Projects, designs, and writings on health IT

Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

2014-10-31

Twitter’s new tool could enable sharing of health data

4:39 PM Posted by David, MD , No comments

David Do, MD 


It’s a common scenario: A patient in the clinic or emergency room says he had a CT scan of the head across town just three days ago, but he doesn’t know the result. To request the records from other facilities can take hours, and can be impossible in the middle of the night. Providers just do not have the time to make the formal requests necessary. Instead, we repeat the tests out of convenience, contributing to the enormous waste in healthcare spending. About 20% of tests are unnecessary repeats [1]. This is a common theme in healthcare; patients receive care within multiple health systems with poor exchange of information, resulting in wasteful spending.

The solution to this problem may seem quite obvious in this electronic age; create a common repository of electronic medical data that can be shared between hospitals. In fact, the ONC's HIE initiative has put forth over $0.5 Billion towards promoting the goal of aggregating data across institutions [2]. In reality, the answer is not so simple, because institutions are not incentivized to share data—they are more concerned with preventing breaches of information. Should this even be up to the institutions? Most people would agree that patients are the true owners of their data, and they should choose who gets to see it. Thus, whether a person’s health record is stored on the cloud, a thumb drive, or on the EMR within a hospital, patients should rightly hold the key.

Meaningful use criteria have, in fact, dictated that patients have access to their medical records via online portals. As a provider, I could provide better care if I could access these portals too. In the prior scenario, I could ask my patient to log in to his portal and look at his CT image together. Sadly, this is not yet reality, and here's why: Usage of portals is a dismal 25% [3]. That’s because most patients we care for are elderly or uneducated and are not savvy enough to access their data from the online portal. In fact, most patients are unable to remember the names of their medications, let alone usernames and passwords.

This week, Twitter announced Digits, a tool for software makers that allows users to sign into apps with just a cellular phone number. That’s one thing my patients have and can remember. Here is how it works: To log in to a website with your telephone number, the service will send a confirmation code that you subsequently type into the website, ensuring that only the owner of the telephone number can access the website. If patient’s medical records were tied to their telephone numbers, I am convinced I could deliver better care.




David Do, MD, is a physician and agile software developer.

2013-08-11

What the Recent Data Breach Says About the State of Health IT

5:48 PM Posted by David, MD , No comments
This post originally appeared the The Health Care Blog 2013-08-11

What the Recent Data Breach Says About the State of Health IT

By David Do, MD

Recently officials at Oregon Health Sciences University discovered that residents in several departments were storing patient information on Google Drive, and had been doing so for the past two years. They treated this discovery as a breach of privacy and notified 3000 patients about the incident.

While I don’t condone the storage of patient information on unapproved services like Gmail or Google Drive, this incident pretty much highlights the sorry state of information systems within the hospital and the unfulfilled need by physicians for tools that facilitate workflow and patient care.

It says something that the Oregon residents felt compelled to take such a drastic action. I don’t know what punishment – if any – those responsible were given by administrators for their “crimes.” I’ll leave it to readers to make up their own minds about the wisdom of the unauthorized workaround and the appropriateness of any punishment. But I do know that the message the incident sends is a very clear one.

We’re screwing this up. There is really no earthly reason why it should be any more difficult to share a patient record than it is to share a Word doc, a Powerpoint or yes, even a cloud-based Google Drive spreadsheet.

Why the Breach Happened

What’s going on here? Let’s say I admit a patient to the hospital.  Our friend was hospitalized here just last month, and like many patients, he has dementia or is poorly educated, and does not know the names of the medications he takes. Unfortunately, I don’t have the ability to see what he takes or how he was treated during the prior admission because the records in the computer are there for documentation’s sake and don’t contain any meaningful information. This is clearly a problem for me.

Therefore I will spend time calling outside facilities to gather information and repeat several tests and imaging procedures.

Medical care has become a team sport, and residents have developed systems for keeping track of their patients and communicating to other physicians. It takes some time to think about and process each patient that comes in, to consolidate all the information. Ultimately, I need to boil that information down to a five-minute description on the patient, their problems, the status of their current admission, and what needs to happen before they go home.  We do this in the form of a signout document.




Figure: The signout document has four to five columns and includes the To Do list for each patient.

The EMR does not have a good way to store information in this format, and  additionally I have no way of editing this in real-time to communicate with my
coworkers what still needs to be done. That’s why residents were storing their  signouts in Google Drive.

What providers need here is simple data management. We need to store and access this list from different computers. We need the ability to enter a subset of those data  using a custom form, and the ability to print subsets of those data to create a To Do lists, rounding sheets, or progress notes.

What we can learn from this breach

In the end, there was no actual breach of data. Don’t blame the residents for what  happened in Oregon. They have, better than anyone, demonstrated an unfulfilled
need for good medical software that is user-tested.  Products that develop through hospital IT departments are slow, non-intuitive, and buggy. Hospitals need to invest
in health IT, above and beyond that need to meet the requirements of Health IT  legislation. We need designers, software product mangers, and user testers from
Google.

David Do, MD is a graduate of The Johns Hopkins University School of Medicine and a resident physician at the Hospital of the University of Pennsylvania. He is an agile software developer and Chief Technology Officer at Symcat.com.