Showing posts with label data-aggregation. Show all posts
Showing posts with label data-aggregation. Show all posts

Thursday, January 25, 2007

MHQP leads the way!

Karen Davis, President of the Commonwealth Fund, has released a report on Models for Achieving the Best Health System in the World. She highlights seven key strategies for improving the US scorecard on high performance health, and gives concrete examples of each.

This is generally a great read, but there's one item in particular that I want to call out. Here's number 5:

5. Increase Transparency and Reward Quality and Efficiency

Increase Transparency Case in Point: Massachusetts Health Quality Partners Increase Transparency

Public reporting of information on the performance of health plans and providers can spur improvements in quality and efficiency, by helping consumers make more informed decisions and by stimulating providers and plans to be more accountable for their results. It can also form the basis for new payment systems that reward providers for excellence and efficiency. Commonwealth Fund surveys indicate that most patients do not have access to the cost and quality information that would enable them to make informed choices, but they very much want access to such information.

Yet, a number of notable initiatives provide purchasers, consumers, and providers themselves with information about quality. With Commonwealth Fund and Robert Wood Johnson Foundation support, Massachusetts Health Quality Partners (MHQP) has publicly released clinical quality data as well as patients' ratings of their experiences with doctors' offices throughout the state. In addition, data on the clinical performance of primary care physicians in Massachusetts are now publicly available at the medical group level.

MHQP is a member of the MAeHC Board of Directors and key partners in our work going forward. Congratulations to Barbra Rabson and the entire MHQP team!

Tuesday, January 16, 2007

Identity theft and digital health records

This weeks’s Business Week has an article on medical identity theft (Diagnosis: Identity Theft). The article outlines three types of fraud that are apparently on the rise: 1) people who steal an identity to get treatment for themselves; 2) providers who steal an identity to submit fake claims; and 3) providers who misuse information they are entitled to have, in order to pad legitimate claims with fake claims.

Like a lot of articles in the area of patient privacy, I think this one touches on all of the right points but sensationalizes the issue with some egregious anecdotes and a few hyperbolic comments from “privacy advocates”. I’m also not sure how new some of this is. Identity theft certainly isn’t new, nor is fraud in medical claims. The Sopranos even had an episode a couple of years ago that was identical to one of the “new” types of fraud described in the article – organized crime “rings” using an ancillary healthcare provider organization to submit bogus claims. (Though according to HBO’s Mobspeak, Tony Soprano found the “taste” of medical fraud to be much less lucrative than racketeering or bookmaking.)

I’m not going to even try to answer whether our data is “safer” in digital health records, because this is unknowable, and anyone claiming otherwise isn’t being intellectually honest. The BW article gives short shrift to the ways in which electronic records will increase protection of patient information.

There are two different issues raised by the article: 1) how to prevent and detect medical fraud; and 2) how to prevent electronic health records from being used for identify theft (which may or may not be used for medical fraud).

It strikes me that EHRs can be helpful in preventing and detecting fraud in care delivery. The most obvious way is by giving a greater ability for “authentication” than is allowed by paper systems, in particular by incorporating photos in the medical record. Digital cameras are incredibly cheap and even the most simple EHRs and practice management systems allow photos to be attached to records. I’ve been a member of three athletic clubs over the last 2 years (including my local YMCA), all of which use photos for authentication every time I visit. It would hardly be an invasion of privacy for health care providers to do the same.

Electronic systems are also helpful in detecting fraud by providing the ability to identify “spikes” in activity that can then be followed up for validity (the article notes this). My credit card company does this now. A health insurer that does this could even use it as a positive opportunity to improve care, customer service, and relationship management – legitimate “spikes” in activity are the result of significant medical events, for which follow-up should be both welcome and appropriate. Honda Motor Corporation called me recently to ask how my local dealer performed during our last service visit. I wish Aetna would call me to ask how my doctor or hospital performed, not only when my activity has “spiked”, but after each visit I make (boy, would they get an earful).

Regarding identity theft, I think that EHRs could seriously reduce one of our greatest sources of risk – medical staff who abuse their privileged access to information. Good EHRs have role-based access, so that staff are able to access only that type of information appropriate to their jobs. Audit logs also allow tracking of access to records and monitoring of user activity. Paper records don’t allow such protections. And while such protections have been available in many hospitals for some time now, making them widely available in physician offices will put literally millions of medical records under a better security umbrella than they’re under today.

Of course, EHRs increase other types of risk by adding more to the amount of electronic data already swirling around the ether, so in that sense they do create greater incremental opportunities for some types of identify theft. This is true for any type of electronic data, however, and I'm not sure how much greater risk it adds on top of what's already out there. I was at Marshall’s department store the other day and they asked for my phone number as part of the payment process for a pair of socks (I didn't give my number to them but noticed that a lot of other customers gave theirs). I’ve also noticed recently that when I return items to Home Depot without a receipt the cashier swipes my credit card and does a search of everything I’ve ever purchased from them on my credit card before giving me a cash refund. I'm sure that these companies have privacy statements detailing what they do with this information -- I haven't bothered to read these statements, nor do I expect to any time soon.

The "digitization" of medical information is just another aspect of a general trend. We don't have to even discuss whether we should stop it, because I don't think we can -- the best protection for patients is to insist that EHRs get implemented in a way that accentuates their positive attributes and explicitly manages any additional risks that they introduce.

Monday, December 04, 2006

Do the right thing

Yesterday’s New York Times article on privacy and security of electronic health records, coupled with an article in the Wall Street Journal last week on WalMart’s foray into electronic health records, points to what could be an ominous twist in the movement to expand the use of EHRs and health information exchange in health care delivery. Large businesses -- burdened by spiraling costs of health cost premiums -- are increasingly investing in technologies to gather health information on their employees to try to more directly manage (and, they hope, stanch) the growth of these costs.

I completely sympathize with the plight of these businesses -- MAeHC is a small business, after all. I also applaud their recognition of the key role that EHRs and clinical IT can play in improving health care delivery. Yet, their whole approach raises serious concerns for patient privacy. By creating proprietary systems to gather and control the health data of their employees, these companies are, perhaps unwittingly, stumbling into the most important and fragile issue in the health IT debate.

There is an irony in all of this. Some existing privacy laws, which were designed for paper-based records, don't make sense in an electronic world, and indeed, are in some cases presenting obstacles to better management of electronic data in ways that no one could have anticipated at the time. Many of those laws were designed to prevent employers from getting access to sensitive information that could affect a person's employment status. Employers need to be hyper-sensitive to those concerns. If they appear to be violating the spirit (even if not the letter) of those laws, it will sow seeds of patient distrust and perhaps draconian laws that will undermine not only their own efforts but also the many community-based efforts around the country that are working hard to do this the right way, namely, using IT to empower physicians and patients to improve the cost-effectiveness of care.

While there is a crying need to bring modern IT systems to health care delivery, this effort won’t be economically or morally sustainable if it’s not based on trust. Patients and physicians have to trust the systems being created. Otherwise, patients won’t agree to having their data in these systems, and physicians won’t agree to using them because they’re concerned about their patients’ privacy and about the legal liability associated with breaches of confidentiality. But neither patients nor physicians will trust these systems if they aren’t set up with privacy as a fundamental design consideration, rather than a bolt-on afterthought.

The reason that employer- and insurer-based schemes are problematic is that they undermine what I think of as a core principle of health information exchange – the need to create the healthcare equivalent of a Chinese Wall between those who collect and aggregate the data on behalf of providers to facilitate direct care delivery, and non-providers who would use the data for any purpose other than direct treatment of patients. Just because electronic data is more easily available for treatment purposes doesn’t mean that we permit it to be more easily available for other purposes. Data collection and aggregation may happen in a new way (ie, using EHRs and secure networks), but access has to happen the old way (ie, explicitly negotiated among the owners and key stakeholders). This is the principle behind such leading community-based efforts as the MA-SHARE, RIQI, IHIE, HealthBridge, THINC, and MAeHC.

So how do you do that? Create, operate, and govern these systems by building on the trust engendered in today’s physician-patient relationship. Patients have a well-placed trust in their physicians. Physicians will only use the systems if they’re valuable from a user design perspective and they promote their patients’ welfare. Rather than setting these systems up as proprietary company systems, they need to be set up more like public utilities. Put hospitals, physicians, and patients in joint control of these systems so that they are designed, managed, and governed by those who are going to be using the systems. These key stakeholders will get behind investments in “wiring” the care delivery system to improve quality, safety, and efficiency; what they won’t get behind is investments whose primary aim is surveillance.

I suggest that employers should get out of the business of trying to electronically capture their employees’ detailed health information, and into the business of getting health care providers to embrace information technology that improves the quality, safety, and efficiency of care. It's fair for them to want better data to measure performance, but they can get that without demanding access to detailed patient information. They can create urgency for better system performance using basic supply chain management principles that they're very familiar with: Invest in their healthcare delivery supply chain by setting basic technology and interoperability requirements for their suppliers (ie, providers), and facilitate their providers’ ability to meet these standards.

So, the program would run as follows. First, require physicians to use EHRs, help physicians pay for the upfront costs of getting outfitted with solid EHR systems, and train them and their staff to use the systems effectively. Second, require them to participate in data exchange networks that facilitate the effective coordination of care and the efficient transmission of clinical information. Third, put in place a new funding model that redirects reimbursement toward paying physicians for improving peoples’ health and away from paying them for the volume of care delivered and/or complexities that arise with their patients due to poor physician performance.

All of this is, of course, easier said than done, and no one knows that better than those of us slogging away in the trenches. But if Walmart and Pitney Bowes and IBM and UPS spent more time working with existing community-based efforts, and less time building their own proprietary data warehouses, it would happen faster than they might think, and it would be lasting and sustainable. There are many community-based efforts out there trying to do just this, and they could benefit enormously from the resources (financial, technical, and managerial), encouragement, and old-fashioned kick-in-the-pants that only the business community can provide.

I think the message employers should send to their employees is: “We don’t want your personal health data, but it's in everyone's interest to better monitor the overall performance of our insurer/provider network because the quality, safety, and cost of health care affects all of us.” That would reinforce the message that they’re not trying to undermine the sanctity of the doctor-patient relationship, but rather, trying to improve the performance of the overall system to better serve physicians, patients, and purchasers alike.

Thursday, November 30, 2006

Hi, I'm from WalMart and I'm here to help.....

Yesterday’s WSJ reported on a WalMart/Intel collaboration in digital health records. I don’t have a well-formed opinion yet on whether this is good news or bad news for the HIT adoption effort that many of us are engaged in, partly because the article didn’t provide a whole of detail on what this collaboration is actually doing. So let me proceed, but with caution. John McDonough asks whether this might be a “disruptive technology”. I don’t think so. He also asks whether this will complement the work of MAeHC and others involved in promoting HIT adoption. I do think so.

On the technology question, it’s not obvious what’s meant by “digital records for employees” and “portable electronic records.” Patients don’t document medical care, physicians do. And only 10-15% of physicians have EHRs, and most of the country’s 7600 hospitals don’t have accessible data either, so unless this is really a program giving digital records to physicians – and then giving patients access to those records – I don’t see how patients will benefit much.

Perhaps the WalMart model will be based on models that are already out there for the two types of data that are already electronic: claims and prescriptions. Health insurers are well down the road toward providing claims-based PHRs for patients, and AHIP has even brokered a deal for portability of the data across health plans. Revolution Health is going to build a portal that allows patient access to health financial information and health education information. KatrinaHealth is a patient-centric digital record of prescription information. None of these incorporate any hospital or physician information (ie, what we typically think of as our medical records) for the same reason noted earlier, namely, the data isn’t accessible electronically.

So, I don’t think this is a “disruptive technology” from a technical or innovation perspective – I personally don’t believe that there’s a technology magic bullet out there (though we all keep wishing for one!). The main obstacles, as always, are structural (our health care delivery and financing system is broken) and cultural (providers are notoriously independent and resistant to change, and patients think they get the best care in the world, even though there’s tons of evidence that they don’t).

I also don’t think it’s a “shift left” a la Andy Grove. You can’t get data out until someone puts it in, so I don’t think there are any good shortcuts here. It also has to be good data -- you can’t aggregate data that isn’t structured, so having physicians use word processors rather than real EHRs won’t facilitate data warehouses and will actually set them back 10-15 years. I agree that we don’t want to have complex technology be a barrier to adoption, but it needs to be sophisticated enough to deliver value.

That said, I do think this WalMart effort might exert “disruptive pressure” which could push the agenda forward and be very helpful to efforts such as MAeHC. The problem in HIT is that there’s no compelling reason for physicians to adopt EHRs or for providers to link up their systems once they have them. Most efforts to date have focused on the supply-side (ie, providers) because there’s been no real pressure from the demand-side (patients and employers, and their proxies, the insurers). Pay-for-performance may be an indirect means of forcing technological transformation, but it’s indirect. By contrast, when working with their other supply chains, WalMart, GM, Intel, and others insist that their vendors set up electronic data interchange systems that allow real-time inventory management, order management, delivery tracking, etc. If employers start thinking of their health care supply chain in the same way – and require that providers have EHRs and interoperability – they will fundamentally alter the pace of change by creating urgency, where none really exists today. Patients will be the main beneficiaries in the end.

I think it’s fair for all of us to be concerned about anything related to healthcare that WalMart is involved in, because their business success is based on cost-reduction, not on maintaining high quality products or service, and they apply this approach to their suppliers and to their employees alike.

I also worry that there could be an element of coercion in their model as described. Will they derive revenue from selling the de-identified data from the warehouse? Will they ask patient permission to sell this data (HIPAA doesn’t require it)? Will they share the revenues with their employees? My fear is that the answers to these questions aren’t on the side of their employees. WalMart of course would argue that the data is theirs since they’re holding it, paying for it, and de-identifying it (I guess possession is 9/10 of the law, or something like that). Yet another reason that we should move away from our system of employer-sponsored health benefits, but I’ll wait for John McDonough to open up that can of worms……