Recently, the president of the National Association for Home Care & Hospice (NAHC) called on all American’s to commemorate National Home Care & Hospice Month. He also stated that in the coming years, home health care is poised to play a central role in the delivery of healthcare throughout the country. Yet, the growing home health market is not without challenges. Solutions that blend innovation and mobility at the point of care can help pave the way for strong patient-caregiver interactions and support positive outcomes.
Home Health Poses Challenges: Mobile Solutions Can Improve Care Delivery
An aging population and tough new compliance and regulatory issues are posing challenges for the home healthcare segment. The unique and specific needs of the home healthcare market must play a paramount role in organizations seeking to develop mobile solutions to address these issues. Home caregivers urgently need “smart” solutions that address not only patient privacy, but also, wireless connectivity, mobile printing, security and remote data access.
There are a number of issues and trends impacting the healthcare industry that solution providers and caregivers need to keep top-of-mind:
Reimbursements/Re-admissions – Medicare reimbursement reductions and new penalties are being imposed on hospitals with high avoidable re-admissions. This increases the pressure on home health agencies to leverage technology to aid patients in following aftercare instructions, adhering to medication plans and accessing their medical information – all to better prevent costly re-admissions from occurring.
CIOs in healthcare face the constant challenge of doing more with less. Most are being asked to dramatically cut costs while continually tackling an ambitious list of responsibilities, including maintaining their organizations’ ability to demonstrate meaningful use, making the transition to ICD-10, sharing information through healthcare information exchanges (HIEs) and maintaining stringent patient privacy and HIPAA compliance programs.
Three key and often overlooked elements can help to address these tasks: document scanning, clinical language understanding and integration standards. Mastery of this electronic health record (EHR) trifecta can significantly simplify the healthcare CIO’s challenge.
Electronic health record adoption levels are steadily increasing, but ongoing interoperability issues result in high volumes of paper-based communications between providers. In fact, a survey conducted by the Bipartisan Policy Center in Washington, D.C., found that 71 percent of physicians identified lack of EHR interoperability and exchange infrastructure as major barriers to HIE.
David Finn, health information technology officer for Symantec, discusses healthcare technology security, HIPAA and meaningful use and the most pervasive security issues health IT faces in the months and years ahead.
What issues do healthcare leaders face from a security perspective?
Well, that is part of the problem right there. Healthcare leaders are inundated with new requirements and market changes. So, there is Meaningful Use, ICD-10, ACO, HIE, new privacy and security requirements – – all in a relatively short time frame – – to name a few. On top of that, you are likely doing that with decreasing reimbursement, a difficult labor market and limited capital budgets. Security, while mandated, frequently falls to the bottom of the list because it doesn’t directly impact care or add to the bottom line. That is a short-sighted view of security. Security needs to be strategic to the business of healthcare, not just IT.
Why? What can they do about this?
Much of this has been driven by HITECH and the Affordable Care Act. So, there are regulatory components and that, in turn, has driven many changes in the healthcare market. Providers now have to do a lot of these things just to keep their heads above water – – not to mention the statutory requirements. The most important thing is to get started … you may not be able to do everything all at once. You do have to understand what needs to get done and then prioritize those things for your organization and get started.
How are HIPAA changes affecting care, coordination, tech implementation and the ability of physicians to do their jobs?
HIPAA has been around a long time and, frankly, if the industry had dealt with these things effectively starting back in 2003, which was the compliance date for the Privacy Rule and then 2005 when the Security Rule became the law, we’d be in much better shape today. Unfortunately, the incentives and drivers were not aligned to make that happen. Don’t get me wrong, a lot of things got started and don’t forget technology is very different than it was 10 years ago – – mobility, virtualization, cloud. We also have a much larger installed-base of EHRs across the entire continuum of care. So, now we have tools that really can aid the physicians and other clinicians in getting things done faster, wherever they are, at their convenience, but we’ve lagged in a lot of the security issues around those new technology tools. And, unfortunately, often systems are put in without proper attention to workflow or process improvement. Organizations that hurried to get some of these things in are now going back to “fix” them.
How is/will meaningful use impact healthcare? Are there security issues?
While the debate is still raging, few would argue that better access to information for providers and patients is a good thing. Meaningful use – capturing and using the right clinical data – over time, will improve the quality of care and outcomes and should reduce costs. It will not happen overnight. Yes, when you have confidential, legally protected information, you have security issues.
How has the push toward EHRs changed the security of healthcare? In what ways?
As healthcare has digitized, it has increasingly become a target for the “bad guys.” We not only keep names, addresses and dates of birth all together to make it easier to care for and bill patients, we also include social security numbers, credit cards and insurance accounts. And every time you share that information (between providers, with an HIE, a drugstore, registries, schools and more) you create another potential point for that data to go astray or someone to maliciously take the information. In the “paper days” a doctor might take home a dozen charts to review; today a jump drive can contain hundreds of thousands of patient records. When all the charts could be locked in a room at night at least you knew where most of them were and they were safe. Information now lives on networks – – in databases, in Word documents, spreadsheets. It can get cut and pasted from an EHR screen into an email and sent anywhere. While many of the issues are the same, the scope and scale of the problem is sometimes hard to imagine. It was horrible for those dozen patients if the doctor’s car was broken into and charts taken, but when you have breaches of hundreds of thousands or even millions of patient records, it can be very difficult to manage and address. And this doesn’t even begin to address the cost issue around a data breach.
In relation to security, what are some of the most pervasive issues physicians face? What are they more surprised by?
Well, mobility is here to stay and yet most organizations don’t even have policies around mobile devices. Social media is a growing concern, whether you are a large healthcare system or a single-physician practice. The underlying problem is not knowing where that patient data is. Nearly everyone is surprised when you start to show them how that information comes into your organization or practice, where it goes and who uses it and how it may leave the organization. There are tools to help you find, manage and track the data, but most people are still focused on the EMR, the PCs that clinicians use. The issue is the data and the problem is the data is everywhere.
What are some of the most overlooked security protocols?
First, is encryption. If you are focused on the data, the best thing to do is encrypt it. That said, encryption is not a panacea and just encrypting everything is not a good answer. Things like laptops, tablets, smart phones, backup tapes, jump drives – – those really need to be encrypted. The other thing is understanding your data and there are tools, like Data Loss Prevention tools, that help you find the data;who created it, how it is being used and so on. If you don’t understand the data, you can’t really protect it appropriately.
Is the health IT market overly paranoid when it comes to security and breeches?
Based on the number of records breached since 2009 — 20+ million — I’d say the IT market needs to do something. Being paranoid about breaches is one thing, actually managing your data and mitigating potential breaches is another. It is time for the industry to take the issues of privacy and security seriously, assess the problem, develop a plan, get the money and start fixing it. Healthcare has to realize this isn’t a technology issue – – this is an enterprise issue and it starts with your people.
How will health IT security change in the months or year ahead? What trends can we expect? What’s irrelevant? What’s not?
I think you will see privacy and security being addressed as part of a system implementation or a process improvement initiative instead of something you try to do after the fact. If you do it afterwards, the security is never is good and always costs more. You’ll see more training and policies that address mobility, social media. I think as enforcement picks up and fines increase, healthcare will recognize that this not just a technology problem. I think you’ll see a lot more training and awareness around privacy and security. More investment in tools that monitor data and in that sense are monitoring workforce behavior around patient data – – regardless if it is on email, the EHR, web sites – – it is still the patient’s data. You’ll also see more focus on identities and authentication, it is likely coming in future regulations, but the other part of protecting the data is making sure only the right people get it.
Here is what is irrelevant: 1) Policies that are not enforced or cannot be enforced; 2) Enforcing policy and procedure inconsistently; 3) Thinking this is an IT or security problem when it is an enterprise wide, cultural issue.
Anything else you’d like to mention that I haven’t asked?
First, I think now that we have all these EHRs up and running and are collecting all this data digitally, the industry is just figuring out how to use it to drive improvement. So, big data, analytics, informatics – whatever you want to call it – will be a huge driver. Big data comes with some unique security and data management issues.
The next tidal wave in health information technology that we are not doing a good job addressing, yet, is the medical devices. These are often patient-touching devices ranging from anesthesia machines to smart-pumps, which may deliver controlled substances or chemotherapy to pacemakers. More care is being driven to the home and remote home-care is a growing area. Yet, these devices tend to run old operating systems, can’t take the newer protective software, yet they are on hospital networks, connect to the Internet and are unmanaged in terms of information technology. Many of them store and transmit patient data and the issue just isn’t getting the focus it needs.
David Finn, CISA, CISM, CRISC is the Health Information Technology Officer for Symantec. Prior to that role he was the Chief Information Officer and Vice President of Information Services for Texas Children’s Hospital, one of the largest pediatric integrated delivery systems in the United States. He also served as the Privacy and Security Officer for Texas Children’s. Prior to that Finn spent seven years as a healthcare consultant with IMG/Healthlink and PwC. Serving last as the EVP of Operations for Healthlink.
Texas Children’s Hospital won the ECRI Institute 2007 Health Devices Achievement Award, and because of Finn’s departmental support, TCH also was awarded recognition for Employee Support of the Guard and Reserve. Finn also received the Symantec Visionary Award in 2008 for Security. He has presented nationally and internationally on such topics as project management, professional leadership and staff development, and privacy and security. He has contributed to or written articles on IT Management, Disaster Recovery and Security for such as journals as CIO Digest and Baseline.
Along with HIMSS’ largest money maker of the year — its annual conference — it’s also time for the results of its annual leadership survey.
While the results, which are reflected in the infographic below, are certainly interesting there is one point that seems to raise a flag immediately.
Prior to that, however, let’s take a quick look at the results. Accordingly, about 66 percent of the all health IT leaders say their organization qualified for meaningful use Stage 1 and 75 percent of the same folks expect to qualify for Stage 2. Additionally, nearly 90 percent of those who took the survey say they be ready for the ICD-10 switch later this year.
As such, there’s quite a need to hire new IT folks to carry the torch.
Next, it appears that nearly 20 percent of respondents said their health systems’ security was breech (at least those who admitted as much) and that 22 percent of said security was a priority for the coming year, which should be the case if 20 percent of them faced a security issue.
I understand the scope of the survey and who its respondents are, but doesn’t it strike anyone else as slightly odd that all of the changes to come are related to the IT? All, or much, of the reform is designed to engage patients and bring them closer to their care providers? Shouldn’t it be implemented to help improve outcomes and to drive better results and make the system more fluid? I guess IT is going to be what get’s us there. But along the way, couldn’t more be done at the care level as well as the IT level? Could some of the hiring take place to serve patients rather than the practice?
I digress. Apparently, for now, we’ll have to be thankful that all of this change is leading to improved job growth and fixes to the breeches that await us.