Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Saturday, February 14, 2009

Darn, I'm a breach victim......

I just got the following email.
Important Message from Pentagon Federal Credit Union
Ref. Card Number
Ending In: XXXX

Dear Member,
Visa Fraud Control has recently notified us that your Pentagon Federal Credit Union Visa credit card account number, name, expiration date, and CVV (a three-digit verification value on the magnetic stripe of the plastic) may have been compromised in a processor level breach at Heartland Payment Systems, Inc. Heartland Payment Systems, Inc. is one of the nation's largest payment processors delivering credit/debit/prepaid card processing, payroll, check management and payments solutions. Heartland has dedicated a website, www.2008breach.com to provide additional information on the breach.

Information pertaining to your other Pentagon Federal Credit Union account(s) has not been associated with this event or compromised in any way. The compromise did not occur at Pentagon Federal Credit Union nor did it involve any of our systems. All of your Pentagon Federal Credit Union account information remains absolutely secure.

We continue to take all necessary precautions to safeguard and monitor your Pentagon Federal Credit Union accounts to protect against unauthorized activity. We have provided a series of frequently asked questions below that provide additional details and tips.

Please review them and if you would like to receive a new card with a new account number, please use the instructions provided below. You may reach us toll free at 800-247-5626 or online at PenFed.org.

If you have recently closed the referenced card, please disregard this correspondence. We apologize for any inconvenience this may cause. We appreciate the continued trust you have placed in Pentagon Federal Credit Union. Thank you for remaining a valued member.

Sincerely,
Vincent Gay
Director, Security
Pentagon Federal Credit Union


In this simple email we see the complexity of breach notification. Let me say for the record that I love PFCU -- I've been a member of PFCU for many years and will continue to be for many more.

On the negative side of this notification is the ambiguity. My information "may have been compromised" -- not sure if it actually was, so I'm not sure what the actual risk is. They're fulfilling a legal and/or ethical obligation to tell me the nature of the breach, but are they really helping me by telling me that it's a "processor level breach", without further explanation? And how am I as a consumer supposed to assess my level of exposure? Does this mean that there was an actual intrusion of Heartland's environment, or that they discovered a security hole that could have been entered without their knowledge but they really have no idea whether it was.

On the positive side, I'm alerted, so I myself can keep my eyes open for suspicious activity.

This notification was for a relatively simple incident in a disciplined corporate setting, and it still raises more questions than it answers. Makes me wonder about how we're going to strike the right balance as we move to stricter breach notification regimes in health care.....

Wednesday, November 28, 2007

It takes more than money

Just about a year ago I wrote about Britain's Connecting for Health program's privacy policy or, more appropriately, their lack thereof. Their approach at the time can best be described as "opt-NOT" -- patients getting care through the NHS would automatically have their data shared on the "Spine" (the national HIE). No fooling around with the niceties of opt-in vs opt-out -- patients could only opt-out by opting out of getting their care from the publicly-funded health service that they pay dearly for.

The NHS has since backed off from this stance and now allows an opt-out policy. That's still a far cry from the opt-in approach taken by MAeHC, and in the context of a burgeoning US movement toward "personally-controlled" health data management, it's downright archaic.

The latest report is that despite this change in policy, physicians themselves are rebelling against the system: 2/3 of NHS family physicians say that they will boycott data-sharing in the system according to a recent poll (see Family doctors to shun national database of patients' records). In a country where individuals have historically deferred to the government on issues of information access, this is a pretty stunning development.

Our policy in the MAeHC project is to allow patient opt-in, meaning that no information will be made available to other entities without the specific permission of patients. Our current opt-in rate is about 93%.

While an opt-in approach clearly has some short-term risks -- such as, slower adoption of systems by physicians, delays in achieving the benefits of clinical data-sharing -- it provides a firmer foundation for the overall enterprise. In the end, we won't be able to reap the benefits of clinical integration unless we build systems that both patients and clinicians can trust.

Thursday, October 25, 2007

The challenges of secondary uses of data

Part of the presumed value of greater health information exchange lies in so-called "secondary uses" of data, i.e., using patient data for activities that go beyond payment/treatment/operations, such as bio-medical and health services research and clinical trials. Many health information exchanges (including those sponsored by MAeHC) have taken an "opt-in" approach to data exchange, whereby a patient's information cannot be disclosed to "the network" without prior permission of the patient.

This has left open the question of what to do about secondary uses of de-identified data, however. HIPAA does not require patient permission if the data being used is fully de-identified, and many HIE projects are operating on the presumption that secondary uses are okay as long as they release only de-identifed data, which HIPAA allows them to do.

I've been in an increasingly large number of conversations with HIE projects around the country who are saying that even though HIPAA allows it, they're going to ask for blanket permission from patients before they release even de-identified data. And they're hoping that this "belt and suspenders" approach fully protects their activities.

Some new work sponsored by the Institute of Medicine suggests that this approach may be the minimum requirement for satisfying increasing patient demands for privacy protection (see Striking a balance between privacy and health). Of over 300 patients surveyed:
  • 38% said that they'd want researchers "from each research study....to first describe the study to me and get my specific consent for such use";
  • 19% would allow use of de-identified data without consent as long as the research was overseen by an IRB;
  • 13% would not want their data used for research "under any circumstances";
  • 8% said an upfront "general consent" would be enough for use of their data in future research projects;
  • 1% said researchers could use their data without their consent

The implications are pretty startling. We have a serious disconnect between what the law allows and what patients want (and expect). Over 80% of people would NOT want their data to be used for research without their consent, even if it was de-identified and overseen by an IRB. And while it's hard to read from the survey's summary data, a large fraction may want some type of consent for each use.

There's a lot of hope that health trusts and personally controlled health records will solve all of this by giving patients ultimate control of their health information. We're a long long way off from being able to give patients that type of control, so we'll be facing these issues for a long time to come.

There's obviously no "right" or "wrong" here because it is what it is. On the other hand, we should always be cautious about surveying people about abstractions -- a little education and concrete experience may change people's perceptions dramatically. That said, the threshhold on privacy protection is clearly getting higher, and what may have seemed like conservative approaches to privacy protection yesterday may become barely adequate tomorrow.

Wednesday, October 24, 2007

George Clooney's heart's in the right place, but his head isn't

One of my favorite news sources, People magazine, is reporting that George Clooney thinks that the Palisades Medical Center should go easy on the 40 employees who illegally looked at his medical records (see George Clooney Addresses the Leak of His Medical Records). The employees have been suspended without pay for a month. While I love Mr. Clooney as an actor, and am very sympathetic with his politics, on this one I think his compassion has gotten the best of him.

Unauthorized disclosures of patient information happen all the time. Most of the time it's unintentional and no harm is done. With intentional disclosures, there is a temptation to tailor punishment to motive -- specifically, to separate cases where a person looks at a record "with malice" from cases where it's "without malice". That's clearly what's going on at Palisades, and implicitly, in Mr. Clooney's head. I assume that the punishment would be different if an employee was found to be stealing Clooney's identity, or looking for his address or phone number to stalk him.

As more health care institutions convert to electronic medical records, there is increasing concern about privacy protection, and most of that concern is understandable and well-placed. The enormous benefits that can come from greater use of EMRs will go unrealized if we adopt a cavalier attitude on technologies and policies related to patient privacy. Suspending workers without pay in this case strikes me as being unbelievably lenient. If I was a patient at Palisades Medical Center, I would switch immediately to an institution that has greater respect for the trust that I've placed in them as the custodian of my records.

Monday, March 19, 2007

"Free" EHRs: A Faustian bargain on patient privacy?

One of the biggest barriers to wider adoption of electronic health records (EHRs) is affordability. Regardless of whether you "rent" (ie, pay a monthly fee for access to a web-based product) or "buy" (ie, purchase a license to put the software on your own computer), the first-year costs for a respectable system are $15K-$25K per clinician. It was inevitable, therefore, that some "free" products would enter the market. As it turns out, there's no such thing as a free lunch.

First came a non-commercial alternative, VistA-Office, which the government has already paid for. VistA-Office is the office-based version of the VistA system that has been so successfully deployed in the US Department of Veterans' Administration, and it can be downloaded without charge from a non-profit, government-sanctioned vendor called WorldVistA. Of course, there's more to the cost of an EHR than just the software, so though the license is free, a potential user would still have to pay for hardware, implementation, training, support, and maintenance. Nevertheless, it's always great, and economically efficient, when the government is able to create commercial spin-offs from work it's already funded.

If VistA-Office can be thought of as a non-commercial approach to "free" EHRs, Practice Fusion, a San-Francisco-based startup is its hyper-commercial opposite. Launched last August, the company's original plan was to offer their EHR without charge in return for access to the deidentified clinical data generated by users, which the company would sell to pharma companies, insurers, and researchers. If that isn't controversial enough, the company announced last Friday that they'll be partnering with Google's advertising arm, AdSense, to put context-sensitive ads on the EHR in real-time. As described in the San Francisco Chronicle: "When a doctor using the service calls up a patient's health record, AdSense will recognize certain keywords -- such as "diabetes" -- and ads related to that condition will appear on the page."

I assume that all of this is HIPAA-compliant, though it would take some convincing that no places or dates of service are being compromised when ads are being delivered to a physician's EHR in real-time based on what they type into the system. And we haven't event talked about state laws yet.

Regardless of whether it's legal, this approach does pose issues for physician-patient trust. For example, does a physician really know what they're getting into? The slippery slope has already been demonstrated. In August, the story was:
The “completely hosted, community-based model” EHR will be subsidized on the back end by selling de-identified data to insurance groups, clinical researchers and pharmaceutical companies, said CEO Ryan Howard.
Now, seven months later, it's clear that selling data isn't going to generate enough revenue.

Practice Fusion's deal with Google is what makes a free medical records system possible. Google's AdSense program will generate ads that will be displayed as the records system is used.
What's next if that doesn't work? If I'm already using the product, do I get a say in how it's expanded? If I don't like that, is my only option to leave, with all of the switching costs that that would entail?

Practice Fusion claims that health insurers will be eager to get into this action as well. Insurers have a hard enough time trying to keep patients on their formularies. How much harder will that be when drug ads are being inserted into the physicians' thought process at the point-of-care?

Purely on a user-interaction level, I'm not sure how many physicians will like having ads on their screen (actually, I am sure but I don't have any data to back me up). It's already a challenge to figure out how to present meaningful medical information on a screen without overloading the user. Dynamic ads won't help that.

Finally, but most important, how will patients feel about this? The first time a patient sees a Paxil ad pop up on his physician's screen, the questions will start flying. And the physician will be in the awkward position of saying that those ads don't affect his/her decision-making, that the company generating those ads is Google, but not to worry, through the magic of technology, Google has no access to private medical records (and the physician will be crossing his/her fingers hoping that that's true).

Practice Fusion's CEO says that "he does not expect data-sharing will be a concern to physicians who accept the free EHR." If that's true, it's only because they haven't asked their patients yet.

Wednesday, March 07, 2007

Question: Do you know where your credit card info is? Answer: Literally, everywhere.

Those of us in health care IT are obsessed with security, and rightly so -- we're dealing with some of the most personal information imaginable, and none of this works if it doesn't engender the trust of patients and physicians alike. So, I guess I'm more attuned to security policies and technologies than any normal person ought to be.

With that in mind, I was intrigued by the story that the restaurant chain Ruby Tuesday is moving to an "ultra-secure credit card processing system". (Maybe it's just me, but their adding the word "ultra" here doesn't make me feel better -- reminds me of Animal House, when Dean Wormer puts Delta House on "double secret probation"). As described by the company's hometown newspaper, The Daily News Journal, the system "leaves no credit card information at the restaurant and is instead sent to the bank in encrypted form."

I'll bet that most people would be surprised to learn that they weren't already doing this. You kept my credit card information? But you already got your money -- who gave you permission to keep it beyond that. You're going to start using encrypted communication? You mean, you don't do that now???

A USA Today story on the same topic reports that some restaurants like Hooters and Legal Seafoods are now looking at using mobile credit card systems that allow the credit card transactions to happen at your table. (Many possibile jokes here -- I'm not going there.) I was in Europe last summer with my family and I noticed that every restaurant we went to in Spain and France had such devices. I don't know why the US is so far behind.

The story also reports that Massachusetts (my home state) is considering a law that would penalize companies for credit card data breaches. That's interesting, because Massachusetts is one of a minority of states that doesn't have a breach notification law today (please see: Massachusetts among 16 states that don't have breach notification laws).

I've written before about my personal experiences at Marshall's and Home Depot where I learned how much info they keep (please see: Identity theft and digital records). Think of all of the loosely protected mini-repositories of credit card info out there -- basically every store you go to -- and how much of that information is flying through the ether without basic encryption protections. Patients and physicians should take comfort knowing that modern health IT systems and processes aim higher than that.

Wednesday, February 28, 2007

What is the federal approach to privacy and HIT?

While I was away on vacation last week, HealthcareITNews published the following: "Federal privacy panel leader resigns, raps standards". It describes how privacy expert and advocate, Paul Feldman, has resigned his position as co-chair of the Confidentiality, Privacy, and Security Workgroup of the American Health Information Community (AHIC).

For those of you who don't know, AHIC is an advisory group -- chaired by HHS Secretary Mike Leavitt -- that is supposed to make recommendations to the federal government on how to accelerate HIT adoption. Since 9 out of its 18 members are federal or state government employees, I'm not sure how much of a "community" it really is, but that aside, it's chaired by the Secretary himself so it's clearly important. (Then again, since the government is responsible for 2/3 of all health care spending in the US, maybe the government is under-represented on this panel. And maybe we should more seriously consider a single-payer model since we're almost there anyway. But I digress.....)

It's hard to know from the outside what's really behind public resignations of this type, but the very fact that it's happened is not good. Feldman's letter of resignation cites the following:

We have determined we are unable to continue given that the workgroup has not made substantial progress towards the development of comprehensive privacy and security policies that must be at the core of a nationwide health information network (NHIN)...We support the development of an NHIN with strong and enforceable privacy and security rules in place and believe that the failure to achieve a privacy framework acts as a significant barrier to a robust and secure environment for e-health.

It would be one thing if this was an isolated incident. Unfortunately, it comes on the heels of a GAO report whose title says it all: "Health Information Technology: Early Efforts Initiated but Comprehensive Privacy Approach Needed for National Strategy". And last summer, the National Committee on Vital Health Statistics issued a report with similar findings.

While I wouldn't say this is much ado about nothing, I do think it's much ado about the wrong thing. Both Feldman and the GAO focus on the need for standards for a national network, citing President Bush's goal of having this in place by 2014.

As interesting as that discussion might be, I don't think an interoperable national network is going to happen by 2024, let alone 2014. Indeed, we don't even know what we should argue about because we don't know what such a network would look like, let alone when it would be created. For example, if the only justification for a national network is to aggregate deidentified data for population health measurement, there are a whole host of issues that we don't have to argue about. Worrying about too many of these details now is like fretting over relocation policies for coastal communities displaced by rising seas from global warming -- let's worry about it if the time comes.

Where we should focus attention is on where the action is: state- and local-networks. Many such networks will be up and running in the next few years (including three MAeHC networks before the end of this year). Yet, there is tremendous variation in state privacy policies at present. For many states, HIPAA is the binding constraint. For others, like Massachusetts, state privacy standards are much higher.

Anyone putting systems in place right now is basically making up a whole bunch of stuff as they go (with varying degrees of diligence). They're doing this because they have to. Federal and state laws aren't nearly clear or detailed or coherent enough, lessons learned in one state don't always translate to other states, and the urgency to get systems in place won't wait for the law to catch up.

Yet, the question remains, shouldn't a citizen of Louisiana or Ohio expect to have the same basic privacy protections as a citizen of New York or Massachusetts? That question won't be answered by setting policies for a national network that may never be built -- rather, it requires discussion of how to regulate state- and local-networks that are already being built, and in particular, on whether HIPAA and other federal privacy statutes and regulations provide an adequate floor of privacy protections for such networks.

The federally-sponsored Health Information Security and Privacy Collaborative (HISPC) is currently doing an inventory of state-level privacy policies, which is a necessary step in the right direction. (The MA-HISPC project is doing this work for Massachusetts.) The first results from this work are going to be presented in Washington on March 5-6. Whether this work is progressing nearly fast enough to address what's already happening on the ground remains to be seen.......

Saturday, February 10, 2007

Massachusetts among 16 states that don't require notification of data breaches

A new survey published in the Journal of the American Health Information Management Association made me aware of something that hadn't caught my eye before. Massachusetts, my home state, is one of a minority of states that DOES NOT have a data security breach notification law. California, which enacted its law in 2003, has the strongest such law in the country and was the inspiration for many other states' laws. In 2006, 27 states had such laws; beginning on January 1, 2007, 7 more state laws went into effect. But not in Massachusetts.

I'm not sure how much such laws do -- in Massachusetts, for example, TJX recently reported a huge data spill despite the fact that we have no such law, and according to a recent survey by PricewaterouseCoopers, as many as 1 out 6 companies required to comply with the California law do not do so.

Ironically, the market may be taking care of this in ways that it hasn't been able to before. TJX stock plummeted after the Massachusetts Bankers Association directly linked cases of fraud to the data spilled by the company (click here for an interesting description of this).

There is much talk about the need for more transparency in the healthcare market. Most healthcare organizations aren't publicly traded, of course, but the idea is that patients will vote with their feet if they see meaningful differences in health care quality among providers. If data breaches start becoming more widely reported, data security could become another factor that patients use to decide where they get their care.

Wednesday, January 31, 2007

Up next on Fox News! Dr. John Halamka!

It's nice to have a luminary as your front man. Dr. John Halamka -- a founder, advisor, board member and friend to MAeHC -- was on Fox News (live!) yesterday discussing our North Adams project (click here to check it out).


The interview focused on privacy concerns, but of course it wouldn't be Fox News without equal parts sensationalism and distortion:

"A person's private health records are about to become public in one local city, North Adams, Massachusetts."

Just to set the record straight, we are NOT making health records public in North Adams. Let me rephrase this in case there's any confusion: We are NOT making health records public in North Adams. Or in Brockton. Or in Newburyport. Or in any other community that MAeHC sponsors.

What we are doing is launching a health information exchange that will allow medical staff, with patient permission, to exchange health information for treatment purposes and for the improvement of care. This exchange will occur over a private, encrypted network that can only be accessed by authorized medical staff users.


Anyway, as expected, John handled the interview beautifully. Gave the issue the appropriate balance, described the security measures we're putting in place, stressed that patients will choose whether to participate, and finally, crisply explained why a patient might want to make that choice.

By the end he even had the interviewer admitting that it would be good to have health information available in this way. It was particularly impressive given that he was crammed in between stories on a student who wants to rent a girlfriend, and what's happening on American Idol.

Thank you, John, for so eloquently getting out the message on MAeHC's approach to patient privacy and health exchange. But next time, please try to get in before the girlfriend rental story....

Tuesday, January 30, 2007

North Adams in the news

Today's Boston Globe has a front-page article on MAeHC's North Adams project. The trigger for the story is the launching, next month, of the first comprehensive, community-wide health information exchange in the country.

I think the reporter, Liz Kowalczyk, did an excellent job of capturing a pretty complicated story. The article accurately describes our approach to privacy and security, and the reach-out that we've done to get patient permission. There are some great interviews with patients as well.

I have only two quibbles with the article. First, it exaggerates the income loss that physicians participating in the program have experienced during the transition to their EHR systems. The article claims that physicians have reduced patient loads by "20% to 50%" during the first month. In fact, the vast majority of practices in the project are back at 100% within 2 weeks of going live. And for a capacity-constrained community like North Adams, this isn't a permanent income loss, because some of those patients get crammed into the schedule in weeks 3, 4, and 5 -- they have nowhere else to go, after all. I'm not saying that they don't have some permanent income loss, because they do -- it's just not as high as the article claims.

My second quibble is that the story doesn't focus enough on the key role played by the community to make this a success. Health information exchange isn't going to happen at a state-wide level before it happens within communities. And that requires higher EHR adoption and the creation of local, sustainable HIEs. The article focuses too much on the state-wide network, which isn't where the action is......yet. There's no case for a state-wide (or national) network until we have greater adoption at the local level, as was made clear at a recent national conference sponsored by the federal government.

Nationally, 30 percent of EHR implementations end in failure -- the MAeHC communities won't have anywhere near that level. And that's not just dumb luck. High adoption requires more than just money -- it takes a community.

In each of our communities, MAeHC has created a community steering committee to oversee and monitor the program, community user groups (physician- and staff-level), centralized implementation and IT support, consumer councils to get patient input, and group training sessions -- all of which are helping to get a high level of adoption. It's not the technology that's the real innovation in North Adams, or Brockton, or Newburyport -- it's the greater sense of community, among physicians and patients alike. You don't get that with random acts of technology -- you get it by engaging a community in a conversation about how to use technology to improve their lives.

In the end, these are tiny quibbles -- I think the article was terrific, and we greatly appreciate the Globe's interest in the story. WBZ radio's interest was a little less welcome in their unexpected 6 am call on my home number this morning. Fortunately, I was already awake -- we appreciate their interest as well.......

Tuesday, January 16, 2007

Identity theft and digital health records

This weeks’s Business Week has an article on medical identity theft (Diagnosis: Identity Theft). The article outlines three types of fraud that are apparently on the rise: 1) people who steal an identity to get treatment for themselves; 2) providers who steal an identity to submit fake claims; and 3) providers who misuse information they are entitled to have, in order to pad legitimate claims with fake claims.

Like a lot of articles in the area of patient privacy, I think this one touches on all of the right points but sensationalizes the issue with some egregious anecdotes and a few hyperbolic comments from “privacy advocates”. I’m also not sure how new some of this is. Identity theft certainly isn’t new, nor is fraud in medical claims. The Sopranos even had an episode a couple of years ago that was identical to one of the “new” types of fraud described in the article – organized crime “rings” using an ancillary healthcare provider organization to submit bogus claims. (Though according to HBO’s Mobspeak, Tony Soprano found the “taste” of medical fraud to be much less lucrative than racketeering or bookmaking.)

I’m not going to even try to answer whether our data is “safer” in digital health records, because this is unknowable, and anyone claiming otherwise isn’t being intellectually honest. The BW article gives short shrift to the ways in which electronic records will increase protection of patient information.

There are two different issues raised by the article: 1) how to prevent and detect medical fraud; and 2) how to prevent electronic health records from being used for identify theft (which may or may not be used for medical fraud).

It strikes me that EHRs can be helpful in preventing and detecting fraud in care delivery. The most obvious way is by giving a greater ability for “authentication” than is allowed by paper systems, in particular by incorporating photos in the medical record. Digital cameras are incredibly cheap and even the most simple EHRs and practice management systems allow photos to be attached to records. I’ve been a member of three athletic clubs over the last 2 years (including my local YMCA), all of which use photos for authentication every time I visit. It would hardly be an invasion of privacy for health care providers to do the same.

Electronic systems are also helpful in detecting fraud by providing the ability to identify “spikes” in activity that can then be followed up for validity (the article notes this). My credit card company does this now. A health insurer that does this could even use it as a positive opportunity to improve care, customer service, and relationship management – legitimate “spikes” in activity are the result of significant medical events, for which follow-up should be both welcome and appropriate. Honda Motor Corporation called me recently to ask how my local dealer performed during our last service visit. I wish Aetna would call me to ask how my doctor or hospital performed, not only when my activity has “spiked”, but after each visit I make (boy, would they get an earful).

Regarding identity theft, I think that EHRs could seriously reduce one of our greatest sources of risk – medical staff who abuse their privileged access to information. Good EHRs have role-based access, so that staff are able to access only that type of information appropriate to their jobs. Audit logs also allow tracking of access to records and monitoring of user activity. Paper records don’t allow such protections. And while such protections have been available in many hospitals for some time now, making them widely available in physician offices will put literally millions of medical records under a better security umbrella than they’re under today.

Of course, EHRs increase other types of risk by adding more to the amount of electronic data already swirling around the ether, so in that sense they do create greater incremental opportunities for some types of identify theft. This is true for any type of electronic data, however, and I'm not sure how much greater risk it adds on top of what's already out there. I was at Marshall’s department store the other day and they asked for my phone number as part of the payment process for a pair of socks (I didn't give my number to them but noticed that a lot of other customers gave theirs). I’ve also noticed recently that when I return items to Home Depot without a receipt the cashier swipes my credit card and does a search of everything I’ve ever purchased from them on my credit card before giving me a cash refund. I'm sure that these companies have privacy statements detailing what they do with this information -- I haven't bothered to read these statements, nor do I expect to any time soon.

The "digitization" of medical information is just another aspect of a general trend. We don't have to even discuss whether we should stop it, because I don't think we can -- the best protection for patients is to insist that EHRs get implemented in a way that accentuates their positive attributes and explicitly manages any additional risks that they introduce.

Saturday, December 16, 2006

We don't know what we don't know

Two friends recently sent me emails alerting me to security breaches in the health care industry. Since MAeHC is launching health information exchanges in 3 communities beginning in early 2007, we're very interested in such news.

One breach was a theft of back-up tapes containing medical claims of 130,000 Aetna subscribers (my health insurer!). The other breach came from the theft of a laptop with medical information of 38,000 Kaiser Permanente members in Denver.

I found out about these within the same week (they actually occurred about 1 month apart), and it got me wondering about the incidence of such events generally, and whether it might be getting worse as more data becomes electronic.

There's been a steady drumbeat of news on such breaches since the infamous ChoicePoint blunder in 2005, and the US recently crossed the dubious milestone of 100 million security breach victims since the counting began with Choicepoint.

The best (and most accessible) data I'm aware of is maintained by the Privacy Rights Clearinghouse, which tracks breaches on its website. My quick-and-dirty assessment of the data on the website suggests the following:

The frequency of all reported breaches is increasing. 413 reported breaches in the last 2 years -- 106 in 2005 and 307 in 2006.

Health care providers are a very small part of the problem. Sources of breaches breaks down as follows -- non-clinical commercial enterprises (37%), federal/state/local government (29%), universities (25%), hospitals and ambulatory providers (9%).

Breaches involving medical data may be increasing. 16% (69) of these breaches involved health data, but this share almost doubled over time, from 11% of breaches in 2005 to 19% in 2006.

Most medical breaches are committed by hospitals and the government. Hospitals accounted for most medical breaches (39%), followed by government (20%), health insurers (13%), physician offices (10%), and universities and ancillary services (9% each).

Big breaches involve institutions that have a lot of data. The biggest breaches by far in terms of number individuals affected have been by banks and by the government, which one would expect since they are the institutions that have a lot of data.

Most reported breaches do not seem to involve theft of data for the data itself, but rather, they involve theft or improper destruction of files, tapes, and computers that happen to have private data in them. Not to dismiss the importance of breaches, but the actual damages resulting from these breaches are likely much much smaller than the gross numbers suggest.

There are all sorts of cautions with making too much of this data: is this better reporting or higher frequency of actual breaches? what other types of breaches never get reported? is it higher incidence as well as higher frequency? is the reporting consistent across sectors and over time? are the differences statistically significant (both across sectors and over time)?

Assuming the data are somewhat representative of reality, they seem to highlight some important points for EHRs and health information exchange.

First, the world is full of data repositories. Financial institutions, the government, universities, hospitals, health insurers -- all hold huge stores of our personal information already. The discussion of whether to have a repository in an HIE needs to be had in that context.

Second, what's not reported is at least as important as what is. MAeHC's experience with health care providers is that bigger organizations like insurers and hospitals have a very small frequency of big data spills, which get reported, and small organizations such as physician offices have a high frequency of tiny data spills, which never get reported. Also, it's pretty well known that one of the biggest sources of breaches are insiders, who are often found out but are not publicly reported (for example, this week's Information Week article, the ongoing problem of medical staff trying to peep at VIP's medical records, and the now well-known story of the Diva of Disgruntled who posted confidential information of Kaiser Permanente patients on-line).

Third, breaches seem to be committed by organizations of all sizes and levels of sophistication. Physician offices -- as they become more interconnected with each other and with existing repositories of data -- could add many more chinks to the health data security armor. This isn't because they're irresponsible, it's because they don't have the staff or experience to even know how to address it.

For example, how many physician offices have already gone to Staples, bought a $30 Linksys box, and set up a wireless network that they don't realize is akin to leaving their medical charts in the parking lot in front of their office? How many are remotely accessing their computers using retail products and services that don't have industry-standard authentication and encryption? They haven't really had to worry about all of this up until now, because they're protected by the high friction of exchanging paper records -- the very same friction, by the way, that prevents huge improvements in quality, safety, and cost of care.

We need to get rid of this friction, of course, because the benefits are so huge, but it has to be done under some type of policy and management umbrella that doesn't undermine security. HIEs can play a very beneficial role in this regard, because they can provide the policies, processes, staffing, experience, and technology to bring physicians "onto the grid" in a way that protects everyone's interests.

Wednesday, December 06, 2006

Privacy Request: Denied.

Yesterday's Guardian had a startling article on the British National Health Service's approach to patient privacy. The NHS is spending 24 billion pounds (ie, really really serious money) on wiring health care nationwide. They're providing EHRs to all physicians, linking them all up over a national network, and creating a national repository of patient-identified clinical data.

Back to the article. Patients have requested to opt out of the national network and repository, and the Government has rejected their requests!

Polls show that 53% of patients are opposed to having their data on the system, and as a result, 52% of general practitioners are opposed to providing their patient's data to the system without their patients' specific consent. Despite this overwhelming display of distrust, according to the article:

[T]he Department of Health said nobody could have genuine grounds for claiming "substantial and unwarranted distress" as a result of having their intimate medical details included on a national computer system, known as the Spine. For that reason, "it will not agree to their request to stop the process of adding their information to the new NHS database".

Yikes!! On top of the increasingly shrill reports of the technical problems the NHS project is suffering, it's hard to imagine that this project is going to get back on track anytime soon.

Back here in the colonies, we at MAeHC are also setting up data exchanges and repositories in our three pilot communities, but we're going with an opt-in approach, meaning that we won't exchange any patient's data without his/her specific, written consent.

This approach certainly takes longer and is definitely more logistically challenging than an opt-out (or the NHS approach of no-choice), but it appropriately puts the burden on us to get the trust of patients and physicians before we start letting their data fly. The very early returns on our experiment are that patients are overwhelmingly opting in -- still early, still small sample, but encouraging nonetheless. In the long run, I think this will build a deeper foundation for the whole enterprise going forward. When problems arise -- and they will arise -- patients will be more forgiving than if we hadn't asked their permission in the first place.....

Tuesday, December 05, 2006

Privacy rules

Sunday's NYT article touched on so many issues it was hard to address them at one sitting. The article asserts that concerns about privacy and security are the major obstacle blocking passage of pending bills on health IT. I wish that was true because it would mean that privacy concerns had become a higher priority than they have been up until now, and that there was agreement on all of other vexing issues in this area. Alas, I don’t think either is true.

Privacy and security are clearly important considerations on lawmakers’ minds, but equally if not more important barriers are:
  1. lack of budget
  2. blurry policy options, stemming from the complexity of health care delivery and little to no understanding at the federal level of the complexity of these issues
  3. disagreement (mostly ideological) on the role of government generally, and the divvying up of power between federal- and state-levels specifically
  4. lack of awareness among the public (or more specifically, voters) of the urgency of taking steps to improve the quality and efficiency of our care
The following commentary from iHealthBeat is indicative:

"Prospects look pretty good" for the 110th Congress to pass health IT legislation in 2007, Michael Zamore, a policy adviser for Rep. Patrick Kennedy (D-R.I.), said in an interview for an iHealthBeat special audio report. According to Zamore, health IT is a "great candidate" for bipartisan efforts because "it's teed up, it's kind of ripe, it's been kicked around, it's had a false start or two," and the "ideas have been percolating and vetted.

"David Merritt, project director at the Center for Health Transformation, said the opportunity still exists to pass a bipartisan conference bill during the 109th Congress' lame-duck session codifying the Office of the National Coordinator for Health IT and allowing hospitals anti-kickback exemptions to provide physicians with health IT equipment.

"Let's not throw away all the progress we've made up to this point simply because of the change in power," Merritt said. However, Zamore and Merritt agree that identifying funding for health IT initiatives with current budget deficits will be a challenge (Rebillot, iHealthBeat, 11/15).

The Democrats on the Hill (especially Ed Markey) do place a greater emphasis on privacy concerns than do the Republicans (outgoing Connecticut Republican Congresswoman Nancy Johnson's bill was silent on the issue, for example), so maybe this will rise in importance in the new Congress. In this environment though, I think cash (or lack thereof) will still be king......

Monday, December 04, 2006

Do the right thing

Yesterday’s New York Times article on privacy and security of electronic health records, coupled with an article in the Wall Street Journal last week on WalMart’s foray into electronic health records, points to what could be an ominous twist in the movement to expand the use of EHRs and health information exchange in health care delivery. Large businesses -- burdened by spiraling costs of health cost premiums -- are increasingly investing in technologies to gather health information on their employees to try to more directly manage (and, they hope, stanch) the growth of these costs.

I completely sympathize with the plight of these businesses -- MAeHC is a small business, after all. I also applaud their recognition of the key role that EHRs and clinical IT can play in improving health care delivery. Yet, their whole approach raises serious concerns for patient privacy. By creating proprietary systems to gather and control the health data of their employees, these companies are, perhaps unwittingly, stumbling into the most important and fragile issue in the health IT debate.

There is an irony in all of this. Some existing privacy laws, which were designed for paper-based records, don't make sense in an electronic world, and indeed, are in some cases presenting obstacles to better management of electronic data in ways that no one could have anticipated at the time. Many of those laws were designed to prevent employers from getting access to sensitive information that could affect a person's employment status. Employers need to be hyper-sensitive to those concerns. If they appear to be violating the spirit (even if not the letter) of those laws, it will sow seeds of patient distrust and perhaps draconian laws that will undermine not only their own efforts but also the many community-based efforts around the country that are working hard to do this the right way, namely, using IT to empower physicians and patients to improve the cost-effectiveness of care.

While there is a crying need to bring modern IT systems to health care delivery, this effort won’t be economically or morally sustainable if it’s not based on trust. Patients and physicians have to trust the systems being created. Otherwise, patients won’t agree to having their data in these systems, and physicians won’t agree to using them because they’re concerned about their patients’ privacy and about the legal liability associated with breaches of confidentiality. But neither patients nor physicians will trust these systems if they aren’t set up with privacy as a fundamental design consideration, rather than a bolt-on afterthought.

The reason that employer- and insurer-based schemes are problematic is that they undermine what I think of as a core principle of health information exchange – the need to create the healthcare equivalent of a Chinese Wall between those who collect and aggregate the data on behalf of providers to facilitate direct care delivery, and non-providers who would use the data for any purpose other than direct treatment of patients. Just because electronic data is more easily available for treatment purposes doesn’t mean that we permit it to be more easily available for other purposes. Data collection and aggregation may happen in a new way (ie, using EHRs and secure networks), but access has to happen the old way (ie, explicitly negotiated among the owners and key stakeholders). This is the principle behind such leading community-based efforts as the MA-SHARE, RIQI, IHIE, HealthBridge, THINC, and MAeHC.

So how do you do that? Create, operate, and govern these systems by building on the trust engendered in today’s physician-patient relationship. Patients have a well-placed trust in their physicians. Physicians will only use the systems if they’re valuable from a user design perspective and they promote their patients’ welfare. Rather than setting these systems up as proprietary company systems, they need to be set up more like public utilities. Put hospitals, physicians, and patients in joint control of these systems so that they are designed, managed, and governed by those who are going to be using the systems. These key stakeholders will get behind investments in “wiring” the care delivery system to improve quality, safety, and efficiency; what they won’t get behind is investments whose primary aim is surveillance.

I suggest that employers should get out of the business of trying to electronically capture their employees’ detailed health information, and into the business of getting health care providers to embrace information technology that improves the quality, safety, and efficiency of care. It's fair for them to want better data to measure performance, but they can get that without demanding access to detailed patient information. They can create urgency for better system performance using basic supply chain management principles that they're very familiar with: Invest in their healthcare delivery supply chain by setting basic technology and interoperability requirements for their suppliers (ie, providers), and facilitate their providers’ ability to meet these standards.

So, the program would run as follows. First, require physicians to use EHRs, help physicians pay for the upfront costs of getting outfitted with solid EHR systems, and train them and their staff to use the systems effectively. Second, require them to participate in data exchange networks that facilitate the effective coordination of care and the efficient transmission of clinical information. Third, put in place a new funding model that redirects reimbursement toward paying physicians for improving peoples’ health and away from paying them for the volume of care delivered and/or complexities that arise with their patients due to poor physician performance.

All of this is, of course, easier said than done, and no one knows that better than those of us slogging away in the trenches. But if Walmart and Pitney Bowes and IBM and UPS spent more time working with existing community-based efforts, and less time building their own proprietary data warehouses, it would happen faster than they might think, and it would be lasting and sustainable. There are many community-based efforts out there trying to do just this, and they could benefit enormously from the resources (financial, technical, and managerial), encouragement, and old-fashioned kick-in-the-pants that only the business community can provide.

I think the message employers should send to their employees is: “We don’t want your personal health data, but it's in everyone's interest to better monitor the overall performance of our insurer/provider network because the quality, safety, and cost of health care affects all of us.” That would reinforce the message that they’re not trying to undermine the sanctity of the doctor-patient relationship, but rather, trying to improve the performance of the overall system to better serve physicians, patients, and purchasers alike.