Showing posts with label fraud. Show all posts
Showing posts with label fraud. Show all posts

Tuesday, October 28, 2014

A "Bag of Money," but Executive Says Don't "Give Me Any of that Ethics Cr*p" - DaVita's Latest Settlement for $400 Million

A striking story of a large recent legal settlement, with reminders of previous related settlements, quietly slipped out in the midst of the ruckus about the Ebola virus.

A $400 Million Settlement

The basics were in a news release by the US Department of Justice.

DaVita Healthcare Partners, Inc., one of the leading providers of dialysis services in the United States, has agreed to pay $350 million to resolve claims that it violated the False Claims Act by paying kickbacks to induce the referral of patients to its dialysis clinics,...

This amount was augmented by 

a Civil Forfeiture in the amount of $39 million based upon conduct related to two specific joint venture transactions entered into in Denver, Colorado.

Also, according to Ed Silverman writing on PharmaLot, it was further augmented thus

DaVita, by the way, has agreed in principle to pay another $11 million to several states that filed false claims charges, according to a document that DaVita filed with the U.S. Securities and Exchange Commission. The DaVita spokesman says the deal involves five states.

So the total cost to the company seems to be about $400 million.   The settlement also  included a corporate integrity agreement,

  DaVita has entered into a Corporate Integrity Agreement with the Office of Counsel to the Inspector General of the Department of Health and Human Services which requires it to unwind some of its business arrangements and restructure others, and includes the appointment of an Independent Monitor to prospectively review DaVita’s arrangements with nephrologists and other health care providers for compliance with the Anti-Kickback Statute.
Kickbacks to Doctors who Refer Dialysis Patients


Here is how the kickbacks worked.

First, using information gathered from numerous sources, DaVita identified physicians or physician groups that had significant patient populations suffering renal disease within a specific geographic area. DaVita would then gather specific information about the physicians or physician group to determine if they would be a 'winning practice.' In one transaction, a physician’s group was considered a “winning practice” because the physicians were 'young and in debt.'  Based on this careful vetting process, DaVita knew and expected that many, if not most, of the physicians’ patients would be referred to the joint venture dialysis clinics.

Next, DaVita would offer the targeted physician or physician group a lucrative opportunity to enter into a joint venture involving DaVita’s acquisition of an interest in dialysis clinics owned by the physicians, and/or DaVita’s sale of an interest in its dialysis clinics to the physicians. To make the transaction financially attractive to potential physician partners, DaVita would manipulate the financial models used to value the transaction.

 So these alleged kickbacks were not envelopes full of unmarked bills, but sophisticated, complex transactions that would be hard for outsiders to understand.

To ensure that those bought stayed bought,

Last, DaVita ensured future patient referrals through a series of secondary agreements with their physician partners. These included paying the physicians to serve as medical directors of the joint venture clinics, and entering into agreements in which the physicians agreed not to compete with the clinic. The non-compete agreements were structured so that they bound all physicians in a practice group, even if some of the physicians were not part of the joint venture arrangements. These agreements also included provisions prohibiting the physician partners from inducing or advising a patient to seek treatment at a competing dialysis clinic. These agreements were of such importance to DaVita that it would not conclude a joint venture transaction without them.

Note that these alleged arrangements ensured the private gains of the physicians involved, and presumably by increasing referrals, ensured the private gains of DaVita, and likely specific managers whose remuneration depended on the fees produced by referrals.  However, the arrangements steered patients to dialysis services not based on what would be best for patients but what would be best for those involved in the arrangements.  Thus these arrangements appeared to fit the Transparency International definition of corruption: "abuse of entrusted power for private gain."  The physicians were entrusted to provide the best possible care of individual patients, yet they put their and the company (and likely the company's managers) financial gain ahead of the patients' care.

No One Admitted Anything or Suffered Any Negative Consequences



Although the company paid a fine and entered into the corporate integrity agreement, apparently no individuals, be they physicians or company managers, paid any sort of penalty.


Like many other settlements we discussed, the company paid out a lot of money but denied it did so because it did anything wrong. Ed Silverman wrote on the PharmaLot blog


In a statement, DaVita says it is 'pleased to announce a civil resolution' and that 'patient care was never an issue, nor were billing or payment practices… We are proud of our commitment to compliance over our 15-year history.'

'We have worked incredibly hard to get things right and it is our belief there was no intentional wrongdoing. We believe this settlement is the right thing to do for our teammates, partners and shareholders. It allows us to move forward with heightened clarity and transparency, both with regulators and our physician partners.'

Why it was good for shareholders and "teammates and partners," presumably meaning employees to pay so much money in the absence of "intentional wrongdoing," when the money would likely come out of stock value and employees' salaries,  was not explained.  Why patient care was "not an issue" when the allegations were that patients were steered to dialysis providers because of financial inducements given to doctors, not due to any consideration of patients' needs and welfare also was not explained.

Furthermore, the whistleblower who triggered the lawsuit suggested there was wrongdoing.  Again, per Ed SIlverman on PharmaLot,


In a July 2009 e-mail cited in the whistleblower lawsuit, which was also filed in federal court in Colorado, one DaVita executive asks for suggestions on how to ensure the financial models used to value transactions pass internal standards. Another executive replies 'You mean gaming the model, right?' To which the first exec writes, 'I do.'

'I think there was a pretty wide understanding that what was going on was questionable at best,' David Barbetta, the former DaVita senior financial analyst, tells us. He says he worked at DaVita from March 2007 until August 2009, when he resigned after being disturbed by several joint venture transactions.

Barbetta, who is now an independent technology consultant, says he mentioned concerns to DaVita managers, but was ignored. 'I did raise this with someone who was a vice president, but he just said not give him any of that ethics nonsense,' he tells us. 'He was a vp and I was an analyst, so I pretty much looked at him and didn’t really push the issue any further.'

Another Denver Post article put it even more vividly,

 One vice president warned Barbetta not to 'give me any of that ethics crap,' court documents state.

And, in internal company e-mails Barbetta provided to the government, top DaVita officials boasted of 'gaming' valuation models. Barbetta also told prosecutors that another DaVita manager once explained to him the deals were used to funnel 'a bag of money' to physicians. Those doctors, in exchange, steered dialysis patients to DaVita.

Why there was no further investigation of these executives, and those to whom they reported, was also not explained.  

Just the Latest Settlement

The few media reports of this settlement suggested that this was not DaVita's first settlement.

The 2000 and 2004 Gambro Inc Settlements

The current DOJ release noted that DaVita

had previously been in a joint venture arrangement involving dialysis clinics with Gambro, Inc., a dialysis company acquired by DaVita in 2005. Prior to the acquisition, Gambro had entered into a settlement with the United States to resolve alleged kickback allegations that, among other things, required Gambro to unwind its joint venture agreements.

Actually, Gambro Inc, which became part of DaVita in 2005, had made two similar settlements.  According to a 2004 Department of Justice news release,

In 2000, Gambro Healthcare and its subsidiary, Gambro Healthcare Laboratory Services, agreed to pay $40 million to settle allegations of healthcare fraud. Gambro and another subsidiary, Dialysis Holdings Laboratory Services, Inc. (DHLSI), have agreed to pay more than $13.1 million to settle similar allegations. 

However, in 2004, a much bigger Gambro settlement was announced,

Gambro Healthcare will pay more than $350 million in criminal fines and civil penalties to settle allegations of healthcare fraud in the Medicare, Medicaid and TRICARE programs,...

Aspects of this settlement were eerily similar to those of the latest DaVita settlement,

As part of this comprehensive global resolution, Gambro Supply Corporation, a sham durable medical equipment company and a wholly owned subsidiary of Gambro Healthcare, admitted to the execution of a healthcare fraud scheme and agreed to plead guilty to criminal felony charges, pay a $25 million fine and be permanently excluded from the Medicare program.

Gambro Healthcare will also pay in excess of $310 million to resolve civil liabilities stemming from alleged kickbacks paid to physicians, false statements made to procure payment for unnecessary tests and services, and payments made to Gambro Supply. The settlement also requires Gambro to allocate an additional $15 million to resolve potential liability for the conduct resolved under the federal agreement pursuant to a preliminary understanding reached with representatives of various state Medicaid programs. Gambro Healthcare has also entered into a comprehensive Corporate Integrity Agreement.

Note that this older settlement actually involved admissions of wrongdoing, fraud, and a guilty plea by a subsidiary to federal felonies.  . 

The 2005 Settlement of Allegations of Illegal Anti Competitive Aspects of DaVita's Gambro Acquisition

DaVita's proposed acquisition of the criminal Gambro also provoked allegations by the US Federal Trade Commission of illegal anti competitive activities. In a 2005 FTC news release,

According to the Commission’s complaint, DaVita’s proposed acquisition of Gambro would be anticompetitive and in violation of Section 5 of the FTC Act and Section 7 of the Clayton Act, as amended. DaVita and Gambro account for a significant proportion of the dialysis clinics and treatment stations in many local areas in the United States, and the acquisition, if consummated, would lessen competition for outpatient dialysis services in 35 markets nationwide.


The 2012 DaVita Epogen Settlement

The 2014 Denver Post article included this offhand reference,

The company settled another whistle-blower lawsuit in 2012 and agreed to pay $55 million for other fraud claims. In that case, a former employee of Epogen-maker Amgen alleged the company overused the anemia drug.

The 2012 Denver Post article to which it referred stated,

Kidney dialysis giant DaVita Inc. has settled a whistleblower lawsuit for the first time, agreeing to pay $55 million over allegations of drug overuse while denying any wrongdoing.

Denver-based DaVita settled fraud claims in a Texas lawsuit challenging the dialysis chain's past use of Epogen, an anemia drug whose high cost and dangers helped change how the government pays for kidney care.


Note that this case suggested actions that could have hurt patients,

 The Texas whistleblower lawsuit accused DaVita of using more Epogen than was medically necessary,...

Epogen is not without serious adverse effects, as noted above, and overdosing multiple patients with it made it likely that some were harmed.

Further, while

DaVita said it was the first time it was settling a claim over federal anti-fraud laws, but noted the government had declined to join the whistleblower' s lawsuit.

Only two years later DaVita had to settle more federal claims, this time due to a suit that the federal government had certainly joined.  And as noted above, a company which DaVita was about to acquire as a subsidiary had admitted to fraud and pleaded guilty to federal charges apparently involving fraud just before the acquisition. 

Finally, just as in 2014, in 2012 DaVita denied responsibility,

'DaVita and its affiliated physicians did nothing wrong and stand by their anemia management practices, which were always consistent with their mission of providing the best possible care for each patient,' a company statement said.

Summary

The latest settlement by DaVita was of allegations that the company gave kickbacks to physicians to get them to refer patients to DaVita facilities, regardless of the patients' best interests.  The company paid about $400 million and signed a corporate integrity agreement, but no individual who authorized, directed, or implemented the provision of kickbacks was identified, or paid any penalties.  This settlement turns out to have been only the latest settlement by DaVita or companies it acquired.  Previous settlements involved penalties of $53 million, $350 million, and $55 million (totaling more than three-quarters of a billion dollars from 2004 to 2014.  Previous settlements were for kickbacks and fraud.  One included a guilty plea to a felony.  Previous settlements involved alleged and sometimes admitted behavior that likely put patients at risk.   One earlier settlement also included a corporate integrity agreement.  However, no settlement imposed any negative consequences on any individual who authorized, directed, or implemented the bad, and sometimes criminal behavior.

The DaVita Statement of Mission and Core Values includes


Integrity
We say what we believe, and we do what we say. We are trusted because we are trustworthy. In our personal, team, and organizational values, we strive for alignment in what we say and do.

and

Accountability
We don’t say, 'It’s not my fault,' or 'It’s not my job.' We take responsibility for meeting our commitments — our personal ones as well as those of the entire organization. We take ownership of the results.

Despite the fact that the above settlements made a mockery of these lofty values, the company managers who presided over the behavior that lead to them prospered mightily during this time period.  The company' 2014 proxy statement showed the current CEO and board chairman Kent J Thiry received $17,099,257 in total compensation in 2013.  The five next best paid executives received collectively about $22 million.  Note that Mr Thiry as been CEO since 1999, and thus all the above settlements and most of the behavior that led to them occurred on his watch.

So the march of legal settlements continues in step with the same old song.  Big health care organizations preach their lofty missions and values, pay their top managers millions, and in some cases turn them into billionaires, while the organizations are accruing amazing records of bad and sometimes criminal corporate behavior.  The legal settlements only provide hints as to this behavior, but nearly every time, the management need not admit nor deny wrongdoing while merrily going on to collect their next huge paycheck which was justified by the corporate financial performance in part generated by the bad behavior.

Leadership that cares not for honesty, transparency, or accountability, and that puts short term revenue, and usually personal enrichment ahead of patients' and the public's health may be the single most important reason that US health care is so dysfunctional.  Yet hardly anyone even dares discuss the damning facts about health care leadership, much less propose solutions.  If we do not reform our health care leadership so that it is transparent, honest, accountable, unconflicted, and it puts patients' and the public's health over personal enrichment, our health care system will continue to founder.  

Tuesday, July 29, 2014

New Allegations About Universal Health Services Inc - Why We Should Not be Surprised

Current Allegations of Poor Treatment and Threats to a Whistle Blower

This month, a Boston Globe article reported trouble at a local hospital,


Arbour HRI, a Brookline psychiatric hospital in recent trouble with regulators, disciplined a mental health worker for talking to the Boston Globe about problems there — an action the employees’ union is fighting.

The hospital also required all staff to sign a policy forbidding them from speaking with the media about Arbour — or risk losing their jobs, according to the union.

An article that appeared in the Globe on May 30 described findings of federal investigators that the hospital failed to provide treatment for at least four patients during a February inspection. Instead of attending group therapy, the patients, whose diagnoses included bipolar disorder and paranoid schizophrenia, spent many hours sleeping or wandering the hallways.

One Tuesday afternoon, three patients on a unit for those diagnosed with both mental illness and a substance abuse disorder were in therapy. Inspectors found eight patients in bed.

Frank Barnes, a longtime mental health worker and a union representative for 1199SEIU, was quoted in the story saying that problems at Arbour HRI reflected the culture of an administration more focused on revenue than quality of care.

But then,

 Nine days later, according to documents the SEIU provided to the Globe, a nurse executive verbally warned Barnes. A 'counseling/corrective action form' stated that the consequences for failing to follow the media policy could include termination.

The policy warns employees they 'are not to speak to any member from the media on behalf of the facility or company,' and that they must immediately refer press inquiries to the chief executive.

Arbour spokeswoman Judith Merel said that the policy is intended to protect the privacy of patients and staff. 'These processes are put in place to ensure that the hospital complies with all patient confidentiality and privacy laws as well as to safeguard the trust placed in us by our patients, employees and staff,' she said in a written statement.

But the SEIU, in a complaint against the hospital filed with the National Labor Relations Board, charged unfair retaliation against Barnes and said the 'overly-broad' media policy violates employees’ rights.

'If Universal Health Services is treating the patients under its care with dignity and respect, then why would it prevent caregivers from talking to the media?' union executive vice president Veronica Turner said in a written statement. 'It raises serious questions about what the company is trying to hide.'

So far we have allegations that insufficient or poor care was provided, and that a hospital employee who discussed the allegations with the press was threatened, apparently based on a media policy that was more like a code of silence.

It turns out these are not the first problems reflecting badly on the management of the hospital.

Arbour HRI has a recent history of problems. Massachusetts regulators prohibited the hospital from accepting any patients in November, citing unsafe conditions. They allowed admissions to gradually resume two weeks later, in early December. But then in February, inspectors for the federal Centers for Medicare & Medicaid Services found serious shortcomings in the quality of treatment at the 66-bed hospital in Brookline.

The problems at Arbour HRI should not come, however, as a big surprise.  Arbour HRI is part of

Arbour Health System [which] operates five psychiatric hospitals and 12 mental health clinics in Massachusetts. Its for-profit parent, Universal Health Services [Inc], is a publicly traded company that earned more than $500 million last year....

Although not mentioned in the current Boston Globe report, Universal Health Services Inc seems to have a sorry record.

In 2012, Settlement of Allegations of Substandard Treatment, Falsified Records

About two years ago, Universal Health Services settled somewhat similar allegations about another of its hospitals.  As announced by the Department of Justice,

Universal Health Services Inc. (UHS) and two subsidiaries have reached a settlement in a False Claims Act lawsuit with the United States and the Commonwealth of Virginia, the Justice Department announced today.   Under the settlement, UHS and its subsidiaries, Keystone Education and Youth Services LLC and Keystone Marion LLC, which did business as the Keystone Marion Youth Center, a residential facility in Marion, Va., agreed to pay $6.85 million to the United States and the commonwealth to settle allegations that they provided substandard psychiatric counseling and treatment to adolescents in violation of Medicaid requirements, falsified records and submitted false claims to the Medicaid program.  UHS closed the Marion facility earlier this year.  

The allegations, made by multiple people, were actually quite lurid.  As reported by the Huffington Post, the lawsuit involved assertions that psychological therapy was provided in hallways;  the facility lacked a required education program and clinical direct; inmates were nearly unclothed; responses to resident complaints were sometimes met with "brutal force;" the staff performed an "exorcism" on an autistic boy; and staff sexually abused residents.


Previous Allegations of Neglect, Suicide Attempts, Rape and Murder

Note furthermore that according to the Huffington Post

Universal Health Services Inc., a large hospital chain which racked up dozens of allegations of abuse during that time -- including everything from rape to suicide attempts allowed by neglect to murder. Over the years, states have barred children from attending UHS facilities over safety concerns and the feds have put UHS on their radar. Department of Justice lawyers have filed two lawsuits accusing the chain of fraudulent activities. 


By the way, the reason the Huffington Post gave this case extensive coverage, however, was not apparently the grievous nature of the allegations.  It was that on Universal Health Services board sat a politician who was at the time of the report a credible candidate for the Republican nomination to be President of the US.

Former Sen. Rick Santorum (R-Pa.) has become a top-tier candidate for the Republican presidential nomination in recent weeks by appealing to evangelical voters as a man steeped in family values and his Christian faith. From 2007 to 2011, however, Santorum served on the board of directors of Universal Health Services Inc.,...

In 2009, Settlement of Allegations of Kickbacks to Physicians

Finally, also mentioned in the Huffington Post, was another settlement by Universal Health Care.  As reported in Modern Healthcare,

Universal Health Services agreed to pay the federal government $27.5 million to resolve allegations that its three hospitals doing business as South Texas Health System paid kickbacks to physicians in the form of sham medical directorships and leases, the U.S. Justice Department announced.  

Note further that this settlement

also requires South Texas Health System to enter a five-year corporate integrity agreement with HHS' inspector general's office. 

Summary

So given the record public since at least2009, should it be a big surprise that Universal Health Services is again facing allegations of poor and unethical treatment of patients and employees?

This is a familiar pattern.  Now that we have been following organizational misbehavior in health care for some years, we see that organizations that get into trouble once are very likely to get into trouble again.

This may be enabled by how government regulators and law enforcement give large health care organizations such  gentle treatment.  We have talked about the march of legal settlements by such organizations before.  Allegations are usually resolved with legal settlements that involve no admissions of guilt, small monetary penalties (compared with these organizations' total revenues), and sometimes apparently toothless corporate integrity agreements.  Settlements get desultory public notice, rarely informed by previous settlements or other evidence of previous misbehavior.  No individual who may have authorized, encouraged, directed, or implemented the bad behavior is likely to suffer any negative consequences.   It does not help that while nominally public, these settlements get little press, and what coverage there is usually fails to put the whole pattern together.

So we would urge the reporters who cover the next settlements by big health care organizations at least look to see if the organizations had been involved in similar settlements in the past.

Furthermore, as we have said all to often,...   The failure of the current limp legal efforts against such corruption is evident by how many corporations have become ethical repeat offenders.  Pervasive bad behavior by large health care organizations has got to be a major cause of our ongoing health care dysfunction.  So, to really deter bad behavior, those who authorized, directed or implemented bad behavior must be held accountable. As long as they are not, expect the bad behavior to continue.

Tuesday, May 13, 2014

The Continuing Mystery of the Fugitive Founder and Missing Money - What it Says About the Opacity of Offshore Medical Schools

The next chapter in the bizarre tale of the fugitive founder of an off-shore (from the US and Canada) Caribbean medical school, and his now convicted spouse, do not solve any mysteries, but raise larger concerns about the accountability, or lack thereof, of leaders of important health care organizations.

Introduction: the Fugitive Founder and Convicted Spouse

As we posted in October, 2013, drawing an amazing for us number of comments, the couple who founded two Caribbean medical schools which catered almost entirely to US and Canadian students ran into significant legal trouble.  Founder David Leon Fredrick and his wife, Dr Patricia Lynn Hough were indicted for tax evasion for failing to report income from the two medical schools they allegedly owned, and later sold.

The schools were Saba University School of Medicine, on Saba, and the Medical University of the Americas, on Nevis.  The initial legal proceedings revealed that while Saba University School of Medicine was apparently first set up by a non-profit foundation (or NGO) run by the couple, somehow it became for-profit owned by Mr Fredrick and Dr Hough, and Saba and the Medical University of the Americas were subsequently sold to a private equity group, Equinox Capital.

Before jury selection started, Mr Fredrick disappeared.  Dr Hough was eventually convicted of defrauding the US Internal Revenue Service, and income tax evasion, after trial testimony to the effect that the couple concealed money in a Swiss bank, got $36 million from the sale of the schools, and bought an airplane, two houses, and a condominium.

Left mysterious at that time were Mr Fredrick's whereabouts, where the money that the couple derived from the sale of the medical schools went, and how a school that began as a non-profit organization became a for-profit corporation owned by the couple.  The case should have lead to some concerns about the leadership and governance of the off-shore medical schools that now train increasing numbers of would be US and Canadian physicians.

However, after Dr Hough was convicted, there was little public discussion of these issues, at least until Dr Hough's recent sentencing.  (There were some interesting comments made on our blog post, many from anonymous erswhile defenders of Saba University and/or Mr Fredrick and Dr Hough.  While they expressed some interesting opinions, in my humble opinion they did not add any substantive facts to the discussion.)

Latest Developments in the Case

In the past few weeks the case got a little more public notice in terms of reporting of the legal proceedings leading to the sentencing of Dr Hough   They brought to light some additional contentions by the prosecution, which deserve some attention because after all, they won their case.

The Amount of Money the Couple Made


As reported by the Sarasota (FL) Herald-Tribune,  Dr Hough was sentenced to two years in federal prison, three years of supervised release, and to repay $15 million to the IRS.  In addition,

 Prosecutors say Hough and Fredrick sold the schools and associated real estate in April 2007 for more than $35 million. An IRS agent testified last Thursday that Hough also made more than $12 million in income from the two schools from 2003 until 2007.

How much Mr Fredrick made was not discussed since it was not relevant to Dr Hough's sentencing. 

The Effort that Went into the Plot

According to Bloomberg,

'Hough’s crimes were neither impulsive nor isolated but required sophisticated transactions, coordination with foreign bankers, annual lies to the federal government, and by her own admissions, trips to Switzerland,' prosecutors wrote in a sentencing memo on April 14. 'Hough made calculated decisions to cheat, over and over again.'

Also,

Prosecutors accused the couple of crafting their scheme with UBS AG (UBSN) banker Dieter Luetolf and Swiss financial adviser Beda Singenberger, both unindicted co-conspirators.

Singenberger, who was separately charged with helping 60 U.S. clients hide $184 million in offshore accounts, hasn’t responded in federal court in New York.

In more detail,

Prosecutors said the couple used an array of accounts in the names of businesses to hide their money and employed 'e-mails, telephone calls and in-person meetings to instruct Swiss bankers and asset managers to make investments and transfer funds from their undeclared accounts at UBS.'

The Mysteries Remain



Where Did the Money Go?

As noted above, the sale of the two medical schools netted Mr Fredrick and Dr Hough about $35 million.  Where that went is still unclear.

How Did Mr Fredrick and Dr Hough Become Owners of a Previously Non-Profit Medical School?

As noted above and in our previous post, Saba University School of Medicine began as a non-profit managed by Mr Fredrick and Dr Hough.  Somewhere along the way, the couple assumed ownership of the school.  There seems to be no record and no discussion of how this happened.  In the US, a conversion of a substantial non-profit, like a medical school, to a for-profit, ordinarily would require some regulatory approval and public discussion.  Furthermore, in most cases, non-profit conversions to for-profit would require some sort of protection of the assets of the former non-profit, often leading to a spin-off of a new non-profit foundation.   None of this apparently happened in this case (which admittedly did not occur in the US.)  How did Mr Fredrick and Dr Hough just take over a non-profit, sell it, and keep all the money involved?

Where is Mr Fredrick and Why did He Flee?

We need Sherlock Holmes for this. 


What Does This Case Say About the Leadership and Governance of Offshore Medical Schools?

So the latest details revealed suggest a fairly intricate plot by the American couple who founded two Caribbean medical schools.  The plot allegedly netted them millions, and now resulted in one of the couple remaining a fugitive, and the other convicted of federal crimes.

The biggest issue raised by this case, in my humble opinion, is not about financial crimes, tax-evasion, or the hiding of assets in Swiss banks.  It is about the leadership and governance of offshore Caribbean medical schools, and by extension, of academic medicine and health care.  In 2010, Eckhert documented that the number of offshore medical schools, "for-profit institutions whose purpose is to train U.S. and Canadian students who intend to return home to practice," but not to train physicians to practice in the countries in which these schools are located, was rapidly growing.(1)  By 2010, there were 33 such schools, 20 of which were new since 2000.

These offshore medical schools are not accredited in the US or Canada, and such accreditation is currently not required for individual graduates of such schools to be admitted to US house-staff programs or for US licensure.  So perhaps it is not surprising that little is known about these schools.

How they choose students, the qualifications, or even names of their faculty, their curriculum, how they supervise clinical training (which is mostly done by affiliated North American hospitals), and what happens to their graduates are boscure.  Eckhert attempted to describe what is known, but noted "variability exists in the availability of information on faculty; where data exists, it is noted that most of the permanent on-site basic science faculty are internationally trained, many have no documented medical education experience in the United States, and it is not uncommon for them to be OMS [offshore medical school] alumni."

Even less is known about who leads these schools, who if anyone is responsible for their stewardship, and even who owns them.  The current case suggests that Saba University School of Medicine was run by couple who mysteriously assumed ownership of the school after leading it as a non-profit organization, then sold it to private equity for millions in a transaction that eventually left one a convicted criminal and the other a fugitive.  Yet none of this came to light until the federal government launched an investigation not of offshore medical schools, but of offshore money laundering and happened to catch the couple in the investigational web. No regulatory process, no watchdog organization in the US or Canada, or on Saba apparently found this out until it was revealed in an investigation by the US federal government that had nothing specifically to do with health care or offshore medical schools.  This suggests that offshore medical schools now can be lead and run by anyone, qualified or not, honest or criminal, without any oversight or accountability.  

For example, even today little is known about the leadership of Saba University School of Medicine.  The school currently provides only minimal biographical information on its administration.  Its President is listed as Joseph Chu MD MPH, who appears to have the same educational credentials (MD from Georgetown, MPH from University as Washington) as one Joseph Chu who is apparently a Clinical Associate Professor of Epidemiology at the University of Washington.   Dr Chu's specialty and previous experience are not apparent.  Whether the Dr Chu at University of Washington is the same as the President of Saba is unclear.  If they are the same, how Dr Chu holds down these two jobs is not clear.

For comparison, most US schools provide extensive information about their leadership.  Just as an example, see the introductory page on the Dean of the University Washington medical school.

Even less is known about the stewardship or governance of Saba University School of Medicine.  Many US medical schools have their own boards of trustees who are supposed to provide stewardship. For example, the UW board is here.  Their membership is generally known.  Furthermore, most US medical schools report to university leadership, again whose identity is known, and are subject to governance by a university board of trustees.  We have certainly criticized the leadership and governance of US academic medicine.  At least, however, it is possible to find out the names of the people responsible. 

However, while Saba University School of Medicine is still apparently owned by Equinox Capital according to the latter's website, to whom Dr Chu reports at Equinox Capital is unclear.  Whether Saba has a board of trustees, or any such similar stewardship mechanism, is unclear.  So who is ultimately accountable for Saba is unclear.  Probably just as unclear is who leads, who stewards, and who is accountable for the leadership of most other offshore medical schools.

While Eckhert wrote in 2010 that the increasing presence of offshore medical graduates in the US "obligates U.S. medicine to take a closer look at these educational programs," no such scrutiny has occurred since then.  While offshore medical schools account for the training of an increasing proportion of US (and presumably Canadian) physicians, we know next to nothing about their leadership and governance.  This seems to be just another part of the decreasing accountability of the leadership of US health care, and the increasing opacity of the governance and stewardship of US health care organizations.  True US health care reform would make leadership transparent and accountable.         

Reference
 1.  Eckhert NL.  Private schools of the Caribbean: outsourcing medical education.  Acad Med 1010; 85: 622-630.  Link here

Wednesday, April 30, 2014

The Pervasiveness of Health Care Corruption as Shown by Another Roundup of Legal Settlements

Legal settlements are one way to document unethical and even corrupt behavior by large health care organizations, even if they may not deter bad behavior in the future.  It is time for another roundup of settlements by large pharmaceutical and device companies, presented in alphabetical order

Abbott Laboratories

This one goes back to late December, 2013.  As described in the Chattanoogan (from Tennessee):

Abbott Laboratories, a global healthcare company, has agreed to pay $5.475 million to settle alleged violations of the False Claims Act, and other federal laws and regulations in connection with the operation of its medical device business which manufactures, markets and supplies carotid, biliary, and peripheral vascular products.

The US Justice Department accused Abbott of kickbacks to physicians,

 As alleged in the settlement agreement, between 2005 and 2010, through its employees and a third party continuing medical education providers, Abbott offered physicians paid teaching and training assignments, consulting arrangements, speaking engagements, and/or sponsorship grants for physician conferences, for the purpose of inducing physicians to arrange for or recommend that the hospitals with which they were affiliated purchase or order Abbott’s carotid, biliary and peripheral vascular products.

Note in particular that the kickbacks were disguised as payments for consulting or speaking. 

As is usual in such cases, no individual seems to have paid any penalty or been subject to any punishment.  Because this was a legal settlement, the company did not admit wrongdoing.

Abbott's previous issues are discussed here, including a $1.6 billion settlement in 2012

Baxter International

This was reported in April, 2014 by Modern Healthcare,

 Baxter International agreed to pay $64 million to settle a class-action lawsuit that alleged the Deerfield, Ill.-based company and some of its competitors colluded to raise prices of plasma-based therapies.

Unlike the other cases above and below, this seemed to be a purely financial misadventure, although one that clearly increased health care costs,

Hospitals and drug distributors, saying they bought the plasma products at inflated prices, sued in 2009 Baxter; Victoria, Australia-based CSL; and the Plasma Protein Therapeutics Association, an Annapolis, Md.-based trade group.

Once more, the company admitted no wrongdoing, and no individuals seemed to be subject to any negative consequences.  

Baxter International's previous misadventures are here, including the striking case of its marketing of contaminated and sometimes deadly heparin made from Chinese pigs. 

Endo Health Solutions

This one is from February, 2014, as reported by Bloomberg

Endo Health Solutions entered a deferred-prosecution agreement and will pay $193 million to settle whistle-blower claims that it marketed the shingles drug Lidoderm for unapproved purposes, the U.S. said.
Endo will pay $20.8 million in forfeitures and $171.9 million in civil false claims settlements with the states and the U.S. government, the Justice Department said today in a statement. 

This one was all about marketing for uses not approved by the US Food an Drug Administration,

Between 2002 and 2006, Endo sales managers instructed some representatives on how to expand 'sales conversations' with doctors beyond the treatment of shingles-related pain, the U.S. said. Under the deferred-prosecution agreement, Endo admitted that it intended Lidoderm to be used for uses not approved by the U.S. Food and Drug Administration, the Justice Department said. 

Note that this case involves false claims, that is, fraud, because it is illegal to bill government programs for unapproved uses.

Again, no individual suffered any consequences, and the company offered the usual kind of statement that admitted neither responsibility nor guilt,

'We are pleased to resolve this matter and are confident that we have robust programs in place to assist us in satisfying our legal and regulatory agreements,' Endo Chief Executive Officer Rajiv De Silva said in a statement.  

One wonders, as usual, why a company would pay so much merely to avoid the legal expenses of a trial, unless of course the lawyers suspected the trail would not go well?

Hospira

This one was about hiding quality problems due to cost-cutting from investors, as reported by Reuters in March, 2014.  

Hospira Inc has agreed to pay $60 million to resolve a class action lawsuit accusing the drug maker of misleading investors about quality control problems that undermined an initiative to improve the company's margins and operations.

The details included,

As Hospira was promising to address issues raised by the U.S. Food and Drug Administration following inspections, the plaintiffs said the company was 'making the problems worse by gutting quality control efforts through cost cutting aimed at boosting short-term profitability.'

The lawsuit said those cost-cutting moves stemmed from a March 2009 initiative called 'Project Fuel' intended to increase shareholder value by eliminating underperforming and duplicative units and reducing its global workforce.

Plaintiffs contended the cuts in the budget and workforce hurt Hospira's quality control efforts, particularly at Rocky Mount, the company's largest facility.

An FDA inspection in January 2010 of the Rocky Mount facility found a number of problems with the company's quality control and drug validation processes, the lawsuit said, and the agency issued a warning letter that April.


Note that this involved quality control problems presumably in drug or device production, possibly leading to safety risks for patients.  Yet it was investors who brought the lawsuit.

Note also that this seemed to be a clear case in which cost-cutting measures meant to improve short-term corporate revenue lead to problems that could have caused such risks.  

One interesting feature of this case was that company executives were named as defendant (presumably again because it was investors, not patients or law-enforcement officials who initiated the suit.)


The lawsuit ... also named executives including Chief Executive Officer Michael Ball as defendants,...


I cannot find any information about whether these executives were personally liable for any payments, however.   

Pfizer

This is yet another settlement involving the marketing of Neurontin, as reported by Bloomberg in April, 2014,


Pfizer Inc the world’s biggest drugmaker, agreed to pay $190 million to end a lawsuit claiming it violated federal antitrust laws by delaying generic versions of its Neurontin epilepsy drug. 
Pfizer agreed to settle the class-action litigation pending in federal court in Newark, New Jersey, according to a filing today. U.S. District Judge Faith Hochberg must approve the accord, which would cover purchasers of Neurontin from December 2002 to August 2008. 

Note that this settlement, like many others, is of matter from a long time ago.  When it comes to bad behavior by big health care corporations, any form of justice is not swift.

Note also that this is only the latest chapter in the long saga of Neurontin, for whose mis-marketing Pfizer has already shelled out a lot of money (see this post to start, and here for the collection).  Pfizer has an amazing record of bad behavior on view here.  In fact, it has had a conviction as a Racketeering Influenced Corrupt Organization (RICO) on the basis of its previous marketing of Neurontin (look here).

This particular bad behavior involved included,

 improperly listing certain patents with the U.S. Food and Drug Administration, engaging in illegal promotion and sales of Neurontin for unapproved uses, filing and maintaining sham litigations with respect to certain patents, and making misrepresentations to the patent courts,

Note that while much of this was legalistic, illegal marketing was in there too.

Once more, I found nothing about any negative consequences for individuals who authorized, directed, or implemented questionable actions.

Summary

So it is all drearily familiar.  Big health care organizations seem to repeatedly engage in deceptive marketing, providing kickbacks to health professionals, fraudulent billing, anti-competitive practices, etc, etc.  These practices increase health care costs, and may risk patients' health and safety.  Many of these practices are corrupt, at least according to the Transparency International definition of corruption, "abuse of entrusted power for private gain."  Drug and device companies, for example, are entrusted to provide safe and effective products.  Deceptive marketing, kickbacks to health professionals to encourage overuse, and cutting quality control to cut costs all seem to be examples of abuse of this entrusted power.  The private gain obviously goes to any managers and executives who score bigger bonuses due to the increases in revenue that result. 

Yet there are very few examples of any individuals who gained ever being subject to any negative consequences.  Given that lack, and the lack of any requirement for corporate leaders to admit responsibility, much less guilt, is it any surprise that these practices go on and on.  The failure of current limp legal efforts against such corruption is evident by how many corporations have become ethical repeat offenders.   (Note that in fact, as noted above, one of the pharmaceutical companies above actually was convicted of being a RICO, racketeering influenced corrupt organization, yet that conviction seemed to have no real negative consequences for the organization or any of the people involved.)

As I have said again and again, pervasive bad behavior by large health care organizations has got to be a major cause of our ongoing health care dysfunction.

So, to really deter bad behavior, those who authorized, directed or implemented bad behavior must be held accountable. As long as they are not, expect the bad behavior to continue.

Thursday, December 19, 2013

EHR cut-and-paste problem is only one of the several mechanisms to clone documentation - and facilitate fraud

In my Dec. 10, 2013 post "44% of hospitals reported to HHS that they can delete the contents of their EHR audit logs whenever they'd like" (http://hcrenewal.blogspot.com/2013/12/44-of-hospitals-reported-to-oig-that.html) I observed that the "money quote" of the Modern Healthcare article that prompted the post, "Feds eye crackdown on cut-and-paste EHR fraud" by Joe Carlson was not the issue of EHR cut-and-paste features and billing fraud, but EHRs and audit trail alteration.

Dr. Stephen R. Levinson, an E/M compliance and healthcare quality expert among other areas of expertise (see http://www.linkedin.com/in/stephenlevinson), wrote me with the following regarding the issue I glossed over in favor of the audit trail concerns, namely, EHR cloning.

Reproduced with Dr. Levinson's permission:

This long-recognized and high-profile problem [EHR cut and paste, copy forward, etc. - ed.] covers only one of the several mechanisms EHRs provide to create CLONED Documentation.

Other non-compliant short-cuts include documentation by exception (auto-entry of extensive negative history reviews and normal comprehensive examinations), use of restricted pick list words and phrases, and "translation."

Translation is my own terminology for taking actively entered "yes" or "no" responses in medical history (and "normal" or "abnormal" findings in physical exam) and using pre-loaded software to convert (i.e., translate) the response to a long pseudo dictation paragraph. For example, check a box for lungs being "normal" may automatically appear in a paragraph as "lungs clear to percussion and auscultation; respiratory effort is normal on inspiration and expiration with normal excursions of the diaphragm; there are no rales or rhonchi, and no wheezes are present."

This extended statement will appear identically in patient after patient and visit after visit, regardless of whether this level exam was performed. Further, the likelihood of every patient having completely normal lungs is non-existent.  [This is one mechanism by which reams of "legible gibberish" are produced even with modest hospital stays, e.g., see my Feb. 27, 2011 post "Two Weeks, Two Reams" at http://hcrenewal.blogspot.com/2011/02/electronic-medical-records-two-weeks.html - ed.]

Finally, although cloned documentation is egregious, there are four other equally egregious non-compliant documentation and coding features, common to most EHRs, that are being totally ignored by OIG. These 4 features are:

1) non-compliant coding engines (including failure to consider medical necessity of the level of care)

2) Replacing narrative documentation of differential diagnoses with billing codes (ICD-9) and billing semantics

3) Failure to document the qualitative components of E/M coding, while addressing only quantitative components (e.g., when patient has a positive response to review of systems question on chest pain, compliance (and quality care) requires further investigation and documentation of further details; most current systems either lack ability to document these details or fail to guide and require physicians to document them)

4) Failure to incorporate consideration of "medical necessity" (indicated in E/M coding as the "nature of the presenting problems") into care, documentation, and coding

As evidenced by these explanations, common commercial EHRs in use today were either designed by amateurs or by crooks, with the gatekeepers turning a blind eye towards abuses since at least 2007 (per commenter and EHR compliance expert Dr. Reed Gelzer who, at http://hcrenewal.blogspot.com/2013/12/44-of-hospitals-reported-to-oig-that.html, indicated ONC and OIG knew of these issues since a 2007 report he contributed to).

The gatekeepers have turned a blind eye, that is, until now when they've finally opened one eye very slightly, like a ten-day-old puppy, as the abuses become more widely known.


Young puppy begins to open its eyes.


-- SS

Tuesday, December 10, 2013

44% of hospitals reported to HHS that they can delete the contents of their EHR audit logs whenever they'd like?

Modern Healthcare published an article "Feds eye crackdown on cut-and-paste EHR fraud" on Dec. 10, 2013 by Joe Carlson.

The article is about federal efforts to reduce the amount of clinician cut-and-paste from prior notes of a patient - which can even be done between charts of different patients.  This practice can result in overbilling for work not actually performed.  The practice can also result in no-longer-accurate data being carried forward; I have been consultant to cases where that phenomenon, in my opinion, contributed to grave patient injury in cases that have settled out of court.

It is at this link:  http://www.modernhealthcare.com/article/20131210/NEWS/312109965/feds-eye-crackdown-on-cut-and-paste-ehr-fraud?utm_source=articlelink&utm_medium=website&utm_campaign=TodaysHeadlines#

Subscription required, but googling the article title may allow reading it in its entirety.

The article begins:


Federal officials say the cut-and-paste features common to electronic health records invite fraudulent use of duplicated clinical notes and that there is a need to clamp down on the emerging threat. That concern is enhanced by the fact that it's too easy to turn off features of EHR systems that allow tracking of sloppy or fraudulent records.

In an audit report released Tuesday morning (PDF), [HHS Office of Inspector General, "NOT ALL RECOMMENDED FRAUD SAFEGUARDS HAVE BEEN IMPLEMENTED IN HOSPITAL EHR TECHNOLOGY"], HHS agencies confirmed that they are developing comprehensive plans to deter fraud and abuse involving EHRs, including guidelines for cut-and-paste features. The issue arises at a time when critics say federally subsidized digital patient record systems are sometimes being used inappropriately by providers to drive up reimbursement.

“Certain EHR documentation features, if poorly designed or used inappropriately, can result in poor data quality or fraud,” according a report from HHS' Office of the Inspector General.

None of this is a surprise to me, and to readers of this blog.

However, the real "money quote" in the article, I believe, is this:


"In addition, only 44% of hospitals' “audit log” systems could record whether cut-and-paste was used to enter data, and an identical percentage of hospitals reported [to OIG] that they can delete the contents of their internal audit logs whenever they'd like."


From page 11 of the HHS OIG Report linked above (http://www.modernhealthcare.com/assets/pdf/CH92135129.PDF):

[In 2006, ONC contracted with RTI International (RTI) to develop recommendations to enhance data protection; increase data validity, accuracy, and integrity; and strengthen fraud protection in EHR technology.]

... Hospitals' control over audit logs may be at odds with their RTI- recommended use as fraud safeguards:

RTI recommends that EHR users not be allowed to delete the contents of their audit log so that data are always available for fraud detection, yet nearly half of hospitals (44 percent) reported that they can delete their audit logs. Although these hospitals reported that they limit the ability to delete the audit log to certain EHR users, such as system administrators, one EHR vendor noted that any software programmer could delete the audit log.

RTI recommends that the ability to disable the audit log be limited to certain individuals, such as system administrators, and that EHR users, such as doctors and nurses, be prevented from editing the contents of the audit log because these actions can compromise the audit log's effectiveness. Hospitals reported they have the ability to disable (33 percent) and edit (11 percent) their audit logs, although they reported restricting those abilities to certain EHR users, such as system administrators or EHR vendors. All four EHR vendors we spoke with reported that the audit logs cannot be disabled in their products, but one vendor again noted that a programmer could disable the audit log.

I further note that, being voluntarily provided, i.e., not part of a formal investigation of any specific organization, those numbers are likely low, perhaps very low considering this issue.

An audit log or audit trail is an automatically-generated dataset, invisible to most users, containing items such as who viewed records, the date/time/location of viewing, and indication of actions they may have performed on the records such as editing/changes/additions/deletions, etc.

As an EHR itself is a collection of magnetized or optically encoded bits on some computer storage medium, it cannot be authenticated as complete and free from alteration by humans.

The audit trail is the only way to authenticate an EHR printout, however (as well as EHR screenshots or any other electronic data turned into a tangible form from those bits) as complete and free from alteration.

If an EHR printout cannot be authenticated as complete and free from alteration, its trustworthiness and perhaps even court admissibility as a business record under an exception to the hearsay rules regarding evidence may be damaged or invalidated.

My concern is that, if true, and considering the conflict of interest a hospital has regarding hiding potential fraud or malpractice that could cost them millions of dollars, a capability to "delete the contents of their internal audit logs whenever they'd like" and to edit audit trails (which based on the capabilities of relational databases also implies an ability to delete sections of audit logs selectively and/or to substitute false data) is simply alarming.

I don't think the EHR pioneers intended EHRs to be used for purposes of allowing evidence spoliation without traceability ...

-- SS

Dec. 13, 2013 Addendum:

I received the following reply from EHR compliance expert Dr. Reed D. Gelzer.  Re-posted with permission:

Good morning Dr Silverstein,

Thank you yet again for the illumination that you bring to matters of truth in Healthcare Information Technology.

Regarding the OIG report’s source document, the 2007 report to the ONC, I was the Fraud Prevention Workgroup Chair for that project, working under Principal Investigators Dr. Don Simborg and Susan Hanson, former Chair of AHIMA. 

For anyone who is interested in this subject matter, I would recommend that you go to the source document and, among other things, review the list of contributors.  These were all individuals who volunteered time to attempt to mitigate harms of defective HIT, in their capacities of records management systems, nearly 8 years ago now.   Many have gone on into leadership roles in related organizations and domains, some still working towards trustworthy health information technology systems.

I believe that I can say that none of those working on the report then would have believed that it was conceivable that even our most basic recommendations regarding the fitness of audit functions would remain "novel" in the industry in 2013.  One cannot be surprised at the low level of authenticity supports in hospitals’ EHRs systems given that fitness as record management systems for patient care has, to date, been either neglected or presumed, not tested or attested.   I am gratified that our 2007 work was utilized for the OIG report to illuminate the deplorable state of integrity supports in these patient care information systems.  This will undoubtedly spur interest in supportive resources such as the HL7 EHR System Functional Model Standard and the HL7 Records Management and Evidentiary Support Profile Standard.

All of us who worked on that ONC report are, I hope, as gratified as I am that the OIG removed our work product from its designated obscurity.   We developed the guidelines via methods that were more qualitative than quantitative, entirely intended to guide initial implementation backed by more methodical research.   We represented the most informed at that time, including those like myself and my ADIC associate Patricia Trites who had performed compliance testing on over 30 among the leading EHRs at the time and found extraordinary ranges of deficiencies, including audit functions that could be disabled at will.   Standards and tools existed then to support mitigation of risks and those Standards and tools have expanded since.  Now that the events and ONC decisions that led to inactions on the report are now in the past, we can more rapidly achieve the potentials nascent in HIT by rendering it more trustworthy, usable, and safe.

Thank you again for your ongoing vigilance.

Sincerely,

Reed D. Gelzer, MD, MPH, CHCC
Trustworthy EHR, LLC
Co-Facilitator, HL7 Records Management and Evidentiary Support Workgroup

To this I add that I also would not have found it conceivable that my concerns about bad health IT and the risks of patient harm it poses, as well as common healthcare IT project mismanagement, of which I started writing about in 1998 (http://cci.drexel.edu/faculty/ssilverstein/cases/) would remain "novel" ideas in the industry in 2013.

The Obamacare healthcare exchange website debacle has made the latter issue mainstream.  The former issues still need more sunlight.

-- SS

2/4/14 addendum:

HHS is apparently starting to pay attention to the importance of robust and secure EHR audit trails.

I note in the HHS document "Meaningful Use Stage 2, 2014 Edition EHR CERTIFICATION CRITERIA 45 CFR 170.314", page 7, regarding audit trails, available at this writing at http://www.healthit.gov/sites/default/files/meaningfulusetablesseries2_110112.pdf:

§170.314(d)(2) Auditable events and tamper-resistance.

(i) Record actions. EHR technology must be able to:
(A) Record actions related to electronic health information in accordance with the standard specified in § 170.210(e)(1);
(B) Record the audit log status (enabled or disabled) in accordance with the standard specified in § 170.210(e)(2) unless it cannot be disabled by any user; and
(C) Record the encryption status (enabled or disabled) of electronic health information locally stored on end-user devices by EHR technology in accordance with the standard specified in § 170.210(e)(3) unless the EHR technology prevents electronic health information from being locally stored on end-user devices (see 170.314(d)(7) of this section).

(ii) Default setting. EHR technology must be set by default to perform the capabilities specified in paragraph (d)(2)(i)(A) of this section and, where applicable, paragraphs (d)(2)(i)(B) or (d)(2)(i)(C), or both paragraphs (d)(2)(i)(B) and (C).

(iii) When disabling the audit log is permitted. For each capability specified in paragraphs (d)(2)(i)(A), (B), and (C) of this section that EHR technology permits to be disabled, the ability to do so must be restricted to a limited set of identified users.

(iv) Audit log protection. Actions and statuses recorded in accordance with paragraph (d)(2)(i) must not be capable of being changed, overwritten, or deleted by the EHR technology.

(v) Detection. EHR technology must be able to detect whether the audit log has been altered. 

From a posting at http://healthcaresecprivacy.blogspot.com/2012/09/meaningful-use-stage-2-audit-logging.html:

... The Information that needs to be recorded: § 170.210(e)(1)(i):  These rules [in a column I did not show here - ed.] identify “sections 7.2 through 7.4, 7.6, and 7.7 of the standard specified”. This is simply the list of attributes that an audit log entry should contain that ASTM E2147 says are mandatory, and excludes the values it outlines as important but not mandatory. Below is about 90% of what is in section 7, I didn't want to copy all of it out of respect for the copyright. But, the part missing is just a one-line definition of each item, nothing more than that.
7. Audit Log Content
7.1 Audit log content is determined by regulatory initiatives, accreditation standards, and principles and organizational needs. Information is needed to adequately understand and oversee access to patient identifiable data in health information systems in order to perform security oversight tasks responsibly.
Logs must contain the following minimum data elements:
7.2 Date and Time of Event
7.3 Patient Identification
7.4 User Identification
7.5 Access Device (optional)
7.6 Type of Action (additions, deletions, changes, queries, print, copy)
7.7 Identification of the Patient Data that is Accessed(optional)
7.8 Source of Access (optional unless the log is combined from multiple systems or can be indisputably inferred)
7.9 Reason for Access (optional)
7.10 If capability exists, there should be recognition that both an electronic “copy” operation and a paper “print” operation are qualitatively different from other actions.

I am not sanguine about the "optional" components, especially 7.7 - the actual data that was accessed and acted upon.

I also note it is stunning that these audit trail 'rules' have only been promulgated recently.  It will be interesting to see how rigorous the EHR "certification" process will be regarding audit trails.

-- SS

Monday, November 4, 2013

What Me Worry? - American Legacy Foundation Executives' Relaxed Response to a $3 Million Plus Fraud

A Washington Post investigation into diversion of money from US not-for-profit organizations provided a striking case study showing the apparently relaxed approach taken by managers to apparent wrongdoing by one of their own. 

Background: the American Legacy Foundation

The Post noted that

The American Legacy Foundation is a revealing case study. While some challenges it faced were uncommon, fraud examiners said many resemble those they see time and again. Legacy was founded as a nonprofit organization in 1999 out of the Master Settlement Agreement that resolved health claims brought against cigarette companies on behalf of the public by authorities in 46 states and the District.

With $50 million in annual expenditures and $1 billion in assets, Legacy is perhaps best known for its edgy anti-tobacco advertising campaign known as 'Truth.'

The Foundation's governance is provided by some top government leaders, including leaders of law enforcement.


Its board includes Idaho Attorney General Lawrence Wasden (R), its chairman; Missourci Gov. Jay Nixon (D), Utah Gov Gary R Herbert (R), and Iowa Attorney General Tom Miller (D).  Janet Napolitano, the recently departed U.S. secretary of homeland security, served on the board, and Sen Thomas R. Carper (D-Del) was Legacy’s founding vice chairman.

Outline of a Diversion

The alleged culprit at the ALC  was

Deen Sanwoola, ... a charismatic computer specialist who was Legacy’s sixth hire. He was tasked with building the organization’s information technology department.

No one realized, during Legacy’s frenetic early days, that the department had been formed without adequate financial controls, Legacy officials said. Or that Sanwoola had been placed in charge of both ordering electronic equipment and logging it as having been received — a mix of responsibilities that an outside auditor later described as a classic error that placed Legacy at risk.

So,

After Sanwoola’s arrival in October 1999, Legacy’s IT department began spending freely on computers, monitors and software, much of it purchased from a single company in suburban Maryland, [Legacy President and CEO Cheryl] Healton said.

Thanks to the court settlement, Legacy enjoyed a tremendous flow of cash, with revenue exceeding $320 million. The first questionable purchase came in December 1999, according to a forensic audit conducted years later. 'The fraudulent billing started almost immediately on his arrival,' said [Idaho Attorney General Lawrence] Wasden, the board chairman.

In that first transaction, the foundation paid more than $18,000 for a computer processor and related equipment that auditors concluded should have retailed for less than $7,000.

Data, documents and a summary of findings that Wasden provided to The Post show that questionable purchases of printers, software and servers steadily increased in size and frequency, peaking with 49 charges in 2006. In some instances, Legacy appeared to have paid many times an item’s worth, auditors said. In others, auditors said Legacy paid an inflated price for 'phantom purchases' of equipment that apparently never arrived.

Over years, Sanwoola is thought to have generated as many as 255 invoices for computer equipment sold to the foundation, Legacy officials said; 75 percent of them later were deemed by the foundation to have been fraudulent. 

A Relaxed Response

Sanwoola left AFC in 2007,

In early 2007, Sanwoola, by then an assistant vice president with a $180,000 compensation package, announced he was leaving. It jolted [AFC President and CEO Cheryl] Healton, who said she 'begged' him to stay. [ALC CFO Anthony T[ O’Toole recalled Sanwoola saying that his wife wanted to raise their children in Nigeria and that the move would allow him to help his ailing mother.

But then,

six months later, when an executive at Legacy approached O’Toole and told him he was unable to locate computer equipment listed in the inventory.  O’Toole said he waved away the complaint without bothering to investigate.

'He just pooh-poohed it,' Healton said of O’Toole, who received current and deferred compensation totaling $568,000 in fiscal 2012.

The Post previously noted that

Sanwoola developed close personal ties to Legacy’s chief financial officer, Anthony T. O’Toole.

'Everybody loved Deen,' O’Toole acknowledged.

After a second complaint, managers took a bit more notice,

Three years later, the same employee — Legacy officials describe him as a whistleblower — again raised an alarm. This time, he bypassed O’Toole and took his concerns to a staffer close to Healton.

The response this time was different. Within days, Legacy hired forensic examiners to investigate and Healton notified the board.

One of the outside auditors’ first reactions, Healton recalled, was, 'There’s no way an organization like yours could spend this much on IT.'

Auditors interviewed employees, reviewed invoices and recovered deleted files from a backup computer server in Chicago. Auditors found a template for invoices from the outside supply company, Legacy officials said, as well as computer code that showed the template had been designed and generated by someone using Sanwoola’s log-in.

Officials concluded that of $4.5 million in checks and credit card charges associated with the Maryland IT supply company, $3.4 million had been fraudulent.


 In late 2010 or early 2011,

foundation executives asked Miller, the Iowa attorney general on Legacy’s board, to call the office of the U.S. attorney.

However, despite the fact that it was ALC money that had been lost, ACL managers thereafter seemed to take little interest in the case,

Legacy officials said they had made no attempt to contact Sanwoola, based on a request from federal prosecutors. In a statement for this article, the U.S. Attorney’s Office responded that they had made no such request.

They also were in no hurry to disclose the foundation's loss,

Word that millions of dollars were thought to be missing remained largely within Legacy until it came time in 2011 to file its annual disclosure, a public document signed under penalty of perjury.

The disclosure said that the 'fraud' of more than $250,000 did not 'meet other materiality tests for financial reporting' and that the organization had told its board and law enforcement. It also said Legacy had filed an insurance claim that had been 'successfully settled.' The document did not reveal that the settlement fell far short of the loss.

When first approached by The Post, Legacy general counsel Ellen Vargyas said the organization had no obligation to identify the full estimate of the loss and stressed that more information was in the foundation’s 2012 filing. That filing included a reference to $1.3 million in miscellaneous revenue from an insurance settlement, without saying what it was for.

'I do think it was a full and appropriate disclosure,' Vargyas said.

Legal specialists consulted by The Post disagreed. 'Those suffering a diversion are obligated to report the dollar amount,' said Gary R. Snyder, a charity consultant who tracks fraud.

Federal filing instructions direct nonprofits to 'explain the nature of the diversion, amounts or property involved . . . and pertinent circumstances.' Charity specialists said there is no established penalty for a nonprofit that fails to follow the instructions.

A day after declining to disclose the amount to The Post, Vargyas reconsidered. 'Our best estimate of the full loss comes to this: $3,391,648,' she wrote in an e-mail. She said her initial reluctance to disclose an amount was because Legacy’s number was based on estimates that had 'never been tested in a court of law.

Wasden added that the absence of a total dollar figure in its public filing was the foundation’s way of being restrained in describing its loss, in deference to the then-continuing federal investigation. The U.S. Attorney’s Office stressed, however, that it did not suggest that Legacy play down the size of the loss in its disclosure.

Legacy officials said they were told in March, for the first time, that there would be no charges. The U.S. Attorney’s Office disputed that, saying the FBI informed Legacy in February 2012 that the investigation had been closed because, despite warnings, Legacy had taken more than three years to report the missing computers and lacked reliable records of what it owned.

It appears that there will be no further action in this case.  The statute of limitations has passed for any further criminal or civil actions, according to the Post.  And Mr Sanwoola seems to be comfortably ensconced in Lagos, Nigeria.

 Summary

The American Legacy Foundation case showed that a "charismatic" management insider (who finished his career as an assistant vice president with a $180,000 compensation package according to the Post), who had "close personal ties" with the organization's CFO (who "received current and deferred compensation totaling $568,000 in fiscal 2012" according to the Post), was apparently able to embezzle something like $3.4 million dollars, then walk away.  Initial whistleblowing was ignored by the CFO (who received compensation of $729,000 in 2012 according to the Post), apparently delaying any action for three years.  A second complaint to the CEO provoked a response, but not exactly an urgent one.  While law enforcement was notified, there is no evidence that any foundation managers followed up on it, nor did they see fit to disclose much detail about the loss on their watch.  As a result, no one seems to have been held responsible, and only some money was recovered, but from insurance.

Now we understand why these managers made the relatively big bucks.

By the way, the Post article included a link to a database of other diversions of money from non-profit organizations, including many prominent health care organizations (e.g., Memorial Sloan-Kettering Cancer Center, Children's Hospital of Pennsylvania, NYU Hospitals Center, Shands Jacksonville Medical Center, Harvard Medical School Faculty Physicians at Beth Israel Deaconess Hospital, and the Society for Academic Emergency Medicine).  Whether the circumstances of the diversions they suffered were anything like those affecting the ALC is unknown pending further investigation of their disclosures.

Again, the top executives of a non-profit organization are supposed to put the organization's mission ahead of personal gain. Yet in this case, executives seemed more interested in keeping quiet about an apparent fraud by one of their own than in recovering the money or holding anyone accountable.

This is yet another instance of top leaders in health care seeming to be more loyal to "managers' guild" than their own organizations, their organizations' mission, or patients' and the public's health in general.   A while ago, chief architect of "managed competition," (and former architect of body counts during the Vietnam War, look here) Alain Enthoven admitted, but only to a European audience, that he wanted to end the influence of the "physicians' guild," which he blamed for rising health care costs, and turn health care over to managers (look here).  That "managers' coup d'etat" seems to have been accomplished.  The result, however, is that health care is now lead by people who seem sworn only to promote their own interests, while hiring public relations and marketing folks to make it appear otherwise.

While many people debate health care reform in terms of the details of health insurance, true health care reform would restore control of health care to people held accountable for putting patients' and the public's health ahead of their personal enrichment.  

Tuesday, September 17, 2013

UnitedHealth's Latest Blunders Include Lax Fraud Detection, Recalled EHRs - So Why is its CEO Worth $13.9 Million, or is it $34.7 Million?

We managed to go four months since our last post about UnitedHealth, but sure enough, the company that keeps on giving... examples of poor management to contrast with ridiculous management pay... has done so again.

There were two obvious examples of poor management that recently appeared in the media.

Lax Fraud Dection

The background, as noted in a Kaiser Health News article published in September, is that it is now fashionable for American states to outsource some or most of their Medicaid health insurance programs to managed care organizations, often for-profit, as is UnitedHealth.  These programs are meant to provide insurance to the poor and disabled.  Yet once they have outsourced Medicaid, the states may be reluctant to cancel contracts, even if the outsourcing is not working:

 In Florida, a national managed care company’s former top executives were convicted in a scheme to rip off Medicaid. In Illinois, a state official concluded two Medicaid plans were providing 'abysmal' care. In Ohio, a nonprofit paid millions to settle civil fraud allegations that it failed to screen special needs children and faked data.

Despite these problems, state health agencies in these - and other states - continued to contract with the plans to provide services to patients on Medicaid, the federal-state program for the poor and disabled.

Health care experts say that’s because states are reluctant to drop Medicaid plans out of fear of leaving patients in a bind.

'You probably won’t find many examples of states flat out pulling the plug. That’s sort of the nuclear option,' said James Verdier, a senior fellow at Mathematica Policy Research, a nonpartisan think tank. 
Never mind that leaving such programs as is means taking money meant to finance care for the poor and using it to finance fraud, and reward managed care organizations for failing to find fraud.

One of the examples, but not a new one, used in the Kaiser Health News article, involved UnitedHealth:


Linda Edwards Gockel, spokeswoman for the Texas Health and Human Services Commission, said that in 2009, officials were concerned about a pilot program in the Dallas-Fort Worth area run by Evercare, a subsidiary of UnitedHealth Group. The program, which coordinated care and long-term services for elderly and disabled people, had been fined more than $600,000 for not providing proper access to care and failing to coordinate services.

Gockel said Texas decided to cancel the contract 15 months early, but continued to do business with Evercare because the problems in Dallas-Fort Worth weren’t affecting services it was providing elsewhere.

Then in July, NJ.com reported an investigation by the state of New Jersey into UnitedHealth's ability, or lack thereof, to detect fraud in the Medicaid managed care program it runs for the state.

 An HMO that earned $1.7 billion from 2009 to 2010 by providing Medicaid coverage to 350,000 low-income and disabled New Jerseyans didn't try very hard to detect fraudulent billing — identifying only $1.6 million, or one-tenth of one percent in improper payouts, according to a report the Office of the State Comptroller released today.

UnitedHealth did not even come close to fulfilling its obligations to provide sufficient resources to fight fraud:


The HMOs in the Medicaid program are required to dedicate one investigator for every 60,000 Medicaid clients. At that ratio, United's special investigations unit should have been comprised of about six employees whose sole focus is to detect fraud and abuse by medical providers and patients.

Instead, United reported it had dedicated the equivalent of two investigators during the two-year study period based on the amount of hours devoted to the unit. Upon scrutiny, the comptroller found United 'overstated' its staffing levels; the unit had one investigator, the report said. 

Note that this abject failure appeared to violate the contract UnitedHealth had with the state,

UnitedHealthcare Community Plan of New Jersey failed to hire enough investigators and train them properly, in violation of the managed care company's contract with the state, according to the report. 

Presumably, if fraud led to excess program expenses, it would be New Jersey, not UnitedHealth who ultimately had to pay them.  Again, it appears that money meant of pay for health care for the poor and disabled was diverted to fraudsters, and to revenue for UnitedHealth (partly because the latter did not see fit to spend enough money up front to detect the fraud.)  Of course, such management by UnitedHealth helped to increase its already fat revenue stream.

Faulty Electronic Health Records

In September, Bloomberg reported that UnitedHealth had to recall electronic health record software because of faults that likely increased the risk of bad patient outcomes,

UnitedHealth Group Inc has recalled software used in hospital emergency departments in more than 20 states because of an error that caused doctor’s notes about patient prescriptions to drop out of their files.

Certain versions of the software made by the largest U.S. health insurer had a bug that didn’t print information related to the medication and failed to add data to patients’ charts,according to a document filed with the U.S.Food and Drug Administration and posted July 29.

The technology is used in 35 facilities in states including California, New Jersey, and Florida, the document shows. The recall began June 21. There were no reports of patient harm and each facility was notified and received a digital fix, said Kyle Christensen, a spokesman for the UnitedHealth division that makes the Picis ED PulseCheck software that was recalled.

The incident shows how software errors can create dangers for patients at a time when digital health records are being implemented as a cornerstone of President  Barack Obams's modernization of the nation’s health-care system.

The "bug" could potentially harm patients,

 Doctor’s notes are critical for some medications, as they contain directions about diet and use. Failure to include the instructions could lead to serious injury or death, [University of Pennsylvania adjunct professor of sociology and medicine Ross] Koppel said.

It turns out that the Picis software has had other problems that could have increased the risk of harm to patients,


An online database maintained by the FDA shows that Picis Inc., a Wakefield, Massachusetts-based company that UnitedHealth acquired in 2010 for an undisclosed price, has reported six recalls involving electronic health record software since 2009.

One incident in 2011 involved anesthesia-management software sold nationwide that in one instance displayed a patient’s medical information in another patient’s file. Anotherinvolved software sold worldwide where on an unspecified number of occasions, the program failed to display the discontinued status on medication orders. Others included glitches that caused a failure to display appropriate allergy interaction warnings, the freezing of administrative controls, and other issues.

Note that it is the same Picis software that our blogger, InformaticsMD, has alleged lead to the death of his mother,


Alleged flaws in electronic health records have led to lawsuits. Scot Silverstein, a doctor and health-care informatics professor at  Drexel University, sued Abington Memorial Hospital in Pennsylvania in 2011 over the death that year of his 84-year-old mother. He blamed her death on a flaw in her electronic health record that he claims caused a critical heart medication to vanish from her file. One of the systems involved was made by Picis, according to his lawsuit. Picis is not being sued.

Linda Millevoi, a spokeswoman for Abington Memorial, declined to comment.

The latest InformaticsMD posts on this case are here and here.

Summary

These cases are just the latest in a long list of blunders and ethical missteps made by UnitedHealth and its top management.  The most significant examples of the latter about which we have posted appear in the appendix at the end.  The latest examples likely diverted money that should have supported health care for the poor, and and may have put patients' health and lives at risk.

Yet UnitedHealth is now the largest US health insurance company, and it has succeeded in making its current and former CEO fabulously wealthy.  According to filings with the US Security and Exchange Commission (SEC), its current CEO, Stephen J Hemsley, got $13.9 million in 2012, up from $13.4 million in 2011, as we posted here.  However, an analysis by the Minneapolis Star-Tribune that took into account stock gains and shares vesting suggested he got $34,721,122 in 2012, admittedly down from a breathtaking $48,075,614 in 2011. 

The previous UnitedHealth once was worth over a billion dollars due to back dated stock options, some of which he had to give back, but despite all the resulting legal actions, was still the ninth best paid CEO in the US for the first decade of the 21st century (look here).

So UnitedHealth continues to provide us with examples of how top leaders of health care organizations can become tremendously rich, despite, or perhaps because of repeated mismanagement and apparently unethical management on their watches.  Only when we make health care leaders truly accountable for their organizations, and especially for their organizations' ethics and effects on patients' and the public's health will be begin to challenge health care dysfunction.

(Note to readers recently joining us from countries other than the US - UnitedHealth is a multi-national that claims to operate in 33 countries (look here).  For example, its UK web-site is here.  So beware the export of bad management for enhanced prices.) 

 
Appendix - UnitedHealth's Ethical Lapses

 - as reported by the Hartford Courant, "UnitedHealth Group Inc., the largest U.S. health insurer, will refund $50 million to small businesses that New York state officials said were overcharged in 2006."
- UnitedHalth promised its investors it would continue to raise premiums, even if that priced increasing numbers of people out of its policies (see post here);
- UnitedHealth's acquisition of Pacificare in California allegedly lead to a "meltdown" of its claims paying mechanisms (see post here);
- UnitedHealth's acquisition of Sierra Health Services allegedly gave it a monopoly in Utah, while the company allegedly was transferring much of its revenue out of the state of Rhode Island, rather than using it to pay claims (see post here)
- UnitedHealth frequently violated Nebraska insurance laws (see post here);
- UnitedHealth settled charges that its Ingenix subsidiaries manipulation of data lead to underpaying patients who received out-of-network care (see post here).
- UnitedHealth was accused of hiding the fact that the physicians it is now employing through its Optum subsidiary in fact work for a for-profit company, not directly for their patients (see post here).