What is HIPPA - Health Insurance Portability and Accountability Act

The The Health Insurance Portability and Accountability Act (HIPAA) of 1996 (P.L.104-191) [HIPAA] was enacted by the U.S. Congress in 1996. According to the Centers for Medicare and Medicaid Services (CMS) website, Title I of HIPAA protects health insurance coverage for workers and their families when they change or lose their jobs. Title II of HIPAA, known as the Administrative Simplification (AS) provisions, requires the establishment of national standards for electronic health care transactions and national identifiers for providers, health insurance plans, and employers. This is intended to help people keep their information private, though in practice it is normal for providers and health insurance plans to require the waiver of HIPAA rights as a condition of service.

The Administration Simplification provisions also address the security and privacy of health data. The standards are meant to improve the efficiency and effectiveness of the nation's health care system by encouraging the widespread use of electronic data interchange in the U.S. health care system.

What is HL7 - Health Level Seven

Health Level Seven (HL7), is an all-volunteer, not-for-profit organization involved in development of international healthcare standards. "HL7" is also used to refer to some of the specific standards created by the organization (e.g., HL7 v2.x, v3.0, HL7 RIM).
HL7 and its members provide a framework (and related standards) for the exchange, integration, sharing, and retrieval of electronic health information. v2.x of the standards, which support clinical practice and the management, delivery, and evaluation of health services, are the most commonly used in the world.

HL7 is an international community of healthcare subject matter experts and information scientists collaborating to create standards for the exchange, management and integration of electronic healthcare information
 
HL7 Standards


Hospitals and other healthcare provider organizations typically have many different computer systems used for everything from billing records to patient tracking. All of these systems should communicate with each other (or "interface") when they receive new information but not all do so. HL7 specifies a number of flexible standards, guidelines, and methodologies by which various healthcare systems can communicate with each other. Such guidelines or data standards are a set of rules that allow information to be shared and processed in a uniform and consistent manner. These data standards are meant to allow healthcare organizations to easily share clinical information. Theoretically, this ability to exchange information should help to minimize the tendency for medical care to be geographically isolated and highly variable.

HL7 develops Conceptual Standards (e.g., HL7 RIM), Document Standards (e.g., HL7 CDA), Application Standards (e.g., HL7 CCOW), and Messaging Standards (e.g., HL7 v2.x and v3.0). Messaging standards are particularly important because they define how information is packaged and communicated from one party to another. Such standards set the language, structure and data types required for seamless integration from one system to another.



HL7 encompasses the complete life cycle of a standards specification including the development, adoption, market recognition, utilization, and adherence. Access to the HL7 standards requires paid membership of HL7 Inc. or one of its affiliates.

What is PHR - Personal Health Record (PHR)?

There is no industry-wide definition for a PHR at this point. However, Connecting For Health published a report entitled “Connecting Americans to their Healthcare” in July, 2004 and defined the PHR as “… an Internet-based set of tools that allows people to access and coordinate their lifelong health information and make appropriate parts of it available to those who need it. PHRs offer an integrated and comprehensive view of health information, including information people generate themselves, such as symptoms and medication use, information from doctors such as diagnoses and test results, and information from their pharmacies and insurance companies. Individuals access their PHRS via the Internet, using state-of-the-art security and privacy controls, at any time and from any location.”1


The American Health Information Management Association also developed a definition of the Personal Health Record and published it in 2005:

“The personal health record (PHR) is an electronic, universally available, lifelong resource of health information needed by individuals to make health decisions. Individuals own and manage the information in the PHR, which comes from healthcare providers and the individual. The PHR is maintained in a secure and private environment, with the individual determining rights of access. The PHR is separate from and does not replace the legal record of any provider.”2 This definition can be accessed at http://library.ahima.org/xpedio/groups/public/documents/web_assets/bok1_016846.hcst.

These two definitions both focus on the individual as the primary user and controller of the PHR. Other perspectives in the industry focus on different models of PHRs such as those provided by insurers and those available from health care providers. PHRs connected with insurance companies may be automatically loaded with claims information such as dates of visits and reasons for visit, generally indicated by ICD-9 CM or CPT 4 codes.

Privacy and Security Considerations


The National Committee on Vital and Health Statistics noted that “public support … depends on public confidence and trust that personal health information is protected. Any system of personal health information collection, storage, retrieval, use, and dissemination requires the utmost trust of the public. The health care industry must commit to incorporating privacy and confidentiality protections so that they permeate the entire health records system.” 3 In response the Office of the National Coordinator for Health Information Technology (ONC), in support of the American Health Information Community (AHIC) Consumer Empowerment (CE) Workgroup, requested a thorough review of existing PHR privacy and security policies from the Altarum Institute. On January 5, 2007 the Review of the Personal Health Record Service Provider Market Privacy and Security was published. 4

It concluded with the following observations:

“Our review of 30 publicly available privacy policies revealed wide variation in understanding and implementation. We also note that not every PHR vendor Web site has a publicly available privacy policy, and we found more than one instance of privacy policies that could only be reached after enrolling and providing private information such as an email address.

We draw the following conclusions from our analysis:

• Based on our analysis of 30 PHR vendors, existing privacy policies are incomplete;

• Consensus requirements for the contents of a PHR privacy policy do not yet exist, and many vendors appear to have focused instead on security procedures and Internet privacy descriptions;

• Transparency of secondary use of data could be greatly improved;

• The majority of vendors reviewed did not reference HIPAA;

• Data disposal rules and regulations are ill-defined, especially for closed accounts and vendors that go out of business; and

• Many specific terms including “personal health information” are not defined in the privacy policy or related documentation.”

The report makes three recommendations, including:

• Privacy, in the context of the PHR, should have a commonly-understood meaning among all vendors, healthcare providers and consumers;

• Consumers and vendors will need to establish a forum to develop a common understanding of the most important components of a PHR privacy policy, especially on the level of transparency in secondary use of data; and

• There is a clear role for the AHIC work groups to help define a “model privacy policy” for the PHR industry, an ideal form against which other policies can be compared, as for example OMB provided for the Federal Web site privacy policy.

The results and recommendation of the Altarum Institute’s report introduce a cautionary note for consumers when considering a PHR. For many individuals the PHR can provide many benefits. However, unless adequate measures are taken to protect the privacy of the individual and the security of their health information harm to the individual may result. Before one embraces the use of a PHR the following questions should be addressed:


• What measures are taken to protect my health information?

• Who has access?

• How is access controlled?

• Who can add, modify, or delete information?

• Is the data encrypted when transmitted and when stored?

• Can my information be decrypted without my password?

• Does anyone have access to my password?

• Is my password encrypted when stored or transmitted?

• How is my information backed-up?

• How would it be restored if lost?

• How can I be sure that my information will always be available on-line?

• What happens to my information if you go out of business?

• Who owns the company?

• Is my information ever used by anyone without my explicit consent?

• Is my information ever de-identified for use by others without my explicit consent?

• Is my information aggregated with that of others for use by others without my explicit consent?

What is EHR - Electronic Health Record?

An electronic health record (EHR) (also electronic patient record or computerised patient record) is an evolving concept defined as a longitudinal collection of electronic health information about individual patients or populations. It is a record in digital format that is capable of being shared within across different health care settings, by being embedded in network-connected enterprise-wide information system. Such records may included a whole range of data in comprehensive or summary form, including demographics, medical history, medication and allergies, immunization status, laboratory test results, radiology images, and billing information.
It is important to note that an EHR is generated and maintained within an institution, such as a hospital, integrated delivery network, clinic, or physician office.

Its purpose can be understood as a complete record patient encounters that allows to automate and streamline workflow in health care settings and to increase safety through evidence-based decision support, quality management, and outcomes reporting.

Standards


ANSI X12 (EDI) - transaction protocols used for transmitting patient data. Popular in the United States for transmission of billing data.
CEN's TC/251 provides EHR standards in Europe including:
EN 13606, communication standards for EHR information
CONTSYS (EN 13940), supports continuity of care record standardization.
HISA (EN 12967), a services standard for inter-system communication in a clinical information environment.
Continuity of Care Record - ASTM International Continuity of Care Record standard
DICOM - an international communications protocol standard for representing and transmitting radiology (and other) image-based data, sponsored by NEMA (National Electrical Manufacturers Association)
HL7 - a standardized messaging and text communications protocol between hospital and physician record systems, and between practice management systems
ISO - ISO TC 215 provides international technical specifications for EHRs. ISO 18308 describes EHR architectures
 




What is EMR - Electronic Medical Record?

What is EMR - Electronic Medical Record?

An electronic medical record is usually a computerized legal medical record created in an organization that delivers care, such as a hospital and doctor's surgery. Electronic medical records tend to be a part of a local stand-alone health information system that allows storage, retrieval and manipulation of records.


Technical Features

Using an EMR to read and write a patient's record is not only possible through a workstation but depending on the type of system and health care settings may also be possible through mobile devices that are handwriting capable. Electronic Medical Records may include access to Personal Health Records (PHR) which makes individual notes from a EMR readily visible and accessible for consumers.

Technical Standards
Though there are few standards for modern day EMR systems as a whole, there are many standards relating to specific aspects of EMRs. These include:


XML - a document format allowing easy interoperability.
HL7 - messages format for interchange between different record systems and practice management systems.
ANSI X12 (EDI) - A set of transaction protocols used in the US for transmitting virtually any aspect of patient data.
CEN - CONTSYS (EN 13940), a system of concepts to support continuity of care.
CEN - EHRcom (EN 13606), a standard for the communication of information from EHR systems.
CEN - HISA (EN 12967), a services standard for inter-system communication in a clinical information environment.
DICOM - a standard for representing and communicating radiology images and reporting

What is Health Informatics?

What is Health Informatics?

Health Informatics is concerned with the development, dissemination and use of information and communication technologies in health care. Exciting career opportunities are emerging for health professionals with knowledge and skills in information and computer science, management, health care systems, and research methods.

The role of the Health Informatics professional is dynamic and involves close liaison with medical, nursing and administrative staff, other health professionals, IT staff and the public. Health Informatics professionals are involved in the innovation and development of information systems that support patient care, health planning, health care evaluation, financial management and medical research.

Current developments in Health Informatics

The field of Health Informatics is one of the fastest growing areas within the health sector. The Master of Health Informatics course was designed to respond to the changing needs of health professionals and health organisations in our increasingly electronic environment. Advances in IT (e.g. Smart Cards, Voice Recognition Technology, Electronic Health Records, Decision Support Systems) are creating very exciting opportunities for Health Informatics professionals in a range of organisations including IT firms, hospitals, government departments and health funds.

Professional associations

Reflecting the broad nature of Health Informatics, the professional bodies associated with the profession include:

The Australian College of Health Informaticians (ACHI)
www.achi.org.au
The Health Informatics Society of Australia (HISA)
www.hisa.org.au
The Health Information Management Association of Australia (HIMAA)
www.himaa.org.au
The two key bodies internationally are:

The International Medical Informatics Association (IMIA)
www.imia.org
The American Medical Informatics Association (AMIA)
www.amia.org

What is Health IT (Health Information Technology)

Health information technology (HIT) provides the umbrella framework to describe the comprehensive management of health information and its secure exchange between consumers, providers, government and quality entities, and insurers. Health information technology (HIT) in general are increasingly viewed as the most promising tool for improving the overall quality, safety and efficiency of the health delivery system (Chaudhry et al., 2006). Broad and consistent utilization of HIT will:

Improve health care quality;
Prevent medical errors;
Reduce health care costs;
Increase administrative efficiencies;
Decrease paperwork; and
Expand access to affordable care.

Interoperable health IT will improve individual patient care, but it will also bring many public health benefits including:

Early detection of infectious disease outbreaks around the country;
Improved tracking of chronic disease management; and
Evaluation of health care based on value enabled by the collection of de-identified price and quality information that can be compared.