Laman

Tampilkan postingan dengan label healthcare IT regulation. Tampilkan semua postingan
Tampilkan postingan dengan label healthcare IT regulation. Tampilkan semua postingan

Selasa, 29 Oktober 2013

Proof positive of government incompetence and recklessness in information technology - H.R.3303 - Bipartisan call for exemption of health IT from the FD&C Act

Here's proof positive of government incompetence and recklessness in information technology.

A new proposed bill that would exempt health IT from the Food, Drug & Cosmetic Act and FDA regulation.

Rep. Marsha Blackburn (R-TN) calls for exemption of healthcare software from FDA regulation with bipartisan co-sponsorship from Reps. Gene Green (D-TX), Phil Gingrey, M.D. (R-GA), Diana DeGette (D-CO), Greg Walden (R-OR) and G.K. Butterfield (D-NC).

H.R.3303 - SOFTWARE Act of 2013 - referred to House Energy & Commerce on 10/22/2013
http://beta.congress.gov/bill/113th/house-bill/3303/text

This remarkable and unprecedented regulatory accommodation is based on nebulous, speculative and largely imaginary grounds that translate to - just because:
 
... (c) Sense of Congress.--It is the sense of the Congress that--
            (1) clinical software and health software (as defined in
        section 201(tt) of the Federal Food, Drug, and Cosmetic Act, as
        added by subsection (a)) [can]--
                    (A) advance the goals of enhanced patient safety
                and continued innovation
;
                    (B) hold much promise to lower costs and improve
                the health of patients; and
                    (C) can improve the quality and efficacy of health
                care provider services 

This is despite known defects and harms in-the-now (e.g., ECRI Deep Dive Study with 8 injuries and 3 possible deaths in 9 weeks from 171 health IT 'mishaps', voluntarily reported in just 36 hospitals, https://www.ecri.org/EmailResources/PSRQ/ECRI_Institute_PSO_Deep%20Dive_HIT_TOC.pdf; Emergency Department EHR dangers as at http://hcrenewal.blogspot.com/2013/10/quality-and-safety-implications-of.html; innumerable "glitches" that can kill, http://hcrenewal.blogspot.com/search/label/glitch and http://hcrenewal.blogspot.com/2011/01/maude-and-hit-risk-mother-mary-what-in.html; baby deaths, http://hcrenewal.blogspot.com/2011/06/babys-death-spotlights-safety-risks.html etc.)

Instead this group of intrepid Cybernetic Crusaders, to whom your life is valuable (as a guinea pig, it seems) call for --

"the President and the Congress [to] work together to develop and enact legislation that establishes a risk-based regulatory framework for such clinical software."

With the Obamacare/Obamaware debacle still in progress ... (see "Drudge Report, Oct. 10, 2013, 9 AM EST: All that needs to be said about government, computing and healthcare" at http://hcrenewal.blogspot.com/2013/10/drudge-report-oct-10-2013-9-am-est-all.html) ...

All I can say is:

REALLY?

-- SS

p.s. perhaps I should have entitled this post "Look, Ma, No Regulation!" (See http://hcrenewal.blogspot.com/2011/06/my-mother-passed-away.html.)

-- SS

Selasa, 08 Oktober 2013

Quality and Safety Implications of Emergency Department Information Systems: ED EHR Systems Pose Serious Concerns, Report Says

A report "Quality and Safety Implications of Emergency Department Information Systems"
appeared in the Oct. 2013 issue of "Annals of Emergency Medicine."  It is available fulltext at http://www.annemergmed.com/article/S0196-0644%2813%2900506-4/fulltext, or in PDF via the tab, free as of this writing.

First, a preamble:  I once tried to alert a hospital where I'd trained decades before, Abington Memorial Hospital (http://www.amh.org/), of impediments to safe care I'd noted in their EHR's, predominantly their ED EHR.  They did not listen.  In fact, their response to my concerns was characterized by an apparent incompetence regarding conduct of safety investigations.  For instance, to my written concern in an April 2010 letter to the CEO and CMO about the ED EHR that:

... I've also had to stop administration [to my mother] of an antibiotic (Levaquin) in the recent past in the ED that she has had an adverse reaction to (torn rotator cuff), despite my having told ED intake she was allergic to it. She relates that administration of Levaquin was then almost repeated on the floor until she herself refused it during that past admission.

This was the sworn testimony in May 2013 about the "investigation" that resulted, from the hospital's VP of Risk Management, Regina Sturgis:

A:      Deborah [hospital General Counsel] asked me to investigate the Levaquin issue which I did.
Q:      Did you do that on your own or did you delegate some of the --
A:      No.  I did it on my own.
Q:      Do you know whether any of the IT folks were ever brought in to look at the -- the EMR issues referenced in this letter?
A:     No, I do not.  I know that I was asked to look at the Levaquin because of my clinical background.
Q:      Okay.  Did you come up with any conclusions?
A:      Yes.
Q:      What was your conclusion?
A:      That she had been ordered Levaquin in the ETC [Emergency Trauma Center a.k.a. ED], that it had been discontinued about a very short period of time later, under a half an hour, and that she never received it.

So, the investigation of a complaint that family and then the patient themselves had to stop the administration of a drug whose staff and EHR had been informed of an allergy consisted of confirming that the medication was never given.  No problem, the ED EHR is safe.

(I am not joking; that is the testimony given.  Imagine such an investigation and conclusion about, say, reported aircraft flaws, or, in the industry in which I was once a safety officer, public transit vehicle defects and dangers.)

However, when competent people investigate similar issues, the findings are concerning.  From Modern Healthcare (http://www.modernhealthcare.com/), a publication for healthcare executives, on the new Annals of Emergency Medicine article:

ED EHR systems pose serious concerns, report says

By Joseph Conn
Modern Healthcare

June 24, 2013
Electronic health-record systems used in emergency departments are beset with poor data displays, loaded with so many alerts warning of potential patient-safety issues that they can lead to user alert fatigue, and may be generating incorrect physician orders, according to a report by two emergency physicians' study groups.

Meanwhile, providers wanting to address these EHR issues are hampered by a lack of research and solid evidence of the extent of the problem with these systems, and by contract provisions with EHR vendors that stymie the free flow of information about system-linked safety concerns, the report authors say.

So, ED's across the country are rolling out technology, often taking advantage of ARRA's HITECH incentives ... but there is a lack of research and solid evidence into the risks.  Allow me to opine - that's simply crazy.

The groups found that “poor data display is a serious problem with many of today's EDISs,” while “the sheer volume” of alerts that range from the “completely irrelevant to life threatening” [or lack of appropriate alerts to relevant, simple issues such as data input errors - ed.] can “dull the senses, leading to a failure to react to a truly important warning.” They also found that “an alarming number of clinicians are anecdotally reporting a substantial increase in the incidence of wrong order/wrong patient errors while using the computerized physician order entry component of information systems.

The word "anecdote", as I have written, is being misused.  The reports are not "anecdotes."  They are risk management-relevant incident reports.  (See "From a Senior Clinician Down Under: Anecdotes and Medicine, We are Actually Talking About Two Different Things" at http://hcrenewal.blogspot.com/2011/08/from-senior-clinician-down-under.html.)

Two study groups from the American College of Emergency Physicians have recommended a program of systemic vigilance over electronic health-record systems used in emergency departments to improve patient safety and enhance quality of care.

ACEP workgroups on informatics and on quality improvement and patient safety published their findings in an article, “Quality and Safety Implications of Emergency Department Information Systems,” in the current issue of the Annals of Emergency Medicine.

Post marketing surveillance, a standard for decades in other healthcare sectors, has been absent from health IT due to a long-obsolete special regulatory accommodation afforded that industry.  This accommodation was initiated when systems were simple and merely advisory - not the comprehensive enterprise clinical resource and clinician command-and-control systems they are today.  Now, clinician investigators of the technology such as the authors of this study are realizing that continuing this accommodation is a mistake.

It follows in the wake of, and references, an Institute of Medicine report from 2011, “Health IT and Patient Safety: Building Safer Systems for Better Care.” That report concluded that “current market forces are not adequately addressing the potential risks associated with the use of health IT.” It also comes eight months after the New England Journal of Medicine published “Electronic Health Records and National Patient-Safety Goals,” which warned that recent evidence “has highlighted substantial and often unexpected risks resulting from the use of EHRs and other forms of health information technology.”

I note that if you frequent this blog, you likely read material similar to the bolded red statements above here first, as authored by me, dating to the founding of this blog in 2004.

... “The rush to capitalize on the huge federal investment of $30 billion for the adoption of electronic medical records led to some unfortunate and unintended consequences, particularly in the unique emergency department environment,” said Dr. Heather L. Farley, the lead author of the report, in a news release. “The irreversible drive toward EDIS implementation should be accompanied by a constant focus on improvement and hazard prevention." Farley is assistant chairwoman of the Department of Emergency Medicine at Christiana Care Health System in Newark, Del.

Ironically, I note in Dr. Farley's statement some of my own advice, given to ED staff when I was Chief Medical Informatics Officer at Christiana Care 1996-8.   I had in that time period advised Charles Reese IV, MD, Chair of Emergency Medicine, to not implement EHRs or, at best, implement document imaging systems (since ED charts are not that long or complex), not full field-based EHRs, due to the "unfortunate and unintended consequences" of bad health IT in such an environment I recognized even then.  It was only a few years ago that my advice was finally overturned.

The authors also report “(t)here are few consistent data on how commonly these errors occur, and few studies are actually focused on collecting evidence of these errors.” Meanwhile, “there is currently no mechanism in place to systematically allow, let alone encourage, users to provide feedback about ongoing safety issues or concerns” with EHRs in general, and EDISs specifically.

On its face, that is not a safety-conscious environment and the rollout and use of such systems seems a fundamental violation of patient's rights, made worse by the fact that there is no informed consent process whatsoever to ED EHR use.

The workgroups came up with seven recommendations: appointing an emergency department “clinician champion,” creating within healthcare delivery organizations an EDIS performance improvement group and an ongoing review process, paying timely attention to EDIS-related patient-safety issues raised by the review process, disseminating to the public lessons learned from performance improvement efforts, distributing vendors' product updates in a timely manner to all EDIS users and removing the “hold harmless” and “learned intermediary clauses” from vendor contracts.

Many of these issues have been discussed on this blog.

“The learned intermediary doctrine implies that the end users (clinicians) are the medical experts and should be able to detect and overcome any fallibility or contributing factor of the product,” the authors said.

I have also pointed out the absurdity of such a "doctors are clairvoyant" attitude, e.g., at my 2011 post on basic common sense on IT adverse consequences at http://hcrenewal.blogspot.com/2011/04/common-sense-on-side-effects-lacking-in.html.

They conclude that the “lack of accountability for vendors through hold harmless clauses and the shifting of liability to the clinicians through the learned intermediary doctrine are significant and additional impairments to safety improvement. Electronic health records and EDISs are sufficiently complex that the physician and other users cannot be expected to anticipate unpredictable errors.”

That aligns with the work of Dr. Jon Patrick in Sydney, whose treatise "A study of an Enterprise Health information System" on the Cerner FirstNet ED EHR is available here: http://sydney.edu.au/engineering/it/~hitru/index.php?option=com_content&task=view&id=91&Itemid=146

Earlier this month, the Electronic Health Record Association, an EHR developers trade group affiliated with the Chicago-based Healthcare Information and Management Systems Society, announced the launch of a voluntary “code of conduct in which adherents would agree to drop “gag clauses” in the contracts with their provider customers.

Great.  Per the wonderful 2007 article "The Denialists' Deck of Cards: An Illustrated Taxonomy of Rhetoric Used to Frustrate Consumer Protection Efforts" by Chris Jay Hoofnagle, available at http://papers.ssrn.com/sol3/papers.cfm?abstract_id=962462, as of this writing free:

... At this point [of losing the argument], the denialist must propose "self regulation" to deal with the problem that doesn't exist. The cool thing about self regulation is that it cannot be enforced, and once the non-existent problem blows over, the denialist can simply scrap it! [20]

[20] In the runup to passage of bank privacy legislation, data brokers created a group called the "Individual Reference Services Group" that promptly disappeared after the legislation passed.

("Denialism" is the use of rhetorical techniques and predictable tactics to erect barriers to debate and consideration of any type of reform, regardless of the facts.)

IMO 'self regulation' of healthcare is, on its face, a deception.  There are simply too many conflicts of interest.

On use of "integrated" big systems:

“These systems do have glitches [indeed - see http://hcrenewal.blogspot.com/search/label/glitch - ed], but it can be plain and simple bad design that can lead to clinical errors,” Cozzens said.  But ED physicians, he said, are “having the enterprise systems forced upon them. To think you can take one system and adapt it to those different environments is totally wrong. That's why you see low physician satisfaction and the productivity is going down, all for the sacrifice of having an integrated system.”

In fact, so-called "best of breed" systems can be bad health IT as well.  See the aforementioned evaluation by Dr. Patrick in Australia.

Bad Health IT ("BHIT") is defined as IT that is ill-suited to purpose, hard to use, hard to customize, unreliable, loses data or provides incorrect data, causes cognitive overload, slows rather than facilitates users, lacks appropriate alerts, creates the need for hypervigilance (i.e., towards avoiding IT-related mishaps) that increases stress, is lacking in security, compromises patient privacy or otherwise demonstrates suboptimal design and/or implementation. 


Through my own work, I've seen bad health IT result in patient harm and death.  It's just unfortunate that I got started in this line of work by being, in effect, shot out of a cannon.  That is, my own mother was a victim.

-- SS

Addendum 10/8/13:

From the article:

End-User Recommendation 4: EDIS-related patient safety concerns identified by the review process should be addressed in a timely manner by ED providers, the EDIS vendors, and hospital administration. Each of these processes should be performed in full transparency, specifically with openness, communication, and accountability. 

I'm not sure the aforementioned levaquin near-accident "investigation" meets these standards.

-- SS

Jumat, 09 Agustus 2013

A War on Patients: Panel Says EHRs Should Not Be Vetted Before Marketing and Deployment

"First, do harm - it's a learning experience, and injured or dead patients are just a bump in the road, anyway" - the apparent creed of the healthcare computing hyperenthusiasts

Joe Conn and Modern Healthcare published the following article:

Work group says OK to some HIT safety regs (link), Joe Conn, Modern Healthcare, Aug. 7, 2013

What is important is what safety regs the Workgroup said "no" to.  It comes as no surprise:
A federally chartered special work group with representatives from three federal agencies has submitted its draft recommendations on establishing a regulatory framework for health information technology. Chief among those recommendations is that health IT should not be subjected to pre-market federal regulation, but there were a few exceptions.

The exceptions are narrow, and are likely already covered as Class III medical devices by FDA (see http://www.fda.gov/MedicalDevices/DeviceRegulationandGuidance/Overview/ClassifyYourDevice/):

The exceptions under which there should be FDA regulation, according to the work group, include medical device accessories to be defined as such by the FDA; certain forms of “high risk” clinical decision support systems, such as “computer aided diagnostics,” also to be defined by the FDA; and some “higher risk software” use cases to be defined by the committee's own safety work group.

They did acknowledge the need for postmarket surveillance:
... The group also recommended: developing a federally supported, post-market surveillance system for health IT products “to ensure safety-related decision support is in place,” creating a process for gathering information on safety issues, aggregated at the federal level and establishing a public process for “customer rating of HIT to enhance transparency.”

Dr. David Bates [a professor at Harvard Medical School], chairman of the Food and Drug Administration Safety Innovation Act work group, presented the preliminary findings Wednesday at a meeting of HHS' Health Information Technology Policy Committee.

Let me translate this to plain English:  the health IT systems that go in (and their upgrades and patches) are recommended to be free from pre-marketing regulation and regulatory vetting.  Patients are to be the guinea pigs for testing of the software.  

If patients are harmed or killed, they get the honor of being named as "postmarket surveillance learning cases" who gave their all for the betterment of healthcare information technology.  

(Without their consent, but who needs consent to test experimental and unvetted devices on guinea pigs?)

Bates did express some liability concerns:

Asked during a question and answer period following his presentation whether the committee had considered the liability implications of its recommendations, Bates said, “It's not something we discussed at length, but it's something we can discuss over the next month.”

I, on the other hand, as a legal consultant on health IT-related medical errors and evidence tampering, am considering liability issues.

Unfortunately, patients would rather be whole than in lawsuits (or dead).  Also, sadly, it's physicians and nurses who will bear the brunt, if not all, of the liability for bad outcomes due to defective IT such as at these two recent posts, with vendor alerts regarding serious flaws of medication and other orders not being retained:

A clarification for all those proletarians who lack Harvard educations, and for the Workgroup members as well. Allow me to point out that the above manufacturer safety alerts of life-threatening fundamental flaws (involving entered text that "disappears", apparently found in live-patient scenarios, and the other "glitches" that did cause life-threatening errors sometimes en masse involving thousands of patients such as another apparent Siemens debacle at http://hcrenewal.blogspot.com/2011/11/lifespan-rhode-island-yet-another.html) would likely not have occurred if the systems had been vetted before being turned loose on patients.

Finally:  David and panel members, my mother and I thank you profusely. 

Oh wait...my mother can't thank you, she's dead from the toxic effects of un-premarket-vetted health IT on simple care processes at the very hospital where I performed my residency two decades ago.

She might have died a few times before she actually did thanks to other IT "glitches" that cropped up during her recovery from the first one, but I was able to (in one case, by sheer happenstance of showing up at  the right time) discover or provide staff with information to work around additional unvetted-health-IT flaws before those did her in.

It's taken more than a decade for critical-thinking, unconflicted writers and researchers ("iconoclasts") to force cybernetics-over-all hyperenthusasts (see here) like Bates and his panel members to own up the risks of health IT at all, e.g. via sites like this blog and this teaching site. These panel members IMO have their heads buried in sand.

Dr. Bates and his panel are, in my opinion, healthcare IT extremists, which is in part the apparent holding of the belief that computers have more rights than patients - and the other beliefs mentioned in this post:  "Another Health IT 'Glitch' - Can Digital Disappearing Ink Kill Patients?" at http://hcrenewal.blogspot.com/2013/08/another-health-it-glitch-can.html.

-- SS

Kamis, 28 Februari 2013

Arguments with Pavlov's Dogs: Health IT Regulation Will "Harm Innovation"? How, exactly?


Health IT hyper-enthusiasts, when faced with the prospect of government regulations, react like Pavlov's dogs with the response "regulation of health IT will harm innovation."

Here's a soliloquy of critical questions that need be asked:

-----------------------

Now, Mr. (or Dr.)  Hyper-Enthusiast, you state HIT regulation will harm innovation.

What aspects of regulation, specifically, will harm innovation?

Good manufacturing processes (GMPs)?

Building a safety case for review and inspection?

Pre-market safety/fitness/quality/reliability testing?

Post-marketing surveillance?

What?

Innovations happen before regulatory evaluation, do they not?

What, exactly, are your objections to safety and quality testing of innovations?

Don't innovations need to be tested for safety and quality?

If innovations are not safe, should they not be used on live patients?

How can the industry with its conflicts of interest effectively regulate HIT?

Even if it could, again, how would additional regulatory oversight harm innovation?

----------------------- 

And perhaps this needs to be asked as well:

  • Don't you really mean regulation would harm the bottom line?

-- SS

Kamis, 28 Juni 2012

FDA Safety and Innovation Act: To contain an "Appropriate, risk-based regulatory framework pertaining to health information technology"

Congress has just released an an Act "to amend the Federal Food, Drug, and Cosmetic (FD&C) Act to revise and extend the user-fee programs for prescription drugs and medical devices, to establish userfee programs for generic drugs and biosimilars, and for other purposes."  Health IT provisions are included.

This Act, S. 3187, is entitled the ‘‘Food and Drug Administration Safety and Innovation Act.’’  PDF fulltext is located at this link:  http://www.gpo.gov/fdsys/pkg/BILLS-112s3187enr/pdf/BILLS-112s3187enr.pdf

With regard to health IT, the Act states the following.  A risk-based regulatory framework pertaining to health IT is to be developed (emphases mine):



SEC. 618. HEALTH INFORMATION TECHNOLOGY.


(a) REPORT.—Not later than 18 months after the date of enactment of this Act, the Secretary of Health and Human Services (referred to in this section as the ‘‘Secretary’’), acting through the Commissioner of Food and Drugs, and in consultation with the National Coordinator for Health Information Technology and the Chairman of the Federal Communications Commission, shall post on the Internet Web sites of the Food and Drug Administration, the Federal Communications Commission, and the Office of the National Coordinator for Health Information Technology, a report that contains a proposed strategy and recommendations on an appropriate, risk-based regulatory framework pertaining to health information technology, including mobile medical applications, that promotes innovation, protects patient safety, and avoids regulatory duplication.


(b) WORKING GROUP.—
(1) IN GENERAL.—In carrying out subsection (a), the Secretary may convene a working group of external stakeholders and experts to provide appropriate input on the strategy and recommendations required for the report under subsection (a).

(2) REPRESENTATIVES.—If the Secretary convenes the working group under paragraph (1), the Secretary, in consultation with the Commissioner of Food and Drugs, the National Coordinator for Health Information Technology, and the Chairman of the Federal Communications Commission, shall determine the number of representatives participating in the working group, and shall, to the extent practicable, ensure that the working group is geographically diverse and includes representatives of patients, consumers, health care providers, startup companies, health plans or other third-party payers, venture capital investors, information technology vendors, health information technology vendors, small businesses, purchasers, employers, and other stakeholders with relevant expertise, as determined by the Secretary.


While a welcome development, it is to be determined if the Working Group representatives will include critical thinkers without conflict of interest, whose contributions to the health IT debate in this country are needed a lot more than the traditional hyper-enthusiasts, industry courtiers and opportunists.

I am actually not hopeful.

The "promotes innovation" and "avoids regulatory duplication" phrases are of especially great concern.  As I've written before, "innovation" that involves non-consented experimentation is not innovation at all, it is exploitation, and "regulatory duplication" can become an excuse for milquetoast regulation by the conflicted (e.g., regulatory capture) or poorly qualified.

I also note that this Act, while welcome, is long overdue - another example of putting the cart before the horse (link), with a national project (including CMS penalties for non-adopters) now several years underway.

Final thought:  if health IT were safe as has been claimed now for decades, or had been made safe through proper development and clinical trials-based testing, we would not need health IT provisions in a  "Food and Drug Administration Safety and Innovation Act" in 2012.

-- SS

Minggu, 03 Juni 2012

WSJ "There's a Medical App for That—Or Not" - Misinformation on Health IT Safety Regulation?

There's a health IT meme that just won't die (patients may, but not the meme).

It's the meme that health IT "certification" is a certification of safety.

I expressed concern about the term "certification" being misunderstood even before the meme formally appeared, when the term was adopted by HHS with regard to evaluation of health IT for adherence to the "meaningful use" pre-flight features checklist.  See my mid-2009 post "CCHIT Has Company" where I observed:

HIT "certification." ... is a term I put in quotes since it really is "features qualification" at this point, not certification such as a physician receives after passing Specialty Boards.

The "features qualification" is an assurance that the EHR functions in way that could enable an eligible provider or eligible hospital to meet the Center for Medicare & Medicaid Services' (CMS) requirements of "Meaningful Use."  No rigorous safety testing in any meaningful sense is done, and no testing under real-world conditions is done at all.

I've seen the meme in various publications and venues.  I've even seen it in legal documents in medical malpractice cases where EHR's were involved, as an attempted defense.

Now the WSJ has fallen for the health IT Certification meme.

An article "There's a Medical App for That—Or Not" was published on May 29, 2012.  Its theme is special regulatory accommodation for health IT in the form of opposition to FDA regulation of devices such as "portable health records and programs that let doctors and patients keep track of data on iPads."

In the article, this assertion about health IT "certification" is made:

... The FDA's approach to health-information technology risks snuffing out activity at a critical frontier of health care. Poor, slow regulation would encourage programmers to move on, leaving health care to roil away for yet another generation, fragmented, disconnected and choking on paperwork.

The process already exists for safeguarding the public for computers in health care. It's not FDA premarket review but the health information technology certification program, established under President George W. Bush and still working fine under the Obama Health and Human Services Department. The government sets the standards and an independent nonprofit [ATCB, i.e., ONC Authorized Testing and Certification Bodies - ed.] ensures that apps meet those standards. It's a regulatory process as nimble as the breakout industry it's meant to monitor. That is where and how these apps should be regulated.

It's a wonderful meme.  Unfortunately, it's wrong.  Dead wrong.

Certification by an ATCB does not "safeguard the public."   Two ONC Authorized Testing and Certification Bodies (ATCB's) admitted this in email, as in my Feb. 2012 post "Hospitals and Doctors Use Health IT at Their Own Risk - Even if Certified".  I had asked them, point-blank:

"Is EHR certification by an ATCB a certification of EHR safety, effectiveness, and a legal indemnification, i.e., certifying freedom from liability for EHR use of clinical users or organizations? Or does it signify less than that?"

I received two replies from major ONC ATCB's indicating that "certification" is merely assurance that HIT meets a minimal set of "meaningful use" guidelines, not that it's been vetted for safety.  For instance:

From: Joani Hughes (Drummond Group)
Sent: Monday, March 05, 2012 1:06 PM
To: Scot Silverstein
Subject: RE: EHR certification question

Per our testing team:

It is less than that. It does not address indemnification although a certification could be used as a conditional part of some other form of indemnification function, such as a waiver or TOA, but that is ultimately out of the scope of the certification itself. Certification in this sense is an assurance that the EHR functions in way that could enable an eligible provider or eligible hospital to meet the CMS requirements of Meaningful Use Stage 1. Or to restate it more directly, CMS is expecting eligible providers or eligible hospitals to use their EHR in “meaningful way” quantified by various quantitative measure metrics and eligible providers or eligible hospitals can only be assured they can do this if they obtain a certified EHR technology.

Please let me know if you have any questions.

Thank you,
Joani.

Joani Hughes
Client Services Coordinator
Drummond Group Inc.

The other ATCB, ICSA Labs, stated that:

... Certification by an ATCB signifies that the product or system tested has the capabilities to meet specific criteria published by NIST and approved by the Office of the National Coordinator. In this case the criteria are designed to support providers and hospitals achieve "Meaningful Use." A subset of the criteria deal with the security and patient privacy capabilities of the system.

Here is a list of the specific criteria involved in our testing:
http://healthcare.nist.gov/use_testing/effective_requirements.html

In a nutshell, ONC-ATCB Certification deals with testing the capabilities of a system, some of them relate to patient safety, privacy and security functions (audit logging, encryption, emergency access, etc.).

What was suggested in the email below (freedom from liability for users of the system, etc.) would be out of scope for ONC-ATCB testing based on the given criteria. [I.e., certification criteria - ed.] I hope that helps to answer your question.

I had noted that:

... My question was certainly answered [by the ATCB responses]. ONC certification is not a safety validation, such as in a document from NASA on aerospace software safety certification, "Certification Processes for Safety-Critical and Mission-Critical Aerospace Software" (PDF) which specifies at pg. 6-7:
In order to meet most regulatory guidelines, developers must build a safety case as a means of documenting the safety justification of a system. The safety case is a record of all safety activities associated with a system throughout its life. Items contained in a safety case include the following:

• Description of the system/software
• Evidence of competence of personnel involved in development of safety-critical software and any
safety activity
• Specification of safety requirements
• Results of hazard and risk analysis
• Details of risk reduction techniques employed
• Results of design analysis showing that the system design meets all required safety targets
Verification and validation strategy
• Results of all verification and validation activities
• Records of safety reviews
• Records of any incidents which occur throughout the life of the system
• Records of all changes to the system and justification of its continued safety

A CCHIT ATCB juror, a physician informatics specialist, has also done a guest post in Jan. 2012 on HC Renewal about the certification process, reproducing his testimony to HHS on the issue.  That post is "Interesting HIT Testimony to HHS Standards Committee, Jan. 11, 2011, by Dr. Monteith."  Dr. Monteith testified (emphases mine):

... I’m “pro-HIT.” For all intents and purposes, I haven’t handwritten a prescription since 1999.

That said and with all due respect to the capable people who have worked hard to try to improve health care through HIT, here’s my frank message:

ONC’s strategy has put the cart before the horse. HIT is not ready for widespread implementation. 

... ONC has promoted HIT as if there are clear evidence-based products and processes supporting widespread HIT implementation.

But what’s clear is that we are experimenting…with lives, privacy and careers.

... I have documented scores of error types with our certified EHR, and literally hundreds of EHR-generated errors, including consistently incorrect diagnoses, ambiguous eRxs, etc.

As a CCHIT Juror, I’ve seen an inadequate process. Don’t get me wrong, the problem is not CCHIT. The problem stems from MU.

EHRs are being certified even though they take 20 minutes to do a simple task that should take about 20 seconds to do in the field.  [Which can contribute to mistakes and "use error" - ed.] Certification is an “open book” test. How can so many do so poorly?

For example, our EHR is certified, even though it cannot generate eRxs from within the EHR, as required by MU.

To CCHIT’s credit, our EHR vendor did not pass certification. Sadly, our vendor went to another certification body, and now they’re certified.

MU does not address many important issues. Usability has received little more than lip-service. What about safety problems and reporting safety problems? What about computer generated alerts, almost all of which are known to be ignored or overridden (usually for good reason)?
 
The concept of “unintended consequences” comes to mind.

All that said, the problem really isn’t MU and its gross shortcomings, it is ONC trying to do the impossible:

ONC is trying to artificially force a cure for cancer, basically trying to promote one into being, when in fact we need to let one evolve through an evidence-based, disciplined process of scientific discovery and the marketplace.

Needless to say, as was learned at great cost in past decades, a "disciplined process" in medicine includes meaningful safety regulation by objective outside experts.

Further, the certifiers have no authority to do important things such as forcibly remove dangerous software from the market.  An example is the forced Class 1 recall of a defective system as I wrote about in my Dec. 2011 post "FDA Recalls Draeger Health IT Device Because This Product May Cause Serious Adverse Health Consequences, Including Death".   Class 1 recalls are the most serious type of recall and involve situations in which there is a reasonable probability that use of these products will cause serious adverse health consequences or death.

In that situation, the producer had been simply advising users (in critical care environments, no less) to "work around the defects" that could indicate incorrect recommended dosage values of critical meds, including a drug dosage up to ten times the indicated dosage, as well as corrupt critical cardiovascular monitoring data.  As I observed:

... I find a software company advising clinicians to make sure to "work around" blatant IT defects in "acute care environments" the height of arrogance and contempt for patient safety.

Without formal regulatory authority to take actions such as this FDA recall, "safeguarding the public" is a meaningless platitude.

It's also likely the ATCB's, which are private businesses, would not want the responsibility of "safeguarding the public."  That responsibility would open them up to litigation when patient injuries or death were caused, or were contributed to, by "certified" health IT.

I have in the past also noted that the use of the term "certification" might have been deliberate, to mislead potential buyers exactly into thinking that "certification" is akin to a UL certification of an electrical appliance for safety, or an FAA approval of a new aircraft's flight-worthiness.

The WSJ needs to clarify and/or retract its statement, as the statement is misinformation.

At my Feb. 2012 post "Health IT Ddulites and Disregard for the Rights of Others" I observed:

Ddulites [HIT hyper-enthusiasts - ed.] ... ignore the downsides (patient harms) of health IT.

This is despite being already aware of, or informed of patient harms, even by reputable sources such as FDA (Internal FDA memo on H-IT risks), The Joint Commission (Sentinel Events Alert on health IT), the NHS (Examples of potential harm presented by health software - Annex A starting at p. 38), and the ECRI Institute (Top ten healthcare technology risks), to name just a few.

In fact, the hyper-enthusiastic health IT technophiles will go out of their way to incorrectly dismiss risk management-valuable case reports as "anecdotes" not worthy of consideration (see "Anecdotes and medicine" essay at this link).

They will also make unsubstantiated, often hysterical-sounding claims that health IT systems are necessary to, or simply will "transform" (into what, exactly, is usually left a mystery) or even "revolutionize" medicine (whatever that means).

Health IT is a potentially dangerous technology.   It requires meaningful regulation to "safeguard the public."  How many incidents like this and this will it take before that is understood by the hyper-enthusiasts?

I've emailed the ATCB's that had responded to my aforementioned query for clarification on the WSJ assertion about their role, being that the statement is in contradiction to their earlier replies to me.  I also advised them of the potential liability issues.

However, if it turns out to be true that the ONC-ATCB's do intend themselves as the ultimate watchdog and assurer of public safety related to EHR's, that needs to be known by the public and their representatives.

-- SS

Minggu, 18 Desember 2011

EHR: "The Dangerous Decade"

A new perspective piece has appeared in the Journal of the American Medical Informatics Association. Although it is not freely available, I thought posting the abstract and the opening would be of interest:


The dangerous decade
JAMIA
Published Online First 24 November 2011
Enrico Coiera, Jos Aarts, Casimir Kulikowski

Abstract

Over the next 10 years, more information and communication technology (ICT) will be deployed in the health system than in its entire previous history. Systems will be larger in scope, more complex, and move from regional to national and supranational scale. Yet we are at roughly the same place the aviation industry was in the 1950s with respect to system safety. Even if ICT harm rates do not increase, increased ICT use will increase the absolute number of ICT related harms. Factors that could diminish ICT harm include adoption of common standards, technology maturity, better system development, testing, implementation and end user training. Factors that will increase harm rates include complexity and heterogeneity of systems and their interfaces, rapid implementation and poor training of users. Mitigating these harms will not be easy, as organizational inertia is likely to generate a hysteresis-like lag, where the paths to increase and decrease harm are not identical.


The perspective piece then opens with this:

There is a paradox in the relationship between information and communication technology (ICT) and patient safety. ICT can improve the quality, safety and effectiveness of clinical services and patient outcomes,1 although the evidence base for this is sometimes weak.2 As a consequence, the rapid deployment of ICT on a national scale is a priority for many nations faced with a diminishing clinical workforce, increasing workloads, and resource constraints. 3 4
However, ICT use can also lead to patient harm.5 Many commentators have raised concerns that ICT has yet to deliver on its promises,6 or that the rapid adoption of ICT is a risk.7 7a Errors persist in clinical practice even after ICT is introduced,8 because manual processes co-exist with the automated, and the interfaces between the two are seldom perfect. Others counter that such overemphasis on ICT-related harm only delays the implementation of a crucial technology that will save lives.9
It appears that we are caught in a bind. The demands for health system reform are now so compelling that there appears no choice but to implement complex ICT on a large, often national, scale. Yet these ICT systems appear less mature than we would like and our understanding about how to implement and use them safely remains in its infancy. As such, we are faced with a pressing policy challenge on both the national and international stages.10

They raise these rhetorical questions:

... Where is the ‘kill switch’ in our health ICT systems when large-scale privacy breaches are occurring, or large volumes of critical patient data are being corrupted? Who is authorized to activate such a switch?

The answers to these questions are, quite frankly: nowhere, and nobody. What we have instead is an environment of 'irrational exuberance' -- as well as 'rational exuberance', i.e., opportunism, often of a pecuniary nature.

To the authors' other observations I would add that:

1) "Organizational inertia" is probably too narrow a concern. I would broaden it to "cultural inertia", especially since the health IT "ecosystem" is grossly lacking of a culture of safety and accountability;

2) The authors note that "Predicting the actual harm rate and total patient harms that we will see through the use of ICT in healthcare over the next decade is currently not possible."

While I agree, and agree this inability needs to be remediated, extrapolations can be performed to achieve estimates. Regarding increased ICT use increasing the absolute number of related harms, that number could already be quite substantial as I wrote in an April 16, 2010 thought experiment at "If The Benefits Of Healthcare IT Can Be Guesstimated, So Can And Should The Dangers."

Ironically and tragically, that post was written just five days before I wrote a confidential warning letter to a hospital about EHR deficiencies I'd noted in my mother's care there, and just one month before she was severely injured at that hospital by an EHR-related error of a nature as identified in the letter. Thus, the numbers in the thought experiment should be incremented accordingly;

3) I would say regarding safety that the health IT sector is roughly in the same place as aviation was in the 1920's (e.g., unregulated, experimental technology abounding), not the 1950's, and as the maritime passenger service was in ca. 1912 (April to be precise); and

4) The authors observe that "There is however caution in the [2011 IOM] report [on health IT safety here, PDF] that safety regulations would impede industry innovation, an argument which would literally not fly in the aviation industry ... the caution toward recommending regulation may however be misplaced. Simply put, if healthcare wants the benefits of ICT then it must actively manage its risks."

I strongly agree that the IOM's cautions on regulation are misplaced, as I wrote here. Robust regulation could diminish ICT harm as in pharmaceuticals and medical devices (and aviation).

Innovation will not be harmed, and the IT industry needs to -- and can afford to -- accept the responsibilities and obligations of being involved in healthcare. See for example "No More Soft Landings For Software: Liability for Defects in an Industry That Has Come of Age" (PDF), Zollers, McMullin et al., Santa Clara Computer & High Technology Law Journal, Vol. 21 No. 4, 2005.

-- SS

Rabu, 16 November 2011

Novel Idea on Healthcare IT: Worth a Billion Dollars!

From an AMIA announcement:

CMS Innovation Center Announces $1 Billion Funding Opportunity:

CMS announced a new initiative, the Health Care Innovation Challenge, which will provide grants for new ideas to improve care and lower costs for those in Medicare, Medicaid and CHIP. CMS will award up to $1 billion in grants for a 3 year period and is encouraging providers, payers, local government, public-private partnerships and multi-payer collaboratives to develop new and innovative ways to improve care. To learn more about the grants and application process, check out the CMS Innovation Center website and be sure to register for the CMS webinar on Thursday.

CMS, I have an idea!

It's a really, really novel idea!

"Let's regulate HIT to improve its safety, usability, usefulness, fitness for purpose, effectiveness, etc."

That will lower healthcare costs! Save lives, too!

----------------------------------

Can I have my Billion Dollars now?

You can do a lot in health IT with a billion dollars - if you're not the HIT industry, that is, that has squandered a large wad of these over the past several decades.

-- SS