Bernie Monegain
The American Health Information Management Association launched an effort to collect 100,000 signatures on a petition to ask the White House to address the need for a unique patient ID.
While other groups, such as HIMSS and CHIME, have both supported a national patient ID – CHIME notably with a million dollar contest – AHIMA is taking a new approach.
“As a patient, you know there’s only one you. But sometimes a name or some personal information is so similar to someone else’s that doctors’ offices or hospitals can have a hard time identifying records correctly,” AHIMA CEO Lynne Thomas Gordon said in a statement. “It’s a dangerous and costly problem that can lead to missed diagnoses, inappropriate treatments or unnecessary tests, as well as making it difficult for providers to exchange health information.”
[Also: Epic CEO Judy Faulkner on the need for a national patient ID]
Thomas Gordon suggested that the government could turn to experts in other sectors, such as banking and finance, as well as security experts, for help in making healthcare safer and more effective.
“The voluntary patient safety identifier – created and controlled by patients – will be a complete and positive game-changer in healthcare in terms of patient safety, quality of care and financial consequences,” Thomas Gordon added.
The petition asks for the removal of the federal legislative ban that has prohibited the U.S. Department of Health and Human Services (HHS) from participating in efforts to find a patient identification solution.
The challenge of accurate patient identification is illustrated by a study conducted by the Harris County Hospital District in Houston, which found that, among 3.5 million patients, there were nearly 70,000 instances where two or more patients shared the same last name, first name and date of birth. Among these were 2,488 different patients named Maria Garcia and 231 of those shared the same birth date.
AHIMA’s petition is available on petitions.whitehouse.gov. Officials said they have to collect the 100,000 signatures by April 19 to ensure a response from the Obama administration.
Twitter: @HealthITNews
EHR giant Cerner on Friday completed the initial stage in a $4.5 billion expansion that company officials and the state’s governor are promising will add thousands of jobs.
Missouri Gov. Jay Nixon said at the ceremony that the area is already seeing benefits of this project, pointing to nearly 4,000 jobs created.
“Once complete, this campus will accommodate Cerner's growth and bring up to 16,000 new jobs to the area strengthening Missouri's position as a top destination for growing tech companies,” Nixon said.
Kansas City has been rebranding itself as a technology innovation hub some people have been calling it Silicon Prairie for the last several years, looking to attract entrepreneurs and employees alike. The region, in fact, was the first to implement the Google Fiber gigabit Internet service. In addition to Cerner, other technology companies in Kansas City include Sprint, DST Systems, and Garmin.
Cerner’s construction ceremony on Friday “marks significant progress for the project and completion of the structural framework for the first two office buildings on our new campus," Cerner COO Mike Nill said.
Nill announced the first buildings would house more than 3,000 engineers and was designed with open concepts and collaborative meeting spaces to encourage creativity and community.
When Cerner first broke ground on the new campus, in late 2014, the company said it intended to add 16,000 jobs in the next decade.
Twitter: @HealthITNews
Pieces Technologies announced $21.6 million in its first round of funding to advance its cloud-based population health management tools.
The Pieces platform provides integrated monitoring, prediction, workflow optimization and organizational learning services specifically for hospitals, health systems. Its cloud-based software is also designed to connect to hospitals’ information systems to provide a holistic view of patients and their healthcare needs.
[Also: Hospitals driving population health with data analytics, mobile apps, telehealth tools]
The goal is to identify and prevent adverse events, such as avoidable mortality and hospital readmission for chronic diseases and illnesses, according to Pieces CEO and founder Ruben Amarasingham, MD.
“Pieces Tech’s solutions are helping us redesign and transform our healthcare delivery models for better population health management,” Fred Cerise, MD, Parkland Health and Hospital System’s president and CEO, said in a prepared statement.
Parkland’s non-profit research and development arm, Parkland Center for Clinical Innovation, served as an incubator for the platform.
[Also: Healthcare IT startups to watch in 2016; Running list of big news]
“While many purport to have solutions for population health, over the last several years the team has stealthily built and validated a robust healthcare IT and clinical services platform that has clinically proven to truly bend the cost curve on quality and care across diverse constituencies,” added Garrett Vygantas, MD, Partner at Jump Capital.
Jump Capital and Pacific Advantage Capital led the funding, along with participation from Children’s Health in Dallas, Order of Saint Francis Healthcare System in Peoria, Ill, PCCI, select Dallas investors and others.
Twitter: @HealthITNews
OCR settles two HIPAA breach suits totaling $5.5 million with North Memorial Health Care, Feinstein…
The Office for Civil Rights used the instances to highlight the importance of holding business associates and research centers accountable to privacy and security laws.
The laptop that was reported missing from Premier Healthcare on Jan. 4, has been returned via U.S. mail. According to a statement from the Bloomington, Indiana physician-led multispecialty healthcare provider, the laptop was returned on March 7.
Premiere had reported the laptop stolen from the billing department in its locked and alarmed administrative office.
[Also: Premier Healthcare faces possible data breach]
Premier hired an information security consulting firm that specializes in digital forensics and incident response to conduct a comprehensive forensic analysis, which revealed the laptop had not been powered since it went missing, Premier officials said in a statement.
Premier had feared a possible breach that could have affected nearly 206,000 patients. For 1,769 of those patients, social security numbers and financial information could also have been accessed.
Premier continues to investigate the case. It has reported return of the laptop to the Bloomington Police Department for use in their continuing investigation.
Twitter: @HealthITNews
Though more hospitals are reporting infection rates publicly, a new report from The Leapfrog Group shows that more than half of hospitals across the country still grapple with sometimes deadly healthcare-associated infections.
"A record number of hospitals make their infection rates public, which shows commendable transparency and candor within the hospital industry,” Leapfrog President and CEO Leah Binder said in a statement. "The bad news is there are still too many infections."
[Also: View all Leapfrog's 'F' hospitals]
According to the Leapfrog report, the central line infection rate was too high at 75 percent of hospitals. Only 25 percent of hospitals met Leapfrog's standardized infection ratio of zero for CLABSI, or central line-associated bloodstream infection. Sixty-seven percent of hospitals had a infection rate between zero and 1.0, while 8 percent had a ratio above 1.0.
Also, only 25 percent of hospitals met Leapfrog's urinary tract infection standard. CAUTI, or catheter-associated urinary tract infections are considered the most common type of healthcare-acquired infections, and Leapfrog's standard for this infection is close to zero.
Infection rates also varied by state, choice of hospital and metropolitan area. On average, New Hampshire had the safest hospitals, with 67 percent reporting a CLABSI rate of zero. Rhode Island and Maryland are most in need of improvement, with no hospitals reporting a CLABSI rate of zero. What's more, hospital infection rates vary significantly within communities. For example, one West Coast city had CLABSI rates range from zero to more than five times the expected rate.
Infection rates are declining, but more transparency and quality improvement are needed, the report stresses.
[Like Healthcare IT News on Facebook]
Public reporting through Leapfrog has helped reduce CLABSI rates, Binder said. For example, the percentage of hospitals reporting a CLABSI rate of zero has steadily increased from 18.8 percent in 2013 to 25 percent in 2015. Yet, three quarters of hospitals still do not meet Leapfrog's standards.
The report on healthcare-acquired infections is the first in a series of five reports Leapfrog has planned to examine key quality and safety measures at hospitals nationwide. The reports are based on data from the 2015 Leapfrog Hospital Survey of more than 1,500 U.S. hospitals and analysis provided by Castlight Health.
Twitter: @HealthITNews
The U.S. Department of Health and Human Services on Wednesday named a slate of healthcare professionals from top providers and tech firms to its Health Care Industry Cybersecurity Task Force.
The Cybersecurity Information Sharing Act of 2015 tasked HHS with the creation of the panel, which is expected to come up with recommendations for helping safeguard the industry.
HHS, the Department of Homeland Security and the National Institute of Standards and Technology selected the task force members based on recommendations from a panel of subject matter experts.
[Also: HHS seeks industry pros to join healthcare cybersecurity task force]
"While all industries continue to face a growing threat of attacks on their information systems, the size and scope of attacks on healthcare information systems have accelerated particularly rapidly in the past two years," HHS officials said in a statement.
The group will schedule four in-person meetings and through teleconferences until March 2017, when the task force will disband. It is expected to report its findings and recommendations before then.
The members are:
Theresa Meadows, RN, senior vice president and CIO, Cook Children's Health Care System.
George DeCesare, a lawyer, and senior vice president and chief technology risk officer, Kaiser Permanente Health Plan
Roy Mellinger, vice president of IT security, and chief information security officer Anthem
Mark Jarrett, MD, senior vice president and chief quality officer, Northwell Health, and professor of medicine Hofstra Northwell School of Medicine
Jacki Monson, a lawyer and chief privacy and information security officer, Sutter Health
Ram Ramadoss, vice president, CRP privacy and information security and EHR compliance oversight, Catholic Health Initiatives
Fred Trotter, data journalist, CareSet Systems
David Ting, co-founder and chief technology officer, Imprivata
Christine Sublett, CISO and head of compliance, Augmedix
David Finn, health information technology officer, Symantec
Michael McNeil, global product security and services officer, Philips Healthcare
Terry Rice, vice president, IT risk management and CISO, Merck & Co.
Joshua Corman, co-founder, I Am The Cavalry
Alissa Johnson, CISO, Stryker Corp.
Vito Sardanopoli, director of cyber security services and governance, Quest Diagnostics
Dan McWhorter, vice president and chief intelligence strategist, FireEye
Anura Fernando, principal engineer, medical and software systems interoperability at UL, LLC
Emery Csulak, CISO, Centers for Medicare and Medicaid Services
Laura Laybourn, director of stakeholder engagement and cyber infrastructure resilience, Office of Cybersecurity and Communications, U.S. Department of Homeland Security
The task force will also include a representative from NIST and one from the Federal Health IT Advisory Council, but they have not yet been named.
Twitter: @HealthITNews
More than 30 healthcare provider organizations have banded together to urge the Centers for Medicare and Medicaid Services to adopt a 90-day reporting period for meaningful use measures in 2016, rather than full-year reporting as CMS has proposed.
Providers proved successful when they rallied for 90-day reporting for 2015.
[Also: Meaningful use will still be part of MIPS reimbursement]
In a March 15 letter to CMS Acting Administrator Andy Slavitt, the groups said the changes CMS made in the Modified Stage 2 final rule for 2015 provided welcomed relief to the provider community.
As they see it, full-year reporting in 2016 would demand complex system changes: "For many providers, these system changes will impact their ability to comply with the full-year reporting period," they wrote.
CHIME, which represents more than 1,800 healthcare chief information officers, is leading the call for 90-day reporting.
[Also: Healthcare industry cheers meaningful use modifications]
"Healthcare providers are firmly committed to using information technology to transform the delivery system," CHIME Board Chair Marc Probst, CIO at Intermountain Healthcare, and CHIME President and CEO Russell Branzell, said in a joint statement. "Changes made to the meaningful use program last year provided welcomed relief from burdensome regulatory requirements.”
"Providers now are awaiting further changes to the program spurred by the Medicare Access and CHIP Reauthorization Act of 2015. However, the current regulatory scheme still calls for a 365-day reporting period. Until the final MACRA rules are issued, providers will be greatly challenged to meet the reporting requirements,” they said.
[Like Healthcare IT News on Facebook]
"Maintaining 365-day reporting period also will force providers to pull resources away from using health IT to innovate care processes and workflows. Additionally, it will limit the amount of time providers and vendors could spend on improving interoperability and information exchange."
Organizations supporting the change are:
American Academy of Dermatology Association
American Academy of Family Physicians
American Academy of Neurology
American Academy of Ophthalmology
American Association of Clinical Endocrinologists
American Association of Neurological Surgeons
American Association of Orthopaedic Surgeons
American College of Cardiology
American College of Mohs Surgery
American College of Physicians
American College of Rheumatology
American College of Surgeons
American Gastroenterological Association
American Society for Dermatologic Surgery
American Society for Gastrointestinal Endoscopy
American Society of Nuclear Cardiology
American Society of Plastic Surgeons
American Urological Association
America’s Essential Hospitals
Association of Medical Directors of Information Systems
Cardiology Advocacy Alliance
Coalition of State Rheumatology Organizations
College of Healthcare Information Management Executives
Congress of Neurological Surgeons
Federation of American Hospitals
Heart Rhythm Society
Infectious Diseases Society of America
Medical Group Management Association
National Association of Spine Specialists
National Rural Health Association
Oncology Nursing Society
Premier healthcare alliance
Society for Cardiovascular Angiography and Interventions
United Surgical Partners International
Twitter: @Bernie_HITN
A recent report from the Department of Health and Human Services Office of the Inspector General claims that HHS could do better when it comes to protecting federal information.
The gaps range from monitoring to security training and contingency planning.
"Exploitation of these weaknesses could result in unauthorized access to, and disclosure of, sensitive information and disruption of critical operations for HHS," according to Ernst & Young, which conducted the independent audit for the OIG. "As a result, we believe the weaknesses could potentially compromise the confidentiality, integrity, and availability of HHS' sensitive information and information systems."
[Also: OIG identifies big HHS security shortfalls.]
Assistant Inspector General for Audit Services Thomas M. Salmon detailed the findings in a March 2016 report by identifying the 10 areas the auditors found lacking. HHS responded to each finding, concurring with some, taking issue with others:
Continuous Monitoring Management. HHS has formalized its Information Security Continuous Monitoring program through development of ISCM policies, procedures, and strategies. However, HHS has not implemented a Department-wide fully-implemented continuous monitoring program which includes continuously monitoring, updating and finalizing policies and procedures indicating how OPDIVs (operational divisions) address, implement strategies and report on DHS metrics. This includes vulnerability management, software assurance, information management, patch management, license management, event management, malware detection, asset management, and network management.
Configuration Management. Some OPDIVs did not consistently review and remediate or address the risk presented by vulnerabilities discovered in configuration baseline compliance and vulnerability scans performed through Security Content Automation Protocol tools.
Identity and Access Management. Some OPDIVs did not consistently implement account management procedures for shared accounts, new personnel, transferred personnel and terminated personnel.
Incident Response and Reporting. Oversight processes had not been implemented by HHS to enforce incident response and reporting procedures at the OPDIVs.
Risk Management. HHS did not implement procedures to oversee that system inventories are complete, accurate and effectively managed, including reconciling to the OPDIV-managed system inventory tools.
Security Training. Some OPDIVs did not monitor the completion of role-based training for significant security responsibilities and other security training for personnel using IT systems.
Plan of Action and Milestones. Plan of Action & Milestones were not consistently documented and tracked by the OPDIVs and HHS.
[Like Healthcare IT News on Facebook]
Remote Access Management. Some OPDIVs had not developed formal and finalized remote access policies and procedures.
Contingency Planning. Some OPDIVs did not complete required contingency planning documentation, including Business Impact Analysis, Continuity of Operation Plans, and Information System Contingency Plans.
Contractor Systems. Some OPDIVs did not have an effective contractor oversight protocols.
Twitter: @HealthITNews
The technology pioneer offered his thoughts on funding new projects and keeping up with change at his HIMSS16 keynote earlier this month. Here are seven takeaways.