I'd like to invite and encourage all clinicians to register for the openEHR Foundation's new Clinical Knowledge Manager (CKM) - found online at www.openehr.org/knowledge.
CKM is an international repository for openEHR archetypes and has two primary purposes - that of archetype publication and archetype governance. It is a real opportunity for clinicians to collaborate and agree on clinical content definitions for publication and use in our electronic health records.
openEHR archetypes are open source, computable specifications that define clinical information about a single and discrete clinical concept. For example there are separate archetypes defining a 'symptom', 'diagnosis', 'blood pressure', 'medication order', and 'risk of disease based on family history'.
As structured and standardised definitions of clinical content, archetypes are increasingly being recognised as fundamental building blocks of electronic health records, especially when integrated with clinical terminologies such as SNOMED CT. If we all start to record information based on the same archetype, then we can meaningfully and unambiguously share health information between systems, and we start to query that information across systems.
A primary goal of CKM is to encourage a broad range of clinician input to make sure that the clinical content in each archetype is correct. Absolutely no openEHR experience is necessary to participate in CKM, although we anticipate you will learn about openEHR as part of the journey. All participation is purely on a volunteer basis, and you can opt out at any point.
Whilst CKM is still in its relatively early days, we are already seeing the benefits that contributions by grassroots clinicians are bringing to the archetypes currently undergoing team review. Technically oriented openEHR experts support the review process to provide guidance on design and implementation issues, so there are no unrealistic expectations of the clinicians. Contributions of clinical and technical nature are equally and gratefully received;-)
By design, each archetype contains all the relevant information about the specific clinical concept - a maximal dataset which can be used in all clinical scenarios. So, for each archetype we are seeking a range of views from a variety of:
- professions - including every type of clinicial expert;
- geographical locations - to make sure we can capture diverse clinical and cultural practice; and
- knowledge domains - from general healthcare to all specialist areas.
Please actively 'adopt' the archetypes that you would like to be involved in. This will ensure that you will be invited to participate in the review of archetypes that are of interest to you. At other times you may also be invited to participate in a review where we consider that your expertise might provide balance out the current team of reviewers.
While we will strive to achieve maximal datasets for each archetype, we are pragmatic and know that we won't get it 100% right - certainly not at first try. However, I suggest that a small group of 3-4 clinicians with complementary skills and appropriate expertise can create and develop a draft archetype to approximately 80-85% complete. Further review within CKM by a team of clinicians from a range of professions, countries, institutions, research, and health domains will contribute and refine the archetype further - maybe this still will only get it to 90% complete; but maybe much more. Our experience to date shows that maximal datasets are much easier to agree on than minimal datasets!!
Over time it will be interesting to see how the models evolve - no doubt a good research topic!
Obtaining agreement on clinical content within archetypes in this manner is a significant achievement, even if in retrospect we find they are not 100% complete at the start. The flow-on benefits that come from sharing a standardised set of clinical specifications for EHRs can potentially transform some eHealth initiatives and is a necessary foundation for the truly sharable electronic health record.
So, all clinicians are welcome to get involved in CKM - we will certainly set you to work very quickly! We expect that by contributing domain expertise and insights, clinicians will also benefit personally by gradually developing openEHR understanding and expertise as part of the experience.
And then of course, there is also the contribution to the good of mankind... ;-)
[Instructions for registering can be found at: www.openehr.org/wiki/display/healthmod/Registration+in+CKM]
Full story...
Monday, April 6, 2009
Guest Blog: Collective Clinical Wisdom by Heather Leslie
Posted by
Jaz
at
12:20 PM
2
comments
Labels:
guest blog,
health information exchange,
standards
Social: DiggIt!
Del.icio.us
Technorati
Tuesday, March 3, 2009
Medical Data Privacy: Consumers v Hackers
I just left the following as a comment over at THCB, but after I got done ranting it seemed like a mouthful so I'm reposting it here.
I enjoy the position of being involved in HIT, clinical and claims data, *and* being one of the afore-mentioned hackers. Please distinguish hacker from malicious hacker or "cracker". The term "hacker" has no negative connotation in the community.
That said, I'd like to promise you all this:
When we're done, your health information will be as private and secure as your credit card information.
It will flow across secured networks using portions of the public Internet. It will be covered by copious security policies, all well-intentioned, and few implemented fully.
It will be accessible to you, the patient, electronically. A vague audit trail will also be available.
People who have access to this data - doctors, nurses, covered entities, HMOs, government workers, will store it on their laptops. Their thumb drives. Some will have identifiable data. Some will have deidentified. Some will have patient-level data, some will have aggregated.
Some of them will have their laptop stolen, forget it at the airport, lose their thumb drive. Some will just take it because they can sell it to some guy in Romania.
Third parties will make decisions about you based on your unique profile. Some of these decision will help you, such as reminding you to go get that mammogram. Some will hurt you, because you, like me, have not yet fully quit smoking.
All the above is going to happen. You have no say in it. It's begun, it's overdue, and it will be as imperfect a system as the current one, but with more detailed history of its imperfections.
It will surface new ways to practice medicine, and many of them will be for the collective good. It will surface new ways to lower cost, and many of them will be for the collective good.
You will be as secure in the safety of your medical data as you currently are with your credit data. You all punch your PIN in to the supermarket checkout machine while 15 people watch you. Right?
The government does not have your credit history any more than I have your credit history. The government may have your health score, the same way it can access your credit score. Or your landlord, or your employer, or your private detective.
You will have no more and no less security than with any other confidential information you currently manage, such as your Web site password for your online broker or your online checking account, the credit card bill you throw away unshredded, your mother's maiden name.
I don't hear any of you cutting up your credit cards.
I am not a doctor, a health provider, nor a policy maker. I am merely a tech-savvy consumer who happens to build health report cards using what little data is available to me. If nothing else, I look forward to the day I can actively score the use of evidence based medicine using clinical data delivered deidentified. That and I'd like to know what my last test result were, even if they were a couple years ago.
This is a non-conversation, and allowing the world and their mother to have a say in the indisputably inevitable is merely costing more money and wasting more time. HIPAA already covers who can see what when; properly implemented using standards-based EHR software is already happening, and will continue to happen.
The sooner we build it, the sooner we can start making it better day by day.
Full story...
Posted by
Jaz
at
11:54 AM
2
comments
Labels:
commentary,
health information exchange,
standards
Social: DiggIt!
Del.icio.us
Technorati
Monday, October 6, 2008
Interoperability, EU Style
Seriously, is anyone in the US paying attention?
Twelve countries. Three years. Internationally-accessible personal health records. Wow.
Full story...
Posted by
Jaz
at
1:22 PM
3
comments
Labels:
health information exchange
Social: DiggIt!
Del.icio.us
Technorati
Tuesday, September 30, 2008
Getting There...
An information exchange of a thousand patients begins with a single discharge.
The Nationwide Health Information Network, basically a separate Internet of health care organisations and systems, underwent it's first real test last week. Among other achievements, we saw the creation of a fabulous new acronym: DURSA. Stands for Data Usage and Reciprocal Support Agreement.
In the test, 19 organisations demonstrated the ability to access and retrieve patient level data, albeit fictitious patients, from NHIN partners, which include DoD, the VA, and SSA.
A live test with real data is scheduled for December, but ten years from now, we'll be looking back at this test as the first successful day we exchanged data, I think this is truly the the beginning of the end of the beginning. We're nearly there. I can smell it.
I've been attending the AHIC meetings remotely, but couldn't make it to this one due to my being Nyquil'ed up to the gills for a week, but you can read more about this truly momentous occasion at GovHealthIT, HIT News, and for bonus points here's an article on the national EHR in the UK, which has finally grown a pair and decided that patients who don't want to be included on the national system need to opt out of the program.
Full story...
Posted by
Jaz
at
11:03 AM
0
comments
Labels:
health information exchange
Social: DiggIt!
Del.icio.us
Technorati
Thursday, September 18, 2008
Too Many Chefs
Colour me cynical, but after reading this article from Gov Health IT by Nancy Ferris, covering eHI's annual survey of Health Information Exchanges, I can't help but hang my head in despair.
I quote:Although the number of HIEs reporting this year held steady at 130, the number that are actually exchanging data grew by 31 percent, from 32 to 42. Eighteen of the 130 HIEs are new to this year’s survey, indicating that interest in using health IT continues to increase, said Janet Marchibroda, chief executive officer of the eHealth Initiative.
On the surface, seems like good news, right?
But wait a minute.
One hundred and thirty HIEs?
130.
Nearly a gross.
Do we *really* need 130 HIEs to cover 50 states?
Unless I'm mistaken, we have four major credit cards, and three credit bureaus. Covering roughly the same amount of transactions for the same amount of people. In real time.
130?
Really?
Full story...
Posted by
Jaz
at
1:42 PM
4
comments
Labels:
commentary,
health information exchange
Social: DiggIt!
Del.icio.us
Technorati
Thursday, September 4, 2008
More Chartered Value Exchanges
Eleven more communities will join the fourteen already designated by Leavitt as Chartered Value Exchanges - collaborations focused on improving care and transparency.
The new Chartered Value Exchanges are:
* Aligning Forces for Quality, based in York, Pa.;
* the California Chartered Value Exchange, in San Francisco;
* the Colorado Chartered Value Exchange in Denver;
* eHealth Connecticut, Inc., of Middletown, Conn.;
* the Greater Louisville Value Exchange Partnership in Louisville, Ky. ;
* the Health Improvement Collaborative of Greater Cincinnati and HealthBridge, in Cincinnati, Ohio;
* the Kansas City Quality Improvement Consortium, in Kansas City, Mo. ;
* Michigan Health Information Alliance, in Mt. Pleasant, Mich.;
* the Nevada Partnership for Value-driven Health Care, in Las Vegas,;
* the Quality Health First program, managed by the Indiana Health Information Exchange of Indianapolis, Ind.;
* and the Virginia Health Care Alliance of Glen Allen, Va.
Full story...
Posted by
Jaz
at
3:34 PM
0
comments
Labels:
health information exchange,
public reporting
Social: DiggIt!
Del.icio.us
Technorati
Wednesday, February 6, 2008
PHI Spy, With My Other Eye...
Oddly enough, if it's not bad enough that the Chinese want to know what's wrong with you, GHIT is reporting that Wisconsin, that bastion of transparency and public reporting, is now pushing for changes to health privacy laws that would enable the sharing of patients' information such as their names, diagnoses, medications, even mental health providers, without the patient's consent!
This underscores two things that I happen to rail on a lot.
1. We need accountability and audit trails built in to any RHIO or health information exchange from the get go.
We can easily pull a credit report and find out who's accessed our credit data, we need the exact same mechanism for our health data. It's not rocket science, we already do this. Just keep on doing it for our health info.
2. We want to share our data, we really do, but only with the right people and only with our permission. Just ask us first.
Everyone already signs a HIPAA consent form when they see a doctor for the first time, just add a paragraph. Do not opt us in! We're smart people, we're allowed to drink and vote and buy guns and drive - albeit not at the same time - but for heaven's sake just ask us.
Health care providers, nay the industry as a whole, can sometimes appear to be incredibly paternalistic. I really think that's half the problem with this whole push to EHRs.
WE KNOW WHAT'S GOOD FOR US. WAKE UP AND SMELL THE INFORMED CONSUMER.
Sorry for shouting.
PS: Bonus question... what do you think is the likelihood that your medical record is currently copied somewhere in India? Hint: very bloody likely.
India is the number one destination for medical records, medical transcription and a host more medical services including case review and appeals. It's 10pm, do you know where your personal health information is?
Full story...
Posted by
Jaz
at
1:03 PM
2
comments
Labels:
commentary,
health information exchange
Social: DiggIt!
Del.icio.us
Technorati
Thursday, January 24, 2008
Google Health Inching Closer to Reality?
Just when you thought Google couldn't know anything more about you...
It's not live yet, not even closed beta, but if you look ever so closely there's a login page for Google Health.
My Google account doesn't do anything, the login doesn't work, but the page promise that you will be able to:
* Build online health profiles that belong to you
* Download medical records from doctors and pharmacies
* Get personalized health guidance and relevant news
* Find qualified doctors and connect to time-saving services
* Share selected information with family or caregivers
The service should be up sometime this year, but a few screenshots have surfaced:
More here
Full story...
Posted by
Jaz
at
5:01 PM
1 comments
Labels:
commentary,
health information exchange
Social: DiggIt!
Del.icio.us
Technorati
Friday, December 28, 2007
Guest Blog: Open Source and Primary Care in the US by Timothy Cook
Tim Cook, a vocal proponent and leader of open source in the health care IT space and owner of possibly the most impressive list of achievements in the FOSS-meets-HIT space, managed to stumble across a post I made a while back about the National Health Information Network. Even though he was apparently having a much more interesting Christmas than I was, he took the time to drop me a note which led to the guest blog below. Thanks Tim!
Back in March 2007 Jaz-Michael King posted about open sourcing the National Health Information Network (NHIN). There are success stories regarding using open source as part of some trials being done with NHIN record locating such as the Mendocino HRE as well as others.
But, as Jaz pointed out in December 2007, Regional Health Information Organizations (RHIOs) are struggling more because of lack of "Information" as opposed to lack of funding. If they could get the information into the systems then the funding would take care of itself.
So the root problem lies in; why can't we collect the information? Virtually all primary care clinics have computerized billing systems. The problem is that billing information is not rich enough to really provide the content and context needed for longitudinal patient care.
The real solution is capturing information electronically at the point of care. That information can then be used for many purposes including driving the billing systems and decision support.
The reasons that US primary care clinics have not adopted electronic health/medical record applications is because of the economics of doing so. Just the licensing of these applications can run into the tens of thousands of dollars. There are several open source alternatives that carry no license fees. However, the real costs of implementation of these systems include so much more than just licensing. Books such as "Computerization and Going Paperless in Canadian Primary Care" (ISBN-13:978-1857756234) detail these processes and expenses. It can easily take up to 24 months to transition from paper to electronic medical records. This is expensive in terms of not only training but in temporary reduced efficiency.
But, even if a clinic forges ahead with an implementation and they are successfully converting from paper to electronic; who gains? In a 2004 View Point paper by the American College of Medical Informatics (J Am Med Inform Assoc. 2005;12:13–19. DOI 10.1197/jamia.M1669.) they identified some primary reasons for the failure of the health information technology market in the US. Two major ones are:
1) Misaligned incentives. Simply, the people being expected to pay for EHR systems are the ones gaining the smallest percentage of pay back. payors and employers have by far the most incentive to see EHRs implemented.
2) Lack of true interoperability standards. In order for payors and employers to gain their maximum benefits, the systems must be able to communicate semantically correct patient information using open standards. In order to be capable of communicating semantically correct information, they must first be able to STORE semantically correct information. I believe that this is a bigger problem than the health informatics community realizes.
Longitudinal patient information is arguably one of the most temporally and spatially complex information sets known. Certainly GIS and others are complex as well but the science of medicine and therefore healthcare is constantly changing creating a moving context. To understand how to treat a patient the healthcare provider needs to be able to understand what has worked as well as what hasn't worked in the context of what was known about the patient and the treatments available at any point in time. This creates an environment of very complex data relationships. If any one of those relationships are broken then the semantic context of the data is lost and now there is a loss of information. Data items need to be bundled and stored as a complete unit of understanding for them to constitute information. Once broken apart into separate data items they are much like Humpty Dumpty.
Open information exchange specifications have been proposed such as the Continuity of Care Document (CCD) but again it isn't really an electronic health record model.
The openEHR specifications ( http://www.openehr.org ) are an object-oriented information model based on over 15 years of research and implementation experience designed specifically as an electronic health record information model. The openEHR specifications provide an opportunity to avoid the Humpty Dumpty data fracture. Through the use of "two-level modeling", openEHR specs describe a solid reference model enhanced by archetypes that bundle data items into an contextual information packet. These information packets can be transported between systems without loss of semantic context. I believe that vendors, proprietary and open source, would do well to examine the openEHR information specifications for use as the basis of their systems.
Use of a common information model will open the door for payors and employers to see their benefits unfold as patient information can be exchanged maintaining its semantic context. I project that this will reduce healthcare costs, improve quality of care and improve patient
satisfaction in the processes of care.
Timothy Cook, MSc
Health Informatics Research & Development Services
LinkedIn Profile: http://www.linkedin.com/in/timothywaynecook
Full story...
Posted by
Jaz
at
10:23 AM
15
comments
Labels:
commentary,
guest blog,
health information exchange,
standards
Social: DiggIt!
Del.icio.us
Technorati
Thursday, December 13, 2007
RHIOs Need Data Not Dollars
GovHealthIT reports on a Harvard study that finds that RHIOs across the USA are failing abysmally. Well duh. Regional Health Information Organisations can only function if and when they have regional health information to organise. Imagine building Google before the Web. Or Facebook before E-mail. That's what we're seeing happen now, and the feds STILL refuse to speak up.
Two systems that work that I think shine a light on how to build a national health network are the Internet and the credit card clearing system. Neither of these systems were written into law, neither came from new taxes, yet somehow they seem to work and sustain themselves.
The calls for funding RHIOs get louder and louder, yet these people HAVE NO DATA to share.
I have a few thoughts:
Incent adoption of electronic health records NOW. We don't need RHIOs, we need records.
Understand that successful implementation of EHRs will REDUCE REVENUE for those people implementing. REIMBURSE THEM.
If we build the data, the network will take care of itself.
Full story...
Posted by
Jaz
at
10:05 AM
0
comments
Labels:
commentary,
health information exchange
Social: DiggIt!
Del.icio.us
Technorati
Wednesday, May 9, 2007
Finally, Someone Gets It
Project To Merge Health Care, Banking Information Systems
The Tennessee-based Medical Banking Project later this year plans to unveil a computer-based platform that would allow banks to share medical record information and offer standards to manage that process, the Tennessean reports.
Full story...
Posted by
Jaz
at
3:50 PM
0
comments
Labels:
health information exchange
Social: DiggIt!
Del.icio.us
Technorati
Monday, March 26, 2007
PHRs: Certifiable?
There was a bit of buzz last week over the American Health Information Council's discussion around certification of Personal Health Records, with the Consumer Empowerment Workgroup not finding consensus on the issue. I've been waiting until the transcript of the CEW February 16 meeting was posted to comment on the workgroup's recommendations, however, the March 13th AHIC meeting which summarizes the CEW's February meeting has its transcript up already, so I'll work from that. When the Feb 16 transcript comes out I'll comment if necessary.
Quick recap on the Consumer Empowerment Workgroup: Broad Charge for the Workgroup:
Make recommendations to the Community to gain wide spread adoption of a personal health record that is easy-to-use, portable, longitudinal, affordable, and consumer-centered.
Specific Charge for the Workgroup:
Make recommendations to the Community so that within one year, a pre-populated, consumer-directed and secure electronic registration summary is available to targeted populations. Make additional recommendations to the Community so that within one year, a widely available pre-populated medication history linked to the registration summary is deployed.
The February 16 meeting of the CEW attempted to find answers to the following questions:
Notably, the question "what is a PHR?" is absent, although it's raised in the statement of dissent. While it may seem obvious, I think there should be a distinction between commercial PHR products and the general hazy notion of your PHI aggregated over a network.
In other words, it's one thing to make a platform for presenting your health record to you on a secure Web site, it's another to give me a report of all the data available to me from multiple sources using a clinical data exchange.
There are PHR products online I can go fill in myself, there are PHRs gaffer-taped onto EHR software products, there are PHRs auto populated by payors, there's a piece of paper in my wallet with my allergies on, there's various hospital records floating around...
Given a RHIO-like structure I could ostensibly aggregate my own data into my own PHR on my desktop by querying the exchange for myself.
I'll cut and paste the relevant sections of the transcript below, but in summary the split is over whether or not to recommend certification of PHRs against as-yet non-existing standards of privacy, security, interoperability and portability. The recommendation is for voluntary certification. Dr. Rose Marie Robertson, the Co-Chair of the group, led the charge for certification, David Lansky spoke for the five members who dissented.
In my estimation, the group is having a hard time defining what it is they're recommending. After Lansky speaks, Nancy Davenport-Ennis - the other Co-Chair - speaks to four different requirements the recommendation is trying to assure, i.e. privacy and security, transparency, affordability and interoperability.Recommendation 1: HHS should support CCHIT and/or other certifying entities in identifying a pathway and timeline for voluntary certification of PHRs after adequate industry experience has been achieved in the market. Such certification should include: specifications for PHR privacy and security, interoperability between PHRs and personal health information data sources (including EHRs) consistent with HITSP-identified standards, and PHR portability. The certification criteria development process should take into account the best practices for security and privacy policies to be identified by the Consumer Empowerment Workgroup, the Confidentiality, Privacy, and Security Workgroup, and other relevant groups.
Recommendation 2: HHS, through the Centers for Medicare & Medicaid Services and the Indian Health Service, and in collaboration with the Office of the National Coordinator for Health IT, should develop plans to offer portable PHRs with adequate privacy protections to their beneficiaries, and HHS should report back to the Community about their plans as available. The plans should take into account the results of the studies and best practices recommended by the Consumer Empowerment Workgroup on January 23, 2007, as they become available, and should build upon work already underway at the agencies.
The dissenting statement was against Recommendation 1 only. The primary dissent was that instead of focussing on certifying a PHR's adherence to privacy and security standards, the workgroup should be formulating actual policy that PHR vendors could be held to, that PHRs are just too young an idea to even consider certifying them.
This is where my hacker side trumps my paranoid side.
PHRs barely exist. There are several Web sites that allow you to populate your own record, but they don't talk to any data sources. There are a few health plans that give you a sort of PHR, but they're not portable to other plans.
No-one has yet figured out what data is even available to populate a PHR, how to transport it across a network, how to audit it and the access to it, how to manage it once it's alive, the list is endless.
It seems almost obvious to me that PHRs must come to exist in exactly the same way personal credit data does now. Think about it:
We can easily rewrite that and substitute clinical data:
So asking providers of PHR technology to adhere to basic principles of security and privacy is great, but what policies will they be measured against?
It's kind of like the HON Code; a voluntary code of conduct that health content Web sites can claim adherence to. It's all well and good, and has certainly made inroads into consumer awareness, but there's nothing forcing me, as a health care Web site publisher, to neither (a) choose to adhere to the principles of the HON Code nor (b) remain accountable for my conduct if I choose to claim compliance.
This has led to billions of health care content pages on the Web that have little to no validity or governance.
The goal of PHRs should be consumer empowerment, and we can only get there by having real policy laid down for PHR producers to follow. We don't need to mandate specific technologies or functionalities, merely solid security and privacy requirements that can be upheld by the PHR hosts.
If the AHIC can't come up with adequate language, why not examine the banking industry and figure out what they use? Is our health information really so different? Is it really more sensitive?
AHIC has so far offered a tremendous amount of effort and work on our behalf, but as adoption becomes less of an issue we need actual governance and direction.
Let's certainly adopt a stance of having certification against standards and policies as a goal, but let's figure out the standards and policies first, yes? Frameworks are awesome, but without development they are useless ghosts of possibility. Man up and write it down. We need policy, not frameworks, and by all accounts we need it sooner not later.
--
[Excerpt from transcript follows]
Dr. Rose Marie Robertson, Co-Chair, Consumer Empowerment Workgroup:
This -- the majority of the Group was convinced that enhancing and assuring privacy and security, as well as interoperability, would lead to greater adoption of personal health records. That this was important to do, and that it was complicated. That we needed to have standards, and expectations and policies, that we needed to derive that from the appropriate bodies. That we needed to be certain that we would not stifle innovation, and in particular, that we would not stifle innovation and entry into the market of groups providing services to those who are disadvantaged, so that small vendors who might aim at a targeted population that we very much want to be involved in, and able to access personal health records, in particular, should not be disadvantaged. We were reassured that sliding scales or perhaps even government grants or other [inaudible] could be found, so that [inaudible] as well as an electronic health record, one could level the playing field.
And we ultimately came to the [inaudible] that health and [inaudible] should support certifying entities [inaudible] other certifying entities, and we carefully worded it. In identifying a pathway and a timeline, so not in certifying, now, but in identifying a way and process for doing this, for voluntary certification of personal health records. So again, not mandatory certification, but voluntary certification that would provide, if you will, the underwriters’ code, that sort of assurance for the public, after adequate industry experience has been achieved in the market to know best how to do that.
That certification would include, we think, most importantly, specifications for privacy and security, and we plan to, as you see there, work with the confidentiality Privacy and Security Workgroup. We have begun those discussions, and will have actually another meeting with them on -- a meeting to discuss that on Friday.
It should also include issues of interoperability between personal health records and sources, because otherwise, those records [inaudible] are ineffectual. And portability. We think it’s quite important for patients to be able to take this information from a tethered system [inaudible] or one employer, and be able to bring that to another system.
We think that this process should take into account practices for those policies, as identified by our Workgroup, DDS Workgroup, and other relevant groups, perhaps; including the Privacy and Security Solutions Group. Not functionalities, as you’ll notice, but privacy and security interoperability and portability.
Let me turn to David Lansky and let him present the views of the dissenting group, whose letter you have in your packet as well.
David Lansky, Markle Foundation
MR. LANSKY: Thank you, Rose Marie. I want to first thank both Rose Marie and Nancy for leading a very vigorous and open discussion about a complex area. It has been a very constructive discussion, and I think all the parties to our Workgroup have felt that we have learned a lot by going through this discussion, and I hope some of you will participate in that with us today.
I think a key point, as I come to you, is that we do not have consensus about this issue. There is, across the industry, across healthcare, across the consumer sector, not yet enough experience or understanding to achieve a unified recommendation regarding how to proceed.
The reason, I think, we don’t have a consensus about the industry at this time on this question is that it’s frankly too early. We simply have not done enough work in the policy development area, in developing, and marketing and using these products, and in testing the relationship between those policies and those products, to know exactly the best way to more toward implementing the policies to help more forward.
I’d also say there is no question, as Rose Marie has said, that we all share the same objective, building a trustworthy, reliable environment where people share their health information, is what we’re here for. And finding the appropriate mechanisms to develop the right policies and enforce those policies is the task we need to have in common.
In some of the ways, I think we are premature in moving the certification process forward. First, we don’t actually know what a PHR is. We can’t yet define the “it.” Secondly, the industry has felt it’s new and improved [inaudible]. Not really talked to each other [inaudible] enough experience to know what can be applied and enforced. Thirdly, frankly, this is one of the first steps most of us have taken, marketing to 300 million Americans with an enormous array of needs and requirements, in health situations, is new for all of us in this environment; and how to evaluate and validate product in the consumer stage is a new challenge that we have not yet done.
And lastly, in terms of the prematurity of the work, while we have all identified, I think, some of the areas of privacy, and other policies where we have a significant need to establish public trust, we haven’t yet developed a policy. We have identified the problem; we have not yet recommended solution. So we don’t have, even as Mark said earlier, the standards yet against which to certify. So we feel that discussion of certification is premature, until we understand what those standards and policies should be, and then determine whether certification is an appropriate tool.
In the letter that you received we’ve identified a number of [inaudible] whether the logic that has supported PHR certification as we’re seeing, does that apply equally to the consumer marketplace? Do we know that certification will enhance privacy and security and trust in the public minds? And what is the risk of impeding innovation in the consumer marketplace, which may be different than the risk in the [inaudible] or physician marketplace.
But the good news, I think -- I want to close with, is that there is tremendous areas of agreement across all the Workgroups, which are highlighted in both letters, and I hope we’ll take some time today, and see if we can move forward in areas of very strong agreement.
We all agree that we need to establish the standards and specifications for both private and [inaudible] PHRs. We all agree we need to gain more industry experiences in the real world with these products and services. And we all agree that we need to develop privacy and security policies that can be used as [inaudible].
So I hope you will undertake efforts to address those three objections that we all share, and defer the question of certification until we understand what are those policies which must be enforced in the environment we’re working in.
The last point I want to make, is really to distinguish this idea of enforcement and policy development, the way we, and those who are [unintelligible] here, have seen the question, certification is one tool among at least half a dozen by which we can implement or enforce good policies. The others include a wide range, health certifications, statutes to [unintelligible]. There are a number of tools available to implement good policies. Certification is one.
I would hope that we would first do the hard work of developing the policies [inaudible], and then determine which method of implementation or enforcement would be appropriate. If certification proves to be one that is helpful at that point, I think we will have a very strong consensus to support it, once we have done the work of developing the necessary policy.
Again, I want to thank both you, Mr. Secretary, and the Community here for letting us be part of this vigorous discussion.
Full story...
Posted by
Jaz
at
1:33 PM
1 comments
Labels:
commentary,
health information exchange
Social: DiggIt!
Del.icio.us
Technorati
Friday, March 9, 2007
California Data Exchange Folds
The Santa Barbara County Care Data Exchange, touted as the longest-running effort to launch a regional health information organization, has closed it's virtual doors because of privacy concerns and doubts about ongoing costs.
With the upcoming round of funding for the NHIN being targeted at the RHIOs themselves, I'm curious as to why they didn't hang on for additional funding, although funding wasn't exactly the problem. Nonetheless, the effort underway now to start figuring out what the RHIOs have learned, and how to share the information nationally will be shortchanged if SBCCDE doesn't get to particpate.
While hugely unfortunate that they can't keep the exchange running, SBCCDE could now serve as a goldmine of lessons learned. An additional bonus is the comment from the California Healthcare Foundation, which put an initial $10 million into the exchange, saying it will consider open-sourcing the software created to run the exchange for other RHIOs to use.
If anyone has any idea who we can write to to show our support for this idea, please comment.
Full story...
Posted by
Jaz
at
9:56 AM
2
comments
Labels:
health information exchange
Social: DiggIt!
Del.icio.us
Technorati
Wednesday, March 7, 2007
NHIN Patient Empowerment Gets Mixed Feedback
GHIT reports that HHS is getting mixed reviews for its decision to insist that the next iteration of the Nationwide Health Information Network allow patients to control who sees their electronic health records.
As I've said before, it's one thing to call for granular control, it's another to lay out guidance for the RHIOs and state-wide HIEs on how to write and implement law and policy that governs the granular controls we're talking about. We're not waiting on the technology, that part is already done.
For a different perspective, read Modern Healthcare's piece on HIPAA ten years later (registration req'd), and the confusion about the law that still reigns. Scary.
Full story...
Posted by
Jaz
at
2:58 PM
0
comments
Labels:
health information exchange
Social: DiggIt!
Del.icio.us
Technorati
Sunday, March 4, 2007
Open Source the Nationwide Health Information Network
I've been catching up on some missed news what with all the travel lately, and I found some bits and pieces that will make it into the next update of my consumer health information presentation.
I'm not sure whether we're looking at an age gap, a technology gap, or simple Ludditism, but whichever it is it needs to be addressed sooner rather than later.
More and more I'm seeing reports talking about what consumers want and expect from electronic medical records. Markle released a study in December of 2006 that reports "Two-thirds of the public (65%) is interested in accessing their own personal health information electronically".
Overall, the survey findings point to consumers wanting control over who has access to their records and being concerned about potential privacy issues.
In a February 2007 prepared statement to the Subcommittee on Oversight of Government Management, Markle's Connecting For Health Chair Carol Diamond underlines these concerns and neatly summarizes the problem: consumers want doctors to have access to their records, but consumers want control and oversight over the doctors who see their records.
Markle has an excellent paper on A Common Framework for Networked Personal Health Information which details the common, standards manner in which health information networks should be structured, including my own favourite; distributed data.
The first paragraph of the paper is especially informative:"The average person’s ability to access data and communicate electronically is proliferating exponentially. Consumer adoption of digitally networked services has transformed the culture of many industries — often in ways
unimaginable barely a decade ago."
Unfortunately, the physician practice, and maybe the physician, hasn't kept up. The same physician who checks his stocks online, obtains electronic CME credit and can book a tee time from the course Web site still doesn't want his patients E-mailing him.
In the presentations I give, I hear push back from the older physicians and excitement from the younger ones. I think it's a simple fact of life, you can't change business practices wholesale. These docs have been doing business without electronic data exchange for decades, it's too much to ask them to lead the way.
As I say time and again, this is not necessarily a bad thing. On the one hand, health care is behind the times. On the other, the industry at large has a golden opportunity to learn from the mistakes of all the industries that *have* adopted electronic information networks as a core of their business.
We have this amazing opportunity to do it right the first time.
The gap, as I see it, is simply that consumers are now way more information-savvy than the health care industry; and the Nationwide Health Information Network (NHIN) doesn't seem to be going down the obvious path of not reinventing the wheel.
My major gripe is the whole *Regional* part of Regional Health Information Networks.
I know this is America and the land of free market and a (perceived) hands-off federal government, but the above survey bears out my belief that this is one instance where the feds should step in and say "this is how you're going to share data, this is how you're going to protect it".
Instead, we have dozens of almost-faceless organisations around the country trying to figure it out as they go, often formed by budget- and market-conscious hospital and physician groups who are the very people we're trying to change, the very people who have spent decades not sharing data with each other.
We have standards. We have lessons learned. We have vast repositories of open, transparent software that can be utilised. We have entire industries including finance and travel that have trodden this path. I don't feel like we're learning from them.
--
AHIMA just released a report that essentially says the same thing. RHIOs, state-level HIEs and the feds just aren't doing enough to coordinate the effort. Some highlights:"Currently, there is little sharing of lessons learned, products (e.g., business agreements, policies, service contracts), and services between the NHIN contractors and the state-level HIEs beyond those states directly involved in the NHIN contract projects."
"There is no central authority that: (1) is accountable for ensuring that HIT is directed toward transforming healthcare, or measuring progress against that goal; or (2) makes key HIT adoption-related decisions, such as resolving disputes among collaborating entities."
"In summary, there is an understanding of how standards harmonization, certification compliance, security and privacy collaboration, and NHIN prototyping all relate strategically to the acceleration of HIT adoption. However, the disconnects among these tactical projects create the perception of multiple efforts directed at individual issues with no overarching strategic plan connecting them."
Linux and Perl figured this out a long time ago. The free and open source software community has a long established tradition of organised adhocracies and distributed development with benevolent dictator oversight.
And yet we seem to be building a national infrastructure like it's 1980; industry-facing, industry-led and industry-serving. I guess it's like those Microsoft / Apple ads. One's the stodgy business type, the other is user-friendly and cool.
AHIC has empanelled a Consumer Empowerment Workgroup, but my bet is the first hurdle will be showing a business case to the HIE/RHIO community that makes it worth their while. It's not anyone's fault, as long as we have disparate entities coming up with infrastructure there'll be no sustainable model for them to invest in providing the patient empowerment in the first place. You can't blame them for not doing it.
We're deep into Web 2.0 and the promise of a semantic Web that delivers on the promise of true user interaction and vastly improved user participation. Let's build a national health infrastructure that acknowledges this, that is people-facing, patient-focussed, open, transparent and accountable.
The culture clash of a closed-source industry such as health care and the open, transparent goals of a national health information network cannot be solved by throwing millions of dollars at closed-source vendors like Northrop Grumman.
Open source is what built and maintains the World Wide Web you're reading this article on, it's the foundation of the Internet, and we manage to keep it up just about 24/7. Everyone seems to like how it works. Open source delivers your E-mail, uploads your photos, gets you your credit card statement and let's you pay bills online.
I'm not saying we should hand the NHIN over to Silicon Valley or the open source community, but we might want to ask them to join the discussion.
--
Further reading: Open source vs. closed source (Wikipedia) and The Cathedral and the Bazaar.
Full story...
Posted by
Jaz
at
11:33 AM
7
comments
Labels:
commentary,
health information exchange,
standards
Social: DiggIt!
Del.icio.us
Technorati
Friday, March 2, 2007
Health Technology Surveys
THCB has a post about a Cisco-sponsored study of Internet use in health care by patients (press release).
Three things stood out for me as being very interesting:
First of all, 11% of respondents said they had used the Internet to evaluate a physician. 11% doesn't sound like very much, but it's 11% compared to 0% not too long ago, when patients had nowhere to go to perform the same kind of evaluations, and the number is growing.
As I mentioned in a recent presentation to the Institute for the Advancement of Health Care Management, this may or may not be a good thing, with increasing self-diagnosis and patients turning up at the doctor's office with armfuls of misinformation, but that's a different problem...
Secondly and thirdly, two questions were asked about how patients thought electronic medical records (EMR) would benefit them.
When asked to choose between being able to control who has access to their EMR or having an EMR available to all medics, 68% chose controlling access. Then, when asked whether they preferred easy access to their EMR over protected privacy, 73% chose privacy as their desired outcome.
--
Another survey out is the American Hospital Association's findings of its 2006 survey of community hospitals and their involvement with health information technology. Of the more than 1,500 respondents, 68% had worked on adding electronic health records programs during the year and nearly half reported a moderate or high use of HIT.
However, reading page 17 - which looks at who the hospitals are sharing information with - we see physician offices, public health departments, other hospitals, labs, the list goes on.
You know who's missing?
THE PATIENTS.
This underscores my belief that HIEs around the country that are currently more concerned with keeping tight, internal ownership of patient records need to understand that patients will demand control over their data, exactly the same way they currently control and have ownership of banking and credit data.
Oddly, when Cisco asked who the patients would prefer to receive such services from, HIE/RHIO type organisations were not included as a possible response, which is a shame because (a) most people don't know they're being formed and (b) have even less idea how much power these HIEs will wield over their personal and highly sensitive data.
These decisions are being made right now and I don't know that the patient population is being adequately involved.
Full story...
Posted by
Jaz
at
2:53 PM
0
comments
Labels:
health information exchange
Social: DiggIt!
Del.icio.us
Technorati
Thursday, March 1, 2007
IBM and Duke Looking Cozy
First of all, Dydd Dewi Sant Hapus! It's Saint David's Day and yes, I'm wearing a leek. The Empire State Building was lit up in Welsh colours last night just for us Cymreig, as part of "Wales in NY Week". Thanks!
Onto business.
The Washington Post reported last week that Duke University had launched a patient portal that will allow patients "to pay medical bills, schedule doctor appointments and eventually view their personal medical histories". (A more technical article is available at ebizQ.)
I'm usually a little bit past cynical when I hear the word "eventually", but I was reminded of this story this morning so I dug around and found out two things I thought were pretty neat.
One, "eventually" in this case means two months! Why they didn't just wait two months and launch a full service I don't know, but still, if it comes together that's half a million people with free access to their medical history. Very, very cool.
Secondly, I was struck by the third option on the home page, after "Request an Appointment" and "Manage Your Account" there's a link that reads "Visit 'Payment History' for information you need if you're itemizing health care expenses on your taxes".
I'm eagerly awaiting the day my medical history is as automated and accessible as my credit history, and it's smart communications like the above that make the data that much more utile and customer-friendly.
It's a shining example that it's not software that makes the system, it's the people implementing that make the system; and people who want to work with touchy-feely open, standards-based systems tend to produce touchy-feely services that the average user can enjoy and gain from. Flickr is a great example of this, a service that was built by people with love in their hearts, not their three-month review.
I keep on thinking that yes, health care has lagged in IT adoption, especially Web services; but then again, now that it's on the table and people are spending money, we have this amazing opportunity to do it right the first time!
The whole thing runs on IBM's WebSphere software, a standards-based middleware infrastructure that basically takes older systems and wedges Web services between them to get more out of them than was previously gettable. IBM, of course, is at the forefront of Open Document Format, another standard that will seriously impact health information exchange for the better.
Duke itself has representation on the OASIS International Health Continuum Technical Committee which all adds up to a very open, standards-oriented electronic health record that goes way beyond billing and labs and could truly immerse the patient in their role as an informed, advocative consumer.
It probably also helped that IBM's vice president of SOA and WebSphere strategy, Sandy Carter, is a graduate of Duke University.
All in all it looks like a match made in service-oriented architecture heaven.
If anyone is a user of the Duke HealthView system, I'd be interested to hear from you.
Full story...
Posted by
Jaz
at
10:17 AM
0
comments
Labels:
health information exchange,
standards
Social: DiggIt!
Del.icio.us
Technorati
Disclosures and Disclaimers
Disclosures
My employer is compensated through funding to provide analytical research, technology solutions, and Web-based public and private health care performance reports by the State of New York, the State of Illinois, the Centers for Medicare & Medicaid Services, the Agency for Healthcare Research and Quality, the Commonwealth Fund and Bridges to Excellence. I am not being compensated by any of these organisations to create articles for or make edits to this Web site or any other medium; and all posts authored by me are as an individual and do not represent my employer or the agencies I work for.