Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Saturday, February 6, 2010

Privacy or Security - what's more important?

While the standards are shaping up, and there is monumental work to be done in a relatively short amount of time. How do you choose which one to do first. It is clear that a reasonable prioritization is needed, some things are relatively more important than others.

Same argument applies to establishing a privacy and security policy. That begs the question - What's more important? Should an organization establish and implement a privacy policy first or should it ensure that a consistent standards-based security policy is implemented so no breach happens in the first place. If you answered "Both", you are on the right track as potentially judged by any reasonable person. However, an organization with limited resources can have the right intent but some things do need to take precedence over others so the implementation goal can be realized.

Establishing and implementing a consistent privacy policy takes precedence and requires unwavering support in any health care organization. Security policy is highly important but it need not be standards-based right for the get-go. You might have heard the saying "Security implementation is a function of the size of your wallet". You can build elaborate checks, audits, disk/server-space, authentication and authorization and make them consistent across the organization if you have the right kind of money to throw at it. With limited funds, you can still uphold the goal of data security by adopting security policies that allow for individual businesses within the organization to have their respective security policies which meet the data security aims. For instance, to fulfill the goal of role-based security, individual businesses can implement an elaborate suite of roles and implement a sophisticated and highly automated mechanism OR can decide a maintain a combination of spreadsheets and manual tracking to fulfill the goal. Either way, the security goal will be fulfilled.


Sunday, September 27, 2009

Ethical use of data for Clinical Decision Support

Noticed this ethics-related question on LOINC website http://loinc.org/articles/Bonney2009

“Is it appropriate, or ethical , to use health data collected for the purpose of direct patient care to develop computerized predictive decision support tools?”

I do not have access to the complete article, but the question itself triggered some thoughts in my mind. I guess the first question to ask is – does the end justify the means? Since use of CDSS (Clinical Decision Support Systems) has been shown on average to lead to better clinical decision-making for providers and hence impact patient care, is it okay to use patient care data for development of such tools?

I will attempt to answer this question using the ethical framework governing the research on human subjects to see if it may apply to this situation (source of framework: Emanuel EJ, Wendler D, Grady C. What makes clinical research ethical? JAMA. 2000;283:2701-11. [PMID: 10819955]).

Here is the list of 7 framework requirements and their applicability to CDSS development as assessed by me –

  1. Social or scientific value: Benefits from CDSS should justify the resources spent and risks imposed on patients whose data has been used
  2. Scientific validity: Predictive decision-making methodology used by CDSS should be properly structured to meet its objectives
  3. Fair participant selection: Participant data should be selected to achieve a fair distribution of the burdens and benefits of CDSS.
  4. Favorable risk-benefit ratio: CDSS should be designed to ensure that the risks to an individual human participant are balanced by expected benefits to the same participant
  5. Respect for participants: Privacy of participant should be protected and confidentiality of their data should be maintained. This can be achieved by using de-identified data and obtaining patient consent for collection, use, and sharing of data
  6. Informed consent: Participant consent to include data in development of CDSS must be obtained. The risk to participant should be measured relative to risk associated with receiving care without use of CDSS. This risk should be communicated to the participant when obtaining informed consent.
  7. Independent review: CDSS development should receive independent ethical review that is appropriate to the level of potential risk it poses to participants.