Friday, August 01, 2008

Electronic Health Records (EHR)

Health Data: Not For Sale

Right now, as Congress considers health IT legislation that would convert our health records from paper to electronic data, patient information is at risk of becoming a commodity that businesses can sell or trade.

While having a nationally connected electronic network for storing and sharing Americans medical information promises to reduce medical error and improve patient care both in emergencies and chronic situations, medical privacy should not become a casualty of the race to set up databases of electronic health records.

We need real patient control of data and damages for misuse or theft. Patients must be able to review files, correct bad data, and block access without consent to personal information. The legislation before the subcommittee does not have these protections.

If Congress fails to require strong privacy and security standards now, during the early stages of development of these online patient records systems, Americans’ medical secrets will be extremely vulnerable to snooping - or being lost or stolen.

Tell Congress: Patients deserve control of their personal health records!

The brief article above is directly from the ACLU’s website. While individuals’ opinions of the organization itself differ widely, it is quite aptly named. It does indeed work toward the preservation and adherence to laws as written, and if there is an inequity in the law, they work toward the fair application of that law to all persons subject to it.

I couldn’t begin to do justice to this topic in a short blog post, but I can tell you that it should scare the bejesus out of you. Think for a moment in terms of the transponders or chips that have been used first to set off alarms if one tried to leave a store without paying for the merchandise, next came barcodes and chips that held information about that product that enabled tracking, dates and places of sale, could correlate that with the credit card that purchased it and know that it was you who bought it. Does your pet have an implanted chip to identify it in case it is stolen or lost? Well, don’t worry, you may have one soon also, only it will have a programmable memory and you will carry your Personal Health Record, implanted under your skin, with you at all times. That could be useful if you ended up in the ER after a car crash and the staff needed information rapidly. Then your treatment, medications, procedures, diagnoses, and any other information would be added to your own little database. This request for information, especially the proposed subject population and agency requesting to carrying it out, should be of concern to all who read between the lines. Physicians’ groups are having qualms about the security of electronic records. This single article is only representative of general concerns.

The issues about the security of the EHR have not come about since last Thursday. It has been a topic of concern for a number of years within the health provider community. It has become a topic of more urgent concern recently since two information giants, Google and Microsoft, have entered the arena, proposing to become the nation’s health information repositories. Have a look at a few other searches here, and here, and especially here.

I will be the first to admit being very suspicious of the EHR. Possibly I border on being paranoid about it, but I don’t think so. Whenever I become confused or uncertain about what is happening in an undertaking of this size and importance, I have to remember to, “Follow the money.” Who stands to profit? Not really the patient or even the doctor who are just as well off with paper records. Who, then? Hospitals, HMO’s, insurance companies (health or disability,) the information transmitters (telecoms which have given the government information illegally and were granted retroactive immunity for their crimes,) the companies of whatever size that are paid to store or backup this health information? Did you notice that little or no profit goes to the individuals involved most directly, and the most to corporations who care little about what happens to a single patient or doc? Who might want this information illegally? Prospective employers not wanting to hire someone with a family history of a particular disease? Life insurance companies that might want a little edge over their actuarial tables? Government or police agencies that might just need a couple hundred thousand DNA codes?

It’s obvious where my feelings lie at this juncture. Given the burgeoning of identity theft over the last few years, is it so unreasonable to believe that the same might well happen with health records? Given the government’s nearly unfettered access to citizen’s private information without their knowledge or consent, can we say that won’t happen in our future? I’m afraid not.

Peace, Doc

Copyright © 2008, Thomas A. Blood, Ph.D.

“He who allows oppression shares the crime.” - Desiderius Erasmus quotes (Dutch Priest, Humanist and Editor of the New Testament, 1469-1536)

Labels: , , , , ,

Thursday, June 19, 2008

US Government Protects Us From Terrorists In Dresses!

You people know I just can’t pass up a chance like this to sing the praises of our government agencies’ efforts to protect us from terrorism. Furthermore, simply tie this article and the privacy and security of Electronic Health Records together and think about it. The following is the text and links directly from the June 18 article in Boing Boing:

“US seizes Danish dress-shop's payment to Pakistan in the name of "terrorism"

Posted: 18 Jun 2008 05:23 AM CDT

Carsten sez, "The owner of a small dress shop in Maribo, Denmark, orders six dresses in Pakistan for a value of $205 and pays by bank transfer - only to find that the transfer is intercepted by the US authorities and the money seized because the seller (fashio.biz) might conceivably support 'terrorism'."

"Christa Møllgaard-Hansen, owner of Christabella's in the town of Maribo on Lolland, routinely buys women's clothing and shoes from around the world to resell in Denmark. But a recent purchase of six dresses from Pakistan for $205 was considered by the American authorities to be money going to support terrorists.

The US froze the funds four months ago and contacted Møllgaard-Hansen's bank, saying they wanted more information on the payment's recipient. Møllgaard-Hansen had put all the necessary information into the original netbank payment, but complied with her bank's request for the additional information."

Link (Thanks, Carsten!)”

No doubt the FBI, NSA, CIA, or “Somebody Else” decided to snoop around a little bit longer while the Patriot Act is still mostly in effect and the FISA Act has yet to be officially modified. You know, I don’t even feel a need to contact my state’s senator, Obama (D IL) because he will quite likely already be on the case. If not, one of the above agencies will intercept this transmission of information, or buy it from one of the large telecoms or search databases. One way or another, I’m sure they’ll know my sentiments on the matter.

Peace, Doc

Copyright © 2008, Thomas A. Blood, Ph.D.

“On account of being a democracy and run by the people, we are the only nation in the world that has to keep a government four years, no matter what it does.” - Will Rogers

Labels: , , , , , ,

Wednesday, May 21, 2008

Air Force Aims For Full Control Of Any And All Computers

Initially, this post was written for a different audience, but I believe it is something that should be of interest to mental health professionals. Although I have a love for computers, I also have a great distrust that anything transmitted from them is secure or private. We need to think of HIPAA requirements, electronic billing, chats with clients online or on the telephone, the elecronic medical record, and so on. Everything on the internet is forever, stored in memory somewhere, and accessible from more and more sources, legal or not A post on this topic geared specifically to the purpose of this blog will be done soon.


Does that read too much like a scare headline from the Far Left? It isn't. Wired News online reports that the US Air Force itself has made it. In an April 13, 2008 article by Noah Schachtman, it is stated that:

The Air Force wants a suite of hacker tools, to give it "access" to -- and "full control" of -- any kind of computer there is. And once the info warriors are in, the Air Force wants them to keep tabs on their "adversaries' information infrastructure completely undetected."

The US Air Force Cyber Command is already being developed. Its website has many articles, pictures, FAQ's, and a countdown timer to "phase one stand up" on October 1, 2008.

I have included links to both the Wired article and to the Air Force website to allow readers to judge for themselves where we are headed. Most of my regular readers know that I border on the paranoid in my responses to be watched by recording cameras at stoplights, at toll road transponder lanes, and on our streets and intersections. I strongly object to being listened to, phone tapped, having my mail read, or just generally being observed in any manner unless someone has reason to believe I am committing a crime or am planning one.

On the other side of this topic, I want my government to protect me - from criminals, from street muggers to multi-national corporate muggers, from enemies foreign and domestic, to preserve our constitution, and defend our land. I appreciate the brave people in the military services and in the public sectors who serve us and take care of us so well and who we too often take for granted.

At a deeply frightened level, I know that a current "World War III" would be fought like no other. China has demonstrated to us their ability to blind and disorient our spy and navigation satellites by shooting down one of their own. In turn, our "accidental" transport of six W80-1 variable yield live nuclear warheads From Minot AFB in ND to Barksdale AFB in LA was given much more publicity than I would expect any military organization to allow the media. I do not see these incidents as unique, or even highly significant in the bigger picture, of which the public sees only tiny fragments through a glass, darkly. If an enemy had unfettered access to any of the Internets or grids that control our distribution of electricity, natural gas, vehicle fuel, traffic and transportation flow, food and water distribution, public and military communications, financial tractions (commercial, investment, and banking,) ... well, you get the picture. Our nation would be brought to its knees in a grinding, chaotic halt. In a much more localized manner, the electromagnetic pulse (EMP) of a conventional atomic weapon or an "E-Bomb" destroys MOSFETs, FETs, transistors, and the like if not Faraday shielded, thus disabling electronic devices in the area of the explosion. The government and Military knows this in infinitely greater detail than do I.

On a personal, much less significant level, I have been affected wrongly by the same type of capabilities as are needed to defend our nation. I sold a car to a friend who ran through four "I-Pass" toll stops without paying. I received a ticket for four infractions, complete with a very clear picture of the back of the car with my plates still on it, and a statement that not being the driver was no excuse for not paying the tickets. In another incident, Medicare gave the Veterans Health Administration all of my personal and business information (including SSN, EIN, bank routing numbers, addresses, etc.) without any notification to me. I found this out when the VHA notified me that a portable hard drive with this information on it was missing. At least they had the decency to notify me and provide for one year of credit fraud alerts. I have no doubt that, despite the precautions I take personally, this type of information has been lost, discarded, or stolen far more times than I am aware. As a simple example of the laxity of transactions in the area of credit, I have written "Require Photo ID" on all my cards, along with my signature. It has been checked only once in approximately 10 years.

So what do we do and where do we go with this sort of information? I honestly do not know. The same technology that protects us can destroy us. The same types of devices that allow surveillance of criminals, terrorists, and enemy actions are easily able to be turned on a country's own law abiding citizens. It is, after all, so very much easier to listen in on our own cell phone conversations and take pictures of our own license plates than it is to definitely identify what is happening in an enemy's hardened military site or know if a satellite is armed and has military capabilities.

*sigh*

Peace, Doc

Copyright © 2008, Thomas A. Blood Ph.D.

"We realize our dilemma goes deeper than shortage of time; it is basically a problem of priorities. We confess, We have left undone those things that ought to have done; and we have done those things which we ought not to have done." - Charles E. Hummel

Labels: , , , , , ,

Tuesday, July 31, 2007

Security Software

Most mental health professionals would agree that we have a duty to keep confidential our clients’ PHI. This seems especially true if we keep that information on computers that can be lost, hacked, or subject to viruses of all kinds.

I recently had, and am continuing to have, an experience of possible identity theft. I did nothing to cause it or to leave myself open to that attack. Stupid things happen. A portable drive with a database of providers was lost or stolen. The VHA wrote to notify me and to offer a year of free credit monitoring and fraud alerts. As most of my personal information including SSN, EIN, name, address, and all the rest was on it, I accepted their offer quickly. My suspicion is that a less experienced employee or an intern copied it to a thumb drive to work on at home. The information was obtained from the Social Security Administration’s database of mental health providers without my knowledge or permission, to be used in a provider demographics study. As a client would feel in a similar situation, I am concerned, anxious, and feel that someone is responsible for potential harm to me. To the VHA’s credit, they immediately admitted their loss and offered some protective measures. Of all the times that I believe my personal information may have been lost, stolen, or compromised this was the only time I was notified.

We owe our clients the best security we can provide. Probably the best security software available to the public is produced by
Norton/Symantec and McAfee. They are good and their respective prices reflect that. Many other commercial security software brands are available and usually, as good as the two named, but possibly not as comprehensive.

I have found free versions of some lesser-known software brands available that have proven as effective, in combination, as one of the major manufacturers’ software suites.
AVG offers free versions of their Anti-Virus, Anti-Spyware, and Anti-Rootkit software. As far as I am currently aware, their Anti-Rootkit program is the only free rootkit software available. I use all three. CheckPoint Software’s ZoneAlarm Firewall is a well-known and effective free security application that I also use and rely on. Spybot-Search & Destroy is a very effective free “donation-ware” anti-spyware application. I also use it with confidence. LavaSoft’s Ad-Aware-2007 is a free adware search and removal application. It has very recently been updated and apparently did not install well on my computer. Its past versions have been quite useful and worked perfectly in combination with all the other free programs listed. Microsoft also offers free anti-virus and internet filters, as well as updates to your operating system. I use Microsoft Update, Windows Live OneCare safety scanner, Windows Defender, and the Malicious Software Removal Tool. All of the Microsoft tools may be found on the single Microsoft link appearing above.

These are some of the best free security programs available. I recommend them with some caveats, however. I am making recommendations based on my personal use of Microsoft’s XP Pro and XP Home operating systems and cannot generalize to other OSs. If you do not use these links to obtain the software, be certain that the providers and spellings of the program names are exactly the same. There are imitators using names very similar to the good software that may contain malware or be malware themselves. Finally, if you like the software, please consider purchasing their commercial versions. Be careful out there.

Peace, Doc

Labels: , , ,