Showing posts with label sale of known defective software. Show all posts
Showing posts with label sale of known defective software. Show all posts

Monday, June 25, 2012

FDA: Software Failures Responsible for 24% Of All Medical Device Recalls

At "FDA: Software Failures Responsible for 24% Of All Medical Device Recalls" via Kapersky Labs, a software security company, it is observed (emphases mine):

Software failures were behind 24 percent of all the medical device recalls in 2011, according to data from the U.S. Food and Drug Administration, which said it is gearing up its labs to spend more time analyzing the quality and security of software-based medical instruments and equipment.

The FDA's Office of Science and Engineering Laboratories (OSEL) released the data in its 2011 Annual Report on June 15, amid reports of a compromise of a Web site used to distribute software updates for hospital respirators. The absence of solid architecture and "principled engineering practices" in software development affects a wide range of medical devices, with potentially life-threatening consequences, the Agency said. In response, FDA told Threatpost that it is developing tools to disassemble and test medical device software and locate security problems and weak design.

... "Manufacturers are responsible for identifying risks and hazards associated with medical device software (or) firmware, including risks related to security, and are responsible for putting appropriate mitigations in place to address patient safety," the agency said in an e-mail statement.

Health IT medical devices are the exception, of course.  A health IT virtual medical device is always of rock-solid architecture, always uses "principled engineering practices" in software development, and never has life-threatening consequences, of course.

Hence its special regulatory accommodations over non-virtual (tangible) medical devices.

-- SS

Sunday, March 01, 2009

An economist's advice on healthcare information technology

In a Feb. 28, 2009 New York Times article entitled "How to Make Electronic Medical Records a Reality", we get advice from the same profession in part responsible for the worst economic downturn since 1982 and perhaps 1929:

... It is scarcely surprising, then, that only about 17 percent of the nation’s physicians are using computerized patient records [to various extents, 13% of that 17% only having basic functionality - ed.], according to a government-sponsored survey published last year in The New England Journal of Medicine.

"This is really not a technology problem,” observed Erik Brynjolfsson (bio), an economist at the Sloan School of Management at the Massachusetts Institute of Technology. “It’s a matter of incentives and market failure.”

No, Prof. Brynjolffson, it is a matter of technology - as in, the misuse thereof. It's also a matter of logic failure, incompetence, conflict of interest, and vendor exploitation of physician learned helplessness.

Vendors are already getting $70 to $100 million and up for these products from individual medical centers, enough to build entire new hospitals. What more incentive to produce reasonable, safe, effective products do they need?

On the other hand, the incentive you need to get physicians and other clinicians to purchase and use ill conceived, cavalierly designed HIT that saps their time and cognitive focus is not monetary. The necessary incentive is HIT that presents an acceptable user experience and that facilitates real, live clinicians in improving the quality of care.

Only in healthcare could products with hundreds or thousands of known defects (known to individual healthcare organizations in isolation, that is, some being critical defects that can kill patients and others merely raising risk of clinician cognitive overload that promotes error), be sold to other healthcare organizations without disclosure of such defects. Further, contractually the customers are usually restricted from sharing those known defect lists with other organizations.

Only in HC could vendors of defective products also be shielded from liability from their products' defects on "learned intermediary" principles, as if these learned intermediaries cannot be misled or caused to make errors by defective information.

As I mentioned in part 5 of my series on HIT's mission hostile user experience, I have now become aware of organizations with defects/clinician complaint lists for contemporary HIT including CPOE, EHR etc. amounting to well over a hundred pages in one case, and well over a thousand individual items in another, and a number of unquantified but considerable in-betweens. How many defects lists are concealed?

(Perhaps it's time to start calling in the state Attornies General on the basis of sale of known defective and possibly harmful software, without disclosing such defects, in my mind a form of fraud?)

One wonders if Prof. Brynjolffson is aware of issues of HIT mission hostile user experiences due to gross violations of the most basic tenets of user centered design such as I've outlined starting here. How about vendors using hospitals as guinea pigs for apparently poorly tested products as in this Civil Complaint (PDF) against HIT vendor AllScripts?

How about the issues at my site on HIT difficulties?

My final comment:

Economists, please spare the medical profession from your advice. It is not helpful nor wanted.

We are getting tired of cross-occupational invasions by biomedical and healthcare informatics dilettantes. If you've not gone to medical school, not done a residency, and/or (for those many competent nonmedical informatics professionals) not had considerable education and experience in information science, computer science, biomedical informatics, social informatics, and other areas, you're an HIT dilettante. Period. No ifs, no buts, no debate.

(Such people perhaps need to read "Unskilled and Unaware of It: How Difficulties in Recognizing One's Own Incompetence Lead to Inflated Self-Assessments" and stop rendering expert advice in areas in which they lack expertise.)

I leave it to other bloggers here to determine if anyone cited in the NY Times article holds financial interests in HIT-related companies.

-- SS