Showing posts with label electronic health record. Show all posts
Showing posts with label electronic health record. Show all posts

Monday, April 16, 2012

Privacy and Security Considerations for Emerging Health Information Exchanges: Notes from Utah and New York

Earlier this month the Utah Department of Health issued a press release describing a cyber attack on its server, in which hackers removed information for approximately 780,000 individuals. According the Department of Health, the information contained personal records of individuals within the state, including Medicaid and Children’s Health Insurance Plan recipients.

Permutations of this scenario- whether hacking into a computer server, losing a USB key, or a stolen laptop- are all familiar news headlines announcing a security breach of individuals' health and personal information. Human error and human opportunism make it likely that we will continue to see such information breaches in the future, despite steps to mitigate potential security threats.

As states begin to develop legislation and promulgate rules to govern their electronic health information exchanges (HIE), they should carefully balance residual security and privacy risks with the potential promises of a functional HIE when determining policies relating to how a system enters an individual’s electronic health record (EHR) and what portion of the EHR the state enters into the HIE.

Last month, the New York Civil Liberties Union (NYCLU) issued a report, Protecting Patient Privacy: Strategies for Regulating Electronic Health Records Exchange, which articulated numerous privacy, security, and functional concerns with the state’s emerging HIE. Currently, New York employs a blanket consent procedure for record access and enrolls patients of participating providers into the state's regional health information organizations (RHIOs). 

Among numerous concerns, NYCLU’s Report highlights two distinct issues with this approach:

(1) New York does not provide a mechanism for patients to limit sharing stigmatizing sensitive information such as substance abuse records or mental health treatment if they consent to participate in the exchange; and

(2) Although physicians must obtain consent to view patient information in the exchange, participating providers enter patient medical information into the exchange without patient consent and patients cannot opt-out of the record locator system.

The Office of the National Coordinator for Health Information Technology’s HIT Policy Committee has asserted that a form of granular control over health data can protect the confidentiality of narrow categories of sensitive health information while fostering patient autonomy, promoting trust in medical providers, and building confidence in the growing use of HIT. Although too much data segmentation or exclusion options could confuse patients and undermine the purpose of the HIE as a comprehensive record system, some groups, such as the NYCLU, argue that existing state law requires the capacity for granular control over statutorily identified categories of sensitive medical information. This assertion serves as a reminder that each state contains varied protected categories of sensitive medical information as well as different standards defining additional measures relating to sharing and accessing this information. Earlier this month, the New York Department of Health and the New York eHealth Collaborative established the State Health Information Network of New York Policy Committee to examine these and numerous other concerns over the state’s current policies and procedures governing the exchange.

Patients may also be wary of the security of their identifying records available in the HIE registry system, as a breach could reveal both personal information and the entirety of the patient’s medical records that providers have entered into the HIE. A breach of the HIE would not only invade the patient’s abstract notion of privacy over sensitive information, but could also expose the patient to quantifiable concrete harms such as identity theft, fraud, and the costs associated with investigation and mitigation.

Some victims involved in major medical security breaches have asserted that once information such as social security numbers, patient demographic information, and medical records are accessible in a breach, victims face an imminent and continuing risk arising from the security breach itself regardless of whether an outside party has used the information. Currently, some courts have ruled that even where a third party steals media containing patient information, if the victims cannot prove that a third party actually accessed or used the information, then claims for future financial harm arising from a security breach are insufficient to constitute an actionable injury. To address these legitimate concerns, jurisprudence should evolve with the recognition that potential third party use of this information may be difficult to identify and costly to monitor. Further, months may pass following the initial breach before victims notice fraudulent activity, such as in the substantial TRICARE data breach.

State legislatures should remain cognizant of both patients' desire for privacy and their corresponding wish to limit access to sensitive medical information as well as security concerns from both accidental as well as intentional breaches of patient information during the initiation or expansion of the state's HIE .
-Katherine Drabiak-Syed

Wednesday, November 10, 2010

Mercy Health Plan's Medical Data Security Breach Should Inform OCR's Harm Standard

A recent medical data security breach occurring in Keystone Mercy Health Plan and AmeriHealth Mercy Health Plan in Philadelphia lends support to removing the harm threshold written into the Interim Final Rule of HIPAA and the HITECH Act before promulgating the Final Rule. In August of 2009, the Office of Civil Rights (OCR) published the Interim Final Rule with request for comments on breach notification of protected health information (PHI), which set forth additional definitions and standards to relating to the Privacy Section. OCR is expected to issue the Final Rule by the end of this year or early next year.

When OCR published the Interim Final Rule last year, the media jumped on the inclusion of instructing the covered entity responsible for a breach of PHI to perform a risk assessment as a deciding factor of whether or not to disclose the breach to the individuals and the Department of Health and Human Services (HHS). Eight members of Congress expressed their concern by writing a letter to Kathleen Sebelius, noting that the American Recovery and Reinvestment Act (ARRA) that sets forth the statutory mandates relating to privacy of PHI does not include nor imply a harm standard and urged HHS to repeal or revise the harm threshold standard.

Section 13402 of the ARRA states that health care entities must notify the individual when there is an “unauthorized acquisition, access, use, or disclosure of protected health information which compromises the security or privacy of that information.” In order to decide whether a breach compromises the individual’s security or privacy, the Interim Final Rule set forth a risk assessment criteria and translated a “compromise” of security or privacy to mean a “significant risk of financial, reputational, or other harm” to the individual. Problematically, the covered entity is tasked with assessing the risk of harm to determine whether it meets the threshold for disclosing the breach to the individual and HHS. The Interim Final Rule states that the covered entity should consider to whom the information was disclosed, the type and amount of information, and whether the information contained materials relating to potentially stigmatizing health conditions.

The letter written on behalf of eight Congressional representatives clarified that Congress specifically excluded a threshold for harm when promulgating Section 13402. Furthermore, requiring mandatory disclosure serves as a powerful incentive to health care entities to enact strict privacy and security protections to decrease the likelihood of a breach even occurring.

The Keystone Mercy Health Plan and AmeriHealth Mercy Health Plan (MHP) incident is only the latest in a long line of PHI breaches. In late October, the Philadelphia Inquirer reported that a computer flash drive belonging to Keystone Mercy Health Plan and AmeriHealth Mercy Health Plan (MPH) was lost at a community health fair. The flash drive contained the medical record information of over 280,000 Pennsylvanian Medicaid recipients.

Donna Burtanger, Vice President of Communications at MHP, stated that company representatives were trying to use the health plan members’ PHI to personalize service at community health fairs. Burtanger offered the example of when a health plan member visits a church sponsored health fair, the insurance company representative can access the member’s medical record to schedule an appropriate screening test such as a mammogram.

As one article pointed out, MHP assumes that the patients under the plan would want company employees to have and access the patient’s full medical record or bring that sensitive health information into a less secure location such as a community health fair. This situation highlighted the vast discrepancy between how an insurance company and its members would view the risk-benefit calculation of permitting non-essential access of their sensitive medical information.

If a health insurance company such as MHP does not know when its members would not want their information shared, accessed, or transported, it likely would also face a disconnect when attempting to determine potential harm arising from a breach of its members’ PHI and whether that level of harm would require disclosure of the breach.

OCR should consider whether placing a level of discretion in the hands of health care entities given the knowledge of this difference will build the public’s trust of using electronic health information.


--Katherine Drabiak-Syed

Wednesday, April 29, 2009

Genetic Testing and Privacy: Are Our Health Care Policies Adequate?

As a genetics professional who provides genetic testing, I am aware of the fact that many individuals contemplating genetic testing cite insurance and employment concerns as major reasons to forego testing. For that reason, I heaved a sigh of relief on May 21, 2008 when the Genetic Information Non-Discrimination Act (GINA) was signed in to law. First introduced in 1995, at a time when only about 300 genetic tests were currently in use and these for mainly rare diseases, it was called both forward-thinking and premature. Now hailed as the first civil rights law of the new century, GINA will prohibit group and individual health insurers from using a person’s genetic information in determining eligibility or premiums and prohibit employers from using a person’s genetic information in making employment decisions such as hiring, firing, job assignment, or other terms of employment. Guidelines for segregating genetic information from other medical records are expected to be forthcoming.

As I thought more about it, however, I realized that the world has changed rapidly in the 14 years since this bill was first introduced, and that these changes may well undermine the protections that GINA was meant to provide. I see four main threats: 1) more genetic information everywhere, 2) data expansion, 3) genome wide association studies, and 4) electronic medical records.

Under the more information heading, the terms “Genetic information” and “genetic condition” are becoming more difficult to define. We are finding that almost all illness has some genetic component such that making clear distinctions between genetic and non-genetic health information is becoming increasingly meaningless. Under the data expansion category, genetic research has shifted from diseases linked to a single gene (Huntington disease, cystic fibrosis) to more common and complex illnesses characterized by the interactions of multiple genes and environmental factors (asthma, diabetes). There are now over 1500 genetic tests in use and in the not-so-distant future, nearly all health records will include substantial genetic information. Genome Wide Association Studies (GWAS) look for single changes in the hundreds of thousands of base pairs (A,T,C,G) that make up the human genome associated with a particular illness or condition. These conditions may be as serious as breast cancer or as frivolous as what type of ear wax you are prone to develop. These tests are being aggressively marketed directly to consumers and can be ordered on line for less than $400. There is little oversight of the companies marketing these tests and as one who works in the field of genetics, it seems almost criminal to test for one mutation associated with cystic fibrosis out of the more than 1000 known CF mutations and call that information useful in the absence of extensive educational efforts. It may not be long before our patients come to our offices with their printouts from 23&Me and ask to add them to their medical record. The fourth threat may be the shift from paper-based medical records to electronic health records (EHR) with their goal of standardization, compatibility, and ease of transport. In a paper-based system, the greatest protection of individual privacy is chaos, the inability to aggregate a complete record from multiple providers over time. Comprehensive and longitudinal medical records will inevitably contain sensitive information and patients will no longer have the option of selective recall in the sense of “is that depressive episode I experienced in graduate school after being mugged really relevant information for the orthopedist performing my knee surgery twenty years later?” Electronic medical records will make it even more difficult to sequester genetic information.

One other developing trend may also play a role, the refinement of personalized medicine, the ability to target drug therapies customized to each person’s genetic makeup to both improve the effectiveness of current treatments and to reduce side effects. Pharmacogenetic testing is becoming standard practice in selecting drugs and dosages for certain cancers while toxicogenetics, the use of GWAS studies to predict how individuals may respond to certain toxins, is becoming more important in assessing both individual and public health risks. If genetic factors appear to play a role in individual and/or community resistance to flu viruses, who knows what might happen.

Technology moves rapidly while our legislature does not. A bill introduced to fix a problem in 1995 may not be as relevant or as useful in 2009. So while I am still happy that GINA was finally passed, the devil, as they say, is in the details, and it remains to be seen how much protection is actually provided for our patients and their families.

Kimberly A. Quaid, Ph.D.