Live data from Hacker News

OpenEMR: Electronic Medical Records and Medical Practice Management Software

open-emr.org

201–210 of 214 posts

Re: OpenEMR: Electronic Medical Records and Medical Practice Management Software

#201

Earlier quoted context omitted.

Thanks- ideally the auditing would be done regularly, and require a reason to be entered for any access the first time a new provider accesses your information. Even better each patient would have a USB stick with a One Time Token generator that would 1) hold basic emergency information on the USB drive) 2) Generate One Time Keys to grant access to new providers. Of course, in an emergency situation where a provider…

So I think your ideas are good, but you have to realize the multiple competing priorities in healthcare. When you say ideally, you mean from a privacy standpoint. In my opinion "best health outcome of the patient" should be the highest ideal. Say I am working a night where I may be paged on 100 patients who I am meeting for the first time. Just opening their records on The EMR eats a significant amount of time. Time…

I see your points- I agree that "best health outcome of the patient" is the priority. I don't think that is always at the cost of privacy, though. In fact, if people feel more secure about the privacy of their information, they will be more likely to be open and to even visit a health care provider in the first place. (Some people may not care either way, but there are those who do- and certain circumstances that people are more likely to care about than others).

I don't think the challenges you mention are unsurmountable-

An ER doctor seeing 100 patients a night might have the system setup to automatically log in as an emergency, and they already need to log the reason for the appointment- or else there is no there is no record of it...

Setting up the initial access should be handled by staff during check-in for non-emergency visits.

Patients are generally already expected to carry a health insurance card (at least in the US- not sure how that is handled in countries with Government provided health-care). As the system becomes more widespread, it would become normal for everyone to have a security token, and they could use those tokens for access to multiple systems, not just health care (The USB disk thing is probably optional, just a slight improvement for when the network is down or you can't otherwise access the information).

I also think the User Experience on the systems I have seen could be greatly improved to reduce unnecessary clicks- and I have noticed that more often then not though- loading information over a slow network takes more time than navigating the GUI.

I would agree that the problems with health care go far beyond EMR systems, but they were the topic of the discussion.

Thanks for participating, I want to better understand all of the issues and these types of discussions help a lot toward that goal.

Re: OpenEMR: Electronic Medical Records and Medical Practice Management Software

#202
post #69

Earlier quoted context omitted.

As far as I can tell, there's no economic incentive for health care systems to undergo these transformations willingly. Remember, the digital transformation didn't occur until the HITECH act in 2009, which mandated the use of electronic health records. Why digitize your operations and worry about maintaining tech infrastructure when you can do everything on paper with a handful of secretaries? You could argue providi…

> ...exception to this is Kaiser Permanente They are notorious in the medical community for valuing efficiency above all else. Kaiser also doesn't serve extremely difficult cases, uninsured patients or patients on Medicaid. Academic hospitals do. Kaiser can do a lot of things differently by virtue of being subsidized by the generosity of the state and the state's highly talented doctors. I don't know how much there i…

I work at an academic hospital, and I've seen how the incentives drive policy. Frankly, it's terrifying.

> Nobody at an academic hospital makes money every time you get sick.

Of course they do! Every time you go in for treatment, they make money, and there only incentives for preventative care come from government/Medicare mandates (e.g. hospital readmissions, ACOs.)

Let me color the picture a bit more vividly. At a public pitch competition within the university, a department head--and judge of the competition--laughed at an ML start up: "you do realize we make money from the procedures you're trying to prevent."

> Discharging patients is a high priority.

Hospitals are often penalized for long stays by insurance.

> Doctors are constantly trying to figure out how to do preventative care with the sorts of "frequent flyer" patients that tie up emergency rooms and hospital beds.

Aside from tying up resources, high-utilizers can't afford to pay for services and the hospitals treat them at a massive loss. Naturally, a hospital would like to free up these resources for patients who can pay.

> It's doctor as antagonist.

I never said this, and nor do I believe this. Doctors are victims of this system. I even made the point that doctors hate the EHR because it's been warped by hospital administrators into a billing-centric machine with umpteen documentation requirements at every turn.

For this reason, many who went into medicine for altruistic reasons end up disenchanted with the health system that's been wrecked by those running the business.

Re: OpenEMR: Electronic Medical Records and Medical Practice Management Software

#203

Earlier quoted context omitted.

So I think your ideas are good, but you have to realize the multiple competing priorities in healthcare. When you say ideally, you mean from a privacy standpoint. In my opinion "best health outcome of the patient" should be the highest ideal. Say I am working a night where I may be paged on 100 patients who I am meeting for the first time. Just opening their records on The EMR eats a significant amount of time. Time…

I see your points- I agree that "best health outcome of the patient" is the priority. I don't think that is always at the cost of privacy, though. In fact, if people feel more secure about the privacy of their information, they will be more likely to be open and to even visit a health care provider in the first place. (Some people may not care either way, but there are those who do- and certain circumstances that peo…

I agree that the challenges aren't unsurmountable, but we have to make sure that we realize everything we change has unintended and unforeseen consequences, even things that seem as simple as adding an additional click or checkmark.

You are right there are those who do not seek care because of privacy, but in my experience they are by far a minority compared to the people who don't get healthcare because there aren't enough providers to get an appointment (mostly because they are all already too busy and overwhelmed to take on new patients), are worried about cost, or who just are in denial about how sick they are.

The deal with insurance cards though is that there is no problem or issue if you don't remember to carry it. Registration can still be done, they just look you up by name, address, or SS# if needed. Not to belabor the point (because as you mention you could use a network) but any system that depends on people carrying something will have a lot of caveats.

No matter what you pick it will sometimes not work, the network will be down, the USB flash memory will no longer work, the USB port will be broken, etc... so there will have to be a non-emergency allowance for 'token' system not working. How are you going to verify it really isn't working and that people aren't just clicking 'not working' because it is easier (or because they are malicious and lying to steal data...).

With regards to automatically logging people in: Consider your ER doctor system, ok that works when it is logged as an emergency in the ER. Now consider my role. I am a hospitalist, meaning I admit patients to the hospital and take care of the ones already admitted. Should I already be covered under the emergency since they are sick enough to be in the hospital or do I have to go through additional steps to log in to address a patient who just needs some extra nausea or pain medications or a sleeping pill? If I have to log in it detracts from the time I can spend dealing with a patient who suddenly has a more pressing issue (such as new chest pain that needs to be seen)? Of course, I am going to see the chest pain patient and so the nauseated patient is miserable for a few extra minutes. Now this sounds like squabbling over a loss of seconds but in reality managing an inpatient service is juggling multiple pages at once for sometimes several hours straight on many patients, triaging what needs to be done urgently vs later, and admitting patients, etc... It can be nonstop. So just one additional step really does add up.

So you can then say, why not have it set up that once a patient is admitted, they get logged in once and then you don't have to worry. I would then answer that that is basically what we do now. When you get admitted to the hospital you sign a release which covers this.

I will bring up another issue: you say a new provider should only have to log in once. Do you really want a provider you saw maybe 5 years ago for a one time visit have access to your records. How long until they have to reregister?

Another issue: What if you have tests done that aren't resulted by the time you leave the hospital. For example you have a blood culture that becomes positive after 5 days which means you need to be notified to get new labs done. The doctors that took care of you are off shift or on vacation. Usually this is taken care of by another provider, who you may never meet, are they going to be covered under the token system?

Out of curiosity what is your background in this since you mention User Experience?

Re: OpenEMR: Electronic Medical Records and Medical Practice Management Software

#204
post #162
post #69

Earlier quoted context omitted.

As far as I can tell, there's no economic incentive for health care systems to undergo these transformations willingly. Remember, the digital transformation didn't occur until the HITECH act in 2009, which mandated the use of electronic health records. Why digitize your operations and worry about maintaining tech infrastructure when you can do everything on paper with a handful of secretaries? You could argue providi…

It's no longer necessarily true that providers make money every time you get sick. Insurers have shifted risk to providers in some areas in the form of accountable care organizations (ACOs) which receive a flat fee per patient. So in theory the ACOs have a financial incentive to prevent you from getting sick. Kaiser Permanente uses the same Epic EMR software as many other large provider organizations.

And I have seen shifts that ACOs have caused first hand! Unfortunately, the only insurer running ACOs is Medicare which is an example of a political solution to the problem. While we have yet to see what the financial implications of ACOs are, I can say that I've seen admins work hard to develop data-oriented preventative care. However, these advances are still only limited to the ACO population, which gets back to my point. Hospitals aren't going to fund patient risk analysis until the economic incentives are in place, and for that reason, I fear that the issue of bad interoperability will exist for as long as we live in a "fee-for-service" world.

As for Kaiser adopting Epic, remember I noted that hospitals can customize the EHR to their needs in detail--it does however require troves of cash. Since Kaiser heavily relies on data-driven preventative care as part of their business model, they pay to have a lot of data systems in place to facilitate their operations. Hell, Kaiser even had an Open API since 2013!![0] Good luck finding that anywhere else!

[0]: http://interchange.kp.org/

Re: OpenEMR: Electronic Medical Records and Medical Practice Management Software

#205
post #191
post #162

Earlier quoted context omitted.

It's no longer necessarily true that providers make money every time you get sick. Insurers have shifted risk to providers in some areas in the form of accountable care organizations (ACOs) which receive a flat fee per patient. So in theory the ACOs have a financial incentive to prevent you from getting sick. Kaiser Permanente uses the same Epic EMR software as many other large provider organizations.

In fact they were essentially the first and the reason it has become a near monolopoly

Kaiser was, however, one the first systems to start (2000) and finish (2010) their electronic transition. Their decision had nothing to do with the government mandate in 2009, precisely because their business depended on it.

Also, don't forget that EHRs don't come with a data governance model, so the entire onus of maintaining clean, available, interoperable data falls on the institution. Again, since Kaiser depends on clean, available, interoperable data, they made that a priority both internally and in their contracts with Epic.

Re: OpenEMR: Electronic Medical Records and Medical Practice Management Software

#207

I came here to ask the question "Has anyone (hopefully) done a 3rd party security audit of this open source medical records software?" But then I saw this: http://www.open-emr.org/wiki/index.php/FAQ#What_is_ImageMagi... And then this: http://www.open-emr.org/wiki/index.php/FAQ#What_are_the_corr... ..... http://www.open-emr.org/wiki/index.php/FAQ#What_do_I_do_if_I... http://www.open-emr.org/wiki/index.php/FAQ#What_is_…

Agree that security is an important topic. Note there has not been a default password for about 5 years, and will update the FAQ. Regarding the other FAQ links you posted, what specific security issues are there with those? To get an idea of OpenEMR's security, recommend checking out the following section on the wiki(1 of those links has several 3rd party security audits): http://www.open-emr.org/wiki/index.php/OpenE…

It shows the use of ImageMagick, a legendarily buggy and insecure application and library. It shows the use of system crypt() for password hashes, which isn't really very secure since (afaik) it doesn't support pbkdf2 on most systems or bcrypt (not the blowfish one) or script. It shows hardcoding database credentials in a flat file. And it shows it uses PHP, which has its own security problems as well as being well known as a language used by people not aware of secure coding practices.

Re: OpenEMR: Electronic Medical Records and Medical Practice Management Software

#209
post #69

Earlier quoted context omitted.

As far as I can tell, there's no economic incentive for health care systems to undergo these transformations willingly. Remember, the digital transformation didn't occur until the HITECH act in 2009, which mandated the use of electronic health records. Why digitize your operations and worry about maintaining tech infrastructure when you can do everything on paper with a handful of secretaries? You could argue providi…

I agree with everything you say besides the claim there is no economic incentive. Just a few 1) Getting patients to pay their bills. 2) Spending less time on each patient. 3) Reducing errors. All these have economic incentives. But yes it's still a hard sell.

[deleted]

Re: OpenEMR: Electronic Medical Records and Medical Practice Management Software

#210

Earlier quoted context omitted.

Yeah, I have. A health record is a collaboration - unlike a medical record, which just shows a slice of your health from the perspective of a single institution, a health record aims to show as many facets as possible. An EHR system should be agnostic about who access the record, and what they use it for - obviously gps, specialists, hosptitals, labs, the patient should all have access - but what about, as your said,…

So, if I want to run an daily analysis of every record in your system, does that processing happen on your system, or do you somehow replicate the data to me? I guess my point is... it's likely that you may want a "single source of truth" for the data, but farm out copies for other applications. And once you do that, you probably want some kind of "replication protocol" that sends updates, rather than making a full c…

It's a self hosted system - so you as an institution have a copy of all of your patients records on your own servers, which you control. So analyse away.

What it provides is a way to replicate some or all of the record to other health institutions. Say, you share the patient's medication list with the hospital - they also keep a copy. When you prescribe a new medicine, the hospital's copy also gets updated.

And yes, arguably this is just another version of interoperability. However, if you want to share healthcare information, in a way which allows institutions to have freedom, it's unavoidable. The concept of interoperability isn't bad, just the implementation is.

The alternative is all patients records are kept, and accessed from the same place. However, this is very tricky. Many governments have tried to make national health record storage systems, which had immense budgets, and didn't really work out. Often with systems controlled by one party, it's hard to work on ideas which don't fit their goals. Say if you have this great idea for a new format to manage diabetes - that wont fit into their standard format, and you'll have to work outside of their system. Not to mention the control over the population this organisation would have.

Patient owned and controled systems are often suggested, and have been built, but I've never seen one work. Patients expect their doctor to manage their record - and they pay for them. It would be a huge challenge to get every patient to pay their yearly 'health record server fees'.

On top of that, heath records also belong to the doctors - legally in NZ they have to keep a copy of your record for 10 years since your last visit. For their own liability they need access.

In my mind only two models can really work - Goverment run systems which are run better than current systems - A better take on the interoperability model

Post reply on HN