Minggu, 31 Mei 2009

Enhancing Health Information Exchange in Massachusetts

The HIT Policy Committee and its Meaningful Use Working Group will be defining meaningful use very soon. Although I have no inside knowledge of what meaningful use will be, I think it will likely include several elements of health information exchange.

To me, health information exchange is three things

1. Policies for exchange which protect confidentiality, ensure compliance with regulations, and meet the service expectations of stakeholders.

2. Workflow which supports the business processes of payers, providers and patients.

3. A technical architecture which implements the workflow.

To achieve meaningfully useful health information exchange, Massachusetts has recently convened three committees under the auspices of the Eastern Massachusetts Healthcare Initiative. During May and June, we'll complete meetings of our Policy Committee, the Workflow Committee and the Architecture Committee which will take our existing health information exchanges to the next level.

I'm an active participant in these activities and want to share our work in progress with you.

Policy Committee - we're working through complex issues of consent, liability, service levels, and the division of responsibility between the health information exchange and local organizations sending/receiving data. Last Friday, we discussed these issues in detail. Here's the powerpoint outlining the issues and the draft policy for health information exchange we have developed thus far, based on our experience with NEHEN.

Workflow Committee - There are several high priority workflows among our stakeholders including clinical summary exchange, referral management, admission notification, results exchange, and quality reporting. Here's an overview of our workflow activities in progress.

Architecture Committee - In Massachusetts, we've tended to implement a service oriented architecture using CAQH Core Phase II common data transport and XML constructs such as CCD. I'll post the details of our implementation guides when they are complete.

With sound policies, prioritized workflow, and a single architecture including content, vocabulary, and secure transmission standards, Massachusetts will be "shovel ready" for health information exchange supporting meaningful use by this Summer.

Jumat, 29 Mei 2009

Cool Technology of the Week

In my recent blog about the Red Flags rule, GreenLeaves commented that biometric checking would help reduce errors by establishing identity and uncovering fraud.

Using biometrics to verify identity seems like a good idea, so I met with Jim Sullivan from BIO-key, a leading provider of biometric solutions.

In the past, I've been reluctant to adopt biometrics because of the expense of buying fingerprint or Iris scanners for each of my 8000 client devices.

However, now that many laptops and hospital ready tablets include embedded fingerprint swipe scanners and that the price of USB fingerprint scanners has dropped significantly, it is realistic to consider biometrics.

BIO-key has developed a next-generation algorithm that reduces the fingerprint to set of calculated unique identifiers. A person’s fingerprint graphic is not the credential; their finger is. BIO-key ensures that only a real finger is being scanned to produce these unique identifiers, making a stolen fingerprint graphic useless to a potential imposter. It's the computed values that are stored when the user's finger is scanned at enrollment, and is later used for comparison with future scans. To me, it's similar to the way NTLM authentication works - there is no need to store or exchange the actual password, it's a mathematical hash of the password that is compared to a stored mathematical hash of the original password. BIO-key allows you to enroll and identify on most of the different fingerprint scanners in the market, allowing an open, heterogeneous fingerprint hardware environment.

There are several interesting ways that biometrics could be used in healthcare:

1. As an alternative authentication method for clinicians instead of having to constantly type a username and password. BIO-key provides a web-enabled fingerprint scanning authentication method that interfaces seamlessly between web applications and an enrollee database or Active Directory. Every authentication, from connecting initially to a secure Wi-Fi hub, to authenticating to Active Directory, to authenticating to web-based or thick client applications, can be done using a finger scan.
2. As a two factor authentication mechanism for secure remote access to sensitive data - instead of a token, you carry your finger with you wherever you go. Note that modern fingerprint scanners include measurement of living tissue, so your finger cannot be stolen and used as an authenticator.
3. As a way to protect patients from identity theft or mis-identification. The first time you register for care, you present your passport and your finger for scanning. On every successive visit, your fingerprint scan is used to verify your identity, without the need to hand-check the paper credentials again.

Some people may think that fingerprints are used to identify criminals and thus be reluctant to use a fingerprint scanner. As noted above, we're not using the fingerprint itself - this is not an FBI comparison to a stored library of fingerprints. Instead, it's comparing the scan of finger to specific computations made on earlier scans of the finger when the patient first registered. Hopefully, this will make patients accept scanning as a positive way to protect their identity instead of a negative "police-like" search of their past.

If you'd like to try this yourself, just get a USB fingerprint scanner or use a laptop with a built in fingerprint swipe reader such as HP, Lenovo, or Dell. Go to http://www.bio-key.com/hitdemo.asp and follow the instructions to download the web client and test the fingerprint enabled applications. Note that it only works in Windows at this time.

A simple way to prevent identity theft and to authenticate web applications using your finger. That's cool!

Kamis, 28 Mei 2009

Data Center Space in the Northeast

Yesterday I wrote my personal blog for the week, so today's blog is a return the typical issues of a CIO - building and renting data centers in the Northeast.

I was recently asked about a report being published this week on health care data center costs in Boston compared with other U.S. metropolitan areas. The report claims that, although huge opportunities exist for data center providers to house growing amounts of health care data, the high costs of running a data center in Boston and other Northeast cities will drive providers to house their data in low-cost areas in the Midwest.

Here's my view of the needs of healthcare CIOs for data center space in the Northeast.

My sense is that most IT organizations are embracing virtualization which reduces server space needs. However storage needs are increasing 25% per year, consuming more space.

Thus, the demand for data center real estate, on average, will experience modest growth. Healthcare data center space is not likely to cost much more than typical data center space.

The choice of build/owned verses co-located data center space is mostly a function of network connectivity and capital availability.

The breakout of BIDMC data center expenses, not including the operating and capital needed to suppport our applications is roughly as follows:

Space and Utilities 15%
Salaries & Benefits 29%
Elect Wiring/KVM/LAN Cabling/Racks/Etc. 5%
Storage 18%
Tape/Backup 4%
Servers 14%
Monitoring Software 3%
Network 1%
UPS/PDU/CRAC 11%

Moving the data center to the Midwest MAY save on space cost and would likely save on energy. Most of the other costs would be the same whether we were located in Boston or Lincoln, Nebraska. Some costs may actually be higher in the Midwest as we are within driving distance of engineering support centers for some of our OEM's such as EMC. We currently have a favorable space rental rate compared to the square foot cost of hosting facilities in Boston. Consequently, savings for us is not going to be as great as it may be for other companies who use hosted space. Moving the data center MAY also reduce computer operations salaries, but that's questionable and assumes the labor pool is readily available in the Midwest.

I estimate the annual savings for space, utilities, and salaries, in our case, would be $150k to $300k per year. Offsetting this would be increases in wide area networking expenses and, given the distance, there would need to be dual paths for redundancy which would increase the expense. There would be a significant one time expense for the relocation cost. The combination of these could easily overwhelm any projected savings.

Relocating the data center would also require a major project that would absorb much of IT's time thereby causing us to halt or slow down other, more pressing requirements of the Medical Center. There would also be a risk element in that we would be placing our IT assets in the hands of a party we do not directly control except through contract terms and conditions.

Unlike some companies that have national or international presence, we are limited to metro-Boston. The incentives to relocate the data center to the Midwest are not compelling for us.

I predict Boston and Northeast data center space will continue to be well utilized.

Rabu, 27 Mei 2009

The Number 5

In the movie "The Number 23", the main character played by Jim Carrey is obsessed with the idea that all incidents and events are directly connected to the number 23, some permutation of the number 23, or a number related to the number 23.

I'm not obsessed, nor do I have OCD in any way, but much of my life is neatly organized into groups of 5.

Why 5?

I find that 5 is the maximum number of tasks I can do simultaneously without losing track of the details. Here's my framework for my career and personal life

Career
1. BIDMC - As CIO of BIDMC, I have 5 direct reports
a. Clinical Systems
b. Financial Systems
c. Infrastructure
d. Knowledge Services (includes medical library and all online
e. Media Services

2. Harvard Medical School - As CIO of HMS, I have 5 direct reports
a. Administrative IT
b. Educational IT
c. Informatics
d. Infrastructure
e. Research IT

3. Standards- Chair of HITSP and Vice-chair of the HIT Standards Committee (Although the work we're doing includes 5 Tiger Teams,that was not a conscious choice on my part!)

4. Healthcare Information Exchange - Chair of NEHEN and CEO of MA-Share (MA-Share and NEHEN merger will be finalized in June) which supports 5 different use cases for data sharing.

5. Advisory Councils - I have 5 advisory positions
a. Food and Drug Administration Subcommittee on IT
b. Social Security Administration Future Technology Advisory Panel
c. Anvita Health Board of Directors
d. Epocrates IT Advisory Council
e. Robert Wood Johnson Foundation National Advisory Committee for Project HealthDesign

Personal Life
1. Family - (wife, daughter, mother, father and me)
2. Home and Garden (my Thursday blog will describe my 5 small gardens)
3. Japanese Flutes (I have 5 instruments)
4. Outdoors - (Hiking, Kayaking, Climbing, Running, and Biking)
5. Writing (blogs, IT journals, academic publications, popular press, lectures)

Each night before bed, I review my 5 career organizations and my 5 direct reports in each of my jobs to ensure I've resolved all the issues of each day. By always balancing five tasks, five people, and five projects in every area, I maximize my breadth without sacrificing the depth of my attention span.

There's no need to worry about my sanity, the number 5 is just a convenient mnemonic and not a pre-requisite for getting through the day. And now it's time to prepare for my 5 meetings tomorrow...

Selasa, 26 Mei 2009

A Personal Reflection on Standards Harmonization

As HITSP prepares for the demands of ARRA by reorganizing its work around meaningful use rather than use cases, here is my view of the state of standards harmonization in the US. This is my personal opinion, not a statement from HITSP or ONC.

1. Medication management and e-prescribing

This area is very mature and widely implemented.

NCPDP Script 10.5 is the right messaging standard to support e-prescribing workflow in ambulatory and long term care settings.

The National Library of Medicine's RxNorm is the right vocabulary to specify medication names.

The Food and Drug Administration's Unique Ingredient Identifier (UNII) is the right vocabulary for chemical substances and is especially useful in allergy checking.

Structured SIG, although still evolving, is good enough to describe the way to take a medication.

The Veterans Administration's National Drug File Reference Terminology (NDF-RT) is the right vocabulary for medication class and is especially useful in drug/drug interaction checking and formulary enforcement.

There are few controversies in the medication standards area. The only outstanding issues are the fact that some of these standards such as Structured SIG and RxNorm are relatively new and continue to evolve.

2. Laboratory

HL7 2.51 is good enough for results reporting to EHRs, public health, and biosurveillance.

LOINC is the right vocabulary for lab test names.

UCUM, although very new, is a reasonable vocabulary to describe units of measure.

The only controversy around lab is the timing of implementation, given that thousands of commercial labs in the US need to update their interfaces to support HL7 2.51, LOINC and UCUM. Of these, standardizing units of measure with UCUM is probably the most controversial, given that using UCUM is new for lab stakeholders. I've recently spoken with healthcare IT leaders from other countries and all agree that standardizing units of measure for labs is a priority and should move forward.

3. Clinical Summaries

Just about all stakeholders agree that clinical summaries (problem list, medication list, allergy list, diagnostic test reports, discharge summaries, other documents) should be represented in XML.

The question is what flavor of XML - HL7's Clinical Document Architecture or ASTM's Continuity of Care Record.

HITSP harmonized these two approaches with the HL7 Continuity of Care Document (CCD).

The major controversy in the area of clinical summaries is the nature of the XML format and schema. Some have described the CDA as overly complex XML. I've also heard that some believe CCR's XML could be improved. My hope is that all stakeholders continue to work together to converge on a single, simple XML representation of a clinical summary that works for everyone and is more similar to the typical XML structures used widely on the web.

4. Quality Measures

The National Quality Forum's HITEP efforts have fostered a new way to represent quality measures in terms of a collection of data types. Additional work needs to be done to uniformly map these data types to specific standards. It's likely that the same standards mentioned above for medications, laboratory and clinical summaries will be suitable for transmitting quality measures to data marts.

The only controversy in the world of quality measures is the need to rewrite existing measures in terms of EHR data types. The National Quality Forum will be the catalyst for such a project.

5. Common Data Transport

The above discussion on medications, labs, summaries and quality has been about content and vocabularies, not the secure transmission of data from place to place. How should transport work for all healthcare data exchange?

Just about everyone agrees that the internet/TCPIP/HTTPS is the right approach. However, there are controversies about the other standards to be used - enveloping, authorization/authentication, and architecture.

Some have proposed simple RESTful web services. Some have suggested that SOAP with WS* constructs provides a more solid security framework.

In Massachusetts, we've used CAQH CORE Phase II with SOAP over HTTPS and X.509 certificates. We do nearly 100 million transactions a year with this approach and it works very well.

HITSP will work on harmonizing common data transport as part of its 2009 Extensions and Gaps efforts. It will harmonize the transport work done to date, the efforts of the NHIN pilots and the requirements of the Common Data Transport Use Case recently released to HITSP by ONC.


In general, how do we resolve remaining standards controversies by the end of 2009 when a interim final rule must be finalized per ARRA? Here's my understanding of the process:

1. The HIT Policy Committee will propose a set of priorities for "meaningful use", likely in the next 60 days. The National Coordinator will deliver these to the HIT Standards Committee.

2. The HIT Standards Committee and its 3 workgroups (Clinical Operations, Clinical Quality, Privacy and Security) will determine what existing accepted /recognized standards best support the HIT Policy Committee's priorities, likely in the next 90 days. The HIT Standards Committee will draw on the work of harmonization organizations (including HITSP), standards development organizations, and implementation guide writers. The Standards Committee will also engage NIST for standards testing.

3. The National Coordinator will review this work and if it is appropriate deliver it to the Secretary of HHS for acceptance and publication in the interim final rule.

There will be several periods of public comment and administrative review along the way.

What will HITSP's role be in this process? Initially it will provide expert testimony about harmonized standards to the HIT Standards Committee. In general, HITSP responds to the priorities established by the Office of the National Coordinator. It is independent of any particular administration/political party. If there is a need to approach priorities in a different way, HITSP will align to do that, just as it has with the ARRA focused efforts of the past 60 days.

Jumat, 22 Mei 2009

Cool Technology of the Week

Massachusetts Data Protection regulations require that data on portable devices be encrypted. As I've written about previously, we have encrypted all our laptops with McAfee Safeboot/Endpoint

However, it's commonplace for folks to backup their data on removable USB drives. How can we ensure portable drives are protected?

The answer is hardware encryption. I tested the Maxtor BlackArmor 160GB Encrypted Portable Drive and it's my cool technology of the week.

Here are the specs:

» Hardware-Based Full-Disc Encryption: Prohibits access without a password, no exceptions-not even a professional data recovery service can access the data without the password.

» KeyErase™: Permanent removal of encryption key allows secure redeployment of the drive.

» USB Powered: Powers your drive and ensures fast data transfer-

» 5400RPM, 8MB Cache Buffer: For fast drive performance and fast access to your files.

» Backup Software: Maxtor Manager software lets you easily set your automated backup schedule, sync to multiple computers, and restore files.

» Capacity (Model #): 160GB (STM901603BAA1E1-RK)
» RPM: 5400
» Cache Buffer: 8MB
» Interface: USB 2.0
» Bus Transfer Rate: USB 2.0 480MB/sec
» Dimensions: 5.17" H x 3.32" W x 0.67" L [131.2 mm x 84.2 mm x 16.9 mm]
» Weight: 7.20 oz [204.12 g]
» Warranty: 5 years

The software provided autostarts upon USB connection and sets the drive password. It only runs on Windows, so I had to test the device on one of our clinical subnotebooks - a Dell laptop running XP.

The drive mounted without a problem, queried for a password, and enabled me to place data on the device without error. Each time I reconnect the device it queries for my password. Without the password, the data is completely unreadable - I cannot even see the file names.

A portable, inexpensive, removable, hardware encrypted data store that complies with all current federal and state data protection regulations.

That's cool!

Kamis, 21 Mei 2009

Kayaking the Charles River

From Spring to Fall each year, I kayak 6 miles a day on the Charles River between route 128 and the Moody Street Dam.

My general rule of thumb is that I kayak when the sum of water temperature plus air temperature is greater than 120. The risk of hypothermia is much less when the water temperature is above 55 and the air temperature is above 65. This usually occurs sometime in May and lasts until October. Today's water temperature was 65 and the air temperature was 75F with a very light wind - perfect conditions.

The route I take passes through the "Lakes District" of the Charles - a wide, shallow, and particularly beautiful stretch for flatwater paddling.

I generally kayak between 5:30-6:30pm, stopping at the Charles River Canoe and Kayak boathouse on my way home. It's a great way to get some exercise and decompress - I can work a full day, kayak, have dinner with my family, and the continue to read and write until bedtime.

The early evening on the Charles is a perfect time to view widelife - Great Blue Herons, Trumpeter Swans, American River Otters, Snapping Turtles, and enormous Carp. The river is different every time I kayak with variable weather, changing wildlife, and new people. Today I did a rescue of a mother and daughter from Montreal who tipped their kayak in the deepest part of Charles. We did a T-rescue and all is well.

The boat I prefer is the Epic Kayaks V10 Surf Ski, a fast 17" wide boat that's a racing and fitness kayak, just unstable enough to keep the trip very challenging. In windy or turbulent conditions, I'll pick the Epic 18X. Here's my guide to choosing a kayak.

The other advantage of daily kayaking is the calorie burn - greater than 500 calories per hour.

Incredible sights, a relaxing river, 2500 calories of aerobic exercise, and an ever-changing riverscape. Highly recommended!