Monday, March 15, 2010

Third-Party Reviews of Medical Devices Come Under Scrutiny at the FDA - Except Healthcare IT Medical Devices, Which Get Special Accommodation

This WSJ article caught my eye:

Third-Party Reviews of Devices Come Under Scrutiny at the FDA
March 15, 2010
By ALICIA MUNDY and JARED A. FAVOLE

WASHINGTON—When medical-equipment makers like Philips Electronics NV, Siemens AG and General Electric Co. need approval for some new devices, they don't always have to start at the Food and Drug Administration. They can pay companies to do the reviews, which are then routinely approved by FDA officials most of the time.

Now this third-party outsourcing program has come under fire at the FDA, and the agency is weighing whether to end it. Agency officials question the quality of the reviews and whether they have served the program's original purpose: saving U.S. taxpayers money.

The "real value to industry may be that this is perceived as a way to 'sneak things,'" said an FDA official at a December meeting on device approvals, according to minutes reviewed by The Wall Street Journal. Some third-party reviewers advertise speed and a friendlier process.

At a time when the FDA is moving against third party device reviews, HHS and its Office of the National Coordinator for health IT (ONC) are soliciting to create third party EHR "certification" bodies for healthcare information technology (HIT) medical devices such as electronic medical records systems, decision support tools, clinician order entry and alerting, etc. (see RIN 0991-AB59, "Proposed Establishment of Certification Programs for Health Information Technology", PDF available at this link.)

This comes at the same time as FDA admitting this technology harms and kills patients, but the extent is unknown (existing FDA data is likely the "tip of the iceberg" reports Jeffrey Shuren MD JD at the HIT Policy Committee, Adoption/Certification Workgroup, special meeting on health IT safety on February 25, 2010).

See:

"FDA on Health IT Adverse Consequences: 44 Reported Injuries And 6 Deaths, Probably Just 'Tip of Iceberg'" at http://hcrenewal.blogspot.com/2010/02/fda-on-health-it-adverse-consequences.html

and

"On ONC's "Proposed Establishment of Certification Programs for Health Information Technology" at http://hcrenewal.blogspot.com/2010/03/on-oncs-proposed-establishment-of.html

More from the WSJ article:

... The agency's concerns about the third-party reviews come as the FDA is re-evaluating its entire device-approval process. In addition, the agency has recently announced tighter regulation of some machines that deliver radiation in the wake of reports of more than 300 cases of overdoses from CT scanners at four hospitals.

Changes under consideration at the FDA include terminating the third-party program, limiting the kinds of devices that it covers, or giving the outside reviewers more data on devices to improve the quality of their work, according to the minutes and interviews with agency officials. Jeffrey Shuren, the device division director, said the FDA will release proposed changes later this year and cautioned that no decisions have been made.

To qualify for an outsourced review, a new device must be similar to a device already on the market, and it must carry low or moderate risk to the patient.

The December 2009 minutes say "third parties often don't have appropriate expertise." The minutes cite "poor quality of review documents— they often just repeat what is in the submission, and don't provide any analysis of the data."


(The point on lack of expertise is a point I raise in my aforementioned commentary on ONC's "Proposed Establishment of Certification Programs for HIT." I wrote: HHS should not be creating new, potentially (likely?) amateur organizations and bureaucracies overseeing these new virtual medical devices that will have variable (or no) experience in software validation, certification, regulation, postmarketing safety surveillance, etc. Rather, HHS should be leveraging existing governmental expertise in certifying, validating and regulating mission critical IT.)

The industry as always is looking out for - itself, patients coming in second:

Terry Sweeney, vice president of clinical affairs at Philips Healthcare, said the third-partyprogram benefits industry and helps relieve the FDA of a burden. "Every week's delay [i.e., in rigorously assuring medical device safety - ed.] can cost the company a large sum of money," he said.

It's not like the time differential is enormous:

It takes an average of about 72 days for a company to get final clearance for a device when it goes the third-party route, according to the FDA. That includes the time for the agency to sign off on the outside reviewer's conclusion and compares with an average 109 days for similar applications that go directly to the FDA.

So, the vendors seem to be saying, let's compromise the device safety evaluation process via third party reviewers so we can get to market a month sooner.

The FDA is having serious second thoughts about this state of affairs.

Worse, on health IT devices, the HHS itself via ONC is soliciting for the creation of third party reviewers for HIT, while the FDA itself seems marginalized or even unwilling to shoulder the burden of patient protection from faulty HIT.

Odd. Why do computerized HIT medical devices such as EMR's get special government accommodation?

-- SS

For more on HIT challenges see "Contemporary Issues in Medical Informatics: Common Examples of Healthcare Information Technology Difficulties" - http://www.tinyurl.com/healthITfailure

Sunday, March 14, 2010

City Hospital System Board Member Fined for Conflict of Interest Involving Proprietary, Off-Shore Medical School

Sometimes I think I have now seen every type of conflict of interest that could afflict health care, but then some amazing new variation on the theme comes along...

Last year, the New York Times reported on an unusual deal between the New York City Health and Hospitals Corporation and a proprietary (for-profit) Caribbean medical school that attracts US citizens who were not admitted to US medical schools:
New York City’s Health and Hospitals Corporation has signed a 10-year, $100 million contract with a profit-making medical school in the Caribbean to provide clinical training for hundreds of students at the city’s 11 public hospitals.

The unusual deal, proposed by a member of the corporation’s board who has long worked for the Caribbean school, has been met by an outcry from New York medical schools fearing that clerkship slots will grow scarcer and that they might have to increase tuitions to compete.

Critics worry that the hospital corporation, whose mission is to serve the city’s poor, is conferring prestige on a foreign school whose curriculum, they say, is more vocational than research-based and often caters to affluent students who could not get into schools in the United States.

They say that the contract, with St. George’s University School of Medicine on the island of Grenada, has turned a meritocracy into a bounty system in which struggling city hospitals collect more for every St. George’s student they take, and could squeeze out local students.

'This changes the whole dynamic from an academic relationship to a dollar-based relationship,' said Dr. Michael J. Reichgott, associate dean for clinical affairs and graduate medical education at Albert Einstein College of Medicine in the Bronx.

Traditionally, medical schools have sent third- and fourth-year students into city hospitals to work — and learn — alongside doctors without being charged.

Under the contract, which was signed last year but never publicly announced, St. George’s pays the hospitals $400 to $425 per student per week — St. George’s charges students about $1,000 a week in tuition — on top of an annual fee of $50,000 for hospitals that take 24 or more St. George’s students.

The contract also bans the hospitals from providing clerkships to other Caribbean medical schools — a critical provision to St. George’s, which has faced heightened competition in recent years, particularly from Ross University on the island of Dominica, part of DeVry Inc., a publicly traded educational company, since 2003.

Note that the contract was unusual in several ways.  Not only did it permit a for-profit, proprietary medical school which is not accredited in the US pay hospitals to provide clerkships which they traditionally had provided without a fee to not-for-profit, US medical schools, but also it included a clause that apparently prevented other for-profit, proprietary medical schools from competing for these training physicians by also paying fees, and was signed in secret, only becoming public because of the Times' reporting. 

Furthermore, not only was the contract unusual, but the processes that lead to its approval were also unusual:
The board member who first proposed the exclusive contract, Dr. Daniel D. Ricciardi — a 1981 graduate of St. George’s and a rheumatologist affiliated with Long Island College Hospital in Brooklyn — said he had recused himself from deliberations involving St. George’s. Dr. Ricciardi, who has been on the 16-member corporation board since 2000 and on the St. George’s faculty for about 15 years, said he did not benefit financially from the deal. He was promoted to St. George’s dean of clinical studies and put in charge of United States clerkships shortly before the contract was signed.

'I don’t have to go to confession on this one, I really don’t,' he said. 'Everybody’s saying there’s a conflict here, and it comes back to me. They’re disgruntled, jealous. A report was written on the school, and the judgment was made based on merit, not on political push.'
Dr Ricciardi may or may not have felt obligated to discuss this issue during confession, but three days later, the NY Times again reported:
A board member of New York City’s Health and Hospitals Corporation resigned on Thursday, after the agency began an inquiry into his role in securing a 10-year, $100 million contract for a Caribbean medical school where he has long had a paid position.

The board member, Dr. Daniel D. Ricciardi, submitted a brief letter of resignation to the president of the corporation, Alan D. Aviles.

Dr. Ricciardi did not give any reasons for his resignation in his letter, saying only that he had been proud, 'as a first-generation New Yorker,' to support efforts to provide affordable quality health care to city residents. He had been a board member since 2000. But in a brief telephone interview on Thursday, he expressed bitterness, saying: 'You know what? The elite of the 0.1 percent that you represent have won once again. God bless.'
And just to provide the icing on the cake, despite Dr Ricciardi's denial that his job at St George's constituted a conflict of interest, two weeks ago, the NY Times further reported:
A former board member of New York City’s public hospital system has been fined $13,500 for his role in soliciting coveted training spots in city hospitals for students from a Caribbean medical school, the city’s Conflicts of Interest Board said Tuesday.

The former board member, Dr. Daniel D. Ricciardi, agreed to the fine in a settlement in which he admitted that he had held high-ranking paid positions at St. George’s University School of Medicine in Grenada while soliciting clinical clerkships — a critical part of medical education — from personnel in the city hospital system, which he also helped to lead.

Dr. Ricciardi, a rheumatologist and 1981 graduate of St. George’s, acknowledged that from January 2000, when he was appointed to the board of the Health and Hospitals Corporation, to August 2008, when he resigned after The New York Times disclosed the potential conflict, he had served in positions at St. George’s including dean of clinical studies, chairman of medicine and director of medical education.

During the same period, he said, he had contacted personnel at Kings County Hospital Center, Metropolitan Hospital Center, Woodhull Medical and Mental Health Center, Lincoln Medical and Mental Health Center, and Elmhurst Hospital Center to try to get them to increase the number of placements available to St. George’s students, a violation of prohibitions against representing a private interest before his public agency.

'I now acknowledge that my dual capacities created at least the appearance that the actions I took as an H.H.C. board member were done in part to benefit the school,' Dr. Ricciardi said in the settlement, dated Feb. 24.

Ana Marengo, a spokeswoman for the Health and Hospitals Corporation, said Tuesday that the contract was granted through competitive bidding, and that Dr. Ricciardi had recused himself from the board’s deliberations.

But Dr. Ricciardi admitted that he had violated city law prohibiting a public servant from having a position in a company that he knows is doing business with his city agency. Dr. Ricciardi said in the settlement that he had disclosed his affiliation with St. George’s to the hospitals corporation, and that he had not intended to violate any laws.

We constantly hear from its advocates that commercialized health care will lead to wonderful innovation.  At least, it certainly seems to lead to innovation in the creation of new variants of conflicts of interest.  Here, we see a board member of a municipal, not-for-profit hospital system also working for a for-profit off-shore medical school, and apparently using his board position to provide competitive benefits to that medical school, by means of a contract that was meant to be secret.  Each time we think we have begun to understand the extent that conflicts of interest pervade health care, we find new examples suggesting we have underestimated.

As we have now said ad infinitum, an important reason for rising costs, declining access, stagnant quality, and disgruntled professionals are health care leaders who undermine the missions of their own institutions in pursuit of self-interest, often driven by their own conflicts of interest.  We have now seen an amazing set of variations on this theme.  If we truly want to reform health care, we need to ensure that its leaders put their organizations' missions, and the fundamental values of health care, ahead of their own self interest.      

Thursday, March 11, 2010

FDA Asks Hospitals to Report Safety Glitches in Digital Health Systems

A theme of my writings on this blog and on my teaching site for the past decade has been mismanagement of healthcare information technology by an industry and people who have been operating for many years far beyond their qualifications and competencies. Technology requiring the highest levels of biomedical-IT cross disciplinary expertise has most commonly been designed, managed, implemented, led and defended by amateurs [see note 1].

As a result of this mismanagement, the technology is not without its perils. The problem is that this industry suffers from constricted information flows for a number of reasons, and we do not know the magnitude of the perils. Even speculation is difficult since data is scarce. The technology remains experimental.

After a commitment of tens of billions of economic recovery act funds to roll out this technology nationally, the Federal government has finally taken notice:


FDA Asks Hospitals to Report Safety Glitches in Digital Health Systems
In Letter to 350 Health Centers, Agency Signals Growing Concern

By Fred Schulte and Emma Schwartz
Huffington Post Investigative Fund
3:24 pm | 11 Mar 2010

Concern over safety risks posed by health information technology has led the Food and Drug Administration to step up scrutiny of the products, including digital medical records systems on which the government plans to spend billions of dollars in coming years.

The FDA last month asked a network of 350 hospitals it set up across the country to report data on potential hazards from a range of computer-assisted medical devices, according to an agency document obtained by the Huffington Post Investigative Fund.

This should have occurred a decade ago, but better late than never (of course, this action will not help people already harmed by this technology such as these and these).

The FDA action comes as federal officials forge ahead with plans to use as much as $27 billion in economic stimulus money to replace paper patient records with digital ones. The Obama administration wants to create a digital health file for every American by 2014, saying the conversion will save money and improve the quality of health care.

From an analysis that I concur with from the Heartland Institute:

... Proponents of this spending rely heavily on a short RAND Corporation analysis from 2005 that predicted $77 billion in annual savings and improved outcomes. RAND estimated “implementation would cost around $8 billion per year, assuming adoption by 90 percent of hospitals and doctors offices over 15 years.” It said, “The benefits can include dramatic efficiency savings, greatly increased safety, and health benefits.”

Unfortunately, RAND assumed an error-free system that is quickly and enthusiastically adopted by virtually the entire health care system. That might happen, but it is an absolute best-case scenario. [See my aforementioned HIT teaching site on why a "best case scenario" is a near impossibility - ed.] Even then, instead of “dramatic savings,” the $77 billion hoped-for savings amounted to a mere 4.5 percent of total costs, placed at $1.7 trillion by RAND.


Far more likely is that every penny of the $20 billion will be wasted on systems that don’t work and can never be implemented.
[As per my Feb. 18, 2009 Letter to the Editor in the Wall Street Journal - ed.] That was the outcome of federal attempts to upgrade technology at the IRS, the FBI, and the air traffic control system. And these are all relatively simple enterprises involving single federal agencies. Health IT is vastly more complex and must include hundreds of thousands of private organizations that have invested in legacy systems that work reasonably well and are as varied as there are providers.

Back to the Huffington Post Investigative Fund article:

... Reports that hospitals send to the FDA are to be posted on an agency Web site. The FDA maintains it has the authority to regulate the technology, but has not taken steps to do so, leaving the industry largely to police itself. Reporting of problems is voluntary and most manufacturers have not done so.

I think it accurate to say reporting is nearly nonexistent, yet I regularly hear stories from colleagues, former students, and others that make my hair stand on end. These people are afraid to speak out publicly, lest their careers be threatened by hospital sham peer review, vendor lawsuits, or other forms of retaliation against 'whistleblowers' (see an example here).

... In the letter sent to hospitals last month, Marilyn Flack, of the FDA’s Center for Devices and Radiological Health, said use of digital medical equipment “continues to grow and affect patient care and safety.” The FDA “is exploring problems….that may affect patient safety,” she wrote.

The agency plans to collect reports using its Medical Product Surveillance Network, called MedSun. It is asking hospitals to note a wide range of problems involving electronic health records and other computerized systems for hospital laboratories, pharmacies and anesthesia and radiology devices, including hand-held ones.

Here is the FDA letter. Click to enlarge:


FDA letter on health IT safety reporting, page 1 (click to enlarge)

FDA letter on health IT safety reporting, page 2 (click to enlarge)


I note that this letter is remarkable, a real breakthrough. It is also remarkable that this 'breakthrough' had to wait until 2010, not 1990 or 2000, and only after the government has pushed hard to spread this technology nationally without knowing the flip side. The expression "ready, fire, aim" comes to mind.

Some of the 'glitches' were mentioned:

... She also cited an example of a software package used in a hospital emergency room in which lab tests “ordered for one patient returned the results for another.”

In another case, a hospital in the MedSun network reported an operating room software product that often “locked up” during surgery, without alerting anyone that “data entry had ceased.”

According to the FDA letter: “At the end of the surgical procedure, surgical procedure notes were incomplete—compromising the accuracy of the data as nurses had to manually re-enter from memory many of the surgical notes.”

In a third case cited by Flack, a radiology workstation became “extremely slow, delaying procedures and causing X-ray techs to subject patients to repeat X-rays.” The cause was determined to be a software glitch that happened when too many characters were entered in.

These 'glitches' largely come from poor design, engineering, implementation and support and don't even include mission hostile user experiences from software that is 'working correctly.'

... Arthur Bartosch, director of Biomedical Engineering Services at Westchester Medical Center in New York, agreed [that in the past, cinical engineering staff would not have been involved in health IT safety reporting]. He said he planned to circulate the FDA’s alert to the hospital’s chief medical information officer and they would “probably” create a task force to figure out how to document any problems.

It is pathognomonic of IT irrational exuberance and special accommodation given to this technology (greased by ignorance, money, politics and other pathologies among healthcare and hospital leadership juntas) that such 'task forces' are not as common as health IT itself.

... “The fundamental problem we have here is we’re dealing with an industry that really isn’t used to a transparent reporting of problems,” [Paul Egerman, co-chair of a government panel looking at the safety of health information technology] said.

[Isn't used to transparent reporting? I would have said "hostile to the extreme" regarding that kind of transparency - ed.]

Egerman, whose advisory panel expects to make its findings public in April, said government officials have a long way to go in fully understanding the potential hazards of adopting the new technology.

I noted a "hit" from EOP.gov (Executive Office of the President) on my ten year old HIT teaching site just yesterday. I believe it is the first. Welcome to Medical Informatics 101, Mr. President.

“Are there much more serious problems that we would know about if we had the data?,” he said. “These are all reasonable questions to ask.”

I injured my career in the past for asking just those questions, having been badgered to stop asking them essentially to the point of constructive discharge in my former CMIO role.

Let's see if the change of culture is real, or just talk.

It's not that safety reporting and transparency are anything new or special. From the Joint Commission in their August 2009 Sentinel Events Alert #43:

Existing Joint Commission requirements:
The Leadership chapter in the standards manual addresses leadership and safety, specifically relating to the organization's governing body, the chief executive and senior managers, and medical and clinical staff leaders.

The standards specifically require that these three leadership groups create a culture of safety (11) by creating an atmosphere of trust and fairness that encourages reporting of risks and adverse events, by allocating the resources necessary to support safety, by discussing and reporting safety issues and indicators, and by developing plans to assure and improve safety performance, especially in relation to high-risk or problem-prone processes. Other issues covered in the standards are: the implementation of important systems within the organization that support safety; the organization's safety program for reporting adverse events and near misses; and the design or modification of processes to support safety.
And:
Suggested Actions (item #2):
Institute an organization-wide policy of transparency that sheds light on all adverse events and patient safety issues within the organization, thereby creating an environment where it is safe for everyone to talk about real and potential organizational vulnerabilities and to support each other in an effort to report vulnerabilities and failures without fear of reprisal. (8,9)

Finally, considering that the average salary offered to a hospital "Director of Informatics" is a penurious $90-120K per annum with respect to the true expertise required for top roles (don't just take my word for it, take ONC's), and that 'lowball hiring' in terms of expertise is pervasive, I predict that if robust error reporting takes place, the next few years in HIT will be a wild ride indeed.

-- SS

[1] I use the term "amateur" in the same sense that I am a telecommunications amateur, not a professional. Even though I hold the highest license class possible, the Extra, I would not even dream of leading a large telecom project.

Tuesday, March 09, 2010

On ONC's "Proposed Establishment of Certification Programs for Health Information Technology"

The Office of the National Coordinator for Health Information Technology of HHS (the Department of Health and Human Services) has issued a proposed rule "RIN 0991-AB59 Proposed Establishment of Certification Programs for Health Information Technology." The proposed rule is available in PDF at this link and more information is available from ONC itself at this link.

I have written a response to the proposed rule that will be sent as a public comment to the Federal eRulemaking Portal (http://www.regulations.gov/search/Regs/home.html).

I reproduce my response below:

Mar. 9, 2010

Re: RIN 0991-AB59, "Proposed Establishment of Certification Programs for Health Information Technology" (http://www.federalregister.gov/OFRUpload/OFRData/2010-04991_PI.pdf):

Dear HHS/ONC:

I believe the deadlines driving establishment of a certification program for health IT as proposed in RIN 0991-AB59, as well as for achieving “meaningful use of healthcare IT” and for onset of medicare penalties for “non adopters”, will result in diffusion of healthcare IT that, in the words of the Jan. 2009 National Research Council report on health IT “will not be sufficient to achieve medical leaders' vision of health care in the 21st century and may even set back the cause” (http://www8.nationalacademies.org/onpinews/newsitem.aspx?RecordID=12572).

I believe the national health IT system that will result will be injurious to patients at an unacceptably high level as well.

I am a physician and Yale-trained medical informatician and have been writing about the challenges of healthcare IT since the late 1990’s. My bio is at http://www.ischool.drexel.edu/faculty/ssilverstein/biography.htm and my teaching site on HIT difficulties is at http://www.ischool.drexel.edu/faculty/ssilverstein/failurecases/ . I also write on Medical Informatics and HIT for the Healthcare Renewal blog of the Foundation for Integrity and Responsibility in Medicine (FIRM), a 501(c)(3) policy think tank, at http://hcrenewal.blogspot.com.

I have labored over the past decade to steer health IT efforts away from known and predictable paths of difficulty, failure and adverse consequences based on medical science, the science of Medical Informatics, ethical considerations, and the experience of other nations with HIT. I am writing to you to express serious concerns about ONC’s HIT Certification Program NPRM (http://www.federalregister.gov/OFRUpload/OFRData/2010-04991_PI.pdf).

In effect, the NPRM calls for healthcare IT to receive a special governmental accommodation, apparently in part due to politically-decided, and certainly non-scientifically derived timelines. The special accommodations are in the areas of certification, post-market surveillance and inadequate use of existing regulatory expertise over safety-critical IT by agencies with specific domain expertise in that undertaking, thus “reinventing the wheel.”

(On the non-scientific nature of the timelines, see, for example, “Predicting the Adoption of Electronic Health Records by Physicians: When Will Health Care be Paperless?”, Ford et. al, JAMIA 2006 13: 106-112, http://jamia.bmj.com/content/13/1/106.full.pdf.) [note: also see addendum below - ed.]

First and foremost, the term “safety” itself appears in the RIN 0991-AB59 proposal text only four times, and not in the context of strong provisions to safeguard patients from adverse consequences of healthcare IT. This in and of itself is, quite frankly, of great concern, especially in the context of known HIT safety issues.

For instance, FDA’s testimony at ONC’s HIT Policy Committee Adoption/Certification Workgroup meeting on HIT safety (Feb. 25, 2010) itself revealed known patient injuries and deaths related to healthcare IT difficulties.

Even more importantly than the fact of these HIT-related adverse events, however, was the revelation that the true extent of these adverse events is unknown. As FDA’s Jeffrey Shuren, MD, JD expressed it, the data he provided is likely “just the tip of the iceberg.” This supports the contention that the technology is still in an experimental phase, rather than being tried and true.

A growing body of literature supports that view (e.g., see “2009 a pivotal year in HIT” at http://www.ischool.drexel.edu/faculty/ssilverstein/failurecases/?loc=cases&sloc=2009).

It also seems that unscientifically arrived at timelines (i.e., the politically-decided timelines for HIT adoption and achievement of “meaningful use”) that ignore the experimental nature of healthcare IT – that it is not yet “ready for prime time” in a national rollout - are promoting a rush to a superficial certification and surveillance process.

This is alien to the science, culture and ethical obligations of medicine and its practitioners.

The latter process, surveillance, is apparently intended to merely surveil continued conformance of HIT to agreed-upon standards, not patient safety as in the pharmaceutical and tangible-medical device postmarketing surveillance process.

I consider HIT a medical device that is virtual in nature, but a medical device nonetheless, a position the EU is steering towards. See "The Medical Products Agency’s Working Group on Medical Information Systems: Project summary" (available in English translation in PDF at http://www.lakemedelsverket.se/upload/foretag/medicinteknik/en/Medical-Information-Systems-Report_2009-06-18.pdf).

While I believe the NPRM proposal is a step up from the former certification roles envisioned by CCHIT and HIMSS, the proposal still lacks the rigor I have called for in many of my writings about HIT over the past decade.

On the formation of new “ONC-Approved Accreditors” (ONC-AA’s) for certification, this is a special accommodation for the HIT industry that appears to inexplicably place that sector in a favored position compared to the pharmaceutical, medical device and other industries that utilize safety-critical IT.

The FDA, for example, has significant expertise in validating and regulating IT in the pharmaceutical and medical device industries, including that used in clinical trials which bear similarities to HIT used in the delivery sector. For instance, see "General Principles of Software Validation; Final Guidance for Industry and FDA Staff" at http://www.fda.gov/downloads/RegulatoryInformation/Guidances/ucm126955.pdf.

This document opens with the statement:

  • This guidance outlines general validation principles that the Food and Drug Administration (FDA) considers to be applicable to the validation of medical device software or the validation of software used to design, develop, or manufacture medical devices.
As yet another example, NASA has published a document “Certification Processes for Safety-Critical and Mission Critical Aerospace Software” (http://ntrs.nasa.gov/archive/nasa/casi.ntrs.nasa.gov/20040014965_2004000657.pdf). This document begins:

  • Since safety-critical aerospace software is prevalent and important to human life, what is the rationale behind certification of such software? In other words, how do engineers know when a new software product works properly and is safe to fly? In the United States, software must undergo a certification process described in various standards by various regulatory bodies including NASA and the Requirements and Technical Concepts for Aviation (RTCA) which is enforced by the Federal Aviation Administration (FAA).
  • How do researchers know which standards apply to their software? Each NASA center and the FAA have unique certification processes for different types of software. For example, there are special processes for the Space Shuttle and different processes for the Space Station. Any software that flies onboard an aircraft in FAA airspace must adhere to special FAA certification processes. There are also different processes depending upon whether the software is safety- or mission-critical or falls into another category. The UK and Europe have similar certification processes.
HHS should not be creating new, potentially (likely?) amateur organizations and bureaucracies overseeing these new virtual medical devices that will have variable (or no) experience in software validation, certification, regulation, postmarketing safety surveillance, etc. Rather, HHS should be leveraging existing governmental expertise in certifying, validating and regulating mission critical IT.

Further, what is to protect these new bureaucracies from being staffed by those with conflicts of interest with the industry whose products they are purported to certify and surveil? At the very least, existing federal agencies have policies on such conflicts.

Of note, we have a prime example of what can occur due to politically-mediated rushing of healthcare IT – that of the UK’s National Programme for Healthcare IT (NPfIT).

British PM Tony Blair repeatedly sought to shorten the timetable for the NHS national IT programme in a move that would have brought results for patients in time for a general election in 2005 (see http://www.computerweekly.com/Articles/2008/02/18/229447/secret-downing-street-papers-reveal-tony-blair-rushed-nhs.htm.) The result was predictable. A summary of the UK’s House of Commons, Public Accounts Committee’s 2009 report on near-disastrous problems in their £12.7 billion national EMR program is at http://www.publications.parliament.uk/pa/cm200809/cmselect/cmpubacc/153/15304.htm. From that summary:

  • “Recent progress in deploying the new care records systems has been very disappointing …The Programme is not providing value for money at present because there have been few successful deployments of the Millennium system and none of Lorenzo in any Acute Trust … Despite our previous recommendation, the estimate of £3.6 billion for the Programme's local costs remains unreliable … Little clinical functionality has been deployed to date, with the result that the expectations of clinical staff have not been met … Patients and doctors have understandable concerns about data security."
And so forth.

Further, from the UK National Audit Office Executive Summary of 16 May 2008 (http://www.nao.org.uk/publications/0708/the_national_programme_for_it.aspx):

  • At the outset of the Programme, the aim was for implementation of the systems to be complete and for every patient to have an electronic care record by 2010, although the timetable from 2006 was described as tentative. While some parts of the Programme are complete or well advanced, the original timescales for the Care Records Service – one of the key components of the Programme – have not been met.
We ignore the UK experience at our peril, an experience in a medical environment smaller and far more government-controlled than our own.

Finally, I call attention below to the actual ONC NPRM passages from which my concerns arise on “time constraints” leading to a rushed and superficial certification program (which I believe is frankly cavalier and irresponsible considering the stakes involved).

I believe that a rushed National Program for HIT in the United States will suffer the same fate as the aforementioned National Programme for IT in the UK, and perhaps even a worse fate as the UK’s socialized medicine system is certainly a smaller, more homogeneous and more controllable testbed environment for experimenting with HIT.

In summary, I believe the current approach to Healthcare IT certification is inadequate, in large part due to time constraints set upon the effort that are themselves artificially rushed and inadequate. I believe much more significant leveraging of existing biomedical and mission critical IT certification/validation expertise is essential, and that patient safety, not continuing adherence to existing standards should be a primary concern of post-implementation surveillance.

Thank you for considering these views.

I believe rushing health IT, and burying our heads in the sand about the predictable and demonstrated repercussions of doing so as outlined above and on this and other websites, is a very bad idea.


Making like an ostrich on national-scale healthcare IT is a very bad idea.


I have written about FDA myself and not always in complementary terms (e.g., here, here), but my concern is that the creation of multiple new potentially amateur organizations does not bode well for HIT, either.

The key to successful HIT certification, validation and patient safety is 1) leveraging the needed expertise but 2) without industry conflict of interest and 3) without the pathologies of the HIT 'ecosystem' and culture spoiling the environment (see my aforementioned website on HIT difficulties for more on that topic, as well as the HIT ecosystem essay at that site).

Perhaps a new federal HHS subunit is a potential solution - a Clinical Computing Administration (CCA) with regulatory teeth.


The oversight of hundreds of billions of dollars of technology and the patients the technology itself affects calls for a quite serious approach to these issues, in my view.

-- SS

March 9, 2010 Addendum:

On rushing national health IT programs - unknown to me when I wrote the post above, this article just appeared in the British Press:

Patients' medical records go online without consent
Telegraph.co.UK
By Kate Devlin, Medical Correspondent
Published: 10:20PM GMT 09 Mar 2010

Those who do not wish to have their details on the £11 billion computer system are supposed to be able to opt out by informing health authorities.

But doctors have accused the Government of rushing the project through, meaning that patients have had their details uploaded to the database before they have had a chance to object.

... Hamish Meldrum, [the British Medical Association] chairman, writes: "The breakneck speed with which this programme is being implemented is of huge concern ... "If the process continues to be rushed, not only will the rights of patients be damaged, but the limited confidence of the public and the medical profession in NHS IT will be further eroded."

... Norman Lamb, the Liberal Democrat health spokesman, said: "The Government needs to end its obsession with massive central databases. "The NHS IT scheme has been a disastrous waste of money and the national programme should be abandoned."


Read the whole thing.

-- SS

Friday, March 05, 2010

Computers and Prostate Problems in Pennsylvania, East and West

At "Bungled Brachytherapy, Computer Interfaces and Other Mysteries At The Philadelphia Veterans Administration Hospital" at this link I reported on serious problems involving brachytherapy treatment of prostate cancer at the VA Medical Center in Philadelphia.

One of the issues involved computer problems, in the form of failure to network a key computer involved in treatment evaluation.

Now at the other end of the state, Pittsburgh, more prostate-related computer problems have occurred:

Prostate cancer test interpretation flawed
By Walter F. Roche Jr.
PITTSBURGH TRIBUNE-REVIEW
Friday, March 5, 2010

A computer programming error caused West Penn Allegheny Health System's laboratory to send physicians incorrect interpretations of prostate cancer tests for 288 patients over 15 months.

Hospital officials say physicians who ordered the tests were advised about the errors in recent weeks. They were sent revised, corrected interpretations, said Dr. Jan F. Silverman, chairman of the Department of Pathology and Laboratory Medicine.


One wonders how such a "programming error" can occur.

Silverman said actual test results were correct, and most physicians would rely on those and not interpretations. He said hospital officials found no evidence that incorrect test interpretations resulted in delayed or improper care ... The erroneous interpretations were provided on a test physicians use to assess whether patients need biopsies of their prostates. The test provides a comparison of total prostate specific antigen, or PSA, versus free or non-attached PSA.

That there was no apparent delayed or improper care was by happenstance. The purpose of health IT, however, is not to give physicians the opportunity to have a lucky day, or to have placed upon them the additional cognitive burden of deciding which is correct: the test results, or its interpretation.

This episode raises another question: in addition to whatever "programming error" caused this problem, was there no QC of the actual reports to ensure the "interpretation" matched the pathological, serological and other results and findings?

Dr. Ralph Miller, head of the Allegheny Prostate Cancer Center, said it was "theoretically possible, but very, very unlikely" that erroneous interpretations resulted in delayed or improper care.

[That may be true, but is it due to luck and/or the inconvenient fact that most physicians 'did not rely' (i.e., ignored) the computer-generated interpretations? Also, will luck run out the next time a "programming error" occurs, resulting in dead patients? - ed.]

Silverman said those interpretations were sent between Oct. 1, 2008 and January. Of 818 PSA tests the West Penn Allegheny Core Laboratory performed during that period, 412 included comparisons of the two PSA figures. Of those, 288 included incorrect interpretations of that ratio, Silverman said.


That's a very high percentage of error. Should that have occurred in a drug trial, the FDA would likely have been all over the responsible parties. However, health IT is unregulated, therefore all that's required is an "please excuse us, we'll do better the next time" from the involved parties.

The programming error was discovered recently when a physician questioned an interpretation, Silverman said.

I have written before on these electronic pages that physicians and clinical settings should not be the testing labs for IT personnel, with the clinicians using their clinical skills in locating programming bugs.

-- SS

VA / DoD EHR Interface Debacle: Will It Take the Luminosity Of A Dozen Supernovas To Shed Light On The Obvious About Healthcare IT?

(Note: Academic/military readers of this post, I would enjoy your comments. Email sms88 AT drexel DOT edu. Thank you -- SS.)

(Dec. 2010 note: I have observed a large number of "hits" on this post from multiple offices of the Mitre Corporation in the past several weeks. Dear Mitre, I ask that if you use my materials in your proposals or writings, that you please let me know. Thank you. My email address is in my profile under "Contributors." -- SS)

The VA and DoD have been working for a number of years on interfacing the VistA EHR system and the military's EHR, AHLTA (why anyone would want to interface to AHLTA in its present state is of concern to me, but...)

[Note: this is not to denigrate the military, and I am very thankful to all who serve and defend our country and freedoms. HIT problems seem unfortunately universal - ed.]

The interface attempt, likely done by the usual actors in the traditional "business IT" manner has resulted in the predictable:

Glitch prompts VA to shut e-health data exchange with Defense
NextGov.com
By Bob Brewin 03/04/2010

The Veterans Affairs Department closed off access to the Defense Department's huge electronic health record system on Monday because it found errors in some patients' medical data clinicians downloaded from the Defense network, according to a departmental patient safety alert, which Nextgov obtained.

Although no patient was injured, the errors shed light on how software glitches could affect the accuracy of electronic medical records and a planned national system that has been backed by the Bush and Obama administrations.

"Shed light on how software glitches could affect the accuracy of electronic medical records?"

As my early medical mentor, Hahnemann cardiothoracic surgery pioneer Victor P. Satinsky would have said about purveyors of such wisdom: they are Masters of the Obvious.

I ask:

Why do we keep needing to "shed light" on the blatantly obvious, in your face, computer science 101 reality about electronic information systems? The light was shed when the first stored-program computers were developed in the late 1940's.

Exactly how much light do we need to shed before IT personnel "get it" about the need for the most extreme diligence in IT-based medical records?

Perhaps the light of a dozen supernovas?


Is this the amount of light it will take before the IT world "gets it" about the need for the utmost engineering rigor in healthcare IT? (click image to play video).


------------------------------------

*** Nov. 2011 addendum:
I now personally face the aftermath of the worst-case "perfect storm" caused by health IT that began in May 2010, just two months after I wrote this post -


Here is what EHR dysfunction caused to me, personally

------------------------------------


It's fortunate the error was found in a somewhat less than life-threatening manner:

VA first discovered the problem in late February, when one of its doctors accessed the Defense health records system, called AHLTA, to review the prescription information of a female patient. The data showed a Defense physician had prescribed her an erectile dysfunction drug. The VA doctor suspected the system displayed erroneous information [although females have been known to use these drugs- ed.] and a check with the Defense medical facility that supposedly prescribed the drug informed VA that the data was wrong and the VA query had returned information for another patient.

...
When doctors queried the Defense system for patient information, they received no data, a portion of the data, incorrect information, or the complete, correct data for the patient, according to the alert.

[Where have I seen these types of patient data errors mentioned recently? Perhaps at my recent post "
FDA on Health IT Adverse Consequences: 44 Reported Injuries And 6 Deaths In Two Years, Probably Just Tip of Iceberg" ? - ed.]

The glitch did not cause harm to any patient, but "the potential exists for decisions regarding patient care to be made using incorrect or incomplete data," said Jean Scott, director of the Veterans Health Administration's Information Technology Patient Safety Office, in the alert issued on Wednesday.

Indeed.

"The VA clinician may see the patient's data during one session, but another session may not display the data previously seen," the alert noted. "This problem occurs intermittently and has been reported when querying DoD laboratory, pharmacy and radiology reports."

I would add that "intermittent errors" are by definition unpredictable. This is the most dangerous type of IT malfunction of all.

Until those systems are reactivated, VA doctors will have to obtain a patients' health information from their paper medical files, faxes or PDF attachments that are e-mailed to the physicians, Scott said.

What? That old-fashioned, unreliable 5,000 year old artifact upon which the foundations of modern medicine were built, and favored by Luddites?

The errors occurred in the Bidirectional Health Information Exchange, a project started in 2004 that allows clinicians in VA and Defense to view health information in patient files. Older code in the system became stressed at peak periods when clinicians were making the most number of queries, said Roger Baker, chief information officer at VA. At these times, the system did not clear out a memory cache, resulting in memory leaks "so that information from one patient is presented as it is from another," he explained.

Good software and information architecture engineering practices call exactly for testing under stress. Failure to clear caches, memory leaks, etc. are fundamental flaws that should never be permitted to see the light of day in clinical settings. That is what acceptance testing is designed to do. That's what mission critical software undergoes in other sectors. That is what drug and device clinical trials are designed to do.

At this link, for example, is NASA's Certification Processes for Safety-Critical and Mission- Critical Aerospace Software from 2003 (PDF). From that document:

... Since safety-critical aerospace software is prevalent and important to human life, what is the rationale behind certification of such software? In other words, how do engineers know when a new software product works properly and is safe to fly? In the United States, software must undergo a certification process described in various standards by various regulatory bodies including NASA and the Requirements and Technical Concepts for Aviation (RTCA) which is enforced by the Federal Aviation Administration (FAA).

There are no analogous requirements or enforcement in the healthcare IT sector. None.

In fact, the VA, of all places, should have been exceptionally wary of these types of malfunctions and exercised the highest levels of engineering rigor.

Why?

See "IT Vulnerabilities Highlighted by Errors, Malfunctions at Veterans Medical Centers" at this link. From that posting, reflecting a March 4, 2009 JAMA article by the same title by Bridget M. Kuehn (JAMA 2009;301(9):919-920):

... After a software update of the electronic medical records system at VA hospitals in August [2008], health care workers at these facilities began to report that as they moved from the records of one patient to those of a second patient, they would sometimes see the first patient's information displayed under the second patient's name. [If not for the diligence of the users then, that type of error could have led to dead patients -ed.]

This records-scrambling problem was reported at 41 of the 153 VA medical centers, said Gail Graham, deputy chief officer of Health Information Management at Veterans Health Administration Headquarters in Washington, DC. Graham explained that the jumbling of records was an uncommon occurrence that only occurred after a particular sequence of events.

...
Health care workers at the VA medical centers were notified about this potential problem in October, and on December 20, the centers received a software "patch" to fix the problem.

Nine VA medical centers reported another type of problem related to their electronic records system: physician orders to stop medication were missed, causing some patients to receive intravenous medications longer than necessary. The problem occurred because after the software upgrade, physician orders to discontinue such medications, which had previously appeared at the top of the screen, were not displayed.

In 3 cases, patients received infusions of drugs such as heparin for up to 11 hours after their physician had ordered the drug to be discontinued. Graham said the affected patients were not notified because they had not been harmed by the oversights. This software problem was corrected on December 8.

As I noted in that post: "... if this type of error occurs once too often, your patient's dead."

Back to the current VA / DoD interface "glitch":

... The VA has fixed the [current] bug and plans to bring the BHIE back online on March 9. Baker emphasized the bug's effect on the medical records of patients that VA and Defense clinicians share was sporadic and occurred in one out of 100 queries. The glitch caused errors only in the records that VA clinicians accessed. Defense doctors still have access to records Veterans Affairs stores.

"Only" 1 out of 100? ... that's only 10,000 errors per million EHR queries. Not too bad at all ... how many soldiers are in a military division?

Baker said the department's response to the glitch showed VA's overall health system worked "because there is always a doctor in the loop" who checks the accuracy of a patient's health data in combination with a well established patient safety organization that quickly alerts clinicians to any errors.

The "system worked" because luck prevailed that fallible, busy human clinicians were not deceived by erroneous information provided by a computer? I fall back on first principles of IT:

A computer can free professionals from tedious, repetitive work which does not require judgment. It can provide facts and figures with lightning speed, giving domain experts more time to exercise their judgment thoughtfully

The system is not working when computers add to the tedium, and having to expend precious cognitive capacity in ferreting out computer errors is certainly in that category. This excuse reminds me of a recent quote from our Homeland Security secretary about how the "system worked" when an airplane nearly was blown out of the sky.

These failure excuses, possibly written by a public relations 'spin doctor' in an effort at damage control, remind me of a humorous sign I bought in a novelty store once, for placing on the wall: "Our policy is to always blame the computer."

Perhaps clinicians need to stand up for this motto: No more alpha and beta software rollouts in healthcare.

Robert Charette, a risk management consultant and president of the ITABHI Corp. in Fredericksburg, Va., which consults with Defense, said VA was lucky it discovered an error as obvious as prescribing an erectile dysfunction drug for a female patient. He wondered if VA would have detected the error if it were for drugs with similar names, adding that despite the low error rate, "it's the one out of 100 that can bite you."

It's also the one out of fifty thousand that can bite you, for instance as Merck recently discovered.

Baker said the complexity of medical records systems like BHIE would make regulating such networks [by agencies such as FDA - ed.] a daunting task.

I thought we were just at the point of transforming health with one thunderous click of a mouse after another per our prior HHS secretary at the 2005 HIMSS summit. Perhaps not...

Dave deBronkart, a patient advocate in Nashua, N.H., who spoke at last week's Health IT Policy Committee meeting, said in an interview with Nextgov that the glitch paralleled the problems he encountered last year when he tried to transfer information from his hospital medical record to Google Health, an online electronic health record database the search giant launched in 2008.

I wrote about that at "Should Google Seek the Resignations of Those Responsible for This Healthcare IT Debacle?" here.

If the United States wants to develop a national health electronic record system, it needs to make sure heath information exchanges work correctly, said deBronkart, who added VA should be commended for reacting quickly to the software problem and issuing the patient safety alert.

I believe this is not possible under the current leadership, organizational and regulatory structures found in the healthcare IT sector. As I've written before, healthcare cannot be 'reformed' or even improved by IT, until IT and its culture are themselves reformed.

For more on these issues, see my site below.

-- SS

For more on HIT challenges see "Contemporary Issues in Medical Informatics: Common Examples of Healthcare Information Technology Difficulties" - http://www.ischool.drexel.edu/faculty/ssilverstein/cases/

Thursday, March 04, 2010

FDA Criminal Division to Increase Prosecutions

In many posts on this blog, Roy Poses has lamented the fact that there are no personal repercussions for healthcare executives embroiled in malfeasance and scandals.

He recently wrote:

So, here we go again ... To repeat, seemingly ad infinitum, these are just the latest in a now long parade of settlements and guilty pleas and criminal convictions, sometimes involving charges like bribery, fraud, or kickbacks, that serve as reminders of poor behavior by myriad health care organizations. As we have previously noted, these settlements seem to have little deterrent effect on future bad behavior. (Note that many large health care organizations have settled or plead guilty in several major cases since we started commenting on such settlements.) Usually, the companies involved only need to pay fines, and no individual who performed, directed or approved unethical or illegal acts will suffer any negative consequences. I submit once again that such fines are viewed merely as costs of doing business by the affected companies, and do not deter future bad behavior. Until the people who approve, direct, and perform unethical or illegal acts pay some penalties, expect such acts to continue. I again suggest that to truly reform health care, we need rigorous regulation of health care organizations that has the power to deter unethical behavior that may risk patients' health.

The companies of the bad actors are fined; the fine is considered a "cost of doing business"; but personal actions against the responsible executives engaged in malfeasance do not usually occur. Dr. Poses feels healthcare reform cannot occur under these conditions, and I agree.

Apparently, so do others at high levels:

FDA Criminal Division to Increase Prosecutions
Wall Street Journal
March 4, 2010

By ALICIA MUNDY

WASHINGTON—The Food and Drug Administration plans to increase prosecutions of pharmaceutical and food industry executives as part of an effort to refocus its criminal division, which has been under attack in Congress and is criticized in a new government report.

In a letter to Sen. Chuck Grassley (R., Iowa), the FDA says an internal committee has recommended that the FDA and its Office of Criminal Investigations "increase the appropriate use of misdemeanor prosecutions, which allows responsible corporate officials to be held accountable and is a valuable enforcement tool."

Misdemeanor prosecutions are a start; however, some of the behaviors seem to my uninformed legal mind to perhaps be more felonious in nature...

An FDA official said the agency has the authority to prosecute corporate executives for criminal actions within their companies under a provision called "strict liability." He said the government doesn't have to show intent to defraud in order to get a conviction. He added that the provision is an important tool that hasn't been used much in recent years.

As has been noted repeatedly on this blog.

A report set to be released Thursday by the Government Accountability Office, Congress's watchdog arm, says the Office of Criminal Investigations has operated autonomously for years with little or no accountability to top FDA officials

... The report said the FDA "has relied largely on the OCI director to determine which aspects of OCI's operations and investigations are made known to FDA's top management."

The GAO also said the FDA's criminal unit has fallen short compared with other agencies in developing performance standards.

This clearly must be corrected.

The FDA officials largely agreed with the assessment and in the letter said the agency is "developing meaningful performance measures" for the criminal office as part of an initiative begun in August. The FDA said it wants the criminal office to share information with FDA leaders regularly, and to do a better job picking cases.

I know where they can look to find cases ... here, for example.

... In 2008, Rep. Joe Barton (R., Texas) criticized the Office of Criminal Investigations, saying its budget had increased while its workload stagnated.

I think the many posts on healthcare corruption here and elsewhere suggest that the workload of the Office of Criminal Investigations needs to pick up quite substantially, if the behaviors are to be discouraged and the actors shown that the penalties are not just a "cost of doing business" (unless one is willing to acquire a criminal record or go to jail for one's company as a "cost of doing business", that is).

It is my hope that one day this increased vigilance will be extended to the healthcare IT industry.

-- SS

Wednesday, March 03, 2010

On the "Wickedness" Of Healthcare IT (And Is CPOE Just a "Typewriter For Orders?")

Large-scale implementation of comprehensive healthcare IT, especially if meaningful ROI on the hundreds of billions of dollars spent is to be attained, is more of a wicked problem than a tractable one, as I have written on this site and in a number of presentations (such as this one on HIT challenges and perils - PDF).

A "wicked problem" describes a problem that is difficult or impossible to solve because of incomplete, contradictory, and changing requirements that are often difficult to recognize. Moreover, because of complex interdependencies, the effort to solve one aspect of a wicked problem may reveal or create other problems.

In the current environment of irrational exuberance, healthcare IT has been presented as a ready-for-prime-time, "mouse click away from great healthcare", put-it-in-and-reap-the rewards technology. An example of this 'HIsTeria':

“We have the capacity to transform health with one thunderous click of a mouse after another,” said (former) HHS Secretary Michael Leavitt - 2005 HIMSS Summit

"Transform" healthcare via "one thunderous mouse click after another?" On an irrational hyper-ebullience having taken over in healthcare IT, I rest my case.


Thunderous computing! Oh my!

Unfortunately, realizing the capabilities of healthcare IT is not simple. It is in fact devilishly complex. For instance, is CPOE a "typewriter for orders", as it's sometimes represented in this industry to de-emphasize its potential hazards?

Far from it.

In recent testimony submitted at the HIT Policy Committee, Adoption/Certification Workgroup of HHS on February 25, 2010, a meeting on HIT safety, Geisinger medical informaticist/CMIO James Walker, MD wrote (PDF) the following (emphases and red comments mine):

... In 2005, Geisinger was preparing for its first inpatient EHR implementation. Several months into the project, the project director informed the CIO and me that the EHR team’s business analysts were unable to map safe and effective workflows between the new order-entry system and our existing pharmacy system (provided by another vendor).

[As an aside, one might question why "business analysts" were attempting a clinical mapping such as this - ed.]

They and the project director believed that the only safe approach was to de-install the existing pharmacy system and replace it with the pharmacy system provided by the order-entry vendor—at a cost of several hundred thousand dollars and a nine months’ delay in the project.

Pharmacy’s management was pained by the need to remove what was indisputably the best pharmacy system on the market [yet, even so, it needed to be removed and replaced with something that may, or may not, be equivalent in safety, ease of use, customizability, lifecycle maintenance, etc. - ed.] (which they had used very effectively to improve safety and efficiency). Nevertheless, they agreed with the workflow analysis and supported the change. Executive leadership approved the change and we proceeded.

Two years later (2007), when I reported this experience to an EHR-safety conference, David Classen noted that the results of the Leapfrog CPOE test in 62 carefully studied hospitals confirmed that this hazard ... appears to be present regardless of which vendors’ products are used. (Classen, in press).

[The effects of the disruptions at those 62 carefully studied hospitals might likely increment the "tip of the iceberg" HIT-related injury/death figures cited at the same meeting by FDA official Dr. Jeffrey Shuren- ed.]

In other words, any organization that implements a CPOE system needs to throw away whatever IT system is being used in pharmacy, with all of the familiarity and experience of pharmacy staff, and safety improvements that software might have provided because interfacing the systems is (allegedly) impossible and/or impractical. Then, after a learning curve characterized by disruptions in service, it is hoped the new pharmacy system will provide similar benefits to the old, and that the CPOE itself will work well (and not do this).

This disruption, caused by software dependencies in a complex biomedical setting and perhaps other reasons (see below), certainly represents a complex interdependency, the "solution" to which creates new problems, such as:

  • What if the new CPOE vendor-sourced pharmacy system is inferior to the old?
  • What does the organization due if the single-source vendor folds, now causing orphaned software over two, not one, critical functions?
  • What other software-to-software interdependencies and bottlenecks exist that are not easily remedied by interfaces? CPOE-diagnostic imaging (radiology)? CPOE-laboratory? CPOE-O.R.? CPOE-dietary? CPOE-bed control? And so forth for CPOE and other systems to be installed.
  • What happens if the CPOE fails (as here)?

As to causation of the allegedly irremediable incompatibility between CPOE's and Pharmacy IT, Dr. Walker submitted the following testimony:

... hazards arise due to failures in health IT design, implementation, and maintenance. (While many of these failures are due to a lack of skill or vigilance, many more are due to the interactions of complex healthcare processes and the necessary complexity of IT systems capable of supporting those processes.)

While I await the aforementioned Classen in-press paper on 62 hospitals, I take a more saturnine view and would argue that most of the interfacing problems probably have more to do with "lack of skill and vigilance" as opposed to some "organic" problem in interfacing these systems.

My view is based on experience in the IT backwater of hospitals and HIT, where bureaucrats and IT personnel largely are working far outside their core competencies; where straightforward software adaptations in complex subspecialties can be completely and repeatedly bungled until appropriate expertise is leveraged; where expert advice may simply be ignored and worse; and other pathologies. (See more on ONC Director Blumenthal's call for correction of the healthcare IT skills problem at "ONC Defines a Strategy of Robust HIT Leadership".)

The CPOE interface difficulties may also be in part due to vendor strategies of closed and overly complex software and information architectures, and vendor unwillingness to assist in interfacing to "alien" pharmacy IT products through ominous cost structures and halfhearted attempts. These matters could be strategic business decisions in a highly competitive market. (The supposed incompatibilities might actually be another argument supporting open source in healthcare...)

-------

In either case regarding interface difficulties, i.e., human-based vs. "organic" IT issues, however, one can see that health IT is no easy "plug and play" affair.

There is no predetermined benefit nor ROI. The complexities and "wicked problem" nature of HIT argue that benefits and ROI will not come short term - and never if the technology and its mass implementation are treated as easily tractable, not experimental and "wicked."

Finally, CPOE a typewriter for orders? Perhaps, if this is the kind of typewriter being referred to:


Typewriter for Japanese language

-- SS

For more on HIT challenges see "Contemporary Issues in Medical Informatics: Common Examples of Healthcare Information Technology Difficulties" - http://www.tinyurl.com/healthITfailure

Monday, March 01, 2010

Sacks Medical, KV Pharmaceutical Plead Guilty, Mariner Health Care, SavaSeniorCare Settle

The march of legal settlements and guilty pleas by health care organizations just keeps going.  The most recent participants were:

Sacks Medical Corp

The Pittsburgh Tribune-Review reported:
A Butler County drug company pleaded guilty in federal court in Pittsburgh to international money laundering and violating federal drug laws in an investigation that involved the now-defunct Monsour Medical Center Research Institute.

Sacks Medical Corp. of Evans City was fined $500,000 and ordered to forfeit an additional $500,00 by U.S. District Court Judge Gustave Diamond on Monday. The firm was placed on one year's probation.

The research institute was not charged in the investigation.

According to federal prosecutors, Sacks in 2004 obtained pharmaceutical drugs at discount prices, which were then resold to other drug wholesalers in violation of the Prescription Drug Marketing Act.

Sacks persuaded officials at the Monsour Medical Center in Jeannette to create the research institute, which was nothing more than a shell company, according to the charges.

The institute joined two group purchasing organizations and began buying large amounts of medical supplies that should have been designated only for the hospital's use and not resold, according to the charges.

Purchases were made from major drug companies, AmerisourceBergen of Valley Forge and McKesson Corp. San Francisco. Monsour then sold the medications to Millenia Hope Healthcare Inc., which was located at Monsour.

Millenia then sold the drugs directly to Sacks or to San Med Development Group, which is owned by Sacks, according to prosecutors.

Sacks supplied Monsour with the money to buy the discounted drugs. The company then tried to disguise the transaction by wiring the money to a Canadian bank, which in turn wired the money back to Monsour, according to the plea agreement.

The novel element here seems to be the charge of international money laundering.

KV Pharmaceutical

Bloomberg reported:
KV Pharmaceutical Co. agreed to pay a $25.8 million fine and forfeit $1.8 million to resolve a U.S. Justice Department investigation of its generic pharmaceutical marketing and distribution unit, which will cease operations.

That unit, Ethex Corp., will also enter a plea of guilty to criminal charges arising from its actions in 2008, according to a statement issued today by St. Louis-based KV. The agreement requires court approval, the company said.

Under the terms of the accord, Ethex will plead guilty to two felony counts stemming from its failure to make and submit to the U.S. Food and Drug Administration a report on its discovery of undistributed pills that 'failed to meet product specifications,' KV said separately in a filing today with the U.S. Securities and Exchange Commission.
Note that these first two cases both involved guilty pleas to criminal charges, felonies in the latter case.  Further note, however, that in the latter case, the felony pleas were made by a subsidiary of the corporation, which will then be dissolved, leaving the parent corporation intact.  Although in both cases organizations pleaded guilty to criminal charges, there were no reports that any individuals who worked for or were otherwise involved in these organizations pleaded guilty to any charges.
Mariner Health Care, SavaSeniorCare (and Omnicare)

Again, from a report by Bloomberg:
The U.S. reached a $14 million settlement with nursing home chains Mariner Health Care Inc. and SavaSeniorCare Administrative Services LLC over allegations of kickbacks from a supplier of drugs to nursing home patients.

The accord resolves claims that the companies and their principals, Leonard Grunstein, Murray Forman and Rubin Schron, solicited kickbacks from Omnicare Inc., the U.S. Justice Department said in an e-mailed statement.

The defendants conspired to have Omnicare pay $50 million in exchange for agreeing to use the supplier for 15 years, the government said last March in a complaint in Boston. The alleged kickback scheme involved Omnicare’s paying $40 million to buy a Mariner unit whose only assets were less than $3 million in accounts receivable, according to the complaint.

Note that we discussed another settlement involving Omnicare and kickback allegations here.  It appears, however, that Omnicare paid any additional penalty in this case, despite allegations that it provided the kickbacks.

Summary

Again, another week, another series of colorful legal settlements and/or guilty pleas and/or convictions involving health care organizations.  Again, although organizations settled or pleaded guilty, no individuals seemed to be held accountable for authorizing, directing, or implementing the actions that lead to these pleas and settlements.

So, here we go again ... To repeat, seemingly ad infinitum, these are just the latest in a now long parade of settlements and guilty pleas and criminal convictions, sometimes involving charges like bribery, fraud, or kickbacks,  that serve as reminders of poor behavior by myriad health care organizations. As we have previously noted, these settlements seem to have little deterrent effect on future bad behavior. (Note that many large health care organizations have settled or plead guilty in several major cases since we started commenting on such settlements.) Usually, the companies involved only need to pay fines, and no individual who performed, directed or approved unethical or illegal acts will suffer any negative consequences. I submit once again that such fines are viewed merely as costs of doing business by the affected companies, and do not deter future bad behavior. Until the people who approve, direct, and perform unethical or illegal acts pay some penalties, expect such acts to continue. I again suggest that to truly reform health care, we need rigorous regulation of health care organizations that has the power to deter unethical behavior that may risk patients' health.