Cool Technology of the Week

CIOs are responsible for achieving at least 99.9% uptime and that implies high reliability engineering of every component.   In planning for disaster recovery, we tend focus on power, storage, servers, networks, and desktops.  However if cooling fails, no amount of redundant engineering will save the day.

BIDMC's primary data center uses glycol coolers (installed before we took possession of the building) to maintain a constant room temperature.  We were concerned that the piping which carries the glycol to/from the roof top dry coolers and the computer room air conditioning units may have deteriorated over time and might pose a risk of joint rupture.    Ty Dell, our data center facilities engineer, arranged to have the pipes inspected via ultrasound imaging to assess pipe and joint thickness.   They passed all inspections.

Here's the report which provides us with reassurance that we have low risk for failure in our cooling system plumbing.

Non-invasive ultrasound testing of data center cooling infrastructure - that's "cool".

Reflections on Japan

In my blogs of the past two weeks, I've included many references to the people, places, and experiences I had while traveling in Japan speaking about the  need to implement healthcare IT to support earthquake/tsunami response, hospital rebuilding, and the healthcare needs of the aging Japanese society.

Here are few personal observations about the country and its people in the aftermath of 3/11 (the Japanese term for the events that took place on Friday, March 11, 2011)

Impact on electric power
The area served by TEPCO does remain significantly affected by the reduction in power availability due to nuclear plant shutdown . Currently Tokyo has voluntarily reduced power consumption by 30% by limiting cooling, public lighting, and private consumption.   West of Tokyo in Kyoto and Hiroshima, I did not experience any specific power reduction measures.   When I talked to people in the Kansai  and Chugoku regions about their post earthquake experiences,  they noted that power savings of 15% is requested in the Kansai region for large institutions such as Kyoto University.   It is not mandated as in Tokyo, but folks in Kyoto feel psychologically compelled to save power.

Impact on tourism
In Hiroshima, we stayed on Miyajima (a small sacred island off the coast) at the Yamaichi Bekkan run by a wonderful woman named Shinko Yamamatsu and her son Teppei.   She noted her ryokan experienced a significant number of cancellations by foreign tourists who fear that Japan is unsafe or unstable following the earthquake.   My experiences in Kyoto, and Hiroshima were flawless - safe food, completely functional infrastructure, and a very welcoming people.  I highly recommend that foreign tourists proceed with any Japanese travel plans to Kyoto and Hiroshima.    During this trip, I enjoyed freshly prepared meals at all my favorite vegetarian restaurants in Kyoto including OkutanFujino,  and Kiko.   On Miyajima, all our extraordinary meals were prepared by Shinko and her staff.

Impact on government trust
Communication from government officials about the radiation levels and food safety in the area immediately surrounding Fukushima, has been problematic.  As a people, the Japanese generally trust their government to be good stewards of resources and supportive of public interests.  However, people are now doubting government reports about environmental and food safety.     Some are beginning to monitor radiation levels in their local neighborhoods by purchasing sophisticated equipment   .   Sales of pre-disaster food products are brisk.

Impact on Electronic Health Record acceleration
Currently, the use of information technology for medical care is getting attention in Japan. The Japanese Kantei created a task force on healthcare IT in August 2010 and the May 2011 task force report advocates acceleration of electronic health records and personal health records, including a concept called My Virtual Hospital.   Here's an English translation of the current thinking.  In addition to the policy recommendations that I proposed in my paper and lectures during this trip, I will work with US and Japanese experts on a privacy whitepaper to outline a path forward for secure internet-based healthcare information exchange in Japan that takes into account existing Japanese privacy regulations. There are three kinds of regulations concerning medical record privacy protection in Japan. The first is a series of laws which stipulate confidentiality of specific occupations related to medical services such as physicians. The second is the Act concerning Protection of Personal Information approved in 2003, which more generally regulates privacy protection including medical records. The third is the Guideline of Privacy Protection for Medical and Nursing Care Services, which is not legally binding but backs up the other two types of laws comprehensively in the medical and nursing care sector.

Impact on future policy planning
On August 6, 1945, the United States dropped an atomic weapon on Hiroshima.   Hiroshima hosts annual meetings in August to reflect on the policy impacts of nuclear weapons, nuclear power and health.   This year, the focus was the aftermath of the Fukushima events and the need to reconsider dependence on nuclear power.

Japan is my second home and I have deep affection for its people, culture and geography.   Recovery is proceeding rapidly and I recommend we do all we can to help by visiting Japan, contributing our expertise and volunteering our time.

The Burden of Compliance

In a recent email noting the challenges of implementing ICD-10, 5010, eRx, EHR, and HIE simultaneously, Jim Walker (CMIO of Geisinger) referenced a paper in the British Medical Journal by Enrico Coiera ( BMJ 342: d3693, 2011)

"Experimental computer modeling has shown that as the number of dependencies increases in a system, the height of the local optimums [of organizational fitness] in a landscape lowers.  In other words, the more dependencies there are in a system, the more likely they will be in conflict (through competing demands), flattening the landscape and diminishing the potential for improving system fitness. Thus the more complex a health system becomes, the more difficult it becomes to find any system design that has a higher fitness."

As we draft new regulations that impact healthcare IT organizations, we need to keep in mind that every regulation has a cost in dollars, time, and complexity.

Many people have spoken to me about the burden created by the Accounting of Disclosures NPRM, highlighting three major challenges it creates - an implementation burden that goes beyond the intent of HITECH, an inadequate impact analysis especially on small entities, and administrative overhead that is incompatible with impending budget cuts from the recent debt ceiling compromise plan.

The wording in the proposed rule which summarizes its intent is

"These two rights, to an accounting of disclosures and to an access report, would be distinct but complementary. The right to an access report would provide information on who has accessed electronic protected health information in a designated record set (including access for purposes of treatment, payment, and health care operations), while the right to an accounting would provide additional information about the disclosure of designated record set information (whether hard-copy or electronic) to persons outside the covered entity and its business associates for certain purposes (e.g., law enforcement, judicial hearings, public health investigations). The intent of the access report is to allow individuals to learn if specific persons have accessed their electronic designated record set information (it will not provide information about the purposes of the person's access). In contrast, the intent of the accounting of disclosures is to provide more detailed information (a 'full accounting') for certain disclosures that are most likely to impact the individual."

Here's a commentary based on the feedback I've received.

Challenge 1 – Scope beyond the intent of the HITECH Act

Protecting privacy is essential to building patient trust in electronic health records and health information exchanges.

To me, the intent of HITECH is to offer patient access upon request to EHR audit trails and HIE audit trails.   However, the proposed rule goes beyond that, creating the concept of a "designated record set" and "disclosure logs" while exempting HIE transactions.  It's too much and too little at the same time.

The Designated Record Set (DRS) is a super-set of information that includes the Electronic Health Record as well as data housed in many other systems including billing, quality, research, and operational data bases.   It includes data shared with business associates such as small entities which provide specialty billing, transcription, and other services.   By characterizing the accounting requirements around the more broadly defined DRS, the burden of compliance has been greatly increased, requiring new technologies to aggregate audit logs from a broad array of software applications.

Disclosures are broadly defined as the release of patient information to other entities.   This means that every access to the Designated Record Set by physicians, nurses, allied health, lab, billing, accountants, auditors, legal staff, and numerous other "business associates" which are involved with a patient episode of care within the covered entity must be logged, aggregated, and reported to patients on-demand.

Business Associates are extensions of a health care provider, plan or clearinghouse’s workforce.   An example is a business hired by a physician practice to bill and collect medical fees.   Another example is an independent contractor who provides coding or transcription services.   Business Associates provide a wide variety of services.  Some may access content of the Designated Record Set as a direct consequence of their role such as a transcriptionist.   Some may access DRS content as an incidental part of their role, such as a software vendor performing troubleshooting on a data base.    Under the proposed rule, each of these must be logged and included in the disclosure accounting. 

By requiring providers to create disclosure logs on designated record sets including business associate access,  I believe HHS has gone beyond the intent of HITECH.

Challenge 2 – Inadequate Regulatory Analysis

In describing the regulatory impact, HHS under-stated the expense burden that the proposed rule will impose.

On page 31442 of the May 31, 2011 Federal Register, the proposed rule notes  “We estimate the effects of the requirement for covered entities (including indirect costs incurred by third party administrators, which frequently send out notices on behalf of health plans) to issue new notices of privacy practices, would result in new total costs of $20.2 million.”

The accompanying commentary suggests most of the information needed is already available for disclosure logging.   This suggests a lack of knowledge of current state of  healthcare information systems.

HHS notes costs will be limited because the number of requests for disclosure accounting will be few.  However, it's not the number of requests that will drive the cost, but the preparation needed to meet a request whether there is one or one thousand.

In the Federal Register, HHS suggests there are 673,324 entities that will be impacted by these regulations.  This is another understatement as it only includes providers, insurance carriers, and third party administrators.  To this count, must be added the hundreds of thousands, perhaps millions of businesses and independent contractors who do commerce with a one of the 673,324 and receive protected health information under a Business Associates Agreement.  

Without counting Business Associates, this works out to $30 per entity, an absurdly low figure.

With Business Associates included, the proposed rule will impact more than a million entities.  Every business and independent contractor that provides transcription, billing, computer repair, auditing, or other service to a health care provider, plan or clearinghouse will be affected.  A high percentage of these are small businesses.

The cost of modifying or upgrading just one software application and educating a two person staff would easily exceed $5,000 in first year implementation cost.   Many organizations face modifications to dozens of systems, educating thousands of employees, and modifying hundreds of Business Associates Agreements.  

Even if only 500,000 firms are affected, at $5,000 each the total cost to implement the proposed rule would be $2.5 billion.   A more realistic estimate is in excess of $10 billion.

Challenge 3 – Incompatibility with the Federal debt challenge

The debate on the debt ceiling over the past two weeks included a discussion of reductions in payments to providers and hospitals.   Yet, as currently proposed, the rule adds billions in additional costs.

A 1999 study comparing Canadian and U.S. health care costs showed administrative overhead consumed 31 percent of the U.S. health care dollar.   In Canada, administrative overhead accounted for only 16.7 percent of their health care costs, nearly half what we require in the U.S.   We cannot add more administrative overhead and hope to reduce Medicare cost without affecting access or quality of care.

The healthcare industry has often been criticized for inefficiencies.  What other industry, including the Federal government is asked to produce an accounting, on demand, of everyone who touches data for any reason?    It does not occur in banking, brokerage firms, or credit card processors.  It doesn’t even occur with the Internal Revenue Service.

To impose such demanding requirements on the healthcare industry at a time when administrative cost reduction is a top priority seems counter intuitive.

In summary:

The rule should be revised to limit scope to that which is needed to support the spirit of HITECH.

The rule should not be implemented until a realistic regulatory impact analysis can be completed.

The healthcare industry will undergo an upheaval as it contends with healthcare reform and reimbursement decreases.    It does not make sense to impose significant regulatory burden while constraining supply (Medicare funding)  and maintaining all Medicare benefits such that demand will continue to rise.

I look forward to reading the HHS analysis of comments and hope the final rule supports enough auditing to foster patient trust, while realistically constraining the burden on implementers.

Characteristics of High Performing Teams

I've written previously about those times in my career when alignment of leadership and resources led to major achievements.   High performing teams are a pre-requisite to such achievement and here are a few characteristics of high performing teams I have worked with:

Competence
Domain expertise and an ability to execute assigned tasks are key to ensuring vision is turned into successful implementation.   My experience is that "A" players hire "A" players and "B" players hire "C" players.   This means that highly competent people surround themselves with skilled people because they do not feel intimated  by having subordinates or colleagues who are smarter, more talented, or more successful.   No member of a team can do everything, so having a group of smart people working together creates a sum greater than the parts.  On the other hand, incompetent people tend to hire even less competent people to shore up their own egos and self image.   Leaders need to be very careful when retaining marginally performing teams, because incompetent people hiring less competent people can get the organization in trouble very quickly.

Trust
As a rock climber, I know that my life depends upon the skill and decision making of my climbing partner.   No matter how good I am, a mistake by my partner could kill both of us.   Every day I think about my teams and ask if I would trust them to hold my rope.   A high performing team requires a level of trust and confidence that fosters a joy of collective achievement rather than fear of individual failure.   Creating an environment of trust has worked for me as a parent and is an essential part of a optimized team.

Communication
I realize that carrying mobile devices creates the burden of being connected 24 hours a day.   I do not inflict my own work schedule on any of my teams (my last true day off was in the summer of 1984).   However, creating a level of communication among team members that enables rapid escalation and resolution of issues is essential to high performance.   Teams should respect the need for time away but arrange coverage such that email, instant messaging, paging, phone calls, and web-based collaboration can be initiated at a moment's notice for resolution of complex issues that are often precipitated by circumstances beyond the control of the team.   Teams should create a level of transparency that keeps all members informed of current priorities, strategies, and challenges using blogs, wikis, and meetings (to the extent necessary).   Great communication reduces friction, enhances decision making, and reduces unnecessary work.

Loyalty
Highly functional team members are always there for each other.  No matter what happens, they do not throw their colleagues under the bus.  They give an early heads up when projects or staff members are in trouble.  They accelerate decision making by contributing positively to consensus building.   They respect hierarchical boundaries, escalating problems by collaborating with team leaders and managers.   The result is a team that is deeply loyal to its members rather than focused on highlighting the success of any one individual.

The Greater Good
In my trip to Japan, I discussed priority setting in the Japanese bureaucracy.   At times it appears that ministries set priorities based on sustaining their own power and authority.  Bureaus within ministries can set priorities in silos.   Rarely is the greater good for the country the driving force that unifies budgeting at every level.   Highly functional teams think about the overall goals of the organization and craft their plans around those activities which will create the greatest good for the greatest number.   There is not siloed thinking about resources, budgets, or achieving individual goals at the expense of team of goals.

High performing teams are hard to create and sustain, but when they happen, they are to be treasured.   There is nothing I will not do for my high performing teams.

The Pace of Change

My travels in Japan included lectures in Tokyo and Kyoto, sharing lessons learned from the US health information technology national efforts.    I highlighted that the Office of the National Coordinator has to balance the desire for innovation with a pace of change that vendors and clinicians can tolerate.

This led me to think about the pace of change that CIOs are experiencing right now.  The IT innovations of the past few years have been dizzying and the cycle between the peak of hype to the trough of obsolescence is now measured in months, not years.

Some examples of rise and fall

1.  Blackberry - I was one of the earliest adopters of Blackberry technology, using a small pager-like device for short text messages.  As each new model was announced, I welcomed the innovations - the evolution from thumbwheel to joystick to track pad, larger color screens, cameras, video features, and voice memo recording.   However, in 2011, my mobile device needs have outpaced Blackberry's engineering.  I now need a full featured web browser, a book reader, the ability to zoom/drag via touch screen, and a robust App Store.   Until 2010, Blackberry seemed to be unstoppable in the corporate messaging world.  Now it is laying of 2500 people as the iPhone and Android devices rapidly replace Blackberries in consumer and business settings.   They tried very hard to introduce new devices such as the Storm, the Playbook, and the Torch, but came up short as customer expectations exceed their pace of innovation.

2.  MySpace - Remember when personalized portals were hot? At its height, social networking company MySpace had 1500 employees.   It was purchased in 2005 by Rupert Murdock for $580 million.   It was recently sold for $35 million.   At this point, MySpace does not appear on lists of popular social networking destinations.    Given that the value of most websites is based on usage and thus potential for selling advertising, shifts in the market can occur almost instantly.   Who knows, in a year or two surfing to today's popular sites such as twitter.com may yield the error "URL not found"

3.  Google Health - Google is a great company and I have no doubt that it will continue to succeed.  Google+ is a wonderful social networking site that is likely to steal some of Facebook's market share.   However, like most technology companies, Google now has to deal with the mire of maintenance that comes with a mature set of highly used applications.  More resources are spent on operations and less are available for pure innovation.   Smaller, more nimble companies are likely to outpace Google and will either be acquired by Google or erode Google's leadership position.   Many of my friends and colleagues who joined Google a few years ago (when it was considered unstoppable) have now left Google as the company has matured and its culture has changed.   The closing of Google Health is just one symptom of the changes in focus that occur when a company is faced with the maintenance and regulatory burdens of maturing products.

4.  Microsoft Windows - In 1995, I remember standing in line at midnight in a Torrance, California electronics store to buy one of the first copies of Windows 95.   My early Dell computer (a 386 processor) ran DOS and Windows 3.1, so Windows 95/Office 95 was a remarkable innovation.   It was stable  and easy to use.   Windows 98 Second Edition included built in internet features and was remarkably fast and reliable.   Thereafter, Microsoft has introduced new features, but not achieved the same kind of game changing innovation that occurred 1995-2000.  How many people stood in line at midnight to buy Microsoft Vista?  How eagerly anticipated was Windows 7?  How many people brag about their Windows Phone or Windows mobile device?  The market share numbers tell the story - as of 2011, the majority of Windows computers in the world still run XP.  Microsoft is a great investment - its stock price is low and its product line is very broad.  It's Kinect device was the top selling consumer electronics product over the past year.   However, the burden of maintaining compatibility with an operating system developed for the IBM XT era has led Microsoft to lose its edge in a cloud-based, mobile centric world.

5.  Cisco -  The CareGroup network outage of 2002 taught me many lessons about network architecture.  In response, we installed an updated end to end Cisco infrastructure, embraced Cisco technical services, and worked closely with Cisco salespeople to plan the lifecycle of the network.   Since then, the purchase and maintenance costs of end to end Cisco networks have outpaced Cisco innovation and other companies such as Juniper and HP offer better value on some components.   Cisco is laying off 20,000, closing entire businesses such as the Flip camera (a wonderful technology company that Cisco acquired in 2009 for 500 million dollars, then shut down in 2011) and is rethinking its entire consumer product strategy.  By becoming a sprawling company and attempting to maintain very high margins, Cisco lost control of its core business.   Its competitors are more agile and cost effective.

The general theme is that it's very hard for CIOs to skate where the puck will be when last year's shrewd investment becomes this year's white elephant.  A side effect of this accelerating market change is that customer expectations for constant innovation are higher than ever.  The CIO gets credit for change, but does not receive kudos for impeccable stability, reliability and security of the existing infrastructure and application stack.

While I was in Japan I had lunch with a leading Japanese business thinker, Professor Ikujiro Nonaka.  He told me "If you are doing business as usual, you are falling behind."

Put another way, no matter how good your daily operations, customers in 2011 measure your performance based on the pace of change.

Later this month, I'll take a few of my senior staff to dinner so we can reflect on this challenge.  How can we deliver infrastructure and applications services at an accelerating pace of change for reasonable cost while maintaining staff morale, quality, and compliance with escalating regulatory complexity?   I'll let you know what we decide.