Showing posts with label IT malpractice. Show all posts
Showing posts with label IT malpractice. Show all posts

Thursday, October 10, 2013

Drudge Report, Oct. 10, 2013, 9 AM EST: All that needs to be said about government, computing and healthcare

Per Drudge Report. Oct. 10, 2013, 9 AM EST:

From the same people who brought us HITECH, the stimulus bill for rapid rollout of commercial electronic medical records, order entry, results reporting and other components of enterprise clinical "command and control" software for hospitals through which every transaction of care must pass.

More IT malpractice.  The Drudge links, as they appear on the page:

Obamacare website cost more than FACEBOOK, TWITTER, LINKEDIN, INSTAGRAM...
'How can we tax people for not buying a product from a website that doesn't work?'
Major insurers, Dem allies repeatedly warned Obama admin...
REPORT: WH knew site might not be ready...
POLL: Just 1 in 10 report success...
DNC head says site designed for 50,000 max...
Once you get in, you can't get out...
Crazzzzzzzy code...
'It looks like nobody tested it'...
WASHPOST: Not code, but 'outdated, costly, buggy technology'...
CARNEY: 'I Don’t Know' If Obama Has Tried Website...
Hawaii forced to relaunch after zero sign-ups...


I won't comment any further; I don't think I need to.


Drudge Report, Oct. 10, 2013, 9 AM EST.  Click to enlarge.


Of course, the Anecdotalists [1] and Denialists [2] will probably say this is all a "glitch" and that things will be great in ver. 2.0.

Fools all.

Oh, and the cost, via Drudge, per the linked story.  A mere:



-- SS

[1]  See "Health IT: On Anecdotalism and Totalitarianism" at  http://hcrenewal.blogspot.com/2010/09/health-it-on-anecdotalism-and.html)

[2]  See "The Denialists' Deck of Cards: An Illustrated Taxonomy of Rhetoric Used to Frustrate Consumer Protection Efforts" by Chris Jay Hoofnagle, available at http://papers.ssrn.com/sol3/papers.cfm?abstract_id=962462)

Oct. 10, 2013 addendum:

Also see "Analysis: IT experts question architecture of Obamacare website" at http://uk.reuters.com/article/2013/10/05/us-usa-healthcare-technology-analysis-idUKBRE99407T20131005.  If the allegations here are even partially true, every programmer and manager who ever worked on this system should be summarily fired and never permitted to touch another computer involved in healthcare - ever.

-- SS

Wednesday, October 02, 2013

Another in the "Health IT Crashed, But Patient Care Was Not Compromised" Series - NHS Greater Glasgow and Clyde

We must have health IT to prevent stupid doctors and nurses from making mistakes.  Without it, patients are at the mercy of dreaded Paper Records, which by definition cannot ever be used to provide quality care.

But when the IT goes down, Patient Care Has Not Been Compromised.  This line should be trademarked, as it's seen so often.  (I even have an indexing tag for it, see this query link: http://hcrenewal.blogspot.com/search/label/Patient%20care%20has%20not%20been%20compromised.)

Care is never, never compromised when the IT goes belly up en masse due to information technology malpractice.  Care is only compromised by paper, no matter how good the paper records and its human stewards are.

Here's the latest example that made it to the news, in Scotland:

1 October 2013
BBC News
Appointments postponed after major IT failure at NHSGGC (NHS Greater Glasgow and Clyde)

Hundreds of outpatient appointments and a number of operations had to be postponed after computer systems failed at Scotland's biggest health board.

NHS Greater Glasgow and Clyde said technicians were working through the night to fix a "major IT problem" which occurred on Tuesday morning.

It affected staff access to clinical and administrative systems.

Delaying hundreds of appointments and delaying surgeries at up to 10 major hospitals seems on its face to represent "compromised care."

The health board apologised to patients and said all appointments would be rescheduled.

In total, 288 outpatient appointments, four planned inpatient procedures, 23 day surgery cases and 40 chemotherapy sessions were postponed.

There was also some delay in calls to the switchboard being answered.

The problem may have affected up to 10 major hospitals across the health board area.

One wonders how these appointments and surgeries were triaged for delay.  Clearly the downed computer was of no help.

Here's that wonderful line:

But emergency operations were not compromised - neither were community services.

So when does computer failure actually compromise patient care?  I'd like to see some hospital executive with a spine for once admit that IT malpractice does disrupt patient care, create distractions, and thus create safety risk.  Considering the domain, however, I doubt I'll ever see that.

A spokeswoman said: "Our technical staff are working flat out to resolve this.

It should never have happened in the first place.

"The problem relates to our networks and the way staff can connect to some of our clinical and administrative systems.

Well, sick patients really appreciate that explanation.

It was not clear how long the disruption would last.

NHSGGC said if it did continue, people who were scheduled for treatment would be contacted directly.

Per a computer guru from my past:  "Either you're in control of your information systems, or they're in control of you."

In this instance, the latter clearly applies.

In healthcare, having your information systems in control of you is, sooner or later, going to be deadly.

-- SS


Wednesday, August 28, 2013

Setback for Sutter after $1B EHR crashes (in followup to post "RNs Say Sutter’s New Electronic System Causing Serious Disruptions to Safe Patient Care at East Bay Hospitals")

At my July 12, 2013 post "RNs Say Sutter’s New Electronic System Causing Serious Disruptions to Safe Patient Care at East Bay Hospitals" (http://hcrenewal.blogspot.com/2013/07/rns-say-sutters-new-electronic-system.html) I reproduced a California Nurses Association warning about rollout of an EHR at Sutter:

RNs Say Sutter’s New Electronic System Causing Serious Disruptions to Safe Patient Care at East Bay Hospitals

Introduction of a new electronic medical records system at Sutter corporation East Bay hospitals has produced multiple problems with safe care delivery that has put patients at risk, charged the California Nurses Association today.

Problems with technology are not unique to health care ...  [What is unique to healthcare IT is the complete lack of regulation - ed.]

In over 100 reports submitted by RNs at Alta Bates Summit Medical Center facilities in Berkeley and Oakland, nurses cited a variety of serious problems with the new system, known as Epic. The reports are in union forms RNs submit to management documenting assignments they believe to be unsafe.

Patient care concerns included computerized delays in timely administration of medications and contact with physicians, ability to properly monitor patients, and other delays in treatment.  Many noted that the excessive amount of time required to interact with the computer system, inputting and accessing data, sharply cuts down on time they can spend with patients with frequent complaints from patients about not seeing their RN.  [Note: patients are not given the opportunity for informed consent about the risks, nor opt-out of EHR use in their care - ed.]

In related posts I'd observed such concerns being ignored by hospital management.  See header of the aforementioned post.

Now we have this:  a major system crash.

Healthcare IT News
Setback for Sutter after $1B EHR crashes
'No access to medication orders, patient allergies and other information puts patients at serious risk'
 
Worse, clinicians must now serve their Cybernetic Master to perfection, or be whipped (apparently to improve morale):

... "We have been on Epic for 5 months now, and we can no longer have incorrect orders, missing information or incorrect or missing charges. Starting on September 1st, errors made in any of the above will result in progressive discipline," according to another hospital memo sent to staff.

In the setting of dire warnings by the nurses of EHR dangers several months back that were likely largely ignored, if any patient was harmed or killed as a result of this latest fiasco, the corporate leadership has literally begged to be sued for negligence, in my view.

However I'm sure a press release soon will claim that "patient care has not been compromised."

Of course this includes now and moving forward, even with informational gaps all over the place.

-- SS

Aug. 29, 2013 additional thought:

The punishment for not being a 'perfect' user of this EHR is the ultimate "blame the user" (blame the victim?) game, considering the pressures of patient care in hospitals in lean times - partly due to EHR expense! - and EHRs that have not been formally studied for usability and are poorly designed causing "use error" (that is, a poor user experience promotes even careful users to make errors).  Cf. definition of bad health IT:

Bad Health IT ("BHIT") is defined as IT that is ill-suited to purpose, hard to use, unreliable, loses data or provides incorrect data, causes cognitive overload, slows rather than facilitates users, lacks appropriate alerts, creates the need for hypervigilance (i.e., towards avoiding IT-related mishaps) that increases stress, is lacking in security, compromises patient privacy or otherwise demonstrates suboptimal design and/or implementation.

The study of usability is getting underway only now via NIST but will likely be done in an industry-friendly way due to health IT politics.

-- SS

Aug. 29, 2013 addendum

There have been numerous comments over at HisTalk (at http://histalk2.com/2013/08/27/news-82813/) defending the outage as not EPIC's fault.   From the point of view of clinicians - and more importantly, patients - it doesn't matter what component of the hospital's entire "EHR" (an anachronistic term used for what is now a complex enterprise clinical resource and clinician command-and-control system) went down. 

Aside from all the EPIC issues the nurses have been complaining about (see earlier July 12, 2013 post linked above), the larger problem is that IT malpractice occurred.  The term "malpractice" is used in medical mishaps; I see no reason why it does not apply to major outages of mission critical healthcare information technology systems.

IT malpractice in healthcare kills.

These are the types of nurses I'd want caring for me and mine.  Letting this kind of snafu go "anechoic" does not promote proper management remedial education on Safety 101 and on health IT risk, two areas of education that management appears to desperately need in hospitals.

-- SS

Wednesday, December 28, 2011

IT Malpractice? Yet Another "Glitch" Affecting Thousands of Patients. Of Course, As Always, Patient Care Was "Not Compromised."

At my Nov. 2011 post "Lifespan (Rhode Island): Yet another health IT glitch affecting thousands - that, of course, caused no patient harm that they know of - yet" I wrote:

There's been yet another health IT "glitch" that, of course, caused no patients to be harmed. See other "glitches" here, here, here and at other posts which can be found by searching this blog on the banal term 'glitch'.

Add another case to the health IT glitch file, under the "do we feel lucky today?" patient risk category.

From the Pittsburgh Post-Gazette (I am quoted):


Computer outage at UPMC called 'rare' Systemwide disruption potentially dangerous, expert warns Saturday, December 24, 2011 By Jonathan D. Silver, Pittsburgh Post-Gazette

UPMC's electronic medical records system for inpatients went offline for more than 14 hours at nearly all its hospitals in the region, marking what the health system called a "rare" outage, but one that it claims did not harm patients.

First, as my aforementioned Nov. 2011 post and its contained links point out, these events are not as "rare" as they should be. (The asteroid colliding with Earth that caused the extinction of the dinosaurs - now that's a "rare" event.)

Second, as multiple posts on this blog have pointed out, the claims that "no patients were harmed" is both misleading and irrelevant:

Such claims of 'massive EHR outage benevolence' are misleading, in that medical errors due to electronic outages might not appear for days or weeks after the outage, depending on what information was corrupted/lost/misindentified/or otherwise mishandled after it is 'backloaded' once the system is up. All it takes is one med lost to cause misery and death. (I can speak about that from unfortunate personal experience.

Claims of 'massive EHR outage benevolence' are also irrelevant in that, even if there was no catastrophe directly coincident with the outage, their was greatly elevated risk. Sooner or later, such outages will maim and kill.

The outage affected a system designed by Cerner Corp., a global electronic records company, and customized by UPMC that doctors and nurses rely on for communication about patient records, medical orders and prescriptions.

It was unavailable from about 8:45 p.m. Thursday to 11 a.m. Friday at almost all of UPMC's hospitals except for Children's and UPMC Hamot in Erie, spokeswoman Wendy Zellner said.

"This is rare. This kind of widespread, extensive downtime would be rare," Ms. Zellner said.

Doctors and nurses continued to have access to patients' electronic records through backup systems, she said. They also had to resort to using old-fashioned paper records for documentation and orders.

"These things happen. They have really well spelled-out procedures for what to do when something goes down," Ms. Zellner said.

She acknowledged that doctors and nurses faced some challenges.

Faced 'some challenges?' In other words, care was compromised by the outage and the 'challenges' were to avoid medical error (and, of course, to make sure billing was unaffected):

Compromised -
a. To expose or make liable to danger, suspicion, or disrepute
b. To reduce in quality, value, or degree; weaken or lower.


Thousands of patients were affected, again reinforcing my point about how IT can and does greatly amplify the risks of paper -- as in my Rhode Island post -- such as errors and confidentiality breaches.

I cannot, for example, think of a single instance where thousands of paper records went unavailable simultaneously (unless, that is, someone lost the key to the Medical Records department), were made available to identity thieves en masse, or where thousands of medical orders were scrambled or truncated in a relatively short period of time as in Rhode Island.

These amplified risks could wipe out any advantages of EHR's over paper in a microsecond.


A partial list of facilities apparently affected in this latest episode of EHR mayhem, from this list:

That accounts for several thousand active patients, I am sure.

(12/28 Addendum: Bed counts of PA hospitals are here. Searching on "University of Pittsburgh Medical Center", it can be seen that thousands of beds were indeed involved.)

"Whenever people aren't working in their native system and workflow I have to believe that is more cumbersome for the clinicians, but these folks are well-trained in what to do when these things happen."

This seems at best an insensitive and perhaps even inhumane bit of P.R. More "cumbersome" for the clinicians? What about the poor patients? How would Ms. Zellner feel, I wonder, if it were her mother, child or significant other on the Operating Room table or having an acute MI when the EHR/CPOE systems went down?

Ms. Zellner said UPMC's public relations staff was unaware of the outage until contacted by a reporter.

It appears P.R. is not very high on the list for receiving information when a crisis arises. I may have known of the outage before they did.

The outage was caused by a "bug" or glitch in software designed by a vendor affiliated with Cerner, Ms. Zellner said. She refused to identify the company.

"We're not trying to point fingers at different vendors. It's a database bug, that's all I can tell you."

(That is, it's not our fault, it's the fault of the database vendor. Hospitals, I regret to inform you - you are responsible for unapproved medical devices used in your facilities, no matter what the source.)

And there's that word "glitch" again, accompanied by the equally banal "bug."

It's just a "bug." Cute little critter!

Me again in the Post-Gazette:

Scot M. Silverstein, a doctor and assistant professor Healthcare Informatics at Drexel University in Philadelphia, disagreed with the use of the terms "bug" and "glitch."

"What occurred here was a disruptive, potentially dangerous major malfunction of a life-critical enterprise medical device," he said.

Somehow, when a clinician makes a mistake, the terms "bug" and "glitch" are never used. In fact, when clinicians fail to meet accepted professional standards of healthcare practice, it is called "malpractice."

I think we can all agree that a major near-full-day outage of an enterprise EHR affecting multiple hospitals and thousands of patients does not meet accepted professionals standard of life-critical computing practice. Yet, all this merits is the word "glitch." It seems to me that if patients are harmed by, in reality, what is (on its face) IT malpractice during such events, not only the clinicians affected should be held liable.

Ms. Zellner said the problem was not a "crash" of the system because there were alternate methods used to cope that prevented patient care from being compromised.

The usual refrain. Let me repeat my definition of "compromised:"

Compromised -
a. To expose or make liable to danger, suspicion, or disrepute
b. To reduce in quality, value, or degree; weaken or lower.

A simple question - if extended EHR outages like this never seem to "compromise" care, then why not eliminate health IT entirely and spend the hundreds of millions saved on patient care?

"This is not a crash of Cerner either," Ms. Zellner said. "I think a crash is, 'Oh my God, the sky is falling,' nobody can get anything."

I leave it to the readers to ascertain the computer expertise levels and reasonableness of what Ms. Zellner thinks a "crash" is.

Technicians from UPMC, Cerner and the third company [the 'mystery' database company? - ed.] worked together on-site to identify and fix the problem. Ms. Zellner said she did not know why it took 14 hours to fix and the underlying cause was still unclear.

"They know what the problem is and I believe it's been fixed, but we really don't know what triggered it," Ms. Zellner said. "I think the next step would be some actual software upgrades."

They "don't know what triggered the 'problem'" - is a proper translation that they have no idea what went wrong?

In fact, regarding another Cerner EHR system which was extensively studied (see "A Study of an Enterprise Information System" at this link), Dr. Jon Patrick came to the conclusion that one of the sources of catastrophic failures is poor software engineering that has made the behavior of the studied system "non-deterministic." Further, software upgrades are not protected from incremental changes made by maintenance and customization staff, and may introduce even more instability.

A software upgrade without clearly understanding "what triggered the problem" is simply asking for more trouble. (My bet, however, is that they attempt it anyway.)

A Cerner representative could not be reached for comment.

What's to say?

How about this:

Dr. Silverstein said based on what he was told about the computer outage, it means that hospital medical staff would have been unable to update patient charts and probably would not have been able to issue any orders through the system during the time it was off line.

He also questioned how up-to-date the hospital's redundant records were.

Repeating UMPC's statement from the article that appeared after I gave my quotes to the reporters: "Doctors and nurses continued to have access to patients' electronic records through backup systems, [the UPMC spokesperson] said. They also had to resort to using old-fashioned paper records for documentation and orders."

My stated fears of disruption and increased risk due to compromised care seem well-grounded.

In May, Allegheny General Hospital had to shut its electronic medical records computer system down because of problems with the vendor's hardware.

The hospital used backup procedures to continue care for patients, including using paper orders and record-keeping.

Wait ... I thought I'd heard these events were "rare." Two in the same city within six months?

---------------------------

Truth be told:

The primary rule in computing is:


Either you are in control of your information systems, or they are in control of you.

Clearly the latter was the case here.

The following questions arise:

  • Was the software containing the "bug" properly vetted before being used on live patients? This is not just the vendor's obligation.
  • If it was not vetted properly, why not?
  • Was it an "upgrade" or patch? (If so, the same vetting rules apply.)

Further, the soft-selling of these incidents must end. The use of terms such as "bug" and "glitch" must also end. What occurred here, echoing my newspaper quote, was a disruptive, potentially catastrophic major malfunction of a life-critical enterprise medical device.

System-wide EHR crashes are not merely ‘glitches’ or ‘bugs.’ They need to be considered, as in medicine itself, as 'never events.' From AHRQ:

The term "Never Event" was first introduced in 2001 by Ken Kizer, MD, former CEO of the National Quality Forum (NQF), in reference to particularly shocking medical errors (such as wrong-site surgery) that should never occur. Over time, the list has been expanded to signify adverse events that are unambiguous (clearly identifiable and measurable), serious (resulting in death or significant disability), and usually preventable.

Further, re: "patient care was never compromised." How do they know that? In fact, this is 'spin' and word games on its face. By definition, if CPOE and chart updating was unavailable, patient care was compromised, where "compromised" means "increased levels of risk for error were created, requiring workarounds."

Further, as mentioned earlier, harms might not show up for some time. Lost orders, corrupted data, errors of omission or commission transcribing backup paper records into the computer ("backloading"), etc. can take their toll later. Post-outage vigilance is essential, putting even more stress on clinicians that increases likelihood of further error and that they certainly do not need. Clinicians are stressed enough already.

Finally:

IT personnel have not only deliberately inserted themselves into clinical affairs (e.g, via the HITECH Act of 2009), they have also done so with a stunning arrogance and unproven braggadocio about their systems "revolutionizing" medicine (whatever that means).

Indeed, they need to accept the medical responsibility and obligations this territorial intrusion entails.

On its face, this massive outage was the result of issues that did not meet accepted professional standards of IT practice for life-critical environments. Res ipsa loquitur.

Something was not vetted properly, there was a lack of redundancy, the IT personnel were NOT in control of their systems.

Just as when physicians don't provide care that meets accepted professional standards of healthcare, this incident and others like it are, by definition, a result of IT malpractice.

If patients are harmed, IT personnel and their management (often non-IT C-level officers) involved in this system need to be held accountable.

If they can't take the clinical heat (as clinicians do daily since the time they enter medical or nursing school), then they need to get out of the clinical kitchen.

-- SS

Note: see this take on these matters at the HIStalk blog:

UPMC’s Cerner systems go down for 14 hours at most campuses last Thursday and Friday, forcing them to go back to paper. The PR person blamed “a database bug,” which makes the above Oracle press release from this past summer a particularly fun read. Cerner and UPMC have an atypical vendor-customer relationship since they’ve invested big money together in innovation projects and UPMC runs a Cerner implementation business overseas.

Now we know who the unnamed "mystery database vendor" is...

-- SS

Dec. 29, 2011 Addendum:

Was UPMC acting as a "proving ground" for some Oracle-Cerner-UPMC experimental health IT technology that resulted in the crash? The claim of being an IT "proving ground" has been made in the past:

Pittsburgh Tribune
May 2, 2006
UPMC partners with technology provider

The University of Pittsburgh Medical Center is taking another step in a quest to commercialize new medical technology.

UPMC on Monday signed a three-year deal with health care information technology provider Cerner Corp. to develop and market medicine-related technological advances. Both parties will contribute $10 million in cash, services and intellectual property to the effort.

The deal is a smaller version of an April 2005 deal between UPMC and information technology behemoth IBM.

As is the case in the IBM deal, UPMC will serve as a built-in proving ground for jointly developed technologies and products, with Cerner marketing the products and UPMC awarded a share of profits.

As I wrote at "Proving Ground for IT Tests On Children: Pioneers in Health IT, or Pioneers in Ignoring the Past?":

"A hospital and patients are not a learning lab for HIT vendors. The appropriate "proving ground" for new medical technology is the controlled clinical trial where participants (in this case, patients and healthcare professionals alike) have freedom of choice whether or not to participate, and a chance to give (or deny) consent after being fully informed of potential risk."This is a fundamental human rights issue.
-- SS