Warung Bebas
Tampilkan postingan dengan label Reed Gelzer. Tampilkan semua postingan
Tampilkan postingan dengan label Reed Gelzer. Tampilkan semua postingan

Selasa, 10 Desember 2013

44% of hospitals reported to HHS that they can delete the contents of their EHR audit logs whenever they'd like?

Modern Healthcare published an article "Feds eye crackdown on cut-and-paste EHR fraud" on Dec. 10, 2013 by Joe Carlson.

The article is about federal efforts to reduce the amount of clinician cut-and-paste from prior notes of a patient - which can even be done between charts of different patients.  This practice can result in overbilling for work not actually performed.  The practice can also result in no-longer-accurate data being carried forward; I have been consultant to cases where that phenomenon, in my opinion, contributed to grave patient injury in cases that have settled out of court.

It is at this link:  http://www.modernhealthcare.com/article/20131210/NEWS/312109965/feds-eye-crackdown-on-cut-and-paste-ehr-fraud?utm_source=articlelink&utm_medium=website&utm_campaign=TodaysHeadlines#

Subscription required, but googling the article title may allow reading it in its entirety.

The article begins:


Federal officials say the cut-and-paste features common to electronic health records invite fraudulent use of duplicated clinical notes and that there is a need to clamp down on the emerging threat. That concern is enhanced by the fact that it's too easy to turn off features of EHR systems that allow tracking of sloppy or fraudulent records.

In an audit report released Tuesday morning (PDF), [HHS Office of Inspector General, "NOT ALL RECOMMENDED FRAUD SAFEGUARDS HAVE BEEN IMPLEMENTED IN HOSPITAL EHR TECHNOLOGY"], HHS agencies confirmed that they are developing comprehensive plans to deter fraud and abuse involving EHRs, including guidelines for cut-and-paste features. The issue arises at a time when critics say federally subsidized digital patient record systems are sometimes being used inappropriately by providers to drive up reimbursement.

“Certain EHR documentation features, if poorly designed or used inappropriately, can result in poor data quality or fraud,” according a report from HHS' Office of the Inspector General.

None of this is a surprise to me, and to readers of this blog.

However, the real "money quote" in the article, I believe, is this:


"In addition, only 44% of hospitals' “audit log” systems could record whether cut-and-paste was used to enter data, and an identical percentage of hospitals reported [to OIG] that they can delete the contents of their internal audit logs whenever they'd like."


From page 11 of the HHS OIG Report linked above (http://www.modernhealthcare.com/assets/pdf/CH92135129.PDF):

[In 2006, ONC contracted with RTI International (RTI) to develop recommendations to enhance data protection; increase data validity, accuracy, and integrity; and strengthen fraud protection in EHR technology.]

... Hospitals' control over audit logs may be at odds with their RTI- recommended use as fraud safeguards:

RTI recommends that EHR users not be allowed to delete the contents of their audit log so that data are always available for fraud detection, yet nearly half of hospitals (44 percent) reported that they can delete their audit logs. Although these hospitals reported that they limit the ability to delete the audit log to certain EHR users, such as system administrators, one EHR vendor noted that any software programmer could delete the audit log.

RTI recommends that the ability to disable the audit log be limited to certain individuals, such as system administrators, and that EHR users, such as doctors and nurses, be prevented from editing the contents of the audit log because these actions can compromise the audit log's effectiveness. Hospitals reported they have the ability to disable (33 percent) and edit (11 percent) their audit logs, although they reported restricting those abilities to certain EHR users, such as system administrators or EHR vendors. All four EHR vendors we spoke with reported that the audit logs cannot be disabled in their products, but one vendor again noted that a programmer could disable the audit log.

I further note that, being voluntarily provided, i.e., not part of a formal investigation of any specific organization, those numbers are likely low, perhaps very low considering this issue.

An audit log or audit trail is an automatically-generated dataset, invisible to most users, containing items such as who viewed records, the date/time/location of viewing, and indication of actions they may have performed on the records such as editing/changes/additions/deletions, etc.

As an EHR itself is a collection of magnetized or optically encoded bits on some computer storage medium, it cannot be authenticated as complete and free from alteration by humans.

The audit trail is the only way to authenticate an EHR printout, however (as well as EHR screenshots or any other electronic data turned into a tangible form from those bits) as complete and free from alteration.

If an EHR printout cannot be authenticated as complete and free from alteration, its trustworthiness and perhaps even court admissibility as a business record under an exception to the hearsay rules regarding evidence may be damaged or invalidated.

My concern is that, if true, and considering the conflict of interest a hospital has regarding hiding potential fraud or malpractice that could cost them millions of dollars, a capability to "delete the contents of their internal audit logs whenever they'd like" and to edit audit trails (which based on the capabilities of relational databases also implies an ability to delete sections of audit logs selectively and/or to substitute false data) is simply alarming.

I don't think the EHR pioneers intended EHRs to be used for purposes of allowing evidence spoliation without traceability ...

-- SS

Dec. 13, 2013 Addendum:

I received the following reply from EHR compliance expert Dr. Reed D. Gelzer.  Re-posted with permission:

Good morning Dr Silverstein,

Thank you yet again for the illumination that you bring to matters of truth in Healthcare Information Technology.

Regarding the OIG report’s source document, the 2007 report to the ONC, I was the Fraud Prevention Workgroup Chair for that project, working under Principal Investigators Dr. Don Simborg and Susan Hanson, former Chair of AHIMA. 

For anyone who is interested in this subject matter, I would recommend that you go to the source document and, among other things, review the list of contributors.  These were all individuals who volunteered time to attempt to mitigate harms of defective HIT, in their capacities of records management systems, nearly 8 years ago now.   Many have gone on into leadership roles in related organizations and domains, some still working towards trustworthy health information technology systems.

I believe that I can say that none of those working on the report then would have believed that it was conceivable that even our most basic recommendations regarding the fitness of audit functions would remain "novel" in the industry in 2013.  One cannot be surprised at the low level of authenticity supports in hospitals’ EHRs systems given that fitness as record management systems for patient care has, to date, been either neglected or presumed, not tested or attested.   I am gratified that our 2007 work was utilized for the OIG report to illuminate the deplorable state of integrity supports in these patient care information systems.  This will undoubtedly spur interest in supportive resources such as the HL7 EHR System Functional Model Standard and the HL7 Records Management and Evidentiary Support Profile Standard.

All of us who worked on that ONC report are, I hope, as gratified as I am that the OIG removed our work product from its designated obscurity.   We developed the guidelines via methods that were more qualitative than quantitative, entirely intended to guide initial implementation backed by more methodical research.   We represented the most informed at that time, including those like myself and my ADIC associate Patricia Trites who had performed compliance testing on over 30 among the leading EHRs at the time and found extraordinary ranges of deficiencies, including audit functions that could be disabled at will.   Standards and tools existed then to support mitigation of risks and those Standards and tools have expanded since.  Now that the events and ONC decisions that led to inactions on the report are now in the past, we can more rapidly achieve the potentials nascent in HIT by rendering it more trustworthy, usable, and safe.

Thank you again for your ongoing vigilance.

Sincerely,

Reed D. Gelzer, MD, MPH, CHCC
Trustworthy EHR, LLC
Co-Facilitator, HL7 Records Management and Evidentiary Support Workgroup

To this I add that I also would not have found it conceivable that my concerns about bad health IT and the risks of patient harm it poses, as well as common healthcare IT project mismanagement, of which I started writing about in 1998 (http://cci.drexel.edu/faculty/ssilverstein/cases/) would remain "novel" ideas in the industry in 2013.

The Obamacare healthcare exchange website debacle has made the latter issue mainstream.  The former issues still need more sunlight.

-- SS

Senin, 04 Maret 2013

Comments by Dr. Reed Gelzer on RAND Health IT Report and Op-Ed in Pittsburgh Post Gazette

A 2005 RAND Corporation report predicted that health IT could save the U.S. healthcare system $81 billion a year. Since then, however, annual health spending has increased by almost a trillion dollars, and quality and efficiency have not budged much, even with an increase in health IT adoption, according to researchers Arthur L. Kellerman and Spencer S. Jones in a Jan. 2013 RAND study published in Health AffairsKellermann is chair in policy analysis, and Spencer Jones is an information scientist..

A new Op-Ed by Kellerman and Jones entitled "IT in health care is MIA" appeared on Mar. 3, 2013 in the Pittsburgh Post-Gazette.

They wrote:

Because information technology has so quickly transformed people's daily lives, we tend to forget how much things have changed from the not-so-distant past. Today, millions of people around the world regularly shop online; download entire movies, books and other media onto wireless devices; bank at ATMs wherever they choose; and self-book travel while checking themselves in at airports electronically.

But there is one sector of our lives where adoption of information technology has lagged conspicuously: health care.

Some parts of the world are doing better than others in this respect. Researchers from the Commonwealth Fund recently reported that some high-income countries, including the United Kingdom, Australia and New Zealand, have made great strides in the use of electronic medical records among primary-care physicians. Indeed, in those countries, the practice is now nearly universal.

Yet some other high-income countries, such as the United States and Canada, are not keeping up.

Of course, the U.K. recently suffered a rather severe blow, on the order of 13 billion Pounds' worth, to its National Programme for Health IT in the NHS (NPfIT).  Australia is not exactly an "Emerald City" in terms of health IT, either, as can be seen from numerous links at the blog of Sydneysider Dr. David More, Australian Health Information Technology.

The RAND authors throw in some boilerplate grandiose predictions of certainty about health IT, which seems to have become a common phenomenon in newspapers and even scientific publications of late:

 ... The U.S. government is trying to help. In 2009, Congress passed the Health Information Technology for Economic and Clinical Health Act. HITECH has undeniably accelerated IT adoption, yet the problems of usability and interoperability persist.

... The sky is the limit when it comes to potential gains from health IT ... The payoff will be worth it. Indeed, as with the adoption of IT elsewhere, we may soon wonder how health care could have been delivered any other way.

Read the whole Op-Ed at the Gazette.

(My mother, an unwitting expert with significant experience on health IT adverse effects, is unavailable for comment, as she is dead due to a HIT-related accident.)

However, another expert is available:

Reed D. Gelzer, MD, MPH is an EHR/HIT systems and policy analyst for private and Federal agency clients, primarily in program integrity and clinical quality support.  In clinical practice for 11 years before transitioning into health IT, he also co-chairs the HL7 Records Management and Evidentiary Support (RMES) Workgroup.  He served US Navy Medicine’s Data Quality Office, various private insurers, as well as three years on CCHIT workgroups.  He was the Prevention Workgroup Chair for the 2007 ONC study on mitigation of EHR mediated waste fraud and abuse.

I find his opinions posted at the Gazette comment board of interest.  Some of the themes are very familiar. His comments are reproduced here with just a few comments of mine interjected:

Good afternoon Mr. Kellerman and Mr. Jones,

Thank you for the recitation of the arguments for HIT. I am particularly pleased that you note that a principle block to advancing HIT in the US is the fact that systems are not standardized.

One of the reasons many of our Industrialized Nation peers are far ahead of us is that they, in effect, standardized their systems by having one customer, a government entity operating health care. I assume you are not proposing that. If not then what, in the absence of regulation, will achieve your proper objective of standardizing HIT?

Well, we could simply let the market decide among the current non-standardized, non-regulated systems by accepting the accompanying burdens of cost, patient harms, and highly variable to unreliable data, and so on, in a nationwide experiment using the citizens of the U.S. as the test subjects [without informed consent or opt-out provisions, I might add - ed.] . A free market though would necessitate an absence of market-corrupting subsidies and transparency on comparing products, so that we can all equally hear when systems don't work as expected or cause problems for users, clinics, hospitals, and patients. No subsidies, no advantage to legacy vendors, and publicly available information about system problems, defects, and harms for a free market in HIT seems as unlikely as a single payer, government run system in the U.S., so what other options do we have?

We could say, we as a country want to improve this faulty and expensive industry, and so that is what we will hold providers responsible for. Doctors, hospitals, nurses, clinics, everybody -You have a duty to achieve better.  IT is a means, not the end. Purchase and apply the tools you decide you need to fix the problems you see. If you find you cannot do it, then close your doors and go to work for someone who can.

In support of this, as we do with drugs, we do not expect doctors, hospitals, nurses, clinics to independently research what is safe, what is usable in medications, in lab and imaging equipment and medical devices. We make sure that the tools available are safe, reliable, and do what they are intended to do. We do not de-regulate pharmaceuticals to speed innovation [due to the common claim by HIT hyper-enthusiasts that regulation would harm IT innovation, one might surmise they presumably would support pharma deregulation as well - ed.], we regulate minimum requirements of safety and efficacy so that such tools of medicine can be delivered to the bedside without the clinicians having to spend hours worrying about whether they're even fit for use.

Improving the safety, value, and effectiveness of patient care is not dependent on HIT.  Fit HIT is an indispensable enabler of KNOWING that we are doing our best and KNOWING where we are falling short and where improvements can best be directed.

Meanwhile, there can be no doubt that we will increasingly regulate HIT simply because it is the only way we can ever have non-anecdotal and systematic reporting on what HIT actually does (or doesn't do) for benefiting patients. Otherwise we will continue to be stuck where we are now: between a defective government policy that has bought the vision and promise (and there's a "no return" policy) without evidence, and the accumulating evidence of the difficulty, complexity, costs, and harms rendered by the current national experiment. [This evidence is often ignored or denied by the hyper-enthusiasts - ed.]

Again, thank you for reiterating the necessity of standardization. This should progressively elevate the attention to the vast library of HIT standards existent (and still evolving) that remain unused by vendors. Not just vendors, though. Standards also remain unused by doctors, nurses, hospitals, and clinics (and their organizational advocates) who still, amazingly do little, if any due diligence on the fitness of HIT to their use as patient care tools and records thereof.  [This is known as "negligence" and perhaps "gross negligence" - ed.]  Given that Meaningful Use has lowered the Certification bar so much lower than it was in 2009 and since subsidies have made it a Sellers market (and a race to avoid penalties) it is hard to imagine how the geometric progression of risk of non-standardized [systems] untested for safety, usability, or fitness will not assure pain and suffering of many kinds for years to come.

I look to you RAND to project your dynamic model for how Standardization will be achieved. In the meantime, of course this means that, among other things, they are not standardized for fitness in use for patient care.

RDGelzer, MD, MPH.

These are good thoughts.

I repeat my warnings that until sanity and caution is restored to the health IT sector (or started, as it may never have  existed) it is not likely that "we may soon wonder how health care could have been delivered any other way."

-- SS
 

ZOOM UNIK::UNIK DAN UNIK Copyright © 2012 Fast Loading -- Powered by Blogger