have issued a press release identifying a suspect in the case of inappropriate touching first reported late last year. The suspect is a former first year medical resident at Christiana Care.

The prompt and thorough work of our Department of Public Safety when the allegations first surfaced, and information we shared with the State Police from our robust health information technology system, was instrumental to the process. We quickly identified the medical resident as a person of interest, and took swift action to prevent any further patient contact. As a result of our preliminary investigation, he was suspended and upon further investigation dismissed from employment.

Our rapid response when the allegations were first reported revealed no systemic issues contributed to this incident. As an organization guided by learning, we are continuing a thorough review of best practices in hospital security to determine if there are any new security measures we should adopt.

[Hopefully in the intervening years since I was CMIO, they've become even more of a learning organization compared to here, here and here, where under the prior "C" level leadership they learned so much from me and made me feel so at home, I felt compelled to leave to maintain my sanity - ed.]

We remind and encourage all patients and family to always ask health care providers to identify themselves, explain why they are there to see the patient, and explain the care provided to them. All Christiana Care employees are required to prominently display their identification badges.

[One wonders if they now permit PhD holders to use that credential on the badge, not permitted when I was there - ed.]

We deeply regret the alleged incidents and our concern for the affected patients is shared throughout our health system.

Gary Ferguson
Chief Operating Officer

As I knew Mr. Ferguson in a prior role, and as he is a good person, I with some regret point out that this appears to be corporate spin control.

A truly "robust" HIT security system, in my opinion, would have flagged the perpetrator after the first victim. It might even have prevented the molestation if there was a time delay between when he, as a trainee, trolled for a victim by viewing the records of a private patient, and then saw the patient, without some medical emergency that could have justified the records breach.

Merriam-Webster dictionary

ro·bust
adj \rō-ˈbəst, ˈrō-(ˌ)bəst\

a : having or exhibiting strength or vigorous health
b : having or showing vigor, strength, or firmness [a robust debate] [a robust faith]
c : strongly formed or constructed : sturdy [a robust plastic]
d : capable of performing without failure under a wide range of conditions [robust software]

This "robust" system, after all, is a system critical to human life and well-being, not an inventory system of medical data.

Let an unauthorized person access, say, government intelligence files, and see how far that flies...

(Notwithstanding the Wikileaks affair, where the low-level person who accessed the diplomatic files did have authorization to access the servers, through managerial complacency.)

-- SS

Feb. 26 Addendum:

This story was picked up by the Newark Post, the local newspaper in Newark, Delaware, where Christiana Hospital is located.

Questions raised about access to hospital medical records
By Doug Rainey, Newark Post
Published: Thursday, February 24, 2011

-- SS

EHR as Molestation Candidate Selector: What was this Resident looking for in the EHR before "examining" female patients?

As I was the Director of Clinical Informatics/CMIO (Chief Medical Informatics Officer) at Christiana Care Health System in Delaware back in the mid to late 1990's, and was the physician-architect of their EHR systems then, I find this story particularly disturbing:

First-Year Resident Accused Of Fondling 6 Patients
FoxPhilly.com, Feb. 18, 2011

Warrants Issued, Police Searching For Suspect

NEWARK, Del. - Delaware State Police are trying to find a former first-year resident at Christiana Hospital who they have identified as a suspect in alleged sexual contact with six patients.

According to state police, [the former Medical Resident] has been charged with six counts each of third-degree unlawful sexual contact and abuse, mistreatment or neglect of a patient or resident of a facility.

... The incidents were reported between Oct. 1 and Nov. 15 at the hospital in Newark.

The female patients were between the ages of 20 and 32, police said.

Authorities interviewed victims and hospital staff, reviewed patient charts, and audited access to computer records, which led to the identification of [the Resident] as a suspect, according to state police.

... State police said investigators found [the Resident] accessed the computerized hospital records of the six victims prior to the incidents
, performed "physical exams" on the victims and failed to provide clinical documentation of the examinations in the victims' hospital charts. Scheduling records also indicated that [the Resident] was working when the incidents occurred.

... In three of the incidents, it was determined that the victims were identified as "non- teaching" patients for whom [the Resident] had no direct patient care responsibilities and had no authority to conduct physical exams or access their hospital records.

Also noted in another account of the story in the Delaware News Journal (a newspaper) is this:

... State police initially released details about three of the assaults on Nov. 12 and said at the time that they were investigating why hospital officials did not report the incidents to police until after the third assault, some two weeks after the first victim reported the incident to hospital staff.

During the subsequent police investigation, three additional women contacted state police to report similar incidents.

One could ask, then, why the Medical Resident was able to access these medical records, and why the unauthorized accesses apparently took some time to discover by "investigators" (presumably law enforcement officers), only after complaints were made.

It is also reasonable to assume this Resident did not abuse the first woman's records he found in a search. There was likely a larger series of unauthorized chart accesses as he searched the EMR system. In other words, I don't think he was peeking at an individual record, and then going in to a room to do his nasty work, one at a time. He was likely looking at a number of potential "candidates" before each incident; i.e., he was likely "trolling around" for potential victims.

It would be interesting to see the electronic "footprint" he left.

I had horrifying firsthand experience with abuse of electronic medical information in an earlier role in the public sector.

Specifically, I had observed the events in John Doe vs. the Southeastern Pennsylvania Transportation Authority (link). In this situation a gay co-worker, the SEPTA Employee Assistance Program liaison John Eakes (now deceased of AIDS) with whom I had worked extensively in the SEPTA Medical Department, was discriminated against by administration after peeks at his prescription records. His medications included those used in treating HIV-positive patients:

...[After the disclosure to SEPTA Chief Administrative Officer (and Deputy General Manager - ed.) Judith Pierce, Doe - a.k.a. Eakes] testified that he felt as though he were being treated differently. A proposal he had made for an in-house employee assistance program met with scant interest; he felt that this was because of his HIV condition. In addition, an administrator who reported to Pierce did not call on Doe to assist in the same way that he had called on Doe earlier. Doe testified that he felt as though there was less social chitchat, co-workers ate less of the baked goods he brought to the office to share, and that his work space seemed more lonely than before. He also became fearful of Pierce, who never told Doe that she knew of his illness. Doe alleges that he became depressed and requested a prescription for Zoloft, an antidepressant, from his physician. Later, another antidepressant called Elavil was added to the medications Doe was taking.

John Eakes was a good and conscientious employee and deserved none of this, in these relatively early years of HIV+ intolerance.

Therefore, when I was CMIO at Christiana Care Health System just a few years later, and as Chair of the committee on compliance with the then-new Health Insurance Portability and Accountability Act of 1996 (HIPAA), I recommended strongly that chart audits for unauthorized access be performed on a regular basis by a dedicated person or team, and rapid action taken if it occurred. (Then again, my counsel on healthcare IT was not infrequently ignored.)

Multiple accesses by a resident (trainee) to EHR records of non-teaching (private) patients should have sent up a very large and immediate cybernetic red flag.

Ding! Ding! Ding! Warning! Unauthorized accesses detected...

I am also concerned about the characteristics this former trainee was seeking in reviewing the EHR. A history of gynecological or breast disease to serve as a ploy for performing an intrusive exam? Was he looking for a psychiatric history? A history of prior sexual abuse?

While the EHR proved helpful in post hoc forensics, are we now seeing another potential abuse of EHR's for the identification of patients who may be preyed upon by the disturbed?

It would be helpful to know if there was a common medical theme regarding the patients affected in this rather shocking affair.

-- SS

Feb. 19 Addendum:

This affair reminds me of a saying that became news in the election of President Barack Obama:

"The Chickens Have Come Home To Roost" - Rev. Jeremiah Wright

Feb. 21 Addendum:

It appears that the corporate PR folks are monitoring the airwaves in planning their responses to this scandal. From the blog viewing logs:

IP Address 167.112.160.# (Christiana Care Health Services)
ISP Christiana Care Health Services
Time of Visit Feb 21 2011 9:36:32 am
Last Page View Feb 21 2011 9:42:03 am
Visit Length 5 minutes 31 seconds
Page Views 5
Referring URL http://us.cisionpoint.com/NewsItemDetail.aspx?id=1671771040
Visit Entry Page http://hcrenewal.blogspot.com/2011/02/what-was-this-medical-resident-looking.html
Visit Exit Page http://hcrenewal.blogspot.com/2011/02/what-was-this-medical-resident-looking.html

On the "Cisionpoint" company, us.cisionpoint.com, the "referring" URL that led to this post:

CisionPoint brings together - in one integrated customized dashboard - the on-demand tools you need to create, execute and evaluate superior campaigns from start to finish.

Log in to plan your campaign, connect with the media directly, monitor news coverage and analyze campaign results.


It will be interesting to see how this horrifying episode is "managed" by the corporate spin doctors.

-- SS

Feb. 21 addendum #2:

Here is a message posted by the organization:

Message from the chief operating officer

Posted today

Christiana Care is steadfast in our commitment to the safety and well-being of our patients, employees and all visitors to our campuses.

The Delaware State Police have issued a press release identifying a suspect in the case of inappropriate touching first reported late last year. The suspect is a former first year medical resident at Christiana Care.

The prompt and thorough work of our Department of Public Safety when the allegations first surfaced, and information we shared with the State Police from our robust health information technology system, was instrumental to the process. We quickly identified the medical resident as a person of interest, and took swift action to prevent any further patient contact. As a result of our preliminary investigation, he was suspended and upon further investigation dismissed from employment.

Our rapid response when the allegations were first reported revealed no systemic issues contributed to this incident. As an organization guided by learning, we are continuing a thorough review of best practices in hospital security to determine if there are any new security measures we should adopt.

[Hopefully in the intervening years since I was CMIO, they've become even more of a learning organization compared to here, here and here, where under the prior "C" level leadership they learned so much from me and made me feel so at home, I felt compelled to leave to maintain my sanity - ed.]

We remind and encourage all patients and family to always ask health care providers to identify themselves, explain why they are there to see the patient, and explain the care provided to them. All Christiana Care employees are required to prominently display their identification badges.

[One wonders if they now permit PhD holders to use that credential on the badge, not permitted when I was there - ed.]

We deeply regret the alleged incidents and our concern for the affected patients is shared throughout our health system.

Gary Ferguson
Chief Operating Officer

As I knew Mr. Ferguson in a prior role, and as he is a good person, I with some regret point out that this appears to be corporate spin control.

A truly "robust" HIT security system, in my opinion, would have flagged the perpetrator after the first victim. It might even have prevented the molestation if there was a time delay between when he, as a trainee, trolled for a victim by viewing the records of a private patient, and then saw the patient, without some medical emergency that could have justified the records breach.

Merriam-Webster dictionary

ro·bust
adj \rō-ˈbəst, ˈrō-(ˌ)bəst\

a : having or exhibiting strength or vigorous health
b : having or showing vigor, strength, or firmness [a robust debate] [a robust faith]
c : strongly formed or constructed : sturdy [a robust plastic]
d : capable of performing without failure under a wide range of conditions [robust software]

This "robust" system, after all, is a system critical to human life and well-being, not an inventory system of medical data.

Let an unauthorized person access, say, government intelligence files, and see how far that flies...

(Notwithstanding the Wikileaks affair, where the low-level person who accessed the diplomatic files did have authorization to access the servers, through managerial complacency.)

-- SS

Feb. 26 Addendum:

This story was picked up by the Newark Post, the local newspaper in Newark, Delaware, where Christiana Hospital is located.

Questions raised about access to hospital medical records
By Doug Rainey, Newark Post
Published: Thursday, February 24, 2011

-- SS

Friday, December 10, 2010

Don't Worry, the Feds Say Your Medical Information Will Be Kept Absolutely Private

With the planned burgeoning of health IT nationally and the formation of information "exchanges", ensuring information privacy, confidentiality and security become paramount. Systematic threats to medical privacy, confidentiality and security could do significant damage to our Republic.

Yet, according to Modernhealthcare.com in "Looking to loosen privacy rules in Calif." (Dec. 7, 2010):

The head of a federal privacy and security advisory committee and a lawyer for a prominent consumer affairs organization are scheduled to press California officials this week to revise that state's health information exchange (HIE) guidelines [which have strong opt-in consent requirements -ed.] to conform to less-stringent federal privacy recommendations.

Joseph Conn, author of the article relates:

Deven McGraw, director of the Health Privacy Project at the Center for Democracy & Technology, a Washington think tank, and Mark Savage, a San Francisco-based lawyer for Consumers Union [McGraw is also an appointee to a prominent role in the federally charted HHS Health IT Policy Committee; see below - ed.], are to participate via telephone Thursday in a meeting of the California Privacy and Security Advisory Board [CalPSAB].

Here's the problem:

The CalPSAB advises the state's health secretary on healthcare privacy and security policy. Given the traditional leadership role that California plays in the healthcare industry, the board's recommendations could influence how patient consent is handled in electronic health information exchanges nationwide.

Why these recommendations? To satisfy the needs of the reckless rush to national health IT:

McGraw, a lawyer, is a member of the federally charted Health IT Policy Committee, created pursuant to the American Recovery and Reinvestment Act of 2009 to advise the Office of the National Coordinator for Health Information Technology at HHS. McGraw also serves on five work groups or subcommittees of the Health IT Policy Committee. She is chairwoman of its privacy and security workgroup and co-chairwoman of its privacy and security tiger team. [The name "tiger team" makes me wonder who's going to get mauled - ed.]

McGraw and Savage sent a letter Oct. 6 to California Health and Human Services Sec. S. Kimberly Belshe along with a copy of the tiger team's recommendations on privacy and security for health information exchange originally sent to ONC head David Blumenthal on Aug. 19. They also sent Belshe a 10-page "briefing paper" summarizing those recommendations and a follow-up letter Dec. 5.

The briefing paper urged California to "adopt a comprehensive framework of privacy protections such as that recommended by the tiger team." [I.e., that are less stringent than California's - ed.]

They threw a little fear into their recommendations:

The brief also warned that with the first stage of a federal IT incentive program beginning soon, without a consent policy in place, "California's privacy and security framework for patient health information cannot be completed." Furthermore, if that framework isn't completed, the brief asserted, "eligible providers cannot achieve the meaningful-use criteria and benefit from the substantial federal reimbursements."

In other words, "The feds have rushed you to such a point that you cannot possibly have enough time to seriously consider and put into place rigorous privacy regulation, so adopt our 'tiger team' recommendations (or you ain't gonna get money from the feds)."

This is not reassuring.

Among other issues, it seems another example, as in HITECH itself, of the Federal Government setting timelines and policies and using the "fear, uncertainty and doubt" (FUD) principle to manipulate and strong-arm the States into ceding their rights to regulate healthcare. Such Federal overreach seems to be common these days.

Only now, due to the nature of the data involved, this gets personal.

Listen to us, we're the Tiger Team!

Of course, there's always plausible deniability:

Officially, the ONC is not a party to the push by McGraw and Savage to leverage the federal tiger team's work in California, according to the ONC. Asked whether the ONC was aware of and supports the efforts of McGraw in California, spokeswoman Nancy Szemraj said, "We have no knowledge of this letter."

Again, not very reassuring or credible, considering:

1) as above, that McGraw and Savage sent a letter Oct. 6 to California Health and Human Services Sec. S. Kimberly Belshe along with a copy of the tiger team's recommendations on privacy and security for health information exchange originally sent to ONC head David Blumenthal on Aug. 19.

and:

2) McGraw's role on five work groups or subcommittees of the Health IT Policy Committee:

Health IT Policy Committee (A Federal Advisory Committee)

The Health IT Policy Committee will make recommendations to the National Coordinator for Health IT on a policy framework for the development and adoption of a nationwide health information infrastructure, including standards for the exchange of patient medical information. The American Recovery and Reinvestment Act of 2009 (ARRA) provides that the Health IT Policy Committee shall at least make recommendations on standards, implementation specifications, and certifications criteria in eight specific areas.

-- SS

Addendum Dec. 10, 2010:

This post generated a comment containing a significant logical fallacy, apparently from Harley Geiger, staff counsel of the CDT (Center for Democracy and Technology) which is one of the key actors mentioned in the Modern Healthcare story. The comment and my comment back can be seen in the comments section at this post.

If the comment was truly from Mr. Geiger, I would be even less confident than before that an organization whose staff counsel will not or cannot proffer a logically coherent argument will protect our precious freedoms.

-- SS

Don't Worry, the Feds Say Your Medical Information Will Be Kept Absolutely Private

With the planned burgeoning of health IT nationally and the formation of information "exchanges", ensuring information privacy, confidentiality and security become paramount. Systematic threats to medical privacy, confidentiality and security could do significant damage to our Republic.

Yet, according to Modernhealthcare.com in "Looking to loosen privacy rules in Calif." (Dec. 7, 2010):

The head of a federal privacy and security advisory committee and a lawyer for a prominent consumer affairs organization are scheduled to press California officials this week to revise that state's health information exchange (HIE) guidelines [which have strong opt-in consent requirements -ed.] to conform to less-stringent federal privacy recommendations.

Joseph Conn, author of the article relates:

Deven McGraw, director of the Health Privacy Project at the Center for Democracy & Technology, a Washington think tank, and Mark Savage, a San Francisco-based lawyer for Consumers Union [McGraw is also an appointee to a prominent role in the federally charted HHS Health IT Policy Committee; see below - ed.], are to participate via telephone Thursday in a meeting of the California Privacy and Security Advisory Board [CalPSAB].

Here's the problem:

The CalPSAB advises the state's health secretary on healthcare privacy and security policy. Given the traditional leadership role that California plays in the healthcare industry, the board's recommendations could influence how patient consent is handled in electronic health information exchanges nationwide.

Why these recommendations? To satisfy the needs of the reckless rush to national health IT:

McGraw, a lawyer, is a member of the federally charted Health IT Policy Committee, created pursuant to the American Recovery and Reinvestment Act of 2009 to advise the Office of the National Coordinator for Health Information Technology at HHS. McGraw also serves on five work groups or subcommittees of the Health IT Policy Committee. She is chairwoman of its privacy and security workgroup and co-chairwoman of its privacy and security tiger team. [The name "tiger team" makes me wonder who's going to get mauled - ed.]

McGraw and Savage sent a letter Oct. 6 to California Health and Human Services Sec. S. Kimberly Belshe along with a copy of the tiger team's recommendations on privacy and security for health information exchange originally sent to ONC head David Blumenthal on Aug. 19. They also sent Belshe a 10-page "briefing paper" summarizing those recommendations and a follow-up letter Dec. 5.

The briefing paper urged California to "adopt a comprehensive framework of privacy protections such as that recommended by the tiger team." [I.e., that are less stringent than California's - ed.]

They threw a little fear into their recommendations:

The brief also warned that with the first stage of a federal IT incentive program beginning soon, without a consent policy in place, "California's privacy and security framework for patient health information cannot be completed." Furthermore, if that framework isn't completed, the brief asserted, "eligible providers cannot achieve the meaningful-use criteria and benefit from the substantial federal reimbursements."

In other words, "The feds have rushed you to such a point that you cannot possibly have enough time to seriously consider and put into place rigorous privacy regulation, so adopt our 'tiger team' recommendations (or you ain't gonna get money from the feds)."

This is not reassuring.

Among other issues, it seems another example, as in HITECH itself, of the Federal Government setting timelines and policies and using the "fear, uncertainty and doubt" (FUD) principle to manipulate and strong-arm the States into ceding their rights to regulate healthcare. Such Federal overreach seems to be common these days.

Only now, due to the nature of the data involved, this gets personal.

Listen to us, we're the Tiger Team!

Of course, there's always plausible deniability:

Officially, the ONC is not a party to the push by McGraw and Savage to leverage the federal tiger team's work in California, according to the ONC. Asked whether the ONC was aware of and supports the efforts of McGraw in California, spokeswoman Nancy Szemraj said, "We have no knowledge of this letter."

Again, not very reassuring or credible, considering:

1) as above, that McGraw and Savage sent a letter Oct. 6 to California Health and Human Services Sec. S. Kimberly Belshe along with a copy of the tiger team's recommendations on privacy and security for health information exchange originally sent to ONC head David Blumenthal on Aug. 19.

and:

2) McGraw's role on five work groups or subcommittees of the Health IT Policy Committee:

Health IT Policy Committee (A Federal Advisory Committee)

The Health IT Policy Committee will make recommendations to the National Coordinator for Health IT on a policy framework for the development and adoption of a nationwide health information infrastructure, including standards for the exchange of patient medical information. The American Recovery and Reinvestment Act of 2009 (ARRA) provides that the Health IT Policy Committee shall at least make recommendations on standards, implementation specifications, and certifications criteria in eight specific areas.

-- SS

Addendum Dec. 10, 2010:

This post generated a comment containing a significant logical fallacy, apparently from Harley Geiger, staff counsel of the CDT (Center for Democracy and Technology) which is one of the key actors mentioned in the Modern Healthcare story. The comment and my comment back can be seen in the comments section at this post.

If the comment was truly from Mr. Geiger, I would be even less confident than before that an organization whose staff counsel will not or cannot proffer a logically coherent argument will protect our precious freedoms.

-- SS

Monday, December 6, 2010

Annals of Electronic Information Security

At The Hill, former House Speaker Newt Gingrich raises a good point about the leak of hundreds of thousands of diplomatic cables and other private information:

"You have a private first class who downloads a quarter million documents, and the system doesn't say, 'Oh, you may be over extended?' I mean, this is a system so stupid that it ought to be a scandal of the first order," Gingrich said.

Regardless of which administration(s) are responsible (these systems probably took many years to reach their current form), one wonders if commercial EMR's suffer from the same oversights.

-- SS

Annals of Electronic Information Security

At The Hill, former House Speaker Newt Gingrich raises a good point about the leak of hundreds of thousands of diplomatic cables and other private information:

"You have a private first class who downloads a quarter million documents, and the system doesn't say, 'Oh, you may be over extended?' I mean, this is a system so stupid that it ought to be a scandal of the first order," Gingrich said.

Regardless of which administration(s) are responsible (these systems probably took many years to reach their current form), one wonders if commercial EMR's suffer from the same oversights.

-- SS

Wednesday, December 1, 2010

The Economist, Information Privacy, Microsoft, and Technological Determinism: An Online Debate

At The Economist, an online "debate" entitled Health 2.0 has been posted (link). It poses a debate between two experts.

In this case, the debate is between Peter Neupert, Corporate vice-president, Microsoft Health Solutions Group, vs. Deborah Peel, MD, Founder, Patient Privacy Rights and leader of the Coalition for Patient Privacy.

The readers are asked to vote upon whether they agree or disagree with this statement:

This house believes that any loss of privacy from digitising health care will be more than compensated for by the welfare gains from increased efficiency.

Note the phrase "will be."

Readers are also permitted to post comments.

My response was as follows:

30/11/2010 19:16:26 pm

Dear Sir,

The premise of this entire debate is logically fallacious, in fact begging the question.

This statement implies proven or inevitable "gains" from health IT. This is far from certain.

Health IT such as electronic medical records systems and computerized order entry systems (CPOE) remain highly experimental medical devices. They are unregulated devices as well. Their effects on medical care can be toxic, and patients are exposed to these effects without informed consent. The "gains" attributed to them are increasingly doubted in a growing body of literature.

See

"Common examples of healthcare IT difficulties" at http://www.ischool.drexel.edu/faculty/ssilverstein/cases/

and

"2009 a pivotal year in healthcare IT"
at
http://www.ischool.drexel.edu/faculty/ssilverstein/cases/?loc=cases&sloc...

for exposure to some of this literature.

In essence, management information systems and other business computing-derived approaches, customs and traditions for software design, development and lifecycle have proven ill suited in healthcare. Clinical computing and business computing are conflated; yet, they are two fundamentally different subspecialties of computing.

Further, medicine is a scientific discipline, yet the approach to IT in healthcare has been nearly devoid of science and critical thinking.

Sacrificing privacy for a dream that may or may not be true is not good social policy.

In the aftermath of the latest Wikileaks disclosures, a scientific approach - such as assertions about the beneficence of IT in healthcare not being made without strong, robust scientific evidence and without consideration of the downside evidence not being proferred so freely - would be a fine start.

S. Silverstein, MD
Drexel University
College of Information Science and Technology
Philadelphia, PA USA.


I found the position of Peter Neupert (Corporate vice-president, Microsoft Health Solutions Group) defending the motion particularly concerning:

Consumers must trust that the organisations they are engaged with are accountable and will respect—and protect—the privacy of their data.

"Must trust?"

I find this remarkable in the context of repeated violations of "trust" I've noted at this blog such as at my posts:


Neupert's view is especially paternalistic and naive in the context of Wikileaks repeatedly and recently leaking hundreds of thousands of supposedly secure documents, stolen from U.S. intelligence by at least one known person and probably others. If the Pentagon and U.S. intelligence cannot keep information secure, how can lowly hospital IT departments?

The moderator's initial comments are also disturbing:

... Supporters argue that health information technologies have advanced to the point that such [security] concerns are vastly overblown. After all, do not financial data flow freely and with little incident over digital systems? On this argument, any loss of privacy will be more than offset by efficiency gains. In arguing for the motion, Peter Neupert of Microsoft, a software firm, insists that digital medicine must be centred on the patient—rather than, say, the doctor or the insurer, as is often the case today [this 'centered on the patient' meme sounds good, but what exactly does it mean? - ed.] —and that medical information must be as mobile as the patient. If that is the case, he argues, it is not merely the efficiency of health systems that will improve but also the value of health care—and perhaps health outcomes too.

MR VIJAY V. VAITHEESWARAN
Correspondent, The Economist

Note the statements of absolute certainty - "will be more than offset by efficiency gains", "will improve", etc. They remind me of the statements made in the NEJM by the Director of ONC, Dr. David Blumenthal, as I wrote at "Science or Politics? The New England Journal and The 'Meaningful Use' Regulation for Electronic Health Records":

The widespread use of electronic health records (EHRs) in the United States is inevitable. EHRs will improve caregivers’ decisions and patients’ outcomes. Once patients experience the benefits of this technology, they will demand nothing less from their providers. Hundreds of thousands of physicians have already seen these benefits in their clinical practice.

On that I had commented:

Even though it is a "perspectives" article, I once long ago learned that in writing in esteemed scientific journals of worldwide impact, statements of certainty were at best avoided, or if made should be exceptionally well referenced. I note the lack of footnotes showing the source(s) of these statements.

The meme of technological determinism, that computerization in medicine is synonymous with, and will deterministically provide "improvements", no matter what the evidence, is quite concerning coming from a company as profoundly large and influential as Microsoft.

Further, the complete omission of consideration of the adverse clinical consequences (let alone mere information breaches) that may occur along the way to cybernetic utopia in healthcare is very disturbing. These are experimental medical devices, are unregulated, and are used without patient informed consent. Yet the IT industry seems to opine as if these systems are only to be used on experimental lab rats.

These systems produce "legible gibberish" of no clinical use to clinicians, but take clinician time to generate through distracting "clickorrhea." For example, just the placement of an IV and fluid infusion generates a half page of nonsense:


Actual "legible gibberish" from an ED EHR report, major health IT vendor. Half a page on how an IV was started and a saline infusion given. (How many distracting clinician mouse clicks did it take to produce this?) Click to enlarge.

Addendum 12/8/10 - From "Hidden Malpractice Dangers in EMRs", Steven I. Kern, Esq., Medscape.com:

Too Much Information

... Pages of repetitive documentation can be more time-consuming to review than brief, handwritten notes. When important information is embedded in paragraphs of boilerplate, it can easily be overlooked. The chance of missing critical data increases.

Overlooking important information is, of course, a significant cause of malpractice. A positive finding embedded in a string of negative findings can easily be missed.


Ironically, my relative was injured as a result of EHR-related disruption not long ago. Further, just the initial two and a half weeks of hospitalization generated more than 2,800 laser printed pages of "legible gibberish" (which cost just under $1000 to obtain; Kinko's should only have it so good).

A fellow physician I know well related:

From: [redacted name of MD]

Good Lord! I am so sorry to see this and hope your Mom gets better. You must be furious.

May I add to the cacophony? My wife went to [another local hospital's] ER for emergency transfusion. Their Emr displayed someone else's info under her name & SSN. Had I not been there she would have received incorrect treatment.

My wife went to [yet another hospital] for hip replacement. After surgery, while she slept off her anesthesia, a nurse came in and started injecting her. I asked and learned it was insulin. I stopped the nurse (with difficulty). My wife's not diabetic. Her screen showed someone else's orders. Had I not been there she might have died.

So keep up the good work... please!

[redacted name of MD]

How many other patients have been injured or killed as a result of EHR's?

In fact, we really don't know how many adverse events related to EHR's occur. As the Joint Commission itself admits in its Sentinel Events Alert #42, Safely implementing health information and converging technologies: "There is a dearth of data on the incidence of adverse events directly caused by HIT overall." I further wrote on this issue in a paper "A Dearth of Data on Unintended Consequences of Healthcare IT" here.

Is this a proper environment for national rollout of these clearly experimental medical devices, one should ask?

The memes of technological determinism and health IT "white-as-driven-snow" beneficence seem as difficult as vampires to eradicate.

Yet if this technology is to achieve the benefits of which it is capable via remediation of current IT industry customs, traditions and practices, these memes must be challenged and defeated.

Regarding health IT in the real world, reality matters.

-- SS

The Economist, Information Privacy, Microsoft, and Technological Determinism: An Online Debate

At The Economist, an online "debate" entitled Health 2.0 has been posted (link). It poses a debate between two experts.

In this case, the debate is between Peter Neupert, Corporate vice-president, Microsoft Health Solutions Group, vs. Deborah Peel, MD, Founder, Patient Privacy Rights and leader of the Coalition for Patient Privacy.

The readers are asked to vote upon whether they agree or disagree with this statement:

This house believes that any loss of privacy from digitising health care will be more than compensated for by the welfare gains from increased efficiency.

Note the phrase "will be."

Readers are also permitted to post comments.

My response was as follows:

30/11/2010 19:16:26 pm

Dear Sir,

The premise of this entire debate is logically fallacious, in fact begging the question.

This statement implies proven or inevitable "gains" from health IT. This is far from certain.

Health IT such as electronic medical records systems and computerized order entry systems (CPOE) remain highly experimental medical devices. They are unregulated devices as well. Their effects on medical care can be toxic, and patients are exposed to these effects without informed consent. The "gains" attributed to them are increasingly doubted in a growing body of literature.

See

"Common examples of healthcare IT difficulties" at http://www.ischool.drexel.edu/faculty/ssilverstein/cases/

and

"2009 a pivotal year in healthcare IT"
at
http://www.ischool.drexel.edu/faculty/ssilverstein/cases/?loc=cases&sloc...

for exposure to some of this literature.

In essence, management information systems and other business computing-derived approaches, customs and traditions for software design, development and lifecycle have proven ill suited in healthcare. Clinical computing and business computing are conflated; yet, they are two fundamentally different subspecialties of computing.

Further, medicine is a scientific discipline, yet the approach to IT in healthcare has been nearly devoid of science and critical thinking.

Sacrificing privacy for a dream that may or may not be true is not good social policy.

In the aftermath of the latest Wikileaks disclosures, a scientific approach - such as assertions about the beneficence of IT in healthcare not being made without strong, robust scientific evidence and without consideration of the downside evidence not being proferred so freely - would be a fine start.

S. Silverstein, MD
Drexel University
College of Information Science and Technology
Philadelphia, PA USA.


I found the position of Peter Neupert (Corporate vice-president, Microsoft Health Solutions Group) defending the motion particularly concerning:

Consumers must trust that the organisations they are engaged with are accountable and will respect—and protect—the privacy of their data.

"Must trust?"

I find this remarkable in the context of repeated violations of "trust" I've noted at this blog such as at my posts:


Neupert's view is especially paternalistic and naive in the context of Wikileaks repeatedly and recently leaking hundreds of thousands of supposedly secure documents, stolen from U.S. intelligence by at least one known person and probably others. If the Pentagon and U.S. intelligence cannot keep information secure, how can lowly hospital IT departments?

The moderator's initial comments are also disturbing:

... Supporters argue that health information technologies have advanced to the point that such [security] concerns are vastly overblown. After all, do not financial data flow freely and with little incident over digital systems? On this argument, any loss of privacy will be more than offset by efficiency gains. In arguing for the motion, Peter Neupert of Microsoft, a software firm, insists that digital medicine must be centred on the patient—rather than, say, the doctor or the insurer, as is often the case today [this 'centered on the patient' meme sounds good, but what exactly does it mean? - ed.] —and that medical information must be as mobile as the patient. If that is the case, he argues, it is not merely the efficiency of health systems that will improve but also the value of health care—and perhaps health outcomes too.

MR VIJAY V. VAITHEESWARAN
Correspondent, The Economist

Note the statements of absolute certainty - "will be more than offset by efficiency gains", "will improve", etc. They remind me of the statements made in the NEJM by the Director of ONC, Dr. David Blumenthal, as I wrote at "Science or Politics? The New England Journal and The 'Meaningful Use' Regulation for Electronic Health Records":

The widespread use of electronic health records (EHRs) in the United States is inevitable. EHRs will improve caregivers’ decisions and patients’ outcomes. Once patients experience the benefits of this technology, they will demand nothing less from their providers. Hundreds of thousands of physicians have already seen these benefits in their clinical practice.

On that I had commented:

Even though it is a "perspectives" article, I once long ago learned that in writing in esteemed scientific journals of worldwide impact, statements of certainty were at best avoided, or if made should be exceptionally well referenced. I note the lack of footnotes showing the source(s) of these statements.

The meme of technological determinism, that computerization in medicine is synonymous with, and will deterministically provide "improvements", no matter what the evidence, is quite concerning coming from a company as profoundly large and influential as Microsoft.

Further, the complete omission of consideration of the adverse clinical consequences (let alone mere information breaches) that may occur along the way to cybernetic utopia in healthcare is very disturbing. These are experimental medical devices, are unregulated, and are used without patient informed consent. Yet the IT industry seems to opine as if these systems are only to be used on experimental lab rats.

These systems produce "legible gibberish" of no clinical use to clinicians, but take clinician time to generate through distracting "clickorrhea." For example, just the placement of an IV and fluid infusion generates a half page of nonsense:


Actual "legible gibberish" from an ED EHR report, major health IT vendor. Half a page on how an IV was started and a saline infusion given. (How many distracting clinician mouse clicks did it take to produce this?) Click to enlarge.

Addendum 12/8/10 - From "Hidden Malpractice Dangers in EMRs", Steven I. Kern, Esq., Medscape.com:

Too Much Information

... Pages of repetitive documentation can be more time-consuming to review than brief, handwritten notes. When important information is embedded in paragraphs of boilerplate, it can easily be overlooked. The chance of missing critical data increases.

Overlooking important information is, of course, a significant cause of malpractice. A positive finding embedded in a string of negative findings can easily be missed.


Ironically, my relative was injured as a result of EHR-related disruption not long ago. Further, just the initial two and a half weeks of hospitalization generated more than 2,800 laser printed pages of "legible gibberish" (which cost just under $1000 to obtain; Kinko's should only have it so good).

A fellow physician I know well related:

From: [redacted name of MD]

Good Lord! I am so sorry to see this and hope your Mom gets better. You must be furious.

May I add to the cacophony? My wife went to [another local hospital's] ER for emergency transfusion. Their Emr displayed someone else's info under her name & SSN. Had I not been there she would have received incorrect treatment.

My wife went to [yet another hospital] for hip replacement. After surgery, while she slept off her anesthesia, a nurse came in and started injecting her. I asked and learned it was insulin. I stopped the nurse (with difficulty). My wife's not diabetic. Her screen showed someone else's orders. Had I not been there she might have died.

So keep up the good work... please!

[redacted name of MD]

How many other patients have been injured or killed as a result of EHR's?

In fact, we really don't know how many adverse events related to EHR's occur. As the Joint Commission itself admits in its Sentinel Events Alert #42, Safely implementing health information and converging technologies: "There is a dearth of data on the incidence of adverse events directly caused by HIT overall." I further wrote on this issue in a paper "A Dearth of Data on Unintended Consequences of Healthcare IT" here.

Is this a proper environment for national rollout of these clearly experimental medical devices, one should ask?

The memes of technological determinism and health IT "white-as-driven-snow" beneficence seem as difficult as vampires to eradicate.

Yet if this technology is to achieve the benefits of which it is capable via remediation of current IT industry customs, traditions and practices, these memes must be challenged and defeated.

Regarding health IT in the real world, reality matters.

-- SS

Friday, November 19, 2010

Insurers Test Data Profiles to Identify Risky Clients

Stories like this one today at the WSJ disturb me.

Insurers Test Data Profiles to Identify Risky Clients
Wall Street Journal
Nov. 19, 2010

From that story:

Life insurers are testing an intensely personal new use for the vast dossiers of data being amassed about Americans: predicting people’s longevity.

Insurers have long used blood and urine tests to assess people’s health—a costly process. Today, however, data-gathering companies have such extensive files on most U.S. consumers—online shopping details, catalog purchases, magazine subscriptions, leisure activities and information from social-networking sites—that some insurers are exploring whether data can reveal nearly as much about a person as a lab analysis of their bodily fluids.

In one of the biggest tests, the U.S. arm of British insurer Aviva PLC looked at 60,000 recent insurance applicants. It found that a new, “predictive modeling” system, based partly on consumer-marketing data, was “persuasive” in its ability to mimic traditional techniques.

The research heralds a remarkable [alarming? -ed.] expansion of the use of consumer-marketing data, which is traditionally used for advertising purposes.


Read the entire article.

The reason I find this article disturbing is that it can and probably should be looked at as another example of technophiles and opportunists with no knowledge of (or lack of caring about) Social Informatics, a decades-old discipline with a focus on studying the unintended consequences of new information and communications technologies (ICT's), enabling our society to move one step closer to centralized control.

Social Informatics (SI) refers to the body of research and study that examines social aspects of computerization, including the roles of information technology in social and organizational change, the uses of information technologies in social contexts, and the ways that the social organization of information technologies is influenced by social forces and social practices.

Stories such as the above WSJ story, and others in their running series on Internet privacy, also dampen my enthusiasm about the possibility that electronic medical information will be kept private, confidential and secure.

-- SS

Insurers Test Data Profiles to Identify Risky Clients

Stories like this one today at the WSJ disturb me.

Insurers Test Data Profiles to Identify Risky Clients
Wall Street Journal
Nov. 19, 2010

From that story:

Life insurers are testing an intensely personal new use for the vast dossiers of data being amassed about Americans: predicting people’s longevity.

Insurers have long used blood and urine tests to assess people’s health—a costly process. Today, however, data-gathering companies have such extensive files on most U.S. consumers—online shopping details, catalog purchases, magazine subscriptions, leisure activities and information from social-networking sites—that some insurers are exploring whether data can reveal nearly as much about a person as a lab analysis of their bodily fluids.

In one of the biggest tests, the U.S. arm of British insurer Aviva PLC looked at 60,000 recent insurance applicants. It found that a new, “predictive modeling” system, based partly on consumer-marketing data, was “persuasive” in its ability to mimic traditional techniques.

The research heralds a remarkable [alarming? -ed.] expansion of the use of consumer-marketing data, which is traditionally used for advertising purposes.


Read the entire article.

The reason I find this article disturbing is that it can and probably should be looked at as another example of technophiles and opportunists with no knowledge of (or lack of caring about) Social Informatics, a decades-old discipline with a focus on studying the unintended consequences of new information and communications technologies (ICT's), enabling our society to move one step closer to centralized control.

Social Informatics (SI) refers to the body of research and study that examines social aspects of computerization, including the roles of information technology in social and organizational change, the uses of information technologies in social contexts, and the ways that the social organization of information technologies is influenced by social forces and social practices.

Stories such as the above WSJ story, and others in their running series on Internet privacy, also dampen my enthusiasm about the possibility that electronic medical information will be kept private, confidential and secure.

-- SS

Thursday, October 21, 2010

Medical data breach of the week - but your EMR data is secure, trust us, we're IT experts

I have written frequently about the pipe dream of secure national electronic medical records, such as in February 2010 at my post "Networked EMR's and Healthcare Information Security: Practical When Massive IT Security Breaches Continue?", my post "Networked, Interoperable, Secure National Medical Records a Castle in the Sky?", as well as "Operation Aurora And a Widespread Reluctance to Discuss IT Flaws: Is Universal Healthcare IT Really a Good Idea in 2010?" and others.

I was also quoted on July 30, 2010, in a Philadelphia Inquirer story about the theft of a laptop computer with data on 21,000 patients from Thomas Jefferson University Hospital here, and also interviewed August 2 by local NPR station WHYY-91FM, where I stated:

"There is almost no excuse for unencrypted data to be sitting on any computer at a hospital or any organization," said Scot Silverstein, a Drexel University expert on health-information technology.

In the latest health-data-on-computer-theft-of-the-week, the Inquirer ran this story today about a local theft ten times as large as July's:

Medical-data breach said to be major
A computer flash drive containing the names, addresses, and personal health information of 280,000 people is missing - one of the largest recent security breaches of personal health data in the nation.

"We deeply regret this unfortunate incident," said Jay Feldstein, the president of the two affiliated Philadelphia companies, Keystone Mercy Health Plan and AmeriHealth Mercy Health Plan.

The breach, which involves the records of Medicaid recipients, is the first such Medicaid data breach in Pennsylvania since at least 1997, according to the state's Department of Welfare, which has oversight.

There is little more I can add to my prior postings on this issue except the words of privacy advocate, psychiatrist Dr. Deborah Peel:

The security failure, one of the several largest in nearly two years, involves nearly two-thirds of the insurers' subscribers. It became known only after The Inquirer requested information Tuesday evening. The insurers said the drive was missing from the corporate offices on Stevens Drive in Southwest Philadelphia. It noted that the same flash drive was used at community health fairs.

"That seems grossly irresponsible," said Dr. Deborah Peel, a Texas psychiatrist who heads Patient Privacy Rights, an advocacy group.

"Why would you be hauling around private patient information to a health fair," she said. "I can't imagine what they were thinking, taking this data out of a locked room at company headquarters.

"What's tragic is that this is a particularly vulnerable group of people," Peel said. "They tend to be vulnerable to identity theft, vulnerable to discrimination." Medicaid recipients are low-income people.


As to encryption (a built-in feature of the upper tier versions of Windows and of Mac OS X):

They [the companies] would not comment on the riskiness of taking the drive to health fairs, nor would they say whether the data on the drive was encrypted.

Highly likely translation: no.

The companies issued an apology:

"At Keystone Mercy Health Plan and AmeriHealth Mercy Health Plan, our number one priority is our members. Since reporting this unfortunate incident to the Department of Public Welfare, we have actively and responsibly executed a multifaceted plan to inform those affected, while also evaluating and enhancing our security measures to ensure this does not happen again."

[Did any employee have their "privileges revoked" -- the medical term of art for a physician who is 'fired' -- I wonder? - ed.]

Perhaps the executives in charge of this data, as well as the IT department, should read stories like the aforementioned July 30, 2010 story.

However, I fear there are those who are ineducable or hopelessly irresponsible when it comes to acting cautiously and responsibly regarding computer-based medical information, in the poorly bounded, complex, unpredictable world of healthcare.

That is not to even mention deliberate theft for personal gain.

This is why the dream of
secure national electronic medical records seems a pipe dream for the foreseeable future.

-- SS

10/23 Addendum

in an updated story, the Inquirer reports the data was indeed unencrypted, although the companies claimed an encryption project was in progress.

Medical data breach of the week - but your EMR data is secure, trust us, we're IT experts

I have written frequently about the pipe dream of secure national electronic medical records, such as in February 2010 at my post "Networked EMR's and Healthcare Information Security: Practical When Massive IT Security Breaches Continue?", my post "Networked, Interoperable, Secure National Medical Records a Castle in the Sky?", as well as "Operation Aurora And a Widespread Reluctance to Discuss IT Flaws: Is Universal Healthcare IT Really a Good Idea in 2010?" and others.

I was also quoted on July 30, 2010, in a Philadelphia Inquirer story about the theft of a laptop computer with data on 21,000 patients from Thomas Jefferson University Hospital here, and also interviewed August 2 by local NPR station WHYY-91FM, where I stated:

"There is almost no excuse for unencrypted data to be sitting on any computer at a hospital or any organization," said Scot Silverstein, a Drexel University expert on health-information technology.

In the latest health-data-on-computer-theft-of-the-week, the Inquirer ran this story today about a local theft ten times as large as July's:

Medical-data breach said to be major
A computer flash drive containing the names, addresses, and personal health information of 280,000 people is missing - one of the largest recent security breaches of personal health data in the nation.

"We deeply regret this unfortunate incident," said Jay Feldstein, the president of the two affiliated Philadelphia companies, Keystone Mercy Health Plan and AmeriHealth Mercy Health Plan.

The breach, which involves the records of Medicaid recipients, is the first such Medicaid data breach in Pennsylvania since at least 1997, according to the state's Department of Welfare, which has oversight.

There is little more I can add to my prior postings on this issue except the words of privacy advocate, psychiatrist Dr. Deborah Peel:

The security failure, one of the several largest in nearly two years, involves nearly two-thirds of the insurers' subscribers. It became known only after The Inquirer requested information Tuesday evening. The insurers said the drive was missing from the corporate offices on Stevens Drive in Southwest Philadelphia. It noted that the same flash drive was used at community health fairs.

"That seems grossly irresponsible," said Dr. Deborah Peel, a Texas psychiatrist who heads Patient Privacy Rights, an advocacy group.

"Why would you be hauling around private patient information to a health fair," she said. "I can't imagine what they were thinking, taking this data out of a locked room at company headquarters.

"What's tragic is that this is a particularly vulnerable group of people," Peel said. "They tend to be vulnerable to identity theft, vulnerable to discrimination." Medicaid recipients are low-income people.


As to encryption (a built-in feature of the upper tier versions of Windows and of Mac OS X):

They [the companies] would not comment on the riskiness of taking the drive to health fairs, nor would they say whether the data on the drive was encrypted.

Highly likely translation: no.

The companies issued an apology:

"At Keystone Mercy Health Plan and AmeriHealth Mercy Health Plan, our number one priority is our members. Since reporting this unfortunate incident to the Department of Public Welfare, we have actively and responsibly executed a multifaceted plan to inform those affected, while also evaluating and enhancing our security measures to ensure this does not happen again."

[Did any employee have their "privileges revoked" -- the medical term of art for a physician who is 'fired' -- I wonder? - ed.]

Perhaps the executives in charge of this data, as well as the IT department, should read stories like the aforementioned July 30, 2010 story.

However, I fear there are those who are ineducable or hopelessly irresponsible when it comes to acting cautiously and responsibly regarding computer-based medical information, in the poorly bounded, complex, unpredictable world of healthcare.

That is not to even mention deliberate theft for personal gain.

This is why the dream of
secure national electronic medical records seems a pipe dream for the foreseeable future.

-- SS

10/23 Addendum

in an updated story, the Inquirer reports the data was indeed unencrypted, although the companies claimed an encryption project was in progress.