Showing posts with label ICD. Show all posts
Showing posts with label ICD. Show all posts

Friday, October 25, 2013

Justice Delayed - Two Device Companies Still Settling Cases from 10 Plus Years Ago

Here we go again.  After a hiatus during which the US media and perhaps parts of the government were preoccupied with such issues as the ongoing controversy over health care reform, and a government shutdown apparently arising out of this controversy, the march of legal settlements involving big health care organizations has resumed.

In alphabetical order,...


Boston Scientific

From the Minneapolis Star-Tribune on 17 October, 2013, an account of a settlement arising from alleged misbehavior that started in 2002,


A $30 million settlement between the U.S. Department of Justice and Boston Scientific will likely end a case involving the sale of defective heart devices from 2002 through 2005 by subsidiaries Guidant, Guidant Sales and Cardiac Pacemakers.

Note that the allegations were particularly egregious since they involved a company selling products they knew to be defective in ways that could prove fatal as if they were quite safe,

The settlement closes a fraudulent-claims lawsuit that alleged Guidant knowingly sold defective implantable defibrillators to health care facilities that implanted them into thousands of Medicare patients. 

In particular,


The government’s complaint said that Guidant knew as early as April 2002 that its Prizm 2 line of devices was defective and knew in November 2003 that its Renewal 1 and 2 devices were capable of short-circuiting and delivering an electric shock that 'arcs' back onto the device instead of being directed to an irregularly beating heart.

According to Boston Scientific’s website, 83 malfunctions and nine reported deaths have been connected with the Renewal devices and 40 confirmed malfunctions and five patient deaths have been associated with the Prizm devices. About 500 Renewal devices remain implanted worldwide; about 1,400 Prizm devices remain in patients, according to the website.

Although Guidant took action to fix the defects, the government alleged that the company continued to sell its remaining stock of the old, defective versions of the devices. In fact, federal officials say that as Guidant learned about the cause of the defect, it took steps to hide the problem from patients, doctors and the Food and Drug Administration.

According to the government, Guidant did not fully disclose the problem until May 2005, when two Minneapolis doctors publicly aired their concerns about one of the defibrillators after it failed to revive a 21-year-old Grand Rapids, Minn., patient. Guidant later admitted it had known for three years that the device could short-circuit, but chose not to alert doctors or the public.

This is only the latest settlement made by Boston Scientific since 2005,


Boston Scientific paid $27.5 billion to acquire Guidant in 2006. It has been paying quite a bit since in relation to Guidant’s defective defibrillators.

In 2007, Boston Scientific paid $240 million to settle claims with thousands of patients who had sued Guidant after the defective devices were recalled. Later, in February 2010, Guidant pleaded guilty to misleading the FDA about problems with the devices and paid a fine of $296 million.

In fact, the then case of the allegedly concealed implantable cardiac defibrillators (ICD) was one of the first cases of apparently unethical health care corporate management behavior leading to bad patient outcomes we discussed on Health Care Renewal.  (Look here for a more recent summary of this case.)

Yet despite the fact that this apparently deeply unethical conduct lead to patient deaths, no individual who authorized, directed or implemented the bad behavior has suffered any negative consequences for it over the eight years since the details first became public.

One physician who helped bring this case to light was also apparently concerned about the impunity of those responsible,


 Dr. Robert Hauser, one of the doctors who went public back in 2005, criticized the settlement on Thursday.

'The $30 million should have little impact on their business,' Hauser said in an e-mail. 'I find it very disturbing that such a small settlement was accepted by the DOJ in view of the magnitude of wrongdoing by Guidant management.'

Stryker Corp

This week, MLive.com reported on another settlement involving allegations of unethical behavior by a device company dating back to 2003,

 An investigation by federal authorities found that Stryker Corp. subsidiaries in five foreign countries made illicit payments and tried for several years to bribe doctors, health care professionals and government-employed officials in order to obtain or retain business.

Stryker  has agreed to pay more than $13.2 million to settle the charges.

The SEC charged the Kalamazoo-based medical technologies company with violating the Foreign Corrupt Practices Act,  alleging that its subsidiaries in Argentina, Greece, Mexico, Poland and Romania made illicit payments totaling approximately $2.2 million 'that were incorrectly described as legitimate expenses in the company’s books and records.'

The SEC said descriptions of the payments varied from a charitable donation to consulting and service contracts, travel expenses, and commissions.

The SEC states that Stryker made about $7.5 million in illicit profits as a result of the improper payments. It did not specify during what year all of the events occurred, but indicated some as far back as 2003.

Note that the payments seemed deliberately designed to corrupt health care professionals and managers, for example,

According to the SEC’s order, Stryker’s subsidiary in Greece made a purported 'donation' of nearly $200,000 in 2007 to a public university in Greece to fund a laboratory that was a pet project of a public hospital doctor. In exchange for the payment, the doctor agreed to provide business to Stryker.

Also,


The SEC stated that its investigation also found that Stryker subsidiaries bribed foreign officials by paying their expenses for trips that lacked any legitimate business purpose.

'For example, in exchange for the promise of future business from the director of a public hospital in Poland, Stryker paid travel costs for the director and her husband in May 2004,' according to the SEC. 'This included a six-night stay at a New York City hotel, attendance at two Broadway shows, and a five-day trip to Aruba.'

As in the case above, it appears that no individual who authorized, directed or implemented the questionable payments will suffer any negative consequences.  In fact, as is usual in such cases,

 The settlement does not not require Stryker to admit or deny the allegations,...

However, an SEC official did say,

 Stryker’s misconduct involved hundreds of improper payments over a number of years during which the company’s internal controls were fatally flawed. Companies that allow corruption to occur by failing to implement robust compliance programs will not be allowed to profit from their misconduct.

While Health Care Renewal has not discussed this particular case before, it is hardly the first case of bad conduct by Stryker that we have discussed.  In the past we noted
-  In 2012, a Stryker subsidiary pleaded guilty to misbranding in response to allegations that its marketers conspired to defraud physicians in order to sell a product to promote bone growth that proved harmful to patients (look here).
-  In 2010, Stryker settled a case alleging unfair and deceptive sales practices again used for bone growth accelerators (look here).  
-  In 2009, some apparently low-level Stryker employees pleaded guilty to promoting off-label use of these same products (look here). 
- In 2007, Stryker made an agreement allowing federal supervision after charges one of its units had violated anti-kickback laws when making supposed "royalty" payments, often huge, to orthopedic surgeons in connection with its production of prosthetic hips and knees.  Several other device companies signed deferred prosecution agreements, and as a result, for a time all had to make public their payments to doctors and various non-profit organizations.  (See summary here.) 

Summary

 This recent crop of settlements has some features in common.  The settlements involved multinational device companies.  The settlements occurred at least a decade after the alleged bad behavior started.  The settlements required only small payments - at least on a corporate scale -from the companies involved, but no negative consequences for anyone who authorized, directed, or implemented the bad behavior.  Finally, the settlements were made by companies who had striking past records of previous settlements of bad behavior.

The march of legal settlements demonstrates the pervasiveness of unethical behavior, often involving harm to patients or sullying of health care professionals, involving large, rich health care corporations.  It also demonstrates the impunity of the top leaders of such corporations who often make huge amounts of money despite, or perhaps because of their companies' misconduct.  Despite intermittent threats by US government officials to get tough with unethical behavior by health care corporations, this pattern has continued for years, as we have documented. 

True health care reform would hold leaders of health care organizations accountable for their organizations' behavior, and its effects on patients and health care professionals. 

Friday, October 12, 2012

Back to the Future - Another Medical Device Company Accused of Hiding ICD Defects

Suppression of data about defects in and failures of implantable cardiac defibrillators (ICDs) was one of the big issues we featured in the early days of Health Care Renewal (2005-06). 

At that time, Guidant, later acquired by Boston Scientific, was accused of hiding data that certain of its defibrillator models failed, possibly leading to preventable patient deaths (see this post and follow links backward).  Boston Scientific, which acquired Guidant, settled a civil lawsuit and was put on probation in 2011 after it pleaded guilty to misdemeanor charges of failing to file required reports with the US Food and Drug Administration (see post here).   Similarly, in 2010, Medtronic settled multiple patients' lawsuits charging that it knowingly marketed a faulty ICD (see post here).

St Jude and the Obscure Riata Data

Now in 2012, A Wall Street Journal article suggested that St Jude Medical Inc hid problems with its Riata implanted cardiac defibrillator (ICD) for years.   

In December, 2010, St Jude Medical Inc issued a warning letter to doctors: Wires inside Riata defibrillator leads—cables that connect the heart to implantable defibrillators—were sometimes breaking through their insulation from the inside out.


The problem, which ultimately led to a recall last year, could cause defibrillators to send unnecessary jolts to the heart or fail to deliver lifesaving shocks to return chaotic heart rhythms back to normal. The company said it had identified dozens of cases with visible signs of the problem, and pulled Riata from the market.

For many doctors, this was the first notice of a problem with Riata.

But before that 2010 warning, physicians including Alan Cheng, director of Johns Hopkins Medicine's arrhythmia service; Samir Saba, chief of electrophysiology at the University of Pittsburgh Medical Center; and Ernest Lau at the Royal Victoria Hospital in Belfast, Ireland, say they had encountered this so-called "inside-out abrasion" in their own practices between 2006 and 2009. When these doctors brought the incidents to the attention of St. Jude they say they were told by company officials and field representatives that the incidents were isolated. The malfunctions described by the doctors didn't result in deaths.

St. Jude had been tracking the problem for several years, according to company documents collected by the Food and Drug Administration and reviewed by The Wall Street Journal. Cases involving the so-called inside-out abrasion date to at least October 2005, the documents show. Inside-out abrasion became a focus of an internal St. Jude audit, which examined multiple cases of the failure before April 2008.
The Journal article noted that more transparency about device failures might allow physicians to spot problems earlier and prevent harm to patients.
more than a dozen physicians and device-safety experts say that if St. Jude had acknowledged the inside-out failure earlier, physicians might have identified the scope of the problem sooner.


In some cases, doctors concede that they, too, believed the failures were isolated and therefore didn't act quickly to report problems to St. Jude or the FDA, which may have made it harder to spot the growing trend of failures. The leads were implanted in more than 13,000 patients since July 2008.

'Every time you have a failed lead, you assume it's an isolated event, but, you start to string together isolated events, and then you have a recall,' said Dr. Saba.
Summary

So, for Health Care Renewal, this is a straightforward case, at least so far.  Yet another health care organization, this time, a medical device company, failed to reveal data that might have reflected unfavorably on one of its products, and hence lead to decreases in short-term revenue.  However, by suppressing the information, the company may have allowed doctors to keep implanting a potentially faulty device, and exposed patients to risk, possibly of fatality. 

We have discussed many at least somewhat parallel cases of suppression of research (here), and many cases of other kinds of deception by health care organizations (here).  Yet these cases continue to occur, physicians and other health care professionals continue to be fooled by secrecy and data suppression, and patients continue to be harmed by drugs, devices, or other interventions made by people who knew, or ought to have known that they were more dangerous than they appeared to be. 

One problem may be that the people with the most influence on medical practice and health policy continue to cheer lead for the veracity of information about drugs, devices, and other health care interventions supplied by the people who most stand to gain from selling same.  A few weeks ago, the editor of the august New England Journal of Medicine, Dr Jeffrey M Drazen MD, scoffed at physicians' skepticism of pharmaceutical industry funded clinical research, claiming that there were only "a few examples of industry misuse of publications...." [Drazen JM. Believe the data. N Engl J Med 2012;  367:1152-1153.  Link here.]  In doing so, Dr Drazen seemed to ignore all the stories about suppression of medical research (some of which we have discussed here), manipulation of medical research (some discussed here), and deception (some discussed here) and secrecy (some discussed here) practiced by large health care organizations, including but not limited to drug, device, biotechnology, and health care information technology companies.

Instead, the possibility that St Jude kept hidden data about the failings of one of its ICD models reminds us how skeptical we ought to be about the information provided, or not provided by those with vested interests in selling health care goods or services.  Physicians, health care professionals, those interested in health policy, and the public at large need to collectively exert pressure on the leaders of health care organizations to promote greater transparency, especially about data reflecting on benefits and harms of health care goods and services.  . 

Thursday, December 15, 2011

Medtronic Settles, Yet Again

And the march of legal settlements continues... Circling around the block and coming in front of the viewing stand again is device manufacturer Medtronic. 

The Latest Medtronic Settlement

As Bloomberg reported:
Medtronic (MDT) Inc., the world’s biggest maker of heart rhythm devices, agreed to pay $23.5 million to settle claims it paid kickbacks to doctors who implanted its pacemakers and defibrillators in patients, the U.S. Justice Department said in a statement.

Medtronic agreed yesterday to settle two lawsuits filed in federal courts in California and Minnesota accusing the company of violating the federal False Claims Act by paying physicians $1,000 to $2,000 for each patient who was implanted with one of the company’s devices, according to the Justice Department.

'Patients who rely on their health-care providers to implant vital medical devices expect that those decisions will be made with the patients’ best interests in mind,' Tony West, assistant attorney general for the Justice Department’s Civil Division, said in an e-mailed statement. 'Kickbacks, like those alleged here, distort sound medical judgments with financial incentives paid for by the taxpayers.'

As usual, Medtronic did not admit doing anything wrong:
Medtronic said in an e-mailed statement that it makes no admissions that the studies were 'improper or unlawful.' The company also said it established a reserve for the anticipated payment in the fourth quarter of fiscal year 2011.

'We are happy that the investigation is behind us, so we can continue designing and executing clinical trials that generate evidence to improve patient care, outcomes and cost effectiveness,' Marshall Stanton, vice president of clinical research and reimbursement for the cardiac and vascular group....
Previous Legal Settlements by Medtronic
Note that this is not the first time Medtronic has been accused of paying doctors (kickbacks, this time, which seem to be the ethical equivalent of bribes) to use its products. The Bloomberg report also noted:
In 2006, Medtronic agreed to pay $40 million to settle allegations that its Sofamor Danek unit violated state laws and the False Claims Act by paying sham consulting fees and providing lavish trips to doctors who used its products from 1998 to 2003.
Perusing the Medtronic file on Health Care Renewal also showed that Medtronic has had to settle other lawsuits alleging misconduct:

- In 2008, Medtronic subsidiary Kyphon settled a suit for $75 million and signed a corporate integrity agreement for allegations that it defrauded Medicare through a scheme that lead to excessive hospitalization for patients who received the company's spine surgery device (link here)
- In 2010, Medtronic settled multiple civil lawsuits for $268 million for allegations that it marketed an implantable cardiac defibrillator with faulty leads whose failures lead to 13 deaths (link here)

Cases of Apparent Conflicts of Interest Generated by Medtronics' Payments
In fact, paging through the Medtronic file on Health Care Renewal, we also found these cases of apparent conflicts of interest that Medtronic caused by making payments to or otherwise creating financial relationships with:

- FDA advisory board members (2007 link here),
- health care professionals who appeared on public television programs about heart disease and treatments of it (2007 link here),
- members of a non-profit organization which was supposed to guide the FDA regarding drug development  (2007 link here),
- prominent academic orthopedic surgeons who were in positions to influence other physicians' choices of orthopedic devices (2008 link here and 2009 links here, here and here),
- a military surgeon who wrote questionable articles about the supposed virtues of a Medtronic bone growth product (2009 link here),
- a top leader of US Veterans Affairs Department who objected to the appointment of an industry critic as US Surgeon General (2010 link here),
- spine surgeons apparently who could promote Medtronics' spine surgery products in (2010 link here) and who did not disclose all such payments when writing ostensibly scholarly articles on the subject (2010 link here)

So prior to the current settlement for "alleged" kickbacks, Medtronic had a long history of allegations that it had financial relationships with physicians who were in a position to promote the use of its products or its policy interests.

Why the Bad Behavior Continues

The latest settlement by Medtronic illustrates why the anemic approach by US government agencies to health care corporate misbehavior does not deter bad behavior.

- The punishment was a fine not large enough to have any effect on the finances of the corporation.. Such a relatively small financial penalty might just be seen as a cost of doing business by company executives.  (See these comments on the current case by Dr Howard Brody on the Hooked: Ethics, Medicine and Pharma blog.)
-  The punishment was not a result of any specific bad behavior.  In this case, like many others, the corporation did not have to admit to anything.  This leads to the paradox of a punishment meted out for apparently nothing other than "alleged" actions, making it appear that the actual punishment was just a payment by the company to allow it to continue the sorts of actions that were alleged with impunity.  (Such punishments without clear crimes happen all the time in cases affecting the finance sector.  See a federal judge's condemnation of this practice here.) 
-  The punishment seems unrelated to the corporation's historic behavior.  In this case, there was no reference to the company's previous settlements, or the other allegations of questionable payments to physicians and health care decision makers in other circumstances listed above.  (Keep in mind that Health Care Renewal strives to present interesting cases, but does not have the resources to report on every single case of bad behavior by health care organizations.  Hence the list above of apparent bad behavior may not be complete.)
-  The punishment applied to the corporation as a whole, and hence may disadvantage many people, stockholders and corporate employees in particular, who had nothing to do with the alleged bad behavior.  On the other hand, those who authorized, directed, or implemented the bad behavior were not subject to any negative consequences. 

So why on earth would corporate leaders cease bad behavior which could increase revenues short-term and hence increase their compensation (e.g., in 2011, the Medtronic CEO received $9,624,709 according to the 2011 proxy statement), when the likelihood of any negative consequences for them appears to be near zero? 

This would be bad enough if the bad behavior only causes financial disadvantage for stockholders or corporate employees.

However, the bad behavior in question seems to repeatedly involve paying physicians and other health care decision makers in ways likely to influence their decisions in favor of Medtronics' products and corporate well-being.  Making decisions this way, however, is unlikely to be good for patients' and the public's health, as it is likely to lead to excess use of expensive tests and treatments that may have adverse effects, sometimes severe.  Thus patients may suffer unnecessary morbidity and mortality, and the public at large may pay far too much for medical care.

So will we see in our lifetimes honest, tough policing of health care corporate behavior?  Will the punishments start to fit the crime, and will they be significant enough to deter future misbehavior?  Why do we continue to accept government actions that seem more solicitous of the executives of big corporations than the public for whose benefit government is supposed to be run?  Where is the outrage?   

So, once more, with feeling.... in my humble opinion, until the people responsible for the bad behavior experience negative consequences from that behavior, they will continue to perform, direct, and condone bad behavior. We will not achieve real health care reform in the US until we effectively deter unethical, self-serving behavior by leaders of health care organizations.

ADDENDUM (15 December, 2011) - On the GoozNews blog, Merrill Goozner called Medtronic's actions "a crime against science."

Friday, September 23, 2011

My doctor will now need to code for when I get bitten by George or Martha Goose

The bureaucrats always seem to find new ways to waste precious medical resources and capital to justify their existence.

Here's the latest twist:

I regularly feed swans, ducks and geese at my local park. In fact, I don't seek them out; the geese in particular come to me when they see me on the trail. They know me for years.

They have tremendous vision, so I can't escape them.

Per the WSJ, medical coding is about to become so hypergranular (could the reason be that bureaucrats needed work to do?) as to be reasonably considered insane:

Walked Into a Lamppost? Hurt While Crocheting? Help Is on the Way

New Medical-Billing System Provides Precision; Nine Codes for Macaw Mishaps


Wall Street Journal
Sept. 13, 2011

... Billing experts who translate doctors' work into codes are gearing up to start using the new system in two years. They say the new detail is welcome in many cases. But a few aspects are also causing some head scratching.

Some codes could seem downright insulting: R46.1 is "bizarre personal appearance (see code)," while R46.0 is "very low level of personal hygiene (see code)."

It's not clear how many klutzes want to notify their insurers that a doctor visit was a W22.02XA, "walked into lamppost, initial encounter" (or, for that matter, a W22.02XD, "walked into lamppost, subsequent encounter").

Why are there codes for injuries received while sewing, ironing, playing a brass instrument, crocheting, doing handcrafts, or knitting—but not while shopping, wonders Rhonda Buckholtz, who does ICD-10 training for the American Academy of Professional Coders, a credentialing organization.

... Much of the new system is based on a World Health Organization code set in use in many countries for more than a decade. Still, the American version, developed by the Centers for Disease Control and Prevention and the Centers for Medicare and Medicaid Services, is considerably more fine-grained.

The WHO, for instance, didn't see the need for 72 codes about injuries tied to birds. But American doctors whose patients run afoul of a duck (see codes), macaw (see codes), parrot (see codes), goose (see codes), turkey (see codes) or chicken (see codes) will be able to select from nine codes for each animal, notes George Alex, an official at the Advisory Board Co., a health-care research firm.

There are 312 animal codes in all
, he says, compared to nine in the international version. There are separate codes for "bitten by turtle" and "struck by turtle." (See codes.)

Examples:

W6151XA Bitten by goose, initial encounter
W6151XD Bitten by goose, subsequent encounter [Killer Goose?]
W6151XS Bitten by goose, sequela
W6152XA Struck by goose, initial encounter
W6152XD Struck by goose, subsequent encounter
W6152XS Struck by goose, sequela
W6159XA Other contact with goose, initial encounter
W6159XD Other contact with goose, subsequent encounter
W6159XS Other contact with goose, sequela

Sometimes my favorite Canada Goose couple, George and Martha, and their annual young'uns will overextend their beaks when being fed and nip my finger. They've never broken my skin (geese have no teeth, just ridges) but if they do ... my doctor is likely to have to code for "bitten by Canada Goose."

I wonder if CDC will then send out the Goose Patrol. George and Martha, be careful, or your goose may be cooked!



George, I'm going to feed you, but don't W6151XD me (bite me) or the Feds will be after you ... (click to enlarge photos)



Young'uns, you better watch out, too!



This guy has already done a W6152XA and W6152XD to me with his wings, leaving me with a W6152XS (bruise on my leg) when I didn't feed him before the Canadas! You can just tell he's looking to create coding mayhem from that expression on his face.



Is there an ICD-10 code for "foot bitten by cute little Mallard duckie?"


What a perverse waste of resources this coding mania represents...


Hat tip: The Galen Institute/Grace-Marie Turner


-- SS

Friday, March 14, 2008

Hacking an ICD - A Dual Medical Informatics/Ham Radio Perspective

Roy Poses wrote at "Hacking an ICD" that:

An ICD is a device whose correct operation is critical for the health and safety of patients in whom it is implanted. One would think that the managers responsible for the design of such devices would have pushed to make sure that the operation of such devices could not be hacked or accidentally altered in ways that could put patients' health and lives at risk.

Indeed.

It is probably not well known that in addition to being a Medical Informaticist, I am also a ham radio enthusiast, licensed at the Extra class. I know more about electronics than most physicians - and most IT people in hospitals to boot, although that often didn't matter in the dysfunctional world of hospitals and health IT.

As a medical informaticist and ham radio operator, I am concerned by the possibility of long(er) range hacking of implantable medical devices than that accomplished by researchers recently.

Apparently ICD's use a frequency of about 175 kHz for data communications. 175 kHz is in a band known as longwave. For comparison and orientation, the bottom of the familiar medium wave band -- a.k.a. ordinary AM radio-- is 520 kHz.

(An aside for those interested: shortwave starts at about 1,800 kHz or 1.8 MHz and extends to about 30,000 kHz or 30 MHz, and is called "shortwave" for historical reasons; the actual wavelengths are appx. 160 meters to 10 meters. These wavelengths were considered "short", comparatively speaking, in the early days of radio. The shortwaves have the property, under proper conditions, of being refracted back to earth by the earth's ionosphere and can be reflected by the earth itself. This allows the waves to do "multiple hops" and propagate over great distances far in excess of line-of-sight, even around the world. Hence the ability of ham radio enthusiasts to talk to people all over the world on the shortwave bands allocated to them.)

When I was 13 years old I built a one-transistor transmitter on a cigar box from a plan by Heathkit that transmitted low power morse code at a frequency of about 550 kHz. It ran off a few AA batteries and used a short wire as an antenna. It was easily receivable on a radio across the house.

The first cordless phones ca. early 1980s, wireless baby monitors, and other devices operated at about 1,700 kHz, just above the AM radio band. They were very low power devices with short antennas relative to wavelength (~175 meters) but were usable at dozens of feet from their base units.

Using an antenna, say, the size of a CB whip (properly loaded electrically to resonate at 175 kHz, not very efficient but usable), or even better, a directional loop antenna, plus a transmitter of 5 or 10 or, perhaps, 100 watts of power (not very hard to build), and using a sensitive receiver designed for those frequencies (my $150 retail Grundig Yacht Boy is an example, http://www.eham.net/reviews/detail/816) with modifications and a suitable low-noise receiving antenna, would potentially extend the range of communications with RF-controlled implantable devices.

Not to miles with any type of portable equipment, I should add, due to efficiency issues with very short antennas (relative to wavelength) and the low power of the ICD's transmitter, but tens of feet might be possible. Throw in digital signal processing on the hacker's receiver, which is available via common, cheap, off-the-shelf DSP chips and algorithms, and even more range would be likely. You would be surprised at what a DSP-equipped and/or computer-enhanced receiver can pull out of the "ether" even under extremely poor signal conditions.

One wonders if any ICD's transmitter and receiver are encrypted in any way - apparently the devices tested were not. My car FOB is, although even those can be hacked (e.g., "Prius Security System Cracked", http://www.treehugger.com/files/2007/08/a_talk_given_at.php):

A talk given at the computer security conference, CRYPTO 2007, explained how the key-fob system installed on the Toyota Prius has been cracked. The KeeLoq auto anti-theft cipher is used in common devices made by Microchip Technology Inc, which are also used by Chrysler, Daewoo, Fiat, General Motors, Honda, Volvo, Volkswagen, and Jaguar. The attack requires that the thief gets within range of your RFID keyfob, in order to break the encryption. This could mean stealing your keys, or just sitting next to you in a cafe with a laptop. The cipher used in these devices is 64 bit, which has always been theoretically possible to break, but has now been shown to be breakable in about an hour. This is important, because the shorter the amount of time required with the key, the more likely this attack is to become used outside of a research lab.

May I add that while encryption is not foolproof, lack of encryption seems the work of fools.

On a somewhat unrelated note, you can buy a wrist watch that picks up time-setting signals from an atomic clock via station WWVB, Fort Collins, Colorado (http://en.wikipedia.org/wiki/WWVB) at long wave frequency 60 Khz for $30. I have one and in Philadelphia, it works well.

Some hams bounce signals off the moon for earth-moon-earth communications. They use high power, high gain antennas, and very low noise receivers. It works quite well.

Never underestimate what can be done at RF.

On one (predictable) industry response:

Medtronic's Rob Clark said the company's devices had carried such telemetry for 30 years with no reported problems. 'This is a very low-risk event for patients that have these devices,' Clark said in a telephone interview."

It would have been just a bit harder to hack a computerized device 30 or 20 or even 10 years ago. When kids can buy a laptop with computing power exceeding that of the Cray supercomputer for $500 and crack into, say, the Pentagon's systems, we are indeed living in different times.

Dr. Poses also wrote that:

The most charitable explanation for why they [the manufacturers] did not think to [engineer ICD's to be exceptionally hacker-proof] is that they really did not understand the clinical context in which this device would be used.


I think a better explanation is that the manufacturers' management has little imagination and underestimate the capabilities of people much smarter and more creative than themselves (e.g., tech-savvy kids). It would not surprise me to find engineering memos warning management that more safeguards needed to be incorporated, only to be asked "What's the ROI?"

The bottom line is: manufacturers might need to work a little harder when they deploy wireless devices, as hacking of gadgets and computerized equipment such as cell phones seems to be an increasingly common pastime for today's youth. (It's too bad ham radio is itself losing numbers as the previous generation ages and dies out.) The internet itself is used to spread techniques and malicious code among hackers.

One can imagine the consequences of a malicious RF device hacker or smart-but-delinquent kid in, say, a crowded shopping mall.

Finally, ham radio experimenters worldwide are not unfamiliar with longwave experimentation. Note in particular the bolded statement below:

With no Amateur Radio low-frequency [longwave -ed.] allocation in North America, stations operating under FCC Part 5 Experimental licenses in the US or under special experimental authorizations in Canada nonetheless continue to research the nether regions of the radio spectrum. By and large, LF experimentation is occurring in the vicinity of 136 kHz--typically 135.7 to 137.8 kHz--where amateur allocations already exist elsewhere in the world. The FCC rejected the ARRL's 1998 petition for LF allocations at 135.7 to 137.8 kHz and 160 to 190 kHz, however, after electric utilities objected that ham radio transmissions might interfere with power line carrier (PLC) signals used to control the power grid.

"Most of the new LF activity of Part 5 licensees has been in the shared 137 kHz amateur allocation available in some parts of the world," says low-frequency experimenter Laurence Howell, KL1X/5. "Although not in the Amateur Radio Service, these Part 5 experimental stations continue to add to our knowledge on propagation and engineering."

The holder of Part 5 Experimental license WD2XDW, Howell who's also GM4DMA, previously operated LF from Alaska. He's since relocated to Oklahoma, and has now resumed his LF work on 137.7752 and 137.7756 kHz. Already he's reporting some spectacular success, despite antenna limitations. On October 28, New Zealand LFer Mike McAlevey, ZL4OL, copied WD2XDW's 137 kHz carrier "bursts" over a path of more than 13,000 km (8000 miles).


The take-away message is that:

  • In biomedicine, the most meticulous resilience engineering is never a bad idea.

When drug and device manufacturers understand this fully, perhaps we will no longer have incidents of bad health informatics that can kill.

-- SS

Hacking an ICD

Implantable cardiac defibrillators (ICDs) are battery-powered, computerized electronic devices implanted in the body. They are designed to detect dangerous heart rhythms and administer a shock to the heart to stop these them. We have discussed these devices before, including a story about how one manufacturer suppressed data that suggested some of their ICDs were less reliable than heretofore thought.

It appears that a new, and potentially worrisome adverse effect of these devices has just been discovered.

An article to be published in the IEEE Symposium on Security and Privacy [Halperin D, Heydt-Benjamin TS, Ransford B et al. Pacemakers and implantable cardiac defibrillators: software radio attacks and zero-power defenses. IEEE Symposium Security Privacy 2008; in press. Link here.] demonstrated the vulnerability of an implantable cardiac defibrillator to computer hacking.

Let me set the stage. ICDs, and other implantable devices may need to be tested, and sometimes their functional parameters need to be adjusted. Obviously, it would be cumbersome and hazardous to remove such a device after it was implanted to check and adjust it. So the devices incorporate methods to check and adjust them remotely. It appears most do so using "wireless" means. Wireless, of course, is the traditional UK term for radio.

Halperin et al found that they could communicate with a representative ICD, the Medtronic Maximo DR VVE-DDDR model via radio. Note that the ICD they tested was not implanted in a patient, but sitting on a bench, and that their radio equipment used to "hack" it was in close proximity to it.

Once they figured out how to communicate, the found that they could:
- Discover patient data such as name, date of birth, medical ID number, and medical history
- Monitor electrophysiological telemetry data
- Turn off specific ICD functions
- Induce the ICD to deliver a shock, potentially one that could cause a severe rhythmn disturbance
- Increase the power consumption of the ICD so that its battery would fail prematurely.

Further, they found that they could overcome a design feature of the ICD meant to prevent anyone from communicating with it from more than a very short distance. The ICD is not supposed to respond to radio signals unless it is first exposed to a strong local magnetic field which triggers a magnetic switch in the device. But the investigators found, "in order to rule out the possibility that proximity of the magnet ... is necessary for the ICD to accept programming commands, we tested each ... attack with and without a magnet near the ICD. In all cases, both scenarios were successful."

Thus, this article suggested this ICD could be hacked, and that hacking it could pose significant risks to patients who had the ICD implanted.

Some people doubted that such hacking could actually take place in real-life, as opposed to laboratory settings. For example, per the AP story, FDA spokesperson Pepper Long "acknowledged a hacker could use specialized software and a small antenna to intercept transmissions from a defibrillator. But she said the chance of that happening — or of a defibrillator being maliciously reprogrammed using a technique similar to the one a doctor would use to program it — was 'remote.'" Furthermore, per the Reuters story, "Medtronic's Rob Clark said the company's devices had carried such telemetry for 30 years with no reported problems. 'This is a very low-risk event for patients that have these devices,' Clark said in a telephone interview."

In my humble opinion, however, the problems that Halperin et al found with the Medtronic ICD have real importance. Let me first note that both the FDA and Medtronic representatives treated the issue epidemiologically. They based their pronouncements on the assumption that an adverse event that has not happened in the past due to a device in wide use is not likely to happen in the future. That does not make sense if the potential adverse event would involve conscious, malicious human action. Just because hackers have not yet attacked an ICD does not mean they will not do so in the future, especially after the possibility of doing so has gotten wide publicity.

Another way some have minimized the practical importance of their findings is that the experiment by Halperin et al was carried out on an ICD on a bench, using equipment that was in close proximity. Some may thus feel that the possibility of hacking carried out from longer range is low. I strongly believe that is not a good assumption. Many features of the ICD and its radio communication system suggest that hacking could be carried out from considerably longer range. There are hints in the Halperin et al article that could suggest to anyone moderately knowledgeable about radio how this could be done. I do not want to discuss these in any more detail, because I do not want to facilitate such long-ranging hacking. But I believe it is a real danger.

But why is this relevant to Health Care Renewal? It seems glaringly obvious that the risk of hacking could have been substantially reduced had the ICD been designed so it would not respond to any radio communication that did not have an appropriate authorization code, and/or if communication with it were encrypted. In fact, Halperin et al suggested some relatively simple measures that could be used to increase the security of these devices. Yet the Medtronic ICD, and presumably other ICDs and implantable devices, were not designed with such elementary security precautions in mind. As security expert Bruce Schneier wrote (reported in Information Week),

Of course, we all know how this happened. It's a story we've seen a zillion times before: The designers didn't think about security, so the design wasn't secure.

But an ICD is a device whose correct operation is critical for the health and safety of patients in whom it is implanted. One would think that the managers responsible for the design of such devices would have pushed to make sure that the operation of such devices could not be hacked or accidentally altered in ways that could put patients' health and lives at risk. The most charitable explanation for why they did not think to do so is that they really did not understand the clinical context in which this device would be used.

This is yet another reminder that those who run health care organizations often fail to think about patients' welfare first instead of other considerations. We need to change the culture of health care organizations to put patients first. Until we do so, we are going to get hacked.

Wednesday, January 17, 2007

Medtronic Marketers Try to Sell Implantable Cardiac Defibrillators Direct to Patients

The latest subject of direct to consumer (DTC) advertising is medical devices. The Minneapolis Star-Tribune reports,


Medical technology giant Medtronic Inc. will launch a $100 million marketing campaign today to raise awareness about the dangers of sudden cardiac arrest -- and the role of heart defibrillators in saving lives.

Fridley-based Medtronic said the 'What's Inside' sudden cardiac arrest ad campaign is part of a bigger awareness push that is the largest in size and scope in company history.

'This is about saving lives,' said Dr. David Steinhaus, vice president and medical director of Medtronic's Cardiac Rhythm Disease Management division. 'Sudden cardiac arrest kills more people than breast cancer, lung cancer and HIV/AIDS combined.'

Sudden cardiac arrest can be prevented with a device called an implantable cardioverter defibrillator (ICD) -- a stopwatch-sized device implanted in the chest that shocks an errantly beating heart back into rhythm. But a series of safety recalls by manufacturers in 2005 -- including market leader Medtronic -- dampened demand for the device in the past year

Part of the problem is that patients who need the devices aren't necessarily getting them -- Medtronic estimates roughly 850,000 Americans are in this category.
Sometimes prospective patients don't have symptoms, which can make it difficult for doctors to persuade them to undergo an ICD implant procedure, Medtronic's Steinhaus said.

In addition, sometimes patients are not referred to the appropriate specialists (called electrophysiologists) who implant the devices -- which is why Medtronic is also targeting the general cardiology community with physician education programs, he said.

Sorry, but to me, this one smells bad from the get go.

The kicker here is the populations of patients for whom ICDs might be indicated. The notion that there are patients who ought to have ICDs implanted, but are walking around, without any symptoms, in blissful ignorance of this fact does not make a lot of sense to me.

Right now, there are two groups of patients for whom ICDs might have benefits that outweigh their harms. The first are patients who have already had a "near sudden death" experience, i.e., patients who have dropped their blood pressure, or fainted (had syncope) due to a particularly dangerous kind of rapid heart beat (ventricular tachycardia). To have had such diagnoses, such patients, have had to already come to medical attention. They do not need advertising campaigns to tell them they ought to have an ICD. [For a discussion of this group, see Josephson ME et al. The role of the implantable cardioverter-defibrillator for prevention of sudden cardiac death. Ann Intern Med 2000; 133: 901-910.]

The second group are patients at very high risk of such deranged heart rhythms. The MADIT II Trial suggested that patients who have had a heart attack (myocardial infarction) and have poor heart function (left ventricular ejection fraction less than 30%) have increased survival after placement of an ICD. [Moss AJ et al. Prophylactic implantation of a defibrillator in patients with myocardial infarction and reduced ejection fraction. N Engl J Med 2002; 346: 877-883.] The SCD-HeFT trial suggested that patients with congestive heart failure who are moderately symptomatic (New York Heart Association classes II and III) and have a ventricular ejection fraction of less than 35% may also so benefit. [Gardy GH et al. Amiodarone or an implantable cardioverter-defibrillator for congestive heart failure. N Engl J Med 2005; 352: 225-237.] Again, most people who have had myocardial infarction resulting in poor heart function are not walking around blissfully unaware of these major problems, nor are people with at least moderately symptomatic heart failure.

Furthermore, there are many legitimate reasons that people who fit into the categories listed above should not have ICDs. In particular, many people with such serious heart disease also have other severe medical problems. The benefits versus harms of ICDs is unknown in such patients, who would have been excluded from the trials above. (For example, MADIT II excluded anyone with another severe disease that increased the risk of death during the trial time-frame.) Patients with other severe medical problems could die or become seriously ill from these other problems before having any opportunity for an ICD to prevent a dangerous rhythm disturbance.

So I question the whole notion that the DTC advertising would flush out tens of thousands of patients who were totally unaware that they could benefit from ICD placement.

So why do this advertising campaign? Is it just a result of how marketers have come to dominate nearly every health care organization, including device manufacturers? Many of those of the marketing persuasion seem to be totally focused on selling more product. That may be good for the marketers' careers, but it may not be good for those having these particular products implanted in their chests.

In health care, our goal should be first only to do things to patients whose benefits are likely to outweigh their harms, not just to move expensive products off the shelves.

Hat tips to the Over My Med Body blog and the Schwitzer Health News Blog.

Please also see the comments on SurgeonsBlog, on having one's mind blown by one of the print advertisements from this campaign in the New York Times.

Wednesday, March 22, 2006

Call for Transparency and Physician Input at Guidant

We have posted frequently about the troubles afflicting Guidant Inc (scheduled to be acquired by Boston Scientific). These troubles revolved around Guidant's failure to reveal defects in its implantable cardiac devices. (See posts here, here, here, here, and here.)

The New York Times has just revealed the findings of an external review that Guidant, to its credit, commissioned. Its main findings were:
  • "Decisions on how to assess product defects were made by Guidant engineers rather than medical experts."
  • "As a result, Guidant officials could claim a device's performance fell within engineering limits without considering the medical consequences of product failures...."
  • "'There was no medical input to speak of' in the review process...." "Even the top medical officer of Guidant's cardiac device unit, Dr. Joseph Smith, acknowledged in an interview with the panel that he had not been hired to be a 'patient safety officer' but rather to interact with other physicians on educational issues."
The panel's conclusions were striking, "in addition to recommending the creation of an outside panel to monitor device performance, the panel suggested that Guidant, among other things, employ a physician whose main duty would be patient safety. The group also concluded that both Guidant and other makers of heart devices needed to significantly increase the level of data they collected about possible device failures."
More transparency, and involving physicians, not just managers and engineers, in decisions affecting patients' well being sounds just about right. (We have been saying similar things on Health Care Renewal for quite a while.)

Wednesday, March 01, 2006

More About Guidant: "It Is Possible That Physicians and Others May Pull On These Threads"

The New York Times is continuing to investigate the operations of Guidant Corporation. We have previously posted quite a bit about Guidant in the past, focussed on its history of withholding information about possible adverse effects of its devices. (For our more recent posts, go here, here, here, and here.)

The Times' most recent article focuses on newly released documents from an ongoing court case against Guidant. Some key quotes:


As the Guidant Corporation came under scrutiny last spring for not telling doctors about potentially fatal defects in its heart devices, the company's public message was upbeat and insistent: concerns about the safety of its products were overblown, it said, and perhaps even irresponsible.
But newly released documents show that, inside Guidant, executives were struggling to contain a mounting crisis.
The company's crisis started last May after two doctors in Minneapolis, Dr. Robert G. Hauser and Dr. Barry J. Maron, learned from Guidant executives that an electrical flaw in a company defibrillator had played a role in the death two months earlier of a college student who was their patient. They urged the company to alert doctors about the potential of the device, the Prizm 2 DR, to short-circuit. When Guidant hesitated, they contacted some other doctors and The Times.
Mr. [R. Frederick] McCoy [Jr., President, Cardiac Rhythm Management] struck an upbeat rallying tone in many of his messages. After The Times article about the Prizm 2 DR appeared, Mr. McCoy jotted on a note pad: 'Positive proactive visible,' summing up the company's strategy. In another note, seemingly dismissing the problem, he wrote, 'Nobody calling our decision and action into question.'
But even as Guidant was assuring doctors that it did not plan to recall the device, executives inside the company were less sanguine. On June 2, for example, Dr. Beverly H. Lorell, Guidant's chief medical officer, sent an e-mail message to Mr. McCoy about other company devices that might attract outside scrutiny. Some data about them, she noted, was in a public F.D.A. database.
'Parts of the data for each of the three trends are in public domain and thus amenable to further external scrutiny and discussion,' Dr. Lorell wrote. 'It is possible that physicians and others may pull on these threads in the near future.'
As those threads began to unravel, executives like Mr. McCoy soon found themselves backtracking.
Strikingly, some Guidant executives realized early, according to records, that the crisis might be contained if the company overhauled its disclosure practices and provided doctors with more detailed failure data. But a draft press release, dated June 3, shows that Guidant planned to combine the announcement of such a policy change with a marketing initiative to promote a new product. The release apparently never went out, and five months passed before Guidant issued its new and detailed report on product failures.

It is striking that although some Guidant managers thought that a transparent approach to releasing data about possible product flaws might be best for the company, those in charge circled the wagons.

To make important medical decisions, like those about implanting cardiac devices, patients and physicians need accurate, unbiased data about the possible benefits and harms. Withholding data about the possible harms caused by devices is bad for patients, a threat to physicians' professionalism. And ultimately, it appears to be bad for device makers' bottom lines. (The Times article noted that Guidant's market share for cardiac devices has fallen from 35 percent to 24 percent.)

So, instead of tying up all the threads in secret cloths, health care organizational leaders need to pull on them themselves.

Monday, January 30, 2006

New Problems for Guidant and Boston Scientific

Device manufacturer Guidant, Inc., was recently the object of a bidding war between Boston Scientific and Johnson & Johnson, seemingly won by the latter. We had posted quite a bit about Guidant in the past, focussed on its history of withholding information about possible adverse effects of its devices. (For our more recent posts, go here, here, and here.)

Guidant has just had to recall yet more devices, this time, older pacemakers. (See story here.)

Furthermore, the New York Times reported that documents possibly related to charges that Guidant withheld negative information about its products were just subpoenaed by a US Attorney. The Times reported:
Among other things, the records indicate that company executives debated whether to warn doctors that some heart defibrillators could short-circuit. The records suggest that Guidant might have sold potentially flawed devices.
The documents include a hand-written annotated chronology related to the Contak Renewal that was apparently composed by the head of Guidant's cardiac unit, J. Frederick McCoy Jr. It suggested that Guidant executives debated in January 2005 whether to alert doctors to the Contak Renewal problem.
At the time of the debate, one entry also states "Informed Ron Dollens: Guido Neels of the development," an apparent reference to Guidant's chief executive and chief operating officer at the time; both men have since retired. Mr. Dollens declined, through a company spokesman, to comment. Mr. Neels, reached by telephone, also declined to comment.
The released documents, hand-dated Oct. 20, 2004, apparently projected that existing inventories of Contak Renewals would run out in mid-November 2004. The company did not disclose the Contak Renewal problem until June 2005, after the F.D.A. had opened an inquiry.

Furthermore, Boston Scientific, which apparently won the bidding war for Guidant, has quality problems of their own. The Boston Globe just reported that the company
has been slapped with a rare federal warning letter that could prevent the Natick company from introducing new products until it fixes 'continuing serious deficiencies' in quality control, the Food and Drug Administration said last night.
The FDA warning letter focused on the Natick company's top management, saying executives failed to fix numerous problems the agency had already outlined at particular plants and offices. Such emphasis is unusual for the FDA. This week's 'corporate warning letter' was only the third issued in a decade by the agency's medical device division, officials said.
'The problems we identified in this letter we consider very serious,' said Daniel G. Schultz, the director of the FDA's medical device division, in a phone conference last night.
Boston Scientific received three FDA warnings last year about shipping errors and lapses in keeping track of doctors' reports of device problems. In one case, workers were able to override a computer system and ship devices to a hospital even though the products had failed an inspection.
This letter also detailed problems in three other plants, including one facility in Indiana where managers were unaware that one of their products, the Leveen needle electrode, had been recalled.

As we have noted many times before, physicians and patients cannot make good decisions about whether to implant medical devices in the absence of unbiased information about the devices benefits and harms.

Furthermore, such devices are now so expensive that physicians and patients should expect that the devices will be manufactured to exceptional quality standards.

Saturday, September 17, 2005

More Concerns About Delayed Reporting of Faulty Medical Devices

We have posted about a series of stories suggesting that manufacturers of implantable cardiac defibrillators (ICDs) and the US Food and Drug Administration (FDA) were slow to warn the public about serious defects in these devices that lead to premature device failure.
As stories of failing ICDs have received more attention, more editorials are calling for improved behavior by device manufacturers and a revamp of how the FDA regulates these devices.
The Indianapolis Star stated its editorial position, "medical device makers need to better disclose malfunctions to doctors and the public."
The St. Petersburg Times charged that "the Food and Drug Administration once again has demonstrated a level of incompetence that threatens public health." Already, "Americans have lost faith in the FDA for the agency's lax policing of prescription drugs and failure to share information about drug safety with consumers. This episode makes the government look inept even if it wanted to be more responsive." So Congress "needs to reform an agnecy that serves as a critical watchdog for Americans."
And just to add more fuel to the fire, the FDA just released a report that the failure rate of ICDs is increasing. According to the Washington Post, "in the mid-1990s, some 7.9 ICDs per 1000 implants were replaced because of malfunctions. That rose to a high of 38.6 per 1000 implants in 2001 before dropping slightly to a rate of 20.7 the following year. " Of these failures, "eighty percent were device hardware problems, such as with electrical connections."
Again, physicians and patients need accurate data about benefits and harms of treatments, especially expensive, invasive treatments that are meant to prevent future problems, not immediately treat disease, like ICDs. Information that such devices fail more frequently in clinical use than they did in controlled trials performed in ideal conditions is important in the clinical decision-making process. Neither the financial self-interest of device manufacturers nor the bureaucracy of government regulatory agencies should keep this information from doctors and the public.

Thursday, September 15, 2005

How the FDA Sat On Data About Failures of Guidant's Implantable Cardiac Defibrillators

The story of failures of implanted cardiac devices made by Guidant just gets more complex. The New York Times reported this week that Guidant had sent detailed data about the performance of its implantable cardiac defibrillators (ICDs) to the US Food and Drug Administration (FDA) in February, 2005. This included data that suggested that about one of its Ventak Prizm 2 DR defibrillators was failing a month. The FDA did not make public this information suggesting a relatively high failure rate for the device, partly because the FDA treats such information as confidential. Dr. Daniel G Shultz, director of the FDA Center for Devices and Radiological Health, said that it would take too many resources to review "hundreds of filings the FDA receives each year and determine which data should be routinely released and what should be treated as confidential." The news article also noted that "the FDA initially refused a Times request for several years of Guidant annual filings that was made under the Freedom of Information Act, contending that the filings contained trade secrets."
We have posted frequently about the ongoing Guidant saga. A recent post is here, with links to earlier ones.
Before I had a chance to write some blustery prose about this latest part of the saga, the New York Times editorial page beat me to it.
The deplorable story of how a medical-device company sat information about a flawed heart defibrillator while a hapless recipient died has now engulfed the Food and Drug Administration as complicit in the silence.
What is disturbing is how long it took the company, the Guidant Corporation, and the regulators to get a meaningful warning to doctors and patients.
The agency's excuse for not making the failure data public right away is too feeble to withstand scrutiny.
The bigger points are:
The FDA needs to rededicate itself to protecting the health and safety of the public as its first mission. Being nice to pharmaceutical and device manufacturers is a distant second.
Pharmaceutical and device manufacturers must remember that if they want physicians and patients to trust them enough to buy their products, often offered at very handsome prices, they must be absolutely honest and transparent in how they present data about their products' performance to them. Insisting on the confidentiality of data about clinical results of using devices will not inspire such trust.

Monday, August 08, 2005

How the FDA Hid Data About Failures of Guidant's Devices Under the Cloak of "Trade Secrets"

The New York Times has produced yet more revalations about how data about Guidant's implantable cardiac defibrillators (ICDs) has been witheld. A reporter asked the US Food and Drug Administation (FDA) for results of the reports Guidant has been sending annually about device failures. According to the Times, "under little-known FDA regulations, the makers of defibrillators and pacemakers must provide detailed data each year to the agency, including the frequency of failure in individual models, the cause of such failures and the number of deaths and injuries."
But in response to the Times' inquiry, an "agency official," Joy B. Lazaroff, said "this information is a trade secret and exempt from release."
A Guidant spokesperson, Steven Tragash, "declined to respond to written questions on the frequency of the risk assessments of the Prizm 2 DR [a model of an ICD]...." Furthermore, Mr. Tragash would not let the CEO of Guidant, Ronald W. Dollens, submit to an interview on the topic.
I can't comment on the legal aspects of this case, but surely from a policy perspective, the FDA, which is charged with protecting US citizens' health and safety, should not be hiding data on potentially life-threatening failures of cardiac devices as "trade secrets."
The Times editorial staff apparently now also agrees that the Guidant issue is an important one. On Sunday, a Times editorial entitled "When a Heart Device Short-Circuits," based on the Guidant case, called for improved regulation of medical devices.

Wednesday, August 03, 2005

The New York Times Examines Why Implantable Cardiac Defibrillators Are So Expensive

The New York Times ran an analytic article that raised some important points about the pricing of medical devices, and, by extension, the costs of health care. The report focused on the recent controversy about Guidant's multiple recalls of implantable devices, and allegations that the company withheld data about faulty devices from physicians and patients (see our most recent post here).
Here are some key points:

Last year, an estimated 135,000 devices were implanted in patients in the United States alone, a near tripling of the number in 2000. Meanwhile, the three major device manufacturers, Guidant, Medtronic, and St. Jude Medical, have reported a financial bonanza as domestic sales rose during the same period to $3.5 billion....
Defibrillator prices are like those found on a new car, ranging from $20,000 to $35,000 each.
==> The devices are expensive, they cost the health care system a lot of money, but the manufacturers make big profits
Physicians ... and health policy experts say that manufacturers have used a variety of strategies to increase profits by keeping device prices high. For example, rather than offering a low-cost unit that does the basic job of stopping a bad heart rhythm, defibrillator makers are engaged in a sort of medical arms race in which producers turn over models by adding new features.
'These companies don't compete on price, they compete on features,' Dr. Hlatkey (Professor of health research and policy at Stanford)
Doctors and patients also have no reason not to go for a top of the line model, said experts like Dr. Hlatkey. Many physicians acknowledge that they do not consider product prices when deciding on which model defibrillator is best for their patient. And patients have little reason to care about cost because insurers like Medicare cover the cost of an inpatient procedure, which includes the device, regardless of cost.
In just two years, defibrillator-related costs to both Medicare and private insurers are expected to reach $10 billion....
The price of a defibrillator, like other medical devices, follows its own unique economics, experts say. For example, while the prices of other high technology devices like computers and digital cameras have plunged, the price of a standard defibrillator has remained steady or declined slowly....
Many cardiologists ... say they have long lobbied major producers, without success, to make a less-costly defibrillator that performs the device's basic functions of saving a life.
Daniel Schaber, a vice president at Medtronic, said it was unfair to compare defibrillators with consumer products like computers because the market for heart devices was tiny relative to computer sales. And both he and Dr. Eric Fain, an executive at St. Jude Medical, said that the technologies might be costly but were in response to what doctors wanted. 'We have said to our advisers, what would you be willing to back to in terms of functionality?' said Dr. Fain, referring to doctors who serve as St. Jude consultants. And those consultants, he said, have routinely rejected changes that would result in loss of certain features.
Separately, a hospital consulting firm, Aspen Healthcare Metrics of Englewood, Colo., said last year in court papers as part of a lawsuit that the device makers kept doctors loyal to its brand by giving them 'clinical research grants, consulting arrangements, and other gratuities.'
==> The device manufacturers seem to base their argument that physicians only want devices with bells and whistles on the comments of physician "consultants" whom the manufacturers pay for their advice, and hence might be inclined to tell the companies what they want to hear.
The big question again is why Medicare and commercial managed care companies do not challenge the pricing of these devices? The rationale for commercial managed care, of course, was to save money. And clearly Medicare has been aggressive in cutting costs, especially when it comes to paying fees for physicians' cognitive services, and for basic hospital care for acute disease.
It's significant, I think, that the Guidant story has become so big that the New York Times is starting to do both investigative reporting and analytical pieces on it. Let's keep an eye out for what turns up next.

Saturday, July 23, 2005

The New England Journal of Medicine on Guidant

In this week's New England Journal of Medicine, the indefatigable Robert Steinbrook has provided a nice summary of the Guidant case to date, complemented by some notable original reporting. (The link is here, but getting the full article requires a subscription. The full citation is: Steinbrook R. The controversy over Guidant's implantable defibrillators. N Engl J Med 2005; 353:221-224.)
Steinbrook summarized the events in the case, including how in 2002 Guidant discovered a fault in its implantable cardiac defibrillators (ICDs) that could cause them to short-circuit and fail; how Guidant re-designed the devices in 2003, but continued to ship devices prone to the fault; and only notified physicians and the public of the problem in 2005. (We have posted frequently on the Guidant case, most recently here.)
The problems with Guidant's ICDs first became evident to physicians after a young man with an ICD implanted for hypertrophic cardiomyopathy (pathologic excessive growth of the heart muscle) died in 2005 of a rapid heart rhythm that his ICD failed to stop. Steinbrook reported how his physicians at the Minneapolis Heart Institute investigated, searching the Manufacturer and User Facility Device Experience (MAUDE) data-based held by the US Food and Drug Administration (FDA). They found other reports of short-circuit induced failures of Guidant ICDs. Steinbrook quoted Dr. Barry Maron, director of the Hypertrophic Cardiomyopathy Center:
"We became very concerned. We were keeping a secret not just from our patients and their physicians, but also from all the patients with the device and their physicians. On May 12, four Guidant officials came to my office and gave a very educational presentation. I asked, 'What are we going to do about this? We are in an untenable situation ethically and morally with our patients. How are we going to get the word out?' They said, 'Well, we are not. We don't think we need to. And we don't think it's advisable.' The officials expressed doubt that the patients would be able to understand the medical issues involved in determining whether or not to replace the devices. I said, 'I think this is the biggest mistake you will ever make.' They said they didn't agree."
This appears to be a chillingly direct example of external threats to physicians' core values arising when the leaders of a large health care organization put the organization's short-term financial interests ahead of their ethical obligation to provide the information needed by doctors and patients to make good clinical decisions.
Steinbrook concluded, "For more than three years, Guidant kept quiet about the serious malfunctions of some of its ICDs and continued to sell defective devices after it made manufacturing changes to fix the defects. The company will have to regain the trust of patients and physicians."
The New England Journal and Robert Steinbrook deserve commendation for treating this story as one of broad significance. This article stands in sharp contrast to the kid-glove treatment given the Guidant's Chief Executive Officer Robert W. Dollens during his interview by a senior editor of Health Affairs (see our post here). The interviewer never acknowledged either that Guidant had manufactured ICDs that were prone to fail, that they had knowingly shipped such ICDs from stock after beginning re-designed models that corrected the fault, or that Guidant had concealed these facts from physicians and the public for three years. The Health Affairs interview seemed to be an example of the "anechoic effect," how stories about threats to physicians' core values arising from concentration and abuse of power produce no echoes outside of the local news media. The New England Journal and Dr. Robert Steinbrook have dealt the anechoic effect a mighty blow.
[In other news about Guidant's troubles, also note that the New York Times has just reported that Senator Charles E. Grassley, Chair of the Senate Finance Committee, may have his committee review the recent Guidant recalls; and the Times also reported that Guidant's recommendations for correcting problems with some of its ICDs by reprogramming them might not prevent the devices from failing, and that Guidant has yet to come up with an alternative solution, other than removing and replacing these devices.]

Sunday, July 03, 2005

Don't Ask, Don't Tell: Health Affairs Interviews Guidant CEO Ron Dollens

Health Affairs, which bills itself as " the leading journal of health policy thought and research," just published a lengthy (18 page in the PDF version) interview of Guidant CEO Ronald W. Dollens by Founding Editor John K. Iglehart. The interview was notable for the interviewer's extreme deference to the interviewee, and more for what the interviewer didn't raise that what he did.

The Case of Guidant's ICDs

An accompanying editor's note stated, "On May 24, 2005, one month after the interview that follows was conducted (25 April), the New York Times reported that an implantable cardiac defibrillator (ICD) sold by the Guidant Corporation had failed to operate properly while a twenty-one year old college student who had the device implanted in his chest was suffering a cardiac arrest. The student later died. Following the Times report, John Iglehart posed an additional question...." Furthermore, the note stated that Guidant had issued a press release on June 17, 2005, that Guidant was "volunatarily advising physicians about important safety information regarding certain devices [three ICD models]"; and that the Associated Press quoted a US Food and Drug Administration spokesman as saying "This is a voluntary recall." It also noted that Guidant confirmed reports of 45 failures of ICDs out of 63,000 implanted worldwide. Finally, the note quoted Dollens, "Patient safety is paramount and our highest priority."
The question that Iglehard asked Dollens about this issue was:
  • "A recent New York Times story, which focused specifically on ICDs, raised broad questions relating to the inherent risk associated with invasive procedures and the understanding of various groups of risk. Could you share with us your thoughts on the specific issues addressed in the Times article?"
Dollens replied,
  • "The article focused on the communications issues surrounding the continuous evaluation of patient risk when using novel, life-sustaining medical technology. We encourage public debate and discussion about the pros and cons of broader dissemination of infomation about product safety. Guidant looks forward to participating in that discussion."
This interview and the accompanying editor's note, however, left out some important information. In particular, the New York Times article of May 24 reported not only on the failure of the defibrillator that was associated with the death of the young patient, but also that Guidant had known for three years of a flaw in the design of that particular defibrillator, the Ventak Prizm 2, that could cause the unit to short-circuit and fail, and that the company had made changes in its manufacturing process three years earlier to correct this flaw. We posted about this New York Times article on Health Care Renewal, and concluded, " there seems to be no good excuse to hide data about this device's flaws from the public and from doctors."
Furthermore, there was other news about Guidant that appeared after the May 24 but before the June 17, 2005 press release. On June 2, the New York Times reported that Guidant continued to sell ICDs from stock manufactured before the flaw was corrected after it had started manufacturing an upgraded version that corrected the flaw. (See our post here.)
A day after the Guidant press release, the New York Times published another article disclosing flaws in additional models of Guidant ICDs, that Guidant had also failed to previously disclose these flaws to doctors as soon as it knew of them, and also that Guidant continued to ship the old version of these models of ICDs from stock after it started manufacturing new models which corrected the flaw. (See our post here.)
Thus, the prominent, lengthy interview in Health Affairs of Guidant CEO Dollen, done by the most senior Health Affairs editor, avoided mentioning most of the serious criticisms made of how Guidant handled the problem of faulty ICDs. Iglehart characterized the problem only in the most general terms, and allowed Dollen to provide an answer that was equally vague. Although the editor's note suggested that Health Affairs editorial personnel were aware of news about Guidant made public from May 24 to June 17, 2005, it failed to mention that the news after May 24 had raised additional issues about Guidant ICDs.

The Case of the Ancure Endograft System

Iglehart asked Dollens to opine about such diverse matters as "the era of evidence-based medicine," how Guidant provides health care coverage to its employees, and how "the American way of delivering and financing health care is flawed." Yet he never mentioned another serious problem in Guidant's past that eerily presaged the ICD problem.
In 2003, Guidant agreed to plead guilty to multiple felony counts for hiding, as the New York Times put it, "serious health problems, including 12 deaths, caused by one of its products." Guidant agreed to pay over $90 million in civil and criminal penalties, the largest fine ever paid by a device-maker for concealing problems with one of its products.
In summary, the facts reported by the Times in 2003 were as follows. In 1999, Guidant began marketing a new type of aortic graft that was inserted via a catheter, the Ancure Endograft System. Soon after the device was marketed, physicians who inserted it began complaining that the device would be become lodged prior to achieving correct positioning, requiring abdominal surgery to repair the problem. Guidant sales represented began instructing doctors to break the device into pieces and then extract them, even though this method had never been clinically tested, and despite the sales representatives' lack of qualifications to give such clinical advice. Guidant eventually reported 172 reports of problems with the device to the FDA, but later prosecutors charged that Guidant had concealed more than 2000 of the the reports it had received. The FDA heard of the scope of the problem in 2000 after seven anonymous whistle-blowers sent it a letter. Guidant pulled the aortic graft system off the market in 2001, and then revealed it had received thousands of reports of problems with the device. (See summaries of other news articles here, but most original articles are no longer on the web.)
Yet the Iglehart interview never mentioned the case of the Ancure Endograft System, which was undoubtably important, and seemed relevant not only to the more recent case involving ICDs, but indicative of the extent that Guidant really regards safety as "paramount."

In Summary

A prominent editor of a prominent health policy journal devoted considerable effort to and published considerable pages of an interview with the CEO of a large device manufacturing firm, yet avoided asking skeptical or probing questions about a current problem that raises substantive concerns about the quality of the company's products, and even bigger concerns about how the company has dealt with quality problems. The interviewer avoided asking any questions about a similar case from a few years ago.
This is only one article, but it seems to indicate how deferentially the health services and policy literature may treat leaders of large health care organizations. This literature is a major source of information about the health care system and health care policy for physicians, researchers, and policy-makers. While it may show deference to leaders of large organizations, however, this literature often includes pointed criticisms of physicians.
Here is another example of the "anechoic effect," the curious lack of echoes resulting from cases that show the down-sides of concentration and abuse of power.
But to fix these problems, we will at least have to start talking about them.
To help us do that, journals about health services and health policy should begin to show skepticism of the powers that be befiting these journals' scholarly aspirations.