Skip to main content
Tag

HIMSS

Security vs. access: threading the needle

By healthcare industry, media commentary, politics, technology

The annual big-data party known as the HIMSS conference played out in Chicago – and online – last week. During the event, one of the central issues that arose in the social media conversation under the #HIMSS15 tag involved the one facing patients trying to access their health records, either digitally or on old-school paper: the security/access conundrum. Data that’s accessible to a patient could also wind up accessible to Romanian hackers (you’ve heard me on this topic before), and efforts at making patient data “secure” mean that data is often secure from the patient whose data it is. Patients give their forehead some serious keyboard every day over that one.

The folks over at Software Advice released a report on HIPAA breaches on March 12*, which I only caught up with when I returned from my Mighty Mouth 2015 Tour of Info-Sec and Right Care. Full disclosure, I’m quoted in the report, but that’s not why I’m talking about it here.

Here’s my biggest takeaway from the piece: 54% of the patients surveyed for the report would consider ditching a healthcare provider if that provider had a breach.

Most Patients Would Switch Providers After Breach

pie chart of likelihood of switching providers

 

Key findings in the report:

  1. Forty-five percent of patients are “moderately” or “very concerned” about a security breach involving their personal health information.
  2. Nearly one-quarter of patients (21 percent) withhold personal health information from their doctors due to data security concerns.
  3. Only 8 percent of patients “always” read doctors’ privacy and security policies before signing them, and just 10 percent are “very confident” they understand them.
  4. A majority of patients (54 percent) are “moderately” or “very likely” to change doctors as a result of a patient data breach.
  5. Patients are most likely to change doctors if their medical staff caused a data security breach, and least likely to change doctors if hackers were responsible.

Given the rising number of breach reports hitting headlines, including the massive one that impacted 80 million Anthem customers (possibly including me – not 100% confirmed yet) in January, this is not an issue that will go away. From the expert patient perspective, this is doubly frustrating, because the first thing that happens after a breach headline is the throttling of patient access to our records. Additional sign-on protocols, tighter credentialing, or a full-on “no more digital access” from smaller providers, all laid at the door of “because HIPAA.”

This doesn’t just affect access, it can have an impact on care. Here are the report’s stats on patients withholding information from their medical providers due to breach concerns:

Security Concerns Can Stifle Communication With Doctor

pie chart on patient withholding info

Quoting from the report:

“Health care lawyer and blogger David Harlow is also troubled by our results. Doctors need to get a full picture of a patient’s health history, he explains. If they don’t, the effectiveness of treatment could suffer—or worse, the patient could be harmed. For example, if a doctor is not told about a patient’s current prescriptions, the doctor could inadvertently prescribe a second medication that has adverse interactions with the first drug.

“That’s an invitation for disaster,” Harlow says. “It means we have a lot of work to do to convince people of the safety and importance of sharing information with physicians.”

My thinking on this topic can be summed up in the closing quote from the report, from yours truly:

Concerns over digital privacy and security have obscured the real conversation, which is, ‘How can we make health care more accessible, frictionless and safe with the data we collect about patients?’”

*Source: Practice Management systems consultancy Software Advice

Report from the front lines: Technology, engagement, and killing paternalism

By healthcare industry, politics, technology

I’ve spent a good portion of the last two months on the healthcare equivalent of the political stump – called the “rubber chicken circuit” in political circles. Thankfully, there was no actual rubber chicken served during these sojourns, although there was the incident of the seductive breakfast sausage, followed by my solo re-enactment (off stage) of the bridal salon scenes from the movie “Bridesmaids.” I will draw the veil of charity (and gratitude for travel expense coverage) over the details of that incident, and just advise all of you to stick to fruit, cereal, or bagels at conference breakfasts. ‘Nuff said.

My original editorial calendar plan was to turn this into a series of posts, broken down by focus into technology and clinical categories. However, since a big part of my goal in standing on the barricades at the gates of the healthcare castle, waving my digital pikestaff in service of system transformation, is breaking down silos … well, go grab a sandwich, and a beverage. This is gon’ be a long one.

HIMSS Patient Engagement Summit

In early February, I headed to Orlando for the first Health Information and Management Systems Society (HIMSS) Patient Engagement Summit. I was asked to participate in two panel discussions, one titled “Patient Perspectives: The State of Engagement,” the other “Can We Talk? The Evolving Physician-Patient Relationship.” Both were moderated by Dr. Patricia Salber, the bright mind behind The Doctor Weighs In.

Being a person with no letters after her name (like Elizabeth Holmes [update: she’s trash, so redacted] and Steve Jobs, I’m a college dropout), I’m used to showing up at healthcare industry events and being seen as something of a unicorn fairy princess. That’s how people commonly called “patients” are usually viewed in industry settings outside the actual point of care. Healthcare professionals/executives are so used to seeing us as revenue units, or data points, or out cold on a surgical table, but not as walking/talking/thinking humans, they can do a spit-take when meeting an official “patient” at an industry conference. Which is fun if they have a mouthful of coffee, but I haven’t seen anyone actually get sprayed yet.

All kidding aside, I really have to hand it to HIMSS for their uptake speed on seeing people/patients as valuable voices in the conversation about healthcare IT and quality improvement. In the time since they first noticed (in 2009, I believe) that people like ePatient Dave deBronkartRegina Holliday, and others might have something to add to the discussion, they’ve made a visible effort to include people/patient voices in their national programs. Of course, had they not invited patients to present at their Patient Engagement Summit, they would have been line for a public [digital] beating … and so there we were: Amy GleasonKym MartinAlicia Staley, and yours truly, ready to grab a mic and speak some truth.

A favorite tweet during the opening keynote by Dr. Kyra Bobinet, a friend of mine via our mutual membership in the Stanford MedX community:

I see patient engagement as healthcare that nourishes the people it serves, and also as a nutrient for the healthcare delivery system itself. Healthcare itself will get better, in its body (clinicians and all other folks who work inside the system) and in its spirit (its culture), with authentic connection – engagement – with the human community who seeks its help in maintaining or regaining good health.

Both panels went well, and the audience seemed to be both awake, and interested in what we had to say. For those of us who have been working the user – PATIENT – side of healthcare transformation, it’s frustrating that we’re still saying the same things to professional audiences that we’ve been saying for (in my case) close to 20 years now. But those of us on the patient side of this change management rodeo can sense a paradigm shift, and are starting to believe that we’re seeing transformation slowly deploy across the healthcare system. As the oft-repeated William Gibson quote goes, “The future is here, it’s just not evenly distributed.”

 

Patients ARE engaged. We’re working our butts off to get medical professionals and healthcare execs on the same page as us. Like the old story goes, when it comes to bacon and eggs, the chicken’s involved, but the pig’s fully committed. In the bacon-and-eggs of healthcare, patients are the bacon. We’re all in, and we know more, in many ways, about how to fix the system than the “professionals” do. Alicia Staley said, again, what she says consistently to healthcare audiences, “You need a Chief Patient Officer on your board.” So … get one. And we all need to be wary of blaring headlines, which can be very misleading when it comes to the real health risks we all face:

HIMSS Privacy + Security Forum

 

In early March, I winged my way out to San Diego, one of my several hometowns (growing up a Navy kid means you get more than one) for the HIMSS Privacy + Security Forum. I was a panelist for the last session of the conference, which I knew meant that many of the attendees would already be in the TSA screening line at Lindbergh Field, but I was going to share my thoughts with whomever stuck around, even if it was just the busboys. Our session was titled “What Matters Most: Patient Perspectives on Privacy & Security,” and what happened at the end of our panel was something I had hoped for – several of the folks who had stuck around come up to us and said, “that panel should have opened this conference!”

When it comes to IT security, the healthcare industry is rightly terrified, given the epic bitch-slap that a HIPAA fine can be ($1.5 million dollars per incident) – and the irony of the Anthem data breach affecting up to 8.8 million of their members making headlines the week before this conference was not lost on me … or any of the other folks at the HIMSS Forum meeting. Yet it’s critical to note that access, by patients and by clinicians, particularly at the point of care, to all the relevant data necessary to deliver the right care at the right time to the right patient, is still an undelivered promise across the health IT landscape. So don’t be Mordac, Dilbert’s Preventer of Information Services – we have enough of him. He’s like a freakin’ virus.

Hilariously, the day before I traveled to San Diego, I had to threaten a HIPAA complaint to get my records transferred from one provider to another. I had been asking for TWO MONTHS for the rads practice where I had gotten my mammograms 2009 through 2011 (twice a year in 2009 and 2010, given my Cancer Year of 2008) to send my scans and reports to my current mammography radiologist, and it took a voicemail with a HIPAA violation threat to get someone to call me back. My records are so damn secure that NO ONE can get them, except for “Robert in the basement” at [rhymes with … Bon Secours]. It felt like I was talking to Central Services in the Terry Gilliam movie “Brazil.” And people wonder why I have a QR code linked to my health history tattooed on my sternum …

 

Lown Institute RightCare conference

Speaking of right care/right time/right patient, two days after the HIMSS Privacy + Security Forum wrapped, the Lown Institute’s RightCare 2015 conference kicked off just down the street.

Dr. Bernard Lown is the cardiologist who invented the cardiac defibrillator in the 1960s, and who won the Nobel Peace Prize in 1985 for his part in creating the International Physicians for the Prevention of Nuclear War. The Lown Institute, founded to continue the work on healthcare and human rights that Dr. Lown has devoted his life to, states as its mission “We seek to catalyze a grassroots movement for transforming healthcare systems and improving the health of communities.”

In short, this event made me feel like I’d taken a trip in the Wayback Machine to my college days 1970-1973 in the Haight Ashbury in San Francisco … without the LSD, but with all the fire of my youth, mixed with the wealth of mature knowledge I’ve managed to velcro on to myself in the decades since. The real beauty part? There were lots of young people in the room, who are the age today that I was 40 years ago (in my early twenties), speaking up for the human rights of the people served by the healthcare system. The ones commonly called “patients.”

I got a chance at a scholarship to #Lown2015 after meeting Shannon Brownlee during our work on the Patient & Family Engagement Roadmap, and our attendance at Dartmouth’s SIIPC14 “informed patient choice” conference last year. She tipped me off that scholarships were available, I applied, and got lucky by snagging one. Doubly lucky, because it put me in the room while some of the leading voices on the clinical side of medicine called out the industry they work in for being slow to fully enfranchise the people they serve – patients – by being too driven by money, and not driven enough by their own humanity. A sampling:

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

And, because it just ain’t a movement unless this gets thrown down:

The bedrock message here? The democratization of knowledge that’s been delivered thanks to the Information Age has lifted the scales from the eyes of the early-adopter people/patients who are on to what healthcare is now, and what it must become to remain sustainable, or even relevant. Patients are coming up off their knees. The occupants of the ivory towers of medicine must descend from their aeries, or risk being flung from the parapets. Like winter …