Showing posts with label healthcare IT dangers. Show all posts
Showing posts with label healthcare IT dangers. Show all posts

Wednesday, June 11, 2014

Canada: Province-wide electronic medical record computer system 'glitch' causing patients to be turned away from care

This story describes a very bad scenario for sick Canadians.  I offer just a few pithy comments, as not much more than that is needed:

http://medicinehatnews.com/news/local-news/2014/06/10/system-failure-has-docs-patients-upset/
System failure has docs, patients upset

By Gillian Slade on June 10, 2014

Many patients were turned away from their doctor’s office Monday because a province-wide electronic medical record computer system had collapsed.

Province-wide.  Stunning.  A very big argument against centralization of EHR resources.

“This is the third straight week of issues with the TELUS Wolf system,” said Dr. Donovan Nunweiler at Southlands Medical Clinic. “We feel we were encouraged by government to switch to Wolf and now it’s not working.”

I wonder when someone in the Canadian government is  going to issue that now-famous slogan "but patient safety has not been compromised"...

A year ago 202 physician clinics across Alberta using TELUS Wolf were unable to access patient records for most of the day.

More than 200 physician clinics are blind, deaf and dumb?  Wonder what happens to acute patients on days like that.

On Monday patients arrived only to be told the electronic patient files were not accessible making it impossible to see test results, past medical history and medications.

Paper never goes on strike.  Perhaps elimination of paper completely is not such a good idea?

“This is affecting me big time and affecting my income,” said Ken Hoeppner, a patient at HealthWORX Medical clinic, who had waited 15 days for his appointment. “Every time government touches something they wreck it. Our health care used to be good here before Alberta Health Services took over.”

No comment.

At HealthWORX, office manager Carel Liebenberg said the office was doing what it could to reschedule people. One patient had driven three hours to be there for his appointment early Monday.

It's just a "glitch", sir or madam.  Stop complaining. (http://hcrenewal.blogspot.com/search/label/glitch)

At Health Matters Medical Clinic, staff confirmed they too were dealing with no access to patients’ records on TELUS’s Wolf system.

Originally to encourage physicians to move to electronic medical records, the government gave a monetary incentive. Alberta Health selected TELUS Health Solutions Wolf EMR after a request for proposals in 2008.

There was a requirement for the service to be available 99.9 per cent of the time between 6 a.m. and midnight with financial penalties for failure to do so.

“There is no longer any government support,” said Nunweiler. “We (Southlands Medical Clinic) pay $2,000 a month for this. Who is going to hold TELUS accountable now? The government has abandoned us. Cost and issues switching patient data, when systems are not compatible, prevents us from going somewhere else.”

Seems to be this TELUS:  https://www.telushealth.com/health-solutions/electronic-health-records-%28ehr%29.  Sounds like a monopoly to me.

On that page:

TELUS Electronic Health Records (EHR) provides a better way to share, access and consolidate information.

Without quick, secure access to complete and reliable information, healthcare provision can be inefficient, preventing patients from receiving the best care possible.

How ironic.

Liebenberg reached TELUS at 9 a.m. Monday.

“They said they had just become aware of the issue and that their data technicians were in a meeting discussing the problem,” said Liebenberg. “Last week the system was extremely slow, taking 15 minutes for a physician to simply renew a prescription.”

Data technicians were in a meeting?  Sounds like a fantastic way to respond to a Province-wide medical emergency.

Nunweiler said he’d made notes on paper as he struggled to manage the snail’s pace of the system last week. Monday he would be adding to those notes and envisaged several hours at night entering the data to make it current.

Paper never goes on strike.

Liebenberg said the need to re-schedule appointments reflects badly on the clinic and some patients don’t understand it’s a system failure beyond the clinic’s.

That's just great for patient-physician relations.

Dr. Franz Yonker said HealthWORX had been using JonokeMed but the government endorsed TELUS Wolf and physicians were encouraged to switch.

“I think this is really bad for a government-backed system,” said Yonker.

"Wolf" is a somewhat humorous name considering these problems.  As in, a predatory EHR ... one wonders just how much better the others are.

Becky Nelson arrived for her appointment to refill prescriptions and was concerned about how long it would take to get another appointment.

“The government needs to get this on track. We are suffering the consequences,” said Nelson.

I wonder if any patients will suffer the ultimate consequence.  (Hint to Canadians:  never become too dependent on the Government.  Stuff like this happens.)

Donna Schneider brought her mother Vernie Ferguson in for results of some tests. Ferguson said she was not at all well.

“There is nowhere else to go and get my test results,” said Ferguson.

Held medical hostage to bad health IT.  How horrible.

The News requested an interview with TELUS but there was no response on Monday afternoon.

The News requested information from Alberta Health but that was not available on Monday.

Perhaps they're busy, in meetings discussing how to fix the problem.

-- SS

Friday, February 28, 2014

Patient Safety & Quality Healthcare: "Malpractice Claims Analysis Confirms Risks in EHRs"

Two "EHR beneficence is not exactly as advertised" stories in one day.  It's hard to keep up:

After my earlier post today "EHRs: The Real Story" - Sobering assessment from Medical Economics, now there's this.

From the journal "Patient Safety & Quality Healthcare" (PSQH):

Malpractice Claims Analysis Confirms Risks in EHRs
Jan/Feb 2014

Article available at this link.

[Short header on several EHR-related care foul ups]

... Distressing situations like those described above are happening around the country as healthcare organizations adopt electronic health records (EHRs) in growing numbers. Although these systems promise to reduce costs and improve quality and safety, they’ve also ushered in unintended consequences as a result of human error, design flaws, and technology glitches.

Recognizing these emerging risks, CRICO—the patient safety and medical malpractice insurer for the Harvard medical community— is taking action. The Massachusetts-based company has expanded its proprietary coding system to capture EHR-related problems that have contributed to patient harm, and to guide the hospitals, physicians, and other providers it serves toward addressing vulnerabilities in their systems.

I had previously written about another Med Mal insurer who had noted these problems at http://cci.drexel.edu/faculty/ssilverstein/cases/?loc=cases&sloc=norcal.

... CRICO recently analyzed a year’s worth of medical malpractice claims in its comparative database and found 147 cases in which EHRs were a contributing factor. Computer systems that don’t “talk” to each other, test results that aren’t routed properly, and mistakes caused by faulty data entry or copying and pasting were among the EHR-related problems found in the claims, which represented $61 million in direct payments and legal expenses.

The article notes this:

... Half of the 147 cases resulted in severe injury.

Patient deaths were a likely result, too, I note.

Note that this is just one insurer's data and assuming a good number of them were local to Massachusetts, could represent a significant percentage of the annual medical malpractice lawsuits in the state (Pennsylvania, a much larger state, has about 1500 med mal lawsuits filed annually). 

Note also that most cases of harm never make it to litigation due to the harsh economics of medical malpractice.

Numbers such as this will be going up as implementation, driven by HITECH incentives and penalties, accelerates in coming years.  This is especially true as medical centers and physician practices with far less clinical IT expertise and savvy than Harvard's become HIT users, and as the ability to capture such events increases.

The ECRI Institute "Deep Dive" study of health IT risk also speaks to a rise in numbers, with its finding of 171 health IT "events" in just 36 hospitals over 9 weeks voluntarily reported (i.e., just a fraction of the total), with 8 injuries and 3 possible deaths as a result (http://hcrenewal.blogspot.com/2013/02/peering-underneath-icebergs-water-level.html).

... The team asked its CRICO and Strategies members, “What vulnerabilities are you seeing? What are your risk managers worried about? What are your doctors complaining about?”

It used that feedback to draft a set of EHR-specific codes and then tested them in three datasets: CRICO (Harvard users) and two of Strategies’ larger clients, !e Doctors Company and Princeton Insurance. Based on those results, CRICO revised and approved 15 new EHR codes that went “live” in January 2013.

That means CRICO’s cadre of nurse coders can now identify EHR as a contributing factor to a malpractice claim, instead of using one of the less specific factors available in the past. [It's about time for a dose of transparency in the health IT sector - ed.]  And they can flag whether the problem involved user issues, system/technology issues, or both. “In some cases,” Sato points out, “the system design sets up humans to make errors.”

This should all be no surprise to any reader of this blog.  Read the whole article.

A more comprehensive list of "EHR harm modes" are at my posts "Internal FDA memorandum of Feb. 23, 2010 to Jeffrey Shuren on HIT risks. Smoking gun? I report, you decide" (http://hcrenewal.blogspot.com/2010/08/smoking-gun-internal-fda-memorandum-of.html) and "Cart Before the Horse, Part 3: AHRQ's Health IT Hazard Manager" (http://hcrenewal.blogspot.com/2012/06/cart-before-horse-part-3-ahrqs-health.html).

The actual Hazards Manager report is at http://healthit.ahrq.gov/sites/default/files/docs/citation/HealthITHazardManagerFinalReport.pdf. It contains this summary of known hazards:


AHRQ's taxonomy of health IT hazards.  Click to enlarge.

-------------------

Having written on these issues since 1998 as a "health IT iconoclast" (http://rtg.cis.upenn.edu/MDCPS/Posters/IT%20Iconoclasts.pdf) and having been largely ignored by the cognoscenti, can I now say "I told you so?"

-- SS

Sunday, February 9, 2014

A Day In The Life Of A (Reluctant But Coerced) EHR-Using Physician - And Her Patients

A reader, a physician who wishes to be unnamed due to fear of retaliation, writes the following:

Dear Dr. Silverstein,

As you write, there is not a transaction of medical care that does not go through EHR systems.

However, these poorly usable EHR systems stifle creative and artistic thought required to link risk, benefit, and probability of diagnosis with risks and benefits of testing and therapeutics.

Assuring safety and efficacy with pre- and  aftermarket surveillance will maximize the possibility of achieving the potential of the technologies.

Additionally, when I use these electronic ordering systems and  libraries of medical information, they fail to keep up with the agility and nimbleness of my mind as I seek 'random access' to pieces of data to formulate and synthesize diagnoses and therapeutic strategies.

The EHRs are too slow, do not have a robust (if any) search function, randomly and whimsically store key information with ever changing formats, and generally obfuscate what should be simple. They are cumbersome and disable the ability to simultaneously and contemporaneously compare myriad data points.

They get an "F" as enablers of complex diagnostics.

Paper, since it can be organized as needed and set out on a desk to be seen and compared as quickly as the eye registers the data, gets an "A".

The EHRs  are impediments and disrupters of communication.

Example: Just today, I was witness to the fact that a stat EKG was ordered by CPOE  on a heart patient yesterday at or shortly after 4:30 pm. The intended recipient of the order (heart station) never got it because they close near 4:30 pm and there was no warning to the ordering health professional that was so.

Thus, the EKG was never done, and this morning, when the requisition was seen, no one did it because it was ordered stat "yesterday", and the techs asked themselves "what good would it do for a 'stat' to be done now, a day late?"

I do not know what happened to the patient.  I have many other examples of such delays facilitated by the CPOE and EHR systems that I am required to use at numerous facilities.

They facilitate 'stealth' alterations in care.  Also just today, a disease-critical test ordered 3 days ago was not done because it was cancelled in 'stealth' (automatically "expired") without warning to me by the lab responsible for doing it.

There is the "silent silo" syndrome as you've called it.  Also just today, a disease critical test ordered 5 days ago came back with results, but the results were posted in the information 'silo' of 5 days ago. The lab screen default on the EHR only goes back 4 days (so unless I knew to look for it, it would not be seen or acted on), further obfuscating data and delaying treatment.

The EHRs lose data and orders.  Also just today, I found that blood coagulation monitoring tests that were ordered to be done with kidney dialysis (3 days per week) on a patient somehow got "lost" and were not being done for 5 days, putting my patient at risk of bleeds - or stroke if the blood was not 'thin' enough.

I just walked in to examine a hospitalized patient with multi-organ failure and diabetes, on multiple meds including insulin, and recovering from respiratory failure.

The nurse anxiously informed me that the blood sugar was dangerously low. I ordered treatment stat.

I see patients in the morning before labs come back, and depend on nurses to review labs and notify me.

Turns out that the patient was hypoglycemic on yesterday morning labs that arrived in the EHR 'silo' after I left the hospital; and was also low in potassium, but the tests just laid there comfortable in their silos; and were not communicated to anyone like in the old days when a human ward clerk or other undistracted human received them and disseminated them to the appropriate professionals.

Thus, instead of getting less insulin, the patient got the usual dose with near catastrophic adversity.

Misidentifications are facilitated by EHRs.  I  noticed that on several critical clinically significant changes that arose on my patient that were entered as such in an EHR silo by the RN, it was stated that they called attending physician 'Dr X', which was not me...obviously a case of EHR-facilitated misidentification.

Here is a misidentification variant:  yesterday, someone (non doctor but not clear who) ordered a specialist consultation on one of my patients under my name. I did not order it nor was it needed, yet it showed up as an order for me to sign.

Like you, I agree this is representative of a toxic impact of these systems on medical care and I feel like the care environment is foul, like a cesspool, compared to what has been replaced.

These systems of medical devices cannot be trusted in the care of sick patients. Perhaps, they are OK for managing hang nails.

I offer no additional comments other then if I am sick, I do not want my care interfered with in this manner by IT.

Rest assured, though - there are IT hyper-enthusiasts out there (http://hcrenewal.blogspot.com/2012/03/doctors-and-ehrs-reframing-modernists-v.html) who would see little problem with this, as any accidents that occur are "anecdotes", "learning experiences" or "bumps in the road."

That's if they don't simply blame the user.

-- SS

Wednesday, December 18, 2013

An Idiotically-Designed EHR Medication Discontinuation "Feature"

Over at The Healthcare Blog, Michael Chen, MD, a family physician and EHR designer in Portland, Oregon wrote a piece entitled "Why EHR Design Matters" (http://thehealthcareblog.com/blog/2013/12/18/why-ehr-design-matters/).  I am cited.

Dr. Chen reports on a major commercial EHR with the following "feature":

... In this well known EHR, you are presented a medication list for a patient. As a physician, you assume that this list is a current medication list and is up to date.  However, the reality is that this EHR system automatically removes a medication from the list when it is determined to be expired even if it should be appearing on the current medication list.

When a physician prescribes a medication from this system, it calculates the duration of usage of the medication based on the instructions, quantity of medication prescribed, and the number of refills. Once the duration exceeds the number of days that has elapsed since the prescription was made, the medication is taken off the current list automatically by the EHR.  

In other words, the EHR drops the medication from the meds list when the time elapsed exceeds the amount of time the total # of doses written for would be consumed.   As any medical student would say, "that's just brilliant."

Now, taken at face value, this sounds like the logical approach to manage a medication list and utilizes the computing power that an EHR will gladly show off as a benefit to physicians.

Misuses, actually, and at the Warp-10 speeds of today's machines, that's a lot of misuse...

Unfortunately, the EHR programmers failed to understand that medications are not taken regularly by all patients all the time. In fact, no physician assumes that at all. So why should an EHR make that assumption? Furthermore, there are plenty of treatments that are to be taken only as needed so how can an EHR account for that? Absolutely, impossible.

Perhaps the designers and programmers, simply brimming with medical degrees and expertise, thought they knew everything about medicine.  After all, you go to see a doctor, the doctor taps on you and squeezes here and there, puts a stethoscope on you, then pulls out a prescription pad and scribbles a few lines.  How hard can medicine be compared to, say, programming?

Here's how this "feature" worked out in the real world:

So I recently treated a patient that reportedly has asthma. I happened to look at a previous note and find out that the patient was denied a refill request for Albuterol, a bronchodialator that is meant to be taken as needed. She ended up in a life threatening asthma flare up and needed emergent care. It turns out the physician on call who was given the refill request several days prior didn’t realize that the EHR removed the Albuterol from her list and subsequently instructed that the patient needed to have a physician visit for having the medication prescribed. After going through 2 different windows and unclicking a check box, I was able to identify that the patient did in fact have an active prescription for Albuterol, but the EHR made it disappear. She has used it infrequently, probably because her asthma was well controlled. Unfortunately, she ended up in worse shape when she needed the medication the most.

It's a good thing the patient didn't go into Status Asthmaticus (http://emedicine.medscape.com/article/2129484-overview) and suffer severe complications, or die ... (if she had, would any of the system designers, programmers and/or purchasers have shared in liability?)

I think it fair to say this EHR "feature" was idiotically conceived, designed and implemented, and that term is the most polite I can come up with.  Failure to know what they were doing, especially in the domain of medicine, compounded by failure to consult someone - even someone with basic medical commonsense -  who would see the folly and danger of such a "feature" is inexcusable. 

The state of clinical IT will improve when such characters are placed very far from any computer that is to be used in life-critical settings, of which medicine is by definition, or at least have their work subject to rigorous testing and validation by those who know what they're doing.

That will not happen, of course, until health IT is more rigorously regulated.

-- SS

Sunday, November 17, 2013

Another 'Survey' on EHRs - Affinity Medical Center (Ohio) Nurses Warn That Serious Patient Complications "Only a Matter of Time" in Open Letter

I've written previously about substantial problems nurses at Affinity Medical Center, Ohio (http://www.affinitymedicalcenter.com/) and other organizations are having with EHRs, and how hospital executives were ignoring their complaints.  The complaints have been made openly, I believe, in large part due to the protection afforded by nurses' unions.

See for example my July 2013 post "RNs Say Sutter’s New Electronic System Causing Serious Disruptions to Safe Patient Care at East Bay Hospitals" at http://hcrenewal.blogspot.com/2013/07/rns-say-sutters-new-electronic-system.html (there are links there to still more examples), and my June 2013 post  "Affinity RNs Call for Halt to Flawed Electronic Medical Records System Scheduled to Go Live Friday" at http://hcrenewal.blogspot.com/2013/06/affinity-rns-call-for-halt-to-flawed.html, along with links therein to other similar situations.

Particularly see my July 2013 post "How's this for patient rights? Affinity Medical Center manager: file a safety complaint, and I'll plaster it to your head!" at http://hcrenewal.blogspot.com/2013/07/hows-this-for-patient-rights-affinity.html, where a judge had to intervene in a situation of apparent employee harassment for complaints about patient safety risks.

Here's the latest at Affinity Medical Center - an open letter to the Chief Nursing Officer (CNO) dated August 15, 2013.  Images and text below:


Page 1 - click to enlarge (text is below)




Page 2 - click to enlarge (text is below)

The letter to the CNO states (emphases and comments in red italics are mine):

August 15, 2013

Mr. Osterman,

Nurses at Affinity Medical Center are pleased to see that you have responded to our request and provided additional Cerner education classes, but education was only one of many concerns. [I note that education cannot compensate for the toxic effects of bad health IT that is poorly designed and/or poorly implemented, and that it's legally the responsibility of a hospital to ensure all apparatuses implemented and the environment of care are themselves safe - ed.]

Since the implementation nurses throughout the hospital have brought many serious concerns to the attention of both yourself and other supervisors.  When nurses have reported these concerns they have been either ignored or dismissed. It is distressing that Affinity would so blatantly disregard the concern of their RN staff surrounding issues that concern patient safety.  It is clear to direct-care RNs that many of the problems that exist with Cerner are a direct result of the failure to include nurses in the planning stages. [Exclusion of enduser domain experts from health IT development, in 2013, is grossly negligent IMO - ed.]

Some of the concerns that nurses have brought to the attention of management include:

  • Medication errors/scanning issues - perhaps the biggest concern of all RNs 
  • RNs unable to access patient records for hours at  a time
  • Incorrect descriptors and inaccurate drop-down menus
  • Incorrect calculations in the I&O [fluid input and output, especially important in very ill patients - ed.] and MAP [mean arterial pressure, used to calculate drip rates of potent drugs that raise or lower blood pressure in critical care, among other things - ed.] portions of the chart 
  • Inaccurate medication times and the inability of RNs to ensure medications are scheduled correctly
  • Endless loops of computer prompts that are unable to be dismissed by RNs in an emergency 

[It should be apparent that these 'issues' - some due to fundamental design flaws - are quite serious in terms of the harm they can cause, even with the exceptional and stressful RN hyper-vigilance their presence necessitates- ed.]
 
These threats to patient safety cannot continue.  It is only a matter of time before a communication error or a medication error lead to a serious complication for a patient.  These types of errors have the ability to harm every patient and must be addressed immediately. 

[This is not theoretical or unlikely.  Such an error led to my own mother's crippling injuries and death, and to injuries and deaths in numerous other cases of which I am aware through my legal work - ed.]

We ask that you set up a meeting with a delegation of RNs from our Facility Bargaining Council to discuss the concerns that nurses have documented on 'Technology Despite Objection' forms [complaint forms about use of technology with objections - ed.] and make a plan to fix these life-threatening problems.

You may set up a meeting by contacting Pam Gardner, RN at [redacted] or our National Representative  Michelle Mahon, RN.  [For the National Nurses United labor union, http://www.nationalnursesunited.org/, with close to 185,000 members nationwide - ed.]  We look forward to hearing from you.

The letter is followed by the signatures of about 70 nurses.

I am informed by a Union rep in mid-November 2013, 3 months after the date of this letter, that (emphasis mine):

Nurses there are continuing to document the problems and concerns that they are experiencing.  I have attached a letter sent to the CNO at Affinity signed by nearly 70 RNs.  This is a pretty significant number of nurses especially in light of the fact that managers stole the circulating letter two times to prevent nurses from signing on.  The response to this letter was…….nothing.  The nurses have been ignored yet again. [Ellipsis in the original, I did not redact - ed.] 

It is clear the administration of this healthcare system has been explicitly put on notice of likely if not imminent danger to patients by multiple qualified experts, its own RNs.  If they do not act and patient harm occurs, it is my belief criminal negligence charges could be merited.

I also highly doubt patients are informed of these EHR system 'issues' and have been afforded the opportunity to give informed consent to the use of these computer systems in their care, or to go elsewhere for treatment.

These problems are repeating themselves over and over across this country and others, but many clinicians, especially those not protected to some degree by a labor union, do not speak out due to fear of retaliation.

Let's hope the nurses who signed this letter don't get their complaints plastered to their foreheads, as some were threatened with as in the aforementioned post.

-- SS

Saturday, November 9, 2013

"We’ve resolved 6,036 issues and have 3,517 open issues": Extolling EPIC EHR Virtues at University of Arizona Health System

The public may believe that, in healthcare, only the Obamacare insurance exchange website has lots of bugs.  On those, see my Oct. 10. 2013 post "Drudge Report, Oct. 10, 2013, 9 AM EST: All that needs to be said about government, computing and healthcare" at http://hcrenewal.blogspot.com/2013/10/drudge-report-oct-10-2013-9-am-est-all.html.

Another pillar of the Affordable Care Act, electronic medical records (promoted with incentives for adopters and with penalties for non-adopters via the HITECH section of the 2009 economic recovery act or ARRA) are pretty damn bad themselves.  Only, those systems don't make it hard to find insurance.  Through bugs and other features of bad health IT, they directly interfere with safety and provision of quality care:

Bad Health IT ("BHIT") is ill-suited to purpose, hard to use, unreliable, loses data or provides incorrect data, is difficult and/or prohibitively expensive to customize to the needs of different medical specialists and subspecialists, causes cognitive overload, slows rather than facilitates users, lacks appropriate alerts, creates the need for hypervigilance (i.e., towards avoiding IT-related mishaps) that increases stress, is lacking in security, compromises patient privacy or otherwise demonstrates suboptimal design and/or implementation. 

At my Oct. 20, 2010 post "Medical center has more than 6000 'issues' with Cerner CPOE system in four months - has patient harm resulted?" (http://hcrenewal.blogspot.com/2010/10/medical-center-has-more-than-6000.html) I observed:

From the October 2010 "News for Physicians affiliated with Munson Medical Center" newsletter, a large medical center in Northern Michigan, about more than six thousand "issues" with their Cerner CPOE.

... One wonders how many of those 6,000, and how many of the 600 remaining "issues" fall into categories of "likely to cause patient harm in short term if uncorrected" or "may cause in patient harm in medium or long term."

I note that Cerner CPOE is not a new product, nor are similar products from other vendors also afflicted with long lists of "issues." That there could be more than 6,000 "issues" at a new site suggests deep rooted, severe problems with CPOE specifically and health IT design and implementation processes in general.

Here's another such multi-"issue"-laden EHR, this at University of Arizona Health Network.  Image of frequent periodic "EHR Update" below.



"We’ve resolved 6,036 issues and have 3,517 open issues."

[Ignore the 'kewl dark sunglasses' worn by the hipsters at the top of this announcement.  Not sure if this has something to do with EPIC, but I consider the wearing of dark sunglasses by clinicians or any other staff in a hospital setting - where people are sick and/or dying - to be in exceptionally bad taste.]

The text starts:

ISSUES UPDATE as of 4:00 p.m., Nov. 8
We’ve resolved 6,036 issues and have 3,517 open issues.

That's a total of nearly ten thousand "issues."  As of now, that is.  "Issue" is a euphemism for "glitch" a.k.a. "software defect" and/or "implementation error", see http://hcrenewal.blogspot.com/search/label/glitch.

These "issues" are  in a supposedly "mature" product for which this organization has spent enormous sums of money, that has undergone "innovation" for several decades now - in an environment free from regulation, I might add.

Many of the "issues" reduce patient safety, and could or already may have resulted in patient harm.  Such items on this listing, seen below, which is updated frequently, include:
    • Pharmacy Medication Mapping Errors – Making good progress: watch for further notices.  [Perhaps these should have been tested and fixed before go-live? - ed.]
    • Microbiology Results Mapping Incorrectly [does that mean "mapping" to the wrong patient? - ed.]  – all known errors fixed, monitoring and working on enhancements. [As above, perhaps these should have been tested and fixed before go-live? - ed.]
    • Prescription printing - output for prescription printing has been fixed
    • Refill requests for providers will be routed to the CLIN SUPPORT In Basket pool for the provider’s department.  This was a decision made by UAHN leadership. [Not sure why this is being done; perhaps for approval by managers? - ed.] 
    • Errors transmitting prescriptions will also be sent to the CLIN SUPPORT In Basket.  [Errors transmitting prescriptions? That's not reassuring regarding data integrity.  See ECRI report below  - ed.]

      This is not to mention that all of the "reminders" that follow are a distraction to clinical personnel, who cannot be expected to remember all of them.

      Bad as this is, at my April 1, 2012 post "University of Arizona Medical Center, $10 million in the red in operations, to spend $100M on new EHR system" (http://hcrenewal.blogspot.com/2012/04/university-of-arizona-medical-center-10.html) I observed that:

      ... $100 million+ is probably enough to pay for AN ENTIRE NEW HOSPITAL or hospital wing ... or a lot of human medical records professionals.

      To add more bitter icing to this cake, I wrote about a campaign for clinicians to speak only in wonderful terms about the new U. Arizona Health System EHR at my Oct. 3, 2013 post "Words that Work: Singing Only Positive - And Often Unsubstantiated - EHR Praise As 'Advised' At The University Of Arizona Health Network."  I observed the following about the "words that work" is the shameless 'suggested' script:

      Efficient - see aforementioned links as well as "Common Examples of Healthcare IT Difficulties" at http://cci.drexel.edu/faculty/ssilverstein/cases/

      Convenient - as above.  According to whom?  Compared to what?  Pen and paper?

      Improves patient safety and quality - see IOM report post at http://hcrenewal.blogspot.com/2011/11/iom-report-on-health-it-safety-nix-fda.html .  We as a nation are only now studying safety of this technology, and the results are not looking entirely convincing, e.g. ECRI Deep Dive Study of health IT safety at http://hcrenewal.blogspot.com/2013/02/peering-underneath-icebergs-water-level.html.  171 health IT mishaps in 36 hospitals, voluntarily reported over 9 weeks, with 8 reported injuries and 3 reported possible deaths is not what I would call something that "improves patient safety and quality" without qualifications.

      The Cadillac of its kind - according to whom?

      Patients at hospitals using this system love it -  Do most patients even know what it, or any EHR, looks like?  Have they provided informed consent to its use?

      Exciting - clinician surveys such as by physicians at http://hcrenewal.blogspot.com/2010/01/honest-physician-survey-on-ehrs.html and by nurses at http://hcrenewal.blogspot.com/2013/07/candid-nurse-opinions-on-ehrs-at.html shed doubt on that assertion.

      The best thing for our patients - again, according to whom?

      Sophisticated new system - "New"?  Not so much, just new for U. Arizona Health.  "Sophisticated", as if that's a virtue?  Too much "sophistication" is in part what causes clinician stress and burnout, raising risk

      Considering the near 10,000 issues, the new ECRI Institute report "Top Ten Technology Hazards in Healthcare", 2014 edition comes to mind (https://www.ecri.org/Press/Pages/2014_Top_Ten_Hazards.aspx).  Named in that report, as has been the case for the past several years, is healthcare IT. 

      This year's problem description is:

      #4. Data Integrity Failures in EHRs and other Health IT Systems

      "Data integrity failures" include "issues" (per the bad health IT description) such as: data loss, data corruption, data attributed to the wrong patient, etc.

      ECRI Institute, a nonprofit organization, dedicates itself to bringing the discipline of applied scientific research to healthcare to discover which medical procedures, devices, drugs, and processes are best to enable improved patient care. As pioneers in this science for 45 years, ECRI Institute marries experience and independence with the objectivity of evidence-based research. Strict conflict-of-interest guidelines ensure objectivity. ECRI Institute is designated an Evidence-based Practice Center by the U.S. Agency for Healthcare Research and Quality. ECRI Institute PSO is listed as a federally certified Patient Safety Organization by the U.S. Department of Health and Human Services. For more information, visit www.ecri.org.

      ECRI also produced the 2012 Deep Dive Study of Health IT Risk (http://hcrenewal.blogspot.com/2013/02/peering-underneath-icebergs-water-level.html), where in a volunteer study at 36 member PSO hospitals, 171 health IT "mishaps" were reported in just 9 weeks, 8 of which caused patient injury and 3 of which may have contribute to patient death.

      In summary, The University of Arizona Health System, with components in the red, is spending hundreds of millions of dollars on an EHR system, that has had decades to mature. Yet, they are finding 10,000 "issues" already, a number of which reduce patient safety and are unresolved, with many more likely to be found.

      They are also 'advising' their staff to speak in glowing, unsubstantiated terms to patients about an EHR system that has 10,000 issues, and not seeking patient consent to its use in mediating and regulating their care - or giving elective patients the information that might allow them to choose another less "buggy" hospital.

      If (when) patient harm results from such cavalier hospital (mis)management, the juries are going to just love the dark sunglasses, I bet.

      -- SS

      Thursday, October 31, 2013

      More "anecdotes" of health IT-related errors - System errors with Victoria's trouble-plagued HIT program caused more than 100 medication mix-ups at two Melbourne hospitals

      There are those in the field of health IT who see every health IT-related mishap as an "anecdote" - the "anecdotalists" - and every "positive" study, no matter how weak, as "solid evidence" of the technology's beneficence and efficacy.

      See "Anecdotes and Medicine, We are Actually Talking About Two Different Things" at http://hcrenewal.blogspot.com/2011/08/from-senior-clinician-down-under.html for more on the risk management/scientific method confusion it represents, from a clinician Down Under.

      More "anecdotes" from Down Under to make the anecdotalists' heads explode:

      Computer errors blamed for medication mix-ups
      The Age.com (Australia)
      October 30, 2013
      Kate Hagan

      System errors with Victoria's trouble-plagued health technology program have caused more than 100 medication mix-ups at two Melbourne hospitals and need to be fixed urgently, the state's Auditor-General has found.

      ... Auditor-General John Doyle said problems at three hospitals were putting patients at risk of missing prescribed medications or receiving incorrect doses, in a report tabled in Parliament on Wednesday. 

      [Note: the full government audit report is available at http://www.audit.vic.gov.au/reports_and_publications/latest_reports/2013-14/20131030-clinical-ict-systems.aspx in fulltext and PDF.  Other risks besides medication errors were found.  The general problems it reports in the Victoria health IT program were written about here since 2004 and at my Drexel site since 1998 - poor planning and an inadequate understanding of system requirements, underestimated project scope, costs and time lines, as well as underestimations of the required clinical workflow redesign and change management efforts. More on this in a future post.]

      Problems included HealthSMART recording patients as having being discharged when they had only moved within the hospital, and difficulties for doctors in recording complex medications in the system.

      Mr Doyle said a voluminous medication list meant doctors sometimes [picked whatever was easy -ed.] [and] printed out an incorrect prescription and then changed it manually, resulting in an inaccurate electronic record.  

      The doctors likely did this on order to be able to actually see patients and not fiddle with the computer incessantly.

      He said incident reports at two hospitals had recorded "more than 100 reported incidents of missed or nearly missed medication, as well as medicines being administered at a higher dose than prescribed".

      They included incidents in which "pain relief, antibiotics and other medication were given twice or not at all due to this issue".

      That's a good way to injure or kill people.  Trust me, I know - personally.

      ... He said hospitals had put manual measures in place to mitigate risks but they were not fail-safe, created inefficiencies and did not provide a long-term solution.

      Workarounds always introduce new risk.  I also remind that one should never need to work around something that's not in your way.

      "As a result, there is continuing potential risk to patient safety that needs to be closely monitored by both [the Victorian Health Department] and the relevant health services," he said.

      At least in Australia they state the truth, clearly, as opposed to Americans, who make excuses (see for example my Sept. 16, 2013 post "An Open Letter to David Bates, MD, Chair, ONC FDASIA Health IT Policy Committee on Recommendations Against Premarket Testing and Validation of Health IT" at http://hcrenewal.blogspot.com/2013/09/an-open-letter-to-david-bates-md-chair.html).

      At least there's this:

      Health Minister David Davis said this week that Victoria had "learnt the lessons from the flawed HealthSMART program" and promised that hospitals and health professionals would have more say on future projects, which would be based on sound business cases.

      In my view we don't need non-clinician hospital management (including and especially the business computing personnel) to "have more say", we need the health professionals to predominantly have that role.

      For those who've never completed medical/nursing school nor completed a medical internship/residency/practice, only the exceptional can comprehend the true complexities of healthcare and health IT to support it [see note 1].  As observed in "Hiding in plain sight: What Koppel et al. tell us about healthcare IT", Nemeth & Cook, Journal of Biomedical Informatics 38 (2005) 262–263 at http://www.wapatientsafety.org/downloads/article-8.pdf:

      ... On the surface, healthcare work seems to flow smoothly. That is because the clinicians who provide healthcare service make it so. Just beneath the apparently smooth-running operations is a complex, poorly bounded, conflicted, highly variable, uncertain, and high-tempo work domain. The technical work that clinicians perform resolves these complex and conflicting elements into a productive work domain. Occasional visitors to this setting see the smooth surface that clinicians have created and remain unaware of the conflicts that lie beneath it. The technical work that clinicians perform is hiding in plain sight.

      Those who know how to do research in this domain can see through the smooth surface and understand its complex and challenging reality. Occasional visitors cannot fathom this demanding work, much less create IT systems to support it.

      Unfortunately, the truly exceptional in hospital management are few and far between, despite the Lake Woebegon stories seen about them in their P.R. (See Roy Poses' post "Where No Hospital CEOs are Below Average" at http://hcrenewal.blogspot.com/2010/07/where-no-hospital-ceos-are-below.html.)

      It's becoming clearer the "anecdotalists" were quite wrong about health IT and its propensity to cause or contribute to medical error, especially when done poorly, i.e., is bad health IT which is all too common.  I attribute this to conflict of interest and fairy tale views about IT.

      From my teaching site:

      Good Health IT ("GHIT") provides a good user experience, enhances cognitive function, puts essential information as effortlessly as possible into the physician’s hands, can be easily, substantively and cost-effectively customized to the needs of medical specialists and subspecialists, keeps eHealth information secure, protects patient privacy and facilitates better practice of medicine and better outcomes.

      Bad Health IT ("BHIT") is ill-suited to purpose, hard to use, unreliable, loses data or provides incorrect data, is difficult and/or prohibitively expensive to customize to the needs of different medical specialists and subspecialists, causes cognitive overload, slows rather than facilitates users, lacks appropriate alerts, creates the need for hypervigilance (i.e., towards avoiding IT-related mishaps) that increases stress, is lacking in security, compromises patient privacy or otherwise demonstrates suboptimal design and/or implementation.  

      -- SS

      [1] A corollary is as seen in a comment By Bruce Landes MD here in what he calls the Landes EHR rule: "The enthusiasm for EHRs increases with the square of the distance from actual medical practice."

      Monday, September 16, 2013

      An Open Letter to David Bates, MD, Chair, ONC FDASIA Health IT Policy Committee on Recommendations Against Premarket Testing and Validation of Health IT

      From http://www.healthit.gov/policy-researchers-implementers/federal-advisory-committees-facas/fdasia:

      The Food and Drug Administration Safety Innovation Act (FDASIA) Health IT Policy Committee Workgroup is charged with providing expert input on issues and concepts identified by the Food and Drug Administration (FDA), Office of the National Coordinator for Health IT (ONC), and the Federal Communications Commission (FCC) to inform the development of a report on an appropriate, risk-based regulatory framework pertaining to health information technology including mobile medical applications that promotes innovation, protects patient safety, and avoids regulatory duplication.

      My Open Letter to the Committee's chair speaks for itself:

      From: Scot Silverstein
      Date: Mon, Sep 16, 2013 at 9:39 AM
      Subject: ONC FDASIA Health IT Policy Committee's recommendations on Premarket Surveillance
      To: David Bates

      Sept. 16, 2013

      David Bates, Chair, ONC FDASIA Health IT Policy Committee
      via email
         
      Dear David,

      I am disappointed (and in fact appalled) at the ONC FDASIA Health IT Policy Committee's recommendations that health IT including typical commercial EHR/CPOE systems not be subjected to a premarket testing and validation process.  I believe this recommendation is, quite frankly, negligent. [1]

      As you know, my own mother was injured and then died as a result of EHR deficiencies, and nearly injured or killed again in the recuperation period from her initial injuries by more health IT problems in a second EHR used in her care.  In my legal consulting and from my colleagues, as well as from the literature, I hear about other injuries/deaths and many "near misses" as well.  That your recommendations came in the face of the recent ECRI Deep Dive study is even more appalling, with the latter's finding of 171 health IT-related incidents in 9 weeks from 36 member PSO hospitals, resulting in 8 injuries and 3 possible deaths, all reported voluntarily. [2]

      It is my expert opinion the issues that cause these outcomes would never have made it into production systems, had a reasonable, competent, unbiased premarket testing and validation process been in place.

      Consequently, I have shared the FDASIA HIT Policy Committee's recommendations with the Plaintiff's Bar, and will use its recommendations in my presentations to various chapters of the American Association for Justice (the trial lawyer's association) - as well as to interested Defense attorneys so they may advise their clients accordingly.

      I am also making recommendations that in any torts, individual or class, regarding EHR problems that would likely have been averted with competent premarket testing and validation, that the FDASIA HIT Policy Committee members who agreed with the recommendation be considered possible defendants.

      I am sorry it has come to this.

      Please note I am also posting this message for public viewing at the Healthcare Renewal weblog of the Foundation for Integrity and Responsibility in Medicine (FIRM).

      Sincerely,

      Scot Silverstein, MD
      Consultant/Independent Expert Witness in Healthcare Informatics
      Adjunct Faculty, Drexel University, College of Computing and Informatics

      Notes:


      [1] FDA Law Blog, Recommendations of FDASIA Health IT Workgroup Accepted, September 11, 2013, available at http://www.fdalawblog.net/fda_law_blog_hyman_phelps/2013/09/recommendations-of-fdasia-health-it-workgroup-accepted.html: "Of particular interest is the recommendation that health IT should generally not be subject to FDA premarket requirements, with a few exceptions:  medical device accessories, high-risk clinical decision support, and higher risk software use cases."

      [2] "Peering Underneath the Iceberg's Water Level: AMNews on the New ECRI 'Deep Dive' Study of Health IT Events" , Feb. 28. 2013, available at http://hcrenewal.blogspot.com/2013/02/peering-underneath-icebergs-water-level.html.

      -----------------------------------------------

      Note: the following are listed on the linked site above as members of the committee:

      Member List
      • David Bates, Chair, Brigham and Women’s Hospital
      • Patricia Brennan, University of Wisconsin-Madison
      • Geoff Clapp, Better
      • Todd Cooper, Breakthrough Solutions Foundry, Inc.
      • Meghan Dierks, Harvard Medical Faculty, Division of Clinical Informatics
      • Esther Dyson, EDventure Holdings
      • Richard Eaton, Medical Imaging & Technology Alliance
      • Anura Fernando, Underwriters Laboratories
      • Lauren Fifield, Practice Fusion, Inc.
      • Michael Flis, Roche Diagnostics
      • Elisabeth George, Philips Healthcare
      • Julian Goldman, Massachusetts General Hospital/ Partners Healthcare
      • T. Drew Hickerson, Happtique, Inc.
      • Jeffrey Jacques, Aetna
      • Robert Jarrin, Qualcomm Incorporated
      • Mo Kaushal, Aberdare Ventures/National Venture Capital Association
      • Keith Larsen, Intermountain Health
      • Mary Anne Leach, Children’s Hospital Colorado
      • Meg Marshall, Cerner Corporation
      • Mary Mastenbrook, Consumer
      • Jackie McCarthy, CTIA - The Wireless Association
      • Anna McCollister-Slipp, Galileo Analytics
      • Jonathan Potter, Application Developers Alliance
      • Jared Quoyeser, Intel Corporation
      • Martin Sepulveda, IBM
      • Joseph Smith, West Health
      • Paul Tang, Palo Alto Medical Foundation
      • Bradley Thompson, Epstein Becker Green, P.C
      • Michael Swiernik, MobileHealthRx, Inc.
      Federal Ex Officios
      • Jodi Daniel, ONC
      • Bakul Patel, FDA
      • Matthew Quinn, FCC

       -- SS

      Wednesday, August 7, 2013

      Today's Bad Health IT Systems: More Dangerous Than Paper?

      I believe in 2013 that they are.

      (Definition of bad health IT is here:  http://www.ischool.drexel.edu/faculty/ssilverstein/cases/)

      I recently posted about two "glitches" in a major EHR seller's clinical systems, Siemens Healthcare, affecting safety-critical functions of medication reconciliation and medication ordering.


      Considering these, plus the many "glitches" reported by the only EHR seller who does so via FDA's MAUDE database (see here: http://hcrenewal.blogspot.com/2011/01/maude-and-hit-risk-mother-mary-what-in.html), and the others posted at this blog at query link: http://hcrenewal.blogspot.com/search/label/glitch, the following issue needs serious consideration by policymakers.

      Namely, the issue that enterprise electronic medical command-and-control systems, which today's "EHRs" in reality are, are on their face more risk-prone than the paper systems they are replacing.

      The "glitches" reported above are clearly the tip of the iceberg due to industry norms of secrecy, the absence of most of the industry in reporting to FDA MAUDE or anywhere, and my limited sources of information.  It is likely the true level of "glitches" in live EHR/clinical IT installations is far, far higher  - conservatively, I believe, at least two orders of magnitude.

      Workarounds to IT "glitches" such as recommended in the Siemens bulletins at the aforementioned posts cause hospital officials to have to  reliably get the notices to all users of the systems, including medical students, nurses, physicians and allied health professionals.

      The workarounds also cause users to:

      1)  have to deviate from habits of use acquired in training and active use of the systems in question;
      2) remember, without fail, to deviate from habits of use acquired in training and active use of the systems in question, in effect giving them the responsibility of caring for sick patients and for "sick" information technology;
      3) keep in mind any other extant workarounds that exist waiting for "fixes"; and
      4) be constantly on guard for information storage failures.

      In fact, the recent Siemens "glitches" and workarounds represent a clear danger to patient safety.  If these were more conventional medical devices, they'd be recalled.

      See my Dec. 14, 2011 post "FDA Recalls Draeger Health IT Device Because This Product May Cause Serious Adverse Health Consequences, Including Death" (http://hcrenewal.blogspot.com/2011/12/fda-recalls-health-it-software-because.html) and July 23, 2012 post "Health IT FDA Recall: Philips Xcelera Connect - Incomplete Information Arriving From Other Systems"(http://hcrenewal.blogspot.com/2012/07/health-it-fda-recall-philips-xcelera.html) for examples where health IT defects similar to the Siemens issues were, in fact, recalled.

      Further, with paper records or tangible images, a page or image can be lost, or it can be illegible.  In the case of lost, in any quality paper record keeping system the information stewards or others using the paper (e.g., office staff or ward clerks) will generally note the absence and act accordingly.  Further, illegible notes or orders will most often be recognized as illegible and result in attempted clarification or other corrective actions.

      On the other hand, when electronic systems:

      1)  lose modified information en masse as in the Siemens examples but keep the old, or
      2)  when outright errors such as en masse truncation occur (as in the thousands of prescriptions whose long-acting suffixes were cut off at Lifespan in Rhode Island, see "Yet another health IT "glitch" affecting thousands" here: http://hcrenewal.blogspot.com/2011/11/lifespan-rhode-island-yet-another.html), or
      3)  images are lost (see "Potential Image Loss in GE Centricity PACS" here:  http://hcrenewal.blogspot.com/2012/11/potential-image-loss-in-ge-centricity.html) without warning-

      - There are no "flags" that the obsolete, truncated or missing information is erroneous.

      What remains is perfectly legible, perfectly convincing and perfectly deceiving.

      Electronic healthcare information systems on their face create more risk than paper record systems.  Further, the problem with "bugs" and "glitches" will not go away with today's industry models of "hiring down" and lack of regulation.  Every new upgrade or patch is suspect for introducing new bugs.

      Paper does not suffer these issues, unless disappearing ink is used to cross out the old and add new information ...

      Not that I am advocating for a return to 100% paper, but certain critical functions probably are best left to paper.  Further, hundreds of billions of dollars can certainly buy:

      1)  a lot of Health Information Management professionals to perform continuous QA of paper,
      2)  a lot of document imaging systems to make the paper records available anywhere, anytime they are needed, and
      3)  a lot of data entry personnel to relieve clinicians of clerical burdens so they may use their valuable experience more productively, as guest poster Howard Brody points out at http://hcrenewal.blogspot.com/2013/07/guest-post-incompetent-management.html.
      4)  a lot of sensible regulation of this industry's product quality.

      -- SS

      Monday, June 17, 2013

      IT Specialist and the job he wouldn't take: hospital management's health IT "plan" is a checklist for failure

      Received unsolicited on June 14, 2013 from a computer professional whose identity I am redacting.  Posted with his permission:

      Dr. Silverstein,

      Thank you very much for the many insights and helpful references provided on your "Contemporary Issues in Medical Informatics" (http://www.ischool.drexel.edu/faculty/ssilverstein/cases/) web site! In performing my due diligence for a position as an IT Director at a small rural hospital, I have come across your writings. 

      I originally applied for this position in the hopes of leveraging my IT, project management, compliance and security experience to gain new expertise in healthcare IT. After my initial phone interview with the "CIO" and HR Director, at which I discovered that I would have the responsibility to implement a poorly conceived new EMR project, without the authority or resources to make it successful, additional red flags were raised which required further research. This led me to you.  

      I cannot help but chuckle at the organizational, social and project management dysfunctions in medical IT, as described in your "Ten Critical Rules for Applied Informatics..."  (http://www.ischool.drexel.edu/faculty/ssilverstein/cases/?loc=cases&sloc=tenrules).   I have encountered similar dysfunctions in the world of military and commercial IT.  With a little tweaking, your lessons learned are applicable across a wide range of IT disciplines and a good reminder of how to avoid IT project and career failures and achieve successes.

      Yet, I understand and have come to appreciate your thesis that medical IT is fundamentally different from business IT. Even though I am convinced that I could do better than most, I have concluded that it is probably wiser for a competent healthcare informaticist to lead HIT implementation projects. I wonder how many such competent informaticists there can be! Unfortunately, since I have no background in medicine, it is probably a little late for me to become one. 

      I certainly will not engage in this particular opportunity. What I know of the hospital management's "plan" at this point is a checklist for failure. The reality of this rural hospital, and apparently thousands of similar situations, is unnecessarily and depressingly tragic for patients and clinical professionals. I appreciate your crusade to raise the bar for healthcare IT, and therefore IT in general. Thank you for saving me from jumping in to an untenable situation.


      Ironically, and sadly, this letter is similar to others I have received dating to 1999.  Little has changed in nearly 15 years, except that with the rush to implement this unregulated, experimental technology thanks to the HITECH Act, there's likely going to be a lot more patient harm, especially at smaller hospitals new to this endeavor.

      -- SS

      Sunday, December 23, 2012

      ONC's Christmas Confessional on Health IT Safety: "HIT Patient Safety Action & Surveillance Plan for Public Comment"

      This time of year is certainly appropriate for a confessional on the health IT industry and hyperenthusiasts' sins.

      In the first report I've seen that seems genuinely imbued with a  basic level of recognition of social responsibility incurred by conducting the grand human subjects experiment known as national health IT, ONC has issued a Dec. 21, 2012 report "Health Information Technology Patient Safety Action & Surveillance Plan for Public Comment." It is available at this link in PDF.

      Statements are made that have appeared repeatedly since 2004 at this blog, and my health IT difficulties site that went online years before this blog (1998 to be exact); it is possible through my early writing and that of like-minded colleagues that we were the origin of most of these memes.  We wrote them with the result of bringing much scorn upon ourselves. After all, "how could health IT possibly not be a panacea?" was the "you are an apostate" attitude I certainly experienced (e.g., as in my Sept. 2012 post "The Dangers of Critical Thinking in A Politicized, Irrational Culture").

      Observations echoed in the new ONC report:

      • "Just as health IT can create new opportunities to improve patient care and safety, it can also create new potentials for harm."
      • Health IT will only fulfill its enormous potential to improve patient safety if the risks associated with its use are identified, if there is a coordinated effort to mitigate those risks, and if it is used to make care safer.
      • Because health IT is so tightly integrated into care delivery today, it is difficult to interpret this initial research [such as the PA Patient Safety Authority study  - ed.], which would seem to suggest that health IT is a modest cause of medical errors. However, it is difficult to say whether a medical error is health IT-related. [Not emphasized, as I wrote here, is the issue of risk when, say, tens of thousands of prescriptions are erroneous due to one software bug, a feat impossible with paper - ed.]
      • The proper steps to improve the safety of health IT can only be taken if there is better information regarding health IT’s risks, harms, and impact on patient safety.

      Suggested steps to be taken include:

      • Make it easier for clinicians to report patient safety events and risks using EHR technology.
      • Engage health IT developers to embrace their shared responsibility for patient safety and promote reporting of patient safety events and risks. [I am frankly amazed to see this admission.  In the past, that sector excused itself entirely on the basis of the "learned intermediary" doctrine and "hold harmless" clauses; where the clinician is an all-knowing Deity between computer and patient.  I've been writing for years, however, that the computer is now the intermediary between clinician and patient since all care 'transactions' have to traverse what is now an enterprise clinical resource and clinician control system - ed.]
      • Provide support to Patient Safety Organizations (PSOs) to identify, aggregate, and analyze health IT safety event and hazard reports.
      • Incorporate health IT safety in post-market surveillance of certified EHR technology
      • Align CMS health and safety standards with the safety of health IT, and train surveyors.
      • Collect data on health IT safety events through the Quality & Safety Review System (QSRS).
      • Monitor health IT adverse event reports to the Manufacturer and User Facility Device Experience (MAUDE) database. [I've been promoting the use of MAUDE for just that purpose, and much more regarding documenting and reporting on mission-hostile health IT; see this post - ed.]

      These steps are to be taken in order to "Inspire Confidence and Trust in Health IT and Health Information Exchange."

      The title of my keynote address to the Health Informatics Society of Australia this summer was, in fact, "Critical Thinking on Building Trusted, Transformative Medical Information:  Improving Health IT as the First Step".

      My thoughts on this report:

      • It is at least two decades overdue.
      • It was produced largely if not solely due to the pressure of the "HIT apostates", finally overcoming industry memes and control of information flows through great perseverance.
      • It is indeed a confessional of the sins committed by the health IT industry over those decades.  Creating, implementing and maintaining mission critical software in a safety-cognizant way is not, and was not, a mystery.  It's been done in numerous industries for decades.
      • It is still a bit weak in acknowledging the likely magnitude of under-reporting of medical errors, including HIT-related, in the available data, and the issue of risk vs. 'confirmed body counts' as I wrote at my recent post "A Significant Additional Observation on the PA Patient Safety Authority Report -- Risk".
      • It is unfortunate that this report did not come from the informatics academic community in the United States, i.e., the American Medical Informatics Association (AMIA).  AMIA's academics have done well in advancing the theoretical aspects of the technologies, and how to create "good health IT" and not "bad health IT."  However, they have largely abrogated their social responsibilities and obligations, including but not limited to those of physicians, in ensuring the theories were followed in practice by an industry all too eager to ignore academic research (which, in order to follow, utilizes money and resources and reduces margins).
      (On the latter point, just last week did the American College of Medical Informatics [ACMI] refuse to permit me to be a speaker at their early 2013 annual retreat despite support from some of its members.)

      And this:

      • If the industry and the academics had been doing their job responsibly, I might be spending this Christmas and New Years's holiday with my mother, rather than visiting her in the cemetery.

      All that said, the report is welcome.

      Finally, it is hoped - and expected - that public comments will indeed be "public", and that any irregularities in such comments (such as appeared in the public comments period for MU2 due to industry ghostwriting as in my Aug. 2012 post "Health IT Vendor EPIC Caught Red-Handed: Ghostwriting And Using Customers as Stealth Lobbyists - Did ONC Ignore This?" and Sept. 2012 post "Was EPIC successful in watering down the Meaningful Use Stage 2 Final Rule?") will be reported and acted upon in an aggressive manner.

      And finally, from the Healthcare Renewal blog, Merry Christmas.

      -- SS

      Wednesday, December 19, 2012

      A Significant Additional Observation on the PA Patient Safety Authority Report "The Role of the Electronic Health Record in Patient Safety Events" -- Risk

      At a Dec. 13, 2012 post "Pennsylvania Patient Safety Authority: The Role of the Electronic Health Record in Patient Safety Events" I alluded to risk in a comment in red italics:

      ... Reported events were categorized by their reporter-selected harm score (see Table 1). Of the 3,099 EHR-related events, 2,763 (89%) were reported as “event, no harm” (e.g., an error did occur but there was no adverse outcome for the patient) [a risk best avoided to start with, because luck runs out eventually - ed.], and 320 (10%) were reported as “unsafe conditions,” which did not result in a harmful event. 

      The focus of the report is on how the "events" did not cause harm.  Thus the relatively mild caveat:

      "Although the vast majority of EHR-related reports did not document actual harm to the patient, analysts believe that further study of EHR-related near misses and close calls is warranted as a proactive measure."

      It occurs that if the title of the paper had been "The Role of the Electronic Health Record in Patient Safety Risk", the results might have been interpreted far differently:

      In essence, from from June 2, 2004, through May 18, 2012 (the timeframe of the Pennsylvania Patient Safety Reporting System or PA-PSRS database), from a dataset highly limited in its comprehensiveness as written in the earlier post, there were approximately 3,000 "events" where an error did occur that potentially put patients at risk.

      That view - risk - was not the focus of the study.  Should it have been?

      These "events" really should be called "risk events."

      It is likely the tally of risk events, if the database were more comprehensive (due to better recognition of HIT-related problems, better reporting, etc.) would be much higher.  So would the reports of "harm and death" events as well.

      That patient harm did not occur from the majority of "risk events" was through human intervention, which is to say, luck, in large part

      Luck runs out, eventually.

      I have personally saved a relative several times from computer-related "risk events" that could have caused harm if I were not there personally, and with my own medical knowledge, to have intervened.  My presence was happenstance in several instances; in fact a traffic jam or phone call could have caused me to have not been present.

      What's worse, the report notes:

      Analysts noted that EHR-related reports are increasing over time, which was to be expected as adoption of EHRs is growing in the United States overall.

      In other words, with the current national frenzy to implement healthcare information technology, these "risk events" - and "harm and death events" - counts will increase.  My concern is that they will increase significantly.

      I note that health IT is likely the only mission-critical technology that receives special accommodation regarding risk events.  "If the events didn't cause harm, then they're not that important an issue" seems to be the national attitude overall.

      Imagine aircraft whose avionics and controls periodically malfunction, freeze, provide wrong results, etc., but most are caught by hyper-vigilant pilots so planes don't go careening out of control and crash.  Imagine nuclear plants where the same occurs, but due to hypervigilance the operators prevent a nuclear meltdown.

      Then, imagine reports of these "risk events" - based on fragmentary reporting of pilots and nuclear plant operators reluctant to do so for fear of job retaliation - where the fact of their occurrence takes a back seat to the issue that the planes did not crash, or Three Mile Island or Chernobyl did not reoccur.

      That, in fact, seems to be the culture of health IT.

      I submit that the major focus that needs addressing in health IT is risk - not just confirmed body counts.

      -- SS

      Thursday, December 13, 2012

      Pennsylvania Patient Safety Authority: The Role of the Electronic Health Record in Patient Safety Events

      The Pennsylvania Patient Safety Authority has released a report "The Role of the Electronic Health Record in Patient Safety Events."  A press release is at this link, and the full report in PDF is at this link.  In the report, the Pennsylvania Patient Safety Authority analyzed reports of EHR-related events from a state database of reported medical errors and identified several major themes.

      The report was prepared with the assistance of Erin Sparnon, Senior Patient Safety Analyst the ECRI Institute near Philadelphia.  The ECRI Institute is an independent organization renowned for its safety testing of medical technologies and reporting on same, and that "researches the best approaches to improving the safety, quality, and cost-effectiveness of patient care."  I've mentioned it and its bylaws in this blog in the past as a model for independent, unbiased testing and reporting of healthcare techonlogies.

      Regarding the Patient Safety Authority:


      The Pennsylvania Patient Safety Authority was established under Act 13 of 2002, the Medical Care Availability and Reduction of Error ("Mcare") Act, as an independent state agency. It operates under an 11-member Board of Directors, six appointed by the Governor and four appointed by the Senate and House leadership. The eleventh member is a physician appointed by the Governor as Board Chair.  Current membership includes three physicians, three attorneys, three nurses, a pharmacist and a non-healthcare worker.

      The Authority is charged with taking steps to reduce and eliminate medical errors by identifying problems and recommending solutions that promote patient safety in hospitals, ambulatory surgical facilities, birthing centers and certain abortion facilities. Under Act 13 of 2002, these facilities  must report what the Act defines as "Serious Events" and "Incidents" to the Authority.

      The Authority maintains a database of serious events and incidents:

      Consistent with Act 13 of 2002, the Authority developed the Pennsylvania Patient Safety Reporting System (PA-PSRS, pronounced "PAY-sirs"), a confidential web-based system that both receives and analyzes reports of what the Act calls Serious Events (actual occurrences) and Incidents (so-called "near-misses").

      Cutting right to the chase, the paper's summary:

      As adoption of health information technology solutions like electronic health records (EHRs) has increased across the United States, increasing attention is being paid to the safety and risk profile of these technologies. However, several groups have called out a lack of available safety data as a major challenge to assessing EHR safety, and this study was performed to inform the field about the types of EHR-related errors and problems reported to the Pennsylvania Patient Safety Authority and to serve as a basis for further study. Authority analysts queried the Pennsylvania Patient Safety Reporting System for reports related to EHR technologies and performed an exploratory analysis of 3,099 reports using a previously published classification structure specific to health information technology. The majority of EHR-related reports involved errors in human data entry, such as entry of “wrong” data or the failure to enter data, and a few reports indicated technical failures on the part of the EHR system. This may reflect the clinical mindset of frontline caregivers who report events to the Authority.

      Results:

      ... Reported events were categorized by their reporter-selected harm score (see Table 1). Of the 3,099 EHR-related events, 2,763 (89%) were reported as “event, no harm” (e.g., an error did occur but there was no adverse outcome for the patient) [a risk best avoided to start with, because luck runs out eventually - ed.], and 320 (10%) were reported as “unsafe conditions,” which did not result in a harmful event. Fifteen reports involved temporary harm to the patient due to the following: entering wrong medication data (n = 6), administering the wrong medication (n = 3), ignoring a documented allergy (n = 2), failure to enter lab tests (n = 2), and failure to document (n = 2). Only one event report, related to a failure to properly document an allergy, involved significant harm.

      A significant "study limitations" section was included that addressed: 

      • Issues regarding reporting statutes of the PA-PSRS errors database; 
      • lack of awareness of EHRs as a potential contributing factor to an error;
      • limitations of narrative reporting affecting both the types of reports queried and the tags applied (the study used textual data mining methodolgies);
      • query design of the study; and
      • the need for further refinement of the machine learning tool used in creating the working dataset, which may have missed relevant cases.

      Some of these impediments to knowing the magnitude of extant HIT issues are also present in the 2008 Joint Commission Sentinel Events Alert on HIT, the 2010 FDA internal memorandum on HIT Safety, and the 2011 IOM report on the same topic.

      (The IOM report specifically observed that the "barriers to generating evidence pose unacceptable risks to safety.") 

      The major obstacle to this study in my view, though, was the nature of the dataset.  The database is for general reporting of medical errors, and it contains no specific fields or reminders about EHRs or the known ways in which they can contribute to, or cause, medical mistakes.  

      The attempt was made, as acknowledged in the study, to glean information about EHR-related events from, in large part, textual analysis of narrative in the hopes that the reporter recognized the role of IT, and reported it using terms that could be detected by the search algorithms.  In other words, the data was not "purposed" for this type of study.  

      It is axiomatic that one cannot find data that is simply not present, no matter how fancy the search algorithm.  Further, passive analysis of clinical IT risk/harms data in an industry where lack of knowledge of causation and misconceptions abound will produce only partial results that suggest further study is needed, and not give an indicator of just how incomplete the results are.

      Thus, this cautionary statement was made in the new PA Patient Safety Authority report:

      "Although the vast majority of EHR-related reports did not document actual harm to the patient, analysts believe that further study of EHR-related near misses and close calls is warranted as a proactive measure." 

      My comments:

      The report is welcome.

      The most important part of the paper, I point out, is the “Limitations” section. FDA, IOM and others have made similar observations – we don’t know the true magnitude of the problem due to systematic limitations of the available data. 

      Therefore, at best what is available must be deemed as risk management-relevant case reports, a “red flag” that could represent (using the words of FDA CDRH director Jeffrey Shuren regarding HIT safety), the tip of the iceberg.

      It is imperative far more work be done in post-market surveillance as this technology is deployed nationally and internationally.  This is to ensure that good health IT (GHIT) prevails and bad health IT (BHIT) is either remediated or removed from the marketplace.  I had defined those in other writings as follows:

      Good Health IT ("GHIT") is defined as IT that provides a good user experience, enhances cognitive function, puts essential information as effortlessly as possible into the physician’s hands, keeps eHealthinformation secure, protects patient privacy and facilitates better practice of medicine and better outcomes. 

      Bad Health IT ("BHIT") is defined as IT that is ill-suited to purpose, hard to use, unreliable, loses data or provides incorrect data, causes cognitive overload, slows rather than facilitates users, lacks appropriate alerts, creates the need for hypervigilance (i.e., towards avoiding IT-related mishaps) that increases stress, is lacking in security, compromises patient privacy or otherwise demonstrates suboptimal design and/or implementation. 

      An additional major factor that also contributes to lack of knowledge of EHR-related adverse events is hospital reporting non-compliance. For instance, I know of cases from my own legal consulting work and personal experience that I would have expected to appear in the database, but apparently do not.

      But don’t take it from me alone. Here is PA Patient Safety Authority Board Member Cliff Rieders, Esq. on this.

      From “Hospitals Are Not Reporting Errors as Required by Law, Phila. Inquirer”, pg. 4,http://articles.philly.com/2008-09-12/news/24991423_1_report-medical-mistakes-new-jersey-hospital-association-medication-safety:
        

      ... Hospitals don’t report serious events if patients have been warned of the possibility of them in consent forms, said Clifford Rieders, a trial lawyer and member of the Patient Safety Authority’s board.

      He said he thought one reason many hospitals don’t want to report serious events is that the law also requires that patients be informed in writing within a week of such problems. So, if a hospital doesn’t report a problem, it doesn’t have to send the patient that letter. [Thus reducing risk of litigation, and, incidentally, potentially infringing on patients' rights to legal recourse - ed.]

      Rieders says the agency has allowed hospitals to determine for themselves what constitutes a serious event and the agency has failed to come up with a solid definition in six years.

      Fixing this “is not a priority,” he added.

      This coincides with my own personal experience precisely.  In a case where my relative was permanently injured as a result of EHR-related medication error, and then died of the injuries, I never received the required report in writing from the hospital.  I also do not believe the case was reported to the Safety Authority, at least not as IT-related.

      I suspect the true rates of EHR-related close calls, reversible injuries, permanent injuries and deaths is significantly higher than the limited data available suggests. That data is merely a red flag that much more education, stringent reporting requirements,  templates of known causes of error, and enforcement are needed.  (An April 2010  "thought experiment" on this issue I wrote about at "If The Benefits Of Healthcare IT Can Be Guesstimated, So Can And Should The Dangers" certainly suggested as much.)

      Slides where I made those types of recommendations to the Patient Safety Authority, at a presentation I gave in July 2012 at their invitation, are at http://www.ischool.drexel.edu/faculty/ssilverstein/PA_patient_safety_Jul2012.ppt

      A major concern I have is that the HIT industry will use this new report in a manner that ignores its limitations.

      (Disclosure: I was an invited reviewer of this new PPSA report.)

      -- SS 

      Addendum Dec. 13:   

      Also worth review is "Patient Safety Problems Associated with Heathcare Information Technology: an Analysis of Adverse Events Reported to the US Food and Drug Administration", Magrabi, Ong, Runciman, and Coiera, AMIA Annu Symp Proc. 2011.  

      Data here came from FDA's voluntary (i.e., also tip of the iceberg) Manufacturer and User Facility Device Experience (MAUDE) database.  Ironically, the study was done in Australia using Australian grant funds.

      -- SS