Arkansas News Bureau — A federal judge sentenced a doctor and two former hospital employees to a year’s probation each today after they admitted to violating federal privacy laws by looking at the medical records of slain TV reporter Anne Pressly.
Dr. Jay Holland of Little Rock also was fined $5,000 and ordered to perform 50 hours of community service educating professionals on the importance of patient privacy under the federal Health Insurance Portability and Accountability Act, also known as HIPAA.
Sarah Elizabeth Miller of England, a former account representative at the St. Vincent Medical Center in Sherwood, was fined $2,500 and Candida Griffin, a former emergency room unit coordinator at St. Vincent’s main hospital in Little Rock, was fined $1,500.
The three pleaded guilty in July to misdemeanor violations of the health information privacy provisions of HIPAA for accessing Pressly’s medical records without any legitimate purpose. More
Discussions of Interoperability Exchange, Privacy, and Security in Healthcare by John Moehrke - CyberPrivacy. Topics: Health Information Exchange, Document Exchange XDS/XCA/MHD, mHealth, Meaningful Use, Direct, Patient Identity, Provider Directories, FHIR, Consent, Access Control, Audit Control, Accounting of Disclosures, Identity, Authorization, Authentication, Encryption, Digital Signatures, Transport/Media Security, De-Identification, Pseudonymization, Anonymization, and AI Transparency.
Wednesday, October 28, 2009
Three sentenced for privacy violations in Pressly case
HIPAA violations do actually get convictions...
Saturday, October 24, 2009
Groups: Genetic Data Rule Flawed
I find this article and statement somewhat tragically ironic. It shows that although the updates to GINA, a genetic privacy rule, are being seen as going too far. This group would like genetic information to be used to receive discounts, event hough they likely still would be against genetic information being used for increased fees. This is likely a case of a policy going too far. One solution would simply allow a patient to authorize any use of their genetic information including for the purpose of getting a discount.
"As noted, GINA's intent was to prohibit group health plans and insurers from collecting genetic information 1) prior to or in connection with enrollment; and 2) for underwriting purposes," according to the letter. "The final interim regulations broadly define 'underwriting purposes' to mean rules for determining eligibility (including enrollment and continued eligibility), computation of premium or contribution amounts, and application of pre-existing condition exclusions. This definition includes changing deductibles or other cost sharing mechanisms, or providing discounts, rebates, payments in kind, or other premium differential mechanisms in return for activities such as completing a health risk assessment (HRA) or participating in wellness programs. The new regulations clarify that offering reduced premiums or other reward for providing genetic information is an impermissible 'underwriting' activity. More
Thursday, October 22, 2009
HIT Standards - Implementation Workgroup hearing
This workgroup/hearing will be very interesting to help expose the separation between desired capabilities, practicle capabilities, future capabilities, and how that relates to standards selection.
A G E N D A
HIT Standards Committee
Implementation Workgroup
Thursday, October 29, 2009, 9 a.m. to 4 p.m./Eastern
OMNI Shoreham Hotel, 2500 Calvert Street, NW, Washington, DC
Note about this meeting:The HIT Standards Committee has inaugurated an Implementation Workgroup which is charged with bringing forward “real-world” implementation experience into the HIT Standards Committee recommendations, with special emphasis on strategies to accelerate the adoption of proposed standards, or mitigate barriers, if any. The Implementation Workgroup is holding a public hearing on the topic of Adoption Experiences on Thursday, October 29, 2009, in Washington, DC. We have organized a series of panels to address the issue.
9:00 a.m. Call to Order/Roll Call – Judy Sparrow, Office of the National Coordinator
9:05 a.m. Welcome and Introduction – Aneesh Chopra, Chair, Implementation Workgroup
9:15 a.m. Non‐Healthcare Industries Panel – Moderator: John Halamka, HIT Standards Committee Co‐Chair
10:30 a.m. Providers Panel ‐ Moderator: Judy Murphy, HIT Standards Committee member
12:00 p.m. BREAK
- Andy Wiesenthal, Kaiser Permanente (IDN)
- Dick Taylor, CMIO, Providence Health, Portland, OR (IDN)
- Rick Warren, VP/CIO, Allegiance Health, MI (Community Hospital)
- Lisa Bewley, VP/CIO, Regional West Medical Center, Scotts Bluff, NE (Community Hospital)
- Louis Spikol, MD, from Allentown PA (Small Practice)
- Roland Goertz, MD/Waco, Texas (Small Practice)[invited]
12:45 p.m. Vendors Panel – Moderator: Cris Ross, HIT Standards Committee member
2:00 p.m. Quality Measures Panel – Moderator: David McCallie, HIT Standards Committee member
- Rick Ratliff, SureScripts
- Arien Malec, Relay Health
- Sean Nolan, MicroSoft
- Girish Kumar, eClinical Works
- Ian McCrae, Orion Health [invited]
3:00 p.m. Meeting Summary – Aneesh Chopra, Chair
- Ralph Brindis, American College of Cardiology
- Richard Gliklich, CEO, Outcome Sciences
- Kepa Zubeldia, Ingenix [invited]
- Jesse Singer, NYC Health [invited]
3:30 p.m. Public Comment
4:00 p.m. Adjourn
Wednesday, October 21, 2009
Feds crack down on medical ID theft and Medicare fraud
Security technology can do only so much, but it is still important.
Health and Human Services Secretary Kathleen Sebelius and Assistant Attorney General Tony West are urging seniors to take steps to avoid medical identification theft and Medicare fraud. As part of the Obama administration's ongoing effort to fight Medicare fraud, Sebelius and West unveiled at a Thursday press conference new information designed to help seniors and Medicare beneficiaries "deter, detect and defend" against medical identity theft.More
ONC revisits linking consumer preferences to EHRs
This article has some nice content, but fails to explain what they mean in their title about ONC revisiting the linking of consumer preferences to the EHR. I was intrigued by this statement as I had not heard anything like it.
I have posted a blog entry where I request that HHS/ONC/HIT leadership recognize that the current TP30 (BPPC) as meeting some simple needs, while continuing to push for continued developments.
I have posted a blog entry where I request that HHS/ONC/HIT leadership recognize that the current TP30 (BPPC) as meeting some simple needs, while continuing to push for continued developments.
The Office of the National Coordinator is weighing proposed requirements for how consumers’ preferences about their healthcare and personal health information could be made inseparable from their electronic health record.
According to a consumer preferences draft document, for which public comments were due Friday, standards built around the requirements would enable patient preferences about the use of their health information to be “interoperable” among those authorized to handle the record. More
Monday, October 19, 2009
Consumer Preferences and the Consumer
John Halamka posted a blog entry this morning where he discusses the current state of Consumer Preferences for data use (aka Consent to Privacy-Policy). He does a good job of explaining that this is critical to the success of Healthcare IT, and gives his views .
I commented that what he is asking for is supportable with TP30 today. I want to explain a little more detail here. He does leave out some of the details, so I will have to invent some details for him. I assume that he is indicating that a consumer would register a consent with every institution that they want to share data with, and only if there is a specific OPT-IN registered with that institution would information be allowed to flow into that institution. Which unfortunately means that any sourcing institution would somehow need to be able to recognize an OPT-IN policy that was agreed to by the patient at that target institution.
This is not a problem for TP30 (BPPC) today, but is a complexity that may not be as obvious to all readers. Because of this complexity, we would need to have a 'template' OPT-IN policy, where the language is clear as to what can and can-not be done. Given that we are trying for a simple system, lets assume we can say that this OPT-IN policy allows the receiving organization to use the data only for treatment purposes and allows them to archive a copy in their medical-record only for treatment purposes. This forbids secondary use of the data transferred (It says nothing about their own secondary-use of their own created data). We now have the precondition for TP30 complete, a defined policy written in human readable form. I would argue that the policy needs to cover an agreed list of data segments, user roles, and treatment uses including break-glass. TP30 does not require that we now convert this policy into an XML form, a key question I had on John's requirements. But it does require that we globally identify this policy with an OID, lets say 1.2.3.4.5.6 (the standard example OID).
So, a patient would go into an agreement with a receiving institution, possibly signing a copy of the policy on paper with a pen. The institution would create a TP30 document, which is a CDA document that encapsulates the 'Act' of the patient agreeing to the specific privacy policy. Thus we have the patient identity, receiving institution identity, and the policy agreed to identified (OID). This CDA document is registered in the local HIE announcing to the rest of the NHIN that this receiving institution does have an agreement with the patient for this OPT-IN policy. This receiving institution now attempts to query across the NHIN and/or receive documents from other sourcing institutions. The sourcing institutions will not return results unless they can see evidence that the patient has agreed with the OPT-IN policy with that receiving institution, they can in this case so they return the results requested.
This is exactly what the NHIN did with TP30, and they actually went one step further and did this type of enforcement in the NHIN backbone. They can do this because they can see that the receiving institution is authorized by the existence of the CDA document being registered.
The hard part is getting someone to write the policy language. TP30 even envisions that there could be a small set of policies, including those postulated by John (bold added by me)
In my experience, something simple such as opt-in consent for data sharing at the institution level, will result in much more privacy because the security technologies required to support it are simple and easy to understand.Including his vision of requirements (bold emphasis added by me):
My ideal plan for consumer preferences would be
1. We develop national policy which clearly delineates the types of consents we need to support. Ideally, this will be a short list. I prefer consumer opt-in at the institution level. To be compliant with ARRA and state laws I can imagine this being expanded a bit to include very basic segmentation of the record into mental health, HIV results, and everything else.
2. This consent will be recorded electronically and made available via a health information exchange, the PHR of the patient's choice, or via a mobile storage device such as a USB drive. When a patient presents for care, the consent is queried, and all data exchanges follow this declaration of confidentiality preferences.
3. The standard for recording consent would be XML-based and not require a "wet signature" or an image of a signature. I realize that some state laws still require handwritten consents, so policy work is needed here.
Given all this activity regarding consumer preferences, control, and empowerment, let's hope the policymaking gets done by 2011 and the standards to support the policy can be simple to deploy and manage. The more complex meaningful use data exchanges in 2013 and 2015 depend upon it.
I commented that what he is asking for is supportable with TP30 today. I want to explain a little more detail here. He does leave out some of the details, so I will have to invent some details for him. I assume that he is indicating that a consumer would register a consent with every institution that they want to share data with, and only if there is a specific OPT-IN registered with that institution would information be allowed to flow into that institution. Which unfortunately means that any sourcing institution would somehow need to be able to recognize an OPT-IN policy that was agreed to by the patient at that target institution.
This is not a problem for TP30 (BPPC) today, but is a complexity that may not be as obvious to all readers. Because of this complexity, we would need to have a 'template' OPT-IN policy, where the language is clear as to what can and can-not be done. Given that we are trying for a simple system, lets assume we can say that this OPT-IN policy allows the receiving organization to use the data only for treatment purposes and allows them to archive a copy in their medical-record only for treatment purposes. This forbids secondary use of the data transferred (It says nothing about their own secondary-use of their own created data). We now have the precondition for TP30 complete, a defined policy written in human readable form. I would argue that the policy needs to cover an agreed list of data segments, user roles, and treatment uses including break-glass. TP30 does not require that we now convert this policy into an XML form, a key question I had on John's requirements. But it does require that we globally identify this policy with an OID, lets say 1.2.3.4.5.6 (the standard example OID).
So, a patient would go into an agreement with a receiving institution, possibly signing a copy of the policy on paper with a pen. The institution would create a TP30 document, which is a CDA document that encapsulates the 'Act' of the patient agreeing to the specific privacy policy. Thus we have the patient identity, receiving institution identity, and the policy agreed to identified (OID). This CDA document is registered in the local HIE announcing to the rest of the NHIN that this receiving institution does have an agreement with the patient for this OPT-IN policy. This receiving institution now attempts to query across the NHIN and/or receive documents from other sourcing institutions. The sourcing institutions will not return results unless they can see evidence that the patient has agreed with the OPT-IN policy with that receiving institution, they can in this case so they return the results requested.
This is exactly what the NHIN did with TP30, and they actually went one step further and did this type of enforcement in the NHIN backbone. They can do this because they can see that the receiving institution is authorized by the existence of the CDA document being registered.
The hard part is getting someone to write the policy language. TP30 even envisions that there could be a small set of policies, including those postulated by John (bold added by me)
2. Policymaking can constrain technological complexity. If every possible permutation of consent (opt in, opt out, segmentation of the record, approval for sharing at the institution level, approval for sharing at the provider level, approval based on the situation - emergent care or not, etc.) needs to be supported by every stakeholder exchanging data, then the number of standards needed will be significant. Ensuring comformance with a large number of standards at every point of data exchange will be challenging. In my experience, something simple such as opt-in consent for data sharing at the institution level, will result in much more privacy because the security technologies required to support it are simple and easy to understand.So you see, I think that TP30 as it is currently specified, using IHE-BPPC, can and should be used right NOW to give consumers choice, while we continue to develop a privacy/security policy schema and vocabulary that will give them more expressive ability in the future.
Sunday, October 18, 2009
How Private can Electronic Information Ever Be?
This article is yet another article that is discussing how a university researcher took some de-identified data, netflix in this case, and claim they have re-identified some of the customers.
But it does point out that de-identified data can sometimes be re-identified with some effort, something I have already blogged about De-Identification is highly contextual. Thus any de-identified data set must still be considered sensitive, it is just less sensitive than it was before. How much effort it takes is dependent on how much data is left in the data set, and how public the individuals of interest are.
The tie to healthcare is that this article then draws a line between movies-watched to health-information, and some of the typical discussions around the sale of de-identified health-information. There is some discussion of this, but it is clear this section of the article was intended to be google friendly, making sure they used every keyword they could come up with. The article even concludes with a quote from Deborah Peel, a rather interesting point that there is a lack of laws against the act of re-identification. It might be useful to have a law like this.
Their claim is only that they were able to identify some of the customers, customers who had them-selves posted public reviews of the movies they watched. Thus I am not sure this is really a good example of re-identification as the customer had already identified them-selves.By comparing the film preferences of some anonymous Netflix customers with personal profiles on imdb.com, the Internet movie database, the researchers said they easily re-identified some people because they had posted their e-mail addresses or other distinguishing information online. More
But it does point out that de-identified data can sometimes be re-identified with some effort, something I have already blogged about De-Identification is highly contextual. Thus any de-identified data set must still be considered sensitive, it is just less sensitive than it was before. How much effort it takes is dependent on how much data is left in the data set, and how public the individuals of interest are.
The tie to healthcare is that this article then draws a line between movies-watched to health-information, and some of the typical discussions around the sale of de-identified health-information. There is some discussion of this, but it is clear this section of the article was intended to be google friendly, making sure they used every keyword they could come up with. The article even concludes with a quote from Deborah Peel, a rather interesting point that there is a lack of laws against the act of re-identification. It might be useful to have a law like this.
Subscribe to:
Posts (Atom)