Tampilkan postingan dengan label medical record privacy. Tampilkan semua postingan
Tampilkan postingan dengan label medical record privacy. Tampilkan semua postingan

Blogscan: UK unencrypted laptop health breach affects more than 8.6 million records

From the blog "Australian Health Information Technology":

Who Needs Hackers When There Are Accidents Like This? The PCEHR [Personally Controlled Electronic Health Record - ed.] Won’t Avoid Hacker Attention I Suspect.

The following popped up a little while ago.

By Dom Nicastro

Think the United States has its problems with securing patient health information?

We’re not alone.

London Health Programmes, a medical research organization based at the NHS North Central London health authority, has reported missing an unencrypted laptop containing information of 8.63 million patients and 18 million hospital visits, operations and procedures, according to today’s issue of The Sun.

The data does not include names, “but patients could be identified from postcodes and details such as gender, age and ethnic origin,” according to the newspaper. Information on the laptop included records of cancer, HIV, mental illness and abortions.

The computer was one of 20 lost, and officials have since recovered eight. The research organization “only just” reported the missing laptops to police although they went missing three weeks ago, according to the newspaper.

The Information Commissioner’s Office, Great Britain’s independent authority that promotes data privacy for individuals, has issued a statement regarding the laptop theft:

“Any allegation that sensitive personal information has been compromised is concerning and we will now make inquiries to establish the full facts of this alleged data breach.”

More here with a gruesome list of UK breaches.

http://blogs.hcpro.com/hipaa/2011/06/unencrypted-laptop-health-breach-affects-more-than-8-million-records/

Clearly this sort of incident is made more significant when material like this is appearing regularly.


We've posted numerous times at Healthcare Renewal on the impossible dream of electronic medical record privacy, security and confidentiality. See blog query links here and here.

-- SS

Another Blow to the Health IT Idealists: Sony CEO Howard Stringer, and HHS OIG, on Information Security

In a series of Healthcare Renewal posts such as those linked below, I pointed out that healthcare IT information security was largely a pipe dream, and that plans to create a national network of health information, while a seductive idea dating to the beginnings of computer networking, is not a good idea now.


Now you can hear it from another source: The CEO of one of the world's largest electronic companies, Sony.

Emphases mine:

Sony CEO Warns of 'Bad New World'
Wall Street Journal
May 8, 2011

TOKYO—After spending weeks to resolve a massive Internet security breach, Sony Corp. Chief Executive Howard Stringer said he can't guarantee the security of the company's videogame network or any other Web system in the "bad new world" of cybercrime.

Mr. Stringer's comments in a phone interview Tuesday, ahead of a New York roundtable discussion with reporters, come on the heels of a trying month for Sony. The company partially restored two of its online game systems and a streaming movie and music service over the weekend after shutting the services for several weeks when a breach compromised the personal information of more than 100 million account holders.

While Sony has restored part of the PlayStation Network—an online game system for its PlayStation 3 videogame console—in the U.S. and Europe and bolstered security measures, Mr. Stringer, 69 years old, said maintaining the service's security is a "never-ending process" and he doesn't know if anyone is "100% secure."

He said the security breach at PSN, Sony Online Entertainment, an online game service for personal-computer users, and its Qriocity streaming video and music network his company could lead the way to bigger problems well beyond Sony, or the gaming industry. He warned hackers may one day target the global financial system, the power grid or air-traffic control systems. [And healthcare, where identity theft, data alteration, and data destruction might occur - ed.]


I really don't think this is the time to be setting up a national health information network.

Beyond that, I offer no additional comments, other than that regarding the impossibility of keeping healthcare information secure on a national or even regional network, you may have heard it first here at Healthcare Renewal.

It would be prudent and consistent with the Hippocratic Oath to tone down our grandiose expectations and grandiose plans for these technologies in healthcare.

If you feel insecure yet, just wait a moment.

Going from very, very bad to very much worse:


An independent audit of ONC's and CMS's security programs by the HHS OIG (Office of the Inspector General) produced concerning if not alarming results to say the least:

Federal Audits Find HIT Security Problems at CMS, ONC
John Commins, for HealthLeaders Media
May 18, 2011

Audits of the federal agencies charged with implementing and monitoring security measures for healthcare information technology identified this week lax oversight and insufficient standards for healthcare providers.


The audits were conducted by the Department of Health and Human Services' Office of Inspector General, and targeted HIT security standards, privacy protection under HIPAA, and other security measures at the Centers for Medicare & Medicaid Services, and the Office of the National Coordinator. "
These two reports are being issued simultaneously because OIG found weaknesses in the two HHS agencies entrusted with keeping sensitive patient records private and secure," OIG said in a media release.

The CMS audit,
Nationwide Rollup Review of the Centers for Medicare & Medicaid Services Health Insurance Portability and Accountability Act of 1996 Oversight, examined seven hospitals across the country and found 151 "vulnerabilities" in systems and controls that are designed to safeguard electronic protected health information.

Those lapses included 124 "high impact vulnerabilities" such as
unencrypted laptops and portable drives containing sensitive personal health information, outdated antivirus software and patches, unsecured networks, and the failure to detect rogue devices intruding on wireless networks, the OIG audit said.

"These vulnerabilities placed the confidentiality, integrity, and availability of ePHI at risk. Outsiders or employees at some hospitals could have accessed, and at one hospital did access, systems and beneficiaries' personal data and performed unauthorized acts without the hospitals' knowledge," the OIG audit said. "As a result, CMS had limited assurance that controls were in place and operating as intended to protect electronic protected health information, thereby leaving ePHI vulnerable to attack and compromise.


OIG's Audit of Information Technology Security Included in Health Information Technology Standards examined ONC's mandate under the HITECH Act to develop HIT security as part of a national HIT interoperability infrastructure. The audit found "no HIT standards that included general information IT security controls … which provide the structure, policies, and procedures that apply to a healthcare provider's overall computer operations, ensure the proper operation of information systems [which obviously also impacts patient safety - ed.], and create a secure environment for application systems and controls.


That's not very reassuring. In fact, it is downright frightening. ONC has to learn such lessons from HHS OIG? Read the whole thing.

I somewhat mordantly note that organizations such as ONC and CMS would probably never hire a person like me, who might actually kick-start true critical thinking on these issues. This is due to my non-bien pensant "bad attitudes", and lack of faith in cybernetic idols.


Click to enlarge. A well-known idol of gold. Computer circuits use gold, no?

-- SS


EHR as Molestation Candidate Selector: What was this Resident looking for in the EHR before "examining" female patients?

As I was the Director of Clinical Informatics/CMIO (Chief Medical Informatics Officer) at Christiana Care Health System in Delaware back in the mid to late 1990's, and was the physician-architect of their EHR systems then, I find this story particularly disturbing:

First-Year Resident Accused Of Fondling 6 Patients
FoxPhilly.com, Feb. 18, 2011

Warrants Issued, Police Searching For Suspect

NEWARK, Del. - Delaware State Police are trying to find a former first-year resident at Christiana Hospital who they have identified as a suspect in alleged sexual contact with six patients.

According to state police, [the former Medical Resident] has been charged with six counts each of third-degree unlawful sexual contact and abuse, mistreatment or neglect of a patient or resident of a facility.

... The incidents were reported between Oct. 1 and Nov. 15 at the hospital in Newark.

The female patients were between the ages of 20 and 32, police said.

Authorities interviewed victims and hospital staff, reviewed patient charts, and audited access to computer records, which led to the identification of [the Resident] as a suspect, according to state police.

... State police said investigators found [the Resident] accessed the computerized hospital records of the six victims prior to the incidents
, performed "physical exams" on the victims and failed to provide clinical documentation of the examinations in the victims' hospital charts. Scheduling records also indicated that [the Resident] was working when the incidents occurred.

... In three of the incidents, it was determined that the victims were identified as "non- teaching" patients for whom [the Resident] had no direct patient care responsibilities and had no authority to conduct physical exams or access their hospital records.

Also noted in another account of the story in the Delaware News Journal (a newspaper) is this:

... State police initially released details about three of the assaults on Nov. 12 and said at the time that they were investigating why hospital officials did not report the incidents to police until after the third assault, some two weeks after the first victim reported the incident to hospital staff.

During the subsequent police investigation, three additional women contacted state police to report similar incidents.

One could ask, then, why the Medical Resident was able to access these medical records, and why the unauthorized accesses apparently took some time to discover by "investigators" (presumably law enforcement officers), only after complaints were made.

It is also reasonable to assume this Resident did not abuse the first woman's records he found in a search. There was likely a larger series of unauthorized chart accesses as he searched the EMR system. In other words, I don't think he was peeking at an individual record, and then going in to a room to do his nasty work, one at a time. He was likely looking at a number of potential "candidates" before each incident; i.e., he was likely "trolling around" for potential victims.

It would be interesting to see the electronic "footprint" he left.

I had horrifying firsthand experience with abuse of electronic medical information in an earlier role in the public sector.

Specifically, I had observed the events in John Doe vs. the Southeastern Pennsylvania Transportation Authority (link). In this situation a gay co-worker, the SEPTA Employee Assistance Program liaison John Eakes (now deceased of AIDS) with whom I had worked extensively in the SEPTA Medical Department, was discriminated against by administration after peeks at his prescription records. His medications included those used in treating HIV-positive patients:

...[After the disclosure to SEPTA Chief Administrative Officer (and Deputy General Manager - ed.) Judith Pierce, Doe - a.k.a. Eakes] testified that he felt as though he were being treated differently. A proposal he had made for an in-house employee assistance program met with scant interest; he felt that this was because of his HIV condition. In addition, an administrator who reported to Pierce did not call on Doe to assist in the same way that he had called on Doe earlier. Doe testified that he felt as though there was less social chitchat, co-workers ate less of the baked goods he brought to the office to share, and that his work space seemed more lonely than before. He also became fearful of Pierce, who never told Doe that she knew of his illness. Doe alleges that he became depressed and requested a prescription for Zoloft, an antidepressant, from his physician. Later, another antidepressant called Elavil was added to the medications Doe was taking.

John Eakes was a good and conscientious employee and deserved none of this, in these relatively early years of HIV+ intolerance.

Therefore, when I was CMIO at Christiana Care Health System just a few years later, and as Chair of the committee on compliance with the then-new Health Insurance Portability and Accountability Act of 1996 (HIPAA), I recommended strongly that chart audits for unauthorized access be performed on a regular basis by a dedicated person or team, and rapid action taken if it occurred. (Then again, my counsel on healthcare IT was not infrequently ignored.)

Multiple accesses by a resident (trainee) to EHR records of non-teaching (private) patients should have sent up a very large and immediate cybernetic red flag.

Ding! Ding! Ding! Warning! Unauthorized accesses detected...

I am also concerned about the characteristics this former trainee was seeking in reviewing the EHR. A history of gynecological or breast disease to serve as a ploy for performing an intrusive exam? Was he looking for a psychiatric history? A history of prior sexual abuse?

While the EHR proved helpful in post hoc forensics, are we now seeing another potential abuse of EHR's for the identification of patients who may be preyed upon by the disturbed?

It would be helpful to know if there was a common medical theme regarding the patients affected in this rather shocking affair.

-- SS

Feb. 19 Addendum:

This affair reminds me of a saying that became news in the election of President Barack Obama:

"The Chickens Have Come Home To Roost" - Rev. Jeremiah Wright

Feb. 21 Addendum:

It appears that the corporate PR folks are monitoring the airwaves in planning their responses to this scandal. From the blog viewing logs:

IP Address 167.112.160.# (Christiana Care Health Services)
ISP Christiana Care Health Services
Time of Visit Feb 21 2011 9:36:32 am
Last Page View Feb 21 2011 9:42:03 am
Visit Length 5 minutes 31 seconds
Page Views 5
Referring URL http://us.cisionpoint.com/NewsItemDetail.aspx?id=1671771040
Visit Entry Page http://hcrenewal.blogspot.com/2011/02/what-was-this-medical-resident-looking.html
Visit Exit Page http://hcrenewal.blogspot.com/2011/02/what-was-this-medical-resident-looking.html

On the "Cisionpoint" company, us.cisionpoint.com, the "referring" URL that led to this post:

CisionPoint brings together - in one integrated customized dashboard - the on-demand tools you need to create, execute and evaluate superior campaigns from start to finish.

Log in to plan your campaign, connect with the media directly, monitor news coverage and analyze campaign results.


It will be interesting to see how this horrifying episode is "managed" by the corporate spin doctors.

-- SS

Feb. 21 addendum #2:

Here is a message posted by the organization:

Message from the chief operating officer

Posted today

Christiana Care is steadfast in our commitment to the safety and well-being of our patients, employees and all visitors to our campuses.

The Delaware State Police have issued a press release identifying a suspect in the case of inappropriate touching first reported late last year. The suspect is a former first year medical resident at Christiana Care.

The prompt and thorough work of our Department of Public Safety when the allegations first surfaced, and information we shared with the State Police from our robust health information technology system, was instrumental to the process. We quickly identified the medical resident as a person of interest, and took swift action to prevent any further patient contact. As a result of our preliminary investigation, he was suspended and upon further investigation dismissed from employment.

Our rapid response when the allegations were first reported revealed no systemic issues contributed to this incident. As an organization guided by learning, we are continuing a thorough review of best practices in hospital security to determine if there are any new security measures we should adopt.

[Hopefully in the intervening years since I was CMIO, they've become even more of a learning organization compared to here, here and here, where under the prior "C" level leadership they learned so much from me and made me feel so at home, I felt compelled to leave to maintain my sanity - ed.]

We remind and encourage all patients and family to always ask health care providers to identify themselves, explain why they are there to see the patient, and explain the care provided to them. All Christiana Care employees are required to prominently display their identification badges.

[One wonders if they now permit PhD holders to use that credential on the badge, not permitted when I was there - ed.]

We deeply regret the alleged incidents and our concern for the affected patients is shared throughout our health system.

Gary Ferguson
Chief Operating Officer

As I knew Mr. Ferguson in a prior role, and as he is a good person, I with some regret point out that this appears to be corporate spin control.

A truly "robust" HIT security system, in my opinion, would have flagged the perpetrator after the first victim. It might even have prevented the molestation if there was a time delay between when he, as a trainee, trolled for a victim by viewing the records of a private patient, and then saw the patient, without some medical emergency that could have justified the records breach.

Merriam-Webster dictionary

ro·bust
adj \rō-ˈbəst, ˈrō-(ˌ)bəst\

a : having or exhibiting strength or vigorous health
b : having or showing vigor, strength, or firmness [a robust debate] [a robust faith]
c : strongly formed or constructed : sturdy [a robust plastic]
d : capable of performing without failure under a wide range of conditions [robust software]

This "robust" system, after all, is a system critical to human life and well-being, not an inventory system of medical data.

Let an unauthorized person access, say, government intelligence files, and see how far that flies...

(Notwithstanding the Wikileaks affair, where the low-level person who accessed the diplomatic files did have authorization to access the servers, through managerial complacency.)

-- SS

Feb. 26 Addendum:

This story was picked up by the Newark Post, the local newspaper in Newark, Delaware, where Christiana Hospital is located.

Questions raised about access to hospital medical records
By Doug Rainey, Newark Post
Published: Thursday, February 24, 2011

-- SS

Don't Worry, the Feds Say Your Medical Information Will Be Kept Absolutely Private

With the planned burgeoning of health IT nationally and the formation of information "exchanges", ensuring information privacy, confidentiality and security become paramount. Systematic threats to medical privacy, confidentiality and security could do significant damage to our Republic.

Yet, according to Modernhealthcare.com in "Looking to loosen privacy rules in Calif." (Dec. 7, 2010):

The head of a federal privacy and security advisory committee and a lawyer for a prominent consumer affairs organization are scheduled to press California officials this week to revise that state's health information exchange (HIE) guidelines [which have strong opt-in consent requirements -ed.] to conform to less-stringent federal privacy recommendations.

Joseph Conn, author of the article relates:

Deven McGraw, director of the Health Privacy Project at the Center for Democracy & Technology, a Washington think tank, and Mark Savage, a San Francisco-based lawyer for Consumers Union [McGraw is also an appointee to a prominent role in the federally charted HHS Health IT Policy Committee; see below - ed.], are to participate via telephone Thursday in a meeting of the California Privacy and Security Advisory Board [CalPSAB].

Here's the problem:

The CalPSAB advises the state's health secretary on healthcare privacy and security policy. Given the traditional leadership role that California plays in the healthcare industry, the board's recommendations could influence how patient consent is handled in electronic health information exchanges nationwide.

Why these recommendations? To satisfy the needs of the reckless rush to national health IT:

McGraw, a lawyer, is a member of the federally charted Health IT Policy Committee, created pursuant to the American Recovery and Reinvestment Act of 2009 to advise the Office of the National Coordinator for Health Information Technology at HHS. McGraw also serves on five work groups or subcommittees of the Health IT Policy Committee. She is chairwoman of its privacy and security workgroup and co-chairwoman of its privacy and security tiger team. [The name "tiger team" makes me wonder who's going to get mauled - ed.]

McGraw and Savage sent a letter Oct. 6 to California Health and Human Services Sec. S. Kimberly Belshe along with a copy of the tiger team's recommendations on privacy and security for health information exchange originally sent to ONC head David Blumenthal on Aug. 19. They also sent Belshe a 10-page "briefing paper" summarizing those recommendations and a follow-up letter Dec. 5.

The briefing paper urged California to "adopt a comprehensive framework of privacy protections such as that recommended by the tiger team." [I.e., that are less stringent than California's - ed.]

They threw a little fear into their recommendations:

The brief also warned that with the first stage of a federal IT incentive program beginning soon, without a consent policy in place, "California's privacy and security framework for patient health information cannot be completed." Furthermore, if that framework isn't completed, the brief asserted, "eligible providers cannot achieve the meaningful-use criteria and benefit from the substantial federal reimbursements."

In other words, "The feds have rushed you to such a point that you cannot possibly have enough time to seriously consider and put into place rigorous privacy regulation, so adopt our 'tiger team' recommendations (or you ain't gonna get money from the feds)."

This is not reassuring.

Among other issues, it seems another example, as in HITECH itself, of the Federal Government setting timelines and policies and using the "fear, uncertainty and doubt" (FUD) principle to manipulate and strong-arm the States into ceding their rights to regulate healthcare. Such Federal overreach seems to be common these days.

Only now, due to the nature of the data involved, this gets personal.

Listen to us, we're the Tiger Team!

Of course, there's always plausible deniability:

Officially, the ONC is not a party to the push by McGraw and Savage to leverage the federal tiger team's work in California, according to the ONC. Asked whether the ONC was aware of and supports the efforts of McGraw in California, spokeswoman Nancy Szemraj said, "We have no knowledge of this letter."

Again, not very reassuring or credible, considering:

1) as above, that McGraw and Savage sent a letter Oct. 6 to California Health and Human Services Sec. S. Kimberly Belshe along with a copy of the tiger team's recommendations on privacy and security for health information exchange originally sent to ONC head David Blumenthal on Aug. 19.

and:

2) McGraw's role on five work groups or subcommittees of the Health IT Policy Committee:

Health IT Policy Committee (A Federal Advisory Committee)

The Health IT Policy Committee will make recommendations to the National Coordinator for Health IT on a policy framework for the development and adoption of a nationwide health information infrastructure, including standards for the exchange of patient medical information. The American Recovery and Reinvestment Act of 2009 (ARRA) provides that the Health IT Policy Committee shall at least make recommendations on standards, implementation specifications, and certifications criteria in eight specific areas.

-- SS

Addendum Dec. 10, 2010:

This post generated a comment containing a significant logical fallacy, apparently from Harley Geiger, staff counsel of the CDT (Center for Democracy and Technology) which is one of the key actors mentioned in the Modern Healthcare story. The comment and my comment back can be seen in the comments section at this post.

If the comment was truly from Mr. Geiger, I would be even less confident than before that an organization whose staff counsel will not or cannot proffer a logically coherent argument will protect our precious freedoms.

-- SS

Annals of Electronic Information Security

At The Hill, former House Speaker Newt Gingrich raises a good point about the leak of hundreds of thousands of diplomatic cables and other private information:

"You have a private first class who downloads a quarter million documents, and the system doesn't say, 'Oh, you may be over extended?' I mean, this is a system so stupid that it ought to be a scandal of the first order," Gingrich said.

Regardless of which administration(s) are responsible (these systems probably took many years to reach their current form), one wonders if commercial EMR's suffer from the same oversights.

-- SS

The Economist, Information Privacy, Microsoft, and Technological Determinism: An Online Debate

At The Economist, an online "debate" entitled Health 2.0 has been posted (link). It poses a debate between two experts.

In this case, the debate is between Peter Neupert, Corporate vice-president, Microsoft Health Solutions Group, vs. Deborah Peel, MD, Founder, Patient Privacy Rights and leader of the Coalition for Patient Privacy.

The readers are asked to vote upon whether they agree or disagree with this statement:

This house believes that any loss of privacy from digitising health care will be more than compensated for by the welfare gains from increased efficiency.

Note the phrase "will be."

Readers are also permitted to post comments.

My response was as follows:

30/11/2010 19:16:26 pm

Dear Sir,

The premise of this entire debate is logically fallacious, in fact begging the question.

This statement implies proven or inevitable "gains" from health IT. This is far from certain.

Health IT such as electronic medical records systems and computerized order entry systems (CPOE) remain highly experimental medical devices. They are unregulated devices as well. Their effects on medical care can be toxic, and patients are exposed to these effects without informed consent. The "gains" attributed to them are increasingly doubted in a growing body of literature.

See

"Common examples of healthcare IT difficulties" at http://www.ischool.drexel.edu/faculty/ssilverstein/cases/

and

"2009 a pivotal year in healthcare IT"
at
http://www.ischool.drexel.edu/faculty/ssilverstein/cases/?loc=cases&sloc...

for exposure to some of this literature.

In essence, management information systems and other business computing-derived approaches, customs and traditions for software design, development and lifecycle have proven ill suited in healthcare. Clinical computing and business computing are conflated; yet, they are two fundamentally different subspecialties of computing.

Further, medicine is a scientific discipline, yet the approach to IT in healthcare has been nearly devoid of science and critical thinking.

Sacrificing privacy for a dream that may or may not be true is not good social policy.

In the aftermath of the latest Wikileaks disclosures, a scientific approach - such as assertions about the beneficence of IT in healthcare not being made without strong, robust scientific evidence and without consideration of the downside evidence not being proferred so freely - would be a fine start.

S. Silverstein, MD
Drexel University
College of Information Science and Technology
Philadelphia, PA USA.


I found the position of Peter Neupert (Corporate vice-president, Microsoft Health Solutions Group) defending the motion particularly concerning:

Consumers must trust that the organisations they are engaged with are accountable and will respect—and protect—the privacy of their data.

"Must trust?"

I find this remarkable in the context of repeated violations of "trust" I've noted at this blog such as at my posts:


Neupert's view is especially paternalistic and naive in the context of Wikileaks repeatedly and recently leaking hundreds of thousands of supposedly secure documents, stolen from U.S. intelligence by at least one known person and probably others. If the Pentagon and U.S. intelligence cannot keep information secure, how can lowly hospital IT departments?

The moderator's initial comments are also disturbing:

... Supporters argue that health information technologies have advanced to the point that such [security] concerns are vastly overblown. After all, do not financial data flow freely and with little incident over digital systems? On this argument, any loss of privacy will be more than offset by efficiency gains. In arguing for the motion, Peter Neupert of Microsoft, a software firm, insists that digital medicine must be centred on the patient—rather than, say, the doctor or the insurer, as is often the case today [this 'centered on the patient' meme sounds good, but what exactly does it mean? - ed.] —and that medical information must be as mobile as the patient. If that is the case, he argues, it is not merely the efficiency of health systems that will improve but also the value of health care—and perhaps health outcomes too.

MR VIJAY V. VAITHEESWARAN
Correspondent, The Economist

Note the statements of absolute certainty - "will be more than offset by efficiency gains", "will improve", etc. They remind me of the statements made in the NEJM by the Director of ONC, Dr. David Blumenthal, as I wrote at "Science or Politics? The New England Journal and The 'Meaningful Use' Regulation for Electronic Health Records":

The widespread use of electronic health records (EHRs) in the United States is inevitable. EHRs will improve caregivers’ decisions and patients’ outcomes. Once patients experience the benefits of this technology, they will demand nothing less from their providers. Hundreds of thousands of physicians have already seen these benefits in their clinical practice.

On that I had commented:

Even though it is a "perspectives" article, I once long ago learned that in writing in esteemed scientific journals of worldwide impact, statements of certainty were at best avoided, or if made should be exceptionally well referenced. I note the lack of footnotes showing the source(s) of these statements.

The meme of technological determinism, that computerization in medicine is synonymous with, and will deterministically provide "improvements", no matter what the evidence, is quite concerning coming from a company as profoundly large and influential as Microsoft.

Further, the complete omission of consideration of the adverse clinical consequences (let alone mere information breaches) that may occur along the way to cybernetic utopia in healthcare is very disturbing. These are experimental medical devices, are unregulated, and are used without patient informed consent. Yet the IT industry seems to opine as if these systems are only to be used on experimental lab rats.

These systems produce "legible gibberish" of no clinical use to clinicians, but take clinician time to generate through distracting "clickorrhea." For example, just the placement of an IV and fluid infusion generates a half page of nonsense:


Actual "legible gibberish" from an ED EHR report, major health IT vendor. Half a page on how an IV was started and a saline infusion given. (How many distracting clinician mouse clicks did it take to produce this?) Click to enlarge.

Addendum 12/8/10 - From "Hidden Malpractice Dangers in EMRs", Steven I. Kern, Esq., Medscape.com:

Too Much Information

... Pages of repetitive documentation can be more time-consuming to review than brief, handwritten notes. When important information is embedded in paragraphs of boilerplate, it can easily be overlooked. The chance of missing critical data increases.

Overlooking important information is, of course, a significant cause of malpractice. A positive finding embedded in a string of negative findings can easily be missed.


Ironically, my relative was injured as a result of EHR-related disruption not long ago. Further, just the initial two and a half weeks of hospitalization generated more than 2,800 laser printed pages of "legible gibberish" (which cost just under $1000 to obtain; Kinko's should only have it so good).

A fellow physician I know well related:

From: [redacted name of MD]

Good Lord! I am so sorry to see this and hope your Mom gets better. You must be furious.

May I add to the cacophony? My wife went to [another local hospital's] ER for emergency transfusion. Their Emr displayed someone else's info under her name & SSN. Had I not been there she would have received incorrect treatment.

My wife went to [yet another hospital] for hip replacement. After surgery, while she slept off her anesthesia, a nurse came in and started injecting her. I asked and learned it was insulin. I stopped the nurse (with difficulty). My wife's not diabetic. Her screen showed someone else's orders. Had I not been there she might have died.

So keep up the good work... please!

[redacted name of MD]

How many other patients have been injured or killed as a result of EHR's?

In fact, we really don't know how many adverse events related to EHR's occur. As the Joint Commission itself admits in its Sentinel Events Alert #42, Safely implementing health information and converging technologies: "There is a dearth of data on the incidence of adverse events directly caused by HIT overall." I further wrote on this issue in a paper "A Dearth of Data on Unintended Consequences of Healthcare IT" here.

Is this a proper environment for national rollout of these clearly experimental medical devices, one should ask?

The memes of technological determinism and health IT "white-as-driven-snow" beneficence seem as difficult as vampires to eradicate.

Yet if this technology is to achieve the benefits of which it is capable via remediation of current IT industry customs, traditions and practices, these memes must be challenged and defeated.

Regarding health IT in the real world, reality matters.

-- SS

Insurers Test Data Profiles to Identify Risky Clients

Stories like this one today at the WSJ disturb me.

Insurers Test Data Profiles to Identify Risky Clients
Wall Street Journal
Nov. 19, 2010

From that story:

Life insurers are testing an intensely personal new use for the vast dossiers of data being amassed about Americans: predicting people’s longevity.

Insurers have long used blood and urine tests to assess people’s health—a costly process. Today, however, data-gathering companies have such extensive files on most U.S. consumers—online shopping details, catalog purchases, magazine subscriptions, leisure activities and information from social-networking sites—that some insurers are exploring whether data can reveal nearly as much about a person as a lab analysis of their bodily fluids.

In one of the biggest tests, the U.S. arm of British insurer Aviva PLC looked at 60,000 recent insurance applicants. It found that a new, “predictive modeling” system, based partly on consumer-marketing data, was “persuasive” in its ability to mimic traditional techniques.

The research heralds a remarkable [alarming? -ed.] expansion of the use of consumer-marketing data, which is traditionally used for advertising purposes.


Read the entire article.

The reason I find this article disturbing is that it can and probably should be looked at as another example of technophiles and opportunists with no knowledge of (or lack of caring about) Social Informatics, a decades-old discipline with a focus on studying the unintended consequences of new information and communications technologies (ICT's), enabling our society to move one step closer to centralized control.

Social Informatics (SI) refers to the body of research and study that examines social aspects of computerization, including the roles of information technology in social and organizational change, the uses of information technologies in social contexts, and the ways that the social organization of information technologies is influenced by social forces and social practices.

Stories such as the above WSJ story, and others in their running series on Internet privacy, also dampen my enthusiasm about the possibility that electronic medical information will be kept private, confidential and secure.

-- SS

Medical data breach of the week - but your EMR data is secure, trust us, we're IT experts

I have written frequently about the pipe dream of secure national electronic medical records, such as in February 2010 at my post "Networked EMR's and Healthcare Information Security: Practical When Massive IT Security Breaches Continue?", my post "Networked, Interoperable, Secure National Medical Records a Castle in the Sky?", as well as "Operation Aurora And a Widespread Reluctance to Discuss IT Flaws: Is Universal Healthcare IT Really a Good Idea in 2010?" and others.

I was also quoted on July 30, 2010, in a Philadelphia Inquirer story about the theft of a laptop computer with data on 21,000 patients from Thomas Jefferson University Hospital here, and also interviewed August 2 by local NPR station WHYY-91FM, where I stated:

"There is almost no excuse for unencrypted data to be sitting on any computer at a hospital or any organization," said Scot Silverstein, a Drexel University expert on health-information technology.

In the latest health-data-on-computer-theft-of-the-week, the Inquirer ran this story today about a local theft ten times as large as July's:

Medical-data breach said to be major
A computer flash drive containing the names, addresses, and personal health information of 280,000 people is missing - one of the largest recent security breaches of personal health data in the nation.

"We deeply regret this unfortunate incident," said Jay Feldstein, the president of the two affiliated Philadelphia companies, Keystone Mercy Health Plan and AmeriHealth Mercy Health Plan.

The breach, which involves the records of Medicaid recipients, is the first such Medicaid data breach in Pennsylvania since at least 1997, according to the state's Department of Welfare, which has oversight.

There is little more I can add to my prior postings on this issue except the words of privacy advocate, psychiatrist Dr. Deborah Peel:

The security failure, one of the several largest in nearly two years, involves nearly two-thirds of the insurers' subscribers. It became known only after The Inquirer requested information Tuesday evening. The insurers said the drive was missing from the corporate offices on Stevens Drive in Southwest Philadelphia. It noted that the same flash drive was used at community health fairs.

"That seems grossly irresponsible," said Dr. Deborah Peel, a Texas psychiatrist who heads Patient Privacy Rights, an advocacy group.

"Why would you be hauling around private patient information to a health fair," she said. "I can't imagine what they were thinking, taking this data out of a locked room at company headquarters.

"What's tragic is that this is a particularly vulnerable group of people," Peel said. "They tend to be vulnerable to identity theft, vulnerable to discrimination." Medicaid recipients are low-income people.


As to encryption (a built-in feature of the upper tier versions of Windows and of Mac OS X):

They [the companies] would not comment on the riskiness of taking the drive to health fairs, nor would they say whether the data on the drive was encrypted.

Highly likely translation: no.

The companies issued an apology:

"At Keystone Mercy Health Plan and AmeriHealth Mercy Health Plan, our number one priority is our members. Since reporting this unfortunate incident to the Department of Public Welfare, we have actively and responsibly executed a multifaceted plan to inform those affected, while also evaluating and enhancing our security measures to ensure this does not happen again."

[Did any employee have their "privileges revoked" -- the medical term of art for a physician who is 'fired' -- I wonder? - ed.]

Perhaps the executives in charge of this data, as well as the IT department, should read stories like the aforementioned July 30, 2010 story.

However, I fear there are those who are ineducable or hopelessly irresponsible when it comes to acting cautiously and responsibly regarding computer-based medical information, in the poorly bounded, complex, unpredictable world of healthcare.

That is not to even mention deliberate theft for personal gain.

This is why the dream of
secure national electronic medical records seems a pipe dream for the foreseeable future.

-- SS

10/23 Addendum

in an updated story, the Inquirer reports the data was indeed unencrypted, although the companies claimed an encryption project was in progress.

Healthcare Legislation to "Control the People?"

At "AMA And Almost 100 Physician Societies Sound Off To CMS On Health IT" I referred to concern held by AMA and ~94 other medical specialty societies about comments overheard from senior government officials that:

complex measures and high reporting thresholds are needed to discourage EP's - Eligible Professionals (i.e., eligible for government EHR subsidies) from switching back to the use of paper during this transition to EHRs.

Such reporting requirements could not only 'discourage' a switch back to paper even if these 'government-approved' EHR's turned out to be a clinical and/or operational nightmare (which I feel is likely if not unavoidable based on numerous writings at this blog and here), but also could force event those planning to stay with paper and endure the "penalty" for doing so to move to computer systems. The human resources required to satisfy truly ominous reporting requirements via paper records might simply be too burdensome.

This could be perceived as an ingenious and devious plan to establish control of healthcare providers via IT and data. (He who controls the data, controls the playing field.)

Privacy activist Dr. Deborah Peel shares related concerns as expressed in a Wall Street Journal article yesterday "Your Medical Records Aren't Secure."

Along the lines of control, now there's this, recently posted on the Drudge Report:

Shocking Audio: Rep. Dingell Says ObamaCare Will Eventually ‘Control the People’ (link)

I don't care which "people" Dingell's referring to - 300 [sic] Americans (he left out "million"), physicians, insurers, etc. Our government has no business discussing "controlling" anyone.

Ideology aside, the control mentality of government over medicine, facilitated by healthcare IT, is starting to rear an ugly head. I'm afraid this phenomenon might get really out of hand in the very near future.

-- SS

Addendum: there appears to be a healthcare IT industry sockpuppet writing in the comments thread at the aforementioned WSJ article by Dr. Peel, under the especially inappropriate nom de blog "Hank Dagny." The usual dismissal of physician concerns about HIT, unqualified statements, ad hominem attacks, and other games typical of an industry shill occur throughout that comment thread.

See my reply at this link. (It takes a moment to load the WSJ comment thread.)

Also see this summary of a Canadian analysis of electronic health record security at the blog of security technologist Bruce Schneier. Hat tip to Joseph Arpaia, MD.

Networked EMR's and Healthcare Information Security: Practical When Massive IT Security Breaches Continue?

At "Networked, Interoperable, Secure National Medical Records a Castle in the Sky?" I wrote that the holy grail of electronic medical record efforts - the creation of a networked, interoperable, secure national medical records system - may be far more difficult than anyone expected due to vulnerabilities in current, widespread IT networking and OS platforms.

Now we hear the situation is even worse than in the articles I cited at that post:


Wall Street Journal
Feb. 18, 2010
Broad New Hacking Attack Detected

Global Offensive Snagged Corporate, Personal Data at nearly 2,500 Companies; Operation Is Still Running

Hackers in Europe and China successfully broke into computers at nearly 2,500 companies and government agencies over the last 18 months in a coordinated global attack that exposed vast amounts of personal and corporate secrets to theft, according to a computer-security company that discovered the breach.

The damage from the latest cyberattack is still being assessed, and affected companies are still being notified. But data compiled by NetWitness, the closely held firm that discovered the breaches, showed that hackers gained access to a wide array of data at 2,411 companies, from credit-card transactions to intellectual property.

One can only imagine how internet-connected hospitals, generally an IT backwater, might fare under such an onslaught.

... In more than 100 cases, the hackers gained access to corporate servers that store large quantities of business data, such as company files, databases and email.

They also broke into computers at 10 U.S. government agencies. In one case, they obtained the user name and password of a soldier's military email account, NetWitness found. A Pentagon spokesman said the military didn't comment on specific threats or intrusions.

At one company, the hackers gained access to a corporate server used for processing online credit-card payments. At others, stolen passwords provided access to computers used to store and swap proprietary corporate documents, presentations, contracts and even upcoming versions of software products, NetWitness said.

Data stolen from another U.S. company pointed to an employee's apparent involvement in criminal activities; authorities have been called in to investigate, NetWitness said. Criminal groups have used such information to extort sensitive information from employees in the past.


Read the while article. These breaches are an unpleasant reality in 2010, but what's worse is there really are no solid metrics for the true extent of this 'disease.'

Perhaps future Internet technologies will reduce or eliminate the problem, as one reader suggested in a comment to my aforementioned post. I do not believe, however, that patients and their medical records should be used as guinea pigs until those new networking and security technologies are widely deployed and well-proven.

In effect, this is probably not a good time for actual records-level interoperability to be deployed in any manner other than in consideration of a future strategy. Operationalizing that strategy should probably await a time when the "digital ether" in which the data resides and moves is more mature, unless proprietary networks and technology are to be used and without connection to the Internet. Planning data-level compatibility between systems, on the other hand, is work that should continue.

Finally, the layoffs and staffing levels in today's IT departments (at both vendor and user shops), plus the outsourcing of critical IT functions to overseas contractors where workers' loyalty to the primary firm is questionable at best, may be a contributing factor to the nakedness of corporate America's information systems.

-- SS

Networked, Interoperable, Secure National Medical Records a Castle in the Sky?

The holy grail of electronic medical record efforts of late is the creation of networked, interoperable, secure national medical records that would allow a physician in Palo Alto to retrieve the records of a patient from Hoboken if that patient moved or was found (in the hackneyed and somewhat histrionic scenario) unconscious on the streets of San Francisco.

Recent events have made me skeptical we are anywhere near ready for such a technological accomplishment:

McAfee: Big Business Under Constant Cyber Attack
01.29.10

At the World Economic Forum Annual Meeting in Switzerland, McAfee announced the results of a survey of 600 IT security execs in "critical infrastructure enterprises worldwide": that is, in places such as utility companies, banks, and even oil refineries. And apparently, they're constantly under cyber attack and also extortion related to those attacks.


It's a real battlefield out there.

The report, written by the Center for Strategic and International Studies (CSIS), says that 54 percent of those surveyed have already been attacked. The culprits behind the cyber-attacks are listed as "organized crime-gangs, terrorists, or nation-states."

In other words, not simply teenage hackers or cyber-papparazi interested in the medical condition of a movie star.

Only one-fifth of the IT execs surveyed believe their systems are currently secure. One-third say things are worse now, vulnerability-wise, than a year ago, due to budget cuts.

What constitutes a cyber attack? A distributed denial of service (DDoS) is the most typical ... mitigation can be hampered by the local laws, working in multiple countries, or the economics of where they operate. For example, half of those surveyed claim the laws in their countries don't do enough to prevent or deter cyber attacks. That's especially true for Russia, Mexico, and Brazil.

Other attack vectors include DNS poisoning where Web traffic is redirected, SQL injection attacks on back-end data via a public Web site, and plain old theft of services.

If you need a plot for your new thriller novel, keep in mind that 20 percent of these companies are not just cyber-attacked, but have also been threatened with attacks in the last two years in "low-level extortion" attempts.

... Those surveyed said the money loss is the worst part, second is the loss of reputation, and (if you thought you weren't important) loss of customers' personal information is third.

This is a worldwide survey, and almost two-thirds of those surveyed believe foreign governments were responsible in some way for previous attacks. The two countries considering the biggest threats: China (by 33 percent of those surveyed) and the good ol' U.S. of A. (by 36 percent). China believes it's the biggest target.

The full report, called In the Crossfire: Critical Infrastructure in the Age of the Cyber War is free on McAfee's Web site in PDF format.

I note that Google recently called in the National Security Agency to help analyze a major corporate espionage attack:

The attacks targeted Google source code -- the programming language underlying Google applications -- and extended to more than 30 other large tech, defense, energy, financial and media companies. The Gmail accounts of human rights activists in Europe, China and the United States were also compromised.

Then there's this:

Intelligence Chief: U.S. at Risk of Crippling Cyber Attack

Feb. 4, 2010

The United States is at risk of a crippling cyber attack that could "wreak havoc" on the country, Director of National Intelligence Dennis Blair said.

"What we don't quite understand as seriously as we should is the extent of malicious cyberactivity that grows, that is growing now at unprecedented rates, extraordinary sophistication," Blair said.

... He said one critical "factor" is that more and more foreign companies are supplying software and hardware for government and private sector networks. "This increases the potential for subversion of the information in ... those systems," Blair said. [Outsourcing our HIT development overseas sounds like a great idea - ed.]


Read the linked articles in their entirety.

Perhaps we should focus on the local at present. National networked EMR's are a great concept, but there are a few social-technical details that remain to be worked out beforehand.


A Castle in the Sky...

-- SS

Operation Aurora And a Widespread Reluctance to Discuss IT Flaws: Is Universal Healthcare IT Really a Good Idea in 2010?

In an essay that ties together recent exposés of serious IT security flaws (starting with Operation Aurora) and a culture of secrecy that pervades the IT industry and industries who use IT, I ask the question:

Is universal healthcare IT really a good idea in 2010?

The complete essay is at my academic site at this link.

Operation Aurora was a cyber attack, conducted in mid-December 2009 and apparently originating in China, against Google and more than 20 other companies, including Adobe Systems, Juniper Networks, Rackspace, Yahoo, Symantec, Northrop Grumman and Dow Chemical.

The attack used "0-day" vulnerabilities (newly discovered and unknown to the software vendor, i.e., "day zero" of the vendor's knowledge of the defect) in Microsoft's Internet Explorer. One target was Google's email service, Gmail. It is not unrealistic to suspect that successful break-ins to that service could have gotten dissidents jailed or killed. Entire countries have warned users to switch to other browsers, at least until a vulnerability fix can be found. I find this stunning.

I also bring to bear recent reports of a culture of secrecy among IT vendors and users about these defects and vulnerabilities. This culture of secrecy seems prevalent in health IT, with perhaps even higher stakes for people (patients) when systems malfunction.

The essay is long-ish and at times technical.

The IT issues it addresses, though, are at the root of why I believe the current push in health IT is a bad idea and that we need to "slow down" to a more temperate pace.

Again, the full essay is here.

-- SS

1/24/2010 Addendum:

It appears Microsoft has known about the Internet Explorer bug since Sept. 2009.

The flaw was in the Microsoft Security Response Center's (MSRC) queue to be fixed in the the next batch of patches due in February but the targeted zero-day attacks against U.S. companies forced the company to release an emergency, out-of-band IE update.

Actually, this was not a "zero day attack", but a "120 day attack." One wonders if EHR vendors have similar queues.

-- SS

Label