Tuesday, July 31, 2012

The Colonoscopy Experience

Today, as Kathy finished her last radiation therapy appointment, I had my first screening colonoscopy - a right of passage for new 50 year olds.

Although a bit of a personal issue, I'm known for my transparency and I'm happy to share the experience so that others approaching 50 know what to expect.

The preparation is the hardest part.   Three days before the procedure, it's recommended that you reduce the quantity of high fiber foods you eat - fruits, vegetables, nuts etc.  For me that was particularly challenging since my entire diet as a vegan (who tends to avoid white flour, white rice, and white sugar)  is high fiber.    I moved to soups and brown rice.   A day before the procedure (really 36 hours), you move to a clear liquid diet - apple juice, broth, and tea.   In my case I drank a cup of vegetable broth and apple juice every 3 hours.  

At 7pm the night before the procedure, the real challenge begins.  The bottle of magnesium citrate reads "a pasteurized, sparkling, laxative".   Sounds so appealing.   The first dose is 15 ounces.   The bottle warns that the maximum therapeutic dose is 10 ounces in 24 hours for adults, but colonoscopy is a special case.   The 15 ounces of laxative is followed by 24 ounces of clear liquids over the next 2 hours.   Keep in mind that you have not eaten any solid food for 24 hours at this point.   Sparkling laxative followed by broth and apple juice is not Chez Panisse 

A few hours after the laxative, the intestinal rumbling begins.    You'll have a rocky night with an urgency to jog to the nearest bathroom every few hours.   By morning the intestinal cramping will have subsided and then you get to repeat the process!  Six hours before your procedure, you'll drink another 15 ounces of mag citrate followed by 24 ounces of clear liquids over 2 hours, then nothing by mouth for the final 4 hours.    Given the 36 hours without solids and 30 ounces of mag citrate there's nothing really left in your body, so you'll move the clear liquids through your system quickly.    You'll arrive for your procedure just as all the cramping has stopped.

The procedure itself is the easy part.   There are multiple sedation options - nothing at all, versed/fentanyl, and propofol/monitored anesthesia

I received propofol, which works quickly and clears quickly.   I have no memory of the anesthesia, but when I awoke I thought I had just come in from chopping wood on the farm.   The nursing staff were very understanding.   In a few minutes, I was walking, dressed and back on the iPhone, doing conference calls and answering email.    I did avoid work with chain saws and signing a new will.

The Boston Endoscopy Center, where I had my procedure, uses an electronic record called Gcare, which captures images and reports.   The BIDMC enterprise systems are fully interfaced to Gcare, so all endoscopy information is immediately available to patients and providers.      By the time I returned home, I had access to all the images above.   The report was simple and to the point

"Medications: MAC Anesthesia
Pain rating: 0/10
Indications: Screening for colon cancer

Procedure: The procedure, indications, preparation and potential complications were explained to the patient, who indicated his understanding and signed the corresponding consent forms. A physical exam was performed. Moderate sedation was initiated by the physician. Continuous pulse oximetry and cardiac and blood pressure monitoring were used throughout the procedure. Supplemental oxygen was used. The patient was placed in the left lateral decubitus position.The digital exam was normal. The colonoscope was introduced through the rectum and advanced under direct visualization until the cecum was reached. The appendiceal orifice and ileo-cecal valve were identified. Careful visualization of the colon was performed as the colonoscope was withdrawn. The colonoscope was retroflexed within the rectum. The procedure was not difficult. The quality of the preparation was good. The patient tolerated the procedure well. There were no complications.

Findings:
Mucosa: Normal mucosa was noted in the entire colon
Impression: Normal mucosa in the colon
Otherwise normal colonoscopy to cecum

Recommendations: Colonoscopy in as long as 10 years as per the recommendation of Medicare. If you develop symptoms such as bleeding, or if a relative develops colon cancer, this interval would change. Get regular checkups with your primary doctor to check for hidden blood in the stool

Additional notes: The efficiency of colonoscopy in detecting lesions was discussed with the patient and it was pointed out that a small percentage of polyps and other lesions including colon cancer can be missed with the test. Degree of difficulty 2 (5 most difficult)

FINAL DIAGNOSES are listed in the impression section above. Estimated blood loss = zero. No specimens were taken for pathology"

Done for another 10 years!

As July draws to close, both Kathy and I are celebrating.  We'll have a high fiber vegan meal and welcome the simpler August ahead of us.

Friday, July 27, 2012

Cool Technology of the Week

I'm not sure if this should be a cool technology of the week or a scary technology of the week.

I've posted frequently about the increasing challenges of malware, BYOD, and hackers.

This week's cool technology is a hacker's network penetration device, packaged to look like a power strip.

The Power Pwn is a fully integrated enterprise-class linux server that includes Ethernet, wireless and Bluetooth connections.  It also has a fully automated NAC/802.1x RADIUS bypass and secure shell access over 3G and GSM cell networks.

All a hacker has to do is place this power strip under a desk within a corporation and then they can identify network vulnerabilities and mine data as they wish.

I've said before that security is a cold war - an escalating battle between hackers and IT departs trying to control them.   The Power Pwn is a powerful new entry to the hacker's arsenal.

Thursday, July 26, 2012

Our Cancer Journey Week 31

Today marks the end of our cancer journey for now, although the followup will be life long.   In 2012,

*Kathy completed chemotherapy with Adriamycin/Cytoxan and Taxol
*Kathy underwent a lumpectomy of her left breast where the tumor was growing
*Kathy received 33 doses of radiation therapy over 42 days
*We sold our home in Wellesley (it closes today), purchased a farm in Sherborn and moved all our belongings, the contents of Kathy's studio, and her father's belongings to a single location.
*We acquired 8 alpaca, 2 llama (if you count our pregnant guard llama), 12 hens, 1 rooster, and 22 guinea fowl

So now, it's time for a breather.   The month of August has no travel, no visiting family/friends, and a little less chaos in our lives.

We will use our August 8 anniversary (32 years together, married 28) to reflect on where we've been and where we're going.    We'll celebrate the trajectory of the past year.   There was good and bad, but we're on a very positive path.

Although Kathy still has numbness in her feet and hands, the rest of her body and her mind is in good shape.   She's designing our blueberry patch and apple orchard.    She's putting the finishing touches on our barn, paddocks, and fences.   Her new beginning as a cancer survivor is mirrored with by a new lifestyle for our entire family.

I'm a strong believer in the karmic notion that everything happens for a reason.   Life is anything but a linear path and you never know what you'll find around the next turn or how one turn will affect another.  

To me success is not measured in fame or fortune, but in relationships you nuture and the difference you make.  Our cancer journey has been all about relationships - spouses supporting each other, family supporting family, clinicians supporting patients, my employer supporting its employee, and the broad community (Massachusetts colleagues,  acquaintances, and fellow cancer patients) offering unconditional optimism.  

So thank you to everyone who has supported Kathy and me since our diagnosis in December of 2011.   By all measure, you've made a difference and strengthened every relationship  while opening new doors for the future.   We are truly blessed to have you around us.  We look forward to the day we can invite all of you to our farm for blueberry picking, apple picking and alpaca watching in celebration of surviving cancer.

Tuesday, July 24, 2012

Separating Professional and Hospital Records

As Patient Centered Medical Homes and Accountable Care Organizations form, the lines between professional and hospital practice become increasingly murky.

CMS has long required that hospital and professional records be separable, so that in the case of audits or subpoenas, it is clear who recorded what.

Today, the BIDMC ACO continues to expand into the community, adding owned hospitals, affiliated hospitals, owned practices, and affiliated practices.

Our strategy to date has been to use our home-built inpatient and ambulatory systems at the academic medical center, Meditech in the community hospitals, and eClinicalWorks in private ambulatory practices which are part of our ACO.

We share data among these applications via private and public HIE transactions - viewing, pushing, and pulling.   

The challenge with emerging ACOs is that professionals are likely to work in a variety of locations, each of which may have different IT systems and each of which serves as a separate steward of the medical record from a CMS point of view.

Our clinicians are asking the interesting question - can I use a single EHR for all patients I see regardless of the location I see them?  

Our legal experts are studying this question.  

I can imagine several answers

For facilities we own and control, we can tag every note created by every professional with a facility code, enabling us to separate out those records created at given location in the case of audit or subpoena.

For facilities that are affiliated but not owned, clinicians can use their favored EHR, but at the end of the encounter, they must create a paper or digital copy of the record and place it int the hospital record of the location which is the steward of the data from a CMS perspective.

Since it is unlikely that every inpatient and outpatient facility we acquire or affiliate with will have the same HIS and EHR applications, it is not realistic to create one physical shared record across all sites.

Instead, data sharing through the HIE, metadata tagging as to the facility/professional that owns each record, and policies regarding what must be done at each site seems like the logical way to go.

As is often the case with challenging workflow and regulatory issues, I welcome the experience of others.   How have you separated professional and hospital records per CMS regulations, but enabled co-mingling of patient data for care coordination and population health?

Monday, July 23, 2012

The BIDMC Laptop Encryption Program

I've been writing about the Bring Your Own Device (BYOD)/Consumer IT challenge for the past several months.  Today, an action plan goes into effect.   Here's the message we sent to employees:

"Information Systems will be conducting an aggressive campaign to ensure every mobile device is encrypted. This initiative applies to all staff and students. The program is mandatory and required for any mobile device used to access BIDMC-related systems, programs or documents, including email, clinical applications and administrative documents such as financial spreadsheets, grant information or staff lists.

Many of you participated in last month’s program regarding smart phone devices used to connect to the Exchange email system using ActiveSync. These devices now require password protection. Look for more information soon on new smartphone encryption and 'auto wipe' requirements.

Securing Laptops and iPads

The next stage of work is encrypting laptops, iPads and other tablet computers. It will proceed in two phases.

The first phase, beginning this week, focuses on institutionally owned laptops and iPad-type tablet computers.   Other versions of tablet computers will be addressed in a later phase.  Service depots will be set up in and around the main campus. The first location will be the Center for Life Sciences (CLS). This building was chosen because it has the largest population of laptops and iPads.  

We appreciate the cooperation of staff of CLS especially because you are the first to undergo this new process. The CLS experience will guide IS planning for the entire medical center.   We will coordinate our encryption program with Research Administration’s research equipment inventory project, eliminating redundant phone calls to investigators.

What You Need to Do

Prepare Your Device – Prior to dropping off the laptop or iPad at the service depot, delete unneeded applications and data. All valuable data and important files, email, applications and other documents stored on the device should be backed up to your network home directory. Do NOT back up the data to an Internet cloud service such as Apple’s iCloud, or DropBox. Storing protected health or personal information on these sites is against corporate security policy. 


Schedule an Appointment - Information Systems will contact staff for which records show you have been issued an institutionally funded laptop or iPad.

Leave the Device - Encrypting a device may require several hours depending on the method used. For this reason, you will be expected to leave the device at the service depot. Every attempt will be made to complete the work within the same business day.


Pick Up the Device - Upon returning the device, depot staff will brief you on what work was done and your on-going responsibilities for maintaining the security of the device. You will be asked to start the device from a cold boot and verify it is in working order.

What IS Will Do


Intake – To qualify under HIPAA/HITECH 'safe harbor', full disk encryption is required. On arrival at the service depot, an initial assessment of the device’s configuration will be done to determine the most appropriate encryption method, e.g. software or hardware based. Some devices have encryption built in, but it needs to be activated. The method used will depend on the make, model and operating system version of the laptop or tablet computer.


Inspection - The service depot staff will scan the device for malware and vulnerabilities.  They will check configuration settings to assure they comply with corporate security policy such as power-on password, inactivity timeouts, and, for iPads, auto wipe. If time permits, depot staff will apply operating system and third party software patches necessary to eliminate security vulnerabilities.  If malware is detected, the device will be cleaned or re-imaged depending on the nature of the malware. The network address of the device will be recorded so I.S. knows it has been inspected when it appears on the data network. When practical, management (Microsoft SCCM for Windows or Casper for Macs) and anti-virus agents (McAfee EPO) will be installed to allow Information Systems staff to keep the device in good security hygiene throughout its life while in use at BIDMC.


Inventory the Device for Research – If your computer is one that still needs to be scanned as part of the bi-annual Research inventory required by federal law, a member of the Research Administration staff will scan the inventory tag while it is at the depot – or apply an inventory tag as needed. We are combining these efforts to make it more convenient for users.


Return - See #4 above.

What is Next?
The dates and locations for other service depot sites will be announced later this month as IS continues to secure laptops and iPads throughout the medical center.

The second phase will extend the program to other models of institutionally owned tablet computers as well as personally owned laptops and tablet computers that are used to access BIDMC-related data. This phase will begin in the fall after work on institutionally owned devices is completed. We will assist in encrypting and, time permitting, patching the devices. Once done, it will be the responsibility of the owner to maintain the encryption and healthy state of the device.

Information Systems will periodically check your mobile device to ensure the safeguards are still in place. Additionally,  staff must attest, each time their password is renewed, that all mobile devices they use for hospital related business, including personal devices, are encrypted.

From this point forward, newly acquired laptop and tablet computers purchased from institutional funds cannot be used to access the BIDMC data network until their encryption status is verified by Information Systems.

Information Systems will monitor the network for rogue laptop and tablet devices that have not been screened for compliance. If a device is discovered that has not been screened, Internet access privileges will be blocked."

As I've told the press, it is no longer sufficient to rely on policy alone to secure personal mobile devices.    Institutions must educate their staff, assist them with encryption, and in some cases purchase software/hardware for personal users to ensure compliance with Federal and State regulations.   Over the next few months, I'll write several posts about our lessons learned supporting personal device security enhancements.

Friday, July 20, 2012

The July HIT Standards Committee Meeting

The July HIT Standards Committee focused on a discussion of maturity and adoptability criteria for standards, a review of recent testimony regarding best practices for electronic identity authentication of providers, an update from ONC on the certification program, and a continuing discussion of the future processes needed to support the S&I Framework.

Dixie Baker presented the Initial Report on Criteria to Assess Maturity of Standards and Specifications.

A robust discussion followed noting that interpretation of readiness is contextual.  Sometimes it is reasonable for standards to include optionality.  Sometimes it is beneficial to require pre-coordination between trading partners.  Sometimes it is reasonable to encourage adoption of emerging but not widely tested standards.   The excellent framework that Dixie presented will be tested with a sample standard - the  HL7 Infobutton implementation guide for knowledge retrieval.   At our next meeting, Dixie will report  on lessons learned from this evaluation and any refinements she would suggest to the maturity/adoptability criteria.

Dixie also presented an overview of a recent hearing on trusted identification for providers.  In a world filled with malware, screen scrapers and keystroke loggers, it is important to consider the vulnerability of username and password as authentication credentials.  The Standards Committee agreed on the importance of accurately identifying and protecting endpoints in healthcare information exchange, however they noted that healthcare workflows require more complexity than just authenticating individual users.   Sometimes organizational credentials (a practice) are needed since a message is routed to a place not a person.   Sometimes delegation is needed when routing a message to the staff supporting a clinician.   We also discussed the workflow impact of two factor authentication.   Strong authentication is part of a multi-layered defense protecting privacy. Significant work will be required to develop a family of solutions supporting the requirements of healthcare.

Next, Carol Bean provided an update on the Permanent Certification program.   The existing temporary Authorized Testing and Certification Bodies (ATCBs) will be replaced by permanent certification and testing organizations.   The certification organizations are accredited by ANSI and authorized by ONC.   The testing organizations are accredited by National Voluntary Laboratory Accreditation Program (NVLAP) , a division of NIST,  and authorized by ONC.   To date, 5 organizations have been accredited as certifiers, and 5 organizations have been accredited as testers.   ONC plans to authorize these organizations in August, so the temporary program can be sunsetted soon.

Jodi Daniel provided an overview of the national progress on health IT.   110,000 clinicians have attested to meaningful use.   Numerous initiatives including BlueButton, Decision Support (HealthE Decisions) and a Cancer patient engagement program have been launched.   The trajectory is good.

Finally, Doug Fridsma presented an update on the S&I Framework projects.

We discussed the success criteria for S&I efforts to date.   We agreed that projects should be aligned with policy goals.   We noted that a formal priority setting process is important to allocate limited resources among many competing projects.  HITSC hopes to advise that process, using such tools as the maturity and adoptability criteria for standards to assess the level of effort and cost needed to close standards gaps, enabling ONC to optimize the portfolio of S&I projects.

We'll continue to the S&I discussion at the next meeting.   As the end of ARRA funding nears there is an opportunity to reconsider how best ONC, HITSC, and S&I can work together to guide the work on standards for the United States.

Thursday, July 19, 2012

Our Cancer Journey Week 30

Today Kathy visited her oncologist to discuss a 5 year course of anti-estrogen (tamoxifen) therapy.    I've said before that Cancer is chronic disease and although the first phase of our journey ends on July 31 after 8 final radiation treatments, the vigilance for reoccurrence and the medications to minimize risk begins thereafter.

Tamoxifen, a competitive inhibitor for estrogen, makes great sense for Kathy because her breast cancer is estrogen receptor positive - estrogen makes it grow.   She'll have to watch for endometrial cancer (The American Cancer Society lists tamoxifen as a known carcinogen, stating that it increases the risk of some types of uterine cancer even though it lowers the risk of breast cancer recurrence) and possible memory changes.   She'll start taking Tamoxifen about 10 days after the end of radiation therapy.

We're preparing to celebrate the end of her treatment phase (chemotherapy, surgery, radiation) and the transition to maintenance and prevention on July 31.    One small complication - having just turned 50, my first ever colonoscopy is scheduled for that day so the champagne may have to wait until August 1.

Starting in August, Kathy's life becomes much easier since she no longer has to commute daily for radiation therapy.    Since Boston has two seasons - winter and road construction - the fatigue of the past 6 weeks has been significantly compounded by sitting in traffic every day for up to 3 hours.

August will be much more settled than the rest of the year thus far.   Treatment will be done, my office schedule will be iighter, my daughter will be away, and our previous home will have closed escrow.   What will we do with all that free time?

Our llama and alpacas will move to Unity Farm the week of August 20 (assuming all our fences are finished, our hay arrives, and the folks transporting the herd will be available).

We just learned that our llama is likely pregnant, so we'll have a mama llama.  The llama gestation period is 11.5 months, so she'll likely have the cria (baby llama) next Summer.   I welcome suggestions for names.   The suggestions I've had thus far are Dolly Llama and Ding Dong (as in 'who put the Mom in Mama Llama Ding Dong?')

This weekend we'll visit the alpaca herd in Maine to learn about toenail trimming, vaccinations, and general health assessment.   I may be an emergency physician but doing procedures on a 150 pound furry camelid will be a learning experience.

After July 31, Kathy will not have another medical appointment until January 29, 2013 when she has a screening mammogram and a followup with her breast surgeon.

Next week will be my last post about this part of the cancer journey.   It has been an emotional, anxiety-filled time for both of us.   We're looking forward to maintaining wellness instead of treating illness.