With the implementation of the Affordable Care Act pushing hospitals and health systems to provide services more efficiently, a significant number of hospitals, health systems and providers are sharing secure patient information through health information exchanges (“HIEs”), and accountable care organizations (“ACOs”). The advent of both the HIEs and the ACOs are additional opportunities for protected health information to be shared by hospitals, doctors and other providers.
HIEs allow for patient information, including lab tests, imaging tests, prescriptions and treatments, to be shared by the participants in the HIE. The development of these electronic HIEs allow for the secure exchange of health information among entities participating in the HIE. Generally, the rights and responsibilities of those entitled to share the information is governed by participation agreements. Many providers believe that sharing data will improve healthcare and promote not only quality of care, but efficient care, as well. Similarly, the development of ACOs by otherwise independent providers results in more patient information shared in electronic fashion. The advent of both HIEs and ACOs provide another medium for possible breaches of the privacy rule.
The privacy rule requires that covered entities verify the identity and authority of persons requesting Protected Health Information (“PHI”) if the individual requesting it is not known to the entity. The Rule, however, does not specify in great detail the verification that must be made and, thus, there is flexibility that can be applied with regard to HIEs and ACOs.
Generally, in a HIE, the participants agree, by contract or otherwise, to provide to the HIE a list of authorized persons so the HIE can appropriately authenticate users of the network. Documentation required for uses and disclosures may be provided in electronic form, and documentation requiring signatures may be provided as scanned images. It is important from an HIE perspective for the various participants to agree on a common set of privacy safeguards that are appropriate to the risk associated with exchanging PHI to and through the HIE. Similarly, with ACOs, the ACO should establish a common set of privacy safeguards that are appropriate to the privacy risks associated with multiple providers using PHI. These common standards would include a breach notification policy or procedure. To fully understand what must be done, one must have a basic understanding of what is considered a breach.
Today’s healthcare IT departments have a relatively tall order when it comes to effective EHR data management. In an environment that often requires them to be simultaneously budget-conscious, growth-minded and patient-driven, healthcare IT must also address the often-competing data management needs for:
Access
Instant
Secure
Anytime, anywhere
Availability
Security
Data sharing
Data at rest
Privacy
Compliance
HIPAA
PPACA
CFR
Data protection
Backups
Operational recovery
Disaster recovery
Capacity planning
Archival
Growth
Data mining and analytics
Popular EHR system vendors have made significant strides to address several of these data management issues. Unfortunately, they can only go so far given the current state of many healthcare IT environments. Some departments may still require custom software applications, complete with specially configured servers, storage and network hardware to support them.
Guest post by Michael Sherling, MD, MBA, co-founder and chief medical officer, Modernizing Medicine.
At most hospitals and academic medical centers, physicians come together once a month to learn new approaches to treatment, to exchange ideas and to debate the possibilities of a challenging diagnosis. We call this Grand Rounds.
Grand Rounds keeps physicians up to date and helps patients too. Instead of relying on one doctor’s opinion, patients get a collective experience of several doctors. Through open debate, a more thoughtful approach to disease treatment is generated. Unfortunately, 80 percent of physicians do not practice in a hospital or academic medical center where Grand Rounds happen.[1] They practice in private practice. While there are opportunities for physicians in private practice to maintain continuing medical education through journals, online courses and annual meetings, most of these practitioners are on their own, so to speak.
When physicians in private practice see a challenging case, they can read about it in a medical textbook, phone a friend (another specialist) or refer the patient to another physician. They don’t have the luxury of calling a “time out” and presenting the case to five other physicians. Pressured by time constraints of increased documentation and decreasing reimbursement, many doctors opt to refer out the more challenging cases, or shy away from newer treatments simply because they don’t have the same access or shared experiences as doctors practicing in hospitals and academic medical centers.
Today, innovative cloud-based electronic health record (EHR) systems can present an opportunity to break down the barriers in private practice so that physicians can make more informed decisions at the point of care. Cloud-based systems rely on one instance of the software where all de-identified medical data is stored. These systems are HIPAA compliant and patient information is protected and secured. Yet, to advance medicine and improve healthcare outcomes for patients and physicians alike, the cloud-based systems can provide physicians access to de-identified patient data. Instead of relying on underpowered clinical control trials for common diseases, outdated studies for rare diseases and anecdotal evidence for orphan diseases, cloud based systems can reveal to physicians which treatment patterns are used for any given disease.
When Edward Snowden shed light on the National Security Administration’s surveillance programs, Americans were left asking many questions. Questions ranging from “How can the government do this?” to “What information are they gathering?” became conversation topics for many Americans. In the healthcare world, these revelations have made both patients and healthcare providers concerned over how secure information is in the hands of third-party vendors. These vendors, which providers rely on for many things, are being scrutinized for their attention to detail, data storage and potential for breach.
The impact Snowden’s whistleblowing has had on healthcare providers and third-party vendors across America is far reaching. People are closely examining privacy policies now, whereas signing privacy forms at a doctor’s office used to be just an afterthought. It has forced businesses that rely on American third-party vendors to ask if their data is being protected, and at what level. The NSA surveillance program brought awareness to the word privacy and the actions and steps that are, or aren’t, taken by providers and their vendors to keep information protected.
Healthcare providers cannot afford to take security and privacy for granted and assume that their patients’ information is being adequately protected. Patients will hold their healthcare providers accountable if there is a breach. Therefore, to truly ensure data is protected, it is the job of providers to ask vendors the appropriate questions to ensure that the proper security and privacy policies are in place to lessen the risk of a security breach. And beyond asking tough questions, the emphasis on proper due diligence to vet accurate answers and understand processes has never been greater. There are two key focus areas: security and privacy. It is important to remember that you can have security without privacy, but you cannot have privacy without security. In a world where our information can and has been looked at by our government, making information both private and secure is vitally important. Finding a third-party vendor that ensures the information is private and secure has to be a top priority.
Guest post by Michelle Blackmer, director of marketing, Healthcare, Informatica.
The volume of protected health information (PHI) in electronic form is exploding – both from the wholesale move from paper charts to electronic health records for capturing clinical data and with the proliferation of new sources of electronic data from networked medical devices. Additionally, IT staff have been overwhelmed by regulatory mandates, rampant technology changes (e.g., virtualization, BYOD, big data), massive application projects and flat or decreasing budgets.
This increase in electronic PHI combined with the challenges for health systems IT make it even more important for providers and non-providers to find efficient ways to secure their data. However, with malicious activity showing a consistent upward trend, absent a change to an almost maniacal leadership focus on protecting patient data and the deployment of available tools and processes as an organizational imperative, 2014 will bring even more frequent and larger breaches of PHI.
Current data security climate
Even still, many healthcare organizations are not taking the necessary steps to reduce the proliferation of unprotected PHI in non-production test and development environments. Ninety-four percent of respondents to the third annual Ponemon Institute Benchmark Survey on Patient Privacy and Data Security had at least one data breach in the past two years, and 45 percent reported having had more than five total incidents each. Even more surprising is that the leading cause for a breach is a lost or stolen computing device that houses PHI. The survey also found that:
Unrestricted database administrator (DBA) access heightens risk: 73 percent of DBAs can view all data.
Data compromise/theft remains rampant: 50 percent of respondents say data has been compromised or stolen by a malicious insider such as a privileged user.
Organizations are under-coping:68 percent have difficulty restricting user access to sensitive data, 66 percent have difficulty complying with privacy/data protection regulations and 55 percent lack confidence that they would even detect data theft/loss from their own production environments.
Guest post by Barbara Casey, Senior Executive Director for Healthcare Business Transformation at Cisco.
Imagine taking your car in for a routine service, only to be told you’ll need to visit five or six more garages on your own to procure an accurate assessment and treatment of the problem(s). In our current healthcare climate, this disconnected and complicated process is what most patients experience in assessing and treating their health conditions. Many of the most compromised patients, those that are elderly, co-morbid or chronically ill, are alone in their experience, left to connect the dots from cardiologist to radiologist to primary care. Layer in the emotional experience of, for example, being told you have stage four cancer and it’s difficult to focus on, let aloneremember, what the oncologist or surgeon says to do next. Yet, the onus falls solely on the patient, family member or caregiver to create continuity in the care experience.
So, as healthcare professionals, how do we help patients navigate the continuum of care when they are seeing an array of physicians and specialists in currently disconnected care settings? We need to treat the patient more like a true customer, which means upgrading the tools and methods we use to interact with them to be more intuitive and user-friendly so we touch base with them on a more regular basis.
Take for example the retail industry—Amazon and Netflix invest in complex algorithms to understand us better as individuals. As online businesses, they have enough information to recommend the next Father’s Day gift or determine if we prefer science fiction to drama. Can we apply that same logic to healthcare? Wouldn’t you want your own doctor and healthcare network to know you as well as Amazon does—for example, the medications you take, what you’re allergic to and the surgeries you’ve had—so they can recommend what you need to do next to advance your health and wellbeing?
It’s our obligation as technology experts and partners to those in the healthcare industry to find the answers and provide patients guidance in what they need before they need it. So in the end, patients can make the choice about how to approach their health can make the choice. After all, where else would you want to be known more intimately as an individual than in your own healthcare network?
mHealth, video and collaboration tools offer an opportunity to create a true continuum of care and a more seamless patient experience. Communication tools which integrate voice, video and data can also help deliver healthcare more effectively and efficiently. If these mechanisms are in place, the patient is more in control of where, when and how to communicate with care providers. She has the choice of how she wants to connect and communicate with her caregiver—the only question is will it be live in a doctor’s office, via video from her home living room, from a desk chair at the office, or from the path where she’s fulfilling a lifelong goal to hike the Appalachian Trail?
Guest post by Shameem C. Hameed, founder of ZH Healthcare.
The past five years have seen monumental changes in the world of healthcare information technology. As 2013 comes to a close, it seems appropriate to look forward to the developing trends for 2014 and beyond and how they will impact vendors, providers and patients.
Open Source Technology Use and Development Will Accelerate
The continuing acceptance and use of open source software is the most important healthcare trend, since it ties directly into every point on this list. Open source software has become part of the healthcare mainstream and is used in many areas of the healthcare industry. Open source software is behind everything from the EHR system doctors use to enter patient data to the web browser or smartphones and tablets patients use to check their records through patient portals. Even the much talked about Healthcare.gov website utilizes open source software.
The benefits of open source development over proprietary software will continue to fuel its expansion over the next few years. Open source software has many advantages for providers and patients, including interoperability, speed of problem resolution, flexibility and more frequent updates.
An example of how open source software provides these benefits can be found in the area of EHR systems. One of the most common complaints by physicians and staff about EHR software is that the software is difficult to use. Now that EHR adoption has become widespread, there is much more thought and resources going into refining the user interface. With proprietary software, the amount of developer resources that can put into refinements may be limited to that one vendor’s resources. With open source software, countless companies and individuals are constantly collaborating to make the software easier to operate and more user-friendly for everyone.
As we head into the new year, I’d like to thank you for helping me grow Electronic Heath Reporter through your readership, comments, dedication and support.
I also ask that you continue to join me in 2014 to assist me with what I enjoy doing most—providing news, insight, editorial and opinion to those in health technology. You inspire and encourage me to keep bringing you the latest developments.
I look forward to what next year will bring and how, with your continued support, the site will grow and expand. Hopefully this year I’ll get a chance to meet with you – I’ll be at HIMSS — and work with more of you to deliver engaging content.
If I have not had the chance to be introduced to you, please feel free to contact me with your questions, comments or suggestions you may have. I’m always open and ready to hear from you — day or night, and I encourage you to reach out.
On a final note, I’d like to thank SpiceWorks for advertising on the site this year. The organization has been great to work with and I am extremely grateful to them for taking a chance on this site. I encourage readers of this site to check them out at http://www.spiceworks.com/. They really are where IT goes to work!
That said, I wish you and your family a happy holiday season and a Merry Christmas, as well as a healthy, successful and eventful new year.