Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts

Sunday, April 1, 2012

CMIO Survival Skills

While a CMIO is there to help implement the technology, so much of the job is process, workflow, and governance. So since I've now been in the role for five years now, I thought I'd take a moment to look back and reflect on the things I've learned in the last five years that I think are valuable CMIO skills.
Here are the 13 most important skills I can think of, off the top of my head, in my usual tongue-in-cheek style : (Remember, as always - Your mileage may vary, depending on your circumstances.)
  1. Hospital Governance 101 -  It's not enough to just know the clinical side of governance. You need to know the administrative side too. Both of these wings of hospital governance intersect with each other in different places, and knowing where they meet with your bylaws is vitally important. You will be navigating both, so it pays to know the landscape. Bonus points are awarded if you can diagram your committee structure by heart. :)
  2. Document Management - Understanding the basics of how documents are created, drafted, approved, and published is essential. Bonus points are awarded for knowing the details of these steps well - For starters, I wrote a post on the importance of knowing the difference between DEV, TEST, and PROD - These environments typically exist for computer projects, but in reality they apply to all construction and document development (even that email you just sent!). Know them well, why they exist, and how to use them to your advantage in your organization.
  3. Definitions and structure of your Clinical Tools - You should know your clinical tools like the back of your hand - Exactly how your organization defines them, drafts and builds them, tests and reviews and vets them, approves them, and publishes them. You should be able to look at them and have opinions on whether they are as effective as they can be. For starters, the CMIO's checklist is a good place to start working on this. Bonus points are awarded if you can recite your organization's definitions off the top of your head. :)
  4. Compliance with State and Federal Regulations - You will need to know these well, and will probably be asked to help your organization comply with some of them. Even if you don't know them very well, you need to have a good relationship with your regulatory people, and know where to look when you have questions. Bonus points are awarded as you gradually learn this landscape better.
  5. Project Management and managing 'the technical details' - You will need to know the basics of this - Whether or not you have a separate project manager to work with, you will be involved in many projects. Knowing what to expect at different stages when undertaking large month- and year-long projects is very helpful. As for the technical details, you may not want to know how sausage is made, but if you (or your organization) wants to eat sausage (pardon the metaphor), then someone will have to worry about the technical details. If it's not you, then make sure you have a good relationship with the people who understand the details, and work with them closely when undertaking new projects. 
  6. Parliamentary Basics - You will probably be asked to chair a committee or two, and be a member of others. Knowing how to properly run a meeting and conduct a committee is crucial. For starters, Robert's Rules of Order is a fantastic place to start. Also make sure you have a formal, written charter - It not only establishes your authority, it establishes the chain-of-command and is essential for good performance and when questions come up. And a tip : Always publish your minutes after approving them at the next meeting. If you wait to format and approve your minutes, they will just build up and you'll have to play catch-up later.
  7. Meaningful Use, emerging Health IT Trends, and Workflow Analysis - It's almost impossible to keep on top of every detail, but you should have a good understanding of the Meaningful Use rules, timelines, and how your organization is responding to them. You should also understand the basics and be able to comment on various existing and emerging HealthIT, clinical, and legal trends, including your statewide HIE effort, NHIN, ICD-10, clinical decision support, mobile devices, HIPAA, eDiscovery, etc. Finally, you should understand the basics of workflow analysis and why it's necessary to implement all of this technology. A good way to learn to think in a linear fashion is to read food recipes - This will help you think about the relationship between process and outcomes, and help teach you to write a good procedure.
  8. Safety through Information - Safety is not just resident workforce hours and barcoding your medications. Safety needs to be built into all of the documents and information you're overseeing. First, know what a good order set and a good protocol look like - Then learn what good documentation, good policies, good procedures, good guidelines, and good workflows look like. This is one of the big reasons organizations look for a CMIO, so always look for opportunities to improve safety with every tool you see.
  9. Networking - Virtually every hospital is going through Meaningful Use together. You will help save yourself a lot of headache if you know the other CMIOs in your area. Use social networking (e.g. Twitter), or call them up, introduce yourself, and meet them just to talk shop every once in a while. The Interstate 91 Informatics group I've set up has been invaluable to me and others in helping to share lessons and best practices. Look to see if there's any regular gatherings in your area, and try to get to at least one of the national conferences every year (e.g. HIMSS).
  10. Teambuilding, cheerleading, politics - You will undoubtedly meet other doctors, nurses, pharmacists, and other ancillary staff, and need to meet with them. Often, EMRs demand more collaboration between clinical specialties, so you will have to know how to encourage people to work together. Don't try to play sides or favorites - Treat everyone equally and you'll be able to build those teams.
  11. Budgeting realities - Implementing an EMR is expensive. There are costs at every step of the way - Technical costs, training costs, costs to change workflows, staffing costs. "Flexible budgeting" is optimal, but in today's climate, most organizations are focused on cutting costs. Be prepared to work with your budgeting people, and always ask yourself, "What if we don't get everything we ask for?"
  12. Informatics Education - Whether you're the "Chief Medical Information Officer" or the "Chief Medical Informatics Officer", you will be discussing Informatics with many people, probably while you are defining this emerging role in your organization. The term is sometimes frightening to people, until they start to understand it. Don't try to teach too much at once - Small, frequent feedings are better, so try to meet with leadership for frequent, short meetings. Bonus points are awarded if you help set up an entire Informatics department.
  13. Statistics and Process Improvement - After your EMR go-live, you will probably be asked to help optimize the EMR - That means, looking at the results from go-live, and looking for ways to improve results, e.g. higher achievement of core measures, higher CPOE rate, etc. Learn how to get utilization data out of your EMR, and look for statistical relationships that help you improve your processes. Know what a Venn diagramcontrol chart, pareto diagram, and fishbone diagram are. Bonus points are awarded if you can write your own SQL code! :)
It has been enormously rewarding to me, and if you find yourself in the role, I hope it's equally rewarding to you. Although the first CMIOs appeared on the scene back in the 1990s, it's still a relatively new position (especially in the northeast), so be prepared for a lot of change and ambiguity when you start down the road. 

As always, I enjoy simultaneous teaching and learning - Feel free to leave questions, comments, or thoughts below!

Saturday, October 15, 2011

#SpeakFlower : A model for interconnectivity in US Healthcare

UNIQUE IDEA ALERT

So in my last post, I discussed the "patient identifier problem", and how it contributes to poor connectivity between systems. I discussed some of the political problems with sharing health information, and some common, differing perspectives. I also briefly discussed some of the models being developed, including NHIN/Direct (now officially called "The Direct Project").

One thing I forgot to mention that makes this all more complicated are the myriad of privacy laws - Not just HIPAA, but also various state laws about transmitting or even storing data about HIV and other transmissible diseases.

The challenge is then, how do we overcome these issues in the US?

There are a lot of issues to be worked out, clearly, but I think one of the major issues is simply making organized change with all of these political, financial, and technical obstacles in place.

I. WHO'S THE BOSS?

So let me first ask - Who's the most powerful person in healthcare?

I sometimes ask friends and family this question, and it's interesting to hear people's guesses. "Obama?" "Hillary Clinton?" "The insurers?"

My response : It's the patient.

I think people forget : The patient is the boss. They are the ones who pay the tab for healthcare, whether it's the insurance premiums they pay, or the taxes they pay... They are the one making the choice about where to go, and so they have enormous influence about who succeeds in healthcare.

When it comes to healthcare reform, there is often talk about laws, and doctors, and insurance companies, and nursing unions, and medicare and medicaid - But I think patients are an untapped resource in the healthcare reform discussion.

The problem is that, from my experience, a lot of patients are sort of like the substitute teacher we all had in grade school - Even though they are technically in charge, they're new, they just showed up today, they don't entirely understand the routine, and so they sometimes lack confidence and can be subject to "But-Mrs.-Smith-we-ALWAYS-have-three-hours-of-recess"-type arguments that sometimes steer them.

So I've often wondered - What if a group of coordinated, informed patients could really assert their power?

II. COORDINATING A CHANGE

The problem is, as I said, most patients are too new, or too inexperienced to know what to look for. When doctors and nurses become patients themselves, they can be some of the most challenging patients - Why? Because they know what to look for and how to assert their power.

So then I wondered - Could we somehow train all patients to know what to look for? Could we get patients to ask for different care? How would they know what to ask for?


So I thought - To help patients assert their power to make change, we need to make it easy for them to ask for change

So then I thought of solutions. For those readers who are multi-lingual, or amateur linguists, you'll appreciate this : Language is fluid. It's not as precise as most people think. Even though modern English has been around since about 1550, linguists know this : words enter and leave the lexicon all the time.

So what if we employed a linguistic feat and came up for a new word for this new type of healthcare? Something evidence-based, efficient, affordable, and connected?

How could we get patients to ask for this type of healthcare? What if we could get lots of patients to ask for this type of healthcare?

III. DEVELOPING THE STANDARD FOR INTERCHANGE

The first trick is, defining a standard for this future model. From the ground up, the new healthcare paradigm has to be built. The informational framework for healthcare has to be laid to allow hospitals to run efficiently, and for patients to be able to - only if they wish - bring their data with them. That is, one patient = one chart. So when a patient moves from one office to another, the systems will talk to each other and allow true data portability - Without having to push or pull the data.

Why would a patient want a standard for data portability? Why would they care that other doctors can read their chart from another hospital?
  • It reduces errors (because doctor A knows what doctor B has been doing)
  • It reduces unnecessary tests (because doctor A knows what doctor B already ordered)
  • It reduces costs (because fewer tests means lower bills)
  • It reduces waiting times (because doctors don't have to spend time trying to research your history)
What if we could make a standard for data portability? Obviously, many patients would refuse, citing personal privacy reasons - But would other patients ask for this?

IV. THE SPEAKFLOWER PROPOSAL

The next trick would be, naming the standard something easy. A lot of "Health IT standards" have names like HL7, CCR, CCD, LOINC, DRG, ICD-9, etc.... Not too tangible to the average patient.

But what if we named this standard something really warm and friendly and tangible... Like "SpeakFlower"?

In other words, "SpeakFlower" is a placeholder for a standard that allows a patient to ask for a doctor/hospital/office to have all of their medical records transferred to a central site that the patient controls, so that other doctors could look at it in the future. It means not only building a particular HealthIT standard into the EMR, but also adopting the practices needed to employ it.

Could we get patients to ask for SpeakFlower? What if they did?

V. SELLING THE CONCEPT

The joke goes, "Standards are like toothbrushes - Everyone knows what they are, but nobody wants to use yours." We have lots of different EMRs, and a few standards, and yet there doesn't seem to be universal agreement on which standard to use, and how to use them.

Why? I think there are a lot of reasons - Complexity of our healthcare system is one, but there's also privacy issues and a lot of competing financial interests. In the end, fighting for a national standard is very challenging.

So what if a coordinated group of patients developed a 100% optional, national standard and how to use it? And what if they called this optional standard SpeakFlower?

Could we sell this concept of an optional national standard? I think so.

After developing the SpeakFlower technical framework (HealthIT standards, central servers, HIPAA-secure gateways, etc.) - You then need to teach patients about SpeakFlower. And how to do this?

Imagine a commercial on the Superbowl, where Wilford Brimley comes out and says :
"You know, my primary care doctor almost ordered something that interfered with something my cardiologist gave me last week, because she didn't know what my cardiologist had prescribed. And my cardiologist almost ordered a test I had last week in the ED because he didn't know what the ED doctor had done. And all of these extra tests, bills, and waiting time are really getting me down... But now, with SpeakFlower, all of my doctors can share my information easily and I get to keep track of it. So ask your doctor... Do you SpeakFlower?"
Why Flower? Because flowers are ubiquitous. They come in every shape and size, are found in every country in the world, and no matter what it looks like, it's still a flower. Flowers are friendly, peaceful, and represent growth, life, and vitality. This optional standard that patients might ask for should represent peace and life.

Oddly enough, if you diagram the model that puts the patient at the center of the medical record, and have all of the providers/hospitals/labs/pharmacists as connections to the patient in the center - The diagram almost invariable ends up looking like a flower.

Why speak it? Because like a person trying to communicate in a foreign language, we might ask for someone to speak the language we know. Asking to SpeakFlower is asking a doctor/hospital's EMR to speak a particular language - It says, "Please have your EMR speak the language I need to accomplish the goal I'm asking for."

VI. REALLY?

The hope would be that simply discussing an optional, national standard for healthcare data interchange would be enough to get all vendors, doctors, and hospitals to adopt the standard and implement it for those patients wanting their charts to be portable. It would also help simplify the privacy discussion, because patients would actively seek out SpeakFlower - Makes the whole discussion on "opt-in-or-opt-out?" much simpler. It would also allow docs and hospitals to generally keep their legacy systems - Implementing SpeakFlower does not require painful amounts of programming, just adherence to the SpeakFlower standards.

But if the discussion wasn't enough, then the hope is that the Wilford Brimley commercial on the Superbowl could spur the discussion - in the same way pharmaceutical companies have gotten patients to ask for drugs, patients could start showing up saying, "Dr. Stanley, do you SpeakFlower in your office?" and have an understanding of the benefits of SpeakFlower.


And even if 30% of my patients asked me to SpeakFlower,  I'd probably have little choice but to make sure my EMR SpokeFlower, for those patients requesting it. So I'd speak to my vendor and ask them to make sure my EMR can SpeakFlower.

VII. SPEAKFLOWER TODAY

If only...

There is a SpeakFlower.org web site, which I started to develop with two colleagues in our spare time,  but you'll notice the web site is outdated and quite frankly, we realized planting SpeakFlower in our national garden would require much more time and capital than we currently have. (Namely, weekends and nights.)

But we're still trying to build it and transplant it to the right FlowerPot. Our hope is to make SpeakFlower a force of good in healthcare. We also have a #SpeakFlower hashtag on Twitter that we apply to tweets that discuss patient-centered electronic medical records.

Healthcare needs innovative ideas. If you're interested, follow @SpeakFlower on Twitter, feel free to use the #SpeakFlower hashtag, and look for the SpeakFlower gardening team as we look for the right pot to plant in. :)

As always, I welcome any comments and thoughts. 

Monday, September 19, 2011

"Why don't these systems talk to each other?"

Another frequent question I get asked in my job is, "These systems are all plenty expensive - Why don't they talk to each other?"

What this is referring to, of course, is the common phenomenon that the EMR at one hospital may not seamlessly transfer a patient's record to another EMR down the street.

There are actually a few reasons why this is so, but one of the most interesting ones is a phenomenon called the "patient identifier problem."

Q: DIRK, WHAT EXACTLY IS THE "PATIENT IDENTIFIER PROBLEM"?

Here's what it boils down to : It's much harder to identify a human being than you might imagine.

Allow me to explain. (Names below are purely fictional, just for teaching purposes.) :)

So at first glance, it should be easy to identify a human being. After all, we have names, right? When we see our neighbor John mowing the lawn, riding his mower - His name is John - We recognize him - Yep, that's him. Easy, right?

Well the problem is what happens when we actually try to identify someone on paper - That is, have a record that we can match to an actual human being.

At first, we might try to label a chart "John's Chart". The problem with this approach is that there may be lots of Johns, so in a small town (even on a small street), you might have two "John's Charts".

So you might add the last name : "John Smith's Chart". This might work in a small town, but when you expand to collect charts for your whole state, or the whole country, you might find over 700 "John Smith's".

So names are generally a bad way to label a chart for a few reasons :

  1. There might be over 700 "John Smiths" across the country - How will you know which chart is the right one to look for?
  2. Your neighbor, John Smith, might register at Clinic A as "John Smith", at Clinic B as "Johnathan Smith", and at Clinic C as "Jon Smith". This could potentially make three records. How will you know which is the proper record to search for?
  3. Names may also be misspelled by registration staff - If a "Karen" registers in a clinic, will the registration staff write "Karen", "Caryn", "Karin", or "Karyn"?
  4. Ethnic names, over a large country, also may suffer from the poor understanding of the host country. How exactly does one spell Dimitry? Dimitri? Dimytri? Moroch? Morocz?
So one might try to straighten this out with some simple recipe - One I often hear first is, "Why not use the first three letters of the first name, first three letters of the last name, and the date of birth?"

The problem with this approach, again, is that someone might register with a different name in a different clinic. Is it going to be "JOHSMI01011970" (John) or "JONSMI01011970" (Jon)?

Then the suggestions usually continue...

Q : "Dirk, what about by the Medical Record Number?"

The medical record number for this patient at your hospital (123456) may not be the same as the medical record number for the office down the street (654321).

Local medical record numbers might work for a hospital, or a small regional group (if you have centralized registration), but they generally don't work across different healthcare systems.

Q : "Hmmm... Why not use the social security number to identify people?

The social security number suffers from a few problems too :
  1. There is no check-digit in the social security number. A check-digit is a number (or series of numbers) that are mathematically linked to the other numbers, so you can figure out if the number has been falsified. The social security number was invented back in 1935, before things like "identity theft" were around. As a result, the social security number is probably one of the most abused identifiers, often used for fraud by criminals. 
  2. The social security number is a 9 digit number - So in total, we should be able to issue about 999,999,999 of them, BUT... because of certain restrictions (e.g. no numbers that start with 666, no numbers with -13- in them, no numbers with all of the digits the same), there is really only a pool of about 820 million to draw from. Currently the U.S. population is about 350,000,000. Which sounds OK, except that we maintain that number by having some people die every year, and some new babies added every year. In total, about 620 million numbers have already been handed out, so we could potentially run out of social security numbers sometime around 2100. Yes, that will be some time from now, and hopefully we will be able to fix that before it happens - but in our current political climate, will the government ever be able to assign a personal identifier again?
It's funny - I've spoken to informatics people around the globe, and they usually ask me "Dirk, why are you guys in America having so much trouble getting a national health record? In our country it's very simple - Either :
  • "...our national government maintains our national health record.
  • ... or ...
  • "...our national government assigns a health identifier for all citizens."
Well, the problem is that we're Americans. Authors like George Orwell and Ayn Rand have left a significant impression on our national consciousness. We just don't like the idea of the government assigning a number to track all of our health information. In fact, in 1998 Congress forbade the HHS, by law through HIPAA, from creating a health information identifier - Despite many groups asking for an identifier, and an estimated $77 to $154 billion savings in healthcare that a national patient identifier could provide. And perhaps (just to be fair), this is for good reason - see this letter opposing government-issued medical identifiers and this document summarizing the potential abuses. (Please note : I'm not taking sides, just presenting both sides of the argument.) 

Q : "So Dirk, how does the VA (Veteran's Administration) do it? I heard they saved lots of money through their VISTA/CPRS medical record, and their record is a major source of data for reasearch."

The VA essentially has a national patient record because, well, most veterans have a different opinion. When you ask most vets, "Do you care if the government has a number to track you?", they say things like "No, the government has been keeping a file on me since the day I enlisted!" right before they rattle off their rank and military ID number from memory. In reality, the VA has also been using Social Security numbers, but I understand there is currently a movement underfoot to move away from those identifiers to another number - I'm not an expert on the VA architecture, but this might explain why they divide the VA record up into different VISN systems. (Any VA Informatics people reading this willing to help explain the architecture?)

In short - 
  • The culture at the VA supports a nation-wide medical record number.
  • The culture of private and teaching hospitals (the "rest of America") does not.
This is why, when I get asked :

Q : "Dirk - The VA has free EMR software - Written by the government, so it's public domain - Why don't private hospitals use it?"

I usually answer, "Private hospitals *could* use it, but because of these culture differences they probably wouldn't see the cost and efficiency benefits that the VA did."

(In reality, there are also other support reasons why a private hospital might not implement CPRS/Vista - But that might be changing some with cool open-source projects like OpenVISTA.)

Q : "So Dirk, is there any hope for a national EMR? Will patient data ever be truly portable?"

Well, currently there is the NHIN/Direct project (see http://www.directproject.org and http://wiki.directproject.org) which seeks to allow physicians to transmit patient data, securely, between different offices - But without a common patient identifier, this may not have the workflow some patients and most physicians ideally want. Still, it would allow a maximum of privacy and patient control, and it's at least a step in the right direction.

There are also a number of regional Health Information Exchanges currently in use, and new ones being built - But without a common patient identifier, nobody seems to be sure about how this is going to work on a bigger, national level.

So yes, if you're traveling from Texas to NYC for vacation - You had probably better bring your medication list and medical history written on a piece of paper, just in case you need medical care.

Finally - I think there is actually some hope for a solution to this that could fly politically in America.  I've tested the idea with both republicans and democrats and oddly, both seem to like it. It's called the voluntary patient identifier. Unfortunately, I think so far this effort suffers from poor understanding, poor marketing, and quite frankly, poor patient interest. 

But I think there is a way to change that - I'll describe it in my next post.

(Ooh - Cliffhanger ending!) :)

Always glad to share - Feel free to leave comments, thoughts, and questions! :)