January 18, 2012
Collaboration is Key When it Comes to HIT Workforce Development
Written by: Jennifer DennardOne thing that I love about this industry is its willingness to collaborate, and I’m not just talking about collaborative care. I’m talking about healthcare IT’s propensity to brainstorm new ideas as the drop of a hat. Put two HIT folks – be they physician, vendor or blogger – in a room, and 20 minutes later you’re going to have a new idea related to care delivery, product development or possible partnership on your hands. It gets even more prolific when editorially minded marketing folks like me are added to the mix.
I’ve been pleasantly surprised at how even blogs can foster this sort of collaboration. Last month in “Finding an EMR Job Champion,” I chatted with Rich Wicker, HIMS Director at Shore Memorial Hospital in New Jersey, about how this industry can best align recent graduates of HIT certification programs with training and jobs. Some of you may have noticed several comments left on that post by Sean McPhillips, a man of many hats. He is currently an adjunct instructor at Cincinnati State – a community college in the HITECH College Consortia; project manager at the Kentucky Regional Extension Center; and creator of the HITECHWorkforce.com, a free resource to help students enter the HIT work environment.
In his comments, he advocates for a mentor-protégé program: “Students still need some more help finding jobs. What I think needs to happen is a “Mentor/Protégé” model. That is, pairing students with industry professionals who can mentor them into the industry. I’ve passively done that…to success. I think that will work.” He later followed up with the news that he hopes to work with HIMSS, which is developing a similar program, to get this model off the ground.
I recently had the opportunity to speak with McPhillips a bit more about his idea. I was eager to find out just how he plans to jumpstart it:
It seems as if you’ve been kicking this idea around for a while. How did it come about?
Being with the extension center, I’ve mentored a handful of people along the way, and I think there needs to be a more structured process so that students coming out of these [HITECH College Consortia] programs who want to be mentored have a place to go, they know how to get and stay engaged in the process. I think that there is with HIMSS, but I don’t think it’s really been tightly coupled with the workforce development program.
When I spoke with Helen Figge, Senior Director of Career Services at HIMSS, she was really excited to talk with me, and pointed me to HIMSS’ career development page to look around and see what they have out there. I’m thinking of how we can connect [what they’re already doing] into the workforce development program within the overall HITECH project structure, so that we can connect students who come out of these programs with their local HIMSS chapter, which could then pair them up with a mentor that’s in their region. That’s what’s really missing. That’s what’s really necessary to get people plugged into this profession – especially if they’re coming from outside of this profession.
HIMSS does not already have some sort of relationship with the college consortia?
They kind of do, but I don’t think it’s really tightly coupled. I think HIMSS recognizes this, so they’ve been developing their career development program. They’re near completion of a new, entry-level certification called the CSHIMS certification. That is something where you don’t need to have a whole lot of experience in health information technology, but you need to demonstrate some degree of knowledge in subject matter to obtain that certification. That might be a good way to help these students take the next step into the profession, when they’re looking to get a job. That could be part of the whole mentorship program concept.
Isn’t there a double-edged sword to it financially? Wouldn’t students have to become paying members of HIMSS, and then would they have to pay for certification? If they’re looking for jobs, finances might be tighter than usual.
That’s a great point. The question is, what are the costs associated with certification and becoming a member. There is a student membership discount. There’s a cost to certification, obviously, so these are things that are to be considered. That has not escaped me, so that’s going to be part of my brainstorming session. I’m going to meet up with them in Vegas when I go out to HIMSS.
One of the things I want to be able to do is make this attractive for people, particularly students, and if they have to lay out $500 or $1,000, and they’re already unemployed or they’re financially strapped, it becomes not just a double-edged sword, it becomes a disincentive.
I wonder if the vendors couldn’t get involved and offer scholarships.
It’s funny that you mention scholarships because that might be something the local HIMSS chapters can do. I know the Ohio HIMSS chapter used to do a $1,000 scholarship every year for students. So this might be something that the boards or the individual chapters could subsidize.
If you’re in the HITECH workforce development program, maybe HIMSS would be willing to waive membership for one year. That might be something they may be interested in doing.
This is part of the whole brainstorming session that I’m going to try to have over the next month or so. I’ll vet this through HIMSS over the next couple of weeks and hopefully we’ll come up with a good strategy by the end of February. And then we’ll start piloting it in the March timeframe.
I hope to run into McPhillips in Vegas to see how his chat with the HIMSS career development folks is coming along. It’s nice to know that one industry insider’s idea, and subsequent blog comments, might actually create job opportunity in the industry.
Tags: College Consortia • EHR Jobs • EMR • EMR Jobs • EMR Mentor • Health IT • Health IT Mentor • Healthcare IT • HIMSS • HIMSS 12 • HIMSS Las Vegas • HIT • HITECH • LinkedIn • Rich Wicker • Sean McPhillips • Shore Memorial Hospital • workforce developmentJanuary 17, 2012
Sad Illustration of Government’s Understanding of EHR
Written by: JohnI recently saw a tweet to the National Conference of State Legislatures (NCLS) list of “Top 12 Legislative Issues of 2012.” It’s an interesting look into issues that state legislatures will be dealing with in 2012. Plus, it makes an interesting observation at the outset that state budgets have been cut so much in past years that lawmakers won’t have to focus all of their initial energy on budget shortfalls.
Most of the list is not surprising with managing the state budget and jobs are at the top of the list. However, there are a couple healthcare and health IT related sections in their list of top government issues as well.
One of the issues is Medicaid: Efficiencies and quality. It talks about how the tough economy is making the Medicaid budgets in states a real challenge and many are looking for cost containing actions. Plus, it points to ACO type reimbursement based on patients’ health outcomes, medical homes and streamlining services. The ACO part was quite interesting to me. I wonder how much of an effect lack of Medicaid budget will push forward a new model of healthcare.
The disturbing part of the report comes in the “Health: Reform in the states, health care exchanges, technology and benefits. Here’s the section on health IT, the EHR incentive money and HIEs.
HEALTH INFORMATION EXCHANGE: One focus for state legislatures in 2012 will be how to move health care providers, especially those participating in the Medicaid program, toward the adoption of certified electronic health records (EHRs). Essentially, instead of having a different health record at each doctor or provider you visit, an EHR will serve as one file that all of your doctors can see. EHRs, once fully implemented, are expected to provide doctors and health professionals with easier access to patient histories and data, resulting in cost-savings and better health outcomes by removing costly errors and duplications in services.
I love how this basically assumes that by having widespread adoption of EHR software, that we’ll then have one patient record that each doctor you visit can see instead of having a different health record at every doctor. Of course, those of us in the EHR world know that this is a far cry from the reality of EHR software today. In most cases you can’t even share a patient record with someone using the same EHR software as you let alone sharing a patient record with a doctor who is using a different EHR.
The sad part is that whoever wrote these legislative issues must have realized that there was some issue with EHR software exchanging information, because then they wrote the following about the state HIE initiatives.
In addition, states are responsible for building and implementing health information exchanges (HIEs) where those EHRs can be accessed by health care providers. HIEs function like an online file cabinet where your medical record is securely stored, and can be accessed by any doctor or health care professional you visit. By mid-year 2012, every state should have Medicaid EHR Incentive programs in place and will be working toward building an HIE by late 2014 or early 2015 as required by deadlines attached to federal cooperative agreements.
So, wait. If EHR software has created one file where any doctor can access our patient record, then why do we need “an online file cabinet” for our medical records? We know the answer is that we need the online filing cabinet because EHR software isn’t connected and there isn’t one patient record. Each doctor maintains their own patient record and that’s not going to change any time soon.
The above quote also implies that every state is working towards an HIE program per the federal program. I must admit that I haven’t gone through every state, but is every state working on an HIE? I certainly know there are a lot of states working on some sort of HIE project, but I didn’t think that every state had funding for HIE. I guess maybe the question is whether there is any state that doesn’t have some sort of HIE program in the works.
Reading issues described like this, you can understand how government passes legislation with limited understanding. Based on this resource, EHR software creates one patient record. Wouldn’t that be nice if it were the case?
Tags: ACO • EHR Incentive Program • EHR Software • Health Information Exchange • HIE • Medicaid • National Conference of State Legislatures • NCLS • State HIEs • State LegislaturesDecember 9, 2011
EMR Expert Interviews by NaviNet
Written by: JohnI was recently asked by health IT vendor, NaviNet, if I’d be willing to do an interview as part of their “Expert Interview Series.” Since I’m always interested in pontificating about EMR and EHR, I consented. You can find the full interview here.
Here’s one answer I gave that I think really illustrates the key to broad EHR adoption:
You think that will really cause doctors to choose an EHR provider?
I do. I think doctors will talk to other doctors to get first-hand experiences since they’re very social within their own networks. They’ll want to be able to talk to other doctors, hear first-hand experiences. They’ll gravitate to vendors where other doctors say, “Yeah, this is much better for me over using paper.”
Key Message: Doctors Talk!
In the interview, I also suggested three challenges that practices will have in meeting the EHR Meaningful Use requirements:
- The provider didn’t understand the core measure.
- They thought the EHR vendor would do it.
- They thought it was satisfied through HIPAA or something else that they did.
Key Message: Be careful to understand meaningful use properly.
Lots more in the interview, so check out the NaviNet EMR Expert Interview Series for the rest of my answers.
Tags: EHR Adoption • EHR Interviews • EMR Adoption • EMR and EHR • EMR Doctor Talk • EMR Interviews • NaviNetNovember 30, 2011
Guest Post: The Case for Modular EHR Over Complete EHR
Written by: JohnDr. Sullivan is a practicing cardiologist who joined DrFirst in 2004, just after completing his term as President of the Massachusetts Medical Society. He is known throughout the healthcare industry as the father of the Continuity of Care Record (“CCR”) and a leader on the future of healthcare technology. He is assisting DrFirst in ensuring that Rcopia continues to add the functionality necessary to maintain its leadership position both in electronic prescribing and in the channel of communication between various sectors of the healthcare community and the physician. Dr. Sullivan is active in organized medical groups at the state and national level, and is both a delegate to the AMA and the Chairperson of their Council on Medical Service as well as past Co-Chair of the Physicians EHR Consortium.
The buzz surrounding Electronic Health Records (EHR) is nothing short of constant. The daunting task of selection, purchase and implementation is quite confusing, technical, and expensive, with many physicians, clinics and health systems uncertain of their needs and questioning how the technology is going to impact the way they practice medicine and their bottom line. It’s all about workflow and productivity.
More recently, Providers are faced with the intimidating task of deciding which kind of system to install. There are all inclusive systems, often referred to as fully paperless or standard EHRs and there are so called a la carte systems known as modular EHRs.
The Case for Modular
Modular EHR systems allow providers to take a stepping stone approach to health IT clinical documentation and order writing, by choosing the tools and functions which make the most sense in their practices and clinics; improving specialized workflow and efficiency. Going the modular route can gradually ease the provider and the office staff into a more paperless environment without having to make a full and often-times difficult transition to a fully paperless workspace.
There is need for caution however. The sheer volume of modules available can make selecting appropriate ones an overwhelming task. Not only do clinicians need to be wary of which modules they are choosing, but also what functions have been certified by an authorized organization.
By combining specific modular systems, it can become “qualified,” making the user eligible for the monetary reimbursements set forth by Title IV of the American Recovery and Reinvestment Act of 2009 (ARRA).
At DrFirst, our Rcopia-MUTM has taken all of the guess work out of this process and is a completely certified Modular EHR that physicians can implement and start earning incentive money directly out-of-the-box.
The implementation of a complete EHR system can be confusing and time consuming. Herein lays some distinct advantages of implementing a modular EHR. Practices that have already implemented e-prescribing or registry modules may not need to relearn a different system, or move their data from one to another (as long as the current module is certified).
Providers who are considering going the modular route can check the certification status of their options at Certified Health IT Products List. The cost for a modular approach is often much less expensive and providers can select the modules from various vendors to meet their financial and practice-based needs. Upon implementation, providers must show they’re using certified EHR technology in measureable ways to receive their incentive monies from the Federal Government. With this very high ROI, many providers see the advantage of using the modular approach to postpone the decision process in selecting a complete EHR and yet at the same time earn Meaningful Use incentive money to put towards the cost of the much more expensive system.
According to the Centers for Medicare and Medicaid Services, doctors who have not adopted an EHR (either modular or complete) by 2015 will be penalized by Medicare — a 1% penalty to begin, then up to 3% within three years. Many providers are banking on the reimbursement that has been made available by the ARRA to help offset the initial costs.
What is your practice considering, complete EHR or modular? Do you see benefits of one over the other?
Tags: AMA • CCHIT • CCR • CMS • Complete EHR Certification • Complete EHR Software • Continuity of Care Record • Dr. Sullivan • DrFirst • HITECH • Massachusetts Medical Society • Modular EHR Certification • Modular EHR Software • ONC • Rcopia-MUNovember 4, 2011
RECs Expanding “Preferred” Vendor List to Meet Goals
Written by: JohnI’ve gotten word from a couple of different places now that a number of RECs have had to open up another RFP to increase their “preferred” (or whichever term they like to use) EMR vendor list in order to reach the number of meaningful EHR users they need to reach.
Most of you that have read my stuff for a while know how much I dislike how many of the RECs approached the EMR selection process. There are a few RECs that have done a great job of remaining neutral and supporting any and all certified EHR vendors. I applaud their efforts.
I’m just really glad that doctors weren’t fooled by RECs’ preferred vendor lists. The idea that a REC could identify the appropriate EHR vendor for such a wide variety of doctor specialties, sizes, etc is just wrong. I’m glad that the net has been widened by many RECs even if their hand seems to be kind of forced into it to meet their numbers.
I’m fine with RECs specializing in certain EHR software. There’s no way they can be experts in all 300+ EHR software. However, the EMR selection should be driven by the doctors and practice managers and then the RECs support the EMRs selected most often by the actual users.
I guess now we’ll see if RECs start searching for the low hanging fruit to meet their numbers.
Tags: ARRA • EHR Software • HITECH • Preferred EHR Vendor • Preferred EMR Vendor • RECs • Regional Extension Centers • RFPOctober 26, 2011
Pediatrics Face Unique Set of EMR Challenges
Written by: Jennifer Dennard- ACO
- ARRA
- EHR
- Electronic Health Record
- Electronic Medical Record
- EMR
- EMR and EHR Interviews
- Healthcare IT
- Meaningful Use
add to del.icio.us


My recent blog about Sandhills Pediatrics and its successful implementation of an EMR prompted, fortunately, a very intriguing comment from Chip Hart, a Director of Sales and Marketing at Physicians’ Computer Company who also maintains the blog “Confessions of a Pediatric Practice Consultant: True Stories from the land of Pediatric Practice Management.” He wrote: “I’ll spare everyone the diatribe about how ARRA deals with pediatricians and how only about 1/2 of them qualify, as I write to make one quick statement.” There’s a story there, I thought to myself. So, being an avid observer of pediatric EMR news and views, I reached out to him to gauge his thoughts on where healthcare IT solutions fit in the world of pediatricians.
What sort of challenges are you seeing pediatric practices facing when it comes to implementing EMR systems?
“On one hand, most of the challenges they face are hardly unique to pediatrics: resistance to change, practice differences, the lack of time and resources to be trained and configured properly, poor support, etc.
“Specific to pediatrics, there are two major issues. First, children are not simply small adults and EMRs, as a rule, are written for adult medicine. There are many pediatric-specific features and functionality that a pediatric practice needs that simply aren’t met by your large, generic system. Simply claiming “pediatric templates” isn’t enough.
“Second, although every specialty complains about the hit that EMRs take on their productivity, pediatricians are obviously in the worst shape. Their volume is the highest and their payment is the lowest. Just adding a minute to each encounter means an extra 30 minutes of charting a day … and I hear stories, daily, of practices adding another 1 to 2 hours! Pediatricians can’t afford to see 5-percent fewer patients. Radiologists can. And pediatricians really like to eat dinner with their families.
“One second-tier issue is that less than 50 percent of all pediatric practices don’t qualify for ARRA and the regional extension centers (RECs), as a rule, don’t understand the Medicaid rules well. Thus, we have clients and potential clients calling us to ask how they can get money they’ll never get, or to tell us some crazy thing a REC person told them.”
Are there different sets of challenges for those that are private practices versus those that are hospital/healthcare system affiliated?
“Unquestionably – the big one being that hospital/health system pediatricians simply won’t have a choice or even a voice in the process. Yes, I’ve worked with some who appear to be at the table, but in the end … you get what they hand you. Right now, Epic is pushing everyone out but that pendulum will swing back.
Also, those employed physicians don’t have to consider the impact on their productivity in the same way. I’ve met too many peds offices whose docs didn’t take home checks for a few months after implementation – that’s not right.”
Why do you think practices like Sandhills “get it” in terms of moving forward with HIT implementations, and just being forward thinkers in general?
“If I could answer that question, I’d only be working with those practices! Every successful practice I know is successful in a different way for different reasons, but there is one common trait I see in many of them: They run their practices like the businesses they are. Keep the docs in the exam rooms, where they can generate revenue, and hire professionals to actually run the business. Just because it says “MD” after your name doesn’t mean you’re the best-qualified person to run your office. Would Dirk Nowitski or Lebron James make good coaches? I doubt it.
“In the case of Sandhills, they have some excellent, excellent staff who bring some non-healthcare experience to the table. Although I’ve seen it fail, having some management that comes from outside the healthcare system to ask and answer some tough questions pays off for a lot of practices.
“We’ve enjoyed working with them. I should also add that they, like the other ‘heads up’ clients I know, realize that we’re on the same team. That helps tremendously.”
How long have you offered the PCC EMR? What sort of up tick in implementations have you seen since ARRA/HITECH came about?
“Our PM has had pediatric clinical features (immunization tracking, registry interfaces, well visit recall, etc.) for almost 30 years, but the official EMR itself was released about 2 years ago.
“When ARRA was first announced, we received a lot of calls, all along the lines of, “Where do I get my free money?” It was very frustrating to explain that it would be state dependent (about a quarter of them still can’t get it) and half of our clients will never qualify due to the Medicaid requirements.
“Things are starting to settle down and get organized. Still, we are busier right now than we have ever been. We are telling potential clients they might get installed in May or June. A nice problem to have, but it’s not fun to get some excited only to explain it will be 6 months, especially when it used to be 6 weeks!”
Are any of your pediatric clients thinking of becoming involved in ACOs?
“Thinking? Yes. They’re all being told how if they don’t get big, they’ll be out of business, which is utter BS. The rules, as we know them now, seem to make no sense whatsoever for pediatricians. I did see a compelling presentation by Colleen Kraft at the AAP NCE last week that very much supported the ACO-esque model she employs, but I think her situation is both unique and not potentially an ACO.
“With some issues – 5010, PCMH, etc. – we take a pro-active stance. With ACOs, I’m glad to let someone else jump first.”
How will your solutions enable your customers to integrate with ACOs or coordinated care programs?
“Far too soon to tell. In general, I can say, “Hey, we have had really good reports that have tracked patient populations for years.” Our clients use them all the time, as it’s both good medicine and good business. As a practical tool, I’d put our patient recall program up against anyone’s – your front desk can crank out a list of kids who need flu shots or asthma followups in seconds – but we don’t know quite what the ACOs will need.
“One thing we’ve learned, though: when a small peds office puts its data in the hands of a large entity, it’s worth double-checking the results. For more than 20 years, I’ve helped our clients fight insurance companies (which an ACO emulates) and the insurance companies never have the data right. Ever. So if a private peds office can work with us and still be in an ACO, they’ll be able to confirm the accounting.
“Here’s my prediction: As ACOs grow, the practices who participate are going to regret losing control of their data. I’m really going out on a limb there, I know.
What do you think is the greatest challenge being faced by pediatrics when it comes to keeping up with healthcare IT?
“Not getting run over by the Juggernaut. Everyone else’s demands are put ahead of the pediatricians and the peds usually get served what everyone else is eating. And it rarely suits them.
“I also tell them all the time: ignore the Meaningful Use money. Completely. And ignore the “deal” that you can get from your local hospital/IPA/etc. Pick the EHR that suits you the most and go with that. All the discounts or federal checks in the world won’t make up for even a 5-percent hit in your productivity or having to spend an extra 10-20 hours a month on charting or IT work. If you do like the local deal, great! But don’t feel like you have to leap in.”
So there you have it folks. I’d be interested to hear from a pediatrician or two who has gone through or is going through some sort of HIT implementation as a follow-up to these views. Feel free to get in touch with me via the comments section below.
Tags: ACOs • ARRA • Chip Hart • EHR Stimulus • EMR Stimulus • HITECH • Medicaid • Pediactric Practice Management • Pediatric EHR • Pediatric EMR • Physicians' Computer Company • Sandhills PediatricsSeptember 6, 2011
Intermediaries for Meaningful Use Stage 1 – Prime Opportunity?
Written by: Priya Ramachandran- ARRA
- Certified EHR
- EHR
- Electronic Health Record
- Electronic Medical Record
- EMR
- Healthcare
- Healthcare IT
- Meaningful Use
add to del.icio.us


John’s recent post about ONC trained participants finding it difficult to find jobs struck a chord. A different post over at HIMSS had me thinking in overdrive.
Dr. Noam Arzt has a post on Meaningful Use and public health reporting. In it he discusses the problems faced by providers in submitting health information to public health bodies in ways that are also Meaningful Use Stage 1 compliant.
Health records in provider offices are sometimes stored in disparate silos that are cannot/do not communicate with one another. As Dr. Arzt explains with an immunization records example, there is no demonstrable Meaningful Use if an uncertified system makes the data submissions to public health.
Of course, adding additional functionality to the EHR system with a simultaneous revamping of uncertified system to provide Meaningful Use share data with one another is one (costly) solution. Getting the secondary data system certified is another one. A third approach, which Dr. Arzt touches on, is for Health Information Exchanges to act as/provide for certified intermediaries that bridge the data flow between an uncertified system and one that is Meaningful Use certified.
Here’s what HHS had to say about the subject a month ago:
If an intermediary performs a capability specified in an adopted certification criterion and a provider intends to use the capability the intermediary provides to satisfy a correlated meaningful use requirement (submission to public health according to adopted standards), the capability provided by the intermediary would need to be certified as an EHR Module
This intermediary need can be filled, especially by innovative software vendors or those looking to break into the EHR IT industry. From plain data conversions to web services, IT companies have plenty of tricks up their sleeve to assist HIEs. The technology is there, all we need are savvy techies (companies, people) to see the opportunity this presents and act on it.
Tags: Certified EHR • certified intermediaries • Dr. Noam Arzt • EHR • EHR Certification • EHR Module Certificaiton • Electronic Health Records • Health IT • Healthcare IT • HHS • HIE • Meaningful Use • Meaningful Use Stage 1August 25, 2011
Guest Post: ONC-ATCB ICSA Labs – The Future of EHR Testing Requires Security and Privacy Enhancements
Written by: JohnGuest Post – Amit Trivedi – As the healthcare program manager for ICSA Labs, Amit Trivedi spearheads the lab’s overall efforts in the healthcare industry, including launching and managing the 2011/2012 Office of the National Coordinator (ONC) Authorized Testing and Certification Body (ATCB) certification program.

We all know there is no such thing as perfect security. All we can do is try to mitigate as many risks as possible. In this regard, there are areas related to information security that the current ONC-ATCB 2011/2012 (commonly referred to as meaningful use) certification testing does not yet address and that the health IT community should be aware of when implementing systems.
ICSA Labs is an Office of the National Coordinator-Authorized Testing and Certification Body (ONC-ATCB), designated to test both complete and modular electronic health record (EHR) technologies under the auspices of the federal government’s Temporary Certification Program. ICSA Labs has a history rich in the certification of security products. We have been testing security products and developing test criteria for more than two decades and we understand the importance of raising security awareness in the health IT community and helping Eligible Providers and Hospitals understand what meaningful use EHR certification testing does and doesn’t cover.
It is important to remember that regardless of the number of security features a product has, an incorrect or incomplete implementation can introduce vulnerabilities or compromise the security of the system. Certification testing can really only demonstrate that a product is capable of being used securely, not that its security can never be compromised.
Testing bodies must test products within the scope of approved test procedures. As an organization that has developed testing procedures and methodologies, we understand that there is a delicate balancing act when developing requirements so that general concepts and capabilities are covered by the testing, but the testing process is not designed so specifically as to stifle innovation in new products. As such, we recommend that end users and implementers be aware of these requirements when deploying ONC-ATCB 2011/2012 certified products.
Encryption Requirements Do Not Address the “What”
Consider the encryption requirements (criteria 170.302.u and 170.302.v). The current testing criteria require FIPS 140-2 level encryption. This an excellent way to require products to support some of the best levels of encryption available today, and that they are also in line with other federal encryption requirements.
One could compare encryption to a bank vault. You might purchase the most secure, unbreakable vault in the world, but if you don’t put your valuables in the vault, it won’t be of any help when there is a break-in. The current meaningful use testing procedures do not dictate what must be encrypted. Ultimately it falls to end users to make a determination as to how they want to implement security – hopefully basing the decision on a risk-based approach. Fortunately, meaningful use testing and certification follows a staged approach to getting from where we are today to where we’d like to be in the future. The meaningful use certification is planned to be rolled out in three stages. Right now, we are in the midst of Stage 1. Some recommendations to the ONC for Stage 2 security criteria include addressing things like encrypting data at rest (including data in datacenters and mobile devices) – something that is not part of the Stage 1 requirements.
Negative Testing Examines the Unexpected
Another area to highlight is related to negative testing, which is currently out of scope for ONC-ATCBs. The testing performed today relies on giving the EHR an expected input and verifying that the expected result is met. Negative testing, however, is the concept of giving unexpected or invalid inputs to a system and verifying receipt of an expected result (typically, that the data is not accepted or an error is generated that does not crash the system). Negative testing is common throughout ICSA Labs’ proprietary security testing programs and something we feel should be incorporated into future testing of EHR technologies under the ONC Certification program.
Consider the authentication and access control requirements (criteria 170.302.t and 170.302.o). Some of you may be aware of an old Unix bug that resulted in the operating system being unable to correctly support passwords over eight characters. If the password was 12 characters long, a user only needed to enter the first 8 characters to be allowed to login. This made password cracking on Unix servers much easier, and because the system allowed the entry of a longer password, most users were unaware of this limitation.
ICSA Labs has discovered the same or similar problems when testing products in our proprietary security certification programs, and the primary way we discover this is by negative testing. For example, we configure a password greater than eight characters, and then we attempt to login to the system using only the first eight characters. This should be treated as invalid by the system and rejected. However, the meaningful use EHR testing only tests that the system accepts valid passwords. There is no testing done on the system’s acceptance or rejection of invalid passwords.
The Future of EHR Testing Must Increase Security, Privacy
As we progress to the next stages of meaningful use certification, the requirements should begin to look at other areas of security, such as application testing for vulnerabilities like buffer overflows, SQL Injection, and cross-site scripting attacks. These are all examples of security testing best practices. In many instances, ONC has signaled its flexibility in allowing third-party products to complement functionality of EHR technologies, which means that not all of the functionality needs to be native to the product. This can allow EHR developers to focus on functionality that their customers are looking for, while at the same time keeping security as an important consideration in the product life cycle development.
It is our hope that future stages of meaningful use testing will raise the bar and specify how and when features like encryption should be used and the scope of testing will be expanded to include things like negative testing. As the meaningful use criteria evolve, it is critical that both the criteria and testing procedures are developed in ways that consider the long-term security and privacy of patient health records.
Tags: Amit Trivedi • Certified EHR • EHR Certification • EHR Privacy • EHR Security • EHR Testing • EMR Privacy • EMR Security • EMR Testing • FIPS 140-2 • Healthcare IT Security • ICSA Labs • ONC-ATCB • SQL InjectionAugust 22, 2011
101 Tips to Make Your EMR and EHR More Useful – EHR Tips 56-60
Written by: JohnTime for the next entry covering Shawn Riley’s list of 101 Tips to Make your EMR and EHR More Useful. I hope you’re enjoying the series.
If you want to see my analysis of the other 101 EMR and EHR tips, I’ll be updating this page with my 101 EMR and EHR tips analysis. So, click on that link to see the other EMR tips.
60. Reporting, reporting, reporting, reports
What’s the point in collecting the data if you can’t report on it? I’ve before about the types of EMR reports that you can get out of the EMR system. The reports a hospital require will be much more robust than an ambulatory practice. In fact, outside of the basic reports (A/R, Appointments, etc), most ambulatory practices that I know don’t run very many reports. I’d say it’s haphazard report running at best.
Although, I won’t be surprised if the need to report data from your EHR increases over the next couple years. Between the meaningful use reporting requirements and the movement towards ACO’s, you can be sure that being able to have a robust reporting system built into your EHR will become a necessity.
59. Are the meaningful use (MU) guidelines covered by your product?
Assuming you want to show meaningful use, make sure your EHR vendor is certified by an ONC-ATCB. Next, talk to some of their existing users that have attested to meaningful use stage 1. Third, ask them about their approach for handling meaningful use stage 2 and 3. Fourth, evaluate how they’ve implemented some of the meaningful use requirements so you get an idea of how much extra work you’ll have to do beyond your regular documenting to meet meaningful use.
58. It they aren’t CCHIT certified take a really really hard look
Well, it looks like this tip was written pre-ONC-ATCB certifying bodies. Of course, readers of this site and its sister site, EMR and HIPAA, will be aware that CCHIT Has Become Irrelevant. Now it’s worth taking a hard look if the EHR isn’t an ONC-ATCB certified EHR. There are a few cases where it might be ok, but they better have a great reason not to be certified. Not because the EHR certification provides you any more value other than the EHR vendor will likely need that EHR certification to stay relevant in the current EHR market.
57. What billing systems do you interface with?
These days it seems in vogue to have an integrated EMR and PMS (billing system). Either way, it’s really important to evaluate how your EMR is going to integrate with your billing. Plus, there can be tremendous benefits to the tight integration if done right.
56. How much do changes and customizations cost?
In many cases, you can see and plan for the customization that you’ll need as part of the EHR implementation. However, there are also going to be plenty of unexpected customizations that you don’t know about until you’re actually using your EHR (Check out this recent post on Unexpected EHR Expenses). Be sure to have the pricing for such customizations specified in the contract. Plus, as much as possible try to understand how open they are to doing customizations for their customers.
Check out my analysis of all 101 EMR and EHR tips.
Tags: 101 EHR Tips • ACO • CCHIT • Certified EHR • EHR Billing • EHR Certification • EHR Customization • EHR Implementation • EHR Interface • EHR Reports • EHR Selection • EHR Tips • EMR • EMR Billing • EMR Customization • EMR Implementation • EMR Interface • EMR Platform • EMR Reporting • EMR Reports • EMR Selection • EMR Tips • Hospital EMR • ONC-ATCBJuly 14, 2011
EHR Experiences – One Clinic’s Road to Meaningful Use
Written by: John- ARRA
- EHR
- Electronic Health Record
- Electronic Medical Record
- EMR
- EMR and EHR Interviews
- Healthcare IT
- Meaningful Use
add to del.icio.us


Our next edition of EMR and EHR interviews covers the experience of Jan Patterson and the West Broadway Clinic’s path to meaningful use. The full EMR interview with Jan Patterson can be found on the new EHR and EMR interviews website. The following is a summary of that interview written by Kathy Bongiovi.
If you’re a doctor, nurse, practice manager, EHR consultant, CEO or executive of an EHR vendor, etc with EMR experience that’s interested in being interviewed, let us know on our Contact Us page.
West Broadway Clinic is one of the first clinics to show Meaningful Use. Jan Patterson, the office manager of West Broadway Clinic explained it was the clinic’s desire, from day one, to start using an EHR. The EHR certification is a vital piece for meeting the CME incentive requirements. Additionally the providers felt by using an EHR on day one they could ensure a continuity of care, regardless of which provider a patient might see in the clinic.
The clinic had heard about Cerner Corporation through one of the local hospitals. After interviewing several other vendors it felt that the integration of Cerner’s Practice Management System and Ambulatory EHR would suit its needs best.
West Broadway began using its EHR in May of 2008 and Patterson stated it was able to meet at least 9 of the meaning use requirements because of its EHR. Patterson felt two of the major factors contributing to meeting those requirements so easily were the elements already built into the EHR and the use of the Cerner EHR. As the clinic encountered issues it was able to contact Cerner’s Meaning Use team to assist in the process of attestation.
Additionally, attending Webinars set up by Cerner Corporation, examining materials provided by Medical Group Management Association (MGMA), and attending an MU Summit set up by Cerner Corporation to highlight some of the more important segments of MU, all played an integral role in ensuring West Broadway Clinic would meet Meaningful Use requirements.
The most challenging Meaningful Use requirement was encouraging all of the providers to use the electronic prescriptions function. After reaching MU in just over three months, just two days after attestation opened, Jan Patterson states the clinic continues to maintain its high level of entering the patients’ correct and necessary data and the numbers of electronic prescriptions being sent to pharmacies are increasing.
The benefits to patient care are immediate access to the most current visit information and patient history at its finger tips. Patients receive more continuity of care due to the fact that regardless of what provider they are seeing within their office , the provider can quickly and easily track what services and/or medications a different provider has provided the patient. Components such as eprescribe, medicine/drug interactions, allergy checks, complete documentation, immunization schedules and growth charts etc., have made the clinic more efficient throughout the office.
Patterson’s advice to anyone starting the MU process is to make sure you have gathered all the information and facts first and ensure all physicians/staff are not only fully advised of what is required to meet MU but are also committed to following the process through to its completion. It is important they understand the benefits and necessity of Meaningful Use. After three years of being on an EHR, Patterson cannot imagine functioning as efficiently on a paper system. Although Patterson acknowledges the money as an incentive, the real benefit in successfully attesting is the benefit to their patients. As Patterson suggests, “The increased benefits of safety cannot be undersold. With the assistance of the EHR, we are practicing better, safer medicine than we could on paper records.”
Read the full transcript of Jan Patterson’s interview.
Tags: Cerner • Cerner Corporation • CME Incentive • EHR Certification • EHR Selection • EHR Vendor • EMR and EHR Interviews • Healthcare IT Interviews • Jan Patterson • Medical Group Management Association • MGMA • MU Summit • West Broadway Clinic



