Bernie Monegain
Kalorama Information says electronic health record systems are here to stay after recent situations in Flint, Michigan and Hollywood Presbyterian in which electronic medical records played key roles in times of crisis.
In Flint, Michigan, where residents are dealing with a lead poisoning water crisis, the lead was discovered as the result of searches conducted using data from an Epic EHR system.
[Also: Flint hospital hit with cyberattack tied to hacker group Anonymous]
Paper records would have failed the community, Kalorama claimed in its report, "EMR 2015: The Market for Electronic Medical Records."
In Flint, the key physician involved in the case reviewed the EHRs of the children whose blood had been tested at the local hospital. Paper records alone would not have lent themselves to the kind of research needed to detect patterns, Kalorama researchers said.
"The side benefit of EMR conversion, aside from cost savings, is that practice would improve and providers, academics and governments could obtain better epidemiological information," said Kalorama Information Publisher Bruce Carlson in a statement.
"The visibility of the Flint, Michigan, story provides a real-world example of the benefits oft-stated during the conversion and incentive campaign," he said.
[Also: Hollywood Presbyterian gives in to hackers, pays $17,000 ransom]
The Kalorama report also points to EHR's vulnerabilities – most notably the recent case of medical data being held hostage by hackers at Hollywood Presbyterian Medical Center in Los Angeles, which ultimately opted to pay $17,000 to rescue its information from cybercriminals.
Kalorama points to questions raised in that ransomware incident: whether the hospital properly encrypted information, whether staff was properly trained in anti-phishing techniques, whether EMR use audits were conducted, and if anyone was designated as chief security officer at the hospital.
"Such services and consulting offer opportunities for the industry, which has always been as much of a service industry as a software one," the Kalorama report said.
[Like Healthcare IT News on Facebook]
The incident comes a time when many physicians and hospitals have and are continuing to convert to electronic records, driven by federal government incentives, Carlson points out.
Three out of four U.S. hospitals have a basic EMR system and most EMRs are being used without incident," Carlson said. "Ransomware attacks are not limited by any means to EMR or healthcare facilities as corporations and even police departments have suffered attacks."
Twitter: @HealthITNews
The Healthcare Information and Management Systems Society and the Society for Imaging Informatics in Medicine are making progress tackling the issues associated with incomplete data in patients' digital health records.
Founded a year ago, the HIMSS-SIIM Enterprise Imaging Workgroup is focused on unmanaged – and sometimes missing – imaging data in patients' electronic health history.
“Despite widespread electronic health record implementations, many patients and doctors find the majority of their clinical data lies in poorly integrated diagnostic image, documentation image and clinical scanned document silos,” Christopher Roth, MD, vice chair of radiology and director of imaging informatics strategy at Duke Health, said in a statement.
[Also: 21 awesome photos from past HIMSS conferences]
This is where the workgroup comes in, HIMSS and SIMM members point out.
The group offers a platform for sharing enterprise imaging strategies, creating awareness that images are an essential part of the electronic health record, inclusive of, yet broader than the more pervasive radiology or cardiology domains.
“This joint effort between HIMSS and SIIM highlights the importance of this topic and provides timely resources that offer organizations insights on how to manage and share imaging data across the enterprise,” Joyce Sensmeier, HIMSS vice president, informatics, HIMSS North America, said in a statement.
In its first year, the workgroup has addressed critical topics resulting in the publication of several whitepapers.
Among them: Enterprise Imaging Governance: Needs, Models, and Intents to Consider; The Current State and Path Forward for Enterprise Image Viewing; A Foundation for Enterprise Imaging; Orders Versus Encounters Based Image Capture: Implications Pre- and Post-Procedure Workflow, Technical and Build Capabilities, Resulting, Analytics and Revenue Capture; Workflow Challenges of Enterprise Imaging; Technical Challenges of Enterprise Imaging, and Considerations for Exchanging and Sharing Medical Images for Improved Collaboration and Patient Care.
Twitter: @HealthITNews
This story is part of our ongoing coverage of the HIMSS16 conference. Follow our live blog for real-time updates, and visit Destination HIMSS16 for a full rundown of our reporting from the show. For a selection of some of the best social media posts of the show, visit our Trending at #HIMSS16 hub.
Los Angeles-based Complete P.T. Pool & Land Physical Therapy will pay $25,000 to settle HIPAA violations for allegedly posting patient testimonials, including full names and photos, on its website without obtaining authorization.
The Department of Health and Human Services Office for Civil Rights announced the settlement terms on its website on Feb. 16. The settlement also requires Complete P.T. to adopt and implement a corrective action plan, and annual reporting of compliance efforts for one year.
[Also: 8 out of 10 mobile health apps open to HIPAA violations]
The complaint filed with the OCR on Aug. 8, 2012 said Complete P.T. was required by HIPAA to seek authorization for the testimonials.
OCR’s investigation revealed that Complete P.T failed to reasonably safeguard protected health information, disclosed PHI without authorization,and failed to implement policies and procedures with respect to PHI that were designed to comply with HIPAA’s requirements.
"The HIPAA Privacy Rule gives individuals important controls over whether and how their protected health information is used and disclosed for marketing purposes," said OCR Director Jocelyn Samuels in a statement posted on the OCR website. "With limited exceptions, the Rule requires an individual’s written authorization before a use or disclosure of his or her protected health information can be made for marketing."
Twitter: @HealthITNews
The digital tool makes it easy for people to add a new device to their home – or clinic – Wi-Fi network.
Protenus, a health data protection startup co-founded when the owners were medical students at Johns Hopkins University, has raised $4 million in Series A funding.
Arthur Ventures led the investment, joined by LionBird Venture Capital, DreamIt Ventures, Cognosante, TEDCO and the Baltimore Angels.
[Also: Snooping employees sacked, disciplined after HIPAA breach]
Protenus founders Robert Lord and Nick Culberson said they started the company to address the privacy concerns raised by the use of EHRs, particularly from insider threats and employee snooping.
“Essentially, we’ve built an immune system for patient data that identifies when medical records are accessed inappropriately,“ Culbertson said in a press statement, announcing the funding. “Our product gives health systems the ability to deeply understand how and why medical records are accessed and whether or not there is a legitimate reason to look at a given patient’s medical or financial information.”
As Culbertson explains it, Baltimore-based Protenus’ holistic approach to anomaly detection prioritizes the most suspicious events, so healthcare systems focus on actual threats, rather than noise and false positives. The easy-to-use visualizations and automated reporting take what can be a tedious and long investigation to down to resolution in a just a few minutes.
Today, Protenus protects data throughout Johns Hopkins Health System. The company is in pilot stage with Inova Health System in Virginia and Maryland’s regional HIE, CRISP, which covers interchanges of data between nearly all health systems in the Maryland/DC area.
Sage Growth Partners, a Baltimore-based Health IT consulting firm and adviser to Protenus, was instrumental in establishing the CRISP pilot. Johns Hopkins has been a partner to Protenus since the company’s inception, with the university’s dedication to protecting patient privacy serving as an a catalyst to the development of the product, the founders said.
Twitter: @HealthITNews
A high percentage of IT workers admit to not following the same security protocols they are expected to enforce, according to a new survey conducted across the United States by Absolute, a Canadian security firm.
In fact, 33 percent admitted to successfully hacking their own or another organization and 45 percent admitted to knowingly circumventing their own organization's security policies.
"The big surprise for us in this survey is that the gatekeepers are really the gatecrashers," said Stephen Midgley, vice president of global marketing for Absolute. Moreover, he said, while the survey of IT department managers included several industries, the findings apply across the board, with healthcare no exception.
[Also: Hollywood Presbyterian gives in to hackers, pays ransom]
"Given that IT is the security gatekeeper for an organization, it was alarming to see such high incidents of non-compliant behavior by IT personnel," he said. "Even if these actions are being performed to validate existing infrastructure, senior leadership should be aware that this activity is occurring. It may also be worthwhile to consider third-party audits to ensure adherence with corporate security policies."
IT decision-makers bear the brunt of responsibility. Of those surveyed, 78 percent said the organization's security is primarily IT's responsibility. The report also showed that 65 percent of IT decision makers believe they would likely lose their job in the event of a security breach.
"The gaps in current data breach response plans and in upholding general best practice policies must be addressed," Midgley said.
As he sees it, when it comes to security – especially in healthcare, but also in other sectors – there's an accountability divide.
"That is a very precarious space for IT to be in," Midgley said. "They are tasked with data security, but aren't actually responsible for the device that contains that data.”
"I think in healthcare it's magnified," he added, "because of HIPAA, HITECH, PHI. So, you can have all the security in place, but at the end of the day, IT is reliant on the employee to ensure security is implemented correctly. Yet, what we find is those very same employees try to find ways to circumvent the security policies that have been put in place."
There's a lot of work for IT in terms of bridging that gap, he said, and recommended that organizations implement technology that is adapted to their environment that gives them complete visibility and control of the devices.
Midgley mentioned the example of one healthcare entity that has a policy of automatically wiping data from any device – laptop, tablet or phone – that goes beyond a certain location.
[Like Healthcare IT News on Facebook]
"They assume that device has PHI on it," he said. "It's mitigating the risk of a data breach."
The survey – which polled 501 U.S. adults who work in information security management roles in companies or organizations with 50 or more employees – found that security remains at the top of the IT spending list, with 87 percent of respondents expecting increased investment in security this year.
Twitter: @HealthITNews
IBM executives say the purchase adds not only a massive repository of health data to the Watson Health Cloud, but also an extensive client roster to IBM's Watson Health unit.
Lantern, a San Francisco-based startup, with 17 employees, is working with UPMC Enterprises, the commercialization arm of the Pittsburgh-based healthcare giant, to further develop the company’s online mental health wellness services and products.
The startup, founded in 2012, recently closed on a $17 million investment led by UPMC Enterprises on February 10. All other previous investors, including Mayfield Fund, SoftTech Venture Capital and Stanford University, joined the round.
[Also: 3 recent health IT IPOs to watch]
UPMC, one of the largest integrated healthcare delivery systems in the country, is the ideal partner, Alejandro Foung, Lantern co-founder and CEO, said in a statement announcing the new funding.
"A large part of UPMC's appeal, Foung added, is its "focus on disease prevention – a sharp contrast to the fee-for-service model that currently dominates the behavioral health landscape."
"This is for us about a very long-term bid on how we can use technology to engage consumers and patients in their mental health, said Mark Stabingas, executive vice president at UPMC Enterprises.
"There’s an acute shortage of mental health professionals," he said. "There are lots of people who could benefit from mental health services."
UPMC clinicians will work with Lantern on two pilots aimed at expanding Lantern’s programs to address additional behavioral health issues and potentially to address populations of patients with more complex conditions, Stabingas said.
As taken as the UPMC team is with the products, the Lantern team has built to date, Stabingas said, "We are compelled first and foremost by the team. We are as much focused on the idea that we can partner with the team to build something really compelling for the long haul that has the opportunity to help millions and millions of patients."
[Also: Steward ACO picks Patrick Kennedy-backed Quartet]
Among the companies, UPMC has backed is Evolent, a public company that offers a mix of consulting and technology. Its cloud-based IT, which includes population health and analytics tools, is built to help hospitals and health systems migrate from a fee-for-service system to value-based care.
Another behavioral health IT company recently in the news is Quartet, which is backed by Rhode Island Congressman Patrick Kennedy who serves on the board of the New York-based startup.
Twitter: @HealthITNews
Centering Healthcare Institute, Community Care of North Carolina and the Jersey City Medical Center – Barnabas Healthcare will present on their models at a March event.
The hospital was also the first pediatric facility to achieve Stage 7 for its EHR use, the pinnacle on HIMSS Analytics Scale.