There is no industry-wide definition for a PHR at this point. However, Connecting For Health published a report entitled “Connecting Americans to their Healthcare” in July, 2004 and defined the PHR as “… an Internet-based set of tools that allows people to access and coordinate their lifelong health information and make appropriate parts of it available to those who need it. PHRs offer an integrated and comprehensive view of health information, including information people generate themselves, such as symptoms and medication use, information from doctors such as diagnoses and test results, and information from their pharmacies and insurance companies. Individuals access their PHRS via the Internet, using state-of-the-art security and privacy controls, at any time and from any location.”1
The American Health Information Management Association also developed a definition of the Personal Health Record and published it in 2005:
“The personal health record (PHR) is an electronic, universally available, lifelong resource of health information needed by individuals to make health decisions. Individuals own and manage the information in the PHR, which comes from healthcare providers and the individual. The PHR is maintained in a secure and private environment, with the individual determining rights of access. The PHR is separate from and does not replace the legal record of any provider.”2 This definition can be accessed at http://library.ahima.org/xpedio/groups/public/documents/web_assets/bok1_016846.hcst.
These two definitions both focus on the individual as the primary user and controller of the PHR. Other perspectives in the industry focus on different models of PHRs such as those provided by insurers and those available from health care providers. PHRs connected with insurance companies may be automatically loaded with claims information such as dates of visits and reasons for visit, generally indicated by ICD-9 CM or CPT 4 codes.
Privacy and Security Considerations
The National Committee on Vital and Health Statistics noted that “public support … depends on public confidence and trust that personal health information is protected. Any system of personal health information collection, storage, retrieval, use, and dissemination requires the utmost trust of the public. The health care industry must commit to incorporating privacy and confidentiality protections so that they permeate the entire health records system.” 3 In response the Office of the National Coordinator for Health Information Technology (ONC), in support of the American Health Information Community (AHIC) Consumer Empowerment (CE) Workgroup, requested a thorough review of existing PHR privacy and security policies from the Altarum Institute. On January 5, 2007 the Review of the Personal Health Record Service Provider Market Privacy and Security was published. 4
It concluded with the following observations:
“Our review of 30 publicly available privacy policies revealed wide variation in understanding and implementation. We also note that not every PHR vendor Web site has a publicly available privacy policy, and we found more than one instance of privacy policies that could only be reached after enrolling and providing private information such as an email address.
We draw the following conclusions from our analysis:
• Based on our analysis of 30 PHR vendors, existing privacy policies are incomplete;
• Consensus requirements for the contents of a PHR privacy policy do not yet exist, and many vendors appear to have focused instead on security procedures and Internet privacy descriptions;
• Transparency of secondary use of data could be greatly improved;
• The majority of vendors reviewed did not reference HIPAA;
• Data disposal rules and regulations are ill-defined, especially for closed accounts and vendors that go out of business; and
• Many specific terms including “personal health information” are not defined in the privacy policy or related documentation.”
The report makes three recommendations, including:
• Privacy, in the context of the PHR, should have a commonly-understood meaning among all vendors, healthcare providers and consumers;
• Consumers and vendors will need to establish a forum to develop a common understanding of the most important components of a PHR privacy policy, especially on the level of transparency in secondary use of data; and
• There is a clear role for the AHIC work groups to help define a “model privacy policy” for the PHR industry, an ideal form against which other policies can be compared, as for example OMB provided for the Federal Web site privacy policy.
The results and recommendation of the Altarum Institute’s report introduce a cautionary note for consumers when considering a PHR. For many individuals the PHR can provide many benefits. However, unless adequate measures are taken to protect the privacy of the individual and the security of their health information harm to the individual may result. Before one embraces the use of a PHR the following questions should be addressed:
• What measures are taken to protect my health information?
• Who has access?
• How is access controlled?
• Who can add, modify, or delete information?
• Is the data encrypted when transmitted and when stored?
• Can my information be decrypted without my password?
• Does anyone have access to my password?
• Is my password encrypted when stored or transmitted?
• How is my information backed-up?
• How would it be restored if lost?
• How can I be sure that my information will always be available on-line?
• What happens to my information if you go out of business?
• Who owns the company?
• Is my information ever used by anyone without my explicit consent?
• Is my information ever de-identified for use by others without my explicit consent?
• Is my information aggregated with that of others for use by others without my explicit consent?
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment