5 ms·
I was the main contributor and maintainer to OpenEMR about ~20 years ago and then decided it was irredeemable and started over with ClearHealth/HealthCloud. Sho
by duffpkg 2y ago
I was the main contributor and maintainer to OpenEMR about ~20 years ago and then decided it was irredeemable and started over with ClearHealth/HealthCloud. Shockingly some of my code code lives on (from PHP 3). I am reluctant to say don't use it but if you do please don't expose it to anything public, which sadly happens most of the time. There are some real problems that exist in that code base from a security and HIPAA perspective.
- achillean 2y agoLooks like there are at least a few hundred instances of OpenEMR exposed to the Internet: https://www.shodan.io/search/report?query=http.favicon.hash%3A1971268439 https://www.shodan.io/search/report?query=http.favicon.hash%...
- oezi 2y agoClearHealth/HealthCloud is abandoned, right? What would you recommend today as an OpenSource EMR?
- duffpkg 2y agoClearHealth and it's affiliated companies were acquired in 2017. ClearHealth the EMR stopped open source releases in 2017/2018. You can kind of hair split what is and isn't an "EMR" but if you want a system most providers would call an EMR it is extremely difficult to have it be any sort of open source anymore. Basic fundamentals like procedure codes, diagnosis codes, eprescribing, billing, drug databases, interoperability, mandatory reporting and certifications all involve large fees, licensing and other ongoing costs. At ClearHealth our main business was healthcare management. We spent about ~2 million a year on those things, we released what was not encumbered otherwise under the GPL. The EMR is still used and maintained internally by some larger institutional users.
- nradov 2y agoGood points, but diagnosis codes don't generally require any licensing fees. Depending on the use case those are usually either ICD-10-CM or SNOMED CT, both of which code systems are free to use.
- brady_m 2y agoI would recommend the open source EMR project that is literally staring at you in the face here, which is OpenEMR :) There is a reason why there is a healthy community of passionate volunteers and contributors from all walks of life that have spent an inordinate amount of time and resources to support this open source software. Coming from one of the core volunteer developers that has contributed to this project over the last 18 years all I can say is that a lot has changed over that time. I consider it a robust and secure project regardless of its humble origins. And always happy to answer any questions regarding the project.
- Taikonerd 2y agoOn the page, they talk about being ONC certified: [0] Does ONC certification test for that kind of thing? They briefly mention "security"... [0]: https://www.open-emr.org/blog/openemr-achieves-onc-certification-with-groundbreaking-release-70/ https://www.open-emr.org/blog/openemr-achieves-onc-certifica...
- duffpkg 2y agoIf you consult https://chpl.healthit.gov/#/listing/10938 https://chpl.healthit.gov/#/listing/10938 you will see that it is a certification of a subset of the full criteria (toggle 'see all certification criteria'). OpenEMR foundation says they had to raise $125k to do the partial certification, that sounds right. That is a good thing but some items like eprescribing are not certified, which is an absolute deal breaker to most providers. I would guess it's because you have to license a drug database. At ClearHealth we built and maintained our own drug db as open source also, it was a large endeavour. We had to lobby federally for there to be a carve out in the HITech legislation to even allow for an open source drug database to exist rather than the original requirement of two dominant existing providers codified in law. You can stitch together some other third party offerings to meet those needs but hardly anyone wants to do that.