Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Sunday, March 08, 2015

Medscape Issues a Non-Private Privacy Update

With physicians increasingly turning to news aggregators to keep up with medical news and developments, physicians' eyes have become Big Business.

So has sharing their information.

Medscape (a division of WebMD) recently sent all of its registered users an update of their "privacy" policy (By the way, check to see if a "cookie" considers you already "logged on" when you view this policy webpage).

Here's my summary take:

Nothing physicians do with Medscape/theHeart.org/WebMD websites is private and, in fact, our data (including license information) is being shared with just about anyone willing to pay for the data.

Medscape, ironically the same institution charged with managing continuing medical education for the Health and Human Services HIPAA policy, wants to collect physician license information from "third parties," track what doctors are viewing and interacting with on their website, then share this data to anyone willing to pay them a pretty penny.  In fact, we should take special notice of the section entitled "Disclosure of Your Information to Third Parties."

I was particularly interested in the the Companies and People Who Work For Us subsection:
In addition, if you are a healthcare professional, we may request that a third party validate your licensure status and other information against available databases of healthcare professionals. In order to provide these services, we may provide these other companies with Personal Information we maintain about users of our Services. We require that all such companies agree that they will limit their use of your Personal Information to fulfilling their responsibilities to us. (Emphasis mine)
Such a friendly two-way give and take of our information! (Remember that practice information you were recently asked to supply to the American Board of Internal Medicine?)

Privacy?  What privacy? 

-Wes

h/t Mr. Larry Husten

Thursday, July 28, 2011

Rebuttal: The NEJM's Justification of Medical "Mystery Shoppers"

The proposed examination of access to primary care according to insurance status in nine representative states was largely derailed by physicians and other critics concerned about the potential for government invasion of physicians' privacy. They argued that less controversial survey methods would suffice or that additional studies of the well-known primary care shortage are a waste of public resources. I think these arguments are misguided.

- Karin Rhodes, MD NEJM, July 27, 2011 (10.1056/NEJMp1107779)

Fair enough, Dr. Rhodes. You certainly are entitled to your opinion.

But before I take on my rebuttal to your piece, let's both be clear on a separate issue: what is most misguided about your perspective piece in the New England Journal of Medicine was that comments were not allowed. If they were, the "physicians and other critics" could explain their aversion to these tactics.

So, let me be the first to state my position.

Covert, subversive tactics in research in an attempt to avoid bias carries the risk of introducing additional forms of bias. For instance, when a phone call is made to a doctor's office for a new patient appointment and the problem sufficienctly urgent that other real live patients are rescheduled to accommodate a mystery patient's needs, how, exactly are the affects and costs to the established patients compensated? How will those data be "counted" in your statistics when your one new patient's access if offset by the loss of two follow-up patient's access. Who will explain to those affected by these tactics why they were rescheduled? Will you?

You claim that "the study was intended to generate valid national estimates of primary care capacity before the anticipated expansion of private and public insurance to as many as 38 million currently uninsured Americans."

First, recall the problems with that "38 million" number. Wasn't that number "47 million uninsured not too long ago?" Right off the bat, we see how numbers can be spun in policy circles, Dr. Rhodes. Which leads to the most important question that remains unanswered regarding a study that uses these covert tactics: how will the data be used? Will the data (which most certainly are going to "discover" problems with access) be used to justify mandates to shorten office visits from 7.5 minutes per patient to 7 minutes per patient to improve access? Or might doctors be directed to see more patients that are not insured? Seriously. What policy directives can we expect from these data?

You justify the use of this deceptive practice saying "the use of masking and concealed allocation, widely endorsed for randomized, double-blind clinical trials, lends confidence to the interpretation of results." And yet in the circumstance of randomized, controlled trials, patients must sign informed consent to take part in such a study before they are randomized. Hardly a "mystery" process. Should patients and doctors of prospective clinics not be afforded the same respect who might be asked to take part in your study?

You also seem to feel that a sampling 18% of states (9 of 50) is adequate to formulate conclusions. I find this concerning. National policy development should have representation from all states affected, not a minority. To suggest that the concerns of states with relatively high congestion mirror those with more rural populations is certain to bias policy decisions going forward and, more likely than not, exclude the perspective of less populous states.

So these are just a few of my concerns. There are others. Please note that none of them even begin to address the privacy issues raised by "others." But given the flaws I've outlined, paired with the obvious shortage of physicians that we will encounter in 2014 when the full brunt of the Patient Protection and Affordable Care Act kicks in (not to mention our limited research funding these days), this study certainly does appear to squander our limited public resources. Must we spend our resources to become Masters of the Obvious?

No doubt others would like to share their views, so unlike the New England Journal of Medicine, I'll leave my comments open.

-Wes

Friday, June 24, 2011

When Speech Trumps Privacy

I just read the recent report on the Supreme Court striking down the Vermont law that bans the practice of data mining. “Data mining” occurs when third party corporations purchase prescribing information from pharmacies and match it to individual doctors through a 44 million dollar deal with the AMA to utilize its physician master file. The third party corporations then sell this linked data to pharmaceutical companies to assist their detailers in their marketing efforts.

In days gone by, pharmaceutical companies had a hard time acquiring this information because doctors wrote their prescriptions by hand. Today, as we all know, doctors must e-prescribe, that is, electronically transmit their prescriptions via the internet to pharmacies. Each of thise prescriptions are carefully tracked by our significant "stake-holders" of health care: hospitals, pharmaceutical companies, governmental regulatory bodies and the like.

What interests me from this ruling is that the act of collecting this information -- the prescribing physician's name and address; the name, dosage, and quantity of the medication; the date and place where the prescription was filled; and the patient's age and gender -- was considered "speech" with the justices ruling that "the creation and dissemination of information are speech for First Amendment purposes."

Think about that: writing a prescription and disseminating that information is now "speech."

What I wonder, of course, will all our prescribing practices that are entered on an Electronic Medical Record, be they for a medical device, test, order, or request, similarly be classified as "speech" protected under the First Amendment? Might this ruling significantly impact a patient's right to privacy about their health condition as innumerable third parties can now access prescribing (aka, ordering) information in the blink of an eye electronically?

Oh wait, they already are.

-Wes

Friday, April 29, 2011

ACC Responds (Again) to Why They Track Their Membership

I appreciate the American College of Cardiology responding to my concerns regarding the finding of RFID tags in our name badges at the recent ACC.11 & i2 Summit Scientific Conferences and expanding upon their earlier explanation. I encourage all readers of this blog to read it.

Now for a bit of a respectful rebuttal.

I admit: I missed the need to "opt-out" of this tracking when I registered for their meeting. But I really didn't realize that registering for a scientific meeting also required signing (checking?) a contract to not permit tracking when I registered at the time. Who knew?

Now more than ever, I believe the use of our personal data should be on the basis of an “opt-in” policy rather than an “opt-out” policy. Requiring someone the check a box to NOT have something is a pernicious way to illicit approval for an activity. I get that we could “opt-out,” but why should I HAVE to? My privacy (and that of all of the ACC’s membership) should be kept confidential first and foremost, marketing efforts should come second.

The ACC states that they use the RFID data for “two main functions,” (1) meeting planning and (2) to collect “rent” for the use of RFID data by exhibitors:
Exhibitors were able to rent RFID readers from the vendor. They are able to use the data in much the same way as the ACC – to evaluate how effectively their work stations are structured and to improve their offerings to attendees….ACC’s intention was not to create a revenue source by offering attendee data to exhibitors (in fact, only five out of more than 300 exhibiting companies decided to invest in RFID in their booths), but rather to provide exhibitors another resource by which to understand the traffic flow in their booths and to better align their displays with attendees’ needs.
They suggest that the ACC’s “intent” was not to create a revenue source by offering attendee data to exhibitors because only 5 vendors opted to pay for the rental. If so, why not offer the data for free? While the data given was reportedly “the same information that was available on meeting attendees badges in print (name/city/state/institution). No contact information is provided” we really see that other data were also derived from this meeting, and hence distributable:
The attendee then goes to a session on appropriate use of PCI, followed by a session on imaging because he or she is interested in new advances in the intersection of imaging and intervention. Let’s also say that several other people in these sessions followed a similar track. In this scenario, the ACC would receive a report of aggregated data, showing a significant level of physician interest in both imaging and interventional sessions.
If the ACC collected and controlled the data themselves, then the ACC could assure the data’s privacy, but they did not. The ACC contracted with an outside vendor, Alliance Tech, to collect the tracking data and, as such, they have the ultimate control over it. By supplying our demographic information to Alliance Tech, the ACC makes the tracking data useful to vendors and others. What assurance do members have that Alliance Tech has the same good intentions with the data as the ACC? Realize that this same tactic was used by the American Medical Association to provide our prescribing information to Heath Information Organizations with the same "opt-out" requirement.

This is not to say the ACC does not need the revenue. Putting on these meetings is expensive. But we must not lose sight of the real purpose of these meetings, education. Many doctors I know shook their head when the opening plenary session started with a light show and red carpet walk. Is funding of these “shows” why they need to see our personal data? Like it or not, we have to wonder.

Also, RFID data are easily hacked. One only needs to watch the short video of Adam Savage from the popular TV show Mythbusters at the 2010 Hackers Conference to see why the Discovery Channel opted not to air their show on RFID technology to understand how important this data is to businesses.

No doubt the ACC need to find ways to raise funds as pressure mounts on all of us to cut costs in health care. These scientific meetings are a major source of revenue for their organization and they do perform an important advocacy role for cardiologists in Washington. But there is a need to remember why they exist in the first place: to advocate for their physician members while respecting their practice of medicine, not sell us (and our personal data) short to other industry interests.

-Wes

Sunday, April 24, 2011

The Implications of Physician Tag and Release

Not everything that counts can be measured.
Not everything that can be measured counts.

-Albert Einstein
Recently, a disturbing trend of monitoring physician quality and accountability has taken another ominous turn: tracking physician's movements at scientific conferences (so called "tag and release") using RFID tags imbedded in attendees name badges at national scientific sessions. Having had personal experience with the recent American College of Cardiology meeting, this technology will also be imbedded in the name badges for attendees at the upcoming Heart Rhythm Society meeting to be held in San Francisco in May.

On first blush, it shouldn't be such a big deal, right? It was all just a great way for companies to obtain, for a fee, the names and institutions of people who visited their display booths and for the conference organizers to track the movements of attendees. (Heck, maybe they can partner with an industry sponsor to pick up our traffic tolls on the way to the conference hall or arrange other exciting activities for us! [Said tongue-in-cheek, of course])

Instead of "opting in" for tracking at scientific meetings, doctors must "opt out" from the use of tracking technology when registering for scientific meetings. At the upcoming Heart Rhythm Society meeting for instance, doctors had to "opt out" from the use of RFID technology tracking by checking a box that says:
Badge scanning technology will be utilized at this event in order to better understand attendee/delegate interests and preferences. The information collected will be used to improve future events to better address your preferences. No personal information is stored in the RFID badge, only an ID number. We encourage all participants to take part in this process to ensure the most accurate data is obtained. You may check this box to opt-out of the RFID data collection.
There's full disclosure, doctor.

But to me, the default tracking of doctors is disturbing on several levels.

First, tracking was approved by our professional society organizers upon their own members. It is no secret that these societies make a significant portion of their operating revenues from industry sponsors at these meetings. By instituting tracking, the value of their membership's privacy has taken a back seat to the income generated from tracking revenues. By NOT checking a box, we have implicitly "agreed" to this tracking. (Realize we MUST wear our badge to attend these conferences where we gain our REQUIRED continuing education credits.) Because we have "agreed" in this manner, the tracking data are now legally "discoverable." At the risk of sounding like a conspiracy theorist, it is not too hard to imagine one's credentials being called into question in court because a doctor did not demonstrate enough time in CME activities at the scientific sessions to quality for credit or because these data implicate a doctor in a purchasing agreement between a vendor and hospital system simply because a doctor visited a display booth.

Doctors have seen this sort of activity before when "only" our license and demographic information was sold by the American Medical Association (AMA). The AMA currently "licenses" physician state medical license numbers and demographic information to health care information organizations (HIOs), HIOs then collect and compile this information with prescribing data that contains the doctors' license numbers (no names, mind you) and then sell the lists to pharmaceutical companies. The AMA tells its members it does "not collect, license, sell or have access to physician prescribing data" and this is true. But the AMA facilitates an intermediary's ability to pair doctors' license information to a their prescribing habits via a third party. One can only speculate how out prescribing and practice profiles are being developed by other similar health information companies with the use of our RFID tracking data.

Behind all of this is a bigger issue: doctors are frustrated by the increasing intrusion into our day-to-day practice of medicine to measure things. Take, as one example, our "quality performance measures" that have done little to facilitate patients office visits, but rather add burdonsome documentation requirements in the interest of government payments. A number of hospital administrators have confided in me that it costs more to collect this data than they make in government payments. In fact, whether these programs are ultimately are found to be cost-effective or improve the quality of care has been brought into question in our literature. Yet we continue to collect these measures and expand them. We are now dispatching legions of people to collect and compile data to "prove" that Electronic Medical Records are used in a "meaningful" way. But an honest appraisal of this policy discloses the reality: these measures permit health care systems to collect another $40,000 per doctor from the government because they are using computers, not because it improves patients' care in any "meaningful" way. As proof of the overburdensome nature of all this data collection for the physician, doctors (or their health care systems) are increasingly employing "scribes" to relieve them of the data-entry burdens in the name of "efficiency." How much, exactly, do these scribes cost our health care system? Few dare to ask the question since no one wants to deny themselves of that juicy $40,000 pot of gold being paid per doctor.

Adding insult to injury, all doctors will soon be required to disclose if we receive anything over $100 from industry representatives. Like the public, most of us recognize the pernicious nature of industry influence upon our profession. Yet we now find we are being used. Should our professional organizations be any less forthright with their industry dealings and the use of our demographic data at national scientific sessions? How much is at stake?

Finally, we see more and more onerous licensure requirements and fees paid to the same tag-and-release operatives at considerable cost to ourselves. We now spend thousands of dollars to remain "credentialed." We wonder how much the RFID "return on investment" to industry sponsors adds to our annual membership fees. Could it reduces them? Who knows? Maybe, like other IT models, we should insist our membership fees be waived if we agree to being RFID tagged and released because most of us realize someone's making money on this deal.

In summary, doctors increasingly find the imperative to guard the privacy of our patients without regard to our own personal and professional privacy with the very same patients disturbing. Everything about doctors is being measured these days and it's taking its toll on patient care. We are frustrated with the governmental bureaucratic standards that threaten our time with patients. But time with patients does not pay bills. Meeting data-collection milestones do. Our government and employers have lost sight of the main issue here: improving and expanding our contact with (and the ability to do good for) our patients.

But as long as there is money to be made with our personal information, it is clear that there will be those that will try to capitalize upon it, whether we realize it or not. Only by demanding constant accountability and transparency from the collectors of this information be they government bureaucrats or our professional society appointees, can we hope to maintain any modicum of professionalism in our tenuous doctor-patient relationships of the future.

-Wes

Wednesday, April 20, 2011

ACC Explains the Use of RFID Tags on Attendee's Name Badges

In response to my earlier post on the use of RFID tags at the ACC's Scientific Sessions, I left a message on the ACC's blog to inquire about this practice. My comment was not initially published, but today I noticed that traffic came from their blog and that my comment and a response to my inquiry was published on the 12th of April. Here's what they said:
Hi Dr. Fisher,

Thanks for your question and your feedback on the meeting. RFID is used by many large meetings -- the technology allows us to track which sessions an attendee attends, and also to track flow -- this will help us a lot to plan the education program next year, as we will be able to use data to determine co-location of pathways etc. to make for an ever better attendee experience on show site. Info that the ACC collected at ACC.11/i2 will help us better plan meeting rooms and expo entrances, adjust our conference programming & expo hall floor plan, and quantify to exhibitor prospects the value of investing in our event, among other things. We are not using the RFID to award CME.

Thank you again for your feedback. Please know we will certainly take your concerns into consideration as we plan for 2012.

All the best,

Sue Sears Hamilton
Associate Vice President, Annual Scientific Session
American College of Cardiology
First, this was very nice of them to respond. I am concerned, however, that this company that tracks these RFID tags can identify the individual and their associated institution in real-time at these meetings (see their promotional video). As Calvin Powers from IBM notes on his blog:
Is it OK for the ACC to give the names, demographic information, contact info, etc of every individual that visited the booth?

At this point in the continuum we have moved into the realm of identified tracking and I suspect most people would feel like their privacy had been invaded if their individual movements were tracked and this level of detail was sold to the exhibitors. When the tracking becomes identifiable down to the individual, privacy practices regarding transparency, opt in/out policies, etf become very important.
We do not know if this practice occurred, but we do know that the capability was there.

My bet: there will be one heck on an "opt in" clause for this technology going forward for future meetings.

At least I hope so.

-Wes

Wednesday, April 06, 2011

What They Know

Here's a picture of the back of my badge at the recent American College of Cardiology Conference held 2-5 April 2011 in New Orleans, LA:

And here's the scanners used to track those RFID tags above one of the conference rooms:

I wonder what they know about me and if I'll still get credit for the sessions that I walked out early on?

-Wes

Addendum 8 Apr 2011: here's an excellent take on these issues from Calvin Powers from IBM's blog.

Tuesday, March 08, 2011

How Medication Lists Define Your Health Issues

Give me your medication list and I'll tell you your health problems.

It happens every day in emergency rooms across the country as confused elderly patients present for an acute problem unable to describe their past medical history but equipped with a list of medications in their wallet.

Metformin = type II diabetes

Synthroid = hypothyroidism

Lipitor + Altace + Lasix + Slo-K = ischemic cardiomyopathy

Lexapro = He's a little anxious or depressed

Viagra = Well, you know...

I bet I'd be right better than 90% of the time.

Now, imagine you're a pharmaceutical company wanting to target people with those chronic diseases. Where might you find them?

No problem. Just pay the insurers to provide you patients drug lists. No names need be exchanged in keeping with HIPAA requirements. But the drugs list attached to folk's cable TV box?

Perfect. You're in. With no legal strings attached. Then just fire away with that targeted direct-to-consumer advertising on TV, courtesy of your local health care insurance provider.

No wonder our health care industry movers and shakers love the electronic medical record.

Health care privacy? What health care privacy?

-Wes

Sunday, January 09, 2011

An Internet ID for All Americans?

From CBS News:
President Obama is planning to hand the U.S. Commerce Department authority over a forthcoming cybersecurity effort to create an Internet ID for Americans, a White House official said here today.

It's "the absolute perfect spot in the U.S. government" to centralize efforts toward creating an "identity ecosystem" for the Internet, White House Cybersecurity Coordinator Howard Schmidt said.

That news, first reported by CNET, effectively pushes the department to the forefront of the issue, beating out other potential candidates including the National Security Agency and the Department of Homeland Security. The move also is likely to please privacy and civil liberties groups that have raised concerns in the past over the dual roles of police and intelligence agencies.

The announcement came at an event today at the Stanford Institute for Economic Policy Research, where U.S. Commerce Secretary Gary Locke and Schmidt spoke.

The Obama administration is currently drafting what it's calling the National Strategy for Trusted Identities in Cyberspace, which Locke said will be released by the president in the next few months. (An early version was publicly released last summer.)

"We are not talking about a national ID card," Locke said at the Stanford event. "We are not talking about a government-controlled system. What we are talking about is enhancing online security and privacy and reducing and perhaps even eliminating the need to memorize a dozen passwords, through creation and use of more trusted digital identities."
No, they're not talking about a national ID card, just an international internet ID.

Imagine. Anyone registered with such a cyber-ID who conferences with their doctor via a "secure server" can also be tracked by the government with such a mechanism.

And the issue of not needing more than one password? While convenient, the ramifications of multiple accounts being compromised if a data leak were to occur remains with such a mechanism.

But fear not:
Details about the "trusted identity" project are unusually scarce. Last year's announcement referenced a possible forthcoming smart card or digital certificate that would prove that online users are who they say they are. These digital IDs would be offered to consumers by online vendors for financial transactions.

Schmidt stressed today that anonymity and pseudonymity will remain possible on the Internet. "I don't have to get a credential if I don't want to," he said. There's no chance that "a centralized database will emerge," and "we need the private sector to lead the implementation of this," he said.
No doubt you won't have to be "credentialed" unless you want to use a government service. (They have to be sure you're a "trusted user," right?)

Like Medicare or Medicaid.

Privacy? Who needs privacy?

-Wes

Reference: Draft Document: "National Strategy for Trusted Identities in Cyberspace," (pdf) dated 25 June 2010.

Monday, November 29, 2010

What WikiLeaks Means for Health Care Privacy

"By releasing stolen and classified documents, Wikileaks has put at risk not only the cause of human rights, but also the lives and work of the individuals. We condemn in strongest terms, the unauthorized disclosure of classified documents and sensitive national security information."
Official White House statement yesterday regarding Wikileaks disclosure of diplomatic cables
No matter what people think of Wikileaks disclosure of approximately 250,000 classified diplomatic cables to the Internet yesterday with the help of the New York Times, The Guardian, Der Spiegel, and Le Monde, the implications to electronic health care information security are significant.

Day in and day out, I type huge volumes of information on my patients on a computer and my fellow physicians do the same. As a result, vast health care information warehouses are at the disposal of the government, insurers, and major health care institutions eager to become more efficient, strategic, or competitive. We are promised the information is private, confidential, and even stripped of its identifiers for group analysis. It is even protected to remain so by law.

And now we find that even the government's most sensitive and classified diplomatic data is subject to disclosure, some how, some way.

Worse, once the leak occurs, the government is powerless to correct the breech.

While a single individual's private health care information may not carry the gravitas of wartime communiqués, each of us deals with famous patients who might not want their diagnosis, HIV status, or drinking history spread far and wide. For them, this private information might be just as personally damaging as anything disclosed by WikiLeaks.

Yet in our new era of the Electronic Medical Record and government funding of health care in America, we now find that this potential loss of our health care privacy is the price (and risk) for care we'll have to accept.

-Wes

Monday, October 18, 2010

Healthcare's Facebook

This morning, the Wall Street Journal's front page story exposed a significant privacy breech of online personal information via the world's most popular social networking sight, Facebook:
Many of the most popular applications, or "apps," on the social-networking site Facebook Inc. have been transmitting identifying information—in effect, providing access to people's names and, in some cases, their friends' names—to dozens of advertising and Internet tracking companies, a Wall Street Journal investigation has found.

The issue affects tens of millions of Facebook app users, including people who set their profiles to Facebook's strictest privacy settings. The practice breaks Facebook's rules, and renews questions about its ability to keep identifiable information about its users' activities secure.
How could they? Imagine the nerve of marketers using Facebook ID's to develop profiles on people using little socializing games! Facebook has a privacy policy! I was assured that if I set my privacy settings to 'maximum,' this would never happen!

To which I say: "Duh!"

When it comes to money, people get awfully creative.

So while Facebook grapples with its latest public relations nightmare, we should realize our electronic medical record app vendors are doing exactly the same thing. Worse, it's perfectly legal, even though each of use has been assured our privacy settings are set to 'maximum' through the reassurances of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the The Patient Safety and Quality Improvement Act of 2005 (PSQIA).

That's because Clause 4302 of our new Patient Protection and Affordable Care Act of 2010 (PPACA) dealing with "Health Disparities" mandates:
The Secretary (of Health and Human Services) shall ensure that, by not later than 2 years after the date of enactment of this title, any federally conducted or supported health care or public health program, activity or survey (including Current Population Surveys and American Community Surveys conducted by the Bureau of Labor Statistics and the Bureau of the Census) collects and reports, to the extent practicable
(A) data on race, ethnicity, sex, primary language, and disability status for applicants, recipients, or participants; ...
(D) any other demographic data as deemed appropriate by the Secretary regarding health disparities.
Just like Facebook's apps that look for certain characteristics of social media games, patients with health "disparities" will be mandated by law to have their data transmitted to "the Office of Minority Health, the National Center on Minority Health and Health Disparities, the Agency for Healthcare Research and Quality, the Centers for Disease Control and Prevention, the Centers for Medicare & Medicaid Services, the Indian Health Service and epidemiology centers funded under the Indian Health Care Improvement Act, the Office of Rural health, other agencies within the Department of Health and Human Services, and other entities as determined appropriate by the Secretary."

Welcome to healthcare's Facebook.

In comparison, the open-ended phrasing of many portions of our new PPACA law makes Facebook's privacy issues look like chump change.

-Wes

Wednesday, September 22, 2010

"Health Disparities" and The Future of Your Health Care Privacy

"The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized."

4th Amendment, U.S. Constitution


Arie Friedman, MD examines Section 4302 of the Patient Protection and Affordable Care Act of 2010 (PPACA) and breaks down the use, distribution, and upcoming protections of your personal health care data by the government including this passage:
(1) IN GENERAL- The Secretary shall ensure that, by not later than 2 years after the date of enactment of this title, any federally conducted or supported health care or public health program, activity or survey (including Current Population Surveys and American Community Surveys conducted by the Bureau of Labor Statistics and the Bureau of the Census) collects and reports, to the extent practicable--

(A) data on race, ethnicity, sex, primary language, and disability status for applicants, recipients, or participants;

...

(D) (emphasis mine) any other demographic data as deemed appropriate by the Secretary regarding health disparities.
Be sure to read Dr. Friedman's article that touches on the protections assured by the new law. I tend to think I have a pretty balanced readership on both sides of the political spectrum so I'd be interested to hear what others think.

Are we giving up our health care privacy in return for medical coverage in the new PPACA law or do we feel the protections mentioned by the law are sufficient?

-Wes

Tuesday, May 04, 2010

How To Instill Confidence in the EMR

... just post the 1.24 million records that have been compromised online.

So don't worry, your health care records will be in the very best of hands.

-Wes

Friday, October 09, 2009

"Body Computing" and the Right to Health Information

Fellow cardiac electrophysiologist Leslie Saxon, MD thinks patients should own their medical device information in the era of "body computing:"
But there are major obstacles standing in the way of people's rights to access their health care data. There are over 400,000 patients with implanted defibrillators that have networked capability. Up to 20 percent of people with defibrillators will be shocked from the device. While the shock is life-saving and one of the main reasons the device gets placed, patients feel something that is akin to a punch in the chest and it causes great concern and curiosity from the patient. Where does the vital information about the shock go?

It is transmitted to a secure server--managed by device manufacturers--and the information is then downloaded to a secure web site for the patient's physician. I think patients have a right to see the information, and be able to share it with family members and other physicians, but patients are given no opportunity to access it. Device manufactures tell me that they won't allow patients to access the data because they are worried about insulting the physician who implanted the device. Physicians aren't exactly excited to give up the data because they believe it will cause more work and put them at risk for lawsuits.
So what are those "major obstacles" to allowing patients access to their health information?

Privacy and Safety

You can never be too careful with health information - especially if its yours. Powerful governmental rules exist to make sure your cannot access your health information easily. In 1996, with the advent of electronic submission of claims to the US government, concerns over the privacy of electronically-encoded information surfaced and resulted in the development of HIPAA, enforced by the governmental Office of Civil Rights. After the Institute of Medicine's "landmark report" entitled "To Err is Human: Building a Safer Health System," (available for purchase only) which highlighted critical areas of research and activities needed to improve the safety and quality of health care delivery, Congress passed the Patient Safety and Quality Improvement Act of 2005 (PSQIA). PSQIA provides Federal privilege and confidentiality protections for patient safety information called "patient safety work product." Patient safety work product includes information collected and created during the reporting and analysis of patient safety events. These safety events then feed into the Agency for Healthcare Research and Quality (AHRQ) which has responsibility for listing patient safety organizations (PSOs), the external experts established by the Patient Safety Act to collect and analyze patient safety information. Who are Patient Safety Organizations? Well there's one for nearly every state. The data collected from these PSO's feed into a carefully contructed Network of Patient Safety Databases (NPSD). These NPSD's will receive, analyze, and report on de-identified and aggregated patient safety event information with the goal of facilitating aggregation and analyses of patient safety event information to help reduce adverse events and improve health care quality. All of this aggregated information is then protected by the PSO Privacy Protection Center.

But safety concerns don't stop there.

The FDA (pdf) must also regulate the devices themselves to assure their safety, managed adeptly by the Center for Devices and Radiological Health. They, in turn, manage a Medical Device Recall Database so consumers can find out which devices have or have not been recalled. Doctors also must maintain a registry of all patients who receive medical devices, some of which extend information to hospital information systems as well as a database of implant information tied to clinical variables. Companies can use these data to report potential safety problems. Doctors can use these data to protect their turf in the name of safety.

Legal Concerns

Despite all of the above safety and privacy safeguards, legal liability concerns loom large in the minds of health care providers and device manufacturers as violation of privacy laws can lead to jail time and hefty fines. With the increasing need to balance governmental budgets, we're seeing an increase in audits of health information, thanks, in part to the Health Information Technology for Economic and Clinical Health Act (HITECH Act):
American Recovery and Reinvestment Act of 2009 (ARRA) also includes a section that expands the reach of the Health Insurance Portability and Accountability Act (HIPAA) and introduces the first federally mandated data breach notification requirement.

Title XIII of ARRA, also known as the Health Information Technology for Economic and Clinical Health Act (HITECH Act), reserves $22 billion to "advance the use of health information technology" -- in large part so the U.S. will be able to move to e-health records by President Obama's 2014 deadline.

It also expands the reach of HIPAA data privacy and security requirements to include the "business associates" of those entities (health care providers, pharmacies, and the like) that are subject to HIPAA.
This act significantly expands the reach of the HIPAA Privacy Rule and Security Rule, along with the corresponding penalties. Subsection 13410(c) requires civil penalties that are collected under the HITECH Act to be funneled back into the Department of Health and Human Services' Office of Civil Rights enforcement budget, completing the funding "Circle of Life" for the system.

So if you're wondering why you can't get your health information I think it's pretty clear...

... you should probably thank our government.

-Wes

Monday, February 02, 2009

Doctors' Privacy Upheld

Today, the US Appellate Court shot down Consumer Checkbook's request for access to Medicare billing records:
Medicare billing records -- encompassing virtually every doctor's office -- are the mother lode of health-care data. Experts analyzing them can identify waste or poor quality care.

The nonprofit Consumers' Checkbook group had won a lower court decision to release the records. But a federal appeals court in Washington overturned it late Friday, saying doctors' privacy would be violated.
I wonder who these "experts" are that claim they can identify waste and poor quality care from billing records: no written record, just diagnosis and procedure codes. They surely must be smoking something...

Thank goodness the appeals court had the vision to not be swayed by marketing claims and overturned the earlier district court's ruling.

-Wes

Tuesday, July 03, 2007

Electronic Messages Are Part of the EMR

Quick quiz:

What exactly defines portions of the “medical record” in the electronic era?

(a) The patient's family history
(b) The physical examination
(c) The Medication Administration Record (MAR)
(d) Patient chest xrays
(e) Patient billing information
(f) Discharge summaries
(g) Operative reports
(h) Physician “In Basket” Electronic Messages within Electronic Medical Record (EMR) software (specifically defined as NOT "e-mail")
(i) Physician office e-mail messages outside of the medical record software.

Sadly, I learned today that for physicians who use an EMR, “all of the above” is the right answer. No longer can physician colleagues communicate electronically about a patient without fear that their electronic communications are “discoverable” in the eyes of the law. It seems physicians who have adopted the EMR have tactitly agreed that electronic messages are part of every patient's medical record.

I never learned that in medical school.

Back then, we just had the chart in our hands. We used to be able to go down to a medical record room we'd put in a request for a nice lady to "pull the chart." She'd return with a definable entity in her hands. Certainly, e-mail threads were not part of that record.

But in the electronic era, that no longer applies.

Certainly, the potential liabilities in e-mailing patients has been well-recognized. But messaging colleagues about your concerns or doubts about a specific treatment plan for a given patient? It seems that it's all potentially fair game for legally-minded interested third parties.

So if you're thinking about acquiring an EMR, beware. Being forewarned, you're now forearmed.

-Wes

Grand Rounds With an Eye on Transparency

Over My Med Body takes the honors this week.

In this mix was Colorado Health Insurance Insider's approach to taping conversations (mp3 recording - speakers required) with office staff when shopping for surgical procedure prices... I wonder what my office staff would say to these questions? Would their answers have been different if they knew they were recorded?

Empowerment of the health care consumer takes on new meaning, eh?

-Wes

Thursday, April 26, 2007

Patient Blogs Make HIPAA Unenforceable

HIPAA, the Health Insurance Portability and Accountability Act of 1996, contains privacy provisions that provide "protection" of patient's health care information to assure that health care providers, health plans, and health care clearinghouses don't leak such sensitive information in a public forum. You see, our legislature felt that doctors and health care providers might use such information to the detriment of our patients, so they made this law to allow government to reassure others that Big Brother could do a better job at protecting your privacy.

But now comes another realization: patient's family members might leak the informaton instead.

Patient blogs are now the rage at local hospitals here in Chicago, detailing play-by-play accounts of health care delivery and histories on patients themselves. You see, patients aren't covered by HIPAA. They can say what ever they want about themselves. But sometimes the patient isn't the one posting on the patient's blog, family members were, dutifully updating the daily progress of their loved one to the world.
"Many people have been inquiring about him so I would like to share some information with everyone," said the first in a series of near-daily updates posted by Nequin's wife, Dawn.

She described in detail how her husband had slipped on ice March 6 while walking the family dog, hit his head on the sidewalk and, nearly three hours later, asked to be taken to the hospital, complaining of a headache and weakness in his leg.

"Within minutes he was having a CAT scan, and in a few more minutes we knew he had a brain bleed," she wrote.
And companies providing these patient weblogs and message boards are springing up like 17-year cicadas:
TLContact Inc., the Northwest Side company that oversees CarePages, has created more than 50,000 such pages, according to a spokeswoman. CaringBridge, a competing service based near Minneapolis, and theStatus.com, a third major competitor based in Anchorage, claim roughly the same numbers of pages, most of them generated in the last few years as word has spread about their availability.

"Most people don't find out about them until a friend goes into the hospital and starts one," said theStatus founder Mark Pierson.

Such sites have been around nearly 10 years, are free, easy to use and fairly secure -- families can control access to them via passwords and invitation lists. Though the companies contract with hospitals for branding and promotional purposes, any patient anywhere can sign up and use any of the services.

They relieve family members and patients of the tedious job of telling the same story over and over, while the accompanying message areas become a forum for encouragement and prayers.

They offer an advantage for health-care professionals as well. Having the family post updates online allows them to skirt the awkwardness and even legal peril that newly stringent medical privacy regulations have added to such simple questions as "How's he doing?"
So in the future, if doctors or insurers get accused of violating the HIPAA provisions, they'll just look stupid and say, "Hey, I just read what I know about him on his patient blog!"

-Wes