Wednesday, April 19, 2006

Doctor, Doctor, Give Me the News

Here is a stunning example of how not to implement a program:

Today, more than a year later, it's fair to say that the Maine Medicaid Claims System project has been a disaster of major proportions. Since the new system went live, it has cost the state of Maine close to $30 million. The fallout has been broad and deep. In December 2005, Jack Nicholas, the commissioner of the DHS who oversaw the project, resigned.

As of press time, Maine is the only state in the union not in compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA)—a striking irony given that the new system was designed to facilitate that compliance. Although federal authorities have said they will work with the state in extending the deadline, the failure has been a black eye on Maine's ability to manage the health of hundreds of thousands of its residents. And it has become an issue in this year's race for governor.


As always, there are lessons to be learned from the failure of others--- we can add to the standard "...classic blunders! The most famous is never get involved in a land war in Asia, but only slightly less well-known is this: never go in against a Sicilian when death is on the line!", this new one: if you only get two bids for your new end-to-end system, and they are radically different, maybe you have conceptual issues to iron out before you proceed.

Sweet Lies

A right-on rant from Deborah Peel in Government Health IT:

If people believe they do not have medical privacy, they will lie about their medical illnesses or omit mentioning critical tests and details rather than have the information flow to any number of health-related businesses. Such firms are allowed under the Health Insurance Portability and Accountability Act (HIPAA) to receive medical information about patients without their knowledge and consent.

Thursday, March 30, 2006

Flee from Reality

Here is a case of the police losing track of someone and using the convenient HIPAA excuse. But this time, the hospital isn't having it:

In this case, she said, "hospital police say they have no record of any dealings with law enforcement pertaining to Mr. Pharr." Crayton added that she is not aware of any cases at UNC where HIPAA rules have gotten in the way of officials being notified of a criminal defendant's discharge.

So blame HIPAA for the bad guy getting loose didn't work this time, and I think as more folks become better informed we will see less of this. Too bad, it is such a convenient excuse!

Cops and Robbers

When do you give information to the cops, how much do you give, and are you exposed? I am asked this question at nearly every training I give. Here in the state of Washington, the Hospital Association has published a 30+ page guide for front line and emergency room providers. Your state probably has an organization who has at least explored this. On a national level, the National Center for Policy Analysis has this to say:

Daily in emergency departments and inpatient trauma services, and sporadically in other departments, police officers request permission to interview patients who may have experienced, witnessed or perpetrated crimes ranging from motor vehicle crashes to homicides, says the Journal of the American Medical Association (JAMA).
Decision making by both clinicians and police is unstructured, ad hoc and potentially susceptible to adverse outcomes that might be preventable with appropriate guidance, says JAMA.

The cops, who are after all only trying to do their jobs, will always assert that it is okay for you to tell them anything they want. It is important to remember that their goals and exposure are not the same as yours.

Money

A solid two-part article by Diana Kelley in Search Security called "Become compliant -- without breaking the bank":

Here's some good news: For most companies, the lion's share of tools needed to support control objectives for regulatory compliance are already in house. Before investing a single penny in new technology, assess the ability of what you already have.

A lot of the push-back from management comes from the fear of sticker shock. They have heard of other compliant soutions that have cost tons of money. here is your chance to play the hero--- take them a proposal that is cost-effective. They will be happy to take the credit for it :)

Wednesday, March 15, 2006

Yours Truly, Confused

Gotta love this:

A recent Washington, D.C., case suggests that patient privacy continues to be a concern. The Washington Post reported a week ago on the case of a George Washington University sophomore who checked himself into GW Hospital, depressed and thinking of suicide. Soon afterward he received a letter from the university saying he faced possible suspension or expulsion for violating the code of student conduct.
How did the university learn of the student's condition?
"I'm not able to comment on this story due to HIPAA," said Lisa McDonald, the hospital's director of marketing and business development.


Let me see if I have this straight--- our friend Lisa, who is, so far as I can tell from her title, not the compliance officer, but is instead a PR flack for the hospital, says she can't comment on what is on the face of it an egregious violation of the Privacy Rule, because commenting on a HIPAA violation would be a HIPAA violation?
I love this! Let's see if it works for other things--- "I'm sorry officer, I cannot accept this speeding ticket because by doing so I would be violating HIPAA."
"I know I spent the rent money on poker, honey, but we can't discuss it because I don't want to be in violation of the Privacy Rule."
"You know, the Administrative Simplification Rule sets forth civil penalties as high as $250,000.00, and in light of that, I just can't make my child support payment this month--- can't talk about it, though, HIPAA you know."
See how it works! Give it a try!

All My Exes Live In Texas

Here is a good summary of the dust-up going on in the Appeals Court in Texas over HIPAA privacy, from the Dallas Morning News:


Soon after an overhaul of federal health care privacy laws took effect in April 2004, journalists sometimes found they could not gather information usually taken for granted.
Police, fire and hospitals in some cases were using the law to withhold information on crime and accident victims, even refusing to disclose whether someone was injured and how.
Then in December 2004, Texas Attorney General Gregg Abbott ruled that state public information laws trumped the Federal Health Insurance Portability and Accountability Act, known as HIPAA.
Information already deemed public under state laws would remain that way, Abbott said, calling it the strongest legal opinion on the matter in the country.
But that ruling was soon challenged in court. And nearly a year after oral arguments before the Third Court of Appeals in Austin, freedom of information advocates are still waiting for a decision.


As so often happens, there have been cases where administrators have hidden behind HIPAA to avoid accountiblity. There has also been the usual mis-information that has been such a big part of the push-back against the Privacy Rule, including my favorite, the "We can't ask for prayer for our sick church member in the bulletin" canard.

Thursday, March 09, 2006

After the Flood

Got a disaster plan? Other than running in circles and wailing? You better:

According to government studies, two out of five companies that experience a disaster go out of business within five years. If disaster strikes a medical practice, the practice administrator must ensure that business continues in an efficient manner. Downtime means delayed or inaccessible medical records, which impact patient safety and satisfaction, the practice's reputation as well as decreased revenue and productivity. Additionally, HIPAA mandates contingency plans for practice disasters including backup, storage and recovery.

If there is one thing that current events teaches us, it is that we are on our own in the crunch. If you are going to be able to continue to serve your clients after some catastophic event, whether a hurricane, flood, or the janitor tripping over the power cord and frying your server, you need to have a plan. It isn't just the law--- your patients need their information, and you may be the only source for identifying what "that blue pill I take on Thursdays" really is.

Monday, March 06, 2006

That, that dude looks like a lady

Passed on to you, wishing that I found tips like this one in my in-box every monday.

From: Privacy and the Female Impersonator

...It has to do with the HIPPA laws stating that only the patient or insured involved in the issue may speak with an insurance company or health facility on the phone. So, let’s say a husband is trying to sort something out for a sick wife and calls the insurance company.
“It happened to me,” said Cliff P., a friend who was told by an insurance firm that he could not speak for his wife. So, he hung up, called back and said he was Mrs. P.
Cliff, whose voice is a definite baritone, didn’t even bother to hike up his Jockeys.
“I just told them I was my wife,” he recounts. “They handled the business with no problem. How can they question me? What are they gonna say, my voice isn’t feminine enough? That would be an insult, an invasion of my privacy.”
Note to other spouses in similar situations: this may not be legal or even ethical, but it sounds like it might get the job done.
Note to the authorities: Cliff has left the country to debut his act in a Rio nightclub.

Friday, March 03, 2006

Trust Yourself

This question was forwarded to me the other day:

Any thoughts on this issue?
We're having a bit of confusion in our department. One supervisor says it's not against HIPAA for the MTs to transcribe their own reports or their non-adult child's reports (just not spouse or other extended family members). Other supervisor says it's a direct violation and a terminable offense. Can anybody please verify or clarify this for me, point me in the right direction, provide some concise documentation? Greatly appreciated!


The PHI belongs to the patient and it is never a violation for the patient to view, disclose, or use their own PHI. In the case of a non-adult child, as long as the parent is the child’s representative, the same would apply. Possible exceptions would be mental health notes taken by a therapist or analyst, which belong to the note-taker, or cases where the physician or a court have reason to believe the child is at risk from the parent, or where the parent has waived the right to be the child’s representative, once again usually in mental health situations.

Do you have similar questions? Send 'em in. I'll do my best to answer right away!

Monday, February 27, 2006

Down by Law

This seems quite clear to me, and I am glad that the courts agreed with my non-lawyer opining self--

Limits on release of medical records. After the state hospital and state training school denied the P&A's request to access the medical records of its disabled patients, both sides sought guidance on the extent to which HIPAA and the Medicaid Act affected the disclosure requirements of the P&A Acts. The court determined that the limits on the release of protected health information found in HIPAA and the Medicaid Act do not prevent the P&A from accessing protected health information. Under HIPAA, medical records may be released when required by another law. The P&A Acts require the release of medical records in certain circumstances, satisfying requirements for release of the information under HIPAA.

The law is pretty clear. If HIPAA comes into conflict with an existing state law, in most cases the state law will have precedence. Mostly this was intended to allow states to have stronger regulations regarding privacy, but I can see where in this case the state law would need to have more juice, even though it doesn't deal directly with privacy. Lawyers.... tell me if I am mistaken!

Beast of Burden

Balance, Grasshopper, balance. Having a sane approach to compliance doesn't just save you from sleepless nights, it can save your compnay money, time and effort, which as you know are the holy trinity of getting something approved by the higherups, who always have those pesky "why" questions.
From Processor comes this editorial "Taming the Compliance Beast"---

Sarbox and HIPAA are so big (and so feared) that some firms go overboard to comply with them. “The biggest problem is over-scoping,” says Gartner’s Caldwell. Some companies put controls “here, there, and everywhere,” he says, ignoring the narrow intent of the law. For instance, Sarbox was designed to address financial controls and audits and never mentions IT per se. But some auditors have been reluctant to limit their clients’ efforts, a problem that was common in the early days of Sarbox when little was known about it. In contrast, some companies don’t go far enough, approaching Sarbox and HIPAA “as a project, not a process,” says Forrester’s Rasmussen. They don’t see compliance as part of their day-today operations, he says, and too often assign a project manager to an ad hoc job that won’t suffice in the long run.

This is so true. About half the front-line workers I deal with are suffering from HIPAA fatigue. They have been beat on for so long, and been so handcuffed by policies that they despise the very mention of HIPAA.
The other half are working at places that are so casual with PHI that they themselves are concerned, and are attending one of my workshops to cover thier own assets.
Find a sane middle ground. Make your policies transparent enough that your front-line workers can follow them, but integrated into your processes so that they have some effectiveness.

Friday, February 17, 2006

Mind on Our Money

Think protecting your data is expensive? It could cost as much as 15 times as much to respond to a breach---

A September 2005 report by Gartner Inc. states that "a company with at least 100,000 customer accounts to protect can spend, in the first year, as little as $6 per account for just data encryption or as much as $16 per customer account for data encryption, host-based intrusion prevention and strong security audits combined. This compares with an expenditure of at least $90 per customer account when data is compromised or exposed during a breach."
Thus, by approaching security as an opportunity rather than as a burden, an organization can stay ahead of criminals, competitors, reporters and regulators; reduce or avoid cost over time; and transform data security into a strategic advantage for the organization.


That's some mighty simple math for you. A lot of us have to go before the bean-counters to jsutify spending even the smallest amount on things we know to be important, but because many of those things are difficult to explain, we don't always get the tools or resources we need. Put like this, however, we are speaking their language; dollars and cents.

Key to the Highway

Extremely good piece on EHR's and research by Nancy Harris in Government Health IT---

Hidden keys to health
The medical community is sitting on mountains of e-health data that could lead to important medical discoveries. But will its value remain buried by privacy concerns and lack of funding?

Kansas City

There is starting to be some push back against EHR--- and rightly so. I tend to be in favor of systems that allow good access to information to providers, but as an IT guy I have to say that a) any system can be abused, and b) you have to give good data to get good data.
This article from Kansas City Info Zine says it well, right in the title: Electronic Medical Records Have Potential for Misuse---

Advocates of Electronic Health Records say the system will have the tightest possible security. But recent large-scale thefts of credit card and banking information have shown that all databases, even those with state-of-the-art security protections, can be compromised. Electronic medical records systems now in operation have already sprung some serious security leaks. In 2003, a medical transcriptionist in Pakistan threatened to post patient records from the University of California San Francisco's Medical Center on the Internet unless she was paid for her work for a transcription service company hired by the university. The dispute was resolved but meanwhile patients had no idea their records were being sent overseas. In another breach, two computers that held a disc containing the confidential records of close to 200,000 patients of a medical group in San Jose, California, were posted for sale on Craigslist.org. The FBI recovered the information and the medical group informed current and former patients of the theft.The full report on electronic medical records appears in the March 2006 issue of Consumer Reports which goes on sale February 7, 2006 wherever magazines are sold. The investigation will be available online to subscribers of ConsumerReports.org at www.ConsumerReports.org.

We need to be paying attention to this. HIPAA already has a reputation as a clumsy, intricate, annoying, but toothless tiger. If all of that compliance work that we have all struggled to accomplish can be simply bypassed through idiocy, poor implimentation, or loopholes that allow abuse, then shame on us for letting it happen.

Dear Prudence

So disclosing PHI isn't just against the law, it is rude.
Really, this is a good sign. When the Dear Abby's and in this case, Ask Amy's get involved, you know that we have come a pretty long way.
And there is a lesson here--- we sometimes forget, amidst the pain in the neck nit-picking details of the latest set of compliance rules that this information is private, that it belongs to people who should have every right to expect that their personal information not be broadcast to the world.

Dance to the Music

Here it is--- the final version of the enforcement rule. I have only skimmed it at this point, but I didn't find much different.
It is 45 pages of legalese, but if you are any way involved with HIPAA compliance, you need to read it.

Friday, February 10, 2006

Detroit Rock City

I am often asked "Can't I just buy a software to do all this?" --- the short answer is the best one here---- no. In this article from the UK in IT Analysis Clive Longbottom slices and dices the problem with trusting your vendors to make you compliant.

Think of all the computerised solutions that we have had since the advent of the mainframe in the 1960s - barely 40 years ago. Could we now easily recover data from an original Winchester disk? Could we easily provide information to the 'powers that be' if it were stored in Navy DIF or AmiPro version 1.2? This becomes a thorny point when 'they' insist on the original document - even file viewers cannot guarantee fidelity of view...

Overall, the KISS (Keep It Simple, Stupid) approach to governance and compliance is the best - start with a high-level framework and look for the technical solutions that will facilitate the framework. Then look at what a company's needs are for specific areas of governance and layer solutions over the framework. This should give a higher level of flexibility for the future and prevent that horrible feeling when you think you have everything covered and find that the one piece of information Chief Inspector Knacker of the Fraud Squad is demanding is not covered by your swanky, multi-million euro compliance solution.

It is your data, and your behind that will be in a sling if you are not in compliance. As Clive points out, the best solution is to top-to-bottom make sure that your data is secure and available.

Baby I'm Back

I have been very busy lately, so I haven't been keeping up here as much as I'd like. But for now things are less chaotic, so to celebrate the return to order, let's look at this piece from Tech Republic:

After a disaster, not only do you have to get back up and running within the time constraints set forth by regulatory compliance, but you're going to have to continue to ensure that you can meet or exceed standards. This is especially true for privacy regulations like HIPAA, which do not go away just because you're on alternate servers in another location. Quite the contrary, failing over or restoring to new systems is a red flag that you might not be in compliance anymore. In order to prove that the disaster has not destroyed your organisation's ability to protect data, you will have to ensure that security and encryption protocols are being enforced at the backup site, and that compliance-software implementations are performing the same tasks at the alternate site as they do at the production site.

One of the places I find some push back from those who want to be in compliance, but still don't understand how it really works is in the area of disaster recovery. The reason why it is included in the HIPAA rules is that data handling has to be seamless---- it is an end to end process that goes from creation to distruction, and your data needs to be protected along every detour it might take, whether through a BA or through a temporary home in your back-up servers.