3 ms·
The article naysayers correctly point out: Mobile technology presents providers "with a very long list of legal concerns," they point out. "Privacy and securit
by keithflower 15y ago
The article naysayers correctly point out:
Mobile technology presents providers "with a very long list of legal concerns," they point out. "Privacy and security of patient data, compliance with state and federal laws (including Stark and anti-kickback statutes), assumption of risk and liability, along with many other critical issues, should be addressed in the contract between the healthcare provider and vendor of such software."
Unless I'm missing something, this "certification" from Infogard doesn't appear to speak much to these concerns, if at all, which are the overwhelming concerns of physicians with these kind of non-hospital cloud-based system.
The "certification" that the application meets "meaningful use" just means that app use may allow physicians to qualify for the government incentive money for adopting an EHR.
http://www.infogard.com/resources/healthcare_it/meaningful_use_requirements http://www.infogard.com/resources/healthcare_it/meaningful_u...
Security, security, security is the real issue. The drchrono CEO says that a "security audit" was done, but the article gives no details. Who did it, at what level, and where are the results?
Does drchrono assume all risk and liability for patient confidentiality? Is that spelled out contractually? Unfortunately, the problem is that even with such verbiage in a contract, individual physicians would likely not escape the rightful wrath of patients and regulatory bodies if a data breach occurred. Frankly, even if physicians did adopt a system like this, they'd have to provide disclosure and go through an informed consent process with their individual patients about the use of drchrono, and get written approval from individual patients to store their info this way. What happens when many (if not all) patients opt-out? Maintain two systems?
"Tell the court, Dr. Incentive, what drove your use of drchrono? Were you convinced that the system provided any benefits whatsoever to the patients who now have their HIV status, mental health diagnoses, and street drug use information plastered all over the net....or were you more interested in the $44,000 benefit you got from adopting the software?"
But, he [CEO of drchrono] says, with the iPad connected to drchrono's cloud-based platform, "there's no information stored on the iPad except a temporary cache ... it's more secure than locally stored laptops and servers."
This statement makes no sense. We've seen countless breaches and releases of protected health information from cloud-based systems. How is highly sensitive information transmitted to and stored on drchrono and/or third-party servers possibly more secure than leaving patients' data on local systems which are locally controlled, physically fenced (easily quarantined from the net), easily whole-disk encrypted, locally backed-up, locally audited, with locally set retention policies, and locally destroyed when needed?
- Skeletor 15y agoThe legal FUD you bring up would have some basis in fact if the government weren't mandating that all US physicians use EHR systems and passed laws/regulations defining their use and liability under HIPAA and the security rule. The #1 source of patient data theft has occurred from stolen laptops which contained locally stored records. A cloud based solution with mobile access is much more secure since even if an iPad is stolen there is no loss of data.
- drewda 15y agodrchrono, like any other EMR system here in the States, meets HIPAA requirements: https://drchrono.com/security/ https://drchrono.com/security/ If you don't understand what HIPAA entails, have a look at: http://www.hhs.gov/ocr/privacy/hipaa/understanding/ http://www.hhs.gov/ocr/privacy/hipaa/understanding/