Skip to main content

News

By Rebecca McBeth | 05:13 am | April 03, 2019
Telehealth is increasingly being used to connect clinicians within and between New Zealand’s hospitals and to reach into people’s homes, a new survey revealed. The Telehealth Leadership Group’s most recent stocktake questionnaire was sent to all 20 District Health Boards (DHBs) in October 2018. Telehealth Leadership Group programme lead Patricia Kerr says the group is still doing a detailed analysis of results, but initial findings show there has been a general increase in the use of telehealth within DHBs since the last survey in 2014, as well as between DHBs. Also, there are more telehealth services going directly from clinics into people’s homes and a wider range of technologies being used. “There’s not only an increase in the volume of use, but also in the number of clinical services using telehealth,” she said. The number of DHBs with telehealth programme managers has increased and more DHBs are also providing telehealth training to staff. The examples of excellence identified previously – Auckland, Northland, Waikato and Canterbury – have continued to grow and others have emerged. “There are more pockets of excellence, where individuals are taking up use of telehealth because they can see it delivers benefits for their service delivery,” Kerr said. Telehealth is increasingly being used for multidisciplinary meetings with streaming of pathology and radiology images, allowing clinicians who previously could not attend to participate and reducing travel times. New Zealand Telehealth Resource Centre telehealth advisor mobile health Andrew Panckhurst says improved interoperability between providers of video conferencing services has made it easier for people using a variety of different platforms to link up. New entrants to the video conferencing market are often open and interoperable by nature, and better connectivity has also boosted growth. Ministry of Health sector portfolio manager data and digital services Judy Eves says that “virtual meeting rooms”, a concept that was not widely used in the 2014 survey, now enables people to easily join video conferences from a laptop or mobile device. The increased use of telehealth supports the Ministry’s goal of more cost-effective care delivered closer to people’s homes. “There are huge cost and time benefits for both patients and clinicians,” she said. Telehealth also improves access to education and training. “We’re hoping to use the results of the survey to promote communications and share areas of excellence that are happening and further support the uptake of telehealth,” explained Eves. The Telehealth Leadership Group is a clinically led independent group, supported by the Ministry of Health. The group plans to survey GPs and Primary Health Organisations (PHOs) on their use of telehealth later this year. This article first appeared on eHealthNews.nz.
By Staff Writer | 01:00 am | April 03, 2019
Connected medical devices can improve patient care and operational efficiency. However, they also introduce new privacy and security risks. Healthcare providers should rethink their privacy and security practices in light of these new risks. According to the Office of the Australian Information Commissioner’s (OAIC) latest Notifiable Data Breaches (NDB) report, the health sector accounted for 21 per cent or 54 of the 150 breaches reported between 1 October 2018 and 1 December 2018. In addition, the global Internet of Things (IoT) healthcare market is expected to grow by 37.6 per cent between 2015 and 2020, opening up more devices to attack. That’s a frightening statistic considering that the healthcare industry already ranks second in data breaches. Healthcare organisations face two major security challenges:  They are prime targets for hackers Their attack surface expands every day as more and more medical devices are connected to networks.  When it comes to cybersecurity in the healthcare space, there is a need to recognise that information security and medical device cybersecurity are different, and need to be protected in different ways. This means taking a visibility-first approach when it comes to medical devices and ensuring that the cybersecurity in place to classify and protect these devices is specifically designed to support them. According to the Therapeutic Goods Administration (TGA), the Australian regulatory framework for medical devices already captures cybersecurity. Manufacturers have been considering security in their design, and the TGA has been assessing and regulating the security of medical devices through the Essential Principles. However, as the number of networked devices is growing, the risk profile is changing and public awareness of cybersecurity as a risk is increasing. This changing landscape has created new challenges for regulators of medical devices, including poor or unclear standardisation, sharing information, publication of vulnerabilities and exploits by users and security researchers, and poor transparency of expectations between stakeholders. Clinical devices such as glucometers, electrocardiograms and drug infusion systems are potential targets for hackers despite the efforts of manufacturers to secure their products. Considering the essential role these and other devices play in delivering critical care to patients, extra measures need to be taken to protect them. For example, in any patient care scenario, there is a mix of physical and virtual IT endpoints including IoT assets that often can’t accept agents for technical or regulatory reasons, building automation devices that are overlooked, and clinical devices that have legacy operating systems, or applications that don’t meet typical security standards. The main considerations for healthcare providers when it comes to security include: An increased number of medical devices on networks, often using outdated operating systems or uncommon firmware Mobile devices, which are harder to track and secure A wide variety of people connecting to and disconnecting from the network, meaning healthcare personnel, office staff, patients, guests and maintenance teams, all require different policies Ensuring the integrity and security compliance of a mix of IT, IoT, medical and environmental devices without disrupting operations Clinical engineering teams receiving mixed priorities about what they can do to their legacy equipment to maintain regulatory compliance without impacting patient care Protecting patient records from loss and cyber incidents to maintain the integrity and confidentiality of electronic information Third-party vendors and service providers accessing the healthcare network need oversight to prevent security missteps. Healthcare organisations need to be able to safely expand network access to clinicians, caregivers, research organisations and contractors while securely embracing agentless medical devices. This means finding a platform that lets them discover, classify, assess, and continuously monitor devices, including personally-owned and agentless medical devices; enforcing security posture and regulatory compliance policies; notifying users, restricting or blocking access, and automating network segmentation; as well as orchestrating and automating security among third-party security tools. With the volume of networked devices growing and the risk profile increasing, it has become clear that medical device security standards in Australia are lacking, while public awareness of security is growing. This means that healthcare providers need to take a proactive approach to medical device classification to mitigate the risk and prepare for potential future requirements.  Steve Hunter is the Senior Director for Asia Pacific and Japan at Forescout.
By Bill Siwicki | 03:42 pm | April 02, 2019
Case study: The EHR vendor's Happy Together technology enables the health system to incorporate data from patient portals from other healthcare organizations into its MyChart portal.
By Nathan Eddy | 11:23 am | April 02, 2019
Companies say aligning their platforms will help eliminate duplicate records, establish more accurate care histories and improve patient safety.
By Nathan Eddy | 10:16 am | April 02, 2019
Despite the opportunities and the fact that many problems have already been solved, pharma and life sciences are lagging other industry in cloud adoption.
By Leontina Postelnicu | 10:04 am | April 02, 2019
A YouGov poll from 2018 in the North East and North Cumbria region indicated that 94 percent of people surveyed would allow their medical records to be shared within the NHS.
By Staff Writer | 01:00 am | April 02, 2019
Graham Grieve counters the case for smart eHealth cards with the argument that smartphones would work better. Several experts that presented to the senate panel investigating the My health Record in 2019 argued that instead of a central data repository, Australia should instead, invest in a smart card based infrastructure to store consumers’ health care records. These experts proposed an approach where each individual carries their own smart card, and healthcare providers load information to and read information from the card during encounters with health care providers. The experts claimed that using smart cards avoids the central problem of the My Health Record system: a single consolidated record of all health information, with dual consequences: All patients are held to a single set of policy choices about how their information is shared and managed The single repository is a large, attractive target for hackers and any successful hacks may yield many records.  Most of the focus was on the second point – a single gathering of such a large amount of healthcare information is a natural target for hackers of various kinds. Note that although the central system is highly secure and run by a security-focused team with high-discipline, provisioned to be able to make a rapid response to emerging issues, the same cannot be said of the many access points authorised to access data from the system. A hacker gaining control of such an access point (or, a legitimate user misusing the endpoint, as in the Medicare number breach in 2017) would have access to all the records, though the more indiscriminately the access is used, the more quickly it would be detected. The experts claimed that these problems could be resolved by using smart cards instead. SMART CARD EVALUATION It’s certainly true that smart cards would not have the same security challenge – hacking a single smart card, or even the system by which smart cards are accessed/updated would only grant access to the subset of smart cards encountered by the hacked system(s) during the time of the hack, since there is no central database to hack and get global access to. However, smart cards do not make any difference to the rest the of problems a system faces; they simply move them around. The problems of security, integrity, access control and security still arise in any architecture. The challenges for a smart card based approach are: Who has the right to read information on the smart card? How can a patient control how much information is accessed? Who has the right to put information on the smart card? And how is existing information reconciled with new information? Can systems updating records overwrite existing patient information? How do you secure smart cards against non-authorised readers, and still allow for back up?  How do you incentivise consumers to keep track of their health smart cards so they don’t lose them? (and how do you incentivise them to backup their information?) If they lose information, is it stored somewhere else like a new central store? How much information can you fit securely on a smart card? (And how much does the system cost?) Overseas, health smart cards generally store very little information – usually, enough to automatically identify the consumer that carries the card and to connect to a patient record stored elsewhere. In other words, it’s a token that provides access to a central record store. This does not avoid the problems of a central repository. All of these have possible solutions, but because the smart card itself is passive, the solutions must be imposed through rules made about the software that interacts with the smart card. Which means, in effect, the smart card system would hold patients to a single set of policy choices about how their information is shared and managed; at  least to the degree that the government can impose a single set of rules. But the patient doesn’t have any say about this – only the providers of the software to healthcare do. The current arrangements around the My Health Record – with the running problems related to certificates that the agency is not in a position to solve, but is still being held accountable for in public – demonstrate that a single organisation, or the health software ecosystem, cannot solve all these problems. Finally, using smart cards raise a real problem inherited from the “Australia Card” debacle – people are suspicious of government supplied cards that have an identifier.  In fact, this is such a serious perceptual problem that this might be the most important question: Would Australians accept any kind of smart card from the government? (even if it doesn’t serve as an identifying card) A patient controlled record will only truly be patient controlled when the patient holds the information. Unfortunately, smart cards will not get us there. A REALLY 'SMART CARD' All of these questions already have an answer; it’s called the smartphone. Smartphones are the correct package for acting as ‘local store’ for a patient’s information: 89 per cent of consumers already carry a smartphone Consumers part with their smartphones reluctantly  Most consumers backup their smartphones often and generally keep a close watch on them Smartphone vendors invest billions of dollars in making both a secure and usable smartphone ecosystem Rather than building a static framework, the government can specify the API formats used to exchange data between smartphones and the rest of the system, and let innovation bloom in the consumer space. The same APIs can be reused for other purposes in healthcare Applications on smartphones can manage storage/access/reconciliation/ownership issues to the degree that the consumer wants without a central authority having to make all their decisions for them Smartphones typically have plenty of storage space (note: it’s not known how much consumers would allocate to health, but the smartphones can proactively manage this question) Other countries (most notably the US) are already building ecosystems based on APIs that serve smartphones, with active support from the providers of the ecosystems.  In fact, it would be cheaper to buy the remaining 10 per cent of the population a smartphone than invest in a smart card ecosystem. Though many of that Australian population is not in a position to hold and use smartphones – mostly elderly patients and children under the age of two – they can depend on other people to manage their healthcare information. This is yet another challenge to resolve for smart cards. For this reason, the Australian Government should pay careful attention to the foundations of a healthcare information ecosystem to ensure that all consumers, not just digital literati, can leverage any API based system. And it should ensure a robust framework is set up for assessing policy and technical conformance for the APIs (though this no magic bullet). Of course, some consumers won’t want to use smartphones to store their health records at all. Others might want to take advantage of a centrally provided secure repository. The strong benefit of a web/API based framework is that consumers can choose how to engage with the system. As such, future developments for the My Health Record system should move away from the current document repository approach towards a web/API based ecosystem. Grahame Grieve is the Principal of Health Intersections, and a healthcare Interoperability consultant and developer.
By Bill Siwicki | 03:42 pm | April 01, 2019
Blood is a precious commodity nationwide, and often wasted. At University of Missouri Health Care, the mean red blood cell transfusion rate is now 22.4 percent below the original baseline rate. The medical director of transfusion services explains how that was accomplished.
By Mike Miliard | 02:51 pm | April 01, 2019
A new KLAS and Arch Collaborative report finds that RNs generally like their electronic health records more than physicians, perhaps offering hints at improved usability.