Showing posts with label healthcare IT safety. Show all posts
Showing posts with label healthcare IT safety. Show all posts

Thursday, June 14, 2012

Ellmers Calls on Sebelius to Address Health IT Safety Concerns: A Responsible Voice in Government on Health IT and HIT Safety

The following press release is very welcome, and speaks for itself.  There is a responsible voice in the government wilderness.  It is perhaps no surprise it comes from a Congresswoman who is also a registered nurse:

Ellmers Calls on Sebelius to Address Health IT Safety Concerns



Safety Risks and Health IT-Related Errors Cited in IOM Recommendations

WASHINGTON – House Small Business Subcommittee on Healthcare and Technology Chairwoman Renee Ellmers (R-NC) today sent a letter to Kathleen Sebelius, Secretary of Health and Human Services (HHS), inquiring about whether the Department has adopted the Institute of Medicine’s (IOM) recommendations for improving the safety of health information technology (IT).
The report, issued in November, recommended several steps to be taken by HHS and called for greater oversight by the public and private sectors. The Secretary was called upon by the IOM to issue a plan within 12 months to minimize patient safety risks associated with health IT and report annually on the progress being made.  The report further recommended that the plan should include a schedule for working with the private sector to assess the impact of health IT on patient safety, and recommended several other steps to help improve the safety of health IT.

Specifically, Chairwoman Ellmers has requested a copy of the Secretary’s plan to minimize patient safety risks, a description of health IT-related errors that have resulted in patient risks, injuries and deaths, and the status of the development of a mechanism for health IT vendors and users to report health IT-related deaths.  She said that because health IT has the promise to improve health care delivery for patients, physicians and other medical professionals, she remains eager to work with the Secretary to ensure that health IT is safe, effective and affordable.

In an August 11, 2011 letter to Secretary Sebelius, Chairwoman Ellmers said that a modern, well-equipped office is critical to the practice of medicine, and asked the Secretary to undertake a study of health IT’s adoption, benefits and cost effectiveness, including medical error rates.

On June 2, 2011, Chairwoman Ellmers’ Subcommittee held a hearing on the barriers to health IT that are encountered by physicians and other health professionals in small and solo practices.   At the hearing, physicians expressed strong concerns about the cost of purchasing and maintaining health IT systems, as well as the staff training and downtime necessary to implement such a system.  Chairwoman Ellmers noted health IT’s great potential to improve health care delivery, decrease medical errors, increase clinical and administrative efficiency and reduce paperwork.

For more than twenty-one years before being elected to Congress, Chairwoman Ellmers served as a registered nurse, focusing on surgical care as Clinical Director of the Trinity Wound Care Center and later helping to manage the family's small medical practice with her husband, Dr. Brent Ellmers, a licensed surgeon. As a registered nurse and the wife of a surgeon, Ellmers understands that a modern, efficient and well-equipped office is critical to the practice of medicine.    

This voice of sanity is quite welcome.  I've spoken with Rep. Ellmers' office, pointing them to my Drexel Univ. writings and materials and recommending Sebelius' reply be gone over with a fine-toothed comb, from the perspective of health IT realities, not merely from the perspective of the Ddulite's good intentions.  (I also introduced her staffer to the concept of the Ddulite, the HIT hyper-enthusiast who ignores all downsides and ethical concerns.)

I also pointed out the ethical lapse in IOM's position of "wait and see" while HIT is pushed nationally under penalty of law, at the cost of hundreds of billions of dollars, when their own report (along with reports from FDA here, JC here and others) admits they don't know the magnitude of benefits, risks and harms:

... While some studies suggest improvements in patient safety can be made, others have found no effect. Instances of health IT–associated harm have been reported. However, little published evidence could be found quantifying the magnitude of the risk.

Several reasons health IT–related safety data are lacking include the absence of measures and a central repository (or linkages among decentralized repositories) to collect, analyze, and act on information related to safety of this technology. Another impediment to gathering safety data is contractual barriers (e.g., nondisclosure, confidentiality clauses) that can prevent users from sharing information about health IT–related adverse events. These barriers limit users’ abilities to share knowledge of risk-prone user interfaces, for instance through screenshots and descriptions of potentially unsafe processes. In addition, some vendors include language in their sales contracts and escape responsibility for errors or defects in their software (i.e., “hold harmless clauses”). The committee believes these types of contractual restrictions limit transparency, which significantly contributes to the gaps in knowledge of health IT–related patient safety risks. These barriers to generating evidence pose unacceptable risks to safety.
[IOM (Institute of Medicine). 2012. Health IT and Patient Safety: Building Safer Systems for Better Care (PDF). Washington, DC: The National Academies Press, pg. S-2.]

As I wrote in my Nov. 2011 post "IOM Report - 'Health IT and Patient Safety: Building Safer Systems for Better Care' - Nix the FDA; Create a New Toothless Agency", the IOM's response to their own study was reckless and unethical (at best):

... The panel also recommends that the HHS secretary publicly report on the progress of health IT safety each year, beginning in 2012. If the secretary determines at any time that adequate safety progress has not been made, only then should the FDA take the regulatory lead and be given the resources to do so, the report recommends, adding that the agency should be developing a framework now to be prepared.

In the meantime, during each year of "watching for safety progress", innumerable patients are exposed to HIT's hazards and costs.  Pharma and other medical device industries are afforded no such special accommodation.

-- SS

Sunday, June 3, 2012

WSJ "There's a Medical App for That—Or Not" - Misinformation on Health IT Safety Regulation?

There's a health IT meme that just won't die (patients may, but not the meme).

It's the meme that health IT "certification" is a certification of safety.

I expressed concern about the term "certification" being misunderstood even before the meme formally appeared, when the term was adopted by HHS with regard to evaluation of health IT for adherence to the "meaningful use" pre-flight features checklist.  See my mid-2009 post "CCHIT Has Company" where I observed:

HIT "certification." ... is a term I put in quotes since it really is "features qualification" at this point, not certification such as a physician receives after passing Specialty Boards.

The "features qualification" is an assurance that the EHR functions in way that could enable an eligible provider or eligible hospital to meet the Center for Medicare & Medicaid Services' (CMS) requirements of "Meaningful Use."  No rigorous safety testing in any meaningful sense is done, and no testing under real-world conditions is done at all.

I've seen the meme in various publications and venues.  I've even seen it in legal documents in medical malpractice cases where EHR's were involved, as an attempted defense.

Now the WSJ has fallen for the health IT Certification meme.

An article "There's a Medical App for That—Or Not" was published on May 29, 2012.  Its theme is special regulatory accommodation for health IT in the form of opposition to FDA regulation of devices such as "portable health records and programs that let doctors and patients keep track of data on iPads."

In the article, this assertion about health IT "certification" is made:

... The FDA's approach to health-information technology risks snuffing out activity at a critical frontier of health care. Poor, slow regulation would encourage programmers to move on, leaving health care to roil away for yet another generation, fragmented, disconnected and choking on paperwork.

The process already exists for safeguarding the public for computers in health care. It's not FDA premarket review but the health information technology certification program, established under President George W. Bush and still working fine under the Obama Health and Human Services Department. The government sets the standards and an independent nonprofit [ATCB, i.e., ONC Authorized Testing and Certification Bodies - ed.] ensures that apps meet those standards. It's a regulatory process as nimble as the breakout industry it's meant to monitor. That is where and how these apps should be regulated.

It's a wonderful meme.  Unfortunately, it's wrong.  Dead wrong.

Certification by an ATCB does not "safeguard the public."   Two ONC Authorized Testing and Certification Bodies (ATCB's) admitted this in email, as in my Feb. 2012 post "Hospitals and Doctors Use Health IT at Their Own Risk - Even if Certified".  I had asked them, point-blank:

"Is EHR certification by an ATCB a certification of EHR safety, effectiveness, and a legal indemnification, i.e., certifying freedom from liability for EHR use of clinical users or organizations? Or does it signify less than that?"

I received two replies from major ONC ATCB's indicating that "certification" is merely assurance that HIT meets a minimal set of "meaningful use" guidelines, not that it's been vetted for safety.  For instance:

From: Joani Hughes (Drummond Group)
Sent: Monday, March 05, 2012 1:06 PM
To: Scot Silverstein
Subject: RE: EHR certification question

Per our testing team:

It is less than that. It does not address indemnification although a certification could be used as a conditional part of some other form of indemnification function, such as a waiver or TOA, but that is ultimately out of the scope of the certification itself. Certification in this sense is an assurance that the EHR functions in way that could enable an eligible provider or eligible hospital to meet the CMS requirements of Meaningful Use Stage 1. Or to restate it more directly, CMS is expecting eligible providers or eligible hospitals to use their EHR in “meaningful way” quantified by various quantitative measure metrics and eligible providers or eligible hospitals can only be assured they can do this if they obtain a certified EHR technology.

Please let me know if you have any questions.

Thank you,
Joani.

Joani Hughes
Client Services Coordinator
Drummond Group Inc.

The other ATCB, ICSA Labs, stated that:

... Certification by an ATCB signifies that the product or system tested has the capabilities to meet specific criteria published by NIST and approved by the Office of the National Coordinator. In this case the criteria are designed to support providers and hospitals achieve "Meaningful Use." A subset of the criteria deal with the security and patient privacy capabilities of the system.

Here is a list of the specific criteria involved in our testing:
http://healthcare.nist.gov/use_testing/effective_requirements.html

In a nutshell, ONC-ATCB Certification deals with testing the capabilities of a system, some of them relate to patient safety, privacy and security functions (audit logging, encryption, emergency access, etc.).

What was suggested in the email below (freedom from liability for users of the system, etc.) would be out of scope for ONC-ATCB testing based on the given criteria. [I.e., certification criteria - ed.] I hope that helps to answer your question.

I had noted that:

... My question was certainly answered [by the ATCB responses]. ONC certification is not a safety validation, such as in a document from NASA on aerospace software safety certification, "Certification Processes for Safety-Critical and Mission-Critical Aerospace Software" (PDF) which specifies at pg. 6-7:
In order to meet most regulatory guidelines, developers must build a safety case as a means of documenting the safety justification of a system. The safety case is a record of all safety activities associated with a system throughout its life. Items contained in a safety case include the following:

• Description of the system/software
• Evidence of competence of personnel involved in development of safety-critical software and any
safety activity
• Specification of safety requirements
• Results of hazard and risk analysis
• Details of risk reduction techniques employed
• Results of design analysis showing that the system design meets all required safety targets
Verification and validation strategy
• Results of all verification and validation activities
• Records of safety reviews
• Records of any incidents which occur throughout the life of the system
• Records of all changes to the system and justification of its continued safety

A CCHIT ATCB juror, a physician informatics specialist, has also done a guest post in Jan. 2012 on HC Renewal about the certification process, reproducing his testimony to HHS on the issue.  That post is "Interesting HIT Testimony to HHS Standards Committee, Jan. 11, 2011, by Dr. Monteith."  Dr. Monteith testified (emphases mine):

... I’m “pro-HIT.” For all intents and purposes, I haven’t handwritten a prescription since 1999.

That said and with all due respect to the capable people who have worked hard to try to improve health care through HIT, here’s my frank message:

ONC’s strategy has put the cart before the horse. HIT is not ready for widespread implementation. 

... ONC has promoted HIT as if there are clear evidence-based products and processes supporting widespread HIT implementation.

But what’s clear is that we are experimenting…with lives, privacy and careers.

... I have documented scores of error types with our certified EHR, and literally hundreds of EHR-generated errors, including consistently incorrect diagnoses, ambiguous eRxs, etc.

As a CCHIT Juror, I’ve seen an inadequate process. Don’t get me wrong, the problem is not CCHIT. The problem stems from MU.

EHRs are being certified even though they take 20 minutes to do a simple task that should take about 20 seconds to do in the field.  [Which can contribute to mistakes and "use error" - ed.] Certification is an “open book” test. How can so many do so poorly?

For example, our EHR is certified, even though it cannot generate eRxs from within the EHR, as required by MU.

To CCHIT’s credit, our EHR vendor did not pass certification. Sadly, our vendor went to another certification body, and now they’re certified.

MU does not address many important issues. Usability has received little more than lip-service. What about safety problems and reporting safety problems? What about computer generated alerts, almost all of which are known to be ignored or overridden (usually for good reason)?
 
The concept of “unintended consequences” comes to mind.

All that said, the problem really isn’t MU and its gross shortcomings, it is ONC trying to do the impossible:

ONC is trying to artificially force a cure for cancer, basically trying to promote one into being, when in fact we need to let one evolve through an evidence-based, disciplined process of scientific discovery and the marketplace.

Needless to say, as was learned at great cost in past decades, a "disciplined process" in medicine includes meaningful safety regulation by objective outside experts.

Further, the certifiers have no authority to do important things such as forcibly remove dangerous software from the market.  An example is the forced Class 1 recall of a defective system as I wrote about in my Dec. 2011 post "FDA Recalls Draeger Health IT Device Because This Product May Cause Serious Adverse Health Consequences, Including Death".   Class 1 recalls are the most serious type of recall and involve situations in which there is a reasonable probability that use of these products will cause serious adverse health consequences or death.

In that situation, the producer had been simply advising users (in critical care environments, no less) to "work around the defects" that could indicate incorrect recommended dosage values of critical meds, including a drug dosage up to ten times the indicated dosage, as well as corrupt critical cardiovascular monitoring data.  As I observed:

... I find a software company advising clinicians to make sure to "work around" blatant IT defects in "acute care environments" the height of arrogance and contempt for patient safety.

Without formal regulatory authority to take actions such as this FDA recall, "safeguarding the public" is a meaningless platitude.

It's also likely the ATCB's, which are private businesses, would not want the responsibility of "safeguarding the public."  That responsibility would open them up to litigation when patient injuries or death were caused, or were contributed to, by "certified" health IT.

I have in the past also noted that the use of the term "certification" might have been deliberate, to mislead potential buyers exactly into thinking that "certification" is akin to a UL certification of an electrical appliance for safety, or an FAA approval of a new aircraft's flight-worthiness.

The WSJ needs to clarify and/or retract its statement, as the statement is misinformation.

At my Feb. 2012 post "Health IT Ddulites and Disregard for the Rights of Others" I observed:

Ddulites [HIT hyper-enthusiasts - ed.] ... ignore the downsides (patient harms) of health IT.

This is despite being already aware of, or informed of patient harms, even by reputable sources such as FDA (Internal FDA memo on H-IT risks), The Joint Commission (Sentinel Events Alert on health IT), the NHS (Examples of potential harm presented by health software - Annex A starting at p. 38), and the ECRI Institute (Top ten healthcare technology risks), to name just a few.

In fact, the hyper-enthusiastic health IT technophiles will go out of their way to incorrectly dismiss risk management-valuable case reports as "anecdotes" not worthy of consideration (see "Anecdotes and medicine" essay at this link).

They will also make unsubstantiated, often hysterical-sounding claims that health IT systems are necessary to, or simply will "transform" (into what, exactly, is usually left a mystery) or even "revolutionize" medicine (whatever that means).

Health IT is a potentially dangerous technology.   It requires meaningful regulation to "safeguard the public."  How many incidents like this and this will it take before that is understood by the hyper-enthusiasts?

I've emailed the ATCB's that had responded to my aforementioned query for clarification on the WSJ assertion about their role, being that the statement is in contradiction to their earlier replies to me.  I also advised them of the potential liability issues.

However, if it turns out to be true that the ONC-ATCB's do intend themselves as the ultimate watchdog and assurer of public safety related to EHR's, that needs to be known by the public and their representatives.

-- SS

Friday, June 1, 2012

Upcoming Keynote Presentation to Health Informatics Society of Australia: Health IT Must First Do No Harm

Pulse+IT Magazine (http://www.pulseitmagazine.com.au/) is Australasia's first, and they claim only, eHealth and Health IT periodical.

In a May 30, 2012 article entitled "Patient and safety advocates a highlight at HIC2012" at this link, writer Kate McDonald describes my upcoming panel participation and Keynote Presentation at the annual Health Informatics Conference (HIC) of the Health Informatics Society of Australia (HISA) in Sydney.

The focus of the HIC2012 meeting is "Building a Healthcare Future through Trusted Information."

Ms. McDonald had called me from Down Under to discuss my upcoming talk.  She writes:

 ... Also on the panel [one of the conference's annual Q&A panels - ed.] will be NEHTA CEO Peter Fleming, HISA board director and well-known consultant David Rowlands, and Scot Silverstein, an adjunct professor of health informatics at Drexel University in the US.

Dr Silverstein also has a personal story to tell that brings home the importance of what exactly is 'trusted' information. A qualified medical doctor and medical informatics researcher, Dr Silverstein is a strong advocate for safety in health IT systems, having been personally involved in what he believes was a case of medical misadventure caused by an electronic health record that resulted in harm to a close relative.

He will also deliver a keynote speech on the topic of improving health IT systems as a first step towards evidence-based medicine and better clinical outcomes.

Dr Silverstein told Pulse+IT that there is a “syndrome of over-confidence” in computer output that he finds puzzling.

“In other fields people, when they start getting incorrect bills or they keep coming and they can't stop them, it is always blamed on a computer system,” he said. “And yet in medicine, it seems to have evolved a culture around computing that machines in healthcare must deterministically create improvement and are purely beneficent and can't be capable of creating harm.

“It is a strange philosophy because in the same breath, people say healthcare information technology is capable of great benefit, that is a very powerful technology and when it is done well, it is. [As I've written before, "doing HIT well" is a challenge of 'wicked' complexity - ed.]  But anything that is a potential source for great good can also have a downside. There seems to be a cognitive gap in connecting computing in healthcare to its possible risk.”

She summarizes the views expressed in our phone conversation well.  My theme will be that health IT and the information it generates cannot be trusted until the technology itself is trustworthy, and earns our trust, through better engineering and implementation practices.

Ironically, I was invited to 2011's meeting.  I would have attended, but was tending to the injuries of my relative caused by the aforementioned medical misadventure. That relative is no longer with us and is hopefully resting in peace.

HISA was kind enough to re-invite me for 2012, for which I am grateful.

I will also be spending some time with several Medical Informatics professors in Australian universities, which should provide an excellent opportunity for sharing of views.


Sydney, Australia

I look forward to being in Sydney, never having been physically present in Australia, although being a ham radio operator, my single sideband (voice) and Morse code shortwave signals have been there on many occasions over the years.  This is a mere ~ 10,000-mile path.  No Internet or phone lines needed!  (I hope I get the opportunity to operate an Amateur radio station from "Down Under.")

More here after my presentation.

-- SS

Tuesday, February 21, 2012

Is ONC Stonewalling on the issue of HIT Certification, Safety and Liability?

At my Feb. 16, 2012 post "Hospitals and Doctors Use Health IT at Their Own Risk - Even if Certified" I wrote that an ONC-ATCB (Authorized Testing and Certification Body) replied to my email inquiry about health IT certification, safety and liability indemnification by stating that:

What was suggested in the email below (freedom from liability for users of the system, etc.) would be out of scope for ONC-ATCB testing based on the given criteria.

[That is, the criteria used in testing
here - ed.]

What I did not include in that post was the fact that some months ago, I had emailed ONC directly with the same questions, and then called them on the phone with those questions at about the same time as I inquired of the ATCB.

ONC itself never responded.

There are several possibilities:

  • They don't know the answer.
  • They don't want to respond.
  • They don't care to respond.


Dismissing possibility #1, these civil servants appear to be stonewalling on the issue.

It would be nice to hear ONC itself admit the term "certification" is a gossamer guarantee of health IT safety, efficacy and indemnification of purchasers, implementers and users from potential EHR-related liability.

I am not holding my breath.

-- SS

Addendum:

An ONC representative did get back to me on Feb. 27, but I told them my question had already been answered by ONC ATCB's.

Monday, November 7, 2011

IOM Report - "Health IT and Patient Safety: Building Safer Systems for Better Care" - Nix the FDA; Create a New Toothless Agency

[Authors' note: This major part of this post was written before I had the actual IOM report itself. Having now read that report, available here in PDF, my opinions are unchanged.]

The Center for Public Integrity has published a story ahead of the Thursday release of the Institute of Medicine's report on health IT safety. This was a panel, by the way, that rejected my testifying, live, about my own relative's IT- related harm, despite my Medical Informatics credentials and explicit requests [see note below].

The IOM report apparently recommends that an extraordinary special accommodation be afforded to the healthcare IT industry regarding regulation of health IT software devices.

Excerpts from the Center for Public Integrity's article:

Health information technology has been touted as crucial to better health care, but a new report says an entirely new regulatory agency is needed to oversee this largely unregulated sector, which can also injure or kill patients if it’s not operating properly.

We would never have known that if not for the efforts of a small group of specialists with a conscience writing on this issue over the past decade; the industry long emphasized only the beneficence of the technology.
In pushing for a new oversight body, the respected Institute of Medicine, an independent research and advisory organization, is explicitly advising that the Food and Drug Administration (FDA) not be tasked with the job — a recommendation that is bound to be controversial. [Indeed - ed.]
The eagerly anticipated report, titled “Health IT and Patient Safety: Building Safer Systems for Better Care,” will be publicly released Thursday. A copy was obtained by iWatch News. The study details nine other recommendations for how to ensure patient safety when doctors and other health care providers use health information technology, or health IT. The findings from the report were presented October 28 to the Department of Health and Human Services (HHS) and its agencies.

I do not consider the IOM's rationale for excluding the FDA to be reasonable...more below.

... the push [by the Administration] is occurring so far without any agency really ‘watch dogging’ the safety of health IT — the software, hardware and systems that record and manage patients’ health information. These expensive devices by and large have not gone through any regulatory checks for safety in the way that food, drugs and other medical technology must; most of that oversight is handled by the FDA. But at the moment, no one is required to report instances of harm caused by health information devices and no government agency currently monitors their safety.

This is a scandal of major proportions, considering the government has taken the approach "ready, shoot, aim" in putting in place penalties for non-adopters on a fantastically rushed timeline, via the HITECH Act within ARRA, while ignoring the risks.

“With all of that money, marketing and public outreach, most simply affirm the value of health IT as an article of faith, rather than investigate it via careful evaluation,” said Ross Koppel, adjunct professor of sociology at the University of Pennsylvania and its School of Medicine, and investigator for RAND Corporation. He is listed as one of the reviewers of the report.

"Faith" (e.g., irrational exuberance) in a technology has no place in science or medicine.

Addendum:  from the report itself:

... While some studies suggest improvements in patient safety can be made, others have found no effect. Instances of health IT–associated harm have been reported. However, little published evidence could be found quantifying the magnitude of the risk.

Several reasons health IT–related safety data are lacking include the absence of measures and a central repository (or linkages among decentralized repositories) to collect, analyze, and act on information related to safety of this technology. Another impediment to gathering safety data is contractual barriers (e.g., nondisclosure, confidentiality clauses) that can prevent users from sharing information about health IT–related adverse events. These barriers limit users’ abilities to share knowledge of risk-prone user interfaces, for instance through screenshots and descriptions of potentially unsafe processes. In addition, some vendors include language in their sales contracts and escape responsibility for errors or defects in their software (i.e., “hold harmless clauses”). The committee believes these types of contractual restrictions limit transparency, which significantly contributes to the gaps in knowledge of health IT–related patient safety risks. These barriers to generating evidence pose unacceptable risks to safety.
[IOM (Institute of Medicine). 2012. Health IT and Patient Safety: Building Safer Systems for Better Care (PDF). Washington, DC: The National Academies Press, pg. S-2.]

In other words, nobody has any real idea of the magnitude of harms, which also implies nobody knows if the magnitude of harms exceeds the magnitude of benefits.  National rollout under these conditions is a horribly unethical situation on first principles.

Though a variety of studies have concluded that the use of health IT may improve patient safety, mistakes made in the systems or difficulty using the technology can lead to serious injury or death, according to the report.

Other studies actually show little or no benefit or cost savings. See this reading list for examples. So, it has been article of faith that the technology in its present form is of benefit, and is not a risk.

An allergy might be omitted from a computer record, for example, or an incorrect medication dosage might be recorded. In Rhode Island, a Lifespan computer glitch [5] caused about 2,000 patients to receive the wrong types of medications. In another instance [6] in March 2009, an unattended patient suffered multiple seizures for hours after a computer failed to alert doctors the patient was moved from the intensive care into their ward.

And people die needlessly (a few examples are at link, link, link).

As reports of patient harm began to emerge, the federal Office of the National Coordinator (ONC) for health IT asked the Institute of Medicine (IOM) a year ago to establish a Committee on Patient Safety and Health Information Technology to make recommendations to the government about how to maximize health IT safety.

I would rephrase that to: as reports on patient harm were no longer able to be suppressed by the industry...

In its report, the IOM committee says the FDA would likely restrict market innovation in health IT, which could also jeopardize patient safety.

There has been little to no real "innovation" in health IT in well over a decade; if anything, the usability and quality has deteriorated. Further, there is no data supporting the contention that FDA regulation of IT harms innovation. Pharma IT (regulated) is far more innovative than the IT in healthcare delivery (unregulated).

Stringent regulations “can negatively impact the development of new technology by limiting implementation choices and restricting manufacturers’ flexibility to address complex issues,” the report says.

Bull. It will keep the companies honest and "encourage" them to adhere to good software engineering and usability principles (unlike here), which will save lives. It's unfortunate such "encouragement" is needed, I note.

The FDA currently receives voluntary reports [7] of health IT-related incidents, but has no resources or protocols through which to take action; the agency has long fought a losing battle [8] with health IT vendors over trying to monitor the technology. The report also notes the agency does not have the investigative capabilities, funding or manpower to regulate devices such as electronic health records, personal health records or health information exchanges.

Then give them the resources, not develop an entire new agency. The FDA has the talent and experience. [Note: I have no connections to FDA whatsoever - ed.]

... To adequately oversee health IT safety, the committee recommends that the secretary of health and human services create and fund a new independent watchdog agency, along the lines of the National Transportation Safety Board. Like NTSB, the new agency would conduct investigations and make recommendations for all stakeholders, including the secretary of the health and human services, vendors and health care organizations. Vendors of the technology would be required to report adverse events, while reporting would be voluntary for clinicians. Like NTSB, though, the new agency would also have no enforcement power.

That is to say, it will be toothless and ignored, leaving a cavalier industry that should have gotten its act together twenty years ago to continue on with its nihilistic ways.

The panel also recommends that the HHS secretary publicly report on the progress of health IT safety each year, beginning in 2012. If the secretary determines at any time that adequate safety progress has not been made, only then should the FDA take the regulatory lead and be given the resources to do so, the report recommends, adding that the agency should be developing a framework now to be prepared.

This makes little sense. In fact, it's an extraordinary special accommodation to the health IT industry (or should I say lobby) relative to other healthcare medicine/device sectors, and is bizarre. It continues health IT as a human subjects research experiment without informed consent and opt-out.
With catastrophe-inviting events like this one becoming more commonplace, just how many patients will have been maimed or died in the meantime while the HHS Secretary's 'determination of adequate safety progress' is being made? (What, exactly, will be deemed 'adequate', I also ask?)
Creating a new independent agency would, of course, require resources; the current budget for NTSB is set at $559 million over the 2010 to 2014 period. In the current climate of fiscal restraint, convincing Congress to appropriate that sort of cash for a new government body might be a tall order.

I note that it's a waste of taxpayer money to create a new agency to maintain/increase health IT industry profits at the expense of patients - not a wise choice IMO.


... Republican Sen. Chuck Grassley [11] of Iowa, senior member of the Senate Finance Committee, said the new report “adds more to the list of unresolved questions, including which government agency, if any, should regulate health care information technology.” Grassley, who wrote [12] HHS and health IT vendors two years ago asking what was being done to ensure the safety of the devices, said “the approach seemed to be, write checks first, solve the problems later, instead of the other way around.”

Having spoken extensively with Sen. Grassley's staff on these issues, I agree - except for the "seemed to be" disclaimer. Replace "seemed to be" with "was."

The Institute of Medicine committee does have one dissenter. Dr. Richard Cook [13] from the University of Chicago feels the FDA is indeed the proper agency to oversee health IT safety. Cook writes that health IT is considered a “Class III medical device,” that is to say, a device that performs integral medical functions, which the FDA already has the jurisdiction to regulate.

Dr. Cook is a co-author of the short 2005 paper "Hiding in plain sight: What Koppel et al. tell us about healthcare IT" which I consider seminal in understanding why health IT as it exists today is so poorly done.

In its report, the IOM panel also recommended that another study be done to quantify health IT-related deaths, serious injuries or unsafe conditions so that the safety concerns can be properly addressed. “You can only improve what you measure,” says the report.

As I wrote in Oct. 2010, that is putting the cart before the horse again. We study these issues while a national rollout under threat of penalty is underway? That's simply crazy.

Other recommendations in the report: establishing and enforcing criteria for the safety of electronic health records, funding a new Health IT Safety Council to set standards for safety, and requiring all health IT vendors to publicly register and list their products with the Office of the National Coordinator.

No issues there, except these efforts should have occurred over a decade ago, at the latest.

Finally, while I disagree with the action agenda, I do thank the IOM for bringing the issues of health IT risks out into the sunlight. Perhaps now these issues will start to be addressed, and ultimately patient safety and human rights safeguarded.

From the report's introduction:

... Caught in the middle are the patients—the ultimate recipients of care. Stories of patient injuries and deaths associated with health information technologies (health IT) frequently appear in the news, juxtaposed with stories of how health professionals are being provided monetary incentives to adopt the very products that may be causing harm. These stories are frightening, but they shed light on a very important problem and a realization that, as a nation, we must do better to keep patients safe ... the entire committee believes the current state of safety of health IT must not be permitted to continue.

I've been writing words like that for over a decade.

-- SS

Addendum Nov. 8, 2011:

The IOM has issued this press release:

From: National Academies News <InternetMailforONPI@nas.edu>
Date: November 8, 2011 8:25:43 AM PST
To: National Academies News <InternetMailforONPI@nas.edu>
Subject: Health Information Technology and Patient Safety - For Immediate Release


Health Information Technology and Patient Safety – For Immediate Release
Health IT and Patient Safety: Building Safer Systems for Better Care, a new report from the Institute of Medicine, is available for IMMEDIATE RELEASE. The report examines a broad range of health information technologies and recommends actions that the government, health care providers, and technology vendors should take to improve patient safety. Contrary to some early news accounts, the report does not recommend that a new agency be established to regulate these technologies. Reporters can obtain a copy of the report by contacting the National Academies' Office of News and Public Information; tel. 202-334-2138 or e-mail news@nas.edu. In addition, members from the committee that wrote the report will discuss their recommendations and take questions at a one-hour public briefing starting at 10:30 a.m. EST Thursday, Nov. 10, in Room 100 of the National Academies’ Keck Center, 500 Fifth St. N.W., Washington, D.C. Those who cannot attend may participate through a live audio webcast accessible at http://www.nationalacademies.org.

I am not sure why they state "Contrary to some early news accounts, the report does not recommend that a new agency be established to regulate these technologies."

From the report prepub, page 6-28 to 6-29:

... To truly improve patient safety, a new approach is needed. The committee believed that the experiences of other industries such as transportation and nuclear energy in creating the NTSB and the NRC were instructive, and concluded that the development of an independent, federal entity was best suited to performing the needed above-described analytic and investigative functions for health IT–related adverse events in a transparent, nonpunitive manner. The committee envisions an entity that would be similar in structure to the NTSB or the NRC, which are both independent federal agencies created by and reporting directly to Congress.

Among other responsibilities, these entities conduct investigations, for the purpose of ensuring safety. NTSB is a nonregulatory agency that does not establish fault or liability in the legal sense but investigates incidents. The NRC is a regulatory body that has the ability to issue fines and fees. The committee considered both agencies and concluded the NTSB to be most similar to the needs of health IT–assisted care.
An independent, federal entity analogous in form and function to the NTSB is needed. This entity would not have enforcement power and would be nonpunitive. Instead, it would have the authority to conduct investigations and, upon their completion, make recommendations.

This recommendation followed:

... Recommendation 8: The Secretary of HHS should recommend that Congress establish an independent federal entity for investigating patient safety deaths, serious injuries, or potentially unsafe conditions associated with health IT. This entity should also monitor and analyze data and publicly report results of these activities.


Hopefully this issue will we clarified when the final report is generally available and the public briefing occurs.

I hope it's not an issue over the word "entity" vs. "agency", a difference that in practice would probably make no difference, economically speaking.

Addendum #2, Nov. 8, 2011:

After re-reading all of this, it seems the issue at question in the National Academies press release above is "regulation" vs. "investigating and monitoring."

That apparently being the case, let me state again that I have problems with the fact that the recommendations seem to preclude true regulation that should start ASAP, not at the whim of the Secretary of HHS when he/she decides that "adequate safety progress has not been made."

That represents, in my opinion, a special accommodation to the healthcare IT industry as previously mentioned.

In fact, Dr. Cook had a dissenting recommendation in Appendix E of the report that I agree with:

Recommendation 9: The Secretary of Health and Human Services should direct the FDA to exercise its authority to regulate health IT, including all EHRs and associated components, and health information exchanges, as Class III medical devices. [Under the 1976 Medical Device Amendments to the Federal Food, Drug, and Cosmetic Act - ed.]

-- SS

[Note] Regarding the IOM, my presenting in person the events that led to my relative's travails was rejected on the basis of 'protocol.' Despite the remarkable aspect of a physician/Medical Informatics specialist's relative (in fact, a specialist writing on health IT risks for over a decade) being gravely injured as a result of health IT-related disruption of care continuity, despite support for my personal attestation by internal members of the study group, my live testimony was rejected. Considering the issues were not just relevant to the IOM study, but at its heart, the rejection on procedural grounds brings to mind the simian adage "see no evil, hear no evil, speak no evil." The Institute of Medicine, on matters of life and death, acted more as an "Institute of Protocol" (or perhaps "Institute of Politics") in my opinion than an institute of science. I believe this lessens the credibility of their action agenda.


Friday, November 4, 2011

Lifespan (Rhode Island): Yet another health IT "glitch" affecting thousands - that, of course, caused no patient harm that they know of - yet

There's been yet another health IT "glitch" that, of course, caused no patients to be harmed. See other "glitches" here, here, here and at other posts which can be found by searching this blog on the banal term 'glitch'.

(I note that when a clinician makes a mistake, it's never called a "glitch", it's called "malpractice.")

When health IT causes errors that can injure or kill, it's commonly referred to as just a "glitch", the banal, now-standard euphemism for computing malpractice.

Presenting the latest healthcare IT "glitch", affecting thousands:


Computer glitch led patients to receive wrong meds
Senator calls for review of Lifespan

WPRI.com (Providence, RI)
Updated: Thursday, 03 Nov 2011, 5:47 AM EDT
Published : Wednesday, 02 Nov 2011, 11:56 PM EDT
Reported by Steve Nielsen

PROVIDENCE, R.I. (WPRI) - Rhode Island State Senator Jamie Doyle says he is shocked to hear a Lifespan computer glitch caused thousands of patients to receive the wrong types of medication. [Appx. 2,000 across five Lifespan hospitals according to the Providence Journal, see below, and the WaPo - ed.]

Doyle is now calling for an independent review of all the hospitals Lifespan runs, and a review of the Rhode Island Department of Health.

The DOH is investigating after learning patients who were supposed to receive medications taken once a day instead received medications meant to be taken more than once per day.

"Oops."


[11/5/2011 note: As an anonymous commenter pointed out, the 2,000 or so errors at Lifespan should probably be multiplied by the number of organizations using the same software ---> "The entire country may have suffered 25,000-50,000 errors from this one glitch alone", the commenter astutely notes - ed.]


Of course, the customary "we did feel lucky today, and the gun was empty" disclaimer follows:

"Lifespan has not reported any adverse events or situations where patients required additional medications, but the information gathering and investigation is still ongoing," said DOH spokeswoman Annemarie Beardsworth.

In other words, there could have been adverse events, we just at the Dept. of Health don't know yet with certainty, because none have been reported yet.

In addition, some patients who were meant to get a medication with a coating did not receive a coating. The coating can help with stomach pains of other problems.

"I just don't feel comfortable right now with some of the things that are coming out of there," Doyle said, "I really don't want to point fingers in any direction. but what we need to do is we need answers." Senator Doyle wants to have the review started in the next two to three weeks.

Mr. Doyle, see my academic site on HIT failures here and an account of repercussions here from an EHR-related medication error.

Lifespan released the following statement Wednesday:

"Lifespan is actively contacting 2,000 patients affected by this issue to ensure they receive the correct form of their medications. So far, we have reached out to more than 90 percent of the patients, many of whom were already taking the correct medication."

Lifespan expects to finish contacting patients by Thursday.

It will be interesting to understand the nature of this particular "glitch" and who the software vendor is.

All it takes is a single "glitch" to seriously reduce a patient's lifespan.

Siemens software may be involved. See this mutually self promoting, marketing-style Siemens document "Newport Hospital - a Lifespan Partner - At the Forefront of EMR Adoption" (PDF), also cached here. (As an aside, one wonders if the hospital and/or its leadership received special financial or other "incentives" in allowing their name to be used in corporate promotions.)

Also, Siemens was a company that apparently did not listen to an internal informatics specialist physician's concerns that their health IT for critical care was endangering patients (link). They terminated the whistleblower.

Also see my Aug. 2009 post "Why Siemens Healthcare Fails" which I had emailed at the time to the Siemens Healthcare CEO Hermann Requardt.

-- SS

Nov. 4, 2011 addendum:

Felice Fryer of the Providence Journal sent me a link to the story of Nov. 3, 2011 she wrote with a few more details, here. Excerpts:

Flaw found in hospitals’ prescriptions
Some patients discharged from Lifespan hospitals got right drugs in wrong form due to software error

By FELICE J. FREYER JOURNAL MEDICAL WRITER
Some 2,000 patients of the Lifespan hospital group were discharged with incorrect prescriptions over the past 9 to 15 months because of a software glitch.

[It took a year or more to discover these mounting errors? This is beyond the "red flag" warning signs I used to write about. This is crossing the chasm into the territory of "asking for catastrophe" - ed.]

The prescriptions listed the right medications, but in the wrong form: people who were supposed to get time-release pills received prescriptions for short-acting ones.

The error affected dozens of generic medications for a variety
of conditions. Lifespan discovered the problem on Oct. 25 and had fixed the software by Friday, according to Dr. Mary Reich Cooper, Lifespan’s senior vice president and chief quality officer.

The hospitals have placed calls to nearly all the affected patients, although not all have
called back, Cooper said. Most patients reached had already obtained the correct medication because the error was noticed by someone at the hospital, or a pharmacist or doctor outside, she said. So far, Cooper said, there is no evidence that any
one was harmed.

But Dr. Michael D. Fine, state Health Department director, said that the incident is an example of how electronic medical records, which normally help reduce errors, can sometimes amplify them by quickly affecting large numbers of people.
“It’s the flip side of what has otherwise been a process that has improved accuracy and reliability,” he said.

[I don't notice mention of a "flip side" to health IT in the aforementioned glossy hospital/IT company marketing brochure - ed.]

The Health Department is investigating the incident. Fine also plans to examine whether the department should regulate the safety of electronic systems in health care.
[Readers of this blog know my opinion on that matter - ed.]

Asked whether he was worried there may be other as-yet-unrecognized software glitches, Fine said, “I’m reasonably concerned about the accuracy and integrity of electronic medical records.”
... The software in question is not in use at other hospitals in Rhode Island, and the software vendor, Siemens, is notifying hospitals elsewhere in the country, according to Cooper.

[In the interests of public health, I believe it incumbent on Siemens to make this "glitch" widely known not just to the hospitals but to the public in areas served by those hospitals, especially with the admission that "
the (RI) hospitals have placed calls to nearly all the affected patients, although not all have called back." To not do so reflects negligence in my opinion - ed.]
... The errors arose from the process known as “medication reconciliation,” in which the physician compares the medications a patient was taking before hospitalization with those prescribed during hospitalization, and ensures that the patient goes home with a correct set of prescriptions. The Lifespan hospitals recently adopted an electronic system for this process.

Doctors were correctly prescribing medication, and the prescriptions looked right on the computer screen, Cooper explained. But when printing out the prescription list, the software was cutting off a two-letter abbreviation that indicated certain medications should be in long-acting form or coated to protect the stomach.

[As at Case 9 from FDA's MAUDE database at the post "
Our Policy Is To Always Have Unabashed Faith In The Computer". Do these vendors robustly validate their products? The current errors, in fact, were only peripherally related to medication reconciliation. They were primarily related to computer errors impairing (sabotaging?) the clinicians. It would seem med recon now needs to include comparing what the doctor enters to what is output to the nurses and other healthcare personnel who provide written instructions to patients. Is such a task performable by healthcare personnel when the computer cannot be trusted? Further, do the doctrine of the "learned intermediary" and "hold vendor harmless" clauses seem appropriate here? - ed.]
... Cooper said the risk of harm from taking a short-acting medication instead of a long-acting one was “very, very minimal.”

[Cooper misses the point, and IMHO such nihilistic attitudes have no place in healthcare - ed.]


But Fine, the health director, said such mistakes “can be scary.” People taking medication for angina or high blood pressure would find their medication wearing off over the course of the day,
putting them at risk of heart attack or stroke, he said.

Medical errors that might seem innocuous or minor to health IT amateurs can prove catastrophic.  I've seen it happen, leading to injury and death.


-- SS