Tuesday, 19 April 2011

Mobile Applications for Medical Education

Every year in April, we survey the HMS medical students about their use of mobile devices.

At HMS, we encourage students to buy the device of their choice - iPhone/iPod/Ipad, Android, Blackberry, Kindle etc.  We then support these devices with software licenses and controlled hosted applications.  

Our Mycourses Learning Management System has a Mobile Applications tab.  Under General Resources, we offer a mobile version of all course content via connected devices (WiFi, 3G etc.).   We also offer a Kindle version for downloading course content to the device.

On our Mobile Resources page, we offer downloads of many popular applications.  Most include native iPad support.

What are the most popular in 2011?

Dynamed - a clinical reference tool created by physicians for physicians and other health care professionals for use primarily at the 'point-of-care' .

Unbound Medicine uCentral - a collection of popular titles including 5 Minute Clinical Consult, A to Z Drug Facts, Drug Interaction Facts (an interaction checker), Review of Natural Products,Medline Table of Contents Alerts, and Medline Auto Alerts.

VisualDx Mobile - a visual decision support tool. VisualDx merges medical images with a problem-oriented findings-based search.

Epocrates Essentials  - an all-in-one mobile guide to drugs, diseases, and diagnostics which includes Epocrates Rx Pro, Epocrates SxDx, and Epocrates Lab.

iRadiology -  a compendium of over 500 unique images demonstrating classic radiological findings.

I'll post the complete survey for 2011 soon.

Monday, 18 April 2011

The Attestation Experience

This morning at 8am the CMS attestation website went live.

At 8:30am, I completed the attestation for Beth Israel Deaconess Medical Center.

Here's an overview of the experience.

At the top of the Attestation page, you'll see the link "Click here to attest."

Once in the Medicare & Medicaid EHR Incentive Program Registration and Attestation System you need to choose Eligible Hospitals or Eligible Professionals.   I chose Eligible Hospitals and logged in with the same user ID and password we used to register BIDMC.

1.  You're asked to enter your EHR Certification Number from the Office of the National Coordinator.  This is an interesting concept, because the EHR Certification number is not the same as the Certified Healthcare IT Product List (CHPL) Product number assigned during the certification process.  For example, the BIDMC Online Medical Record was assigned a CHPL Product Number of CC-1112-549900-1 during the CCHIT EACH certification process.

To obtain an EHR Certification Number, go to the CHPL Website.

Click on Ambulatory or Inpatient.   I clicked on Inpatient.

I searched by product name for BIDMC's "Online Medical Record".

I clicked Add to Cart.   Do this for all the products you need to meet 100% of the Certification Criteria.  Note that there is a bug in the CHPL page.  See Keith Boone's blog for the workaround.

Once you've achieved 100% of the required criteria, you can click on "Get CMS EHR Certification ID" in the View Cart area.  I was assigned a CMS EHR Certification ID of 30000001TMQOEAC

2.  Next you must specify if you've chosen to count all ED visits or use the "observation services" method for calculating ED visits. This includes ED patients admitted to inpatient or observation services and excludes ED patients discharged from the ED.  We used the observation services method.

3.  Next you attest to the Core Criteria.  Here's a copy of my completed submission.   Of interest, no patient requested an electronic copy of their discharge instructions or an electronic copy of their lifetime record.   Our software has the ability to generate these, but since no patient asked for them during the reporting period, the denominator was zero and no numerator needed to be reported.

4. Next you attest to the Menu Set Criteria.  Here's a copy of my completed submission.   We've tested immunizations transactions with the Department of Public Health sent via secure FTP.  We've tested lab results and syndromic surveillance with the Boston Public Health Commission sent via NEHEN.   Formulary enforcement is included in all our ordering systems.   We have numerous screening sheets and business intelligence tools that generate patient lists based on clinical criteria.

5. Next you attest to the 15 hospital quality measures.  Remember that the ED measures include stratifications for admitted, observation, and psychiatric patients.  The numerators of the ED measures are times measured in minutes.  For all other quality measures you must provide numerators, denominators and exclusion measures using patient counts.   In 2012, CMS will require these measures to be submitted electronically using PQRI XML.   I look forward to the automation of this step, since manually entering more than 50 numbers accurately was challenging.

6. Once you've completed the core, menu set, and quality measures, you're asked to answer a series of questions attesting to the accuracy of your submissions and your authority to perform the attestation.

If you've met all the criteria successfully, your attestation is approved and a submission receipt page appears (the graphic above). Print or save this receipt since it is not emailed to you.

That's it.  It should take 30-60 minutes to complete if you have all your data handy.    I welcome comments on the attestation experience of others so that the Healthcare IT Standards Committee Implementation Workgroup can provide input as Stage 2 is planned.

Friday, 15 April 2011

Cool Technology of the Week

This week's cool technology is not about any specific hardware or software, but is about a trend.

Mobile technology for healthcare is fast replacing desktops and laptops in many settings.

As of this morning, there are 1600 iPhones and 300 iPads connected to the BIDMC network, using our administrative and clinical applications.   These were all purchased by individual clinicians and staff to enhance their productivity.   All we do centrally is provide the server components to access applications (web servers, citric, active synch) and enforce mobile device security polices.

Mobile devices for healthcare are becoming increasingly important at the bedside, in the home, and in hostile environments.

Here's a YouTube video illustrating how the Medical Communications for Combat Casualty Care (MC4) handheld is used to record patient encounters on the battlefield.

Given the increasing prevalence of Traumatic Brain Injury (TBI) in the military due to powerful explosive devices the Army is using handhelds to track and treat personnel with TBI.

The Army is piloting iPads/iPhones/iPods, Android devices, and Windows Smartphones for training.

There's speculation that the military may issue a smartphone to ever solider.

Some IT leaders consider mobile computing to be a burden and distraction - a wild west of client devices brought in by customers demanding new services.   The reality is that CIOs should develop a mobile device strategy assuming that tablets, smartphones and laptops will replace desktops in many settings.  By defining security policies and providing server side applications, IT organizations can become mobile device enablers and leverage the momentum created by users who are investing their own time and resources to make them work.

Mobile devices purchased and supported by users, connected to standardized central services.   That's cool!

Thursday, 14 April 2011

Medicare EHR Incentive Program Attestation To Begin on Monday

On April 18, 2011, attestation for the CMS Medicare Electronic Health Record (EHR) Incentive Program begins. The Medicare EHR Incentive Program Attestation System will be available to eligible professionals (EPs), eligible hospitals and critical access hospitals (CAHs) on that date, enabling the next step in the process for EPs and hospitals to qualify for the Medicare EHR Incentive Program. Once EPs and hospitals successfully attest through the online system, they will then be able to receive Medicare incentive payments from CMS.  I will spend Monday completing the attestation for BIDMC.

CMS has created several resources that will help EPs and hospitals successfully navigate the attestation process, which can currently be found on the CMS EHR Incentive Programs website. CMS is developing a dedicated attestation section on this website, which will be launching Monday.

Sign up for CMS’ EHR listserv updates to receive timely information and updates about the EHR Incentive Programs.

I'll let you know how it goes on Monday!

1951 HZ

I drive a 2005 Prius that just crossed the 100,000 mile mark.   My total cost of owning the car has been very low.  My mileage has averaged 50mpg.   I'm very satisfied.

In Masaschusetts, license plates from 2005 are of the form  xxxx yy.  My license plate 1951 HZ is purely random.   Recently, someone with a musical bent asked me:

"You're a thoughtful person.  I'm sure your personalized license plate has some profound meaning.   What subtle and amazing thing happens at a frequency of 1951 Hertz (HZ)?"

Ok, I need some help here.   I've done my best to search the web for phenomenon that occur between 1900 and 2000 Hertz.   Here's what I've found so far:

*It's a common form of audio tone remote control  from the 1970s.

*It's a common frequency of frog mating calls.

*It's the frequency of the humpback whale grunt.

*It's the frequency of alveolar nasal consonants (such as when you say "mmmmm").

*It's a point in the audio spectrum used to analyze noise induced hearing loss.

Ok, so far, my profound license plate has me
1. walking into a swamp and asking some wayward frog to hop down to my place
2. getting the attention of a distracted humpback whale
3. having my nasal consonants misunderstood by folks who frequent rock concerts.

I welcome your help - my car needs a sublime story as to why 1951 HZ says something about me, the human condition, or the natural world.   Comments welcome!

Wednesday, 13 April 2011

The Care Connectivity Consortium

On April 6, five healthcare organizations announced the Care Connectivity Consortium to accelerate interoperability activities in the US.   Mayo Clinic, Geisinger, Kaiser Permanente, Intermountain Healthcare and Group Health will share patient identified data in real time using Nationwide Health Information Exchange gateways (NwHIN Exchange) incorporating national and international standards.

Each organization will decide how to support NwHIN Exchange transport specifications independently.  Some may choose to implement the Open Source Connect gateway.  Others will implement their own solutions. For example, Kaiser has a self-developed gateway in production.

Initially, content will include problem lists, medication lists, and allergy lists.   The next phase will include laboratories, vitals, immunizations, and other content.  Of course, if organization sends more than the minimum required content, the others will be capable of receiving it.  They plan to use the same Clinical Document Architecture (CDA) implementation specifications as the VA/DOD Virtual Lifetime Electronic Record (VLER) project.

In addition to supporting healthcare information exchange for clinical care, they will implement a patient-chosen portable ID, similar to the HealthURL concept I've discussed.

They will also adopt a common Data Use and Reciprocal Support Agreement.

The five organizations share very few patients in common, so the real benefit is that they are implementing efficient, standard health information exchange methods that are extensible to organizations which do share significant numbers of patients.

If they work out standards-based, secure methods for sharing information among themselves, those methods would then be attractive to and implementable by other organizations with fewer resources for development and become usable, useful, de facto standards for information sharing.

I look forward to their progress.  When five major institutions across the country implement common policy and technology for healthcare information exchange, we'll achieve a tipping point and others will rapidly follow.

Tuesday, 12 April 2011

The RSA Attack

I've worked with RSA Security since my days as an informatics fellow when I first used SecurIDs as part of my early health information exchange work.

Just as I was transparent about the CareGroup Network Outage in 2002, RSA has shared all the details of their recent security breach.

It all started with a well crafted phishing email to a non-technical staff member with the subject line “2011 recruitment plan”.

Attached to the email was an excel spreadsheet that contained an exploit for a known vulnerability in Adobe Flash.

The exploit installed a hard-to-detect remote administration tool named Poison Ivy on at least one RSA computer.   The end result was that an attacker gained access to the RSA network.

The attackers moved from system to system harvesting accounts until they came across those users who had highly privileged access to sensitive systems and data.

An internal staging system was “created” to collect, encrypt and transmit back up lists of usernames/passwords to systems.

Confidential material related to SecurID technology was FTPed to a remote site.

The attackers have not been identified.

The attack was remarkably sophisticated and illustrates the evolution of cybercrime over the past 10 years.    Here are the 4 principal stages:

1st Generation – Because I can
Worms, defacement of web sites

2nd Generation – I can make money
Botnets appear, denial of service attacks, seeking payment to stop attacks

3rd Generation – Organized crime
Large scale management of attacks, coordinated use of tools and techniques, trojans, worms Phishing, targeted attacks

4th Generation – Selling the tools
Tools to perform attacks become “vended” with 24/7 support available, Botnet rentals, sophisticated Id theft services, Licensed Malware appears, Exploit knowledge is sold.  Social Networks just for cybercriminals appear.  Cybercrime supply chains are formalized and fine tuned.

I've described security as a Cold War - the faster we implement protections, the faster the cybercriminals innovate.

Thanks to RSA for sharing their experience with the rest of the industry.
Girls Generation - Korean