Mike Miliard
Former Walnut Hill Medical Center CIO will also serve as VP of government relations for the security vendor.
Centers for Medicare and Medicaid Services chief Andy Slavitt asks hospital executives for 'meaningful engagement' with the proposed new MACRA policy, and hints they should follow Washington rule-making closely in the near future.
With the healthcare industry suddenly accounting for nearly 25 percent of all data breaches, a new study from The Brookings Institution suggests some new cybersecurity strategies are needed.
Niam Yaraghi, a Brookings fellow, conducted in-depth interviews with 22 healthcare organizations – providers, payers and business associates – that had each experienced at least one data breach.
He found some things in common across them, and some differences. But his biggest takeaway was that guidance and enforcement from the federal government isn't doing enough to keep patient data safe, and that a more concerted private-sector strategy is needed to help ensure security best practices.
In his report, "Hackers, phishers, and disappearing thumb drives: Lessons learned from major healthcare data breaches," Yaraghi offered a series of suggestions for both the HHS Office of Civil Rights and those working in the healthcare trenches.
"Consider a simple office visit," he said. "In addition to the physician who sees the patient, it may involve an independent entity that facilitates the scheduling of the visit, an electronic medical records vendor that provides software and cloud storage for saving the doctor’s notes, a health information exchange platform that shares this data with other physicians, another party that creates the bill, the insurance company that pays for it, and sometimes a collecting agency that manages the patient’s late payments."
That scale and complexity has left healthcare "uniquely vulnerable to privacy breaches."
A host of other factors, from the value of detailed patient medical records – containing both medical and financial data – to hospitals' historic ill-preparedness, has led to healthcare earning the dubious distinction of being hackers' new favorite target.
[Also: Status report: OCR's effort to guide HIPAA compliance in mobile health]
"Government incentives led healthcare organizations to adopt electronic health records without being ready to adequately invest in security technologies," said Yaraghi. "Privacy breaches used to have little to no effect on the revenue stream of healthcare organizations, and thus, they did not have strong economic incentives to invest in digital security and patient privacy."
That's all changed now, of course: 23 percent of all data breaches happen in the healthcare industry, according to Brookings. Over the past six years, health records of more than 155 million Americans have potentially been exposed in whopping 1,500 separate breaches – the per-record cost of which is $363, the highest of all industries.
The government isn't always helpful when it comes to addressing this all too vexing problem, the Brookings report argues.
While HIPAA "is clear about the requirement to protect health data," for instance, "it does not specify how to do so and is open to interpretation," Yaraghi said. "HIPAA is also outdated and falls short of addressing modern cybersecurity challenges."
After a breach happens, meanwhile, OCR initiates audits. "While one does not expect the organizations that were audited to have a positive view about OCR, most of them mentioned that the process is very punitive and contributes to organizations’ reluctance to share the details of breaches with peers," he added. "Furthermore, audits usually take more than two years and organizations incur significant legal fees during the process."
As a potential way forward, Yaraghi offered some pointed suggestions to both the healthcare industry and the government.
First and most obvious, health organizations must prioritize patient privacy.
"In many of the interviewed organizations, privacy breaches could have been prevented had the organization spent enough on security technologies or diligently implemented and followed privacy policies," he said. "Healthcare organizations now have access to both the knowledge and technology that is required to ensure the privacy of their patients, and thus should use these resources to their fullest potential."
He emphasized the acute need for better communication: "Information sharing about security technologies, privacy policies, and breach incidents should take place among healthcare organizations and also between healthcare organizations and federal agencies," Yaraghi said.
And he touted the value of cyber insurance – not just as a protective mechanism for individual organizations, but as lever to help drive improvements in security practices industry-wide.
Such an insurance market could "fundamentally improve how patient privacy is viewed and managed in the healthcare sector," he said. "To underwrite the privacy risk of healthcare organizations, cyber insurance companies will be willing and able to conduct timely and efficient audits and proactively manage their clients’ privacy protection efforts. Healthcare organizations will also have a direct economic incentive to reduce their cyber insurance premiums by addressing their security weaknesses and preventing privacy breaches."
Sign up for the Healthcare IT News Privacy & Security Update newsletter.
Meanwhile, Yaraghi had two key recommendations to the Office for Civil Rights.
First, it should better communicate the details of breach incident audits, he said.
"After a breach happens, OCR conducts a thorough investigation to identify its causes. Through these audits, OCR also ensures that the victim organization has put corrective and preventive policies in place to avoid future incidents. Although the lessons learned from each breach can prevent other similar incidents, OCR does not share the details of its investigations. OCR should provide detailed reports on how each breach happened, and how other healthcare organizations can avoid similar occurrences."
Also, the government should get more specific about HIPAA – ideally establishing a "universal HIPAA certification system," said Yaraghi.
"OCR should prevent more than it punishes," he said. "Although the audits that happen after a breach effectively reduce the chances of second incidents, they cannot prevent privacy breaches in the first place. Random audits that take place before a breach occurs will be helpful in preventing one. These random audits are currently conducted very rarely. OCR should accredit certification agencies that can conduct preventive audits in accordance with OCR standards and certify the compliant organizations."
Twitter: @MikeMiliardHITN
Email the writer: mike.miliard@himssmedia.com
Like Healthcare IT News on Facebook and LinkedIn
The National Association for Trusted Exchange and CommonWell Health Alliance are teaming up to keep momentum on interoperability, with each becoming a member of the other's organization. Members of the two groups will begin working together immediately.
UMMC CHIO John Showalter, MD, describes what associative data lakes, honest brokers and more mean to becoming a learning health system.
The technology, seen as a potential move toward bionics, could one day enable wireless updates for corrective lens prescriptions, if it comes to fruition.
Microsoft purchased 10 million long oligonucleotides – DNA or RNA molecules used for genetic testing and research – from San Francisco startup Twist Bioscience, and is using them to encode digital data.
A group of Republican senators who have been looking to "reboot" meaningful us since 2013 released new draft legislation this week they say aims to make the incentive program work better for providers and taxpayers.
U.S. Senators John Thune, R-South Dakota, Lamar Alexander, R-Tennessee, Mike Enzi, R-Wyoming, Pat Roberts, R-Kansas, Richard Burr, R-North Carolina and Bill Cassidy, R-Louisiana – all of whom voted against the 2009 ARRA law that helped establish meaningful use through the HITECH Act – wrote this week to HHS Secretary Sylvia Burwell and CMS Acting Administrator Andy Slavitt, looking for feedback on the bill.
[Also: Republican senators want to ‘reboot’ MU]
The draft legislation would shorten the reporting period for eligible physicians and hospitals from 365 days to 90 days, which would give providers more time to implement EHR systems, relax the all-or-nothing nature of the current program requirement, and extend the ability for eligible providers and hospitals to apply for a hardship exemption from the meaningful use requirements.
"These policies seek to provide CMS with the tools and guidance necessary to advance the use of EHRs as part of utilizing health IT to the benefit of patients in a manner that protects the significant taxpayer investment in our nation’s health care system," the legislators write.
Thune, Alexander, Enzi, Roberts, and Burr are original members of the Senate’s health IT working group, known as Re-examining the Strategies Needed to Successfully Adopt Health IT, or REBOOT.
Back in 2013, they published a white paper outlining their complaints about lack of momentum toward interoperability, patient privacy concerns, EHRs' potential to enable fraud and abuse and other concerns about federal health IT policy.
[Also: EHRA critiques GOP's MU 'reboot' plan]
"We received critical feedback in response to our 2013 report which has informed our work on these issues," the senators wrote to Burwell and Slavitt this week. "We also engaged with stakeholders including health IT developers, providers, and patient-focused organizations to assess their experiences with the meaningful use program, as well as their concerns with the state of health IT, specifically EHRs, over the years.
"In response to this feedback we have identified a few key policy changes outlined in the enclosed draft legislation, and we respectfully request feedback as part of our continued constructive dialogue on these issues."
Population health IT developer Caradigm named its new CEO on Thursday, promoting its chief technology officer Neal Singh to the executive role.
On Twitter, former National Coordinator for Health IT Farzad Mostashari, MD, called it the "most substantive change to how healthcare is paid for in a couple of decades."
The propsed MACRA rule put forth by the U.S. Department of Health and Human Services on Wednesday also holds some pretty big changes for how health IT can be put to work by physicians to drive quality improvement and cost efficiencies.
[Also: MACRA proposed rule published by HHS, streamlining federal programs including meaningful use]
"By proposing a flexible, rather than a one-size-fits-all program, we are attempting to reflect how doctors and other clinicians deliver care and give them the opportunity to participate in a way that is best for them, their practice and their patients," said Patrick Conway, MD, chief medical officer at the Centers for Medicare & Medicaid Services, in announcing the rule. "Reducing burden and improving how we measure performance supports clinicians in doing what they do best – caring for their patients."
So far, most industry reaction to the notice for proposed rulemaking is positive – recognizing the fact CMS seems to have taken the feedback from more than 6,000 frontline healthcare stakeholders to heart, crafting a rule that's attuned to the needs of physicians.
In a statement, HIMSS applauded the "significantly streamlined reporting and the acknowledgement process for MIPS-eligible clinicians" in the new rule.
"We are encouraged by CMS's effort to coordinate reporting periods across federal programs and the decision to align with the ONC Interoperability and Certification Programs," HIMSS officials said. "With the first MIPS performance full-year reporting period expected to begin on January 1, 2017, we're further analyzing the MACRA rule to ensure that Medicare providers will be able to meet the proposed requirements."
American Medical Association President Steven Stack, MD, meanwhile, said it's "hard to overstate the significance of these proposed regulations for patients and physicians."
In particular, he was pleased that CMS has been listening to physicians’ concerns and "has made significant improvements, by recasting the EHR meaningful use program and by reducing quality reporting burdens."
American Health Information Management Association CEO Lynne Thomas Gordon released a statement saying AHIMA supports the MIPS progam's "emphasis on interoperability, information exchange and security measures, which we believe are critical to reaching the rule’s stated long-term goal of ‘better care, smarter spending, and healthier people.'"
The Premier healthcare alliance was less pleased, however – specifically taking issue with one part of the two-pronged MACRA approach to value-based care: its provisions related to advanced payment models, or APMs.
CMS "made a significant mistake in not including any bundled payment or Track 1 Medicare Shared Savings Program ACOs as qualifying advanced payment models under MACRA," said Blair Childs, senior vice president of public affairs at Premier Inc.
"Rather than rejecting bundled payment programs, we believe CMS should focus on ways to alter the bundled payment programs to demonstrate use of certified EHR technology and align measures with other Advanced APMs.
"We also believe CMS seriously erred in excluding Track 1 MSSP ACOs in the APMs for failing to meet the more than 'nominal risk' financial requirement," said Childs.
"As we've learned through members in our Population Health Management Collaborative, these programs require providers to not only forego revenue through a lower volume of services, but also investment millions of dollars in redesigning care through new technologies, data analytics, additional staff, etc.," he said. "We think most businessmen would call that more than nominal risk, yet CMS choses to define it as only cases where there is risk to the government."
Elsewhere in the Twitterverse, the response was mostly positive – with some skepticism and a bit of I-told-you-so mixed in.
And "Meaningful Use" is going "away" by changing its name to "Advancing Care Information" #MACRA #livetweeting as I read the proposed rule
— Joy Rios (@askjoyrios) April 28, 2016
or basically what #MU should have been from day 1 @Travis_Broome
— Harold Smith III (@haroldsmith3rd) April 28, 2016
1/Bottom Line #MACRA NPRM
Game changer. Lots of great changes, 100's of thoughtful details and decisions.
Biggest blind spot can be fixed
— Farzad Mostashari (@Farzad_MD) April 27, 2016
Really good YouTube "whiteboard" connecting the dots of our MACRA announcement. Plain English. No acronyms. Wow. https://t.co/qLHSpYnWRX
— Andy Slavitt (@ASlavitt) April 27, 2016
A tree died for this #MACRA #MIPS #Medicare pic.twitter.com/YsiSd3R9Mf
— Amanda Narod (@AmandaBinDC) April 28, 2016