Pages

Showing posts with label HIPAA. Show all posts
Showing posts with label HIPAA. Show all posts

Wednesday, May 13, 2009

Hearings on Major Revision of Expansive Massachusetts Data Privacy Law today on Beacon Hill

by Sarah Cortes

Public comment was received today on Beacon Hill on a major draft revision to MassachusettsData Privacy Law, Senate Bill 173. House Chairman Theodore Speliotis, pictured left, Senate Chairman Michael Morrissey, below, and a half dozen elected state officials presided this morning over a hearing on dozens of privacy, identity theft and credit card laws and related amendments, including SB 173.

About a dozen representatives of industry organizations plus one IT security professional testified at today’s hearing, unanimously supporting the bill, which revises MGL 93H, Massachusetts’ Data Privacy Law. The amendment makes four revisions:
The most major of the changes defers to existing federal law where applicable. HIPAA and Sarbanes-Oxley cover most enterprises. This takes a considerable burden off firms handling data records and reduces complexity.

Another major revision is the reversal of provisions that would dictate specific technical tools or methods like encryption. The revised law would steer clear of any such specific requirements.
Small firms will find relief in the third change, which requires separate standards for them.
The fourth change allows firms to take action against employees violating the security policy.

“As a major technology state, we need to get this right,” observed Anne Doherty JohnsonExecutive Director, New England Council TechAmerica, which represents about 1,500 member firms. “The current regulations exceeded the intent of the legislature and are very problematic for the reasons outlined. TechAmerica believes this legislation will correct those and is a huge step in the right direction.” Doherty, who testified today as she has in hearings on the bill over the last several months, echoed the opening statement by Chairman Morrissey. Morrissey, pictured left, stated that the hearing marked a crossroads between the approach up to the present, where the legislature expanded the scope and jurisdiction of the law beyond the borders of Massachusetts and beyond its original intent, and a possible future approach by incoming undersecretary of the Office of Consumer Affairs and Business Regulation, Barbara Anthony. (see related story.)

Bradley A. MacDougall, Associate Vice President of Government Affairs for Associated Industries of Massachusetts (AIM), also testified. AIM is the state’s largest nonprofit, nonpartisan association of Massachusetts’ employers with more than 6,500 members who employ nearly one out of every five workers in Massachusetts. MacDougall captured the essence of sentiment expressed during three hours of testimony by approximately a dozen industry representatives:
“Data protection is a top priority for Associated Industries of Massachusetts (AIM) and our members who will continue to pursue the development of reasonable data privacy regulations in Massachusetts. The delay, in the general effective date of May 1, 2009 to January 1, 2010, does not resolve the substantive issues within the current rules that impose high costs and prescribe specific technology solutions. Massachusetts cannot afford additional unreasonable regulations on employers working to protect jobs and prevent layoffs while competing in a global economy. Senate Bill 173 would provide a necessary solution in the absence of regulatory rule changes. The legislation would ensure that clear guidelines for the development of identify theft regulations be utilized to provide consistency for those entities already regulated under Federal law and further provide businesses with greater flexibility to strategically invest their limited operational and IT resources.”

MacDougall,AIM and a broad coalition of industry groups representing Technology, banking, retailers and mutual funds, among others, have been instrumental players in deconstructing and analyzing proposed legislation, explaining it to the public, raising awareness of the proposed law, and advising the legislature and Administration on issues of concern, since the TJ Maxx data breach set in motion the chain of events resulting in today’s hearing.

copyright 2009 Sarah Cortes
Reblog this post [with Zemanta]

Ranch Kimball and John Halamka at HBS

by Sarah Cortes

Another early morning at the sunny and elegant Spangler Center at Harvard Business School finds over 100 leaders of industry preparing for a double feature from two health care movers and shakers. First on the program is the well-known Ranch Kimball, President and CEO of Joslin Diabetes Center and former Secretary of Economic Development under Governor Mitt Romney. As if Kimball weren't enough, John Halamka, pictured left playing the Japanese flute, will be speaking. CIO of Harvard Medical School, among many other roles, posts and responsibilities, this high-profile medical technologist is one of the most sought-after thinkers and speakers in the world of health information technology("HIT"). Although unclear at first why these two are double-billed, it soon becomes apparent.

Kimball runs through a deck of slides with dizzying speed and stunning clarity of message. Russ Vandenpool, a board member of HBSAB, the sponsor of the event, summed it up: "Kimball takes a page directly from Michael Porter's book on competition by applying focus on quality and defect reduction to health care delivery." Although only at Joslin since 2007, Kimball explains he has retooled the center based on lessons from Toyota's famous revolution - focusing on quality of care delivery up front to significantly reduce cost and improve patient quality of life over time. Kimball shows us how tuning and focusing on eight specific service delivery points with patients early on reduces the need for dialysis and surgery later. Some pretty clear slides prove this, he explains, where the purple Joslin cost bar is clearly shorter than the green cost bar for all other providers, as everyone can plainly see for the microsecond it flashes on the screen. It's just long enough to make the point effectively. Complete economy of Kimball's message and our time.

Next up is Halamka, who we look forward to from our acquaintance with his well-regarded daily blog, "Life as a Healthcare CIO." On this topic, electronic health records ("EHR") and electronic medical records ("EMR") are core concepts. Halamka apprises us how BIDMC coordinates with Joslin by sharing medical records, a technical feat in the world of health care, we come to understand. According to Kimball, pictured right, Joslin went to all-EMR seven years ago and was, he believes, the first Harvard hospital to do so. The disarming interchange between Kimball and Halamka informs us how closely these two coordinate professionally. An insight into a human success factor behind technical coordination?

Halamka's part of the program soon conveys how far from simple is his world of medical computing. Halamka's slides reflect a close watch on the Washington pulse, including a HIT Policy Committee, an HIT Standards Committee, and "Regional HIT extension centers." The first of these, the HIT Policy Committee, is apparently focused on "meaningful use," of electronic records, an elusive concept on which Capital Hill is still wandering in the wilderness. $19 billion in federal funds lie in the balance, it seems, available to spend and waiting for consensus on the best way to spend it. Only 2% of hospitals, we learn from Halamka, are currently on-line with EHR, and these funds are intended to encourage and allow the rest to get there as soon as possible. The government has announced it will divide the $19 billion among doctors, providing each with $44,000 to go into electronic records in 2011. Doctors can qualify for reimbursement if they show "meaningful use," whatever that is. As best as anyone can tell, this relates in some way to certification of the electronic method and software that doctors select against some technical standard. Guidance from HHS is expected to be available by the end of the year.

Because state law pre-empts HIPAA, Halamka notes there are, in effect, "50 privacy policies," in the sense that the patchwork of individual state policies effectively prevents information-sharing, quite apart from technical challenges. "Privacy has been protected differently in each locality," notes Halamka.

He hopes policymakers can do away with the current system whereby, after seeing a patient, the doctor calls a phone number on the patient's insurance card and "gets to argue with a high-school educated triage clerk about the appropriate diagnosis." Halamka's cynical humor conveys a deep-seated frustration with the current system, coexisting curiously along with what seems like good-natured optimism that we nevertheless can and should improve health care.

Halamka flashes a detailed slide on the data interoperability capability for all providers in Massachusetts, called the "MA-Share Appliance." Apparently this is opensource software, "built on a common messaging gateway," by which health care providers can communicate with each other to improve quality of patient care delivery.

He shares that he was the fourth human to have his genome mapped as a way of illustrating the rapid way the cost of such sequencing is coming down, from $350 million for the first human (which might include all sunk costs to that date. Or the special carrying case), to $100 million for the second, $100,000 for the third, and his cost only $10,000 for genome sequencing.

Halamka also shares that his annual budget is $30 million, which is 1.8% of revenue, always an interesting data point for IT professionals

Kimball, scheduled tightly, rushes off apologetically after Q&A, while Halamka lingers graciously a few minutes after the meeting ends as a crowd surrounds him, eager for every word with this oft-quoted, pace-setting CIO.

copyright 2009 Sarah Cortes
Reblog this post [with Zemanta]