Skip to main content

News

By Nathan Eddy | 10:01 am | March 22, 2019
Invistics says its platform deploys machine learning algorithms to detect drug diversion that would otherwise go unnoticed or unreported.
By Tom Sullivan | 10:38 am | March 21, 2019
The ultimate goal is patient safety and freeing up money to invest in care.
02:48 am | March 21, 2019
SA Health, the public health agency of South Australia, has made improvements to its troubled electronic medical record (EMR) system, in an attempt to lay the foundation for progressive implementation of new features and functionality. The move is an upgrade from the version the healthcare organisation was using since 2014, and follows an independent review of the program that found its Enterprise Patient Administration System (EPAS) failed, as it “contrasts with other successful EMR implementations in Australia”. The review identified that SA Health’s billing module was “not fit-for-purpose”; and the EPAS has a “flawed governance model” that didn’t empower clinicians to be key decision-makers or allow the system to be tracked, measured or managed, amongst other findings. Following the review, SA Health was expected to scrap and reconstruct its beleaguered electronic patient records.  The upgraded EMR version installed at SA Health’s facilities now consists of Allscripts Sunrise EMR and paperless administration system (PAS), which was a key recommendation in the EPAS Review. Recommendation 13 of the review identified that “the existing Sunrise EMR/Allscripts PAS 14.3 software version be upgraded to 17.3, with the progressive implementation of its new features (not ‘like with like’), and that subsequently there be a regular upgrade path”. Allscripts ANZ General Manager Todd Haebich said the upgrade provides SA Health with a more contemporary, versatile and risk-resilient EMR platform. “The latest version of the Sunrise EMR 17.3 offers many functional benefits, but from an interoperability perspective, it enables SA Health and third-party vendors to extend the EMR with new apps and initiatives, including products from the global Allscripts Application Store,” Haebich said. “The upgrade also brings increased security and resilience, as it provides administrators with greater and more effective capabilities to keep the platform functioning when servers and networks fail.” The upgrade also allows SA Health to introduce the following: Timeline: A patient-centered graphical view of the continuum of care, where the clinician receives a visual view of the patient’s visit history across all settings of care. For a more detailed view of a specific encounter, the clinician can open the desired block to launch the new visit record web portal.   Sunrise Compass: A solution that enables it to build upon and combine the workflow management tool and tasking infrastructure into a single new UI. A new Smart Engine analyses patient conditions such as results, vital signs, problems and observations to dynamically suggest tasks, workflows and actions. Compass aims to increase the quality of care and decrease time to treatment and diagnosis by decreasing manual interventions in the EMR.   Sunrise Mobile: A solution that lets clinicians manage their daily activities. “The upgrade is the first step in ultimately providing SA Health with a system to rival what we have achieved in other geographies like the US, UK and Singapore,” Haebich said. “We welcome the EPAS Review’s recommendation that we play a much greater role in delivering SA Health’s EMR, and we look forward to working more closely with SA Health to fulfil what it has set out to achieve.” This article first appeared on Healthcare IT News Australia.
By Staff Writer | 01:00 am | March 21, 2019
After a delay to strengthen privacy and security protections, the expansion of the government’s centralised digital medical records system is complete. The rollout of My Health Record reflects a significant shift towards the digitisation of healthcare and Australia’s vision to make patient records more accessible. This has resulted in the creation of new opportunities to improve care across a range of health services. The possibilities, while endless, also open up a range of challenges regarding privacy and consent – challenges which nearly 300,000 Australians aren’t prepared to face, having opted out of the system by November 2018. CONNECTED BUT SECURE Using digitised services ranging from online health records to remote monitoring tools such as wearables or apps, organisations are seeking to improve patient outcomes. On the flip side, this heightened level of connectivity also creates additional points of exposure. It may be a bitter pill to swallow, but Australians have shown that they are unwilling to comprehensively divulge all medical information due to privacy and security issues. What is required the establishment of a proper trust relationship among patients, care providers and digital services. The two critical pieces in doing this are authenticated identity and consent management. Systems must be secure whilst also facilitating immediate access to patient data and history to inform care regimes. They must also maintain certain levels of user control to ensure that only relevant information is shared with the authorised third party. As connected care becomes more commonplace, the potential for identity theft also increases, especially if access and controls systems aren’t established from the onset. Ensuring privacy and security of patient data means verifying user identity and permissions to ensure that the mantra “no data about me, without me,” rings true. CREATING A BETTER SYSTEM Balancing health data interoperability with patient privacy is another challenge. Case in point: Sweden’s rollout of electronic health records (EHRs) and the resulting increased regulatory pressure spelt out the need for open healthcare API standards. The use of data from clinical trials, registries and patient outcome databases for research purposes also came under scrutiny when the General Data Protection Regulation (GDPR) was being finalised. However, in every challenge there is an opportunity. Researchers are now able to undertake research and apply deep learning on EHRs to predict healthcare-associated infections. It is these kinds of developments that Australian researchers can look to emulate through secure access to EHR databases. Regardless of the outcome, this kind of progress shouldn’t come at the detriment of meaningful patient control. A simple opt-in checkbox restricts sharing capabilities, limiting a patient's ability to direct how their data is accessed and used on a daily basis. A patient’s health status can deteriorate or improve in a matter of minutes, and their ability to consent needs to be able to adapt in the same way. User-Managed Access (UMA) offers patients a simple and powerful way to manage health data ecosystem impacts, allowing them to determine who gets access, for how long and under what circumstances. Implementing the Health Relationship Trust (HEART) standards, which profile UMA, helps promote patient control and ensure the secure exchange of patient information. A SEAMLESS EXPERIENCE With the My Health Record, patients want to interact with a single health portal. This brings with it the expectation that patients want to take charge of their health and digital identity. In this situation, reducing friction from secure authentication experiences becomes more important than ever. The continued digitisation of the healthcare system, beyond the creation of digital records, means providers must establish systems which accommodate users, devices and the systems which securely facilitate data sharing and recording. This transformation needs to factor in the consolidation of once-isolated systems and devices to create a unified patient profile across all digital channels. This ensures that services are consistent and personalised, delivering better health outcomes. A robust customer identity and access management (CIAM) strategy can enable strong authentication and authorisation, while offering a single view of the patient and relevant data, and keeping controls firmly in the hands of the patient in a way that makes managing their health and relationship with healthcare providers seamless. As digital transformation continues to drive advancements in healthcare, safeguarding patient data will influence widespread adoption. Whether data collected is by devices and apps or through a visit to the doctor, an effective CIAM strategy is critical for organisations wanting to deliver connected care and foster trust with patients.   Eve Maler is Vice-President of Innovation and Emerging Technology at ForgeRock.
By Staff Writer | 01:00 am | March 21, 2019
SA Health has made improvements to its troubled electronic medical record (EMR) system, in an attempt to lay the foundation for progressive implementation of new features and functionality. The move is an upgrade from the version the healthcare organisation was using since 2014, and follows an independent review of the program that found its Enterprise Patient Administration System (EPAS) failed, as it “contrasts with other successful EMR implementations in Australia”. The review identified that SA Health’s billing module was “not fit-for-purpose”; and the EPAS has a “flawed governance model” that didn’t empower clinicians to be key decision-makers or allow the system to be tracked, measured or managed, amongst other findings. Following the review, SA Health was expected to scrap and reconstruct its beleaguered electronic patient records. The upgraded EMR version installed at SA Health’s facilities now consists of Allscripts Sunrise EMR and paperless administration system (PAS), which was a key recommendation in the EPAS Review. Recommendation 13 of the review identified that “the existing Sunrise EMR/Allscripts PAS 14.3 software version be upgraded to 17.3, with the progressive implementation of its new features (not ‘like with like’), and that subsequently there be a regular upgrade path”. Allscripts ANZ General Manager Todd Haebich said the upgrade provides SA Health with a more contemporary, versatile and risk-resilient EMR platform. “The latest version of the Sunrise EMR 17.3 offers many functional benefits, but from an interoperability perspective, it enables SA Health and third-party vendors to extend the EMR with new apps and initiatives, including products from the global Allscripts Application Store,” Haebich said. “The upgrade also brings increased security and resilience, as it provides administrators with greater and more effective capabilities to keep the platform functioning when servers and networks fail.” The upgrade also allows SA Health to introduce the following: • Timeline: A patient-centered graphical view of the continuum of care, where the clinician receives a visual view of the patient’s visit history across all settings of care. For a more detailed view of a specific encounter, the clinician can open the desired block to launch the new visit record web portal. • Sunrise Compass: A solution that enables it to build upon and combine the workflow management tool and tasking infrastructure into a single new UI. A new Smart Engine analyses patient conditions such as results, vital signs, problems and observations to dynamically suggest tasks, workflows and actions. Compass aims to increase the quality of care and decrease time to treatment and diagnosis by decreasing manual interventions in the EMR. • Sunrise Mobile: A solution that lets clinicians manage their daily activities. [Read more: Fremantle Hospital deploys EMR system for better support of care in WA | University Hospital Geelong improves ED clinical workflows] “The upgrade is the first step in ultimately providing SA Health with a system to rival what we have achieved in other geographies like the US, UK and Singapore,” Haebich said. “We welcome the EPAS Review’s recommendation that we play a much greater role in delivering SA Health’s EMR, and we look forward to working more closely with SA Health to fulfil what it has set out to achieve.”
By Bill Siwicki | 03:37 pm | March 20, 2019
Four experts in healthcare cloud computing offer CIOs and other health IT workers who are starting – or maintaining – cloud migrations some well-rounded advice.
By Beth Jones Sanborn | 03:15 pm | March 20, 2019
With increasing buzz around population health and social determinants of health, those two forces are poised to change philosophies around care delivery and how a hospital or health system works to keep the surrounding community healthy. While that likely means good things for patients and outcomes, it also drives more sharing, more data and more risk of losing your privacy. There is also a big push for increasing a patient’s autonomy around their personal health information and the access they have to it, especially via personal devices which are likely to be used in the future to communicate directly with providers, if they aren’t already. There is also the continued push toward interoperability and the use of AI and machine learning. David Finn, EVP of Strategic Innovation for CynergisTek, said that while all these things carry huge potential to positively impact healthcare delivery, they also create new dimensions of risk when it comes to cybersecurity. “It has been my mantra for ten years that we have to change the way we think about data. It is our most valuable asset. It’s how we run our business and care for patients. But we have not adjusted our thinking about data to how the bad guys think of it. Until we think about what you could do maliciously with that information, I’m afraid we will not catch up with them,” he said. Many of these trends are already exploding, so it’s no surprise then that they are all included in Finn’s list of top cybersecurity issues healthcare will face in 2019 and 2020. If they aren’t on your list of concerns, Finn says they should be. 1. FHIR and APIs New proposed standards for interoperability and new FHIR standards for letting systems share health information, as well as facilitating patient access through open APIs, recently made waves through the healthcare landscape. Just as patients have access to other personal information like banking via apps on their devices, the notion is that they should have equal access to their PHI. Finn said that while he doesn’t disagree with that concept, data standards for APIs were proposed but no one talked about security, even though he said APIs are a known security risk in most industries. Such standards and policies need to have cybersecurity standards embedded as well. That means they have to be as big a part of the conversation as patient care itself. “To call for that kind of sharing without addressing security points back to all the issues we had in 2018 and prior. We just haven’t elevated privacy and security to the same level of understanding or given it the same seat at the table as we work through a lot of these issues.” 2. Keep your business associates close and your data closer In 2018, the number of cyber incidents related to business associates climbed, yet the concept of clinically integrated supply chains is gaining traction because it is a faster and more efficient way of operating, Finn said it also increases risk and exposure to third-party error or misconduct. “Unless we design all these things with the security built in up front, I’m afraid we may actually be making things worse for ourselves,” he said. 3. Digital transformation and the silver bullet That transformation, including telehealth, personalized medicine and the use of connected personal and medical devices, is most certainly upon us. While all those methods represent a potential positive impact on care and outcomes, they also mean more data, more formats, more cloud development and they all require specialized security needs, especially when it comes to medical devices. When it comes to medical device security issues, Finn said there are dozens or hundreds of vendors who claimed to have solved medical device security. They get a “fancy new tool” they think will find and fix everything. The inherent problem with the “silver bullet mentality” is tools are just tools. “A stethoscope has never cured anyone. An x-ray has never healed a broken arm. They are very helpful in figuring out what’s wrong but we are getting away from basics by thinking there is a silver bullet. At the end of the day, it’s going to come back to using those tools to find out where your issues are and what you need to do. But we need people to go in and do that work. If there is one area of innovation taking the healthcare world by storm, it’s AI and machine learning. And with good reason. From claims processing to diagnosing cancer, Artificial Intelligence seems to have limitless potential is numerous sectors of care delivery and operations. But much like the headaches we so often hear about when it comes to launching EHRs and other innovations, AI has the potential to be launched badly. And such tools can also expose systems to risk if security is an afterthought, not an equal player. “It takes a really smart person who understands the data to look at what those systems are telling you and make adjustments that actually improve what you are doing. My hope is we start thinking about the security before we start jumping on all this new stuff. We have to do it. There’s no argument about that but we have to do it right.” 4. Moving to the cloud Cloud computing presents another double-edged sword in that operationally, it is cheaper and more efficient, at least when it comes to up-front costs. Moving more data and applications to the cloud and getting that processing out of data centers ]makes a lot of sense, he said. But the pitfall is the frequent perception that once we have given something over to a cloud vendor they are going to protect it. Third party risk and lack of understanding of what the cloud model really means, how you recover when a cloud-based system goes down or in the case of an attack, the response, is going to be very different with a cloud-based system versus if all that data and applications were in your data center, where you have control over everything. We need to back up and look at how we are doing it, Finn said. First and foremost, more front-end vigilance is needed when it comes to arbitrating contract requirements and fleshing out potential vulnerabilities. And whether you are cloud-based or if you are keeping it all in-house, you still need a detailed response plan and recovery team for if your cloud goes down or is taken down by cybercriminals. “Just like in your data center you have to have a disaster recovery plan and you have to test it, you still have to have an incident response plan and you have to exercise it to make sure you’re not missing anything,” Finn said. “And we just typically don’t do that with our cloud providers.” 5. Phishing is still a force to be reckoned with Finally, Finn said that despite rampant usage and success with phishing attacks by hackers, awareness and training related to phishing-related events actually went down from 2017 to 2018. In fact, 2018 had more phishing attacks than ever before in healthcare. It is imperative that this seemingly simple method of invasion be treated with the utmost urgency. “It comes back to awareness and training which will keep us focused on the real issue which is how we think about data and how we use it,” Finn said.
By Mike Miliard | 03:05 pm | March 20, 2019
The CEO of the Alliance for Better Health and former deputy national coordinator talks EHR and interoperability challenges, the need for ROI, physicians' changing roles and why "social determinants" might not be the right term.
By Nathan Eddy | 12:38 pm | March 20, 2019
The system is building on a program that saw early results including a 62 percent mortality rate reduction.