Wednesday, September 10, 2008

Electronic Prescriptions for Controlled Substances

I've recently been asked about the timeline for the DEA to support the electronic prescribing of controlled substances. The prohibition against prescribing controlled substances is a significant barrier to the adoption of e-Prescribing since it requires a separate workflow to write for Lipitor verses Librium.

The DEA has published a notice of proposed rulemaking (NPRM) and offered a comment period until September 25. The DEA has not specified the timeframe for implementation or next steps after the comment period.

In general, the NPRM describes the requirements for the use of electronic systems to create, sign, dispense and archive controlled substance prescriptions.

From reading the NPRM, it is clear that the DEA has framed the issue around law enforcement, which is appropriate given the mission of the DEA:
"These regulations provide pharmacies, hospitals, and practitioners with the ability to use modern technology for controlled substance prescriptions while maintaining the closed system of controls on controlled substances dispensing; additionally, the proposed regulations would reduce paperwork for DEA registrants who prescribe or dispense controlled substances and have the potential to reduce prescription forgery."

The NPRM contains a description of the business processes required to ensure
1. authentication of the prescriber
2. non-repudiation of the prescription
3. integrity of the record keeping process

Each practitioner must have their identity verified through an in-person identity proofing process before they can use an electronic system to prescribe controlled substances. Entities that may conduct in-person identity proofing of a prescriber include:
1. The credentialing office of a DEA-registered hospital;
2. The State professional licensing Board or State controlled substance authority
that authorized the practitioner to prescribe controlled substances; or
3. A State or local law enforcement office.

In order for a prescriber to access the system and write electronic prescriptions, the practitioner must authenticate using a two-factor authentication process, which means using something that you have (a smart card, token or thumb drive containing a digital certificate) plus something that you know (a strong password). This process will have to be used each time the practitioner wants to sign a controlled substance prescription.

Other requirements include:
1. A two minute timeout on the e-prescribing application, requiring two factor re-authentication to return to the e-prescribing screens after timeout
2. For each prescription, the provider must "check a box" confirming the patient's name, the drug being prescribed, the dosage, the applicable DEA number, and a statement indicating that the practitioner understands that he has reviewed the prescription information and intends to sign and authorize the prescription being transmitted.
3. The prescription must be transmitted immediately and cannot be printed in the future if it was transmitted electronically
4. The eRx system must generate a log of all controlled substance prescriptions which the provider must review monthly. Logs must be kept for 5 years
5. Electronic prescriptions of controlled substances cannot be converted to non-electronic form, such as faxes, at any time.

Given the impact of the NPRM on providers, pharmacies, intermediaries (such as Surescripts/Rxhub) and vendors, I am sure there will be many comments made before September 25. Check out the testimony of Paul L. Uhrig, EVP Corporate Development,
General Counsel, & Chief Privacy Officer of Surescripts/RxHub. After the comment period closes, I would guess that we'll have a year before a final rule is published. One the one hand, I want to accelerate e-prescribing by creating a seamless electronic workflow for all medications. On the other, I am not looking forward to supporting tokens, smartcards, and other forms of two factor authentication.

Tuesday, September 9, 2008

Delayed and Embargoed Results on PatientSite

Today I was asked about the way we display results in our personal health records and the way we transmit results to personal health record services like Google Health and Microsoft Healthvault.

In general we share everything with the patient immediately, since it is the patient's data.

However, from our 7 years of supporting personal health records through Patientsite, we've learned that some news is best communicated in person between doctor and patient i.e. do you want to find out you have cancer on the web or via a thoughtful discussion with your doctor?

Here are the reports we delay to enable discussion between doctor and patient to occur first. In the case of HIV testing, since special consents are required, we do not show the results in Patientsite at all.

CT Scans (used to stage cancer) 4 days
PET Scans (used to stage cancer) 4 days
Cytology results (used to diagnose cancer) 2 weeks
Pathology reports (used to diagnose cancer) 2 weeks

HIV DIAGNOSTIC TESTS: Never shown
• Bone Marrow Transplant screen, including
HIV-1, HIV,2 Antibody
HTLV-I, HTLV-II Antibody’
NHIV (Nucleic Acid Amplification to HIV-I
• HIV-1 DNA PCR, Qualitative
• HIV-2, Western Blot. Includes these results:
HIV-2 AB, EIA
HIV-2, Western Blot
• HIV-1 Antibody Confirmation. Includes these results:
Western Blot
Anti-P24
Anti-GP41
Anti-GP120/160

I hope these rules help others who are implementing personal health records. We want the patient to own and be the steward of their own data, but we also want to support the patient/doctor relationship and the notion that bad news is best communicated in person.

Monday, September 8, 2008

Social Networking for Research

On September 4, a group of collaborators at Harvard launched a new website called Catalyst that is publicly available. I encourage you to visit it.

This site is remarkable in many ways. It brings together all the people, lifelong learning, and resources for the Life Sciences across Harvard and its affiliates.

In the People area, you'll find social networking for the research community called Profiles. . It not only shows traditional directory information, but also illustrates how each person is connected to others in the broad research community.

When you view a person's profile, three types of information are displayed:

1. Managed Descriptions
This is the typical information listed in a research profile, including name, titles, affiliation, phone number and email address. Faculty can edit their own profiles, adding publications, awards, narrative, and a photo.

2. Passive Networks
Passive networks are formed automatically when faculty share common traits such as being in the same department, working in the same building, co-authoring the same paper, or researching the same topics (as defined by the "MeSH" keywords assigned to their publications). The passive networks a person belongs to are shown on the right side of the page when viewing a profile.

3. Active Networks
Active networks are the ones that users define by choosing collaborators, advisors, or advisees. Currently, users can manage their own networks. In the future they will be able to share these lists with others.

The website is open to the general public. However, people with a Harvard Medical School login can access additional features, such as "active networking", described above.

All data shown by default on the website is currently available on other public websites, but Profiles integrates the data in novel ways. Directory information was obtained from the Harvard Whitepages, and publications and keywords were copied from PubMed. If faculty had previously entered awards and narratives in the Faculty Affairs CV/Promotion management application called FIRST, then that information can be displayed on this website, but only if those faculty approve it. Default photos are from Harvard IDs, but faculty must also approve the use of those before they are shown on this website. Lists of co-authors and similar people are derived automatically from publications, and the "department" and "neighbor" lists are determined automatically from directory information.

Keywords, co-authors, and list of similar people are derived automatically from the PubMed articles. Keyword rankings and similar people lists are based on complex algorithms that weigh multiple factors, such as how many publications users have in a subject area compared to the total number of faculty who have published in that area.

Breaking down silos in the research community at Harvard via social networking is a great first step toward catalyzing research acceleration. You'll see many new features and functions on this new website over the next year, so stay tuned!

Friday, September 5, 2008

Cool Technology of the Week

Today, I received several requests from customers and other stakeholders to meet with me. Some send Outlook invitations, some call my assistant, some send email, and some propose times without checking with anyone. I'll be honest that Outlook invitations just do not work with my schedule, since I'm usually in five or more different locations each day and Outlook invitations can schedule me in Boston from 1pm-2pm and Washington DC from 2pm-3pm.

Since Outlook invitations, random proposed times, and constant back and forth among assistants can be problematic, is there a create IT solution to help with scheduling a meeting?

Dave deBronkart, the famous e-Patient Dave, works for TimeTrade, which makes enterprise-scale appointment systems for scheduling driving tests with the Department of Motor Vehicles, counseling with financial advisors and even sessions with PetCo pet groomers.

Dave has used their TimeDriver product (free for 90 days, then minimal advertising is included or you can buy a license) for people to pick an open time slot in his Outlook calendar without the usual back-and-forth i.e. Dave ends every email with

To schedule time with me, click here: 15 min 30 min 60 min

showing the timeslots that folks could simply self schedule into his day for conversations, customer service, or followups. Admittedly, Dave's use of the application is novel and not precisely the original design idea of TimeDriver, which was to support eMarketing appointment timeslot scheduling.

It's a cool idea that is a kind of self service social networking application for appointment scheduling.

I like this concept a great deal, since I'm a real fan of web-based self service applications. It will be interesting to see if large enterprises which want to improve their workflow can integrate this kind of technology into their personnel "appointmenting" processes.

Thursday, September 4, 2008

The Wellesley Recycling Mystery

I've written about the Wellesley Recycling and Disposal facility where we recycle nearly 90% of our solid waste as a community.

Each week when I visit the RDF to sort my recycling, I find a 25 foot mass of thin tissue paper in the mixed paper area. It's a mountain of paper and a new supply shows up every week. It's been perplexing.

Could there be a manufacturing plant in Wellesley that uses tissue for packing and shipping? Could this be the by product of some cleaning operation?

I just could not figure it out, so I asked.

The great folks at the Wellesley RDF gave me tour of the paper and cardboard area, pointing out a large number of empty Captain Crunch cereal boxes in the cardboard section.

How could I relate a mountain of paper and Captain Crunch cereal boxes to solve this mystery?

Then, it dawned on me - the Blue Man Group recycles in Wellesley.

For those who have not been to been a Blue Man Group performance, it involves large quantities of twinkies, marshmallows, and Captain Crunch cereal. The finale involves filling the theater and audience by unwinding rolls of tissue paper.

It's great to know that all that paper is recycled and reused. Who would have known that the Blue Men spend their Saturdays recycling!

Mystery solved.

Wednesday, September 3, 2008

Going live with Microsoft Healthvault

Last week, Beth Israel Deaconess went live with Microsoft Health Vault, just as we went live with Google Health last May. Like Google Health, using it is completely optional and patient controlled.

The code to link BIDMC medical records to Microsoft is a subtle variation of the code we used for Google Health. It leverages the same standards and required very little additional work. Here's how it works.

Patients using our Personal Health Record, Patientsite, just click on Microsoft Health Vault in the Patientsite Navigation Bar (screen capture above). They then link their Microsoft Passport credentials with their Patientsite account using the Healthvault login screen. Once this is done, Patients can choose to upload their problem lists, medications, and allergies to Healthvault, enabling patients to maintain their own lifetime health record on the Microsoft site. At any time, patients can deactivate the link to Healthvault and remove their information.

This initiative is part of my ongoing commitment to provide BIDMC EHR data to Personal Health Records such as Google, Microsoft, and Dossia so that patients can be the stewards of their own data and can exchange data with caregivers per their own privacy preferences.

Here's our press release about the effort.

BOSTON – Beth Israel Deaconess Medical Center (BIDMC) is expanding options for users of its secure PatientSite portal by joining forces with Microsoft HealthVault to offer a new way to safely exchange medical records and other health data.

The affiliation follows an earlier commitment to offer a similar service through Google Health.
“We believe that patients should be the stewards of their own data,” says John Halamka, MD, BIDMC’s chief information officer. “BIDMC’s PatientSite is wonderful if all care is delivered at BIDMC. However, many patients have primary care doctors, specialists, labs, pharmacies, and non-traditional providers at multiple institutions.

“Our vision is that BIDMC patients will be able to electronically upload their diagnosis lists, medication lists and allergy lists into a HealthVault account and share that information with health care providers who currently don’t have access to PatientSite.”

PatientSite, which currently has more than 40,000 patient users and 1,000 clincians, enables patients to access their medical records online, securely email their doctors, make appointments, renew medications and request referrals.

HealthVault is designed to put people in control of their health data. It helps them collect, store and share health information with family members and participating health care providers, and it provides people with a choice of third-party applications and devices to help them manage things such as fitness, diet and health.

HealthVault also provides a privacy- and security-enhanced foundation on which a broad ecosystem of providers – from medical providers and health and wellness device manufacturers to health associations – can build innovative new health and wellness solutions to help put people in increased control of their and their family’s health.

“The end result will be when patients leave the BIDMC area or see a provider outside the area they can have all their medical data located in one safe place,” adds Halamka.

Microsoft HealthVault can be found on the web at http://www.healthvault.com/

Tuesday, September 2, 2008

Complex Issues Rarely Have Absolute Right Answers

Listening to Obama and McCain you realize that some issues have no absolute right answer. Pro-Life v. Pro-Choice, Pro-Gun v. Anti-Gun, Less Government v. More Government etc. Everyone has an opinion and often the emotions run high.

The same thing is true about healthcare data standards and interoperability, although the stakes are a bit lower than life and death issues.

Recently folks have asked me to comment about Carol Diamond and Clay Shirky's article in Health Affairs which contains potentially controversial statements such as:

"The Office of the National Coordinator for Health Information Technology established the Health Information Technology Standards Panel (HITSP) to harmonize and designate health information standards and the Certification Commission for Health Information Technology (CCHIT) to certify vendor products three years ago. These efforts deserve praise for increasing public and industry interest in health IT and for encouraging adoption of technical standards. Yet after three years of standards documentation and the resolution of several standards 'disputes,' we remain a long way from seeing these standards used and implemented to enable health information sharing. As Sam Karp of the California HealthCare Foundation stated in his testimony to the Institute of Medicine Board on Health Care Services and National Research Council Computer Science and Telecommunications Board, 'Not a single data element has been exchanged in real world health care systems using standards this process has developed or deployed.' He went on to state that 'greater emphasis is placed on ideal standards and less on what can be feasibly implemented in the short-term—hence three years of work, millions of dollars spent and little real progress toward interoperability.' " (Sam Karp, California HealthCare Foundation, Review of the Adoption and Implementation of Health IT
Standards by the Office of National Coordinator for Health Information Technology, Testimony before the Institute of Medicine Board on Health Care Services and the National Research Council Computer Science and Telecommunications Board, 17 September 2007, http://www.chcf.org/documents/healthit/KarpITAdoptionIOM.pdf )

I did not find Carol and Clay's article controversial. Both are good friends of mine and I agree with their thesis that technology is not enough to ensure successful interoperability. We need to agree on appropriate policies to protect privacy, incentives for implementation, and justifications for continued use of technologies to ensure widespread adoption.

What about Sam's comments? Sam Karp and Walter Sujansky, who works closely with CHCF on their standards projects are also good friends.

Per Sam's comments, should we approach healthcare data standards by making incremental improvements to the status quo or create a blueprint for the ideal and then implement that in a phased way?

Although far less controversial from a philosophical and religous standpoint than the Obama/Mcain issues I've mentioned above, there is no obvious right answer to this question, just opinion.

Sam's point is that incremental additions to the status quo move us forward without the controversy of major change.

I've used Sam's approach for some projects and it's worked. However, the risk of stepwise improvement on the status quo is analogous to a house remodel. Sometimes you end up with a less than perfect floor plan by adding a room here, a staircase there, and a door in anticipation of a future need.

What HITSP has done, which is a reasonable approach in my opinion, is to articulate a vision for a very good endpoint, then work with HHS, AHIC and ONC to implement that endpoint in phases. It's like creating the blueprint for a whole house and then building at the pace your budget allows. The end result will be a logical floorplan, but it will take a bit of time to implement it all.

For example, CCHIT has created functional criteria for e-Prescribing, lab, and read-only clinical summary exchange for this year. Next year, functional criteria will include additional lab details and import of clinical summaries based on HITSP interoperability specifications. The year after, even more will be required.

Implementation of HITSP interoperability specifications for healthcare is similar to BluRay for home entertainment. The stakeholders have decided that BluRay is the preferred format, yet few households actually have BluRay. In the next few years, it will be more common. BluRay is not an incremental improvement, it's a new endpoint that requires replacement of existing DVD players over time.

When Sam Karp made his comments in September of 2007, few HITSP interoperability specifications were in production, because they were not finalized and recognized by Secretary Leavitt until January 2008.

At this point in September 2008, thousands of transactions occur every day using HITSP interoperability specifications. The Massachusetts RHIO uses HITSP's C32 for exchange of clinical summaries among hospitals, BIDMC uses C32 to exchange clinical summaries with the social security administration, and Kaiser is implementing all the HITSP lab specifications in support of its 9 million patients etc.

I want to thank Carol, Clay, and Sam. They're moving us forward.

Every day, healthcare IT and interoperability gets a bit better. There are no absolute right answers, but step by step, all stakeholders are narrowing the optionality in standards, enhancing policy, and implementing pilots.

My tenure as chair of HITSP lasts another year. In the next year, I look forward to working with all our national stakeholders as we change administrations in Washington, continue to implement new interoperability specifications, and assist payers/providers/vendors/patients with implementation of the work HITSP has done thus far through our education and outreach efforts. It will be a great journey for us all.