Showing posts with label medical records. Show all posts
Showing posts with label medical records. Show all posts

Monday, April 16, 2012

Privacy and Security Considerations for Emerging Health Information Exchanges: Notes from Utah and New York

Earlier this month the Utah Department of Health issued a press release describing a cyber attack on its server, in which hackers removed information for approximately 780,000 individuals. According the Department of Health, the information contained personal records of individuals within the state, including Medicaid and Children’s Health Insurance Plan recipients.

Permutations of this scenario- whether hacking into a computer server, losing a USB key, or a stolen laptop- are all familiar news headlines announcing a security breach of individuals' health and personal information. Human error and human opportunism make it likely that we will continue to see such information breaches in the future, despite steps to mitigate potential security threats.

As states begin to develop legislation and promulgate rules to govern their electronic health information exchanges (HIE), they should carefully balance residual security and privacy risks with the potential promises of a functional HIE when determining policies relating to how a system enters an individual’s electronic health record (EHR) and what portion of the EHR the state enters into the HIE.

Last month, the New York Civil Liberties Union (NYCLU) issued a report, Protecting Patient Privacy: Strategies for Regulating Electronic Health Records Exchange, which articulated numerous privacy, security, and functional concerns with the state’s emerging HIE. Currently, New York employs a blanket consent procedure for record access and enrolls patients of participating providers into the state's regional health information organizations (RHIOs). 

Among numerous concerns, NYCLU’s Report highlights two distinct issues with this approach:

(1) New York does not provide a mechanism for patients to limit sharing stigmatizing sensitive information such as substance abuse records or mental health treatment if they consent to participate in the exchange; and

(2) Although physicians must obtain consent to view patient information in the exchange, participating providers enter patient medical information into the exchange without patient consent and patients cannot opt-out of the record locator system.

The Office of the National Coordinator for Health Information Technology’s HIT Policy Committee has asserted that a form of granular control over health data can protect the confidentiality of narrow categories of sensitive health information while fostering patient autonomy, promoting trust in medical providers, and building confidence in the growing use of HIT. Although too much data segmentation or exclusion options could confuse patients and undermine the purpose of the HIE as a comprehensive record system, some groups, such as the NYCLU, argue that existing state law requires the capacity for granular control over statutorily identified categories of sensitive medical information. This assertion serves as a reminder that each state contains varied protected categories of sensitive medical information as well as different standards defining additional measures relating to sharing and accessing this information. Earlier this month, the New York Department of Health and the New York eHealth Collaborative established the State Health Information Network of New York Policy Committee to examine these and numerous other concerns over the state’s current policies and procedures governing the exchange.

Patients may also be wary of the security of their identifying records available in the HIE registry system, as a breach could reveal both personal information and the entirety of the patient’s medical records that providers have entered into the HIE. A breach of the HIE would not only invade the patient’s abstract notion of privacy over sensitive information, but could also expose the patient to quantifiable concrete harms such as identity theft, fraud, and the costs associated with investigation and mitigation.

Some victims involved in major medical security breaches have asserted that once information such as social security numbers, patient demographic information, and medical records are accessible in a breach, victims face an imminent and continuing risk arising from the security breach itself regardless of whether an outside party has used the information. Currently, some courts have ruled that even where a third party steals media containing patient information, if the victims cannot prove that a third party actually accessed or used the information, then claims for future financial harm arising from a security breach are insufficient to constitute an actionable injury. To address these legitimate concerns, jurisprudence should evolve with the recognition that potential third party use of this information may be difficult to identify and costly to monitor. Further, months may pass following the initial breach before victims notice fraudulent activity, such as in the substantial TRICARE data breach.

State legislatures should remain cognizant of both patients' desire for privacy and their corresponding wish to limit access to sensitive medical information as well as security concerns from both accidental as well as intentional breaches of patient information during the initiation or expansion of the state's HIE .
-Katherine Drabiak-Syed

Friday, August 8, 2008

Medical Records, Insurance and Prediction: GINA Will Not Keep this Fox Out of the Henhouse

In a recent Washington Post article (4 August 2008), "Prescription Data Used to Access Consumers", Ellen Nakashima writes about the availability of medical records for data mining. Insurance companies have begun to use databases of prescription records to assess the risks of insuring individuals or when deciding to pay for a treatment. For example, a report could show that an "individual has been on the highest does of the cholesterol-reducing drug Zocor for 18 months" and an insurance company could determine that the patient has "a very high, near-intractable cholesterol problem … and could avoid a costly blood test". The article also points out that these records are more honest than many applicants for insurance and could reduce the cost of insurance while facilitating faster decision making. While HIPAA stipulates that patient consent must be acquired before these records can be accessed, "HIPAA does not give the Department of Health and Human Services the ability to directly investigate or hold accountable … pharmacy benefit managers". Nakashima reports that the increasing availability of electronic records will result in a market in which data mining organizations compete to sell the most complete and cheapest sources of patient data to insurers. Joy Pritts, of the Georgetown University Health Policy Institute observes that "Most people don't even know these organizations exist . . . ." Privacy consultant, Bob Gellman notes that "consumers will likely continue to have no real meaningful choices if they want insurance". Richard Dick, a database designer, suggests better privacy tools for consumers which would allow patients to be more specific when consenting to release medical information, "Otherwise … you have the fox in charge of the henhouse".

I want to know what incentives motivate patients to consent to release this information in the first place. I'm guessing that insurance coverage may depend upon consent; if so, is this real "consent"? – J.O.

Monday, June 23, 2008

Curating Your Personal Genome?

When a member of the PGP-10 and an investor in 23andMe writes about curating one's online, personal data, a lot of people listen. Unfortunately, Esther Dyson (writing in MIT's Technology Review) does not mention the decision to share medical information or how she plans to curate her own genomic data online. Dyson rightly notes that "current website 'privacy' policies don't suffice. They're full of abstractions, euphemisms, and generalities, such as, 'We may, at any point in time, provide certain Specified Information to selected Marketing Partners ... .'" She appears to favor a complex, itemized consent policy, one that would allow users to opt in or out of sharing specific categories of information (user name, address, credit history, etc.) with a list of potential users (advertisers and other companies).

Imagine a similar consent for medical records sharing. For example, could someone like Esther consent to share her genome with a 23andMe social network, but not with researchers in this network? Or, perhaps, Esther could chose to share some of her genomic information, but not all of it. Then, again, maybe Esther would be willing to share her prescription history with an academic researcher, but not with pharmaceutical companies. The options could go on and on, resulting in an increasing complex array of choices.

Esther Dyson is obviously a very sophisticated information agent, but (as the opportunity to share medical information online increases) will the average user and patient be prepared to make informed decisions about the risks and benefits of participating? - J.O.

Monday, March 31, 2008

Best Predictive Health Ethics Blogs - March, 2008

See February and January 2008 for prior reviews of the best predictive health ethics blogs. I have limited this month's installment to the ten posts. If, after reading these, you believe I've omitted a good post, please let me know. This month's blogs (listed chronologically) include some familiar names and a couple of new ones, including: Adventures in Ethics and Science, Synthesis, and Genetics & Health.

CF "success" story. Steve Murphy, Gene Sherpas. 1 March 2008.
Steve Murphy of Gene Sherpas seldom shies away from an ethical issue. Thus, when the NEJM reported the good news that "The number of infants born with cystic fibrosis in Massachusetts decreased by 50% from one four-year period to the next" (MedPage Today, 28 February 2008). Murphy acknowledged the upside, "children born with CF in the future may actually have less significant disease and may need to have less aggressive or less early interventions". He reminds us, however, that some doctors and patients now face heavy decisions:

The number of infants born with cystic fibrosis in Massachusetts decreased by 50% from one four-year period to the next according to this letter in the NEJM. They attribute this to the Newborn screening available in Massachusetts since 1999. … But here's what they don't say.....Preconception screening for this disease is important, but a highly personal choice. ... despite what the ACMG and ACOG say. There are some children who are doing just fine with CF. As for adults with CF like the 74 year old patient who I diagnosed a few years ago, I am certain they would not want to have never been born.

Should Researchers Share Data? Janet D. Stemwedel, Adventures in Ethics and Science. 3 March 2008.
Janet Stemwedel of Adventures in Ethics and Science comments on the widely discussed Andrew Vickers essay in The New York Times – "Cancer Data? Sorry, Can’t Have It" (22 January 2008). Stemwedel does an excellent job of highlighting the importance of data sharing for the success of translational research. She also acknowledges the research subject's contribution to this research and the exposure to risk that they have assumed. Stemwedel writes:

[R]isk is supposed to be offset by the benefits of the knowledge gained from the research. If that data sits unanalyzed, the benefits of the research are decreased and the risks undertaken by the human subjects are harder to justify. Moreover, to the extent that sitting on data instead of sharing it requires other researchers to go out and get more data of their own, this means that more human subjects are exposed to risk than might be necessary to answer the scientific questions posed in the research.

How Private is Private? Is Google a covered entity? Cheryl Lew, Women's Bioethics Blog. 4 March 2008.
After observing that HIPAA was not written with Google's emerging patient managed, personal health records in mind, Cheryl Lew of Women's Bioethics Blog wonders if additional government protections might be required. Lew writes:

[W]ill Google patients be subject to advertising spam or other intrusive advertisement adduced from their prescription lists? What guarantees that the “client” (read patient lists) won’t be sold to Pharma companies as yet another means of developing data bases about physician prescribing patterns? Who is going to regulate these issues? Google is a great search engine—I use it all the time! But I’m not sure I want to use it to manage my healthcare information.

Genomes of the Rich and Famous. Jesse Reynolds, Biopolitical Times. 5 March 2008.
Reacting, in part, to "Gene Map Becomes a Luxury Item" (Amy Harmon, The New York Times. 4 March 2008), Reynolds was the only blogger that I know about that picked up on the irony in drive towards celebrity genomics. Reynolds observes:

The prospect of biotechnology companies capitalizing on genetic information in order to develop profitable products without properly compensating the studied populations brings to mind biocolonialism, in which politically and economically vulnerable indigenous groups are exploited. But a growing convergence of genomics and information technology may lead, ironically, to the genetic "exploitation" of society's most elite.

The moral manipulation of Gattaca. Daniel MacArthur, Genetic Future. 6 March 2008.
Daniel MacArthur of Genetic Future is becoming a regular here in the "best ethics blogs" series. This month MacArthur introduces (with help from Black Belt Bayesian) us to an essay on one of the favorite films for bioethics classrooms—Gattaca:

A man is given strong medical evidence that he will die from a heart attack if exposed to the exertions of space travel, thus risking how own life and the lives of his crewmates. Ignoring this evidence, he fakes his way into astronaut training - and inexplicably, we cheer him on. How did the makers of Gattaca steer us towards this bizarre response?

The full essay, by Neven Sesardic and forthcoming in The Routledge Companion to Philosophy and Cinema, 2008, is available online: Gattaca (PDF – 209 KB).

Genetic testing - ‘recreational genomics’ or the future of diagnostics? Elaine Warburton, Genetics & Health. 18 March 2008.
Reacting to editorials in The New England Journal of Medicine and The British Medical Journal, Elaine Warburton of Genetics & Health acknowledges the limitations of the current methodologies, but notes that "introducing innovative genetic testing technology has to start somewhere". Warburton observes that 23andMe and other genomics companies are taking "huge financial and clinical risk[s] in bringing these tests to market". Warburton sees the uncertainty involved as merely a part of the ongoing cycle of research and development:

The tests are in their infancy and each of these companies are transparent in advising their customers of this fact. That said, massive scientific research continues to take place to build on the knowledge base of these tests, so that they may be refined. This process will never end.

Also see Warburton's related post: Ethical guidelines for whole genome studies. 26 March 2008.

The G.I.N.A. could be a bad thing for healthcare. William Gunn, Synthesis. 20 March 2008.
William Gunn of Synthesis was one of the few, perhaps the only, blogger brave enough to buck the current dogma on value of GINA. After reading Marcelino Fuentes's letter in Nature, "How genetic censorship would harm everyone" (PMID:18354455), Gunn agrees, but notes that: "This is all jumping the gun a little" (I hope that's not a pun) "because actual rock-solid, high-confidence correlations between a genetic feature and a disease are still rather rare, but one thing’s for sure: The better you see what’s ahead, the better you can plan for it (whether a insurance company or an individual), and having a good plan leads to better outcomes for everyone". Gunn, however, does not have a problem with acknowledging the potential inequities: "Everyone’s worried about enabling social injustice, but it can’t really be said that our current insurance system in which many are so under-served is really all that great to begin with, so let that temper your thoughts, as well".

So, what do you think? Are Fuentes and Gunn right?

Your personal health: Crowdsourcing healthcare - Pitfalls and possibilities. Deepak Singh, bbgm. 25 March 2008.
Although Deepak Singh writes more often about technology, his comments on the progress of personalized medicine and the feasibility of predictive health are usually thought provoking. In this post Deepak reacts to the many consumer privacy concerns and asserts a firm position on data ownership:

Whether it be personal genetics, or social health, our efforts must focus on consumer education, consumer privacy and perhaps most of all data ownership. Who owns the data? That is the most important question. As has been said before in these parts, we essentially need some sort of license for personal health information that establishes ownership with the person whom the data belongs to, i.e. you or I and who has access and under what circumstances. That’s where education comes in. We need access to a lot of patient information and genetic profiles for personalized medicine to be successful.

Well said, Deepak, but do you also think that patient control and "ownership" of data will improve the pace medical research?

Bringing the genome home ... but why? Sue Trinidad, Women's Bioethics Blog. March 26, 2008,
Sue Trinidad, also a regular here in the "best ethics" series, reflects on the need for oversight in the future of genetic and personalized medicine. Trinidad responds to "Genetic Testing Gets Personal" (Rick Weiss, The Washington Post. 25 March 2008.), which profiles the consumer genetics movement and the companies, like 23andMe and Knome, that are fueling it. Trinidad cautions:

Here's a fact about all these businesses: not a one of them is subject to FDA oversight. So all these claims about health benefits, etc., resulting from their services can be completely false (or at least, not based on evidence), and nothing can be done about it. If you read even a *tiny* bit of the scientific literature on genetics and "personalized medicine," you will be struck by how few experts make such claims, at least for the near term … In the meantime, though, consumers should be protected from grossly overstated or unproven claims. Whether that falls to FDA or to someone else (though the Consumer Protection Agency probably has enough work to do at the moment -- lead paint in toys, anyone?), it seems to me the Feds ought to step up on this one.

Will information on risk genes actually change behaviour? Doug MacArthur, Genetic Future. 31 March 2008.
In this second post form Genetic Future in this edition of the "best predictive health blogs", MacArthur reflects on a recent news article in Science (PMID:18369117). The article and MacArthur are among the few that have bothered to acknowledge what may be the true downfall of predictive, personalized medicine—the patient. To some extent everyone (with or without genetic information) knows and ignores health risks. MacArthur acknowledges this and observes:

[I]f it turns out that genetic information doesn't reduce risk behaviour in the real world, then the impact on public health of the hundreds of millions of dollars spent on complex disease genetics may actually be very small. I'm hopeful that this won't be the case - but it would be nice to have some actual evidence one way or the other....

- J.O.

Saturday, March 22, 2008

Texas: Your Boss, Your Medical Records and the Information Economy

According to the CDC's Public Health Law News (19 March 2008) and the Houston Chronicle, Texas is now the first state in the nation to require (as of Jan. 1, 2008) that insurance providers hand over employees' health records to their employers. Currently, employees have no way of knowing of (or resisting) their bosses' efforts to acquire their medical records.

This new Texas law, HB 2015 [PDF], passed the legislature despite the opposition of the insurance industry. Thus, at least this time, the insurance industry was arguing in favor of protecting patient privacy rights. As L. M. Sixel writes in the Houston Chronicle: "Medical privacy has been protected for years by the most unlikely guardians: insurance companies." But, before we imagine the insurance industry as a giant defending the front lines in the battle to secure the privacy of medical records, we should think about what was really at stake in this legislative tussle: information in the information economy.

Employers argued that they needed access to their employees' medical records to better assess and more wisely purchase health plans for their workforce. Insurers, on the other hand, would want to restrict access to information they already possess; information, which allows them (and not their customers) to make better bets on their investments. Of course, many worry that employers will misuse medical information about their employees, but I doubt that the insurance industry cares much about discriminatory employment practices. Would, for example, the insurer suffer if employees with increased health risks were some how trimmed from an employer's payroll?

Readers of this blog will want to know what this means for the exchange of genetic and other predictive medical information between insurers and employers. According to the Houston Chronicle, there's nothing to fear in Texas, because "employers still cannot obtain health information protected by other state or federal laws, such as HIV status, genetic test results or mental illness". I'm not a legal scholar, so this was news to me. Do we already have federal protections against the discriminatory use of genetic information in the work place? If so, how will the much discussed GINA add to these protections? - J.O.

Friday, February 29, 2008

Predictive Health: Best Ethics Blogs - February 2008

This second, monthly installment (see January's Best Ethics Blogs) includes blogs on the ethical issues of biobanking, the risks of genetic testing and discrimination, responses to a recent New York Times article, and thoughts about Google Health and HIPAA compliance. Entries are listed below by topic and date.

Biobanks

Biobanking, part 3: returning research results to participants. Sue Trinidad, Women's Bioethics Blog. 4 February 2008.

Continuing her excellent series on biobanking, Sue Trinidad, asks readers to consider the following scenario: "Let's say that--20 years after you consented to participate in a breast cancer study--researchers working on a different project discover that you carry a genetic mutation that has been definitively linked to Serious Medical Problem X. ... Do the researchers have a professional and/or moral obligation to share this information with you?"

More on BioBanking. Sue Trinidad, Women's Bioethics Blog. 6 February 2008.

In a fourth post on biobanking, Trinidad responds to a BBC News story ("Change planned on cloning consent", 2 February 2008). The story reports that the UK government may allow the use of tissues donated for research for embryonic cloning without requiring the explicit consent of donors. Sue asks: "[J]ust what should be the scope of allowed activities under a 'blanket' or 'one-time' consent? Also, should the research imperative (and perhaps the common good) outweigh individuals' preferences in such cases?"

[Also see Trinidad's posts on the clinical utility of genetic tests (1 February 2008) and beneficiaries of prenatal genetic diagnosis (22 February 2008).]

Consumer Genetics

While The DNA Network provides a constant stream of quality blogs on the ups and downs, ins and outs of direct-to-consumer, genetic medicine, two caught my attention this month for demonstrating creativity and gumption.

Polls Closed, Myriad Tallies Up and We await Navagenics! Steve Murphy, Gene Sherpas: Personalized Medicine and You. 11 February 2008.

In an informal survey of his readers, Murphy discovers that most think 23andMe is the most likely to be sued first. In assessing the litigious environment, the Sherpa (Murphy's pithy alter-ego) comments: "If I had a law degree … I would bone up on genetics legal precedent, corporate protections and genetic discrimination. If you think a certain ex-candidate for president made a bundle suing OB/Gyns, you haven't seen the beginning of the legal fortune to be made in genomics."

DNA Videos: Genetic Testing on NBC Nightly News. Hsien-Hsien Lei, Eye on DNA. 13 February 2008.

In this post Lei embeds videos from the Robert Bazell NBC Nightly News series "The Truth About DNA". One of these features Stanford's Hank Greely, who expresses his worries about the genetic testing market place. In a follow-up blog post, Bazell laments a "frightening lack of government regulations". After wondering if Greely and Bazell are "easily scared", Lei takes the advice of a genetic counselor (Ellen Matloff) and writes a sample letter for "Johnny" to open a discussion of his genetic test results with his family members. Will his parents be surprised to discover that he blames them for everything? Maybe someone should persuade Johnny's "parents" to write a reply.

Discrimination

Q&A with MDV’s Bill Ericson: On PacBio’s origin, why Gattaca isn’t our future, and throwing out your statins. David P Hamilton, VentureBeat: Life Sciences. 15 February 2008.

In this interview with Bill Ericson of Mohr Davidow Ventures, Hamilton asks: "What about the potential downsides, such as genetic discrimination that could leave many people uninsurable, or even the possibility that society could end up stratified by genetic caste, as in the movie Gattaca?" Ericson responds, in part, "I worried a lot about those negative implications when we started investing, but American society is, I think, mature enough to deal with the information, whether by legislation or via general social norms."

Rewarding Ignorance. Doug Masson, Masson's Blog – A Citizen's Guide to Indiana. 24 February 2008.

Doug Masson was among the many bloggers (including Steve Murphy and Sue Trinidad) responding to Amy Harmon's New York Times article "Insurance Fears Lead Many to Shun DNA Tests" (24 February 2008). After describing how the insurance industry needs a degree of "ignorance" to survive, Masson observes: "as our knowledge of a person’s likely health care profile increases, paying for medical treatment becomes less about managing risk through insurance and more about determining what our obligations might be toward our fellow humans in subsidizing their ability to live and/or remain healthy".

Bipolar Blood Test? Let The Bloodbath Begin. Philip Dawdy, Furious Seasons. 28 February 2008.

Dawdy, a patient, reacts to the latest research news about the search for psychiatric biomarkers. Research at Indiana University School of Medicine has isolated blood markers to identify mood disorders. Lead author, Alexander B. Niculescu III, M.D., Ph.D. (a future guest at our weekly PredictER meeting), hailed the research as "a major step towards bringing psychiatry on par with other medical specialties that have diagnostic tools to measure disease states and the effectiveness of treatments". If, however, a test is developed, Dawdy declares, "I am going nowhere near that test because its results--unless you do the test privately--will follow me the rest of my life and be used to discriminate against me and people like me in insurance (health and life), employment, schools, housing and God knows what all".

Health IT and Medical Records

Of Slelling and Men. Steve Murphy, Gene Sherpas: Personalized Medicine and You. 3 February 2008.

After defining "slelling" and recounting the scandals that have limited the possibility of selling health data without the explicit consent of patients, Murphy cites Emanuel EJ, Wendler D, and Grady C (2000) to summarize how "ethicists feel" about data acquisition in clinical research.

Engineering Grand Challenges – Advancing health informatics. Deepak Singh, bbgm. 19 February 2008.

In reviewing an article published on the National Academy of Engineering website, Deepak Singh notes that the technological challenges of health informatics are inseparable from some common ethical concerns. Singh's notes that "[w]hile the article refers to privacy and security, it does not address the issues of content ownership and data portability". Among the questions the Singh would like to see answered are: "Who owns someones medical data? How does it move from one system to another? What parts can a physician have access to? [And] what are the dangers of a system controlled by the user … [?]"

Google PHR roll-out: how personal will a personal health record be? David Harlow, HealthBlawg. 24 February 2008.

Although any news about Google's developing personal health records platform "Google Health" results in an avalanche of blog posts, David Harlow was among the rare bloggers to recognize and speculate about the medical research potential of these records. In reflecting on the privacy and HIPAA challenges that Google's personal health records may bring, Harlow remarks:

So let's assume the worst: Google will sell ads to the highest bidders for keywords in your PHR (kinda OK so long as there's adequate disclosure up front), will sell aggregated de-identified data for population-based health studies (ditto, but this seems more like a good thing, and is really at the heart of the value of EHRs and PHRs generally -- though the utility depends on how much data really finds its way into the PHR, and how it's organized) and worst of all, will mistakenly convert your PHR into an RSS feed that ends up on every computer in America (eek! . . . but is that worse than dropping a paper record behind a file cabinet and never finding it again?) … Every innovation comes with a set of benefits and burdens.

Politics

One gene, two genes; red genes, blue genes. Jesse Reynolds, Biopolitical Times. 14 February 2008.

Reynolds responds to an article published in New Scientist, "Two tribes: Are your genes left-wing or right-wing?" (2 February 2008). Following a critical assessment of the media coverage and a skeptical review of efforts to study the genetics of political attitudes and behavior, Reynolds identifies a potential "disturbing" social implication for such research: "accepting that genes determine political orientation could cause deepening political apathy … Heck, why bother voting when you could just have your cheek swabbed?"

Friday, February 15, 2008

Sharing Patient Health Records: Wisconsin Assembly Bill 793

On February 11 legislators in Wisconsin introduced Assembly Bill 793 [PDF – 25.7 KB], which proposes to reduce restrictions on redisclosures of patient health records in particular circumstances to facilitate electronic sharing of information. Wisconsin’s current law (WI ST 51.30) closely follows requirements set forth in HIPAA such as allowing the patient to authorize the disclosure of health records only after the patient is informed of the following: to whom the records will be sent, for what purpose will they be disclosed, and for what length of time the authorization is effective. The current law also requires recording what records are released and to whom they are released, creating a documentation trail.

AB 793 Section 10(b) would modify these restrictions and allow a covered entity to redisclose a patient’s health care record for a purpose for which a release is “otherwise permitted,” such as: if a patient previously has agreed to its release [see Section 9(4)(b)(1)]. Non-covered entities may redisclose [per Section 10(c)] the patient’s record subject to more qualifications, such as redisclosure for a purpose for which the patient health care record was initially received. Read in conjunction with Section 10(c), Section 10(b) would allow a covered entity to redisclose a patient’s health record in more circumstances without that patient’s consent.

As reported by the Wisconsin Technology Network, the Wisconsin Department of Health and Family Services (WDHFS) Secretary, Kevin Hayden, maintains that AB 793 does not apply to disclosures covered under HIPAA. In general, HIPAA requires a patient to consent to the release of protected health information for treatment purposes by the receiving hospital and would extend this release, for example, if the patient is transferred for continuing treatment (45 CFR 164.502). Compiling and transferring patient records for other purposes (such as research or database compilation) not related to the patient’s treatment plan or administrative health care operations generally requires a patient authorization. A valid authorization (45 CFR 164.508) contains, among other elements: to whom the information will be disclosed, the purpose of the disclosure, and the individual’s right to revoke the authorization.

If the purpose of HIPAA is read to limit the release of patient records with exceptions to facilitate present treatment, then in most instances medical records must be explicitly released by the patient for use by other individuals by means of an authorization. If the patient does authorize additional use of his records, HIPAA envisions that the patient can track the release of that record with some accountability. WDHFS seems to modify how they interpret HIPAA’s requirements as AB 793 would eliminate the requirement to obtain consent to disclose the patient’s record as well as eliminating documentation of these disclosures.

It is uncertain how WDHFS and the drafters of AB 793 are interpreting HIPAA coverage, whether their interpretation relies on assuming a patient’s singular consent is sufficient, or they plan to add measures to ensure compliance if the bill is implemented. Do they contemplate “treatment” in terms of all foreseeable future treatment? Is this framework something more state legislatures should adopt to increase the ability to retrieve patient records?

If WDHFS’s further discussion of AB 793 does in fact comply with HIPAA’s requirements, this move toward compiling health records could increase the efficiency of health care for the state’s residents. In order to ensure compliance, WDHFS may need to place additional restrictions to their records system or change the substance of patients’ initial consent. - Katherine Drabiak

Tuesday, January 8, 2008

Biomedical Research Ethics 2.0: MySpace and Pediatrics

Much of the excitement about the future of personalized medicine revolves around the creation of consumer managed, personal health records. To acquire a measure of the anticipation, revisit the blogging blitz inspired the by implicit competition between Microsoft's HealthVault and Google Health (see, for example, David Hamilton's reviews of HealthVault at Venture Beat and Bertalan Meskó's coverage of Google Health at ScienceRoll). Although most are interested in the potential these Web 2.0 developments hold for enhanced, individualized health care, others have speculated that personal health information may become a more common feature of social-networking sites. The big names in social-networking (MySpace and Facebook) already host user-generated groups for individuals with shared health conditions; others, such as iMedix and MyOpenCare (for more examples visit Medicine 2.0) have entered the market with an obvious interest in health 2.0 and shared, personal medical records.

Although many worry about how advertisers might data mine personal information to target potential customers, these networks also offer a new source of information for medical research data and research recruitment. With this in mind, "Research Ethics in the MySpace Era" (Moreno MA, Fost NC, Christakis DA. Pediatrics 2008;121;157-161. PMID:18166570) is a very timely publication. The authors explore the ethical implications of using MySpace profiles as: a source for observational research (potentially exempt from IRB oversight); a tool for research recruitment; and a platform for health intervention studies. Although the authors are particularly interested in the risks and benefits of social-networking sites for pediatric research, the investigation could easily be generalized for research with adult users. The authors, however, do not address the ethical implications of using shared, genetic information. Imagine a day in which users update their profiles and replace zodiac signs with significant genetic biomarkers. How would this "shared" information challenge the ethical framework proposed by Moreno, Fost and Christakis? - J.O.

Monday, December 17, 2007

Predictive Health Legislative Update: GINA, HIPSA and more ...

If you are interested in U.S. legislative developments that may impact the progress of predictive health and genetic research, you've probably heard of The Genetic Information Nondiscrimination Act (GINA). If enacted, GINA (S.358) would "prohibit discrimination on the basis of genetic information with respect to health insurance and employment". Although widely supported, GINA's progress has been stalled by the opposition of one legislator, Sen. Coburn [OK]. Coburn has placed a block on the bill and offers an evolving account for his opposition. As reported in Wired, November 17, 2007, Coburn objects to "the possibility that an employer who provides health insurance for its workers could be sued both as an insurer and as an employer". The bill's sponsor, Rep. Slaughter (NY), dismissed the latest justification for Coburn's hold as "creative".

Although GINA has received the most attention from the press and legislators (and rightly so, as it is only one roadblock away from a vote) other bills relevant to predictive health research have also been introduced. Like GINA, two of these were written with the intent to enhance the privacy of medical records. Both of these are currently waiting for review in the Senate's Committee on Health, Education, Labor, and Pensions:

S.1455 National Health Information Technology and Privacy Advancement Act of 2007
Introduced May 23, 2007, this bill aims "to provide for the establishment of a health information technology and privacy system". The bill's sponsor, Sen. Sheldon Whitehouse [RI], and four cosponsors ask for creation of the "Office of the National Coordinator for Health Information Technology". Among other things, this new "nonprofit national health information technology and privacy corporation" would identify rules for the research use of non-identifiable health care data.

S.1814 Health Information Privacy and Security Act (HIPSA)
HIPSA, reviewed here at PredictER Blog, was introduced by Sen. Leahy [VT] on July 18, 2007. While intending, in part, to "promote the use of non-identifiable information for health research", the bill strengthens personal privacy protections. If passed, individuals would be permitted to inspect a copy of this information and would be notified of security breaches. HIPSA also requires the Health and Human Services Secretary to provide "model written authorization for the disclosure" of health information and establishes criminal and civil penalties for intentional violations.

Readers interested in the development of biobanks and genetic databases for pediatric research, will want to follow the progress of a third bill: S.911 Conquer Childhood Cancer Act of 2007. This bill amends the Public Health Service Act to establish a grant mechanism to sponsor the creation of a national, population-based database for pediatric cancer research—the Childhood Cancer Research Network. The Act, introduced by Sen. Reed [RI], would also provide grants for Research Fellowships and for the public awareness and communication efforts of relevant advocacy organizations. This bill was recently reviewed by the Senate's Committee on Health, Education, Labor, and Pensions and placed on the Senate Legislative Calendar (see General Orders, No. 535). A version of the bill is also making its way through the House of Representatives; H.R.1553 is sponsored by Rep. Deborah Pryce of Ohio and was referred to the House Subcommittee on Health on March 16, 2007. - J.O.

Subscribe to PredictER Blog for updates on these and other legislative developments.

Wednesday, October 10, 2007

Medical Records and the VA: Cancer, Laptops, Babies and Bath Water

In Wednesday's New York Times, Gina Kolata reports on the Veteran Administration's new national directive which requires states to agree to conditions prior to acquiring cancer patients’ personal information and health records. State laws often require hospitals to submit data, but these laws do not apply to federal agencies like the VA. This policy will result in less reliable statistics on the prevalence of cancer and will also chill the progress of state administered cancer research. On the other hand, the protection of patient privacy will be enhanced. The VA'S chief of research and development office, Dr. Joel Kupersmith, noted a "dynamic tension between patient privacy and the desire to use patients’ private information to do research", but stressed that the "paramount issue for us is the protection of patient privacy and the protection of patient information."

The impact of these new restrictions on predictive health cancer research will be especially felt in 17 regions that are part of the National Cancer Institute’s network. According to Kolata, these regions use personal health records provided by hospitals to investigate "cancer risk factors and outcomes" and to "provide data to academic researchers who are doing studies and need to interview patients or need genetic information."While a few states have agreed to sign the directive, many others are holding out--most notably, the state California. States complain that the directives place too many restrictions on the use of the data and that complying with these conditions is both expensive and impractical. Tina Clarke, an epidemiologist at the Northern California Cancer Center estimates that the directive will add over a year to the ethics review process. Clarke added, "Privacy concerns are serious … [b]ut at the same time, this is a baby with the bath water problem." -- J.O.

PredictER Notes:

1. In the next few weeks, as the public begins to digest this news, many cancer patients will be surprised to discover that their medical records and personal information are available for research. Will this story reduce public support and willingness to participate in predictive health research?

2. As Kolata reports, the VA'S chief of research and development, noted that "the department was especially sensitive to privacy concerns in light of incidents like the theft by teenagers last year of a laptop computer containing personal information on 26.5 million veterans." The new directive does not, of course, provide information and privacy protections that would have prevented the theft of a laptop. Will the VA's new policy truly provide the information security and privacy protections that patients expect?

Related document:

VHA DIRECTIVE 2007-023 (pdf) - RELEASE OF VA DATA TO STATE CENTRAL CANCER REGISTRIES. 15 August 2007. Department of Veterans Affairs -Veterans Health Administration.

Thursday, July 19, 2007

HIPSA: The Health Information Privacy and Security Act of 2007

Revising HIPAA
Yesterday, July 18, 2007, Senators Leahy and Kennedy introduced legislation to revise HIPAA. Although Section 215 makes disclosure exceptions for “Law Enforcement, National Security, and Intelligence”, the new bill would tighten HIPAA loopholes. The bill “requires that any health information intended to be used for medi[c]al research first be stripped of personally identifying information to protect an individual’s privacy”. Senator Leahy's website provides a copy of the statement and a summary of the legislation: http://leahy.senate.gov/press/200707/071807c.html

Additional Excerpts from Leahy’s Statement:

    Our bill also requires that patients be notified of a data security breach involving their health information within 15 days of discovery of the breach. ....

    [O]ur bill addresses the growing fear of many Americans that they will not be able to obtain important health information about a parent or child in situations involving a medical emergency, because of confusion about the requirements of current health privacy laws. ....

    The bill also establishes a national office of health information privacy within the Department of Health and Human Services to aid American consumers in learning about their health privacy rights. ....

    The bill makes it a federal crime to knowingly and intentionally disclose or use sensitive health information without an individual’s consent. Violators of this provision are subject to a criminal penalty of up to $500,000 and up to 10 years in prison, if the violation is committed with the intent to sell or use sensitive health information for economic gain.


To read the full statement and a summary of the legislation: Visit Sen. Leahy's press release at: http://leahy.senate.gov/press/200707/071807c.html

Related Press:
Sen. Leahy cites “Keeping Patients’ Details Private, Even From Kin”. July 3, 2007, The New York Times.

Also see: “Senators introduce stringent health records privacy bill”. Government Health IT, July 18, 2007.

Friday, July 13, 2007

Recent Blogs on Predictive Health Topics: Gene Expression; The Daily Transcript; Eye on DNA ...

Medical Records

A top-down approach to genetic networks. July 5, 2007. From p-ter at Gene Expression.
Comments on data mining health records to correlate hereditary disorders.


==========

Reviewing ENCODE

ENCODE. July 4, 2007. From Alex Palazzo at The Daily Transcript. A summary and critique, for the general reader, of: “Identification and analysis of functional elements in 1% of the human genome by the ENCODE pilot project”. Nature 447, 799-816 (14 June 2007) doi:10.1038/nature05874.

==========

Ownership and Genetic Information

One Big Happy Family Genome, July 7, 2007. From Hsien-Hsien Lei at Eye on DNA. Lei comments on the BMJ “Head-to-Head” feature: “Should families own genetic information?” BMJ 2007;335:22 (7 July), doi:10.1136/bmj.39252.386030.AD.

==========

Translation

Towards a World without Genetic Diseases July 7, 2007. From Bertalan Meskó at ScienceRoll.
Mentions recent genetic research advances on muscular dystrophies and potential technologies to speed translation.


==========

Genetic Databases

Indian genetic database offers R&D advances, July 7, 2007. From Albin Paul at Microarray Blog. Describes the work of The Indian Genome Variation Consortium, including: “data on the genetic codes of over a 1,000 genes from among 15,000 individuals belonging to Indian sub-populations”.