Showing posts with label gag clause. Show all posts
Showing posts with label gag clause. Show all posts

Monday, September 14, 2015

Politico 2015: EHR sellers using “gag clauses” (despite Koppel/Kreda's 2009 JAMA article on EHR nondisclosure clauses, and my 2009 JAMA Letter to the Editor on how these clauses violate Joint Commission safety standards)

I have not blogged on EHR issues in some time, despite some interesting source material such as:


These can be read at the links above, and are self-explanatory.

A new Politico investigation and article, however, is worth writing about:
  
Politico
Doctors barred from discussing safety glitches in U.S.-funded software
Darius Tahir
09/11/15
http://www.politico.com/story/2015/09/doctors-barred-from-discussing-safety-glitches-in-us-funded-software-213553

President Barack Obama’s stimulus put taxpayers on the hook for $30 billion in electronic medical records, many of which have turned out to be technological disasters.

But don’t expect to hear about the problems from doctors or hospitals. Most of them are under gag orders not to discuss the specific failings of their systems — even though poor technology in hospitals can have lethal consequences. 

[Change the "can" to "does", e.g., ECRI Deep Dive, http://hcrenewal.blogspot.com/2013/02/peering-underneath-icebergs-water-level.html - ed.]

A POLITICO investigation found that some of the biggest firms marketing electronic record systems inserted “gag clauses” in their taxpayer-subsidized contracts, effectively forbidding health care providers from talking about glitches that slow their work and potentially jeopardize patients.


[E.g., see http://hcrenewal.blogspot.com/search/label/glitch - ed.]

POLITICO obtained 11 contracts through public record requests from hospitals and health systems in New York City, California, and Florida that use six of the biggest vendors of digital record systems. With one exception, each of the contracts contains a clause protecting potentially large swaths of information from public exposure. This is the first time the existence of the gag clauses has been conclusively documented.

I note this Politico article appears six years after the seminal JAMA article on hold harmless and defects nondisclosure clauses:

as well as:


In that 2009 JAMA Letter to the Editor I observed:

... In their Commentary, Dr Koppel and Mr Kreda made clear the problems associated with applying the customs and traditions of business software contracting and sales (where “hold harmless” and “keep defects secret” clauses are commonplace) to health care information technology (HIT) as if they are the same. I believe that ignoring their differences has likely created an epidemic of violations of hospital governing body responsibilities and Joint Commission standards for health care organization leadership.

In 2015 I stand by these assertions.  Computer and business personnel - through arrogance, selfishness, narrow-mindedness and other issues - have made a mess assuming that business software practices apply to clinical medicine and healthcare IT.  In the latter domain, however, increased clinical stress and hypervigilance due to bugs clinicians have to work around (that might have been fixed sooner), lessening their performance and increasing risk, and patient injury and death has been the result of a belief that clinical computing is just a niche area of business computing.  (I've been making this point for at least 15 years, I might add.)

Such contractual practices endanger patients, and in 2015 are reckless, negligent and inexcusable.

http://injury.findlaw.com/accident-injury-law/recklessness.html
Recklessness means the person knew (or should have known) that his or her action were likely to cause harm. Negligence means that the person acted in violation of a duty to someone else, with the breach of that duty causing harm to someone else.

More from the Politico article:

Vendors say such restrictions target only breaches of intellectual property and are invoked rarely.

IP breaches?  While I understand the business issues at hand, in reality this is farcical.  There is little unique and valuable IP in these systems...as if one EHR vendor would really copy off another EHR vendor's screens.  I've seen many EHRs and their instruction manuals and in my opinion there's little worth stealing from any of these look-alike systems.

But doctors, researchers and members of Congress contend they stifle important discussions, including disclosures that problems exist. In some cases, they say, the software’s faults can have lethal results, misleading doctors and nurses who rely upon it for critical information in life-or-death situations.

Change the "can" to "do."  See ECRI link above, posts such as at http://hcrenewal.blogspot.com/2011/09/sweet-death-that-wasnt-very-sweet-how_24.html, and as readers here know, I have one less living relative thanks to EHR faults.  (I know of others that I cannot discuss.)

Critics say the clauses – which POLITICO documented in contracts with Epic Systems, Cerner, Siemens (now part of Cerner), Allscripts, eClinicalWorks and Meditech – have kept researchers from understanding the scope of the failures.

I actually refute that.  I believe many researchers (in the field of Medical Informatics, at least) were blinded by their own wishful thinking about health IT and their own misplaced overconfidence in computing.  My writings for a decade and that of many other "iconoclasts", based on experience and insight from other fields in which we worked, clearly raising huge red flags, were derided or summarily ignored.  For instance, see my post "The Dangers of Critical Thinking in A Politicized, Irrational Culture" from almost exactly five years ago at http://hcrenewal.blogspot.com/2010/09/dangers-of-critical-thinking-in.html.  There was enough data to ascertain that major problems were extant.

Even the ECRI Deep Dive EHR safety study referenced above, now at least three years old, finding 171 IT mishaps in 9 weeks in just 36 hospitals voluntarily reported, causing 8 significant harms and 3 possible deaths, is rarely cited by the "researchers."  See http://hcrenewal.blogspot.com/2013/02/peering-underneath-icebergs-water-level.html.

... Sheldon Whitehouse (D-RI) asked a panel of witnesses [during a HELP committee hearing earlier this summer], including Allscripts CEO Paul Black: “Can anyone on this panel see a single reason why these contracts should have gag clauses in them?”  No one ventured a reason.

Perhaps, I ask, because it would be hard to say something like "Senator, our computers have more rights than patients, and we don't give a damn about patient harm as long as the $$$ keep rolling in, and payouts for screw-ups that do make it to court are manageable", Ford Pinto-style, in such a setting?

After POLITICO disclosed its findings, an aide to HELP Chairman Lamar Alexander (R-Tenn.) said the committee would look at the issue, “exploring potentially harmful effects of these clauses – including how they could inhibit interoperability.”

The interoperability issue is a diversion if not a non-sequitur.  Dreamers still believe billions will be magically saved, and lives saved, via "interoperability", ironically at a time when basic operability is poorly achieved.

Let me state this clearly:  health IT will always be a major cost center and will never result in the mass cost savings attributed by the pundits to it.  From experience, I state that is a pipe dream, a fantasy, a risible statement consistent with a mania over the technology.  The issues in medicine that cost dear money are complex, and are not amenable to solution via cybernetic miracles.

See http://hcrenewal.blogspot.com/2012/09/wsj-koppel-and-soumerai-major-glitch.html for more on this issue:

... a comprehensive evaluation of the scientific literature has confirmed what many researchers suspected: The savings claimed by government agencies and vendors of health IT are little more than hype.

To conduct the study, faculty at McMaster University in Hamilton, Ontario, and its programs for assessment of technology in health—and other research centers, including in the U.S.—sifted through almost 36,000 studies of health IT. The studies included information about highly valued computerized alerts—when drugs are prescribed, for instance—to prevent drug interactions and dosage errors. From among those studies the researchers identified 31 that specifically examined the outcomes in light of the technology's cost-savings claims.

With a few isolated exceptions, the preponderance of evidence shows that the systems had not improved health or saved money.


Rather than saving money, the industry is sucking in some of that $17 or so trillion the United States just doesn't have (http://www.usdebtclock.org/).  See for instance "The Machinery Behind Health-Care Reform: How an Industry Lobby Scored a Swift, Unexpected Victory by Channeling Billions to Electronic Records", Washington Post, by Robert O'Harrow Jr., May 16, 2009.

Back to Politico:

... Take Cerner’s agreement with LA County’s Department of Health Services, signed in November 2012 and worth up to $370 million. It defines the vendor’s confidential information as “source code, prices, trade secrets, mask works, databases, designs and techniques, models, displays and manuals.” Such information can only be revealed with “prior written consent.” The protections cover the provider company, and its employees.

Such agreements, which are typical of the contracts examined by POLITICO, “contain broad protections for intellectual property and related confidentiality and non-disclosure language which can inhibit or discourage reporting of EHR adverse events,” said Elisabeth Belmont, corporate counsel at MaineHealth.

Belmont said she had also seen non-disparagement wordings that prohibit providers from disseminating negative information about the vendor or its software. POLITICO found no direct evidence of such clauses.

"Non-disparagement wording?"

How about good old-fashioned Orwellian thought control?  See my Oct,. 2013 post 'Words that Work: Singing Only Positive - And Often Unsubstantiated - EHR Praise As "Advised" At The University Of Arizona Health Network' at http://hcrenewal.blogspot.com/2013/10/words-that-work-singing-only-positive.html.


... The executive branch—the Office of the National Coordinator for Health IT (ONC) and the Centers for Medicare and Medicaid Services are responsible for the subsidy program— has done little about the clauses, though providers and researchers have been grumbling about them since the 2011 Institute of Medicine report warning that “[t]hese types of contractual restrictions limit transparency, which significantly contributes to the gaps in knowledge of health IT–related patient safety risks.”

...Agency officials say they deplore the clauses but lack the capacity to directly address the problem. “We strongly oppose ‘gag clauses’ and other practices that prevent providers and other health IT customers and users from freely discussing problems and other aspects of their health IT,” an ONC spokesman said.

But, he continued, ONC cannot police them. The clauses take a variety of forms, and the extent to which vendors invoke them varies, making enforcement difficult – particularly for a small agency that doesn’t have investigative or police powers.

A small agency that doesn’t have investigative or police powers?  Really?  Yet - ONC is a promoter of the non-regulatory "Safety Center" concept as a solution to health IT safety risks.  See for instance http://hcrenewal.blogspot.com/2014/04/fda-on-health-it-risk-reckless-or.html.  Their response above to Politico seems disingenuous.

What follows in the Politico article is vendor excuses and soothing reassurances, like this one:

... Epic executives said they encourage open discussion. “With permission, we very frequently allow folks to share information around the software,” said Epic’s vice president for client success, Eric Helsher.

I'll surmise I would not be able to easily get detailed information on the ten thousand EPIC "issues" I highlighted at my Nov. 2013 post "We’ve resolved 6,036 issues and have 3,517 open issues": extolling EPIC EHR Virtues at University of Arizona Health System", http://hcrenewal.blogspot.com/2013/11/weve-resolved-6036-issues-and-have-3517.html, for publication on this blog.

... a lot of problems may go under-reported. That offends [Dr. Bob] Wachter, who says the patient safety world “takes it as religion” that information be shared as widely as possible.

“These are worlds colliding. You can understand why a technology business would put restrictions on screenshots. But we’re not making widgets here, we’re taking care of sick people,” he said.

“At some level, I’d say, ‘How dare they?’”

"At some level?"  What level, exactly?

How about the life-and-death level?

Worlds colliding, indeed; the aforementioned business-IT world and the clinical world.  I would drop the "at some level" phrase, though, and also go back to my 2009 JAMA letter observation that I repeat once again: 

... In their Commentary, Dr Koppel and Mr Kreda made clear the problems associated with applying the customs and traditions of business software contracting and sales (where “hold harmless” and “keep defects secret” clauses are commonplace) to health care information technology (HIT) as if they are the same. I believe that ignoring their differences has likely created an epidemic of violations of hospital governing body responsibilities and Joint Commission standards for health care organization leadership.

Health IT companies are simply not team players in medicine.  Their heavy-handedness and narrow thinking has harmed and killed patients.   How many in total? 

Last year I spoke to a half dozen US House members and a dozen or so aides of House members who could not attend.   I was accompanied by two Plaintiff's lawyers (yes, Plaintiff's lawyers) who told their own tales of EHR-mediated catastrophes whose survivors they had represented.  They were there for that purpose, to inform the US Reps that health IT was killing people.

Extrapolating the ECRI Deep Dive study figures and adding in other known cases, the true level of harms is anything but pretty.

It would be a very useful exercise to measure it explicitly rather than using the Ostrich approach (see for instance my post "FDA on health IT risk:  "We don't know the magnitude of the risk, and what we do know is the tip of the iceberg, but health IT is of 'sufficiently low risk' that we don't need to regulate it" (http://hcrenewal.blogspot.com/2014/04/fda-on-health-it-risk-reckless-or.html). 

However, obtaining the data in a robust matter could result in those reporting the data violating EHR gag and non-disparagement clauses.

We must respect the rights of the computers...

-- SS

Addendum:  the Politico article, unfortunately, while a major piece, did not cite Koppel/Kreda or their pioneering 2009 JAMA article.  I surmise this was an oversight.


Tuesday, January 31, 2012

How the Anechoic Effect Is Institutionalized - A Hospital Policy Against Unsupervised Discussion with the Media

In a single sentence, a short, obscure article in the Worcester (MA) Business Journal on life at a community hospital after a for-profit corporate take-over:
Several Nashoba employees, who didn't want their names used because it's against hospital policy to talk to the media without authorization, said they're happy with the new insurance plan.

We have often discussed the anechoic effect, how cases involving or discussions of the topics we address on Health Care Renewal, the concentration and abuse of power in health care, fail to produce any responses, or echoes.  It was almost an aside, but the sentence above provides evidence of the existence of apparently blanket hospital policies against unsupervised discussion with the media. Here is an example of the institutionalization of the anechoic effect.

This example raises three immediate questions. How prevalent is this? How long has it been going on? What is it meant to hide?

Prevalence

This article is only about a single hospital. However, the context of the article is the take-over of Nashoba Hospital by Steward Health Care. Steward Health Care is a for-profit health care corporation that grew out of the take-over of the formerly not-for-profit Caritas Christi health system by the private equity firm Cerberus Capital Management. Steward Health Care now comprises  eight hospitals, and also owns physician practices (apparently including over 2000 doctors based on a quick search using its "doctor finder" function.) Thus it is likely that the policy at Nashoba Hospital that prevents unsupervised discussion with the media also applies at seven other hospitals, and perhaps to the practices of over 2000 doctors. Thus it is very likely that this hospital gag policy is not unique, and may be widespread. However, recursively, the existence of such gag policies will make it hard to determine their own prevalence.

Note that we have posted a few times about confidentiality clauses mainly within physicians' contracts here.

Duration

This policy is likely relatively new, since the take-over of Caritas Christi by Cerberus occurred in 2010. My guess is that the rise of such policies may parallel the resurgence of for-profit hospitals and hospital systems, and perhaps the new involvement of private equity firms in such organizations.

In my humble experience, gag policies and confidentiality clauses at least within non-profit teaching hospitals were virtually unheard of from the time I began medical school (1974) to when I left my last full-time academic medical position (2005).

Note that we recently found out (because of investigative journalism about presidential candidate Mitt Romney's previous involvement with private equity firm Bain Capital) that such firms are generally rebranded leveraged buy-out firms. They have become known for their secretiveness. Therefore, maybe it should not be surprising that they have imposed such secretiveness on hospitals and health care professionals.

Rationale 

The big question is why should hospital employees not be allowed to talk to the media without management supervision? I can only speculate.

In this case, perhaps such secretiveness is just the habit of the private equity executives who now run the hospital system. Even if this is the reason, they ought to reconsider. Hospitals and health care professionals due have a solemn obligation to keep confidential their patients' medical information. However, otherwise health care organizations and health care professionals ought to be as transparent as possible.

Maintaining such a level of secrecy could lead to some suspicions, for example, that the generic managers of the organization distrust the professionals they hire who actually provide patient care; worse, that the managers fear discussion that might question their actions or abilities; worse, that the managers want to silence whistle-blowers; or even worse, that the managers have something unethical or illegal to hide. That is all speculation, of course.

On the other hand, we have discussed again and again how the anechoic effect has stifled discussion of what is wrong with health care, and hence prevented meaningful health care reform. Gagging hospital employees is an obvious extension and institutionalization of the anechoic effect. It should not be done, because we need honest discussion of what is really wrong with health care so we can come up with some real solutions.

Thursday, August 27, 2009

Cross-occupational invasion of medicine by IT, exemplified

I have written on these pages about a cross-occupational invasion of medicine by IT personnel, wherein the IT personnel seem to forget that they are facilitators of healthcare, not enablers, with a primary purpose of serving the needs of clinicians.

The HISTalk site recently posted an attorney's views on the "hold harmless" and "defects nondisclosure" controversy first reported on by Koppel and Kreda in JAMA, and amplified in my letter to the editor in the same publication. The attorney's views at HISTalk (link below) are quite reasonable regarding such practices.

However, the user comments thread reveals some attitudes exemplifying the "invasion" of which I've written. Both the attorney's post and the responses by a poster under the nom-de-blog "Programmer" to others' concerns can be read at this link.

Read it all. The attitudes of "Programmer" (assuming they are genuine, which is likely) are remarkable.

-- SS

Thursday, August 20, 2009

On HIT Vendor Nondisclosure of Nondisclosure Agreements

Seen at the HIStalk blog in News of 8/19/09:

A couple of readers wisely suggested that I not consider running nondisclosure language from vendor contracts. Reasons: (a) it might identify the client since terms are often customized; (b) it might violate vendor privacy requirements and get a client or me in trouble; (c) clients might not want to share anyway since they may like the idea of being prohibited from sharing patient safety information. A couple of vendors e-mailed to say they don’t include such terms. I’d be very surprised if Cerner and Epic don’t based on my limited history with them.

My response to the HISTalk blog owner, Tim, and other interested parties:


Sent: Thursday, August 20, 2009 7:32 AM
To:
Cc:

To: HISTalk blog

Re: nondisclosure of nondisclosure agreements by HIT vendors

Tim,

Those who've written advising you *not* to post the language of HIT nondisclosure agreements are in fact correct:

As per Koppel and Kreda's March 2009 "Hold Harmless" article in JAMA and my July 21 JAMA letter to the editor commenting on it, nondisclosure and hold harmless agreements stifle HIT innovation, put patients at risk, and cause healthcare executives to violate their Joint Commission and fiduciary responsibilities to protect patients and workers from undue physical or legal jeopardy.

You and other bloggers should *not* be the ones to clandestinely obtain and post such language. The HIT vendors themselves, in an atmosphere of transparency and in deference to patients safety and to hospital governance, should gladly and transparently do so if such language exists in their contracts.

This assumes, of course, that HIT vendors hold patient safety and practitioners' rights as a high priority.

S.S.

I think that says what needs to be said.

-- SS

Tuesday, August 18, 2009

CCHIT Has Company

It appears CCHIT, an offspring of the large HIT trade association HIMSS, won't get its wish for Health IT Certification hegemony. I think the outcome of a multidisciplinary HIT policy workgroup's deliberations on this issue reasonable:

Aug. 17, 2009

iHealthBeat.org

Policy Committee OKs Plan To Establish Multiple EHR Certifiers

On Friday, the [HHS] Health IT Policy Committee adopted recommendations that called for multiple entities to certify electronic health record systems, Health Data Management reports.

The committee's certification and adoption work group issued the recommendations (Goedert [1], Health Data Management , 8/14).

To receive official certification, EHR systems must meet a minimum set of criteria and achieve the "meaningful use" objectives of the federal economic stimulus package. Under the stimulus law, health care providers who demonstrate meaningful use of EHRs will receive Medicare and Medicaid incentive payments (O'Harrow, Washington Post , 8/15).

Recommendations

The work group recommended that:

* Certification criteria allow for open-source software;
* Certification processes should let health care organizations qualify for EHR subsidies under Stark Law exceptions that allow organizations to subsidize the cost of EHRs for physicians;
* Certification should last for four years;
* Multiple groups perform HHS certification under a single set of criteria;
* The National Institute for Standards and Technology should participate in accreditation and certification decisions;
* The Office of the National Coordinator for Health IT should define certification criteria;
* ONC should create an accreditation process for certification groups;
* Officials develop alternative certification processes for self-developed software; and
* Vendors are required to receive certification from only one group ( Health Data Management , 8/14).

The work group said it envisions the establishment of 10 to 12 different EHR certification groups, in addition to the Certification Commission for Health IT (Manos, Healthcare IT News , 8/14).

The recommendations now go to HHS for consideration ( Health Data Management, 8/14).

The workgroup said CCHIT is too closely aligned with the health IT industry, noted that the industry trade group HIMSS helped found CCHIT, and noted that CCHIT's members includes several people with ties to HIMSS and health IT companies. They were clearly uncomfortable with the potential conflicts of interest, especially if CCHIT gained sole responsibility for HIT "certification." [A term I put in quotes since it really is "features qualification" at this point, not certification such as a physician receives after passing Specialty Boards - ed.]

Having been on the receiving end of CCHIT bullying myself ("Open letter to Mark Leavitt, Chairman, Certification Commission for Healthcare Information Technology on Penalties For Use of Non-Certified HIT"), it's clear most Americans don't like bullies, especially bullying from powerful lobbying organizations such as HIMSS and its progeny. (It's also become clear they don't like 1000+ page healthcare reform plans shoved, unread, down their throats by political bullies.)

By the way, since the July 21, 2009 publication of my JAMA letter "Health Care Information Technology, Hospital Responsibilities, and Joint Commission Standards" and Koppel and Kreda's reply, pointing out the terrible situation that HIT "defects nondisclosure" and "hold harmless" clauses create for hospital executives, physicians and patients, I have heard from the Joint Commission, but not from HIMSS.

Perhaps HIMSS leadership believes I have nothing worthy to add to the discussion. (Perhaps another 'Open Letter' is called for.)

-- SS

Monday, August 10, 2009

Shareholders Take Notice That Patients Used As Unconsented Guinea Pigs, Physicians as Bank by Health IT Vendors

At my Jan. 2009 post "Waste Feared in Digitizing Patient Records: Wall Street Journal" and others I have written about the illegitimacy of the abuse of patient rights, as well as abuse of clinician trust committed by health IT vendors using patient care settings as an unconsented software development laboratory and beta testing site. I wrote:

The IT industry uses hospitals, doctor offices and patients as alpha and beta test sites and subjects, unregulated by the FDA or other agency. When HIT fails, there is no central agency to report the failures to, only the vendor. Fixes go into a "queue" for remediation, with priority level decided by the vendor.

Clinicians are also used by HIT vendors as a form of bank and insurance company. HIT vendors depend on (free!) physician and nurse ingenuity in finding workarounds to the ill-conceived design and user experience (link to my eight part series on this issue) that their products usually present so that their products can even be salable. This, of course, taxes and tires clinicians at the expense of patients and hampers and complicates EHR diffusion. Clinicians become, in effect, unpaid development consultants to HIT companies (or, perhaps more accurately, since EHR's do become essential to medical practice, indentured servants to the HIT vendors).

Also, under the unethical, Joint Commission-violating and executive fiduciary responsibility-violating "Hold Harmless" and "Defects Nondisclosure" HIT contracting clauses, clinicians pay the price for bad patient outcomes, even if the causative factor was HIT errors. (See Health IT Hold Harmless and Defects Gag Clauses: Have Hospital Executives Violated Their Fiduciary Responsibilities By Signing Such Contracts?, and my July 22, 2009 JAMA letter to the editor on this issue.) Thus, clinicians become an insurance company, bank and risk safety net (a term that might not be inappropriate is "suckers") for the HIT vendors. This is not an optimal way to treat one's ultimate customers.

HIT is a mess, but that doesn't stop HIT vendors from simply lying about their financial status and future projected business to the investor community.

Now, HIT company shareholders are taking note of these industry (mal)practices. These (mal)practices are hitting shareholders where it really hurts - in the pocketbook. My comments in [red italics]:

Allscripts shareholders file class action suit
Healthcare IT News
August 05, 2009 | Bernie Monegain, Editor

CHICAGO – Allscripts shareholders have filed a lawsuit alleging the company broke federal securities laws when it went live with the newest version of its EHR clinical software, Touchworks [i.e., a "version" that had not been thoroughly tested and validated outside hospital walls, a practice HIT vendors get away with due to the near spinelessness of regulators such as the Joint Commission, FDA, and others - ed.] .

Allscripts officers say the suit is without merit.

[As I pointed out at "Do Healthcare Organizations Truly Want Electronic Health Records To Succeed?" regarding the lawsuit my own organization filed against this company and its partner Medicomp Systems (civil complaint PDF here), where incomplete, untested and non-functional software was sold by this company for use by our physicians, I'd say the allegations do deserve further investigation - ed.]

"We are aware of the lawsuit and have reviewed the complaint," Allscripts officials said Wednesday. "While it is our policy not to comment on the substance of pending litigation, we believe the lawsuit is without merit and will vigorously defend the allegations."

The lawsuit, which seeks class action status, has been filed in the United States District Court for the Northern District of Illinois on behalf of those who purchased the common stock of Allscripts-Misys Healthcare Solutions, Inc. (formerly known as Allscripts Healthcare Solutions, Inc.) between May 8, 2007 and Feb. 13, 2008. It names Allscripts-Misys Healthcare Solutions, CEO Glen Tullman and Chief Financial Officer William J. Davis as defendants.

At a user conference in Orlando, Fla., July 30-31, Allscripts CEO Glen Tullman told some of the attendees that Allscripts might have rushed version 11 of Touchworks to market too quickly.

["Might have" rushed it out too quickly? It had, in fact, been delayed several months according to the lawsuit. "Perhaps" the delays needed to be lengthier. In other words, f*** the doctors and patients, we're getting this cr** out the door so as to not further injure our profits with further delays - ed.]


He said the company was caught off guard by providers who found new uses for the product.

["New uses?" (We all know that when companies sell broken HIT, it's always the doctors' fault) ... Likely translation: clinicians tried to practice medicine the way they saw best, not the way the Allscripts software designers saw best or "approved of." (Arrogance, anyone?) The clinician users tried to use the software in a real-world setting while applying the improvisations needed for proper patient care in a poorly bounded, uncertain environment (per Nemeth and Cook) and found the software's support of the uncertainties and realities of the clinical environment, and likely the software's stability itself, poor - ed.]

Tullman and Faisal Mushtaq, the company's senior vice president of product development, said Allscripts has invested roughly $14 million to improve stability and performance [after throwing the doctor and patient test subjects to the wolves after a "might have rushed it out" premature rollout - ed.], and they expect the next version, to be rolled out soon, to work more smoothly.

[I really despise the "version 1.1 will be much better" in healthcare settings, as it goes back to the issue of sick patients as unconsenting subjects in a software testing lab, and physicians as a bank and insurance company for the vendors when things go wrong -ed.]

The complaint alleges that defendants failed to disclose the following adverse facts:

* Allscripts lacked the necessary resources [i.e., smart, a.k.a expensive, people who actually know what they're doing thanks to the appropriate informatics education and expertise. Were the ones they did have tied up in patchwork remediation and crisis management? - ed.] to install V-11 software at customer sites; Allscripts had no historical basis to estimate the completion of V-11 or the impact V-11 sales might have on the company's 2007 revenues and earnings [if they made stuff up, that would not be too uncommon in today's financial environment. Also, the "lack of necessary resources", not unique to Allscripts, portends quite poorly for the planned, manic rush to national EHR by the cavalierly short deadline of 2014 - ed.]

* The complexity of V-11 had materially and adversely lengthened the sales cycle and revenue recognition cycle for the company's V-11 sales contracts [Another instantiation of my belief that business IT sales practices are inappropriate for clinical IT, where there are unconsenting "customers" with special rights - patients. One also wonders: did clinicians balk at a Rube Goldberg contraption but hospital executives purchase it anyway? - ed.];

* Allscripts was currently experiencing adverse and continuing delays in the installation of V-11 software systems [which were perhaps not revealed by clients, thanks to secrecy clauses regarding defects and problems as noted by Penn's Koppel and Kreda in JAMA? - ed];

* Based on the foregoing, defendants had no reasonable basis for their statements concerning Allscripts' current and future financial performance and projections.

The law firm of Izard Nobel LLP, based in West Hartford, Conn. announced the class action lawsuit on Wednesday.

Click here to read the complaint: http://www.izardnobel.com/allscriptsmisyshealthcare/ .

The PDF of this class action complaint is here.

So, it seems entirely possible the defects nondisclosure clauses promulgated by these vendors, and accepted by meek hospital executives and CIO's, may have supported and/or led to a situation of shareholder fraud.

It would be ironic indeed if these cavalier HIT practices end, and the HIT vendors began to adhere to principles of responsibility and resilience engineering, not due to regulatory pressures but due to shareholder lawsuits.

Finally, Allscripts CEO Tullman was a campaign adviser to the President on healthcare. It's perhaps due to advisers like this that national plans for healthcare reform are sinking like the Titanic. As per my Feb. 18, 2009 Wall Street Journal letter:

... it is the government that has been deceived [rather than the public] by the HIT industry and its pundits. Stated directly, the administration is deluded about the true difficulty of making large-scale health IT work. The beneficiaries will largely be the IT industry and IT management consultants ... The government has bought the IT magic bullet exuberance hook, line and sinker.

-- SS

addendum:

Perhaps I should self-turn in this post as "fishy" to the healthcare reform snitch line at "flag@whitehouse.gov"?

Monday, August 03, 2009

Making Hospitals Safer by Making Healthcare IT Safer

At my July 24, 2009 HC Renewal post "Inquiry to Joint Commission on points raised in my July 22, 2009 JAMA letter on HIT", I reproduced a letter I sent to the Joint Commission seeking their opinions on the issue of Health IT "hold harmless" and "defects nondisclosure" contractual terms. (See "Health Care Information Technology Vendors' Hold Harmless Clause - Implications for Patients and Clinicians", JAMA 2009;301(12):1276-1278 and my HIT difficulties website essay here.)

Those contractual terms cause hospital executives to violate Joint Commission safety standards and their own fiduciary responsibilities to people both providing and seeking care in hospitals. My inquiry was acknowledged, and I await a reply.

In Making Hospitals Safer for Patients, New York Times, Aug. 2, 2009 , Mark R. Chassin, president of The Joint Commission, wrote:

To the Editor:

Jim Hall makes an important point about the costs and preventability of harm caused by medical errors, but his suggestion for a National Medical Safety Board is not the answer. It is not sufficient to investigate health care “crashes” one at a time and hope to transform the health care system into one that performs more reliably.

Too often, the lessons learned are not easily transferable to other hospitals or even to other problems within the same organization.

The key to transforming our health care system into a safer one is to use proven quality improvement methods — already in use in high-risk fields like aviation and nuclear power — as part of everyday work ...


In a followup email to the Joint Commission, I pointed out to Dr. Chassin that this is the same key to improving the quality and safety of EHR, CPOE and other information technology-based medical devices.

I also pointed out that "Hold harmless" and "Defects nondisclosure" -- a.k.a. "gag clause" -- contractual methods (unless I'm mistaken, in which case we're all in jeopardy) are not used in building and deploying safety-critical devices found in the aviation and nuclear energy industries.

-- SS

Friday, July 24, 2009

Inquiry to Joint Commission on points I raised in my July 22, 2009 JAMA letter on HIT

As I posted here, my letter "Health Care Information Technology, Hospital Responsibilities, and Joint Commission Standards" was published in JAMA on July 22, 2009. A preview of the letter can be seen here, or a full version here if you subscribe to JAMA.

This JAMA letter covered some of the same points I addressed extensively at my Drexel HIT website essay "Hold Harmless and Keep Defects Secret Clauses", including the major point that hospital executives signing HIT "Hold Harmless" and "Defects Nondisclosure" contracts are in violation of Joint Commission standards for conduct related to safety, and in violation of their fiduciary responsibilities towards patient and employee safety and freedom from undue liability.

I've sent the following inquiry to Paul M. Schyve, M.D., Senior Vice President, The Joint Commission:

July 24, 2009

Paul M. Schyve, M.D.
Senior Vice President
The Joint Commission
schyve@jointcommission.org

Cc: MChassin@jointcommission.org, otrippi@jointcommission.org

Dear Dr. Schyve,

In testimony to the House Committee on Veterans' Affairs on July 22, 2009 at this link , you state:

... The Joint Commission has established standards that require the hospital to:

  • Create a culture in which adverse events are reported and evaluated for underlying ("root") causes, and preventative actions are taken.
  • Identify high-risk processes and prospectively determine their possible modes of failure, the effects of those failures, and the actions that will prevent the failures or mitigate their effects.
  • Establish a culture of safety throughout the hospital. This accreditation standard became effective January 1, 2009, although its purpose and expectations were publicized for over a year in advance.

In my JAMA letter to the editor of July 22, 2009 entitled " Health Care Information Technology, Hospital Responsibilities, and Joint Commission Standards" ( link ), I point out that the Hold Harmless and Defects Nondisclosure clauses signed by hospital executives in contracting for healthcare information technology (such as CPOE and EHR systems) are in violation of Joint Commission safety standards, as well as hospital executive fiduciary responsibilities to patients and clinicians. These clinical IT systems can and do cause medical errors and patient harm.

My letter was in response to Koppel and Kreda's March 25, 2009 article " Health Care Information Technology Vendors' "Hold Harmless" Clause: Implications for Patients and Clinicians ", JAMA. 2009;301(12):1276-1278.

I am interested in the Joint Commission's response to the issues I raise.

I await a response.

-- SS

Wednesday, July 22, 2009

JAMA letter: "Health Care Information Technology, Hospital Responsibilities, and Joint Commission Standards"

My letter "Health Care Information Technology, Hospital Responsibilities, and Joint Commission Standards" was published in JAMA yesterday. A preview of the letter can be seen here, or a full version here if you subscribe to JAMA.

The letter was in response to Koppel and Kreda's groundbreaking March 2009 JAMA article "Health Care Information Technology Vendors' Hold Harmless Clause: Implications for Patients and Clinicians."

The JAMA letter covered some of the same points I addressed extensively at my Drexel HIT website essay "Hold Harmless and Keep Defects Secret Clauses", including the major point that hospital executives signing such contracts are in violation of Joint Commission standards for conduct related to safety, and in violation of their fiduciary responsibilities towards patient and employee safety and freedom from undue liability. In the Drexel website essay I also noted that:

... these stipulations [hold harmless and gag clauses in contracts] further instantiate my observation that health IT lacks the rigor of medical science itself, its major Achilles heel.

Koppel and Kreda note in their JAMA reply to my JAMA letter that:

Dr Silverstein's letter adds context to our Commentary on HIT vendors' self-protective "hold harmless" clauses while introducing an important discussion about hospitals' and vendors' possible violations of Joint Commission standards. We agree with Silverstein about the misapplication of the standard business software contracting model.

Of interest, the American Medical Informatics Association (AMIA) had authored a reply to Koppel and Kreda quite different than mine, which for a time appeared on their national website (www.jamia.org) but was later withdrawn apparently due to concerns that such a letter might be viewed as an official organizational position. It was entitled "Response to Commentary in JAMA -- Ross Koppel, David Kreda" and can be read in its entirety here.

The AMIA response piece concluded:

"While we support increased transparency around error disclosure, the belief that the best approach to increase the safety and effectiveness of EHR systems is by legal regulation of system vendors is misplaced. Such an approach would stifle innovation and not achieve the desired goals. At a minimum equal attention needs to be given to the role that provider organizations bring to configuration, management and oversight of the software and related processes."

In fact, Koppel and Kreda addressed the provider side issues extensively in their article.

Of interest, JAMA did not publish the AMIA response but instead published mine. Perhaps it's because JAMA felt I had something important to say, as opposed to simply making excuses for HIT vendors and valuing prevention of "stifling of innovation" over hospital leadership's safety and fiduciary obligations to patients and staff.

"The belief that the best approach to improving HIT safety is via regulation is misplaced?" (Misplaced how, exactly?) Tell that to the airline or public transit or pharma or the medical device industries. Or to the public whose care is increasingly dependent upon these HIT systems.

It is my firm opinion that "innovation" done recklessly, in secrecy, without accountability, and via exploitation is not innovation at all.

-- SS

July 23 addendum:

Dr. Koppel has forwarded to me a letter he and Mr. Kreda submitted to AMIA in response to AMIA's aforementioned critique of his March 2009 JAMA "Hold Harmless Clause" article. Koppel and Kreda's letter, "On the AMIA Response to Commentary in JAMA by Ross Koppel and David Kreda" can be read here (MS Word .doc format).

Highlights:

... Where the AMIA authors disagree with us is the emphasis placed on errors produced in the coupling. [The coupling of healthcare organization and software, i.e., alterations and customizations beyond the control of the software vendor - ed.] We say a vast number or errors are generated in the marriage. But they say we have essentially ignored how many errors are created by doctors and hospitals seeking to consummate their relationship with HIT systems in situ ...

... A brief recap of our JAMA commentary seems in order. We wrote about: (1) the HIT vendor “non-disclosure” clauses that prevent clinicians from sharing information about errors generated from faulty software; (2) the clauses that remove all vendor responsibility for errors in their systems – and place all responsibility on clinicians and hospitals (the “hold harmless/learned intermediary” clauses); (3) the need to protect vendors from responsibilities for errors introduced when hospitals implement HIT or when untrained or incompetent clinicians use the HIT; and (4) the need for more balanced contracts that are fair to clinicians and hospitals ...

... Given that we addressed the non-software issues we are said to have ignored, we are not sure why our JAMA commentary earned the response it received on official AMIA letterhead. We hope, therefore that this letter can further a longer conversation about the many ways to make clinical IT software and its implementation better. Nonetheless, we stand by our statement that the imbalance in incentives we described in our JAMA Commentary is a structural obstacle that on balance hurts improving the clinical part of clinical IT.

Read the whole thing at the link above. (I placed Koppel and Kreda's response to AMIA on my faculty server. The response, to the best of my knowledge, was not published by AMIA itself.)

-- SS

Tuesday, May 05, 2009

EHR's and Scarcity of Public Reviews of the User Experience

I recently downloaded the public beta (incomplete trial version) of Apple's new web browser Safari 4.

I like its user experience and features, presenting a main page "posterboard" of most visited or user-selected sites, a searchable, flip-panel history of visited pages (using the Macintosh OS X Spotlight and Cover Flow paradigms), top located tabs, and other useful features. (Note: I use both Macs and PC's, and hold no financial stakes in Apple whatsoever.)

What struck me was the vociferous online discussions and debates about every facet of the new browser version, down to the level of minutiae. The following review particularly struck me for its level of detail - Observations, Complaints, Quibbles, and Suggestions Regarding the Safari 4 Public Beta Released One Week Ago, Roughly in Order of Importance by John Gruber. It includes minutiae such as this:

... THE TABS

Safari’s new tab layout, placing the tabs directly in the window title bar, is a radical change. There’s no use addressing the specific details — good and bad — of this new arrangement, without first trying to figure out why Apple did this. Again, the designers are behind Apple’s wall of silence, so we’re left to speculate.

Rule out the notion that Safari’s designers undertook this change lightly. This is a major change to an important feature that many users feel strongly about. My guess is that this is an attempt to bring tabbed browsing to the masses. The biggest and most important change is that the interface for the tabs is now far more prominent. In fact, previously, the entire interface for tabbed browsing was not visible in Safari by default — in a window with just one tab, Safari’s default settings were such that the tab bar was not shown.

In Safari 4, there’s a prominent and unique “+” button that is always visible in the top right corner of every window, where the standard tic-tac button for toggling the display of the toolbar usually resides.1 Because the interface to create new tabs is now obvious, I can only assume that the point of this redesign is to encourage more people to use, or at least try, tabbed browsing.

But the problems with this new tab layout are significant.

Conceptually, the basic idea is sound. Browser tabs are, effectively, a collection of separate browser windows grouped together in a single parent window. Safari’s new tab layout makes this a tab is like a sub-window metaphor more explicit. The anchor, the conceptual root, of a standard Mac OS window is the title bar, and in Safari 4, the tabs aren’t just in the title bar, they are the title bar ...

Etcetera and so forth, on and on, as in other reviews easily found online.

In Electronic Health Records and other clinical IT, by way of contrast, reviews at this level of detail are ... nearly nonexistent (I use the term "nearly" because I authored such a review, in general terms, starting here). One reason EHR and other clinical IT user experience and performance debates are so rare is because customers are contractually forbidden to engage in them publicly. Koppel's and Kreda's JAMA paper makes that clear:

Health Care Information Technology Vendors' "Hold Harmless" Clause - Implications for Patients and Clinicians, Ross Koppel and David Kreda, Journal of the American Medical Association, 2009; 301(12):1276-1278

Vendors claim they are protecting their "intellectual property." I'm not exactly sure what IP they are holding as closely as the crown jewels.

Is it their:

  • Earth shaking, 22nd century user interfaces?
  • Secretive and ingenious widgets that revolutionize user selection from choice lists?
  • Hyper-efficient, never before seen data structures and algorithms?
  • Artificial intelligence routines that would make Captain Picard and his android sidekick Mr. Data envious?

In other words, what, exactly, is being protected by shielding commercial EHR's from external scrutiny and debate?


Is this the Secret Sauce the commercial EHR vendors seek to conceal?

The loss engendered by such policies is the reduced feedback from, and reduced interaction among endusers. This interaction occurs commonly on the Internet in 2009 on a great number of topics, but EHR user experiences are not one of them.

Companies like Apple and Microsoft, strongly user centric, encourage such debates through release of their beta's, both of enduser tools and of operating systems e.g., Windows 7 Beta. I should note that with these pieces of software, lives are not at stake, unlike with electronic health records systems.

The Veterans Health Administration makes a full working copy of VistA Computerized Patient Record System (CPRS) available as a free public download to anyone in the world here. I use it in my teaching (and am forced to do so, as commercial EHR demos are as available as, say, demos of the National Security Agency's spy and decryption software).

What, exactly, is the commercial EHR vendors' real excuse for the levels of product secrecy they maintain?

Could it be embarrassment and fear of exposure of defects, ill conceived design features and a mission hostile user experience?

-- SS

Friday, April 17, 2009

Complacency and Healthcare IT: Who is Taken More Seriously on Risk, A CMIO or A Public Transit Authority Doctor?

In this post I make a very shameful comparison. Shameful to the healthcare industry, that is, and coming from an unusual perspective due to my diverse professional background.

I received quite interesting comments from a number of informatics colleagues regarding the linked patient's account of Health IT mayhem at "A Most Interesting Patient Account of Misery by EHR". The comments suggested that patient's account was not unusual.

Example:

Without being specific I can say from first hand information that this is not an isolated incident... the horrific experience is unfortunately in my direct experience typical.

and this:


... As you know, I’ve been in the HIT business, advocating for full integration of computing into clinical care, for more than three decades. The upshot, though, is that this country’s hospitals are not ready for wholesale automation of even the most rudimentary kind (such as using barcodes in clinical settings), much less a real EMR. I’d give it another 10-15 years ... before even considering advocacy for much in the way of EMRs. Not that there are EMRs we should advocate for now, in any case.

and this:

This hits home, I hope this gentleman keeps telling his story. He is one of the lucky ones that "lived to tell". These are the stories no one believes until it happens to them or a loved one ... He would be saving lives if he talks. I know the retaliation is hard to swallow. I lost my job, but walked out with dignity because I know that I did the right thing. This was such a traumatic event for him and he was one of the lucky ones who were coherent enough to know that something was wrong.

My colleagues are afraid of giving specifics largely due to fear of reprisal from their healthcare and health IT employers. Health IT chaos, though, is clearly more widespread than commonly reported.

Yet in the U.S. in 2009 we find ourselves poised to rapidly spend $20 billion, more than the annual budget of NASA (at $18.7 billion), on these unproven technologies.

Now, a little history from my heterogeneous past:

After a 1990 subway accident in Philadelphia that killed several people and injured hundreds, at a time when I was Medical Programs Manager [of preventive programs] and Medical Review Officer for the regional transit authority SEPTA (pre-informatics), I became sensitized to the potential outcomes of complacency. As I wrote here, some of the the factors
contributing to the accident involved complacency and the ignoring of medical advice by non medical personnel.

Yet, the National Transportation Safety Board (NTSB) came in and investigated thoroughly. Improvements were made.

Has something similar ever occurred after an HIT failure?

It always puzzled me why my concerns about health IT problems, dating from my time as a
hospital-based Chief Medical Informatics Officer (CMIO) in the 1990's, seemed to raise little concern among the IT and hospital administration and even among some of the hospital physicians themselves. It still puzzles me why my colleagues in active CMIO roles report the same problems in 2009.

It concerns me greatly that HIT is entirely unregulated as its devices become far more complex, and more intrusive in the "biochemical pathways-like" organizational complexities of healthcare. It concerns me that HIT vendors have the best environment of any healthcare vendor: freedom from liability and accountability, and freedom from defect disclosure. It concerns me that hospital executives have agreed to such terms, I believe violating both their Joint Commission safety standards obligations and their fiduciary responsibilities.

As a hospital CMIO observing profound HIT difficulties, it was as if I was supposed to simply acquiesce to the chaos in a medical ICU, in a cardiac catheterization lab, medical clinics, etc. caused by HIT design and implementation deficiencies. It was as if the reaction to my detailed accounts of issues putting patients at risk was that I was simply not a 'team player.' The complacency was palpable. The behaviors consistent with a belief that the IT personnel were wizards, exempt from the scrutiny afforded to mere mortals, was equally palpable.

It was jarring and bizarre. In fact, being a CMIO was more jarring than my earlier physician role in the Philadelphia transit authority, where I sometimes had to deal with very troubled vehicle operators with substance abuse problems and aggressive, sometimes abusive and very scary Philly union officials.

As an example of what I dealt with in that environment, I scanned a 1988 SEPTA transport workers union newsletter whose cover shows a drawing of an injured employee on crutches and a Donald Duck figure with a stethoscope representing the Medical Department physicians, holding a note telling the ostensibly crippled employee to return to work.
The newsletter cover is at this link (jpg) and below.


(click to enlarge)


Note the text about the medical department and the duck cartoon on the right depicting the doctors ("quack, quack").

In retrospect, I felt far less uncomfortable as a physician in the mass transit environment than I did as a CMIO at a major hospital. I did not expect much in the way of rigor and science from a transit agency and transit union leaders.

Remarkably, though, I also never feared retaliation or being fired for pointing out potential safety problems. Doing so, in fact, was taken quite seriously, by the Medical Director, the GM's office, Industrial Relations, the system Safety Officer, even the unions when presented the cold, hard facts. Never as Medical Programs Manager and Medical Review Officer was I ignored, as I was as a hospital CMIO.

I felt less comfortable as a hospital CMIO than in the mass transit authority, as I expected a lot more from hospital leadership ... and still do.

On the other hand, I respected the union leaders' directness and unabashed defense of their membership.

Physicians can learn something from them in regards to defense of patient care, and defense of their own profession.

My writing style has, in part, certainly been informed by past interactions with TWU, UTU, BLET, BRS and other transit union leaders and members.

-- SS

Addendum Apr. 18:

Although the causality of this terrible accident just one day after my post above is yet to be determined, I am often reminded of the public safety aspects of my prior line of work in ensuring fitness for duty of public servants in safety sensitive roles:

Sat, Apr. 18, 2009
Man struck, killed by SEPTA bus

By DAVID GAMBACORTA
Philadelphia Daily News

Milton Boneta cheated death seven months ago when he was struck by a SEPTA bus in his wheelchair at 8th Street and Girard Avenue. Fate revisited him in cruel fashion at the same intersection yesterday. This time, he was not as lucky.

Police said the Route 47 bus crushed Boneta, 61, as he crossed 8th Street in his motorized wheelchair at about 4:15 p.m. Based on the reactions of witnesses and the grisly scene, there was no chance he could have survived this accident ...

"The operator told me to check for a pulse or to see if he was breathing," [a witness] said, adding that his body clearly was too badly mangled for any lifesaving efforts.

Remembering what I used to do in public transit vs. the inability to perform a similar function as a CMIO in hospitals brings into focus the absurdity of allowing IT personnel to have a veto on issues that concern patient care and safety. (As the head of the Division of Biostatistics and Bioinformatics of a major medical center who had his staff review my HIT site recently wrote me, he "could not imagine any reasonable individual" - i.e., hospital executive - allowing that situation to occur, and found it "downright scary.")

Hospitals can cover up and bury their mistakes, especially when related to the relatively esoteric issues of HIT dysfunction, so perhaps their attitudes can be more cavalier than in the transit industry.

-- SS

Monday, March 30, 2009

Will The True Incidence of Healthcare IT-Caused Patient Adverse Outcomes Please Stand Up?

The article Health Care Information Technology Vendors' "Hold Harmless" Clause - Implications for Patients and Clinicians, Ross Koppel and David Kreda, Journal of the American Medical Association, 2009; 301(12):1276-1278 (JAMA) has caused much discussion in healthcare IT circles.

I have become aware of discussions centered on issues such as:

  • The factors besides vendor design flaws and defects that contribute to the unsafe and ineffective use of health information technology,
  • The degree of effect caused by end user organization customizations,
  • whether a focus on legal or regulatory action is misplaced
  • Whether such regulation could "stifle innovation", and
  • Other interesting and stimulating related issues.
These discussions miss the forest for the trees, unfortunately.

They are all speculation.

I could just as easily - as a thought experiment - argue and rationally support a point of view that vendor defects, shortcomings, ill conceived user interfaces etc. are the greatest cause of HIT problems, that a sole focus on regulatory action is the best path, and that regulation would not stifle innovation but promote it by forcing complacent, lazy companies protected by the current status quo to become competitive, to hire the very best and brightest and most experienced who they now forgo as "too disruptive, too expensive, lack the latest programming skills", etc.

None of this speculation really matters in the big scheme of things.

What does matter is the fact that we now have before us a "grand confounder" - the anechoic effect caused by vendor contracting - that throws into doubt existing assumptions about HIT-caused errors.

Who among us can now say what the number of physician observed defects really is, what the rate of HIT error really is?

I've had several of my colleagues already tell me since the Koppel article that they know of HIT caused errors and even patient adverse consequences, but they are afraid to speak out. What is the morbidity and mortality change associated with use of HIT vs. paper?

Who really knows?

There is a significant, perhaps high likelihood that the current state of HIT contracting, and the muting effect it creates, combined with fear of retaliation by potential objective HIT reporters (a.k.a. whistleblowers) makes any such estimation highly questionable at best.

Speculation is irrelevant. What we need is a return to the rigor of medicine - to science - in HIT itself.

That can only happen in an environment where users are free(er) to share their observations and findings about HIT problems.

Such one-sided, safety adverse HIT contractual clauses must end.

-- SS

Thursday, March 26, 2009

Health IT "Hold Harmless" and Defects Gag Clauses: Have Hospital Executives Violated Their Fiduciary Responsibilities By Signing Such Contracts?

July 2009 - Note: also see my letter to the editor in JAMA on this same topic, "Health Care Information Technology, Hospital Responsibilities, and Joint Commission Standards", published July 22, 2009, available online at this link.

Regarding healthcare IT "Hold Harmless" and Defects Gag Clauses as revealed by the JAMA article
Health Care Information Technology Vendors' "Hold Harmless" Clause - Implications for Patients and Clinicians by Koppel and Kreda:

Have hospital executives violated their fiduciary responsibilities by signing such contracts, and violated Joint Commission standards of hospital leadership conduct as well?

Fiduciary
(fidOO'shēe"rē), in law, a person who is obliged to discharge faithfully a responsibility of trust toward another. Among the common fiduciary relationships are guardian to ward, parent to child, lawyer to client, corporate director to corporation, trustee to trust, and business partner to business partner. In discharging a trust, the fiduciary must be absolutely open and fair. Certain business methods that would be acceptable between independent parties dealing with one another “at arm's length” may expose a fiduciary to liability for having abused a position of trust.

Hospital management conduct is not bound by traditional business law only, just as physicians and other clinicians hold additional obligations. In both cases, obligations go beyond that of, say, a manager or worker at a McDonald's or a Wal-Mart. In healthcare there are "special" third parties involved with critical rights and responsibilities, namely, patients and clinicians.

At Health Care Information Technology Vendors' "Hold Harmless" Clause I expressed great concern about the remarkable revelations in Koppel and Kreda's expose of arguably unethical and clearly inexcusable contracting practices by healthcare IT producers and vendors.

The vendors have declared themselves off limits from liability even if patients die as a result of software defects and malfunctions, pushing that liability onto clinicians. Vendors have simultaneously declared themselves the Ministry of Information, Soviet style, on such defects.

I also expressed my concern that the contractual suppression of information dissemination on health IT problems and defects may be one reason websites on health IT difficulties, such as the site I started in 1998 (in fact cited by Koppel and Kreda) remain uncommon on the Web. This is despite my documentation of continued, ongoing, world wide interest in this topic (see my 2006 AMIA abstract on this issue here, PDF, and poster here, PPT).

It is not just the vendors who may be acting against the best interests of medical science and patient safety, however.

It also seems to me that hospital executives, boards and counsel have fiduciary responsibilities, as well as obligations under principles of due diligence, Joint Commission and other regulatory guidelines, etc. to protect not just patients from defective technologies but also to protect their staffs from unfair risks and legal liabilities. I note that these health IT contracts have apparently been signed willingly by hospital executives, against the best interests of patients and medical staffs. Nobody is holding a gun to their heads, and nobody is forbidding negotiation of terms.

As a former CMIO/Director of Informatics I would never have signed such a contract. Period. (Of course, CMIO's and Directors of Informatics don't generally sign or even see health IT contracts, as they are Chiefs and Directors of Nothing.)

Have hospital executives, boards of directors and counsel been violating their responsibilities and obligations every time they've signed a healthcare IT "hold vendors harmless, it's all on your docs" and "shhhh! keep the defects secret" contract? Have they abused their positions of trust?

NIH research leaders and grant reviewers, as an example, consider seriously any problems with research that might place not just research subjects but also investigators at risk, medically, legally and otherwise. I perform this function on NIH study section panels.

Let's look at the Joint Commission Hospital Accreditation Program Leadership Chapter, and its standards for hospital leadership (link, PDF):

Leadership
LD.01.03.01

Standard LD.01.03.01
The governing body is ultimately accountable for the safety and quality of care, treatment, and services.

Rationale for LD.01.03.01
The governing body’s ultimate responsibility for safety and quality derives from their legal responsibility and operational authority for [organization] performance. In this context, the governing body provides for internal structures and resources, including staff, that support safety and quality.

The governing body has a legal responsibility for safety and quality, not just a moral obligation. One of the "internal structures" is healthcare IT that is safe and effective and that does not expose patients or staff to undue risks.

How does signing "hold harmless" and "defects gag order" clauses with an HIT vendor serve such a purpose, exactly?

Hospital executives know, should know, or should have known that such provisions would remove incentives for health IT vendors to produce the best products and to correct deficiencies rapidly, thus increasing risk to patients and clinicians.

Elements of Performance for LD.01.03.01
5. The governing body provides for the resources needed to maintain safe, quality care, treatment, and services.

One of those resources is health IT.

Standard LD.02.01.01
The mission, vision, and goals of the [organization] support the safety and quality of care, treatment, and services.

Rationale for LD.02.01.01
The primary responsibility of leaders is to provide for the safety and quality of care, treatment, and services. The purpose of the [organization]’s mission, vision, and goals, is to define how the [organization] will achieve safety and quality. The leaders are more likely to be aligned with the mission, vision, and goals when they create them together. The common purpose of the [organization] is most likely achieved when it is understood by all who work in or are served by the [organization].

How is a contract with an HIT vendor that calls for hiding defects in health IT and exposing staff to liability for defects in same serving the above purposes?

Standard LD.02.03.01
The governing body, senior managers and leaders of the organized medical staff regularly communicate with each other on issues of safety and quality.

Does that include communication on health IT defects? Can a medical staff member ask to see a database of such defects when the hospital has signed a nondisclosure of defects agreement with an HIT vendor?

Rationale for LD.02.03.01
Leaders, who provide for safety and quality, must communicate with each other on matters affecting the [organization] and those it serves.

I ask the same question as above.


Standard LD.03.01.01
Leaders create and maintain a culture of safety and quality throughout the [organization].

Safety for whom, exactly? Patients, or patients and staff?

How is exposing professional staff to undeserved liability from defective health IT serving the creation of a culture of safety and quality for them? How is suppressing information on health IT defects and problems helping patient safety and care quality?

How is lack of seeking informed consent on health IT use from patients whose care is mediated by health IT devices with known but undisclosable defects creating a culture of quality?

How is hiding such defects creating a culture of quality in the community's other hospitals, that may be considering purchase of the very same health IT?

Standard LD.03.04.01
The [organization] communicates information related to safety and quality to those who need it, including staff, licensed independent practitioners, [patient]s, families, and external interested parties.

Rationale for LD.03.04.01
Effective communication is essential among individuals and groups within the [organization], and between the [organization] and external parties. Poor communication often contributes to adverse events and can compromise safety and quality of care, treatment, and services. Effective communication is timely, accurate, and usable by the audience.

Are physicians and nurses explicitly informed by administration that clinicians are liable for bad outcomes due to software problems? Are they informed of the gag clause? Are patients informed of unremediated health IT defects existing at time of service?

This standard seems a veritable smoking gun regarding breach of fiduciary responsibility and Joint Commission obligations when hospital leadership signs agreements specifically excluding the sharing information about health IT defects and complaints. It is already known that hospitals maintain lists of health IT defects, some in the thousands of items. A number of the defects rise to the level of creating considerable risk to patients, and nobody is in a hurry to remediate them. (See my proposed although somewhat tongue in cheek "HIT Informed Consent" that describes some of these known defect categories here).

Standard LD.04.04.03
New or modified services or processes are well-designed.

... 3. The hospital's design of new or modified services or processes incorporates: Information about potential risks to patients.

4. The hospital's design of new or modified services or processes incorporates: Evidence-based information in the decision-making process. Note: For example, evidence-based information could include practice guidelines, successful practices, information from current literature, and clinical standards.

How does the contractual inability to communicate about health IT defects, which its executives willingly sign, serve this purpose?

Standard LD.04.04.05
The [organization] has an organization-wide, integrated [patient] safety program.

... 12. The hospital disseminates lessons learned from root cause analyses, system or process failures, and the results of proactive risk assessments to all staff who provide services for the specific situation.

Disseminates lessons learned, except when the HIT contract they've signed with a vendor forbids it, that is.

The practices of the health IT industry, and the dealings of the hospital leadership with that industry, may in fact be a scandal of national (or international) proportions.

I urge physicians and concerned others reading this to read the Univ. of PA press release "Why Are Healthcare Information Manufacturers Free of All Liability When Their Products Can Result in Medical Errors?" here, obtain the JAMA article by Koppel and Kreda, and call their congressional and other representatives to have these self-serving industry practices that ignore protection of patients and practitioners from undue jeopardy stopped.

I also believe any clinician under lawsuit related to hospital HIT malfunction, and/or patients harmed, should consider suit against the management that signed the contracts allowing the defective IT's entry into the hospital and mandated clinicians to use the HIT.

I, for one, already have begun discussing these issues with my representatives in Washington, and they've expressed great surprise at these revelations.

-- SS