Skip to main content

News

By Tom Sullivan | 12:07 pm | April 01, 2019
The EHR vendor continues its tradition of April 1 gags.
By Tom Sullivan | 10:03 am | April 01, 2019
New HIMSS Media research finds that nearly 75 percent of hospitals are beyond the basic level of interoperability, that best practices for information sharing are emerging and half are gearing up for APIs and FHIR.
By Piers Ford | 06:20 am | April 01, 2019
With some French hospitals now pondering a move to their next generation of PACS, vendors are stepping up their market ambitions.
By Dean Koh | 05:38 am | April 01, 2019
The Voluntary Health Insurance Scheme (VHIS) officially launched on April 1, 2019, in Hong Kong. Consumers may now choose to purchase Certified Plans as offered by the participating insurance companies.  The scheme is a policy initiative implemented by the Food and Health Bureau to regulate indemnity hospital insurance plans offered to individuals, with voluntary participation by insurance companies and consumers. To alleviate the strain on the public healthcare system, especially during peak periods such as winter surge, Certified Plans under the VHIS have a number of standard features for increasing consumers' confidence in purchasing hospital insurance, thereby facilitating their use of private healthcare services when necessary. At the launch ceremony of the VHIS last week, the Secretary for Food and Health, Professor Sophia Chan, said that the VHIS will provide individual indemnity hospital insurance. To tie in with the publicity slogan "Choose with Confidence," all Certified Plans under the VHIS must meet the benefit standard prescribed by the scheme, including standardised policy terms and conditions, benefit coverage and benefit amounts. The features of Certified Plans include: Guaranteed renewal up to the age of 100 regardless of change in the health conditions of the insured persons (without reunderwriting); No limit on "lifetime benefit"; Coverage extended to cover unknown pre-existing conditions and day case surgical procedures (including endoscopy), etc.; Tax deduction for taxpayers who purchase Certified Plans for themselves and/or specified relatives and pay the premium on or after April 1, 2019; and Transparency on the premiums of Certified Plans. The premium schedules are accessible on the VHIS website. According to an official statement by the VHIS, the VHIS Office will continue work on the registration of participating insurers, vetting of individual indemnity hospital insurance plans for certification of compliance status, enforcement of scheme regulations, etc. Currently, there are 36 companies registered on the list of VHIS Providers on the VHIS website.
By Staff Writer | 01:00 am | April 01, 2019
Good systems analysis requires adherence to a simple recipe – understanding who the stakeholders are and their needs, establishing design goals and working collaboratively to attain them. So how can the My Health Record system, which began in 2012 as opt-in and changed to opt-out 2018, be done better? We like to think the stakeholders are healthcare recipients and providers Australia wide. We would regard privacy, security and utility of health information as key design goals. We would hope that the many design aspects such as legislative, governance, administrative, medical and technical, be developed in harmony. Yet, all these aspects, when recently exposed to public scrutiny, have been found wanting. Researchers at Deakin University Law School under Professor Danuta Mendelson were quoted in Australian Doctor in December 2016 saying, "The My Health Record system appears more suited to supply data for government agencies and researchers than it is suited to healthcare". If the stakeholders rightfully were the Australian healthcare consumers and providers, we should be engaged in the design process and the design goals of utility, security and privacy should be achieved. Key to the design process is the question, "Does the electronic health data need to be in an online central repository?" If the stakeholders are those wanting access to big data about healthcare recipients and providers, the answer is, "Yes." If the stakeholders are Australia's healthcare recipients and providers, that answer may be different. Rights campaigner and lawyer Lizzie O’Shea drew a good analogy on Weekend Sunrise in July last year when she said, "When you centralise information like this … it becomes very attractive to hackers. We’re also putting power into the hands of government to decide how that information is to be used." "You wouldn’t cut a house key for every single plumber in the city, or every house painter [and] electrician… The same is true here; 900,000 medical professionals and 12,000 organisations have access to these records. Why would you design a system like that?” she said. Much has been touted about the benefits of treating doctors, for example, having ready access to an unfamiliar patient's data. The benefits are acknowledged and assumed to be achievable only from a centralised repository of health data. An online central repository accessible by hundreds of thousands of legitimate access points cannot be defended against cyber attack. An attacker need hack only one of these to gain access to every record in the database to see, copy and change at will. A POSSIBLE WAY FORWARD Germany implemented the first-generation of its system of smart eHealth cards in 1993 and this was then developed into the second-generation eHealthcare card in 2017. Data stored on the second-generation German eHealthcare card includes the insured person’s name, date of birth, address, gender, insurance number and coverage status.​ In addition, there is an option for additional personal data to be stored on the card with a person’s consent, such as emergency data and medication, allergies or drug intolerance. Currently, data is accessible by authorised healthcare providers on presentation of the eHealth card. There is no need for a centralised repository, which could be hacked or used for purposes other than for healthcare. If a card is lost or damaged, it is replaced by the issuing authority and data restored from the backup performed at the most recent healthcare consult. The data format is also not constrained by the physical design of the eHealth card memory chip. In 2017, 70 million Germans were in possession of the card. In the near future, a new generation of cards is expected to facilitate the exchange of medical information necessary for treatment, with the inclusion of emergency data, electronic medication plans and electronic patient records on the card. Some other main benefits of the new and improved system are said to include the prevention of redundant medical examinations by different doctors and the online update of administrative data. As such, the benefits of an eCard based system are: Patients control who and only who gets access to the data The entire database of health information is not in a centralised repository connected to the internet Patients don't need to be concerned about what present and future governments, as well as other non-healthcare organisations may do with their health data eCards are flexible about the way data may be stored and retrieved, enhancing the utility of healthcare data A comprehensive telematics infrastructure interface that provides secure communication of health data: eScripts, eReferrals, test results, health insurance, etc. updating the eCard at points of service.  A similar system could be designed for Australia, but the following need to be considered:   How do we make the data useful? It needs to be reliable, complete, up-to-date and stored in a manner which encourages meaningful, apt and rapid retrieval by the healthcare provider and associated recipient. How do we make it secure? We make it virtually impossible for the data to be retrieved by unauthorised actors. How do we make it private? We make it secure and prohibit use outside direct healthcare except only by informed explicit consent of the healthcare recipient. It is possible for Australia to have an eHealth system that services healthcare providers and recipients as primary stakeholders, but Australia is a long way from making such a system a reality. All aspects of the current My Health Record system design – legislative, privacy, health utility, security and technical – need a comprehensive overhaul. To achieve this requires our governments to change the present system, which has shortcomings in legislature, privacy, healthcare delivery, security and technology. There is a fundamental conflict between providing health data for government and non-government organisations, which the My Health Record system is geared to do, and providing an effective eHealth system which respects the privacy and trust of the patient-doctor relationship. Specifically, privacy, powers of the Minister to make rules, substantial powers invested in the System Operator and delegation of these powers need to be reviewed and changed (the original draft legislation commissioned by the Department of Health was substantially changed before presentation to the Parliament 2012). A focus on making the data relevant to immediate healthcare rather than value as cohort data needs to enliven the My Health Record use. A realisation of the fundamental vulnerability of centralised data accessible over the internet needs to drive a new paradigm. The new paradigm must make it practically impossible for everyone's data to be viewed, copied, or changed by unauthorised actors. This will allow for the use of data with informed consent, for example for research, so that it can be aggregated on a case by case basis rather than offering the totality of data by default as a smorgasbord. The most succinct summary of My Health Record’s current state was given in a submission to the Inquiry by an unnamed person who "held a variety of roles at Commonwealth Department of Health":  "In my analysis, both the government and the system operator of My Health Record, the Australian Digital Health Agency... have grossly overstated the benefits to individuals of My Health Record... which is primarily a glorified Dropbox,” he wrote. "The primary functionality of My Health Record is to facilitate secondary data usage, for government and non-government organisations, and that it is they that will be the primary beneficiaries of the system. "In terms of its usefulness for clinical practice and for individual health record management and tracking, it is not fit for purpose, although not entirely useless. This is primarily because My Health Record is about medical records storage rather than providing an up-to-date and accurate medical history overview that can be quickly drilled down into.” The only way the My Health Record can truly be Our Health Record rather than a “glorified dropbox” is if a smart eHealth card system similar to what Germany has in place is adopted.   Paul Power is the head of IT Consultancy to the medical profession, Power Associates. He also appeared as a witness and made submissions to the Senate Inquiry into the My Health Record system in 2018 and the Senate Inquiry into the Medicare card data breach in 2017. Graham Grieve counters the case for smart eHealth cards with the argument that smartphones would work better. Read more.
By Dean Koh | 11:37 pm | March 31, 2019
Singapore Prime Minister Lee Hsien Loong recently announced the appointment of a Public Sector Data Security Review Committee to conduct a comprehensive review of data security practices across the entire public service. The committee will look at measures and processes related to the collection and protection of citizens’ personal data by public sector agencies, as well as by vendors who handle personal data on behalf of the government, according to a statement issued on March 31 by the Prime Minister’s Office (PMO). Deputy Prime Minister and Coordinating Minister for National Security Mr Teo Chee Hean will be the chair for the committee, which also includes private sector representatives with expertise in data security and technology. Ministers involved in Singapore’s Smart Nation efforts – Dr Vivian Balakrishnan, Mr S Iswaran, Mr Chan Chun Sing, and Dr Janil Puthucheary – will also be part of the committee. The committee will review how the government is securing and protecting citizens’ data from end to end, including the role of vendors and other authorised third parties. It will also recommend technical measures, processes and capabilities to improve the government’s protection of citizens’ data, and response to incidents. An action plan of immediate steps and longer term measures to implement the recommendations will be developed as well. International experts and industry professionals, from both the private and public sectors, will also be consulted by the committee, and an inter-agency taskforce formed by public officers across the entire public sector will support the committee. Although security measures such as the Internet Surfing Separation policy in 2016 and the disabling of USB ports from being accessed by unauthorised devices in 2017 have been implemented across the public sector to safeguard sensitive data, the PMO said that the review is “essential to uphold public confidence and deliver a high quality of public service to our citizens through the use of data.” The Public Sector Data Security Review Committee was appointed in light of a series of four data-related incidents that occurred to the Health Ministry in the past 10 months. Notably, the Health Sciences Authority (HSA) also said in a statement on March 30 that one of its vendors, Secur Solutions Group (SSG), reported that there was more unauthorised access to the personal information of 800,000 blood donors as previously reported. The data was uploaded online and left unsecured over a period of two months. The Committee will submit its findings and recommendations to the Prime Minister by November 30 2019.
SPONSORED
By Virtru | Mike Miliard | 03:19 pm | March 29, 2019
HIPAA is inextricably linked to patient privacy, but building a trusted, long-term patient relationship goes beyond HIPAA compliance and requires a deeper commitment to keep patient PHI safe and private.
By Benjamin Harris | 02:58 pm | March 29, 2019
How smart sensors, historical data and machine learning can automate and improve care for seniors.
By Bill Siwicki | 01:46 pm | March 29, 2019
Since implementing a suite of Nuance voice recognition tools, the health system has seen a 23 percent reduction in transcription costs and 71 percent of users reporting that the quality of their documentation has improved significantly.