Organized home health in India is an untapped potential. Home health care is defined as rendering predominantly medically-related services to patients in a home setting rather than in a medical facility. Home health care may include skilled nursing in addition to speech, occupational and physical therapy. It also includes monitoring the patient's prescriptions. In an Indian context, assistance to activities of daily living does not seem to make much sense.
What are the challenges in putting together a home health delivery model?
-> Organizing a fleet of nurses and therapists (Logistics)
-> Maintaining longitudinal patient progress and history
-> Minimize manual documentation requirements
-> Lack of ability to compare the acquired data with reference values
-> Open source software to capture data at patient site
-> Sync up PC data to the Hospital Information System or EMR
-> Connectivity to the Internet at the patient premises for self monitoring
-> Medical device to PC or cellular connection using USB, wire or Bluetooth
-> Data transmission via broadband, GSM, CDMA to Hospital Information System
Some considerations:
(1) Use of wireless Body Area Networks (BAN) as an alternative to conventional monitor - Example: The disposable unit consists of a ECG patch, analog amplification circuit, battery, and radio transmitter that sends signals to a Wireless Handheld Device either through USB or Bluetooth. The handheld will connect to the Mobile Healthcare Platform of the Hospital Information System.
(2) Use of tele-health monitors that capture data from multiple devices and transmit data to back-end servers via broadband.
With advent of 3G networks and low cost broadband services and WiFi, connectivity to the back end servers will be easier than before.
(3) Evaluation of Free Open Source Software (FOSS) for mobile platform and its counterpart back end enterprise application is a challenge.
Based on survey conducted by Center for Social Research India for Novo Nordisk in 2006 for diabetes monitoring, Home based monitoring was 86% less than monitoring at hospital and 89% of the patients are self funded. For a sustainable model for the service provider, more number of people need to adopt home monitoring. Longitudinal information capture and automatic alerting, self reliance, logistical ease are good value proposals for patients to switch.
Showing posts with label Information Technology. Show all posts
Showing posts with label Information Technology. Show all posts
Monday, November 29, 2010
Weaving IT into Organizational Strategy
Information technology has progressively moved from the periphery to the center of corporate strategy. This brief is not a prescription or an exhaustive recommendation but only brings to fore some of points to trigger in depth analysis on IT-Business alignment.
To build an effective foundation for execution, an organization has to pay attention to its operating model, enterprise architecture, and IT engagement model. Such a foundation calls for formulating an IT strategy that aligns with the business strategy, building internal partnerships between IT and business units, and reengineering of IT as a business partner. IT must enable, support, and drive organization growth. Creating or changing the information strategy impacts corporate strategic planning process, organizational structure and power equations, information systems responsibilities, and technology stack.
The first step to having an empowering IT agenda is to recognize the associated cost implications, complexity, and consequences. “Defensive IT” ensures operational reliability while “Offensive IT” helps organizations leapfrog the competition through clever use of emerging technologies and carries an element of risk. Each style has unique governance needs and must be lead by a skilled communicator who can challenge entrenched in-house thinking. An important point to keep in mind is that achieving and sustaining IT-business alignment is difficult and often treacherous.
Health sector in general has been lagging in adopting information technology for a variety of reasons like lack of demonstrated cost effectiveness, interoperability, high adoptions cost, and confidentiality requirements. Some of the challenges are unique to the health industry alone but many are common to industries at large and it may be worthwhile taking lessons from outside of this vertical.
Bringing information strategy into the boardroom makes the organization agile and equips it to respond quickly to a fast changing and evolving market. It brings together motivated experts, empowered decision makers and digitized process. A strategic execution officer or the CIO, under the umbrella of a “Center of Excellence for Innovation and Technology,” could evangelize the need for strategic information management, make IT investment decisions, transition management, and coordinate enterprise change projects.
To build an effective foundation for execution, an organization has to pay attention to its operating model, enterprise architecture, and IT engagement model. Such a foundation calls for formulating an IT strategy that aligns with the business strategy, building internal partnerships between IT and business units, and reengineering of IT as a business partner. IT must enable, support, and drive organization growth. Creating or changing the information strategy impacts corporate strategic planning process, organizational structure and power equations, information systems responsibilities, and technology stack.
The first step to having an empowering IT agenda is to recognize the associated cost implications, complexity, and consequences. “Defensive IT” ensures operational reliability while “Offensive IT” helps organizations leapfrog the competition through clever use of emerging technologies and carries an element of risk. Each style has unique governance needs and must be lead by a skilled communicator who can challenge entrenched in-house thinking. An important point to keep in mind is that achieving and sustaining IT-business alignment is difficult and often treacherous.
Health sector in general has been lagging in adopting information technology for a variety of reasons like lack of demonstrated cost effectiveness, interoperability, high adoptions cost, and confidentiality requirements. Some of the challenges are unique to the health industry alone but many are common to industries at large and it may be worthwhile taking lessons from outside of this vertical.
Bringing information strategy into the boardroom makes the organization agile and equips it to respond quickly to a fast changing and evolving market. It brings together motivated experts, empowered decision makers and digitized process. A strategic execution officer or the CIO, under the umbrella of a “Center of Excellence for Innovation and Technology,” could evangelize the need for strategic information management, make IT investment decisions, transition management, and coordinate enterprise change projects.
Labels:
Change,
Health,
Information Technology,
Strategy
Monday, November 8, 2010
Innovations in Healthcare Management and Innovations
IPQC has some great papers and presentations on the following:
Mobile Healthcare Delivery
e-Health in Asia Pacific
Defining and Testing EMR Usability
Click here to read them. All free IPQC Konwledge Center
Enjoy the read
Mobile Healthcare Delivery
e-Health in Asia Pacific
Defining and Testing EMR Usability
Click here to read them. All free IPQC Konwledge Center
Enjoy the read
Tuesday, February 2, 2010
Information standards in healthcare Part 2 (final)
Writing anything on information standards without the mention of HL7 will be quite meaningless.
HL7 (Health Level Seven) is a Standards Developing Organization accredited by ANSI. It has complied a collection of message formats and related clinical standards that loosely represents clinical information.
Key observation:
HL7 was initiated to speeden up data interface and exchange between computer application and systems within or connected to one healthcare enterprise; irrespective of architecture, programming language or platform. It is less far reaching that HIPAA which is targetted at transforming business and patient are processes.
HL7 is similar to EDI but developed ground up. HIPAA is derived from X12 standards.
Under HIPAA the addtional information to support a patient claim or encoutner must be in HL7 format. THe likely transaction used in HIPAA are 275, 277, 278, 835.
Refer to Corepoint health for more information.
THe most commonly used message types are
ACK – General acknowledgement
ADT – Admit discharge transfer
BAR – Add/change billing account
DFT – Detailed financial transaction
MDM – Medical document management
MFN – Master files notification
ORM – Order (Pharmacy/treatment)
ORU – Observation result (Unsolicited)
QRY – Query, original mode
RAS – Pharmacy/treatment administration
RDE – Pharmacy/treatment encoded order
RGV – Pharmacy/treatment give
SIU – Scheduling information unsolicited
Some videos on HL7 worth listening to:
HL7 & Healthcare Interfacing Videos | Corepoint Health
Posted using ShareThis
HL7 (Health Level Seven) is a Standards Developing Organization accredited by ANSI. It has complied a collection of message formats and related clinical standards that loosely represents clinical information.
Key observation:
HL7 was initiated to speeden up data interface and exchange between computer application and systems within or connected to one healthcare enterprise; irrespective of architecture, programming language or platform. It is less far reaching that HIPAA which is targetted at transforming business and patient are processes.
HL7 is similar to EDI but developed ground up. HIPAA is derived from X12 standards.
Under HIPAA the addtional information to support a patient claim or encoutner must be in HL7 format. THe likely transaction used in HIPAA are 275, 277, 278, 835.
Refer to Corepoint health for more information.
THe most commonly used message types are
ACK – General acknowledgement
ADT – Admit discharge transfer
BAR – Add/change billing account
DFT – Detailed financial transaction
MDM – Medical document management
MFN – Master files notification
ORM – Order (Pharmacy/treatment)
ORU – Observation result (Unsolicited)
QRY – Query, original mode
RAS – Pharmacy/treatment administration
RDE – Pharmacy/treatment encoded order
RGV – Pharmacy/treatment give
SIU – Scheduling information unsolicited
Some videos on HL7 worth listening to:
HL7 & Healthcare Interfacing Videos | Corepoint Health
Posted using ShareThis
Labels:
HIPAA,
HL7,
Information Technology,
Integration
Tuesday, January 19, 2010
Short Primer on HIT data
As i trudge along unlearning and relearning fundamentals in my class, i thought it might be a good idea to pen down some of it.
Some key terminologies
Data: Empirical observations, symbols, numbers. They simply exist with no structure. A "know nothing" stage
Information: Data organized with relationships. No necessarily useful but is the building block for eveything else.. A "know what" stage
Knowledge: Information that has a pattern and is useful. Enables decision making. A "know how" stage
Understanding: Allows use of the known based on principles and fosters new knowledge. A "know why" stage
The types of information in a typical healthcare setting are as follows:
Internal , External and Comparative
Internal information may relate to
Patient encounter (patient-specific or aggregate) & (clinical or administrative)
General Operations
Exernal information is knowledge based
Comparative information - Outcome measure (over a period of time or against standard)
Common categories of benchmarking are patient satisfaction, practice patterns, health plans, clinical indicators, population measures.
A few key standards to note
ICD-9-CM is also known as international classification of disease Clinical modification. It is used to determine diagnostic related group. Critical to accurate institutional reimbursement
CPT - Current procedural terminology. It is used to provide information on medical and surgical services.
CMS 1450 and CMS 1500 are 2 common billing standards
A health executive needs to be sure of the source of the information, its accuracy and semantics. Given multiple standards agencies and multiple forces acting upon the healthcare organization, it is important to have a common understanding of the terms. A good reference is the document embedded below. It is taken as from the hhs.gov website as a reference.
Some key takeaways from a definition standpoint are given below:
EMR - Electronic medical record - Maintain within organization boundaries and owned by the provider
EHR - Interoperable data maintained to be shared across organizations in conformance with national standards
PHR - Personal heatlh record - Individually owned and maintained
Health Information Exchange is the entity that will facilitate the EHR exchange nationally. They will work with Regional Extension Centers (Health Information Organization). HIOs will collaborate with Regional Health Information Organization which are collaborated network between providers in a specific geography.
Some key terminologies
Data: Empirical observations, symbols, numbers. They simply exist with no structure. A "know nothing" stage
Information: Data organized with relationships. No necessarily useful but is the building block for eveything else.. A "know what" stage
Knowledge: Information that has a pattern and is useful. Enables decision making. A "know how" stage
Understanding: Allows use of the known based on principles and fosters new knowledge. A "know why" stage
The types of information in a typical healthcare setting are as follows:
Internal , External and Comparative
Internal information may relate to
Patient encounter (patient-specific or aggregate) & (clinical or administrative)
General Operations
Exernal information is knowledge based
Comparative information - Outcome measure (over a period of time or against standard)
Common categories of benchmarking are patient satisfaction, practice patterns, health plans, clinical indicators, population measures.
A few key standards to note
ICD-9-CM is also known as international classification of disease Clinical modification. It is used to determine diagnostic related group. Critical to accurate institutional reimbursement
CPT - Current procedural terminology. It is used to provide information on medical and surgical services.
CMS 1450 and CMS 1500 are 2 common billing standards
A health executive needs to be sure of the source of the information, its accuracy and semantics. Given multiple standards agencies and multiple forces acting upon the healthcare organization, it is important to have a common understanding of the terms. A good reference is the document embedded below. It is taken as from the hhs.gov website as a reference.
Some key takeaways from a definition standpoint are given below:
EMR - Electronic medical record - Maintain within organization boundaries and owned by the provider
EHR - Interoperable data maintained to be shared across organizations in conformance with national standards
PHR - Personal heatlh record - Individually owned and maintained
Health Information Exchange is the entity that will facilitate the EHR exchange nationally. They will work with Regional Extension Centers (Health Information Organization). HIOs will collaborate with Regional Health Information Organization which are collaborated network between providers in a specific geography.
Wednesday, November 11, 2009
Information Management - Is it Lean?
BACKGROUND
Every organization relies on people, process and technology to carry out business. On a simplistic note, it would be fair to say the people execute the business functions(decision making) by using information made available to them through technology (information process). Organizations may be redefined as cooperative systems with high levels of information processing and decision making at different levels. Hence Information Management (IM) has emerged as an important branch of IT in the recent years.
INFORMATION MANAGEMENT
IM may be regarded as the creation, collection, distribution, storage and retiral of information such that it is made available to the consumer of the information in timely, contextually relevant and accurate form. According to the team that developed the behavioural science theory of management at the Carnegie Mellon University, the desicion making process is mostly sub optimal bounded by the rationality of the user. Considering socio technical aspects in an organization, it may be very expensive and time consuming to have all relevant information available for every decision made. In addition organization culture, rank and structure may prevent rational decision from prevailing. Master Data Management(MDM) is an important part of IM.
MASTER DATA MANAGEMENT
MDM is being recognized as an important activity for oganization wanting to manage their information effectively. All transactional data are tethered to organzation master data. Mostly enterprise system landscape contains a variety of packaged applications from different vendors which means localized master data with different formats and semantics. MDM is not about having a monolithic super database. It is about institutionalizing ownership of data using a software that allow synchronization, deduplication and harmonization of master data from and to different systems. For the sake of performance each packaged application is better off having a copy of the relevant attributes of master data locally. Master data has been traditionally looked at within the individual boundaries of a single application like financial or billing. But as processes begin to span across funcational/departmental lines, it is becomes necessary to have a consistent semantics and accuarate content enterprise wide. Absence of this regimen will lead to inherent inefficiencies. Typically the master data from an upstream application is not contextually relevant to a downsream one in neither semantics nor content and has to be recreated.
DEFINING VALUE - DIRECTIVE FOR LEAN
A lean enterprise is a collection of firms (business partners) involved in the delivery of a service using master and transactional data. It is possible to visualize information as an unit of value distributed intra and inter enterprise through the channels like intranet, extranet and the internet. Information value stream extends beyond the organization boundaries. Lean thinking encourages us to
1. Pull information on demand (Contextual)
2. Eliminate variability and waste in information content by having a golden source (Accuracy)
3. Improve speed of retrieval (Timely)
There is often some kind of a cognitive calculus done in the mind of stakeholder on the value of the information. As with typical Lean engagements the challenge is to establishd the value of information. The key stakeholders and senior management need to understand the value of master data and how it translates into competitive advantage and increased market share.
MDM and HEALTH DELIVERY
A proponent of free market would regard the patient as an unit of market share to be acquired or retained. The most important aspect of patient information is the Electronic Medical Record (EMR). Elements of EMR include master data like patient demographics and patient identifiable information (PII). Hospitals create enterprise master patient index to ensure golden record. It is not uncommon to have upto 30% duplication in patient information in a hospital.
How will the new health reform impact IM/MDM in health delivery.
1. It will be essential to retain and use golden copy of charge master to publish the cost of care.
2. Creation of global patient identifier for interhospital collaboration and exchange of information with the health exchange. The key here is to understand the value of information between different stakeholder groups.
Government - it would mean data for the evidence based research
Hospitals - it will be competitive information
Patient - it means access to medication and charts
Insurance company - it means financial payment.
There is a tremendous potential to get to know the technology needs in the health delivery and how it may be an inadvertent first step towards Lean.
Every organization relies on people, process and technology to carry out business. On a simplistic note, it would be fair to say the people execute the business functions(decision making) by using information made available to them through technology (information process). Organizations may be redefined as cooperative systems with high levels of information processing and decision making at different levels. Hence Information Management (IM) has emerged as an important branch of IT in the recent years.
INFORMATION MANAGEMENT
IM may be regarded as the creation, collection, distribution, storage and retiral of information such that it is made available to the consumer of the information in timely, contextually relevant and accurate form. According to the team that developed the behavioural science theory of management at the Carnegie Mellon University, the desicion making process is mostly sub optimal bounded by the rationality of the user. Considering socio technical aspects in an organization, it may be very expensive and time consuming to have all relevant information available for every decision made. In addition organization culture, rank and structure may prevent rational decision from prevailing. Master Data Management(MDM) is an important part of IM.
MASTER DATA MANAGEMENT
MDM is being recognized as an important activity for oganization wanting to manage their information effectively. All transactional data are tethered to organzation master data. Mostly enterprise system landscape contains a variety of packaged applications from different vendors which means localized master data with different formats and semantics. MDM is not about having a monolithic super database. It is about institutionalizing ownership of data using a software that allow synchronization, deduplication and harmonization of master data from and to different systems. For the sake of performance each packaged application is better off having a copy of the relevant attributes of master data locally. Master data has been traditionally looked at within the individual boundaries of a single application like financial or billing. But as processes begin to span across funcational/departmental lines, it is becomes necessary to have a consistent semantics and accuarate content enterprise wide. Absence of this regimen will lead to inherent inefficiencies. Typically the master data from an upstream application is not contextually relevant to a downsream one in neither semantics nor content and has to be recreated.
DEFINING VALUE - DIRECTIVE FOR LEAN
A lean enterprise is a collection of firms (business partners) involved in the delivery of a service using master and transactional data. It is possible to visualize information as an unit of value distributed intra and inter enterprise through the channels like intranet, extranet and the internet. Information value stream extends beyond the organization boundaries. Lean thinking encourages us to
1. Pull information on demand (Contextual)
2. Eliminate variability and waste in information content by having a golden source (Accuracy)
3. Improve speed of retrieval (Timely)
There is often some kind of a cognitive calculus done in the mind of stakeholder on the value of the information. As with typical Lean engagements the challenge is to establishd the value of information. The key stakeholders and senior management need to understand the value of master data and how it translates into competitive advantage and increased market share.
MDM and HEALTH DELIVERY
A proponent of free market would regard the patient as an unit of market share to be acquired or retained. The most important aspect of patient information is the Electronic Medical Record (EMR). Elements of EMR include master data like patient demographics and patient identifiable information (PII). Hospitals create enterprise master patient index to ensure golden record. It is not uncommon to have upto 30% duplication in patient information in a hospital.
How will the new health reform impact IM/MDM in health delivery.
1. It will be essential to retain and use golden copy of charge master to publish the cost of care.
2. Creation of global patient identifier for interhospital collaboration and exchange of information with the health exchange. The key here is to understand the value of information between different stakeholder groups.
Government - it would mean data for the evidence based research
Hospitals - it will be competitive information
Patient - it means access to medication and charts
Insurance company - it means financial payment.
There is a tremendous potential to get to know the technology needs in the health delivery and how it may be an inadvertent first step towards Lean.
HIPAA– Legal and Technological implications
Abstract: This paper covers fundamentals of the Health Insurance Portability and Accountability Act (HIPAA). Through case studies, it examines some of the practical aspects of administration and enforcement of HIPAA. It makes observations on how EHR (Electronic Health Record) and internet are posing new challenges to the healthcare community.
Keywords — PHI, EHR, HIPAA, Internet, Privacy, OCR, HHS, HITECH
I. EXECUTIVE SUMMARY
HIPAA is separated into two sections.
1. The first is called “Health Care Access, Portability, and Renewability”, It relates to two acts: the Employee Retirement Income Security Act and the Public Health Service Act. This part of the Act protects the insurance coverage of workers between jobs or periods of unemployment.
2. The second is called “Preventing Health Care Fraud and Abuse; Administrative Simplification,” It defines HIPAA offenses, sets penalties for HIPAA violations, HIPAA regulations, and creates programs to control fraud and abuse within the healthcare system. The scope of the paper is limited to this part of act.
A. HIPAA and EHR
EHR is a technology aid for automating (not replacing) activities in healthcare provisioning. It ensures better process control, reduces medication errors and provides controlled access to patient information (protected health information (PHI) and patient identifiable information (PII)) under HIPAA. However the very technology poses new risks like misuse of privileges, vulnerability of systems hacking (frail solutions), poor adoption among healthcare staff etc. This warrants organizations to train their staff and build awareness. This has been a challenge far bigger than what most would imagine.
In the next few years we will see rapid EHR rollouts as a result of the Health Information for Economic and Clinical Health Act (HITECH). This opportunity also presents new challenges to be addressed like stronger penalties, stringent enforcement and contractual ramifications for Business Associates.
B. HIPAA and Internet
Pervasive computing has touched almost all areas of our lives. It has altered the channels of communication and the speed at which information is exchanged. However this presents new challenges too. While internet facilitates instant communication, HIPAA has to do a fine balancing between freedom of communication and right to privacy. Some of points to note are below:
• With growing use of internet, social networking and third party PHI storekeepers, the risk of unwarranted PHI disclosure has increased. It is likely that Google and Microsoft will be liable under HIPAA if the provider community collaborates with them as its Business Associates.
• With changing social dynamics, it becomes meaningful to understand how the ownership of PHI has to be shared by both the patient and the provider. Some alternatives are explored in a search to seek answers for these questions.
The paper ends with a brief outline of enforcement statistics and the road ahead.
II. INTRODUCTION TO PRIVACY
The Privacy Protection Safety Commission states that privacy is a personal and fundamental right to the citizen protected by the US Constitution. Privacy violation results from information misuse arising from unauthorised collection and use of protected individual information. A victim of such a wrongdoing is likely to be impacted by one or more of the following:
• Vulnerability
• Emotionally distress
• Humiliation
• Loss of opportunities.
In an ongoing attempt to uphold privacy, a number of acts have been instituted. Some of them are below:
1. Privacy Act of 1974
2. Confidentiality of Alcohol and Drug Abuse Patient Records Regulations
3. Family Educational Rights and Privacy Act (FERPA)
4. Americans with Disabilities Act (ADA)
5. Genetic Information Nondiscrimination Act (GINA)
6. HIPAA
7. Patient Safety and Quality Improvement Act of 2005 (PSQIA).
III. PILLARS OF HIPAA
HIPAA shifts the responsibility of information privacy from the patients (through simple consent forms) to the covered entities. It addresses several major areas:
• Privacy – Prevent misuse of patient information by safeguards
• Security – Protect information during storage and provide authorised access to patient information.
• Master data – Unique identifiers for interacting entities in a healthcare setting
• Standardization - Industry standard information exchange to reduce manual effort and clerical error.
• Business associate contracts – Important in outsourced services.
IV. PENALTIES FOR HIPAA VIOLATION
1 Offender did not know, and by exercising reasonable diligence would not have known, that he or she violated the law(Ordinary negligence) $100 for each violation, except that the total amount imposed on the person for all such violations of an identical requirement or prohibition during a calendar year may not exceed $25,000
2 Violation was due to reasonable cause and not willful neglect(Ordinary Negligence) $1,000 for each violation not more than $100,000 cumulative
3 Violation was due to willful neglect and was corrected (Gross negligence) $10,000 for each violation not more than $250,000 cumulative.
4 Violation was due to willful neglect and was not corrected(Gross negligence) $50,000 for each violation and not more than $1,500,000 cumulative.
The Department of Justice (DOJ) says that criminal penalties for a violation of HIPAA are directly applicable to covered entities and even its employees (under “corporate criminal liability”). Where an individual of a covered entity is not directly liable under HIPAA, they can still be charged with conspiracy or aiding and abetting. In the HITECH Act HHS is provided with new audit authority to conduct periodic audits and ensure BAs and Covered Entities are compliant with new rules.
The DOJ interpreted the "knowingly" (wilfully) element of the HIPAA statute for criminal liability as requiring only knowledge of the actions that constitute an offense.
V. EXAMPLE - HIPAA VIOLATION –INFORMATION SECURITY
The case discussed below highlights the potential magnitude of the impact of a HIPAA violation.
A. Case
The Federal Trade Commission (FTC) opened its investigation into CVS Caremark following media reports from around the country that its retail pharmacies were disposing PHI into open, publicly accessible dumpsters. The PHI was contained on labels on pill containers. The information included patient names, addresses, physicians’ names, medication and dosages; consumers’ personal information, employment applications, social security numbers, payroll information; and credit card and insurance card information. Simultaneously HHS opened its investigation into the pharmacies’ disposal of health information protected by HIPAA.
CSV was charged with violations for the following
• Lack of sound processes and policies to ensure HIPAA compliance
• Lack of employee training for dealing with PHI
• Lack of internal measures to assess and assure compliance with its policies and procedures for disposing of personal information
• Misleading and superfluous privacy policy statement.
CVS paid HHS $2.25 million to settle the matter.
Discussion: Is CVS a covered entity? Yes it is. Under 1861(s) of the Act, 42 U.S.C. 1395x(s), CVS (Retail Pharmacy chain) provides medical supplies and biological that may not be self administered and that are furnished as an incident to the physician’s professional service. So HIPAA applies to it.
What is the nature of information that CVS failed to handle with reasonable? The FTC press release states that there was sensitive information pertaining to patients and its own employees. It is important to note that patient health information as well as employee medical information falls under HIPAA. CVS compromised PHI and PII.
Where did CVS fail? CVS violated the following tenets under HIPAA even though no discernable harm had been reported
• Security.
• Privacy.
CVS response has included a settlement amount higher than any other payout on HIPAA violation so far.
CVS Caremark made claims such as “CVS/pharmacy wants you to know that nothing is more central to our operations than maintaining the privacy of your health information.” The FTC alleged that the claim was deceptive and that CVS Caremark’s security practices also were unfair. Unfair and deceptive practices violate the FTC Act. Subsequently CVS entered into a consent order with the FTC to resolve claims made by the latter. As a part of the Corporate Integrity Program, CVS agreed to institute a Corrective Action Plan (CAP). It requires CVS, in the next three years, to create processes for
• Correct disposal of PHI
• Institutionalize a training program
• Have a third party audit to certify the effectiveness of the CAP.
A similar example is found in the case against Providence Health and Services in June, 2008.
What is missing? Some of the missing facts that could have given us a better insight into the magnitude of violation are
1. Total number of records compromised
2. Number of locations where the breach took place
3. Number of medical or financial identity thefts following the time span from when the violation has been happening.
VI. EXAMPLE – LACK OF AWARENESS
As the concerns of HIPAA become pervasive, covered entities are reluctant to share information in a healthcare setting. This has been observed to hamper care in such situations. The case below illustrates this point.
B. Case
An emergency department requested the transfer of a 40-year-old homeless man with a history of schizophrenia and psychotropic dependence to a local hospital for undergoing inpatient treatment. In his psychotic state, the patient was unable to sign for the release of his records. The psychiatrist on call requested the emergency room (ER) to send across the test results and relevant records via fax for review before a decision could be made about transfer. The ER nurse refused to fax the records, stating that doing so would violate HIPAA. Furthermore, the nurse reported that even signed consent to fax the records would not protect her against a HIPAA violation. After the transfer was refused, the records were faxed with the patient's name blacked out.
Discussion: This is a case where the health worker was misinformed about HIPAA law. The Act does not forbid transfer of necessary and pertinent medical information to aid the treatment of the patient. Effective training program for healthcare workers is critical to the success of HIPAA.
VII. EXAMPLE - HIPAA AND INTERNET
With rapid adoption of unconventional communication channels, there is a need to re-assess the applicability of HIPAA laws. A few scenarios are presented below with observations.
A. Case: Patient participates in indiscriminate information sharing
Scenario One: The patient uses the hospital communication network (assuming it is made available) to share PHI to friends. Although the disclosure is by the patient but since the communication has happened over the hospital network which is under HIPAA rules, the hospital could be held liable.
Scenario Two: The patient communicates PHI using public internet and posts it on social networking sites. It is expected that patient will be discrete about his PHI. Should PHI be guarded under HIPAA only as long as the patient is not found being indiscrete, similar to the client-attorney privilege?
Scenario Three: The patient maintains PHI with a third party and not a covered medical entity. (For example Google Health). The privacy is guarded solely on the basis of authorised consent given by the individual to the third party and a declaration by the third party to be discrete with PHI. The PHI in this case is not protected by HIPAA regulations. Internet has always been an unsecured channel for storing and transmitting confidential information. Can HIPAA be extended to cover the third parties as well?
Scenario Four: Posting surgery updates on Twitter. There have been cases when the hospital surgeons have used Twitter to post surgery updates. It is likely that the patient would be discovered if the operation was a one of its kind or if it involved a novel procedure. How can we discourage such practices?
Scenario Five: YouTube advertising. In an attempt to avail lost cost marketing channels, the hospitals are seeking consent from patients to post their surgery on YouTube. It is possible that after the advertisement was posted, the patient develops a complication and suffers at the hands of the providers. Yet the advertisement continues to be featured in the YouTube without any mention of the post surgery complication. This leaves the patient traumatized. Even though the law may offer remedy, most patients are easily intimidated by idea of a legal recourse against their doctors, not to mention the time and money needed to go up against establishments.
VIII. ELECTRONIC HEALTH RECORD AND HIPAA
EHR solution is defined as a system of collecting, using, storing, disseminating and destroying PHI.
The challenges of implementing EHR are few but critical:
1. Adoption of technology by healthcare community. Physicians often find it difficult to work with technological limitations. All EHR rollouts need a strong technology change management to ensure speedy adoption. Health workers are notorious for their tendencies to skirt the process.
2. Under pressure to cut costs, HIPAA compliance may be compromised by undercutting features or robustness. This is particularly true when the solution is based on off the shelf products.
3. While EHR helps reduce human error, it makes HIPAA violations easier to commit. This is accentuated by the lack of organizational commitment to train and create awareness.
HIPAA safeguards in the EHR include the following:
1. Seamless integration to the billing system for transmitting EDI (Electronic Data Interchange) messages between payer and the payee.
2. Maintaining secure communication when employing outsourced talent with emphasis on business associate agreements
3. Instituting role based privileges for data access.
4. Proper budget to train and create awareness on HIPAA to avoid attacks through social engineering and breaches due to unauthorized information sharing. It is said that most unauthorized system access are through social engineering, an act of manipulating people into performing actions or divulging confidential information. This is an important point in a highly computerized environment.
5. Having routine and event based audits
6. Having a security officer to oversee HIPAA compliance and putting checks and balances for physical safeguard and back up of storage spaces for PHI.
7. Having technical safeguards for secure information exchange using encryption protocols and data corroboration
8. Implement privacy policies and risk management programs.
HIPAA violations today seldom remain limited to a violation of privacy. It is usually followed with either an identity theft or false claim or both. The case discussed below examines how HIPAA violations are easily committed with EHR solution in place and how it leads to felony. One critical point to note here is that the medical is owned by the covered entity
A. Case: Violation and Criminal Law
Without authorization or approval from United HealthCare, two of its employees gained access to the company’s electronic database and obtained names and dates of birth of certain patients. The patients had Flexible Spending Accounts and were covered by a prescription drug plan sponsored by the Federal Employees Health Benefit Plan (“FEHBP”). The employees used this information to create fake and unauthorized prescriptions. These were then presented to pharmacies to illegally obtain controlled substances. The drugs were then illegally sold to third parties. The defendants caused a loss of $72,746 to the Federal government by making false claims.
Discussion: In this case the defendants were guilty of HIPAA violation because they acquired the patient information and shared it with others who participated in their plan. Typically it would have been a civil case.
However defendants were guilty of identity theft which is a felony and the criminal law differs from one state to another. In the state of Texas, Fraudulent Use or Possession of Identifying Information is a felony whose degree varies based on the number of records stolen.
In addition, the defendants used the information to defraud the federal government by making false claims for reimbursement. Under False Claims Act this amounts to a felony. The defendants got a 10 year prison sentence and 250,000 in penalty.
IX. SOME MORE HIPAA
This section touches upon other areas where HIPAA has an impact.
• Under HIPAA, peer review documents are typically not discoverable. Unless there is a court issued subpoena, the hospital is not required to share the peer review documentation publicly. Peer review is a platform for physicians to discuss negligence and near negligence incidents without inhibition to ensure that patient safety standards and quality of care is consistently maintained.
• Medical records are owned by the covered entity although the patients have the right to suggest corrections to its contents. Providers may be free to use the information for treatment, operation and payment without any consent from the patient.
X. HIPAA AND HITECH ACT 2009
The HITECH Act has put in following checks and balances with respect to HIPAA. The section below mentions the notable areas impacted.
• Notifications in the event of confidentiality breach
• Business Associate liability
• Disclosures of PHI limited to the “Limited Data Set” or “Minimum Necessary”
• Expanded accountability for individuals
• Sale of EHR or PHI
• Limited use of PHI for marketing purposes and fund raising
• Expanded enforcement measures for HIPAA violations
• HIPAA compliance audits
• Business associate liability – The HITECH Act makes significant changes to the HIPAA laws and rules, many of which will impact relationships between covered entities and their business associates
• HITECH will require BAs to comply with administrative, technical and physical safeguard requirements
• BAs are also required to appoint a security official, develop written policies and procedures, and train its workforce on how to protect electronic protected health information (EPHI)
• BAs will now be directly liable under HIPAA for using and disclosing PHI in violation of their BA agreements
• A violation of the BA agreement will subject the BA to the same civil and criminal penalties as a Covered Entity who violates the Privacy Rule
In case of a breach of HIPAA guidelines, the following have been recommended under HITECH
• Perform a “Risk Assessment”
• Do an impact assessment resulting from the breach. This includes extent of misuse and tracking the parties involved in it. Type and amount of PHI involved -can it reasonably cause financial, reputational or other harm?
• Implement Risk Mitigation procedure
• The Covered Entity or BA has the burden of proof in demonstrating that no breach has occurred.
• Strong documentation of the risk assessment vital.
• Individual notification by first class mail required (unless individual has consented to electronic notice). Substitute notice is required if contact info is out of date. For 10 or more, notification must be either posted on website for 90 days or posted in major print/broadcast media for 90 days. Media and HHS notification required for breach involving 500 or more residents of a state or jurisdiction. For cases involving smaller number of breached records, log files must be maintained on an annual basis.
XI. SUMMARY STATISTICS OF HIPAA ENFORCEMENT
The Department of Health and Human Services (HHS) is under the executive branch of the US constitution charged with protecting the health of all Americans and providing essential human services, especially for those who are least able to help themselves. The OCR (Office of Civil Rights) is the primary agency under HHS to receive complaints on HIPAA violations and act upon them. Of the 45,630 complaints received so far, about 80% of the cases have been resolved. During the course of investigation, it has been discovered that almost 50% of the reported cases were not eligible to be tried under HIPAA. This statistics reflects two things
1. There may be gap in how the Act is interpreted. A good number of people do not understand the nuances of HIPAA in statement or spirit
2. There may be a gap in the jurisdiction of the law itself that needs to be addressed in the future.
The top reasons for HIPAA violations have been cited as
1. Unsecured PHI
2. Unauthorized access
3. Inappropriate and impermissible disclosures
4. Unauthorized disclosures
5. Lack of patient access to their PHI
6. Uses or disclosures of more than the minimum necessary protected health information
XII. HIPAA - DOWNSIDE
Restricted access to patient data has its drawbacks.
1. HIPAA has and will continue to have an impact on research as PHI becomes increasingly difficult to acquire. Consent forms have become longer ever since the regulations came into effect. Studies have shown that there is a decline in the participation rate in clinical trials and human research.
2. HIPAA compliance cost money. With static or diminishing healthcare budgets, there is a threat that HIPAA spending could be compensated by a compromise in the quality of care.
XIII. FUTURE – BENEFITS AND ROAD AHEAD
Benefits of HIPAA cannot be over-emphasized. The key ones are:
1. Allows patient information to be securely sent from one provider to another in a seamless and secure way. This will be more effectively felt when the percentage of providers on EHR solution increase.
2. By guarding patient privacy it protects patients from being victims of criminal wrong doings.
3. Patients are very vulnerable when they are in the hands of the providers. HIPAA safeguards ensure that information shared during patient-provider encounters are kept confidential
Its future depends on some best practices and legislations; some of which are mentioned below:
1. Effective training and awareness programs for members of the healthcare community.
2. Recognize that HIPAA is a not a one-time activity. It is part of corporate governance objective.
REFERENCES
[1] David Blumenthal, M.D., M.P.P. Stimulating the Adoption of Health Information Technology [Online] Available: http://healthcarereform.nejm.org/?p=436 , 2009.
[2] Consumer Union Report., To Err is Human - To Delay is Deadly: [Online] Available: http://www.consumersunion.org/pub/core_health_care/011324.html 2009.
[3] HHS Press Release, [Online] Available: http://www.hhs.gov/news/press/2009pres/08/20090819f.html, Aug. 2009.
[4] World Privacy Forum, [Online] Available, http://www.worldprivacyforum.org/hipaa/HipaaGuide3.html.
[5] Center for Democracy and Technology, HIPAA and Health Privacy: Myths and Facts Part 2 — January 2009 [Online] Available: http://www.cdt.org/healthprivacy/20090109mythsfacts.pdf
[6] Augustine Weekly - Holland & Knight HIPAA in Private Tort Litigation [Online] Available: http://www.informlegal.com/articles/view.php?article_id=519, 2008
[7] Press Release, CVS Caremark Settles FTC Charges: [Online] Available 2009. http://www.ftc.gov/opa/2009/02/cvs.shtm
[8] Biometrics Direct, Penalties for HIPAA violation [Online] Available: http://www.biometricsdirect.com/Biometrics/laws/HIPAA/hipaaviolations.htm
[9] American Medical Association, HIPAA Violation and Enforcement [Online] Available: http://www.ama-assn.org/ama/pub/physician-resources/solutions-managing-your-practice/coding-billing-insurance/hipaahealth-insurance-portability-accountability-act/hipaa-violations-enforcement.shtml.
[10] Bryan K. Touchet, M.D., Stephanie R. Drummond, D.O. and William R. Yates, M.D, Brief Report, The Impact of Fear on HIPAA violation on Patient Care [Online] Available: http://psychservices.psychiatryonline.org/cgi/content/full/55/5/575A.
[11] Internet Article, HIPAA Law and Guidelines for Employers, [Online] Available: http://www.hrhero.com/topics/hipaa.html
[12] Internet Article CVS Pays $2.25 Million in Record HIPAA Settlement [Online] Available: http://www.huntonprivacyblog.com/2009/02/articles/hipaa-1/cvs-pays-225-million-in-record-hipaa-settlement/
[13] Comments by World Privacy Forum, [Online] Available: http://www.ftc.gov/os/comments/cvscaremark/540386-00004.pdf
[14] Privacy Rights Clearing House, Chronology of Data Breaches [Online] Available: http://www.privacyrights.org/ar/ChronDataBreaches.htm
[15] Internet Article [Online] Available: http://www.law.uh.edu/healthlaw/perspectives/2008/(NA)%20blog.pdf
[16] OCR website. [Online] Available: http://www.hhs.gov/ocr/privacy/hipaa/enforcement/highlights/numbersataglanceindex.html
[17] U.S. Department of Labor Employee Benefits
Security Administration [Online] Available: http://www.dol.gov/ebsa/publications/top15tips.html
[18] Google Definition [Online] Available: http://www.google.com/search?hl=en&rlz=1R2ADBF_enIN335&defl=en&q=define:Social+engineering+&ei=QfSqSo62B4KntgeEpKDzBw&sa=X&oi=glossary_definition&ct=title
[19] Healthcare Applications and HIPAA [Online] Available: http://citebm.business.uiuc.edu/TWC%20Class/Project_reports_Spring2007/HIPAA/mtmcinto/McIntosh.pdf
Keywords — PHI, EHR, HIPAA, Internet, Privacy, OCR, HHS, HITECH
I. EXECUTIVE SUMMARY
HIPAA is separated into two sections.
1. The first is called “Health Care Access, Portability, and Renewability”, It relates to two acts: the Employee Retirement Income Security Act and the Public Health Service Act. This part of the Act protects the insurance coverage of workers between jobs or periods of unemployment.
2. The second is called “Preventing Health Care Fraud and Abuse; Administrative Simplification,” It defines HIPAA offenses, sets penalties for HIPAA violations, HIPAA regulations, and creates programs to control fraud and abuse within the healthcare system. The scope of the paper is limited to this part of act.
A. HIPAA and EHR
EHR is a technology aid for automating (not replacing) activities in healthcare provisioning. It ensures better process control, reduces medication errors and provides controlled access to patient information (protected health information (PHI) and patient identifiable information (PII)) under HIPAA. However the very technology poses new risks like misuse of privileges, vulnerability of systems hacking (frail solutions), poor adoption among healthcare staff etc. This warrants organizations to train their staff and build awareness. This has been a challenge far bigger than what most would imagine.
In the next few years we will see rapid EHR rollouts as a result of the Health Information for Economic and Clinical Health Act (HITECH). This opportunity also presents new challenges to be addressed like stronger penalties, stringent enforcement and contractual ramifications for Business Associates.
B. HIPAA and Internet
Pervasive computing has touched almost all areas of our lives. It has altered the channels of communication and the speed at which information is exchanged. However this presents new challenges too. While internet facilitates instant communication, HIPAA has to do a fine balancing between freedom of communication and right to privacy. Some of points to note are below:
• With growing use of internet, social networking and third party PHI storekeepers, the risk of unwarranted PHI disclosure has increased. It is likely that Google and Microsoft will be liable under HIPAA if the provider community collaborates with them as its Business Associates.
• With changing social dynamics, it becomes meaningful to understand how the ownership of PHI has to be shared by both the patient and the provider. Some alternatives are explored in a search to seek answers for these questions.
The paper ends with a brief outline of enforcement statistics and the road ahead.
II. INTRODUCTION TO PRIVACY
The Privacy Protection Safety Commission states that privacy is a personal and fundamental right to the citizen protected by the US Constitution. Privacy violation results from information misuse arising from unauthorised collection and use of protected individual information. A victim of such a wrongdoing is likely to be impacted by one or more of the following:
• Vulnerability
• Emotionally distress
• Humiliation
• Loss of opportunities.
In an ongoing attempt to uphold privacy, a number of acts have been instituted. Some of them are below:
1. Privacy Act of 1974
2. Confidentiality of Alcohol and Drug Abuse Patient Records Regulations
3. Family Educational Rights and Privacy Act (FERPA)
4. Americans with Disabilities Act (ADA)
5. Genetic Information Nondiscrimination Act (GINA)
6. HIPAA
7. Patient Safety and Quality Improvement Act of 2005 (PSQIA).
III. PILLARS OF HIPAA
HIPAA shifts the responsibility of information privacy from the patients (through simple consent forms) to the covered entities. It addresses several major areas:
• Privacy – Prevent misuse of patient information by safeguards
• Security – Protect information during storage and provide authorised access to patient information.
• Master data – Unique identifiers for interacting entities in a healthcare setting
• Standardization - Industry standard information exchange to reduce manual effort and clerical error.
• Business associate contracts – Important in outsourced services.
IV. PENALTIES FOR HIPAA VIOLATION
1 Offender did not know, and by exercising reasonable diligence would not have known, that he or she violated the law(Ordinary negligence) $100 for each violation, except that the total amount imposed on the person for all such violations of an identical requirement or prohibition during a calendar year may not exceed $25,000
2 Violation was due to reasonable cause and not willful neglect(Ordinary Negligence) $1,000 for each violation not more than $100,000 cumulative
3 Violation was due to willful neglect and was corrected (Gross negligence) $10,000 for each violation not more than $250,000 cumulative.
4 Violation was due to willful neglect and was not corrected(Gross negligence) $50,000 for each violation and not more than $1,500,000 cumulative.
The Department of Justice (DOJ) says that criminal penalties for a violation of HIPAA are directly applicable to covered entities and even its employees (under “corporate criminal liability”). Where an individual of a covered entity is not directly liable under HIPAA, they can still be charged with conspiracy or aiding and abetting. In the HITECH Act HHS is provided with new audit authority to conduct periodic audits and ensure BAs and Covered Entities are compliant with new rules.
The DOJ interpreted the "knowingly" (wilfully) element of the HIPAA statute for criminal liability as requiring only knowledge of the actions that constitute an offense.
V. EXAMPLE - HIPAA VIOLATION –INFORMATION SECURITY
The case discussed below highlights the potential magnitude of the impact of a HIPAA violation.
A. Case
The Federal Trade Commission (FTC) opened its investigation into CVS Caremark following media reports from around the country that its retail pharmacies were disposing PHI into open, publicly accessible dumpsters. The PHI was contained on labels on pill containers. The information included patient names, addresses, physicians’ names, medication and dosages; consumers’ personal information, employment applications, social security numbers, payroll information; and credit card and insurance card information. Simultaneously HHS opened its investigation into the pharmacies’ disposal of health information protected by HIPAA.
CSV was charged with violations for the following
• Lack of sound processes and policies to ensure HIPAA compliance
• Lack of employee training for dealing with PHI
• Lack of internal measures to assess and assure compliance with its policies and procedures for disposing of personal information
• Misleading and superfluous privacy policy statement.
CVS paid HHS $2.25 million to settle the matter.
Discussion: Is CVS a covered entity? Yes it is. Under 1861(s) of the Act, 42 U.S.C. 1395x(s), CVS (Retail Pharmacy chain) provides medical supplies and biological that may not be self administered and that are furnished as an incident to the physician’s professional service. So HIPAA applies to it.
What is the nature of information that CVS failed to handle with reasonable? The FTC press release states that there was sensitive information pertaining to patients and its own employees. It is important to note that patient health information as well as employee medical information falls under HIPAA. CVS compromised PHI and PII.
Where did CVS fail? CVS violated the following tenets under HIPAA even though no discernable harm had been reported
• Security.
• Privacy.
CVS response has included a settlement amount higher than any other payout on HIPAA violation so far.
CVS Caremark made claims such as “CVS/pharmacy wants you to know that nothing is more central to our operations than maintaining the privacy of your health information.” The FTC alleged that the claim was deceptive and that CVS Caremark’s security practices also were unfair. Unfair and deceptive practices violate the FTC Act. Subsequently CVS entered into a consent order with the FTC to resolve claims made by the latter. As a part of the Corporate Integrity Program, CVS agreed to institute a Corrective Action Plan (CAP). It requires CVS, in the next three years, to create processes for
• Correct disposal of PHI
• Institutionalize a training program
• Have a third party audit to certify the effectiveness of the CAP.
A similar example is found in the case against Providence Health and Services in June, 2008.
What is missing? Some of the missing facts that could have given us a better insight into the magnitude of violation are
1. Total number of records compromised
2. Number of locations where the breach took place
3. Number of medical or financial identity thefts following the time span from when the violation has been happening.
VI. EXAMPLE – LACK OF AWARENESS
As the concerns of HIPAA become pervasive, covered entities are reluctant to share information in a healthcare setting. This has been observed to hamper care in such situations. The case below illustrates this point.
B. Case
An emergency department requested the transfer of a 40-year-old homeless man with a history of schizophrenia and psychotropic dependence to a local hospital for undergoing inpatient treatment. In his psychotic state, the patient was unable to sign for the release of his records. The psychiatrist on call requested the emergency room (ER) to send across the test results and relevant records via fax for review before a decision could be made about transfer. The ER nurse refused to fax the records, stating that doing so would violate HIPAA. Furthermore, the nurse reported that even signed consent to fax the records would not protect her against a HIPAA violation. After the transfer was refused, the records were faxed with the patient's name blacked out.
Discussion: This is a case where the health worker was misinformed about HIPAA law. The Act does not forbid transfer of necessary and pertinent medical information to aid the treatment of the patient. Effective training program for healthcare workers is critical to the success of HIPAA.
VII. EXAMPLE - HIPAA AND INTERNET
With rapid adoption of unconventional communication channels, there is a need to re-assess the applicability of HIPAA laws. A few scenarios are presented below with observations.
A. Case: Patient participates in indiscriminate information sharing
Scenario One: The patient uses the hospital communication network (assuming it is made available) to share PHI to friends. Although the disclosure is by the patient but since the communication has happened over the hospital network which is under HIPAA rules, the hospital could be held liable.
Scenario Two: The patient communicates PHI using public internet and posts it on social networking sites. It is expected that patient will be discrete about his PHI. Should PHI be guarded under HIPAA only as long as the patient is not found being indiscrete, similar to the client-attorney privilege?
Scenario Three: The patient maintains PHI with a third party and not a covered medical entity. (For example Google Health). The privacy is guarded solely on the basis of authorised consent given by the individual to the third party and a declaration by the third party to be discrete with PHI. The PHI in this case is not protected by HIPAA regulations. Internet has always been an unsecured channel for storing and transmitting confidential information. Can HIPAA be extended to cover the third parties as well?
Scenario Four: Posting surgery updates on Twitter. There have been cases when the hospital surgeons have used Twitter to post surgery updates. It is likely that the patient would be discovered if the operation was a one of its kind or if it involved a novel procedure. How can we discourage such practices?
Scenario Five: YouTube advertising. In an attempt to avail lost cost marketing channels, the hospitals are seeking consent from patients to post their surgery on YouTube. It is possible that after the advertisement was posted, the patient develops a complication and suffers at the hands of the providers. Yet the advertisement continues to be featured in the YouTube without any mention of the post surgery complication. This leaves the patient traumatized. Even though the law may offer remedy, most patients are easily intimidated by idea of a legal recourse against their doctors, not to mention the time and money needed to go up against establishments.
VIII. ELECTRONIC HEALTH RECORD AND HIPAA
EHR solution is defined as a system of collecting, using, storing, disseminating and destroying PHI.
The challenges of implementing EHR are few but critical:
1. Adoption of technology by healthcare community. Physicians often find it difficult to work with technological limitations. All EHR rollouts need a strong technology change management to ensure speedy adoption. Health workers are notorious for their tendencies to skirt the process.
2. Under pressure to cut costs, HIPAA compliance may be compromised by undercutting features or robustness. This is particularly true when the solution is based on off the shelf products.
3. While EHR helps reduce human error, it makes HIPAA violations easier to commit. This is accentuated by the lack of organizational commitment to train and create awareness.
HIPAA safeguards in the EHR include the following:
1. Seamless integration to the billing system for transmitting EDI (Electronic Data Interchange) messages between payer and the payee.
2. Maintaining secure communication when employing outsourced talent with emphasis on business associate agreements
3. Instituting role based privileges for data access.
4. Proper budget to train and create awareness on HIPAA to avoid attacks through social engineering and breaches due to unauthorized information sharing. It is said that most unauthorized system access are through social engineering, an act of manipulating people into performing actions or divulging confidential information. This is an important point in a highly computerized environment.
5. Having routine and event based audits
6. Having a security officer to oversee HIPAA compliance and putting checks and balances for physical safeguard and back up of storage spaces for PHI.
7. Having technical safeguards for secure information exchange using encryption protocols and data corroboration
8. Implement privacy policies and risk management programs.
HIPAA violations today seldom remain limited to a violation of privacy. It is usually followed with either an identity theft or false claim or both. The case discussed below examines how HIPAA violations are easily committed with EHR solution in place and how it leads to felony. One critical point to note here is that the medical is owned by the covered entity
A. Case: Violation and Criminal Law
Without authorization or approval from United HealthCare, two of its employees gained access to the company’s electronic database and obtained names and dates of birth of certain patients. The patients had Flexible Spending Accounts and were covered by a prescription drug plan sponsored by the Federal Employees Health Benefit Plan (“FEHBP”). The employees used this information to create fake and unauthorized prescriptions. These were then presented to pharmacies to illegally obtain controlled substances. The drugs were then illegally sold to third parties. The defendants caused a loss of $72,746 to the Federal government by making false claims.
Discussion: In this case the defendants were guilty of HIPAA violation because they acquired the patient information and shared it with others who participated in their plan. Typically it would have been a civil case.
However defendants were guilty of identity theft which is a felony and the criminal law differs from one state to another. In the state of Texas, Fraudulent Use or Possession of Identifying Information is a felony whose degree varies based on the number of records stolen.
In addition, the defendants used the information to defraud the federal government by making false claims for reimbursement. Under False Claims Act this amounts to a felony. The defendants got a 10 year prison sentence and 250,000 in penalty.
IX. SOME MORE HIPAA
This section touches upon other areas where HIPAA has an impact.
• Under HIPAA, peer review documents are typically not discoverable. Unless there is a court issued subpoena, the hospital is not required to share the peer review documentation publicly. Peer review is a platform for physicians to discuss negligence and near negligence incidents without inhibition to ensure that patient safety standards and quality of care is consistently maintained.
• Medical records are owned by the covered entity although the patients have the right to suggest corrections to its contents. Providers may be free to use the information for treatment, operation and payment without any consent from the patient.
X. HIPAA AND HITECH ACT 2009
The HITECH Act has put in following checks and balances with respect to HIPAA. The section below mentions the notable areas impacted.
• Notifications in the event of confidentiality breach
• Business Associate liability
• Disclosures of PHI limited to the “Limited Data Set” or “Minimum Necessary”
• Expanded accountability for individuals
• Sale of EHR or PHI
• Limited use of PHI for marketing purposes and fund raising
• Expanded enforcement measures for HIPAA violations
• HIPAA compliance audits
• Business associate liability – The HITECH Act makes significant changes to the HIPAA laws and rules, many of which will impact relationships between covered entities and their business associates
• HITECH will require BAs to comply with administrative, technical and physical safeguard requirements
• BAs are also required to appoint a security official, develop written policies and procedures, and train its workforce on how to protect electronic protected health information (EPHI)
• BAs will now be directly liable under HIPAA for using and disclosing PHI in violation of their BA agreements
• A violation of the BA agreement will subject the BA to the same civil and criminal penalties as a Covered Entity who violates the Privacy Rule
In case of a breach of HIPAA guidelines, the following have been recommended under HITECH
• Perform a “Risk Assessment”
• Do an impact assessment resulting from the breach. This includes extent of misuse and tracking the parties involved in it. Type and amount of PHI involved -can it reasonably cause financial, reputational or other harm?
• Implement Risk Mitigation procedure
• The Covered Entity or BA has the burden of proof in demonstrating that no breach has occurred.
• Strong documentation of the risk assessment vital.
• Individual notification by first class mail required (unless individual has consented to electronic notice). Substitute notice is required if contact info is out of date. For 10 or more, notification must be either posted on website for 90 days or posted in major print/broadcast media for 90 days. Media and HHS notification required for breach involving 500 or more residents of a state or jurisdiction. For cases involving smaller number of breached records, log files must be maintained on an annual basis.
XI. SUMMARY STATISTICS OF HIPAA ENFORCEMENT
The Department of Health and Human Services (HHS) is under the executive branch of the US constitution charged with protecting the health of all Americans and providing essential human services, especially for those who are least able to help themselves. The OCR (Office of Civil Rights) is the primary agency under HHS to receive complaints on HIPAA violations and act upon them. Of the 45,630 complaints received so far, about 80% of the cases have been resolved. During the course of investigation, it has been discovered that almost 50% of the reported cases were not eligible to be tried under HIPAA. This statistics reflects two things
1. There may be gap in how the Act is interpreted. A good number of people do not understand the nuances of HIPAA in statement or spirit
2. There may be a gap in the jurisdiction of the law itself that needs to be addressed in the future.
The top reasons for HIPAA violations have been cited as
1. Unsecured PHI
2. Unauthorized access
3. Inappropriate and impermissible disclosures
4. Unauthorized disclosures
5. Lack of patient access to their PHI
6. Uses or disclosures of more than the minimum necessary protected health information
XII. HIPAA - DOWNSIDE
Restricted access to patient data has its drawbacks.
1. HIPAA has and will continue to have an impact on research as PHI becomes increasingly difficult to acquire. Consent forms have become longer ever since the regulations came into effect. Studies have shown that there is a decline in the participation rate in clinical trials and human research.
2. HIPAA compliance cost money. With static or diminishing healthcare budgets, there is a threat that HIPAA spending could be compensated by a compromise in the quality of care.
XIII. FUTURE – BENEFITS AND ROAD AHEAD
Benefits of HIPAA cannot be over-emphasized. The key ones are:
1. Allows patient information to be securely sent from one provider to another in a seamless and secure way. This will be more effectively felt when the percentage of providers on EHR solution increase.
2. By guarding patient privacy it protects patients from being victims of criminal wrong doings.
3. Patients are very vulnerable when they are in the hands of the providers. HIPAA safeguards ensure that information shared during patient-provider encounters are kept confidential
Its future depends on some best practices and legislations; some of which are mentioned below:
1. Effective training and awareness programs for members of the healthcare community.
2. Recognize that HIPAA is a not a one-time activity. It is part of corporate governance objective.
REFERENCES
[1] David Blumenthal, M.D., M.P.P. Stimulating the Adoption of Health Information Technology [Online] Available: http://healthcarereform.nejm.org/?p=436 , 2009.
[2] Consumer Union Report., To Err is Human - To Delay is Deadly: [Online] Available: http://www.consumersunion.org/pub/core_health_care/011324.html 2009.
[3] HHS Press Release, [Online] Available: http://www.hhs.gov/news/press/2009pres/08/20090819f.html, Aug. 2009.
[4] World Privacy Forum, [Online] Available, http://www.worldprivacyforum.org/hipaa/HipaaGuide3.html.
[5] Center for Democracy and Technology, HIPAA and Health Privacy: Myths and Facts Part 2 — January 2009 [Online] Available: http://www.cdt.org/healthprivacy/20090109mythsfacts.pdf
[6] Augustine Weekly - Holland & Knight HIPAA in Private Tort Litigation [Online] Available: http://www.informlegal.com/articles/view.php?article_id=519, 2008
[7] Press Release, CVS Caremark Settles FTC Charges: [Online] Available 2009. http://www.ftc.gov/opa/2009/02/cvs.shtm
[8] Biometrics Direct, Penalties for HIPAA violation [Online] Available: http://www.biometricsdirect.com/Biometrics/laws/HIPAA/hipaaviolations.htm
[9] American Medical Association, HIPAA Violation and Enforcement [Online] Available: http://www.ama-assn.org/ama/pub/physician-resources/solutions-managing-your-practice/coding-billing-insurance/hipaahealth-insurance-portability-accountability-act/hipaa-violations-enforcement.shtml.
[10] Bryan K. Touchet, M.D., Stephanie R. Drummond, D.O. and William R. Yates, M.D, Brief Report, The Impact of Fear on HIPAA violation on Patient Care [Online] Available: http://psychservices.psychiatryonline.org/cgi/content/full/55/5/575A.
[11] Internet Article, HIPAA Law and Guidelines for Employers, [Online] Available: http://www.hrhero.com/topics/hipaa.html
[12] Internet Article CVS Pays $2.25 Million in Record HIPAA Settlement [Online] Available: http://www.huntonprivacyblog.com/2009/02/articles/hipaa-1/cvs-pays-225-million-in-record-hipaa-settlement/
[13] Comments by World Privacy Forum, [Online] Available: http://www.ftc.gov/os/comments/cvscaremark/540386-00004.pdf
[14] Privacy Rights Clearing House, Chronology of Data Breaches [Online] Available: http://www.privacyrights.org/ar/ChronDataBreaches.htm
[15] Internet Article [Online] Available: http://www.law.uh.edu/healthlaw/perspectives/2008/(NA)%20blog.pdf
[16] OCR website. [Online] Available: http://www.hhs.gov/ocr/privacy/hipaa/enforcement/highlights/numbersataglanceindex.html
[17] U.S. Department of Labor Employee Benefits
Security Administration [Online] Available: http://www.dol.gov/ebsa/publications/top15tips.html
[18] Google Definition [Online] Available: http://www.google.com/search?hl=en&rlz=1R2ADBF_enIN335&defl=en&q=define:Social+engineering+&ei=QfSqSo62B4KntgeEpKDzBw&sa=X&oi=glossary_definition&ct=title
[19] Healthcare Applications and HIPAA [Online] Available: http://citebm.business.uiuc.edu/TWC%20Class/Project_reports_Spring2007/HIPAA/mtmcinto/McIntosh.pdf
Labels:
Health Quality,
Health Regulation,
HIPAA,
HITECH,
Information Technology
Thursday, October 1, 2009
Health IT spending in India
The article is from expresscomputeronline.com... good read
http://www.expresscomputeronline.com/20090907/expressintelligententerprise05.shtml
Vertical Focus
Focus On: Healthcare
N Geetha examines the business challenges faced by CIOs in the healthcare vertical and looks at how technology is being used as an enabler.
Escalating growth immunities
Arpan Gupta Principal Analyst, IDC
Thanks to various government stimulus packages in the offing, the healthcare vertical is poised for growth. Arpan Gupta, principal analyst, IDC India stated that the turnover of this industry vertical was Rs 150,000 crores and that it was expected to grow at a CAGR of 20% over the next five years. Urban areas are showing a growth curve, while the rural sector is yet to show momentum in the healthcare sector. However, derivative industries such as healthcare insurance, healthcare services and equipment manufacturing companies are growing strongly.
A report from Technopak Advisors, an independent research body, found that healthcare which was a $35 billion industry in India, was expected to reach over $75 billion by 2012 and $150 billion by 2017. Confederation of Indian Industry found that with this sector growing in a linear fashion and that the demand for hospitals and beds was on the rise. Investments to the tune of $50 billion are expected to be made annually for the next 20 years. The stimulus package by the government as part of its National Rural Health Mission program, which allocated $2.42 billion in its recent interim budget, should drive the healthcare industry in a positive direction.
Another indication from a recent study done by FICCI along with Ernst & Young spotted various opportunity areas for investors in the healthcare sector including medical infrastructure, which would call for an investment of $77.9 billion and medical equipment that is projected to reach $4.97 billion by 2012. Clinical trials are on track to become a $1 billion industry by 2010 while the health services outsourcing sector was expected to grow to $7.4 billion by 2012. Healthcare vertical CIOs are aligning their strategy with the growth of their industry and organization. For instance, Suresh Shenoy, CIO of Wockhardt finds aspects such as economic upward mobility, overall structured healthcare awareness, healthcare insurance penetration, growth in population in general and patients from overseas etc., fuelling growth. "Wockhardt Hospitals witnessed an overall growth of 25% during fiscal 2008-09 and we have set a target of 25% for 2009-10," pointed out Shenoy.
Focus on: Healthcare
Top business challenge: Constrained budgets, growing demand for healthcare facilities, disparate IT solutions, lack of skilled labor and the need for quick turnaround time in order to offer better care to patients
Solution: Focus on advanced IT tools, increase workflow efficiency and improve resource management
How it can help: Healthcare Information Systems (HIS), Clinical research trials tools, EMR, PACS, telemedicine, collaborative tools are some of the IT solutions that are available for this sector
Manish Gupta, CIO of the Rs 100 crore Health Care Global Enterprises Ltd. (HCG), the cancer care provider, viewed healthcare's growth as having a fixed component, which was recession and disease proof and a variable part that depended upon doctors, population, disease breakouts, lifestyles etc.
According to Gupta, the factors that were propelling this sector's growth included individual awareness, collective decisions on healthcare, government push, micro-insurance schemes, public private partnerships etc.
Dr. R S TyagiDeputy Director & Head - Computer Facility, AIIMS
HCG clocked 25% organic growth during fiscal 2008-09 and it has a 40-50% revenue growth target with at least 30% growth in margins targeted for 2009-10. The encouraging factor that Dr R S Tyagi, deputy director & head computer facility of All India Institute of Medical Sciences observed that it was the government's drive towards making existing hospitals into super specialty units, which would result in the extensive use of IT infrastructure.
As for growth, Dr Tyagi maintained that the hospital had been provided with additional land and financial resources to open a second campus on 350 acres of land.
Srikanth Raman, CIO of the Bangalore-based Narayana Hrudayalaya expected explosive growth for hospitals with more facilities coming up in Kolkata and Jamshedpur. "Currently we have a 500 bed accommodation in Bangalore and have a target of going up to 30,000 beds soon," said Raman. Ricky Bedi, CEO of Bangalore-based Teleradtech, the technology arm of Teleradiology Solutions, found that the industry was growing at 15% and that there was an upward movement that would result in hyper-growth of almost 200% within a couple of years.
CIOs opined that it was time to pull up their sleeves in making IT the critical component of the anticipated growth. So far, IT has not made sufficient inroads in this vertical because of the conservative nature of the industry.
Under pressure
Suresh Shenoy CIO, Wockhardt
While CIOs across industry verticals are challenged over how to align technology with growth, CIOs in the healthcare sector face the challenge of convincing the top management that technology can be an enabler for driving business. The adoption of advanced IT tools has been minimal in this sector barring a few top medical institutions. Cost is obviously the deterrent here.
Bedi observed, "My greatest business challenge is to bring down the cost of, and optimize the quality of, care. The end goal is customer satisfaction irrespective of what impact my workflow automation creates."
"How do I evolve the best integrated model for better patient information using any technology, that is the challenge," he added.
The crucial challenge for Narayana Hrudayalaya's Raman was the question of putting in place an effective communication process about the ethos of quality care within an organization.
"Given the various applications that run in isolation, the challenge is to have a central infrastructure, and to have a real time information flow," said Raman.
It would be strange to find that, across the healthcare institutions, IT is not looked upon as a catalyst for growth. If an investment is proposed for some IT deployment, the management looks at opting for fresh medical equipment rather than IT.
IDC's Gupta found that CIOs in this industry vertical were burdened with increased overheads, the imperative to ensure quick turnaround time for treatments and constrained about going beyond the basics of IT.
Wockhardt's Suresh Shenoy felt that there was great pressure owing to the slowdown.
"Growth-related pressure is on two accounts, one is that the existing IT infrastructure needs to give a better RoI against major limitations and the second is the need to invest in additional IT systems. Balancing the two is difficult," maintained Shenoy.
The critical business challenge for Shenoy was to capture every small cost at the point of delivery given the complex cost structure with lots of shared services. Shenoy found that activity-based costing such as evaluating which product or service offering isn't easy to do.
While Dr. R S Tyagi did not see growth as a challenge with more funds coming into the fold, selecting a stable solution provider to work on consistent basis streamlining the entire IT infrastructure remained his biggest challenge.
HCG's Manish Gupta's key challenge is always whether the patient or the payer (insurance, government, or employer) is willing to spend for early detection, preventive care, and new technology.
Gupta's other challenge internally was to ensure quick turnaround time in the hospitals. From a technology point of view, he opined that most institutions found sourcing care protocols-based software, mobile phone-based care delivery and tele-health care etc. to be a tough task.
Despite the challenges and priority constraints, CIOs have managed to add the required IT services into their portfolio to drive demand.
IT in Vogue
Ricky Bedi CEO, Teleradtech
Bangalore's Teleradtech has seamlessly integrated radiology with IT to providing consultancy services to hospitals, diagnostic centers, customizing, deploying, maintaining and supporting the PACS (picture archiving and communication systems) and RIS (Research Information Systems) solutions.
Bedi has deployed medical information systems, health information systems and an in-house developed instant messaging system while ensuring that redundancy is built in.
"It was imperative to ensure that the technology improve the workflow within the organization," maintained Bedi. Bedi went in Smartris.Net, a Web-hosted RIS platform with integrated PACS and billing system on a unified database, supporting a RIS-driven workflow.
While facing the integration-related challenges with no standardized process, Bedi is focused on creating a platform with collaborative tools such as unified communication to integrated and enable the active use of EMR and Lab management systems by its clients. By deploying these applications, Bedi ensured that the productivity of radiologists improved, enabled single system access for patients, reduction in resource consumption and overheads for managing the workflow, besides easy maintenance and quick turnaround on implementation changes owing to the configurability of system.
While there have been few accounts of IT deployments at Narayana Hrudayalaya, Raman said that applications such as HIS and ERP were used to scale up operations. While retaining the IT team was a challenge, most of it had been developed in-house.
The biggest implementation had been with regard to HIS software sourced from a Mumbai-based company and Raman had deployed Tally as a backend for accounting purposes. The hospital's IT spend would be less than 1% of its total revenues this fiscal. It has tied up with 250 units as part of its telemedicine initiative to provide quick care to the patients.
According to Dr Tyagi, AIIMS planned to allocate Rs 20 crores towards IT for 2009-10. So far, the major expenditure had been on security, networking and infrastructure. The institution has an internal LAN that hooked up 1,500 odd systems within the campus and IT is used for basic e-mailing. For its other premises, it is connected through a 42 Mbps WAN from ERNET.
Dr Tyagi and his 20-member team's priority has been to computerize the hospital. The applications currently being used at AIIMS include library information, patient registration, diagnostic information, billing, accounting, publishing of literature and other departmental systems.
"We have been using security gateway solutions from Cyberoam as well as Microsoft and Novell operating systems," remarked Dr Tyagi.
AIIMS has been using telemedicine and more than 300 locations are connected to 500 experts.
The Oncology specialist, HCG's Manish Gupta, did not take IT spend on desktops, servers, security and applications, which were anyway mandatory, into consideration. "Our spend covers medical equipment interfaces, custom developed hospital system, disease treatment protocol software, video conferencing, tele-radiology, medical image archival, IP based alerts/alarm instruments, unified communications, and of course the "backend" financial/inventory systems."
Gupta maintains that part of building automation and mobile phone-based spend is also managed by IT and technologies related to embedded systems, RFID and nano-technology is generating interest in healthcare IT.
Gupta argues, the IT spend is highly variable, but a minimum of 1% of revenue is spent and a lot depends on the size of hospitals and interconnectivity needs that, in turn, depends on the level of interaction between physicians.
EMR has helped the doctors and the management effectively. A lot of spending has gone towards clinical research and trials and HCG has deployed business intelligence to capture accurate data for analytical reports. Gupta said that the key business were deploying software related to care protocols, mobile applications, tele-health including teleradiology, tele-diagnostics and tele-medicine.
"HIS is the basic need for all the healthcare has been developed in-house," said Gupta.
Given the economic slowdown, Wockhardt's Suresh Shenoy witnessed pressures on spending as every penny spent needed justification. 2008-09 saw spending towards telemedicine, PACS, RFID, CRM and integration of medical devices and equipment to deploy a central HIS at Wockhardt.
Shenoy and his team focused on deploying Wipro HIS ERP, developed on Microsoft SQL Server to cater to the complete business process at each hospital addressing various functionalities like delivery of care, labs, pharmacy, blood bank services, IP and OP billing, procurement, movement and consumption of materials. "There are about 30 modules, all of them tightly integrated online."
According to Shenoy, while HIS is locally installed at each hospital site, its financial summary in terms of payments, receivables, and GL is captured globally through Oracle Financial ERP as HIS is integrated with this to create a dashboard.
From an infrastructure point of view, Shenoy has gone for a high-end server with cluster management and fault tolerant WAN connectivity, connecting all of the hospitals over a MPLS VPN that is part of Wockhardt's global network.
The other areas of deployment at Wockhardt included centralized Internet access security enforcement, biometric physical access control and integration with the attendance system, while Lotus Notes messaging was in vogue. For each reach, Shenoy opted for digital wireless telephony at hospitals.
Shenoy saw the benefits of integrating disparate systems, medical equipment resulting in labor effort savings and increased accuracy and better delivery of care to customers.
2008-09 has been slow for most CIOs amidst stringent spending criteria, the current fiscal seems to be an exciting time.
IT Outlook
2009-10 could turn out to be a great deployment year for most CIOs in this sector. "Peer to peer collaboration is critical to address the demands effectively," said Bedi.
According to him, video conferencing, VoIP and the use of medical transcription were key to address business needs.
The key agenda that Raman would carry out would be to identify waste areas where costs could be trimmed using IT as a tool.
"My aspiration is to evolve a system where I can communicate to customers about our specialty offerings and services in an effective way with the use of IT," maintained Raman. "Since our growth plans are big, we would invest on IT, and the immediate need is to create a dashboard for providing real-time information using varied applications," he added.
Raman and his team are evaluating the possibility of outsourcing and deploying varied applications to suit their needs.
Dr Tyagi's agenda is to go in for a outsourcing model with a consultant suggesting varied applications and driving technological innovation at AIIMS.
"As we are getting ISO 21000 certification, it is mandatory to get the best security systems and applications which can increase our operational efficiency," remarked Dr Tyagi.
Gupta's thrust would be to deploy technologies that help the institution in the early detection of patient problems.
'I aspire to streamline operational processes in healthcare providers that are often ignored and unlike other industries, technology can build new business or customer base in hospitals," averred Gupta.
Gupta is keen to drive mobile technologies for his care providers (doctors, nurses, and I would even include patient's families) who are always short on time.
Mobile diagnostics is the focus area for HCG, besides Gupta aiming at building a model around imaging software integrated with SAP modules. "We would go in for varied modules from SAP and tweak it to our needs," said Gupta.
With some relaxation in IT spending during this fiscal, Wockhardt's Shenoy intends to align IT strategies with business strategies in a more efficient manner to make IT the major driver and a profit center.
While agreeing that IT penetration in the healthcare sector has been minimal restricting to basics, IDC's Arpan Gupta finds that the IT spend during 2008-09 had been to the tune of Rs 700 crores, which is likely to increase in this fiscal.
The popular solutions deployed include integrated billing systems, PACS, SOA to a certain and virtualization with a focus on telemedicine.
Cashing in on trends
As a technology trend, IDC's Gupta found that the evolution of subsidiary industries such as healthcare insurance, medical tourism, outsourcing and consulting services as the demand for healthcare is growing.
Besides this, from the IT infrastructure and applications point of view, Gupta found growth in networking, peripheral industry, software services and e-prescription applications and so on as the need for IT was growing amongst healthcare institutions.
Raman was keen on outsourcing and he expected health care insurance providers to drive the growth for IT as it involved effective communication.
Gupta expected that technologies related to teleradiology would be aspired for as there was a growing demand for this expertise, but there was a shortage of this community.
Dr Tyagi saw the deployment of storage and server consolidation on the rise with more data coming into the fold.
From a growth perspective, Wockhardt's Shenoy bet upon telemedicine, PACS, Integrations of Medical Equipment, ABCM (Activity based Cost Management) solutions which would be predominantly deployed across healthcare institutions.
With the Union Health Ministry mooting a proposal to set up a series of 'Medical Parks' all over the country to enable domestic health industry to manufacture health equipment at large scale, growth is assured. Besides, to encourage indigenous manufacturing, special economic zones have been initiated to make the industry competitive and regulate the market.
geetha.nandikotkur@expressindia.com
http://www.expresscomputeronline.com/20090907/expressintelligententerprise05.shtml
Vertical Focus
Focus On: Healthcare
N Geetha examines the business challenges faced by CIOs in the healthcare vertical and looks at how technology is being used as an enabler.
Escalating growth immunities
Arpan Gupta Principal Analyst, IDC
Thanks to various government stimulus packages in the offing, the healthcare vertical is poised for growth. Arpan Gupta, principal analyst, IDC India stated that the turnover of this industry vertical was Rs 150,000 crores and that it was expected to grow at a CAGR of 20% over the next five years. Urban areas are showing a growth curve, while the rural sector is yet to show momentum in the healthcare sector. However, derivative industries such as healthcare insurance, healthcare services and equipment manufacturing companies are growing strongly.
A report from Technopak Advisors, an independent research body, found that healthcare which was a $35 billion industry in India, was expected to reach over $75 billion by 2012 and $150 billion by 2017. Confederation of Indian Industry found that with this sector growing in a linear fashion and that the demand for hospitals and beds was on the rise. Investments to the tune of $50 billion are expected to be made annually for the next 20 years. The stimulus package by the government as part of its National Rural Health Mission program, which allocated $2.42 billion in its recent interim budget, should drive the healthcare industry in a positive direction.
Another indication from a recent study done by FICCI along with Ernst & Young spotted various opportunity areas for investors in the healthcare sector including medical infrastructure, which would call for an investment of $77.9 billion and medical equipment that is projected to reach $4.97 billion by 2012. Clinical trials are on track to become a $1 billion industry by 2010 while the health services outsourcing sector was expected to grow to $7.4 billion by 2012. Healthcare vertical CIOs are aligning their strategy with the growth of their industry and organization. For instance, Suresh Shenoy, CIO of Wockhardt finds aspects such as economic upward mobility, overall structured healthcare awareness, healthcare insurance penetration, growth in population in general and patients from overseas etc., fuelling growth. "Wockhardt Hospitals witnessed an overall growth of 25% during fiscal 2008-09 and we have set a target of 25% for 2009-10," pointed out Shenoy.
Focus on: Healthcare
Top business challenge: Constrained budgets, growing demand for healthcare facilities, disparate IT solutions, lack of skilled labor and the need for quick turnaround time in order to offer better care to patients
Solution: Focus on advanced IT tools, increase workflow efficiency and improve resource management
How it can help: Healthcare Information Systems (HIS), Clinical research trials tools, EMR, PACS, telemedicine, collaborative tools are some of the IT solutions that are available for this sector
Manish Gupta, CIO of the Rs 100 crore Health Care Global Enterprises Ltd. (HCG), the cancer care provider, viewed healthcare's growth as having a fixed component, which was recession and disease proof and a variable part that depended upon doctors, population, disease breakouts, lifestyles etc.
According to Gupta, the factors that were propelling this sector's growth included individual awareness, collective decisions on healthcare, government push, micro-insurance schemes, public private partnerships etc.
Dr. R S TyagiDeputy Director & Head - Computer Facility, AIIMS
HCG clocked 25% organic growth during fiscal 2008-09 and it has a 40-50% revenue growth target with at least 30% growth in margins targeted for 2009-10. The encouraging factor that Dr R S Tyagi, deputy director & head computer facility of All India Institute of Medical Sciences observed that it was the government's drive towards making existing hospitals into super specialty units, which would result in the extensive use of IT infrastructure.
As for growth, Dr Tyagi maintained that the hospital had been provided with additional land and financial resources to open a second campus on 350 acres of land.
Srikanth Raman, CIO of the Bangalore-based Narayana Hrudayalaya expected explosive growth for hospitals with more facilities coming up in Kolkata and Jamshedpur. "Currently we have a 500 bed accommodation in Bangalore and have a target of going up to 30,000 beds soon," said Raman. Ricky Bedi, CEO of Bangalore-based Teleradtech, the technology arm of Teleradiology Solutions, found that the industry was growing at 15% and that there was an upward movement that would result in hyper-growth of almost 200% within a couple of years.
CIOs opined that it was time to pull up their sleeves in making IT the critical component of the anticipated growth. So far, IT has not made sufficient inroads in this vertical because of the conservative nature of the industry.
Under pressure
Suresh Shenoy CIO, Wockhardt
While CIOs across industry verticals are challenged over how to align technology with growth, CIOs in the healthcare sector face the challenge of convincing the top management that technology can be an enabler for driving business. The adoption of advanced IT tools has been minimal in this sector barring a few top medical institutions. Cost is obviously the deterrent here.
Bedi observed, "My greatest business challenge is to bring down the cost of, and optimize the quality of, care. The end goal is customer satisfaction irrespective of what impact my workflow automation creates."
"How do I evolve the best integrated model for better patient information using any technology, that is the challenge," he added.
The crucial challenge for Narayana Hrudayalaya's Raman was the question of putting in place an effective communication process about the ethos of quality care within an organization.
"Given the various applications that run in isolation, the challenge is to have a central infrastructure, and to have a real time information flow," said Raman.
It would be strange to find that, across the healthcare institutions, IT is not looked upon as a catalyst for growth. If an investment is proposed for some IT deployment, the management looks at opting for fresh medical equipment rather than IT.
IDC's Gupta found that CIOs in this industry vertical were burdened with increased overheads, the imperative to ensure quick turnaround time for treatments and constrained about going beyond the basics of IT.
Wockhardt's Suresh Shenoy felt that there was great pressure owing to the slowdown.
"Growth-related pressure is on two accounts, one is that the existing IT infrastructure needs to give a better RoI against major limitations and the second is the need to invest in additional IT systems. Balancing the two is difficult," maintained Shenoy.
The critical business challenge for Shenoy was to capture every small cost at the point of delivery given the complex cost structure with lots of shared services. Shenoy found that activity-based costing such as evaluating which product or service offering isn't easy to do.
While Dr. R S Tyagi did not see growth as a challenge with more funds coming into the fold, selecting a stable solution provider to work on consistent basis streamlining the entire IT infrastructure remained his biggest challenge.
HCG's Manish Gupta's key challenge is always whether the patient or the payer (insurance, government, or employer) is willing to spend for early detection, preventive care, and new technology.
Gupta's other challenge internally was to ensure quick turnaround time in the hospitals. From a technology point of view, he opined that most institutions found sourcing care protocols-based software, mobile phone-based care delivery and tele-health care etc. to be a tough task.
Despite the challenges and priority constraints, CIOs have managed to add the required IT services into their portfolio to drive demand.
IT in Vogue
Ricky Bedi CEO, Teleradtech
Bangalore's Teleradtech has seamlessly integrated radiology with IT to providing consultancy services to hospitals, diagnostic centers, customizing, deploying, maintaining and supporting the PACS (picture archiving and communication systems) and RIS (Research Information Systems) solutions.
Bedi has deployed medical information systems, health information systems and an in-house developed instant messaging system while ensuring that redundancy is built in.
"It was imperative to ensure that the technology improve the workflow within the organization," maintained Bedi. Bedi went in Smartris.Net, a Web-hosted RIS platform with integrated PACS and billing system on a unified database, supporting a RIS-driven workflow.
While facing the integration-related challenges with no standardized process, Bedi is focused on creating a platform with collaborative tools such as unified communication to integrated and enable the active use of EMR and Lab management systems by its clients. By deploying these applications, Bedi ensured that the productivity of radiologists improved, enabled single system access for patients, reduction in resource consumption and overheads for managing the workflow, besides easy maintenance and quick turnaround on implementation changes owing to the configurability of system.
While there have been few accounts of IT deployments at Narayana Hrudayalaya, Raman said that applications such as HIS and ERP were used to scale up operations. While retaining the IT team was a challenge, most of it had been developed in-house.
The biggest implementation had been with regard to HIS software sourced from a Mumbai-based company and Raman had deployed Tally as a backend for accounting purposes. The hospital's IT spend would be less than 1% of its total revenues this fiscal. It has tied up with 250 units as part of its telemedicine initiative to provide quick care to the patients.
According to Dr Tyagi, AIIMS planned to allocate Rs 20 crores towards IT for 2009-10. So far, the major expenditure had been on security, networking and infrastructure. The institution has an internal LAN that hooked up 1,500 odd systems within the campus and IT is used for basic e-mailing. For its other premises, it is connected through a 42 Mbps WAN from ERNET.
Dr Tyagi and his 20-member team's priority has been to computerize the hospital. The applications currently being used at AIIMS include library information, patient registration, diagnostic information, billing, accounting, publishing of literature and other departmental systems.
"We have been using security gateway solutions from Cyberoam as well as Microsoft and Novell operating systems," remarked Dr Tyagi.
AIIMS has been using telemedicine and more than 300 locations are connected to 500 experts.
The Oncology specialist, HCG's Manish Gupta, did not take IT spend on desktops, servers, security and applications, which were anyway mandatory, into consideration. "Our spend covers medical equipment interfaces, custom developed hospital system, disease treatment protocol software, video conferencing, tele-radiology, medical image archival, IP based alerts/alarm instruments, unified communications, and of course the "backend" financial/inventory systems."
Gupta maintains that part of building automation and mobile phone-based spend is also managed by IT and technologies related to embedded systems, RFID and nano-technology is generating interest in healthcare IT.
Gupta argues, the IT spend is highly variable, but a minimum of 1% of revenue is spent and a lot depends on the size of hospitals and interconnectivity needs that, in turn, depends on the level of interaction between physicians.
EMR has helped the doctors and the management effectively. A lot of spending has gone towards clinical research and trials and HCG has deployed business intelligence to capture accurate data for analytical reports. Gupta said that the key business were deploying software related to care protocols, mobile applications, tele-health including teleradiology, tele-diagnostics and tele-medicine.
"HIS is the basic need for all the healthcare has been developed in-house," said Gupta.
Given the economic slowdown, Wockhardt's Suresh Shenoy witnessed pressures on spending as every penny spent needed justification. 2008-09 saw spending towards telemedicine, PACS, RFID, CRM and integration of medical devices and equipment to deploy a central HIS at Wockhardt.
Shenoy and his team focused on deploying Wipro HIS ERP, developed on Microsoft SQL Server to cater to the complete business process at each hospital addressing various functionalities like delivery of care, labs, pharmacy, blood bank services, IP and OP billing, procurement, movement and consumption of materials. "There are about 30 modules, all of them tightly integrated online."
According to Shenoy, while HIS is locally installed at each hospital site, its financial summary in terms of payments, receivables, and GL is captured globally through Oracle Financial ERP as HIS is integrated with this to create a dashboard.
From an infrastructure point of view, Shenoy has gone for a high-end server with cluster management and fault tolerant WAN connectivity, connecting all of the hospitals over a MPLS VPN that is part of Wockhardt's global network.
The other areas of deployment at Wockhardt included centralized Internet access security enforcement, biometric physical access control and integration with the attendance system, while Lotus Notes messaging was in vogue. For each reach, Shenoy opted for digital wireless telephony at hospitals.
Shenoy saw the benefits of integrating disparate systems, medical equipment resulting in labor effort savings and increased accuracy and better delivery of care to customers.
2008-09 has been slow for most CIOs amidst stringent spending criteria, the current fiscal seems to be an exciting time.
IT Outlook
2009-10 could turn out to be a great deployment year for most CIOs in this sector. "Peer to peer collaboration is critical to address the demands effectively," said Bedi.
According to him, video conferencing, VoIP and the use of medical transcription were key to address business needs.
The key agenda that Raman would carry out would be to identify waste areas where costs could be trimmed using IT as a tool.
"My aspiration is to evolve a system where I can communicate to customers about our specialty offerings and services in an effective way with the use of IT," maintained Raman. "Since our growth plans are big, we would invest on IT, and the immediate need is to create a dashboard for providing real-time information using varied applications," he added.
Raman and his team are evaluating the possibility of outsourcing and deploying varied applications to suit their needs.
Dr Tyagi's agenda is to go in for a outsourcing model with a consultant suggesting varied applications and driving technological innovation at AIIMS.
"As we are getting ISO 21000 certification, it is mandatory to get the best security systems and applications which can increase our operational efficiency," remarked Dr Tyagi.
Gupta's thrust would be to deploy technologies that help the institution in the early detection of patient problems.
'I aspire to streamline operational processes in healthcare providers that are often ignored and unlike other industries, technology can build new business or customer base in hospitals," averred Gupta.
Gupta is keen to drive mobile technologies for his care providers (doctors, nurses, and I would even include patient's families) who are always short on time.
Mobile diagnostics is the focus area for HCG, besides Gupta aiming at building a model around imaging software integrated with SAP modules. "We would go in for varied modules from SAP and tweak it to our needs," said Gupta.
With some relaxation in IT spending during this fiscal, Wockhardt's Shenoy intends to align IT strategies with business strategies in a more efficient manner to make IT the major driver and a profit center.
While agreeing that IT penetration in the healthcare sector has been minimal restricting to basics, IDC's Arpan Gupta finds that the IT spend during 2008-09 had been to the tune of Rs 700 crores, which is likely to increase in this fiscal.
The popular solutions deployed include integrated billing systems, PACS, SOA to a certain and virtualization with a focus on telemedicine.
Cashing in on trends
As a technology trend, IDC's Gupta found that the evolution of subsidiary industries such as healthcare insurance, medical tourism, outsourcing and consulting services as the demand for healthcare is growing.
Besides this, from the IT infrastructure and applications point of view, Gupta found growth in networking, peripheral industry, software services and e-prescription applications and so on as the need for IT was growing amongst healthcare institutions.
Raman was keen on outsourcing and he expected health care insurance providers to drive the growth for IT as it involved effective communication.
Gupta expected that technologies related to teleradiology would be aspired for as there was a growing demand for this expertise, but there was a shortage of this community.
Dr Tyagi saw the deployment of storage and server consolidation on the rise with more data coming into the fold.
From a growth perspective, Wockhardt's Shenoy bet upon telemedicine, PACS, Integrations of Medical Equipment, ABCM (Activity based Cost Management) solutions which would be predominantly deployed across healthcare institutions.
With the Union Health Ministry mooting a proposal to set up a series of 'Medical Parks' all over the country to enable domestic health industry to manufacture health equipment at large scale, growth is assured. Besides, to encourage indigenous manufacturing, special economic zones have been initiated to make the industry competitive and regulate the market.
geetha.nandikotkur@expressindia.com
Friday, August 21, 2009
Subscribe to:
Posts (Atom)
Lectures
Health Management in India
http://www.ihmr.org/ - Institute of Health Management
http://www.iphindia.org/joomla/index.php - Institute of Public Health
http://www.who.or.jp/sites/bangalore.html - WHO, Bangalore
http://cghr.org/aboutcghr.html - Center for Global Health Research
http://www.hispindia.org/ - HISP India
- PHFI Newsletter
http://www.epos.in - EPOS India
http://www.iphindia.org/joomla/index.php - Institute of Public Health
http://www.who.or.jp/sites/bangalore.html - WHO, Bangalore
http://cghr.org/aboutcghr.html - Center for Global Health Research
http://www.hispindia.org/ - HISP India
- PHFI Newsletter
http://www.epos.in - EPOS India
Center for Medicare and Medicaid Services |
Health Affairs | Books on Healthcare @ Amazon
|
Find Articles on bNET
|
Research on healthcare industry
|
Healthcare on Google Finance
|
Public Health WHO-INDIA
|
HealthReform.GOV
|
Kaiser Health News
|
Lean Healthcare Exchange
|
National Academies Press
|
Kaiser Family Foundation - In Depth
|
American College Of Healthcare Executives
|
Commonwealth Fund
|
HIMSS
|
HIMSS Analytics
|
Health Data Management
|
EHR and Workflow
|
Institute of Medicine