<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Healthcare Strategy</title>
	<atom:link href="http://lukegilliam.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://lukegilliam.com</link>
	<description>Posts on strategy, innovation, and market incentives in healthcare.</description>
	<lastBuildDate>Thu, 17 May 2012 05:05:01 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>Healthcare Data Bill of Rights &#8211; Provider Edition</title>
		<link>http://lukegilliam.com/2012/05/16/healthcare-data-bill-of-rights-provider-edition/</link>
		<comments>http://lukegilliam.com/2012/05/16/healthcare-data-bill-of-rights-provider-edition/#comments</comments>
		<pubDate>Wed, 16 May 2012 20:28:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Market Incentives]]></category>

		<guid isPermaLink="false">http://lukegilliam.com/?p=110</guid>
		<description><![CDATA[Who owns the data in a healthcare system &#8211; the vendor or the customer? If your contract doesn&#8217;t specify ownership &#8211;and&#8211; interoperability, then you don&#8217;t own your own data. Year after year, I see vendors dealing with the same problems &#8211; no timely and relevant exchange of patient data, which means very little or no patient <a href='http://lukegilliam.com/2012/05/16/healthcare-data-bill-of-rights-provider-edition/' class='excerpt-more'>[...]</a>]]></description>
				<content:encoded><![CDATA[<p><a href="http://lukegilliam.com/wp-content/uploads/2012/05/broken-chain-1024x768.jpg"><img class="size-medium wp-image-111 alignleft" title="broken-chain-1024x768" src="http://lukegilliam.com/wp-content/uploads/2012/05/broken-chain-1024x768-300x225.jpg" alt="" width="300" height="225" /></a>Who owns the data in a healthcare system &#8211; the vendor or the customer? If your contract doesn&#8217;t specify ownership &#8211;and&#8211; interoperability, then you don&#8217;t own your own data. Year after year, I see vendors dealing with the same problems &#8211; no timely and relevant exchange of patient data, which means very little or no patient data at the point of care.</p>
<p>On a recent visit to observe physicians at a local ED, I watched two doctors with six decades of combined experience reduced to file clerking as they logged into and searched multiple EMR systems, made phone calls, and dug through 60-page faxes to find relevant medical history. If I had known clerks would make $250/hour, I certainly would have reassessed my career choices.</p>
<p>Healthcare costs are high for many reasons, and poor interoperability is definitely one of them. Let&#8217;s review:</p>
<ul>
<li><a href="http://en.wikipedia.org/wiki/ASC_X12" target="_blank">X12 EDI</a> standards for insurance information exchange: originated in 1979</li>
<li><a title="HL7 on Wikipedia" href="http://en.wikipedia.org/wiki/HL7" target="_blank">HL7</a> standards for healthcare data exchange: begun in 1987, ANSI standard since 1994</li>
<li><a href="http://medical.nema.org/Dicom/2011/11_01pu.pdf" target="_blank">DICOM</a> standards for radiology images: first published in 1985</li>
<li>Bonus &#8211; <a title="History of SSO" href="http://www.opengroup.org/security/sso/sso_intro.htm" target="_blank">Single Sign-On</a>: has been evolving since the early 80s!</li>
</ul>
<p>Interoperability standards have been around for decades&#8230;</p>
<p>I propose that all healthcare IT contracts and renewals contain a Bill of Rights that codifies industry best practices for interoperability and imposes stiff penalties (AKA market incentives) for noncompliance. Instead of waiting on the<a title="HITECH Act" href="http://waysandmeans.house.gov/media/pdf/110/hit2.pdf" target="_blank"> billions-of-dollars</a> government incentives to drag the market forward, let&#8217;s improve patient outcomes right now. Come up with your own Bill of Rights, share it with other organizations, and let the vendors know that the level playing field of interoperability is where they must all compete.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://lukegilliam.com/2012/05/16/healthcare-data-bill-of-rights-provider-edition/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Multiple-Choice: Who is Responsible for Patient Privacy?</title>
		<link>http://lukegilliam.com/2012/04/28/multiple-choice-who-is-responsible-for-patient-privacy/</link>
		<comments>http://lukegilliam.com/2012/04/28/multiple-choice-who-is-responsible-for-patient-privacy/#comments</comments>
		<pubDate>Sat, 28 Apr 2012 12:05:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://lukegilliam.com/?p=93</guid>
		<description><![CDATA[Pop Quiz! Look around your doctor&#8217;s office, and ask yourself who among these people is protecting your private data. Is it: A) The doctor? I hope not! I hope my doctor spends all of her time learning to be the best doctor possible. B) The underpaid front desk clerk who just last week took a <a href='http://lukegilliam.com/2012/04/28/multiple-choice-who-is-responsible-for-patient-privacy/' class='excerpt-more'>[...]</a>]]></description>
				<content:encoded><![CDATA[<h2><a href="http://lukegilliam.com/wp-content/uploads/2012/04/padlock-in-old-town-san-diego.jpg"><img class="alignright size-medium wp-image-94" title="Public domain image, royalty free stock photo from www.public-domain-image.com" src="http://lukegilliam.com/wp-content/uploads/2012/04/padlock-in-old-town-san-diego-300x225.jpg" alt="Old padlock" width="300" height="225" /></a>Pop Quiz!</h2>
<p>Look around your doctor&#8217;s office, and ask yourself who among these people is protecting your private data. Is it:</p>
<ul>
<li>A) <strong>The doctor</strong>? I hope not! I hope my doctor spends all of her time learning to be the best doctor possible.</li>
<li>B) The underpaid <strong>front desk clerk</strong> who just last week took a computer training course to get this job?</li>
<li>C) The overworked <strong>PA or nurse</strong> who performs the bulk of routine care? Does he have time to look after your privacy?</li>
</ul>
<p>The answer is:</p>
<ul>
<li>D) <strong>None of the Above</strong>.</li>
</ul>
<h2>Who is responsible for protecting my data?</h2>
<p>The people responsible for your privacy are the ones you do not see because they are not there. Information security is a <a title="Google search for information security degrees" href="https://www.google.com/search?rlz=1C1CHFX_enUS447US447&amp;aq=f&amp;sourceid=chrome&amp;ie=UTF-8&amp;q=information+security+degree">specific field</a> of knowledge and skills that requires <a title="Google search for information security certification" href="https://www.google.com/search?rlz=1C1CHFX_enUS447US447&amp;aq=0&amp;oq=information+security+cer&amp;sourceid=chrome&amp;ie=UTF-8&amp;q=information+security+certifications">training</a>  and constant practice for proficiency. Have a look<a title="GIAC security essentials exam topics" href="http://www.giac.org/certification/security-essentials-gsec"> here</a> at sample exam topics for a basic certification. You don&#8217;t have time to learn all of this. Nor do you have the inclination, and neither do the people who practice and support medicine.</p>
<h2>Privacy is expensive!</h2>
<p>The bigger problem, though, is that most practices are not aware of the gap between what they know and what<a title="Summary of HIPAA" href="http://www.hhs.gov/ocr/privacy/hipaa/understanding/srsummary.html"> the law</a> requires. So, they are not budgeting for or hiring those who have the knowledge to perform a security risk analysis, educate the staff, and secure the technical infrastructure like computers, networks, and mobile phones, and they are also not budgeting for:</p>
<ul>
<li>Ongoing training on privacy issues</li>
<li>Ongoing maintenance of policies</li>
<li>Ongoing maintenance of IT</li>
<li>Monitoring for compliance and breaches</li>
</ul>
<p>This assumes private practices have the funds for such hirings and the time to supervise them. Likely, most do not, and so we will see many more stories like <a title="Phoenix practice fined $100,000 for HIPAA violations" href="http://www.hitechanswers.net/do-you-have-hipaa-security-and-privacy-exposure/">this</a>. As the market becomes aware of these issues through fines and negative publicity, we may see smaller practices decline as they roll up into hospitals or corporations in order to defray the costs of compliance.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://lukegilliam.com/2012/04/28/multiple-choice-who-is-responsible-for-patient-privacy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why is Healthcare So Complicated?</title>
		<link>http://lukegilliam.com/2012/04/27/why-is-healthcare-so-complicated/</link>
		<comments>http://lukegilliam.com/2012/04/27/why-is-healthcare-so-complicated/#comments</comments>
		<pubDate>Fri, 27 Apr 2012 17:47:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Market Incentives]]></category>

		<guid isPermaLink="false">http://lukegilliam.com/?p=81</guid>
		<description><![CDATA[If you are not in the healthcare space, you may wonder why there is so much talk about it. That&#8217;s too big of a question for one post, or maybe one hundred posts. Instead, let&#8217;s look at some of the industry players: patients doctors, nurses, PAs, NPs, and other clinicians administrators hospitals, private practices, labs, <a href='http://lukegilliam.com/2012/04/27/why-is-healthcare-so-complicated/' class='excerpt-more'>[...]</a>]]></description>
				<content:encoded><![CDATA[<p><a href="http://lukegilliam.com/wp-content/uploads/2012/04/complexity.jpg"><img class="alignright size-medium wp-image-88" title="complexity" src="http://lukegilliam.com/wp-content/uploads/2012/04/complexity-300x260.jpg" alt="illustrative diagram of complex relationships for many objects" width="300" height="260" /></a>If you are not in the healthcare space, you may wonder why there is <a title="Google news search for 'healthcare'" href="https://www.google.com/search?hl=en&amp;gl=us&amp;tbm=nws&amp;q=healthcare&amp;oq=healthcare&amp;aq=f&amp;aqi=d1g2g-s1g3g-s2g1d1&amp;aql=&amp;gs_nf=1&amp;gs_l=news-cc.3..43j0l2j0i10j0l3j0i10l2j0j43i400.1483.2432.0.2617.10.10.0.2.2.0.87.511.8.8.0." target="_blank">so</a> <a title="Google news search for 'meaningful use'" href="https://www.google.com/search?hl=en&amp;gl=us&amp;tbm=nws&amp;q=healthcare&amp;oq=healthcare&amp;aq=f&amp;aqi=d1g2g-s1g3g-s2g1d1&amp;aql=&amp;gs_nf=1&amp;gs_l=news-cc.3..43j0l2j0i10j0l3j0i10l2j0j43i400.1483.2432.0.2617.10.10.0.2.2.0.87.511.8.8.0.#hl=en&amp;gs_nf=1&amp;tok=Mj080I1ztLDOdc0hVvuykA&amp;ds=n&amp;pq=obamacare&amp;cp=6&amp;gs_id=2h&amp;xhr=t&amp;q=meaningful+use&amp;pf=p&amp;gl=us&amp;tbm=nws&amp;sclient=psy-ab&amp;oq=meanin&amp;aq=0&amp;aqi=g3&amp;aql=&amp;gs_l=&amp;pbx=1&amp;bav=on.2,or.r_gc.r_pw.r_cp.r_qf.,cf.osb&amp;fp=c74f0380bf40be70&amp;biw=1241&amp;bih=593" target="_blank">much</a><a title="Google news search results for PPACA" href="https://www.google.com/search?hl=en&amp;gl=us&amp;tbm=nws&amp;q=healthcare&amp;oq=healthcare&amp;aq=f&amp;aqi=d1g2g-s1g3g-s2g1d1&amp;aql=&amp;gs_nf=1&amp;gs_l=news-cc.3..43j0l2j0i10j0l3j0i10l2j0j43i400.1483.2432.0.2617.10.10.0.2.2.0.87.511.8.8.0.#hl=en&amp;gl=us&amp;tbm=nws&amp;sclient=psy-ab&amp;q=ppaca&amp;oq=ppaca&amp;aq=f&amp;aqi=g1&amp;aql=&amp;gs_nf=1&amp;gs_l=serp.3..0.26244.26682.0.26878.5.3.0.2.2.0.88.221.3.5.0.UDO0WFWUO1Q&amp;pbx=1&amp;bav=on.2,or.r_gc.r_pw.r_cp.r_qf.,cf.osb&amp;fp=c74f0380bf40be70&amp;biw=1241&amp;bih=593" target="_blank"> talk</a> about it. That&#8217;s too big of a question for one post, or maybe one hundred posts. Instead, let&#8217;s look at some of the industry players:</p>
<ul>
<li>patients</li>
<li>doctors, nurses, PAs, NPs, and other clinicians</li>
<li>administrators</li>
<li>hospitals, private practices, labs, and clinics</li>
<li>health insurers</li>
<li>healthcare vendors and manufacturers of drugs, equipment, supplies, software, and services</li>
<li>investors in hospitals, health insurers, and healthcare vendors</li>
<li>government</li>
<li>employers</li>
</ul>
<p>Each of these players can have radically different incentives, many of which are not primarily focused on patient care. Don&#8217;t get me wrong &#8211; I am not saying vendors or insurers or employers have evil intent, but the market pressure of increasing shareholder returns is very distracting, and the business of business is difficult, with 1/3 of all new <a title="Statistics on new business failures" href="http://smallbiztrends.com/2005/07/business-failure-rates-highest-in.html" target="_blank">companies failing to survive two years</a>.</p>
<p>Add in patients gaming or abusing the system, government legislation and partisan politics, hospital administrators focused on auditing and compliance, indigent care, and dozens of other factors&#8230;</p>
<p>With this incredible diversity of participants and the difficulty of running a successful business in any industry, a better question is &#8220;how could healthcare not be complicated?&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://lukegilliam.com/2012/04/27/why-is-healthcare-so-complicated/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;Healthcare&#8221; Companies Don&#8217;t Care about Health (Why EHR Solutions Suck)</title>
		<link>http://lukegilliam.com/2012/04/26/healthcare-companies-dont-care-about-health-why-ehr-solutions-suck/</link>
		<comments>http://lukegilliam.com/2012/04/26/healthcare-companies-dont-care-about-health-why-ehr-solutions-suck/#comments</comments>
		<pubDate>Thu, 26 Apr 2012 14:41:44 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Market Incentives]]></category>

		<guid isPermaLink="false">http://lukegilliam.com/?p=56</guid>
		<description><![CDATA[They Care About Money A lot of so-called healthcare companies are simply companies that happen to be in healthcare, and they are not focused on patients and clinicians but instead on taking the biggest slice of the pie in order to propel continuing shareholder returns. Money is Good, Right? Yes! Then Why Complain About Making <a href='http://lukegilliam.com/2012/04/26/healthcare-companies-dont-care-about-health-why-ehr-solutions-suck/' class='excerpt-more'>[...]</a>]]></description>
				<content:encoded><![CDATA[<p><a title="Man carrying large bag of money" href="http://lukegilliam.com/wp-content/uploads/2012/04/johnny_automatic_bag_of_money1.png" target="_blank"><img class="alignright size-medium wp-image-62" title="illustration of man carrying extremely large bag of money" src="http://lukegilliam.com/wp-content/uploads/2012/04/johnny_automatic_bag_of_money1-233x300.png" alt="illustration of man carrying extremely large bag of money" width="233" height="300" /></a></p>
<h2>They Care About Money</h2>
<p>A lot of so-called healthcare companies are simply companies that happen to be in healthcare, and they are not focused on patients and clinicians but instead on taking the biggest slice of the pie in order to propel continuing shareholder returns.</p>
<h2>Money is Good, Right?</h2>
<p>Yes!</p>
<h2>Then Why Complain About Making Money?</h2>
<p>The issue is with incentives, the big piles of money in healthcare that drive greedy behavior and short-term profit taking. The best companies grow by creating value with products and services that solve a need in the market.</p>
<p><span style="color: #000000;">Before you make a capital investment in an EHR, make sure you know what your vendor&#8217;s priorities are: patient outcomes or shareholder wealth? If the answer is &#8220;improved patient outcomes that lead to increased revenue and increased shareholder wealth,&#8221; then you may have found a great vendor.</span></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://lukegilliam.com/2012/04/26/healthcare-companies-dont-care-about-health-why-ehr-solutions-suck/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top 4 Reasons Hospitals Should Never Write Their Own CPOE</title>
		<link>http://lukegilliam.com/2012/04/25/top-4-reasons-hospitals-should-never-write-their-own-cpoe/</link>
		<comments>http://lukegilliam.com/2012/04/25/top-4-reasons-hospitals-should-never-write-their-own-cpoe/#comments</comments>
		<pubDate>Wed, 25 Apr 2012 14:36:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://lukegilliam.com/?p=44</guid>
		<description><![CDATA[1. Software development is difficult! Sure, it looks easy. Just hire a project manager and some developers. But before you write that check, search Google for software project failure, and look at the number of zeroes in the costs. Even the experts who develop software as their main business have trouble delivering projects on time with <a href='http://lukegilliam.com/2012/04/25/top-4-reasons-hospitals-should-never-write-their-own-cpoe/' class='excerpt-more'>[...]</a>]]></description>
				<content:encoded><![CDATA[<div id="attachment_45" class="wp-caption alignright" style="width: 160px"><a href="http://lukegilliam.com/wp-content/uploads/2012/04/728072059_40755c9ca2_m.jpg"><img class="size-thumbnail wp-image-45" title="728072059_40755c9ca2_m" src="http://lukegilliam.com/wp-content/uploads/2012/04/728072059_40755c9ca2_m-150x150.jpg" alt="airport flight status board showing delayed flights" width="150" height="150" /></a><p class="wp-caption-text">courtesy jjvaca/flickr</p></div>
<h2>1. Software development is difficult!</h2>
<p>Sure, it looks <a title="Nine-year-old writes iPhone app" href="http://www.reuters.com/article/2009/02/05/us-singapore-iphone-child-idUSTRE5140FI20090205">easy</a>. Just hire a project manager and some developers. But before you write that check, search Google for <a title="IEEE article: why software projects fail" href="http://spectrum.ieee.org/computing/software/why-software-fails">software project failure</a>, and <a title="Software project failures cost billions" href="http://www.galorath.com/wp/software-project-failure-costs-billions-better-estimation-planning-can-help.php" target="_blank">look</a> at the <a title="Table of failed software projects and costs" href="http://spectrum.ieee.org/image/1436123" target="_blank">number of zeroes in the costs</a>. Even the<a title="Microsoft Surface release delayed" href="http://www.theverge.com/2011/10/12/2486275/microsoft-surface-2-0-delayed-release-date-now-january-2012" target="_blank"> experts</a> <a title="Apple iPhone release delay" href="http://www.appleinsider.com/articles/10/10/26/apple_delays_launch_of_white_iphone_4_until_spring_2011.html" target="_blank">who</a> <a title="Oracle Fusion delayed release" href="http://www.computerweekly.com/news/2240105054/Oracle-customers-face-rising-support-costs-following-Fusion-application-roll-out-delay" target="_blank">develop</a> <a title="Verizon Thunderbolt release delayed" href="http://pocketnow.com/android/verizon-updates-thunderbolt-owners-on-software-delay" target="_blank">software</a> as their main business have trouble delivering projects on time with no <a title="Software error kills patients" href="http://www.baselinemag.com/c/a/Projects-Processes/We-Did-Nothing-Wrong/" target="_blank">major defects</a>.</p>
<h2>2. You don&#8217;t have enough resources to run a hospital AND manage a capital development project</h2>
<p>There is no hospital anywhere that has spare time, so any project you begin at your hospital will take resources away from your primary mission: patient care. Don&#8217;t be deceived about development costs and timelines, either. According to the<a title="Software Development Cost Estimating Guidebook" href="http://www.stsc.hill.af.mil/consulting/sw_estimation/estimatingguidebook.html"> Software Development Cost Estimating Guidebook</a>, &#8220;A realistic estimate is based upon a solid understanding of the software development process and the historical data&#8230;&#8221; &#8211; neither of which your organization has.</p>
<h2>3. You can&#8217;t achieve economies of scale to cover your sunk costs and ongoing maintenance</h2>
<p>Again, software is very expensive to develop and maintain and only makes financial sense if you can sell or license it to many customers. Can your hospital afford to increase its operating overhead? How will you measure return on investment for this project? Don&#8217;t forget to track patient outcomes, throughput (revenue), and employee satisfaction, both before and after your project. And you have to keep sunk costs and ongoing maintenance LOW because you can only amortize these expenses across your organization instead of a large customer base.</p>
<h2>4. Captive users don&#8217;t give honest feedback</h2>
<p>When you have a problem with vendor-provided software, the solution is simple and painless: pick up the phone! When you have a problem with internally developed software, there is a natural tendency to mute complaints for fear of job security. Will you get honest feedback from users if your multi-million-dollar project has poor usability? <a title="Shoot the messenger" href="http://en.wikipedia.org/wiki/Shooting_the_messenger" target="_blank">Nobody</a> wants to be the person to tell the executive sponsor that their capital investment was wasted.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://lukegilliam.com/2012/04/25/top-4-reasons-hospitals-should-never-write-their-own-cpoe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Have You Been Sued Yet for PHI Violations on a Personal Device?</title>
		<link>http://lukegilliam.com/2012/04/24/have-you-been-sued-yet-for-phi-violations-on-a-personal-device/</link>
		<comments>http://lukegilliam.com/2012/04/24/have-you-been-sued-yet-for-phi-violations-on-a-personal-device/#comments</comments>
		<pubDate>Tue, 24 Apr 2012 14:57:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[PHI]]></category>

		<guid isPermaLink="false">http://lukegilliam.com/?p=26</guid>
		<description><![CDATA[ Before I tell you the big problems with patient data and personal smartphones, I want you to keep one visual in mind: You are surrounded by air, and it is vital for life. It&#8217;s free and plentiful, but I&#8217;m going to ask you to breathe through a cocktail straw from now on. That&#8217;s the problem <a href='http://lukegilliam.com/2012/04/24/have-you-been-sued-yet-for-phi-violations-on-a-personal-device/' class='excerpt-more'>[...]</a>]]></description>
				<content:encoded><![CDATA[<p><a href="http://lukegilliam.com/wp-content/uploads/2012/04/7008578415_c1999547ec_m.jpg"><img class="alignleft size-full wp-image-27" title="lost and stolen phones" src="http://lukegilliam.com/wp-content/uploads/2012/04/7008578415_c1999547ec_m.jpg" alt="pile of lost and stolen mobile phones in police evidence storage" width="240" height="160" /></a> Before I tell you the big problems with patient data and personal smartphones, I want you to keep one visual in mind:</p>
<blockquote><p><em>You are surrounded by air, and it is vital for life. It&#8217;s free and plentiful, but I&#8217;m going to ask you to breathe through a cocktail straw from now on.</em></p></blockquote>
<p>That&#8217;s the problem doctors, nurses, and PAs face every day when they need to quickly send and receive vital patient information such as photographs, medical records, and laboratory results to consulting physicians. Even though they are completely surrounded by iPhones, Droids, and high-speed wireless networks, clinicians are forced to breathe through a tiny straw.</p>
<p>&nbsp;</p>
<h2>Big Problem: Restrictive Security Policies Without Supporting Tools</h2>
<p>That tiny straw is your hospital&#8217;s communications policy and supporting IT infrastructure. You have a policy for two very good reasons: patient privacy is important, and it&#8217;s also mandated by federal law, which is backed by large fines and negative publicity. But doctors often need to work quickly, and that free, plentiful supply of life-savings communication is in their pockets: mobile phones.</p>
<blockquote><p><em>Dr. McBride in the emergency department knows Dr. Owen in surgery and has his contact info in her iPhone. When she needs an emergency consult for a critical patient, she pulls out her phone and quickly types a text message with the patient&#8217;s name, chart number, and a brief history, including lab results indicating illicit drug ingestion. Dr. Owen receives the message on his phone, reviews the chart and results, and responds with a diagnosis, also via text.</em></p>
<p><em>Later that night at a bar, Dr. Owen loses his iPhone and thousands of patient records. Now you are in the news for a breach and a fine, the doctors have been fired, and you have an urgent situation to handle.</em></p></blockquote>
<p>Whose fault is this and whose problem is it to fix? Is the doctor at fault for breathing in the plentiful supply of air when you gave her a tiny straw to use for this purpose?</p>
<p>&nbsp;</p>
<h2>Big Problem: High Incentive to Circumvent Policies</h2>
<p>The big obstacle your policies and IT have to overcome is WORKFLOW.  Like water flowing downhill, people naturally flow to the easiest solutions. If your policies and IT services create enough obstacles, people will flow around them to readily available solutions until you ratchet up the penalties so high that all work comes to a halt. And it will come to halt because you didn&#8217;t do one critical thing: offer an effective alternative to that plentiful air supply.</p>
<p>Policies are easy to write, but providing effective technical solutions is very hard. We put the policies in place, and then we leave the users to deal with broken workflow resulting in decreasing patient outcomes, revenue, and employee satisfaction.</p>
<p>SMS text messages are especially hard to replace because they are so very, very easy to use &#8211; there has never been a more convenient method of instant communication to anyone anywhere, and every one of us has it on our pockets most of our waking lives.</p>
<p>&nbsp;</p>
<h2>The Hard Task: Think Long-Term</h2>
<p>Are your users sipping air through a tiny straw? What effective tools do you have in place that meet your compliance goals but also facilitate efficient workflow?</p>
<p>You can meet your short-term compliance goals by checking the box that says, &#8220;Security Policy,&#8221; but if you don&#8217;t support user workflow, you will pay in the long term with decreasing quality of care, decreasing revenue, and increasing expenses.</p>
<p>Interact with your users to ensure their patient-care needs are met, and use meaningful metrics to measure efficiency before and after policy and IT changes. This sounds obvious in the C-suite, but I assure you it is frequently not happening on the ground. There is a disconnect &#8211; make sure it&#8217;s not in your organization.</p>
]]></content:encoded>
			<wfw:commentRss>http://lukegilliam.com/2012/04/24/have-you-been-sued-yet-for-phi-violations-on-a-personal-device/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>3 Big Reasons SMS Text Messages Will Get Your Hospital Sued for a HIPAA Violation</title>
		<link>http://lukegilliam.com/2012/04/23/3-big-reasons-sms-text-messages-will-get-your-hospital-sued-for-a-hipaa-violation/</link>
		<comments>http://lukegilliam.com/2012/04/23/3-big-reasons-sms-text-messages-will-get-your-hospital-sued-for-a-hipaa-violation/#comments</comments>
		<pubDate>Mon, 23 Apr 2012 22:43:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[PHI]]></category>

		<guid isPermaLink="false">http://lukegilliam.com/?p=11</guid>
		<description><![CDATA[81% of healthcare providers use personal devices to send and receive PHI Personal devices are lost or stolen ALL THE TIME, and most don&#8217;t even have basic PIN security enabled All of the phone companies store information about text messages, and Verizon even stores the contents! This is a big problem, and with so many <a href='http://lukegilliam.com/2012/04/23/3-big-reasons-sms-text-messages-will-get-your-hospital-sued-for-a-hipaa-violation/' class='excerpt-more'>[...]</a>]]></description>
				<content:encoded><![CDATA[<div><a href="http://lukegilliam.com/wp-content/uploads/2012/04/IMG_29152.png"><img class="size-medium wp-image-41 alignright" title="Text message with PHI" src="http://lukegilliam.com/wp-content/uploads/2012/04/IMG_29152-200x300.png" alt="iPhone screen capture of text message with PHI" width="200" height="300" /></a></div>
<ol>
<li><a title="Top 11 Trends for 2012 in Healthcare Data" href="http://www.prnewswire.com/news-releases/top-11-trends-for-2012-in-healthcare-data-according-to-industry-experts-136731208.html" target="_blank">81% of healthcare providers</a> use personal devices to send and receive PHI</li>
<li>Personal devices are lost or stolen ALL THE TIME, and most don&#8217;t even have basic PIN security enabled</li>
<li>All of the phone companies store information about text messages, and <a title="How long do carriers store your data?" href="http://www.phonearena.com/news/How-long-do-carriers-store-your-data_id22532" target="_blank">Verizon even stores the contents</a>!</li>
</ol>
<p>This is a big problem, and with so many doctors, PAs, and nurses using personal phones to send emails and texts about patients, we will definitely see major breaches in the news. A little more worrying, though, is that the mobile phone carriers are inadvertently sitting on a LOT of PHI all collected in one place.</p>
<p>This is a hard problem to solve because existing IT solutions simply can&#8217;t match the convenience of SMS. It&#8217;s a worldwide network in your pocket that can reach anyone at any time, and it takes just seconds to send and receive a message with attachments. Do you have an IT solution that provides this level of convenience?</p>
]]></content:encoded>
			<wfw:commentRss>http://lukegilliam.com/2012/04/23/3-big-reasons-sms-text-messages-will-get-your-hospital-sued-for-a-hipaa-violation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
