Friday, September 23, 2011

Comments on CLIA/HIPAA Harmonization (Patient Access to Labs) NPRM

Monday a week ago, HHS announced the publication of a new proposed rule titled: CLIA Program and HIPAA Privacy Rule; Patients’ Access to Test Reports.  John Halamka wrote about it this Monday, and you can find a copy of the Federal Register publication.  Because of the HL7 Working group meeting, I'm a bit behind on writing my review of this rule, so here it is:

Quoting from the summary:
This proposed rule would amend the Clinical Laboratory Improvement Amendments of 1988 (CLIA) regulations to specify that, upon a patient’s request, the laboratory may provide access to completed test reports that, using the laboratory’s authentication process, can be identified as belonging to that patient.
The summary goes on for a couple more sentences, but when I read this I nearly cheered out loud at the HL7 Plenary session.  The CLIA regulations and state laws have prevented many HIEs from providing patients with access to their lab results because of either real or perceived regulatory requirements under CLIA and HIPAA laws and regulations. In many cases, HIEs that have been the desire to share results so have implemented complex workflows to "work through" the requirements of these and local regulations.

Again quoting the NPRM:
Under the current regulations at § 493.1291(f), CLIA limits a laboratory’s disclosure of laboratory test results to three categories of individuals: the ‘‘authorized person,’’ the person responsible for using the test results in the treatment context, and, in the case of reference laboratories, the referring lab. Authorized person is defined in § 493.2 as the individual authorized under State law to order or receive test results, or both. In States that do not provide for individual access to the individual’s test results, the individual must receive his or her results through the ordering provider.  
Table 3 in the NPRM shows how this would impact labs (and patients) in the various regions of the country, and table 6 shows which state laws would be overridden (see *'d columns below) by this new regulation.

TABLE 3—IMPACT OF PROPOSED RULE CHANGE ON LABORATORIES
Impacts laboratories 
Does not impact laboratories 
No State law   Allows test reports
 only to provider* 
 Allows test reports
 to patient 
Allows test reports to patient
with provider approval* 
Alabama  Arkansas  Delaware  California 
Alaska  Georgia  District of Columbia  Connecticut 
Arizona  Hawaii  Maryland  Florida 
Colorado  Illinois  New Hampshire  Massachusetts 
Guam  Kansas  New Jersey  Michigan 
Idaho  Maine  Nevada  New York 
Indiana  Missouri  Oregon  Virginia 
Iowa  Pennsylvania  Puerto Rico 
Kentucky  Rhode Island  West Virginia 
Louisiana  Tennessee 
Minnesota  Washington 
Mississippi  Wisconsin 
Montana  Wyoming 
Nebraska 
New Mexico 
North Carolina 
North Dakota 
N. Mariana Islands 
Ohio 
Oklahoma 
South Carolina 
South Dakota 
Texas 
Utah 
Vermont 
Virgin Islands 

While I can get mine (with provider approval), my mother cannot get hers at all direct from her lab.  The new regulation would change that for both of us.  I would no longer need my provider to approve, and she can get them where she couldn't previously.

What follows is the text of the rule with markup (underlines = insertions, strikethrough = deletions):

Title 42—Public Health 
PART 493—LABORATORY REQUIREMENTS
1. The authority citation for part 493 continues to read as follows:
Authority: Section 353 of the Public Health Service Act, secs. 1102, 1861(e), the sentence following sections 1861(s)(11) through 1861(16) of the Social Security Act (42 U.S.C. 263a, 1302, 1395x(e), the sentence following 1395x(s)(11) through 1395x(s)(16)).
Subpart K—Quality System for Nonwaived Testing
2. Section 493.1291 is amended by—
A. Revising paragraph (f).
B. Adding a new paragraph (l).
The revision and addition read as follows:
§ 493.1291 Standard: Test report.
* * * * *
(f) Except as provided in paragraph (l) of this section, test results must be released only to authorized persons and, if applicable, the individuals (or their personal representative) responsible for using the test results and the laboratory that initially requested the test.
* * * * *
(l) Upon a patient’s request, the laboratory may provide access to completed test reports that, using the
laboratory’s authentication process, can be identified as belonging to that patient.

Title 45—Public Welfare
PART 164—SECURITY AND PRIVACY
3. The authority citation for part 164 continues to read as follows: Authority: 42 U.S.C. 1320d–1320d–8; sec. 264, Pub. Law 104–191, 110 Stat. 2033–2034 (42 U.S.C. 1320d–2 (note)); secs. 13400–
13402, Pub. Law 111–5, 123 Stat. 258–263.
4. Section 164.524 is amended by revising paragraphs (a)(1)(i) and (ii) and removing paragraph (a)(1)(iii) to read as follows:
§ 164.524 Access of individuals to protected health information.
(a) (1) * * *
(i) Psychotherapy notes; and
(ii) Information compiled in reasonable anticipation of, or for use in, a civil, criminal, or administrative
action or proceeding. and;
(iii) Protected health information maintained by a covered entity that is:
(A) Subject to the Clinical Laboratory Improvements Amendments of 1988, 42 U.S.C. 263a, to the extent the provision of access to the individual would be prohibited by law; or
(B) Exempt from the Clinical Laboratory Improvements Amendments of 1988, pursuant to 42 CFR 493.3(a)(2).
* * * * *

For all the preamble and commentary, it's really a very small, but hugely impactful set of changes.  There's been some notable reaction to this rule in the industry, and it was even discussed on today's HITsm chat.  There seems to be two reactions:
  1. Patients should not have access to the information before their doctor does.
  2. Patients should have access to their data in the same form that the doctor does.
These are sometimes presented as being conflicting statements, but I can see where both can be met under the new rule.  The provisions of the HIPAA access rules allow for up to 30 days for a provider to respond with the information.  A lab can easily insert a small administrative delay to ensure that providers have had time to review results and contact patients without any problems under HIPAA.  Some have suggested a 3-day delay.  I believe that physicians also have a responsibility to provide patients with not just their interpretations of the results, but also the data that they have.

Like John, I see this as being a terrific change that will open up more access to patient data.




Thursday, September 22, 2011

IHE XDS for mHealth access to HIE

I submitted (late) a proposal to the IHE IT Infrastructure workgroup a proposal for an IHE Profile titled XDS for mHealth.  I was graciously given time by the planning co-chair to present it even though it was submitted late, to allow the committee to understand it, and determine whether or not to accept it as a late submission.

The committee did agree to accept the proposal through the process, and so now I'll explain it a bit using the same presentation materials I used this morning, just reformatted for this blog.  The next step is to see if it makes the prioritization cut at the October 11-12 IHE ITI Face to Face meeting.  There are 3 other profile submissions and documentation maintenance work to consider.  Ensuring that the committee has identified resources who are willing to work on it is very important in this next step.  After that, it has to make the technical committee cut with respect to "do-ability".  I'll shortly be working on a prototype to show that it is in fact feasible.

If you aren't an IHE member, but want to support this project, join now (it's free).  If you are a member, please show up to the face to face meeting I mentioned above.  I expect there will be T-con access for members who cannot be present at the face to face (there usually is).

  -- Keith


Support for XDS in mHealth Evironment

The Problem

  •  mHealth platforms are resource constrained
    •  SOAP Stack missing or buggy (e.g., WSDL support for Objective C)
    • Bandwidth constrained (10Kbps to 10Mbps)
    • Limited resources (e.g., memory), often no “back-end” server
  • Increasing proliferation of unconnected apps
  • mHealth is an emerging market, failure to support this space could reduce relevance of IHE
  • Difficult to use XMLHttpRequest for browser-based, multi-platform mHealth apps.
1Source: MobiHealthNews http://shar.es/HMlff

Use Case

  1. Patient sees a specialist for a particular condition.
  2. The specialist asks for detailed information from the patient.
  3. The patient, not remembering their list of medications, pulls out their mobile device and activates an application.
  4. The application queries the HIE and retrieves a list of clinical summaries in date order, from most to least recent (or on-demand medication list document).
  5. They select the most relevant document, and it is downloaded to the device.  The application extracts and displays their medication list.

Proposed Standards & Systems

Standards

Systems

  • EHR
  • PHR
  • Patient Portal
  • HIE
  • Mobile Device (iPhone/iPad/iPod, Tablet, Android, Smart Phone, Windows Phone, etc.)
Discussion

  • There has been substantial work already in simplifying the XML in OHT, that could be used as one basis for the effort.
  • Metadata could be transformed from a simplified representation to ebXML representation using XSLT.
  • Transactions could be optimized to use W3C standard XMLHttpRequest object.
  • Below is one example of how the actors and transactions could be organized:

Wednesday, September 21, 2011

IHE News: Demonstrate Leadership in HealthIT

Normally, I'd save this release for tomorrow, but the deadline for the HIMSS showcase registration is this Friday!

Dear IHE Community,

IHE N.A. Connectathon Registration Closes September 30, 2011
The IHE North America Connectathon 2012 will take place January 9-14, 2012, in Chicago. Fast-track your organization’s EHR system, medical devices or drive down the product life cycle and implementation cost and register for the 2012 Connectathon. This year profiles from nine IHE Domains will be tested at the Connectathon: Anatomic Pathology, Cardiology, IT Infrastructure, Laboratory, Patient Care Coordination, Patient Care Devices, Quality, Research and Public Health, and Radiology. Learn how to participate in the IHE N.A. Connectathon 2012 by visiting IHE USA’s Participant Resources or review the Policies and Guidelines document. Connectathon System Registration is closing soon- Register before Friday, September 30, 2011.

HIMSS12 Interoperability Showcase Contracts are due by September 23, 2011
For healthcare providers today, the need to purchase and meaningfully use standards-based interoperable health IT solutions tops their list of mission critical challenges. And the HIMSS12 Interoperability Showcase™ will top their list as the number one place where they can find practical solutions to their unique needs—offering real world case studies  from EHRs and PHRs, Radiology PACS and RIS systems, to public health registries and health IT infrastructure services. Space in the HIMSS12 Interoperability Showcase is Limited! Contracts are due by September 23, 2011. To learn more visit the HIMSS Interoperability Showcase website or contact the HIMSS sales staff.

IHE Patient Care Coordination Technical Framework Volumes and Supplements Published

This apparently got stuck in my inbox. I should have published it a couple weeks ago.  Document links are to the PDFs that were published:



IHE Community,

IHE Patient Care Coordination Technical Framework Volumes and Trial Implementation Supplements published

The IHE Patient Care Coordination Technical Committee has published the following Final Text Technical Framework Volumes as of September 9, 2011:
·       Volume 1 (PCC TF-1): Integration Profiles
·       Volume 2 (PCC TF-2): Transactions and Content Modules

The committee has also published the following supplements to the Technical Framework for Trial Implementation as of September 9, 2011:
·       Antepartum Profiles (includes APE, APHP, APL, and APS)
·       CDA Content Modules Supplement (was published on 2011-09-02)
·       Emergency Department Encounter Summary (includes CTNN, EDPN, NN, and TN)
·       EMS Transfer of Care (ETC) – has been deprecated
·       Immunization Content (IC)
·       Labor and Delivery Profiles (includes LDHP, LDS, and MDS)
·       Newborn Discharge Summary (NDS)
·       Patient Plan of Care (PPOC)
·       Postpartum Visit Summary (PPVS)
·       Transport Record Summary Profiles (includes ETS and ITS and replaces ETC)

These profiles will be available for testing at subsequent IHE Connectathons.  The documents are available for download at http://www.ihe.net/Technical_Framework.

Comments on all documents can be submitted at http://www.ihe.net/pcc/pcccomments.cfm.


Virtualization vs. Fair-Share Scheduling

I was cc'd on a very kind e-mail the other day that was sent up my management chain.  I won't duplicate it all, but the essential points are below:
You may know he was virtually EVERYWHERE at our recent ... conference, which is turning out to have been a crucial meeting in elucidating future roadmaps  ...  I strongly suspect he was in multiple sessions speaking AT THE SAME TIME.
He goes on to ask about sharing our standards expert cloning or virtualization technology.  I wish such a thing did exist because I often want to be two places at once.

This keeps cropping up in my life.  I got my boss yesterday to agree to send me to a conference on HTML5 that I want to go to.  It's not the usual line of activity for me, so that was a big win.  I forgot to check my calendar, because I have other commitments to IHE that week that I must attend.  IHE has to win because I already have that as a prior commitment.

This summer, the Query Health Summer concert series ended in a big bang the SAME week that the CDC Public Health Informatics conference was going on in Atlanta.  Not one presentation at that conference addressed Query Health (which has Public Health as the first of its stakeholders).  Does holding "concerts" the same week that a key audience is going to be out of town make a lot of sense?  I didn't think so.

National Health IT week was last week in Washington, DC.  So was "International Health IT Week", otherwise known as the HL7 Working Group Meeting, in San Diego, CA.  We might as well have been worlds apart.  And it's not like the timing of the HL7 meeting was a well hidden secret, these meetings are scheduled a YEAR in advance.

Yesterday I had to chose between attending the second of two Query Health calls, or being on an HL7 EHR call to promote a project for developing a functional definition for metadata used in Health Information Exchange.  It was an unfortunate choice to have to make, because both calls were of great interest to me.  If I had virtualization technology, I would have been in both places at once.

Today, I have to chose again between a Query Health call, and a CDA Documentation Workgroup call because they were knowingly double-booked.  Fortunately, there is another cochair to run the latter, and I'm going to attend the former.  I truly hate it when the same organization forces me to chose between two of its own activities.  It really demonstrates a failure to effectively use valuable volunteer time.

This isn't a standards problem, or a problem due to lack of available, standards based solutions that are freely available to the public.  What we really need is a public calendar of activities affecting HealthIT that is managed and curated.  I've mentioned this idea to a few folks at ONC.  I hope they can do something to help.

We all have day jobs and pre-existing commitments.  It would be great if we could coordinate schedules better to enable folks to honor them and participate in S&I Framework activities at the same time.  Perhaps ONC has some virtualization technology for standards geeks that they are willing to share...  Until then, we'll have to go back to the age-old, time honored tradition of scheduling jobs in a fair-share scheduling system.  After all, it's one thing to be an impatient conveigner with a perhaps slightly higher priority, but another altogether to hog all of the CPU.  After all, the S&I Framework is simply a source of Health IT solutions, but not the only one.


Tuesday, September 20, 2011

Adventures in Plumbing

One of the disadvantages of working from home is that after a long day, you are right there to address challenges around the house.  Today's after hours challenge was the upstairs toilet.  Besides the fact that the flusher has been finicky lately (it sometimes needed two or even three tugs on the handle), the fill valve would no longer shut off.  So I was constantly running water.  This is a major distraction downstairs where I can hear it running.  So, I went off to the hardware store.

Now, as every do-it-yourselfer knows, every project requires three trips.  First to collect the parts that you think you need.  Second to collect the part or tool you didn't know you were going to need.  Finally, to get the part you should have known you needed but decided you could do without, or to get the part that you broke putting it all back together.  I joked about this with the hardware store clerk.  He said in parting, "See you later!" with a grin.  I was bound and determined to avoid three trips.  So after disassembly, when I couldn't get the big nut off the bottom with my hands, and couldn't find my wrench (yes, there is a tool for that), I improvised a big wrench with a C-clamp and a block of wood.  No way was I going back 3 times. So I won, and got it off.

Getting the fill valve off was a lot harder.  The problem was that it was still attached to the tube that went down to the shut-off valve.  That tube connects to the shut-off valve with a compression fitting.  It was much easier to disconnect that then the ancient and corroded metal pipes that came from the bottom of the fill valve.  Try as I might, even with all the right tools (how many people have 50-year-old plumbers wrenches in their basement), I could not budge the corroded pipe.  Hacksaw I thought, but that meant I was going to need another connector from the shut-off value to the fill valve.  Still, it's only two trips I though.  So off I went.  The clerk and I had another discussion about the number of trips as I purchased a universal connector.  This is the last piece I need I declared.  I thought about getting new washers for the tank bolts, but I had plenty of washers in my tool kit at home.  We joked about breaking hacksaw blades when I explained to him what I was up to next.  I told him I had three hacksaws and plenty of spare blades.

So, I started hacking off the fitting on the fill valve.  After a few minutes of hacking, I got nowhere, sure enough, that blade was very dull.  So I replaced it with another blade.  Off it came easy.  I put everything back together and then began to test fit the new connecting pipe to the shut-off valve.  It didn't fit.  The connector was WAY too big.  Dang it, I thought.  This is supposed to be a universal connector.  But this piece doesn't work.  I remembered some adapters that I still had left over from my dishwasher installation.  I went down to find them only to discover they were the wrong gender.  They were male-to-male or female-to-male,. but I needed a female-to-female size reducer.  I came back upstairs.  I looked at the tube.  This packaging I was about to throw away but saved in case I needed to return it was sitting right there.  "I swore this said universal" I declared, holding it up.  Out fell a bag of three female-to-female adapters.  One of them was the right size and I managed to nearly finish the job.

I reassembled everything, did a test fill, and everything seemed to work.   Then I flushed.  Clean water went everywhere.  I'd forgotten to put back an important rubber washer at the base of the new flapper.  So I disassembled again, put that back on, and reassembled.  It worked, but I had a drip.  And I couldn't find washers of the right size.  The clerk laughed at me when he saw me return.  This is the last trip I said.  Don't worry he said as I departed, we close in another half hour.  You still have time if you need us.

So, I put on the new washers, tightened everything down, and ruminated on the adapters.  Of course I saved the extra parts, I always do.  You never know when you might need one of those things again, and it could save me from that third trip to the hardware store.  Having the right adapter in place for the right purpose is a really good idea.

I'll be proposing a new profile proposal for IHE IT Infrastructure next week.  It's essentially like that  plumbing adapter.  It supports connecting mHealth devices to an XDS Registry/Repository.  It accounts for the fact that on those devices, you don't often have access to a SOAP stack, and that simpler XML would be easier to work with as well, as the best you are likely to have is an XMLHttpRequest object.  That is after all, a standard fitting. Perhaps IHE should have an adapter for that in its toolbox.  We'll see how it goes.

     Keith

P.S.  My wife is calling me.  I need to go re-tighten those bolts.  She hears leaking.  I hope I get it right because the hardware store is closed now.

FY 2012 ICD-9-CM Vocabulary Now Available from CDC

Greetings,
CDC Vocabulary server (PHIN VADS) has been updated with the latest version of ICD-9 CM (FY 2012). This version will be effective from Oct 1st 2011.

CDC PHIN VADS Download Files / Links:
(a) ICD-9 CM Diagnosis - Vol 1 & 2
       - Download File (Excel Spreadsheet)
       - PHIN VADS hyperlink provides metadata needed for HL7 messaging such as OID's.

(b) ICD-9 CM Procedure - Vol 3 
         - Download File (Excel Spreadsheet) 
         - PHIN VADS hyperlink provides metadata needed for messaging such as OID's,

Source file for ICD-9 CM codes have been taken from Centers for Medicare & Medicaid Services (CMS). CMS publishes the ICD-9 Codes with short description, long description and ICD-9 codes without decimals. For electronic data exchange, it is recommended to use the ICD-9 codes without decimals. CMS also publishes the updates (New, Revised and Deleted codes) which may be useful for implementers of ICD-9 CM (link).

CDC Vocabulary team have published the ICD-9 CM FY2012 which includes the ICD-9 codes with and without decimals. We have also created a preferred name that includes long description and ICD-9 CM code with decimals.

Leading and trailing zeroes are important which could be truncated by Microsoft Excel, if the columns are not formatted as "Text". We have imported the ICD-9 CM codes in a spreadsheet for your convenience with the following fields:

Example:
(A)  ICD-9 CM Code without Decimal: 24900
     -concept code to be used in electronic data exchange including HL7 messages.
(B) Short description: Sec DM wo cmp nt st uncn
(C) ICD-9 CM code with Decimals249.00
 (D) Long Description with ICD-9 CM Decimal Codes: Secondary diabetes mellitus without mention of complication, not stated as uncontrolled, or unspecified [249.00]

Thanks
CDC Vocabulary Team