7 ms·
I was "ringleader" (many diverse groups have been involved over the years) of the OpenEMR project in 2003-2005 and went on to create the open source ClearHealth
by duffpkg 6y ago
I was "ringleader" (many diverse groups have been involved over the years) of the OpenEMR project in 2003-2005 and went on to create the open source ClearHealth and HealthCloud EMR (electronic medical record) systems. OpenEMR has a lot of dedicated folks in it and has been a project of some sort of another for ~25 years at this point.
You can read quite a bit about open source in healthcare in my book, Hacking Healthcare. A bit dated but still in print.
Unfortunately there are massive headwinds against open source in US healthcare settings. Regulation requires certifications that cost upwards of $100K first time, $10K with each release, just in fees. Licensed data sets also make for real difficulties in licensing. Required 3rd parties like SureScripts are openly hostile to open source. Most largest buyers of systems are institutional and most current interpretations of law make it so that open source systems cannot be sold as "sole source" which makes life very hard to close and keep those deals. Finally, until a business model emerges that favors open source and patient health, everyone makes more money with lock-in and so that perpetuates.
Ask me anything.
Can confirm, a little concerningly, that code I wrote 17 years ago is still widely present in the OpenEMR codebase including my old office number for test patients, lol.
- russnewcomer 6y agoI recently worked on a very small, very custom open source 'EMR' system for a friend involved in prenatal care in a developing country, and so what I wonder is are there attempts to get OpenEMR/Clear Health etc into countries and settings where there is not the same huge regulatory barriers? To me it seems like the U.S. is largely lost for a generation for open source/patient-centric EMR, but maybe there is hope for other countries?
- duffpkg 6y agoExcluding mexico where a ClearHealth derivative still, as far as I know, powers one of the large hospital chains there, no. In my personal experience the venn diagram of countries where there is not much regulation but yet it is advanced enough medically that EMR is a primary problem is pretty much zero. To put it another way most countries where regulation is low have much more pressing medical needs than software.
- russnewcomer 6y agoThat's clearly true from talking to several foreigners I know who do medical work in developing countries. Yet it also seems like there is a lane for a simple piece of software to do basic record keeping. For example, I wrote the app (https://github.com/russnewcomer/SeventyTwo https://github.com/russnewcomer/SeventyTwo) for my friend to solve the problem (somewhat specific to the culture they work in) where they don't have a clinic site or really the ability to make appointments but instead travel to homes or communities to do their work, and they have to cart around all their binders full of records. My simple app works for their use case, but this also feels like a spot where there are more opportunities to help. Anyway, I definitely support open source EMR efforts, wherever they may lead, and I thank and applaud you for your service!
- duffpkg 6y agoIn hacking healthcare I talk about "the incredible bandwidth of paper". That's still true. Without really first world software and hardware in a very modern physical setting it is difficult if not impossible to solve medical problems better than pen and paper can. In the practice of medicine pen and paper are really adequate tools to deliver quality care. It is in the business of medicine where large scale data necessitates and benefits from electronification.
- russnewcomer 6y agoThanks for that perspective. Helps me understand why their use case ( my friend talked about multiple nurses needing to have about 20in of records organized in binders and then coordinate between the nurses in case Nurse A saw someone in Place 1 but then Nurse B saw them in Place 2 a month later...) is helped by the computerization (along with the record keeping they needed to provide for grants/funding), but people working clinical settings that I've talked to are not really interested...
- breck 6y agoI 100% agree and am going to start using your "the incredible bandwidth of paper" quote (awesome!). Even in the first world, I want an EMR system that treats paper as a first class medium, and it's easily doable.
- mixonic 6y agoHowdy there! I was one of the original authors of OpenEMR back in high school. I'm still good friends with at least one of the other authors. We're always stunned to see OpenEMR in the news, and watching it creep up on HackerNew today has been fun. I've always been curious why OpenEMR seemed to dominate in the OSS space after we walked away from it. I can only theorize that the code was more approachable than other projects (PHP), and that the GPL kept the work from being captured by any one business. I can't imagine that the code was the best, I'm painfully aware of how poor the security practices must have been in hindsight. You've given me the chance to ask a question I never knew who to ask: Why, back in 2003 (just after we stopped giving the project attention), was OpenEMR the project you decided to spend time on? What made it the attractive thing to invest in? If you can tell me I'll bottle that elixir and pour it into every OSS effort I work on today.
- duffpkg 6y agoHi. James? I was CTO of Pennington Firm in that era and it was one of many industries where "internet modernization" was happening to a sort of sleepy status quo. OpenEMR with FreeB were the furthest along open source project at the time and so we started there. There were a lot of legacy type problems inherent in the OpenEMR codebase and I think the change to PHP 3 ultimately is what lead to starting fresh with ClearHealth. I'm dating myself but that's around the time that browser AJAX starting opening up a lot of UI possibilities.
- mixonic 6y agoHowdy! Nope, I'm one of the two Matts from the Synitech, the original publishers. IIRC the codebase as we left it was heavily into iframes. iframes and SQL injection attack surface. I'm not sure it used CSS :-p in 2001 or 2002 I actually did a lot of systems work building a version of OpenEMR which booted from CDROM but wrote the database to an attached USB storage device. The idea was that small offices had to start thinking about HIPAA compliance, and could take the disks home from their server each evening for improved security. I think that was probably the last thing I was working on in OpenEMR.
- tedjdziuba 6y ago
- ethbr0 6y agoWhy aren't more user-visible medical systems built as services: open source backend serving endpoints, closed front-ends? Bespoke front-ends and UX have never been open source's forte, but shared serving technology running behind the scenes has been wildly successful. Health care seems like a good fit for that. (Said as someone with clients in insurance, and well aware of how quickly data interchange can embrittle an architecture)
- duffpkg 6y agoI think there are plenty of open source projects with great UI but that aside I'm not sure I understand what you mean? What type of service for example? HIPAA greatly complicates a lot of data sharing because of appropriate data privacy issues.
- ethbr0 6y agoOne of the most unpleasant things about working in the medical space is how tightly coupled and poorly modularized systems are. Obviously, driven by the reasons and pressures you outlined in your parent comment. (Everything is sold and certified as a system, rather than a component) It seems like there's an opportunity for OSS to eat shared functionality, that no vendor particularly liked implementing, and then allow for closed source UIs to be built on top. E.g. EMR store/server being the open product, with {insert your preferred front end on top, for your specific use case}
- duffpkg 6y agoI see. PACs which are the storage and index systems for medical "imaging" data have seen some pretty big in roads. HL7 processing has become dominated by open source. There is huge institutional inertia to overcome in any corner. You really need to offer something 10X better to get over the "no one ever gets fired for using EPIC" mentality and that's a very high bar.
- ethbr0 6y agoThanks for the keyword pointers. This is a bit outside my expertise: family on provider side, but I work more on the insurance side of the house. In insurance, there seem to be some moves towards cracking monolithic systems into pieces for reasons of development agility. ACA limiting admin costs is a huge driver, as companies rightly identified lack of technical agility as a existential threat (no agility = no ability to update automated processing pipelines to changing requirements = manual processing = penalties for exceeding allowed admin costs). Also, I think there's a generational shift at the executive level from "Buy and trust vendor" to "Own, develop, and operate."
- anonymouse008 6y agoI've noticed a lot of practitioners use PhraseExpander or some other shortcut writing tool to write their patient notes - I'm curious to know how they get around the HIPAA certifications, especially since they are a dedicated key logger on top of any OS. Do you have any insight in this arena? I wonder if it is because they are not 'the record,' but instead are 'tools to create' the record that is eventually uploaded and stored in another platform? Might be a tangential question, thanks for the patience
- duffpkg 6y agoThere is a lot of controversy in this area. Medicare rules are pretty clear that to the extent tools like that are used systematically to enhance bill-ability they are prohibited. Malpractice litigation is having a field day with computerized systems which is why so many states are being pressure to institute caps. Pretty much everyone tries to use templating tools to increase bill-ability to some extent. Healthcare is rife with conflicting goals. The underlying problem is that we need an economical way for doctors to have more time to spend in the room with patients but no one, patients included, wants to pay for that. I really hope "concierge" medicine, a lot of that now happening on the lower priced end not only for "luxury patients", continues to take off. You pay some cash out of pocket but get care that is dramatically better and more preventative.
- anonymouse008 6y agoWoa -- do you have a link to the regulation (chapter, but looking at Medicare fully now) to things that are designed to "systematically to enhance bill-ability"? So you're saying if you use a templating tool to be more efficient and save time, it's explicitly not allowed AND you're opening up either yourself or the technology tool to malpractice litigation?! Goodness!
- duffpkg 6y agoMalpractice is a totally separate thing from Medicare Fraud. With respect to malpractice, having automated or semi-automated encounter notes with huge systematic similarity looks absolutely terrible if something goes wrong. Don't take my word for it, consult your attorneys. With respect to Medicare fraud see the False Claims act and its interpretation in the enforcement actions against many parties beginning in 2016. Keywords would be like "not medically necessary" and "upcoding". I believe the monster enforcement action just this week against GHC also involves that.
- datahead 6y agoHi Duff! Happy to see you on HN. EDIT: not Fred. I work for a large hosp. operations company and serve as the Dir. Engineering for our clinical operations group. Hacking Healthcare is required reading for new members of my team. It serves as an excellent introduction (with a healthy amount of critique) to the dynamics in the hc technology ecosystem. Thank you for providing this perspective on the industry and its challenges with tech. We've been successful developing using open source technology internally. In fact, I take a fairly hard stance on disallowing proprietary healthcare specific "solutions" from working their way into our stack (aside from the EHR itself, it has staying power). We're lucky in that we are positioned as somewhat of a startup within a larger org, and are able to take that approach. To avoid some of the issues you raise, we generally are working to reduce the surface area of the EHR to become simply the transactional backend which is then mirrored to a larger ecosystem of custom apps. This has the effect of boxing in the regulated entity. We focus on data integration (by spending $$$$ on custom HL7 interfaces, unfortunately not everyone can afford) to get outside of the walled garden. This means we can use the information/data for new and interesting purposes without worrying about the EHR vendor's roadblocks/tolls. More importantly to some people, we don't disrupt the billing cycle that originates from the EHR. Do you notice any trends where healthcare operations/providers are starting to develop internal technology that integrates with the EHR to compliment vs. replace the core transactional system?
- duffpkg 6y agoIt's Duff (David) instead of Fred but thanks. Fred is doing great too. Are you a former CHL/TXR managed or sub-owned group or facility? Unfortunately I see the opposite trend right now, more silos, more lip service to interoperability, more tolls. I think driven by the burden of regulatory overhead. Moving forward there could be a shift to a "patient owned" record where providers and facilities feed standardized formats into a patient owned/managed "personal cloud". I hope that continues to pick up steam.
- datahead 6y agoHi Duff! Apologies for the mixup, should have seen that in your handle. No, I'm not part of CHL/TXR. While not open source by any stretch, I see the personal EHR space being ushered along by companies following Apple's lead. Aside from complex patients, I think the generally healthy/mild-chronic person is uninterested in owning/managing their health data unfortunately. Apple is contributing useful tools to understand fundamental determinants of health including cardiovascular, sleep, fitness at massive scale. It just happens to come with your watch and phone, and their vision for health is starting to come into focus. This puts the patient in the position of generating the primary data (sensors, etc.) and sharing it with their care team on their terms (more or less). As telehealth becomes more prominent, I suspect the patient will be required to engage with their data more often as it will be the means of conveying a shared understanding vs. observations recorded in the clinical setting and stashed away in centralized EHRs. Furthermore, if labs and other diagnostics are available directly to consumers it puts the individual in a position of ownership. I think the default position is whoever generates the data owns it, and determines how easy/hard it is to share with others. If the individual is empowered to generate information about themselves- this will start to swing toward "patient owned." I too look forward to more of this, but it will have to come with more direct to consumer and digital offerings. One of the coolest examples I've seen of individuals taking ownership in open source med tech is openaps.org . I'm not one, but T1D's are some of the most resourceful and resilient folks around. Good on them for building a community to solve real problems together. Shout out to the #wearenotwaiting crew.
- absorber 6y ago> Unfortunately there are massive headwinds against open source in US healthcare settings. This reminds me of one of the first articles I've read about Linux and open source in general. It was about a CEO (and largest shareholder) of Medsphere Systems Corp, who open sourced their tech stack (I believe called OpenVista) and was promptly sued by his own company (!) Unfortunately it seems that the sands of time have eroded the original content (which was apparently hosted on linux-watch.com, which now redirects to a VPS provider), but I've still managed to find something [0] [1] [2] 0: https://70.42.23.9/servers/a-medical-open-source-legal-hell-hole https://70.42.23.9/servers/a-medical-open-source-legal-hell-... 1: https://medicalconnectivity.com/2007/10/25/medsphere-settles-with-cofounders/ https://medicalconnectivity.com/2007/10/25/medsphere-settles... 2: https://www.informationweek.com/medsphere-settles-lawsuit-with-former-cto-over-open-source-code/d/d-id/1060683 https://www.informationweek.com/medsphere-settles-lawsuit-wi...
- duffpkg 6y agoThere is a whole bunch to the behind the scenes of Medsphere and OpenVista. I am not sure what I can say except that a lot of big personalities were involved. WebVista by ClearHealth is still in use by a few very large hospital chains.
- dman7 6y agoThanks for AMA. My previous startup was in self-insured employer space so I only saw the issues you're describing from a distance. > "Finally, until a business model emerges that favors open source and patient health, everyone makes more money with lock-in and so that perpetuates" I'm curious to know if you've thought about what such a business model might look like. The closest to a viable business model I've seen gives patients control of their data & allows them to monetize it. But that feels like a pipe dream at the moment because a) EHR vendors don't have incentives to share data, and b) there is no marketplace of buyers for said data.
- schoolornot 6y agoI worked in the EMR space and don't remember the company having to pay $10k per release. Can you share more info on this?
- nradov 6y agoI assume that was to participate in the ONC Health IT certification program. https://www.healthit.gov/topic/certification-ehrs/certification-health-it https://www.healthit.gov/topic/certification-ehrs/certificat...
- kls 6y agoUnfortunately there are massive headwinds against open source in US healthcare settings. Regulation requires certifications that cost upwards of $100K first time, $10K with each release, just in fees. Seems to me like this could be overcome by licencing but not in the general sense but more in a you need accreditation, join this other pool of people utilizing the system and buy an accreditation licence. Seems like there would still be a value proposition there. As for the 3rd party seems that could be hit or miss again if it is money, build those out as modules that cover the licence fees the third party is looking to recoup. Maybe with a little bone in it for the open source developers as well.