Showing posts with label health IT risk. Show all posts
Showing posts with label health IT risk. Show all posts

Friday, February 28, 2014

Patient Safety & Quality Healthcare: "Malpractice Claims Analysis Confirms Risks in EHRs"

Two "EHR beneficence is not exactly as advertised" stories in one day.  It's hard to keep up:

After my earlier post today "EHRs: The Real Story" - Sobering assessment from Medical Economics, now there's this.

From the journal "Patient Safety & Quality Healthcare" (PSQH):

Malpractice Claims Analysis Confirms Risks in EHRs
Jan/Feb 2014

Article available at this link.

[Short header on several EHR-related care foul ups]

... Distressing situations like those described above are happening around the country as healthcare organizations adopt electronic health records (EHRs) in growing numbers. Although these systems promise to reduce costs and improve quality and safety, they’ve also ushered in unintended consequences as a result of human error, design flaws, and technology glitches.

Recognizing these emerging risks, CRICO—the patient safety and medical malpractice insurer for the Harvard medical community— is taking action. The Massachusetts-based company has expanded its proprietary coding system to capture EHR-related problems that have contributed to patient harm, and to guide the hospitals, physicians, and other providers it serves toward addressing vulnerabilities in their systems.

I had previously written about another Med Mal insurer who had noted these problems at http://cci.drexel.edu/faculty/ssilverstein/cases/?loc=cases&sloc=norcal.

... CRICO recently analyzed a year’s worth of medical malpractice claims in its comparative database and found 147 cases in which EHRs were a contributing factor. Computer systems that don’t “talk” to each other, test results that aren’t routed properly, and mistakes caused by faulty data entry or copying and pasting were among the EHR-related problems found in the claims, which represented $61 million in direct payments and legal expenses.

The article notes this:

... Half of the 147 cases resulted in severe injury.

Patient deaths were a likely result, too, I note.

Note that this is just one insurer's data and assuming a good number of them were local to Massachusetts, could represent a significant percentage of the annual medical malpractice lawsuits in the state (Pennsylvania, a much larger state, has about 1500 med mal lawsuits filed annually). 

Note also that most cases of harm never make it to litigation due to the harsh economics of medical malpractice.

Numbers such as this will be going up as implementation, driven by HITECH incentives and penalties, accelerates in coming years.  This is especially true as medical centers and physician practices with far less clinical IT expertise and savvy than Harvard's become HIT users, and as the ability to capture such events increases.

The ECRI Institute "Deep Dive" study of health IT risk also speaks to a rise in numbers, with its finding of 171 health IT "events" in just 36 hospitals over 9 weeks voluntarily reported (i.e., just a fraction of the total), with 8 injuries and 3 possible deaths as a result (http://hcrenewal.blogspot.com/2013/02/peering-underneath-icebergs-water-level.html).

... The team asked its CRICO and Strategies members, “What vulnerabilities are you seeing? What are your risk managers worried about? What are your doctors complaining about?”

It used that feedback to draft a set of EHR-specific codes and then tested them in three datasets: CRICO (Harvard users) and two of Strategies’ larger clients, !e Doctors Company and Princeton Insurance. Based on those results, CRICO revised and approved 15 new EHR codes that went “live” in January 2013.

That means CRICO’s cadre of nurse coders can now identify EHR as a contributing factor to a malpractice claim, instead of using one of the less specific factors available in the past. [It's about time for a dose of transparency in the health IT sector - ed.]  And they can flag whether the problem involved user issues, system/technology issues, or both. “In some cases,” Sato points out, “the system design sets up humans to make errors.”

This should all be no surprise to any reader of this blog.  Read the whole article.

A more comprehensive list of "EHR harm modes" are at my posts "Internal FDA memorandum of Feb. 23, 2010 to Jeffrey Shuren on HIT risks. Smoking gun? I report, you decide" (http://hcrenewal.blogspot.com/2010/08/smoking-gun-internal-fda-memorandum-of.html) and "Cart Before the Horse, Part 3: AHRQ's Health IT Hazard Manager" (http://hcrenewal.blogspot.com/2012/06/cart-before-horse-part-3-ahrqs-health.html).

The actual Hazards Manager report is at http://healthit.ahrq.gov/sites/default/files/docs/citation/HealthITHazardManagerFinalReport.pdf. It contains this summary of known hazards:


AHRQ's taxonomy of health IT hazards.  Click to enlarge.

-------------------

Having written on these issues since 1998 as a "health IT iconoclast" (http://rtg.cis.upenn.edu/MDCPS/Posters/IT%20Iconoclasts.pdf) and having been largely ignored by the cognoscenti, can I now say "I told you so?"

-- SS

Thursday, February 20, 2014

Computer woes hit Banner hospital system: Another large EHR outage ... but patient safety was not compromised

Here is yet another story in the genre of "EHRs go out, but patient care has not been compromised." (See query link at http://hcrenewal.blogspot.com/search/label/Patient%20care%20has%20not%20been%20compromised; there are more than 20 posts there now):

Computer woes hit Banner hospital system
Ken Alltucker, The Arizona Republic 12:30 a.m. EST February 20, 2014
http://www.usatoday.com/story/news/nation/2014/02/19/computer-woes-slam-banner-hospital-system/5630829/

The Phoenix-based health system used backup paper records to help provide patient care.

PHOENIX -- Banner Health grappled with a widespread computer outage Wednesday as hospitals and doctors resorted to backup paper systems to provide care for patients.

The Phoenix-based health system did not immediately know what triggered the computer troubles that started just before 10 a.m. PST. An official described the computer troubles as a rolling outage of computer systems at hospitals and other health care facilities in Phoenix, Colorado and Nevada.

"Not knowing" means that you are not in control of your life-critical information systems; rather, they are in control of you.

By late Wednesday, a spokesman said, technicians had identified the problem and were fixing it. They expect to investigate the root cause of the problem Thursday.

It took from 10 AM to "late Wednesday" to identify a problem causing a mass outage.  That should give anyone pause about dependency on fragile information systems in the hands of hospital IT departments (whose personnel undergo an ocean's less qualification-vetting than the medical personnel who depend on their work product) for one's medical care.

Banner Health, the Phoenix area's largest health care system, activated "downtime procedures" that included using paper-based systems to track medications and other care provided to patients, officials said.

Banner's emergency departments still provided care to patients and accepted new patients.

Some non-emergency surgeries and appointments were delayed because of the computer troubles.

"There have been some delays and inconveniences, but we are still providing care," said Bill Byron, Banner Health's senior vice president of public relations.

In other words, what they are saying is "we really don't need these systems, that cost hundreds of millions of dollars, to provide care with the same degree of safety as with our 'downtime procedures' (a.k.a. paper)" ... and that patient safety was not compromised by this mass outage.

Banner Health, which operates 24 hospitals and several primary-care offices and outpatient centers in more than a half-dozen states, was working to "reboot" the computer systems Wednesday evening through a series of sequential fixes, Byron said.

In the meantime, Banner officials were able to retrieve computer-based records that detailed patients' medical histories, including any medications, laboratory results and procedures that were previously performed.

Officials?  What about line clinicians?  And when did this capability start if the systems needed to be "rebooted?"

Nurses and doctors shifted to writing on paper records after the computer systems experienced trouble Wednesday morning.

Information from those paper charts will be keyed into the patients' computer-based health records after the problem is fixed.

Sure, and nothing will be lost that could adversely affect patients in the future....

Banner Health has been among the most advanced health systems in the nation in converting to computer-based health records.

Banner Estrella Medical Center was among the first hospitals to open as an "all-digital" facility in the past decade. Banner's other hospitals have largely completed the final stages of installing computerized record-keeping in areas such as physician order and entry and electronic documentation.

If they are the most advanced, what does this event say about those less advanced?

Arizona law does not require hospitals to notify state health regulators in the event of such a widespread outage.

Health IT, as usual, enjoys widespread and extraordinary regulatory accommodation.

However, some hospitals have internal policies requiring that they notify health accrediting organizations or federal regulatory agencies, such as the Centers for Medicare and Medicaid Services, an Arizona Department of Health Services spokeswoman said.

And how many do?  Not many, I predict.

-- SS

Thursday, February 14, 2013

Bipartisan Policy Center's Health Innovation Initiative: Health IT Industry Officials Lying to Regulators With Impunity?

On Wednesday, February 13, 2013, The Bipartisan Policy Center's Health Innovation Initiative held a discussion on its new report: An Oversight Framework for Assuring Patient Safety in Health Information Technology.  The announcement is here:  https://bipartisanpolicy.org/news/press-releases/2013/02/bipartisan-policy-center-releases-recommendations-oversight-framework-pa

The report is here (PDF):  "An Oversight Framework for Assuring Patient Safety in Health Information Technology."

The "who's" of the Bipartisan Policy Center's Health Innovation Initiative included these people:

  • Senator Tom Daschle, Former U.S. Senate Majority Leader; Co-founder, Bipartisan Policy Center (BPC); and Co-leader BPC Health Project Carolyn M. Clancy, M.D., Director, Agency for Healthcare Research and Quality, Department of Health and Human Services
  • Farzad Mostashari, M.D., ScM, National Coordinator for Health Information Technology, Department of Health and Human Services
  • Peter Angood, M.D., Chief Executive Officer, American College of Physician Executives
  • Russ Branzell, Chief Executive Officer, Colorado Health Medical Group, University of Colorado Health
  • John Glaser, Ph.D., Chief Executive Officer, Siemens Health Services
  • Douglas E. Henley, M.D., FAAFP, Executive Vice President and Chief Executive Officer, American Academy of Family Physicians
  • Jeffrey C. Lerner, Ph.D., President and Chief Executive Officer, ECRI Institute
  • Ed Park, Executive Vice President and Chief Operating Officer, athenahealth
  • Emad Rizk, M.D., President, McKesson Health Solutions
  • Janet Marchibroda, Moderator; Director, BPC Health Innovation Initiative 

Unfortunately, I was unable to attend.  I was at the 2013 Annual Winter Convention of the American Association for Justice (Trial Lawyer's Association) in Florida, as an invited speaker on health IT risk, its use in evidence tampering, and other legal issues.


"United for Justice" - click to enlarge



I found the following statement from the Bipartisan Policy Center's Health Innovation Initiative report remarkable as a "framework for health IT safety":

The Bipartisan Policy Center today proposed an oversight framework for assuring patient safety in health information technology. Among other guiding principles, the framework should be risk-based, flexible and assure patient safety is a shared responsibility, the authors said. “Assuring safety in clinical software in particular is a shared responsibility among developers, implementers, and users across the various stages of the health IT life cycle, which include design and development; implementation and customization; upgrades, maintenance and operations; and risk identification, mitigation and remediation,” the report states. Among other recommendations, the center said clinical software such as electronic health records and software used to inform clinical decision making should be subject to a new oversight framework, rather than traditional regulatory approaches [e.g.,  FDA - ed.] applied to medical devices given its lower risk profile.

I find it remarkable that the health IT industry and its supporters now feel they can lie to our government and regulatory agencies with impunity.  Stating that health IT has a "lower risk profile" is an example.

One cannot know what is acknowledged to be unknown.

From the Institute of Medicine in its 2012 report on health IT safety:

Institute of Medicine. 2012. Health IT and Patient Safety: Building Safer Systems for Better Care .  Washington, DC: The National Academies Press.

... While some studies suggest improvements in patient safety can be made, others have found no effect. Instances of health IT–associated harm have been reported. However, little published evidence could be found quantifying the magnitude of the risk.

Several reasons health IT–related safety data are lacking include the absence of measures and a central repository (or linkages among decentralized repositories) to collect, analyze, and act on information related to safety of this technology. Another impediment to gathering safety data is contractual barriers (e.g., nondisclosure, confidentiality clauses) that can prevent users from sharing information about health IT–related adverse events. These barriers limit users’ abilities to share knowledge of risk-prone user interfaces, for instance through screenshots and descriptions of potentially unsafe processes. In addition, some vendors include language in their sales contracts and escape responsibility for errors or defects in their software (i.e., “hold harmless clauses”). The committee believes these types of contractual restrictions limit transparency, which significantly contributes to the gaps in knowledge of health IT–related patient safety risks. These barriers to generating evidence pose unacceptable risks to safety.

... More worrisome, some case reports suggest that poorly designed health IT can create new hazards in the already complex delivery of care. Although the magnitude of the risk associated with health IT is not known, some examples illustrate the concerns. Dosing errors, failure to detect life-threatening illnesses, and delaying treatment due to poor human–computer interactions or loss of data have led to serious injury and death.” 

Even to those with particularly thick skulls, this statement seems easy to comprehend:

"The magnitude of the risk associated with health IT is not known."

I repeat once again:

One cannot know what is acknowledged to be unknown.

A statement that health IT has a "lower risk profile" compared to other regulated healthcare sectors such as devices or drugs, in order to seek continued and extraordinary regulatory accommodations, is remarkable.  It is either reckless regarding something that the statement's makers should know, or should have made it their business to know - or a deliberate prevarication with forethought.

The report did attempt to shroud the declarative "lower risk profile" in a sugar coating through misdirection, citing the need to take into account "several factors" including:

"the level of risk of potential patient harm, the degree of direct clinical action on patients, the opportunity for clinician involvement, the nature and pace of its development, and the number of factors beyond the development stage that impact its level of safety in implementation and use." 

These "factors" speak to a higher level of potential risk, not lower, and are a justification for stronger regulatory oversight, not weaker.  I would opine that there is a possibility that health IT. through which almost all transactions of care need to pass (e.g., orders, results reporting, recording and review of observations, finding, diagnoses, prognoses, treatment plans, etc.), could have a higher risk profile than one-off devices or drugs.  Health IT affects every patient, not just those under a specific therapy or using a specific device or drug.

Partial taxonomies developed from limited data themselves speak to the issue of a potentially huge risk profile of health IT, e.g., the FDA Internal Memo on HIT Risks (link), the AHRQ Hazards Manager taxonomy (link), and the sometimes hair-raising voluntary defects reports (largely from one vendor) in the FDA MAUDE database (link).  Further, health IT can and does affect thousands or tens of thousands of patients en masse even due to one simple defect, such as happened in Rhode Island at Lifespan (link), or due to overall design and implementation problems such as at Contra Costa County, CA (link) and San Francisco's Dept. of Public Health (link).

We don't know the true levels of risk and harm - but we need to, and rapidly.  Industry self-policing is not the answer; it didn't work in drugs and devices, and even with regulation there are still significant problems in those sectors.  (Imagine how it would be if those sectors received the special accommodations that health IT receives, and wishes to continue to receive.)

My other issue is with the "shared responsibility" including "users."

The user's responsibility is patient care, not being a beta tester for bug-laden or grossly defective health IT products.  Their responsibility ends at reporting problems without retaliation, and ensuring patient safety.

Their responsibility is to avoid carelessness - as it is when they drive their cars.

In other words, the inclusion of "users" in the statement is superfluous.

It is not a responsibility to be omniscient and be held accountable when bad health IT promotes "use error" (the NIST definition of "use error" I will not repeat again here; search the blog) -- as opposed to and as distinct from "user error" - note the final "r" - i.e., carelessness.

Bad health IT (see here):

Bad Health IT ("BHIT") is defined as IT that is ill-suited to purpose, hard to use, unreliable, loses data or provides incorrect data, causes cognitive overload, slows rather than facilitates users, lacks appropriate alerts, creates the need for hypervigilance (i.e., towards avoiding IT-related mishaps) that increases stress, is lacking in security, compromises patient privacy or otherwise demonstrates suboptimal design and/or implementation. 

One special accommodation that the health IT industry has been afforded for far too long is to be able to "blame the user."

"Blaming the victim" of bad health IT is a more appropriate description.

-- SS