Hearing of the Senate Judiciary Committee - Health IT: Protecting Americans' Privacy in the Digital Age

Date: Jan. 27, 2009
Location: Washington, DC


Hearing of the Senate Judiciary Committee - Health IT: Protecting Americans' Privacy in the Digital Age

SEN. WHITEHOUSE: Good morning. I'm sorry the chairman is not with us at this moment. We are expecting him, but in the meantime he's asked me to get the hearing under way. I'm Senator Whitehouse from Rhode Island and I'm very pleased to have been invited to have the opportunity to chair this hearing.

I'll take the liberty of having the floor here to give my two cents on why I think this is so important. We are on a very bad glide slope for health care in this country, with a $30-plus trillion liability just for federal health care benefits that is totally unfunded -- not a nickel against that liability. We've calculated that the Bush addition to the deficit was $7.7 trillion before we even got around to the bailouts and that seems like an impossibly big number. We've been arguing about $700 billion TARP funds. We've been arguing about $35 billion auto bailouts. Thirty-plus trillion dollars is an astonishing liability to have to face. And I believe that there are only two ways to face it. One is with a very bloody toolbox comprised of benefit cuts, throwing people off coverage, paying providers less and raising taxes. And we are far too far down all those roads with our health care system already, so that would be a very unfortunate toolbox to have to resort to.

The better toolbox is reform of the delivery system to make it more efficient, so it's not creating so many casualties, so it's not creating so much waste and turmoil and division and stress and paperwork and duplication and waste. And in order to do that, health information technology is going to be an absolute key.

The three legs of that stool, I think, are health information technology, investment in quality and prevention, and reimbursement reform, payment reform, so the price signals match what we want. And the health information technology platform is absolutely an essential element -- not sufficient, but essential, to getting that done.

And I very firmly believe that the Achilles' heel of health information technology is privacy. If the American people don't believe we've protected their privacy adequately, then the HIT initiative, the health information infrastructure America needs, will simply not get through this building. And if it doesn't, that's a real tragedy, because that toolbox takes about 10, 15, 20 years to fully deploy. We've got to get going now on that. And if we waste this moment, the time will come when we're only left with that bloody toolbox, because those tools, as awful as they are, have the one advantage that you can deploy them right away. And so if you've missed your moment with the reform toolbox, that's what you have left. And that's, I think, where we are right now. So I put this privacy question at the center of the most important economic issue the country faces.

I'm delighted to have the chance to hear from all these wonderful witnesses. I'm delighted to have the distinguished senator from Utah, Senator Hatch, here; the distinguished senator from Minnesota, Senator Klobuchar, here.

Senator Hatch, would you like to make some opening remarks, sir?

SEN. ORRIN G. HATCH (R-UT): Well, thank you, Chairman Whitehouse. We appreciate you and your leadership here.

And I want to especially thank our panel here today. I appreciate the opportunity to say a few words on health IT this morning and, of course, welcome our distinguished panel.

And especially you, Mr. Houston, from my alma mater, the University of Pittsburgh; I'm pleased to have you here -- but all of you.

There's no doubt that we are living in an information age. Technology has radically changed business and other aspects of American life. And I believe that health IT can greatly streamline the health care sector by saving cost, time and, most importantly, lives.

I'm proud to point out that Intermountain Healthcare, which is headquartered in Salt Lake City, Utah, has been a national leader in adopting, and probably adapting would be a good word, too, health IT in an integrated manner and could serve as a model for other health care delivery systems across the nation.

My colleagues and I on the Senate Finance Committee and HELP Committee have been working for some time to increase efficiency and reduce costs in our nation's health care industry. I believe that widespread use of health IT would undoubtedly reduce medical errors, inconsistent quality and rising costs currently burdening the health care industry today. In fact, a RAND Corporation study projected that health IT has the potential to save the health care system billions of dollars each year.

And I'm proud to have been a co-author of the bipartisan Wired for Health Care Quality Act, both in the 109th and 110th Congress, along with my colleagues on both sides of the aisle, including Senators Kennedy, Enzi and Clinton. Unfortunately, we might not have a chance to reintroduce this bipartisan legislation again in this Congress since health IT is now being addressed through the stimulus legislation.

Now, regretfully, this language was crafted without the input of Republican offices, including mine, who have demonstrated long- standing interest in this important bipartisan issue. The widespread use of health IT would allow medical data to move with people as they move. Health IT would eliminate the costs of paper claims and help spread clinical research within the medical community.

We have the most advanced medical system in the world. The United States now leads the world in technological innovation and I hope we can stay there. There's no reason why people's health files, their medical history, test results, lab records, X-rays cannot be accessed security and confidently from a doctor's office or hospital.

And I believe we have to develop a nationwide interoperable health IT infrastructure that has strong but prudent privacy and security protections. Providers must be able to easily manage their information needs to provide coordinated and quality care delivery while securely managing the needs of their patients.

Now, I believe that the use of information technology is essential in promoting a system of coordinated and quality-focused health care in this country, in the health care delivery system. I think we have to embrace cutting-edge information technologies in health care and we cannot afford to miss this opportunity.

I look forward to hearing from these witnesses here today. I might mention that Senator Specter, our ranking member on this committee, is unable to attend at least at this time and has asked me to be sure that I attend. And of course, as you all know, I take a tremendous interest in everything involving health care around here and so I'm very interested in what you have to say and the contributions that you care to make to us to help us to understand this complicated but understandable set of issues.

Thank you so much, Mr. Chairman.

SEN. WHITEHOUSE: Thank you, Senator.

The role of the states has really been impressive in all of this, particularly in the absence of concerted, effective federal leadership. And Utah, through its Utah Health Information Network and through Intermountain, has shows great, great leadership in the state, and I know Senator Hatch has been keenly interested and involved in those. So we're delighted that he's here.

Another state that has shown great success and leadership is Minnesota. And Senator Klobuchar of Minnesota would like to add an opening statement.

Senator Klobuchar?

SEN. HATCH: Could I interrupt for a minute? We're really happy to welcome both you and Senator Kaufman to the committee. You're going to be -- you'll like the committee and I think you'll make great contributions. And I think both of you will help to make this committee much more of a bipartisan --

SEN. AMY KLOBUCHAR (D-MN): Thank you so much. Well, thank you, Senator Hatch, for that. Thank you, Mr. Chairman, for your leadership on this issue. As you can see -- that serving as both the junior and senior senator from my state has somewhat weakened my immunity system because I have a cold, but it hasn't weakened my resolve to serve on this committee. So I'm very excited to be here.

I served for eight years as the Hennepin County attorney in Minnesota, where I was a prosecutor, but I also represented one of the biggest hospitals in our state Hennepin County Medical Center, so I had a lot of familiarity with some of these issues, although when I think of the technology issues which Senator Whitehouse has so well talked about on the floor and showed such leadership on, actually my real memory is of two things. One is when I had my hip problems, I had my hip replaced at some point at Mayo Clinic. Driving around with multiple X-rays by myself in the back seat of my car where they got hot and one of them almost melted, I thought there must be something better we could do with health care in the country. The second was that one time when I was county attorney, trying to get all of our police departments to change their complaint forms so that they were routine and we could put them in the computer at the same time. And I went to one of the smaller departments and they said we can't do that, we just bought new file cabinets and they only fit one kind. And I think of this all the time when I think of the great challenge it is to try to get institutions to change their technologies so that they match.

It is incredibly important in the health care area. A study published last year in The New England Journal of Medicine found that only 4 percent of U.S. physicians were using fully functional electronic records systems and missing medical records occur in one of every primary care visits (sic). Serious medical errors that come as a result of missing records are costly, time consuming and preventable. With the U.S. spending ($)2.3 trillion per year on health care, we must bring an end to the inefficiencies of the system. And, if implemented thoughtfully and with the kind of balance that I hope we talk about here today, health information technology has the potential to reduce waste, improve quality and stimulate innovation.

No information is more private than an individual's health information, and, despite federally mandated privacy protections, consumers continue to have concerns about the privacy of their records. And I would agree with Senator Whitehouse that this is one of the major issues and tensions we see as we try to implement better medical technology. If we're going to achieve the savings we'd like to see with medical technology, we must work to develop regulations and laws that inspire consumer confidence and trust. As with other industry advances in information technology, consumer confidence is achieved with proper security protection and improvements in business practices. Health IT investment must be designed to achieve modernization and measurable health outcome improvements.

In Minnesota, we are leading the way for health care innovation. Countless hospitals from Winona to Duluth have been recognized for the measured quality outcomes that have resulted from effective information technology. We've also led the way in ensuring that the privacy of the patient remains protected. Patient consent is required in my state for nearly all disclosures of health records, and it's one of the few states that gives citizens a private right of action if the privacy of their medical records have been compromised.

I'm interested in learning from all of you what providers, consumers and businesses are doing to help ensure the advancement of technology in our health care industry while still working to provide the privacy and security of our patients.

Thank you very much.

SEN. WHITEHOUSE: I'm delighted to join Senator Hatch in welcoming Senator Klobuchar to the committee. We were classmates. We spent a lot of time together. We sit next to each other on Environment and Public Works, and it's wonderful to have her join us on Judiciary as well.

Senator Kaufman, in addition to being a new member of the committee is also a new senator representing the great state of Delaware. We're delighted to welcome him and ask him to make an opening statement.

SEN. EDWARD E. KAUFMAN (D-DE): Sure. I just have a few comments. First I want to thank Senator Hatch, and I do want to operate in a bipartisan manner, as you have, over the years with my former senator, Senator Biden.

I just have a few comments I want to make in the beginning. First is thank you for coming here. This is really an important issue. Everywhere I travel in Delaware people are concerned about the privacy of their medical records, and everywhere I travel around here people are concerned about the exploding cost of health care.

So we have this kind of conundrum on how we're going to move forward on these two areas. And the main area I'm interested in today is kind of we're coming up with a very major bill, the Economic Recovery Act, and it's going to be a lot in there, hopefully, some things on health care that are going to help, but we want to make sure there isn't things in there that are going to hurt.

So I'm looking forward to your testimony. I'm looking forward to the hearing. Thank you.

SEN. PATRICK LEAHY (D-VT): Thank you very much, Senator Whitehouse. I apologize for being late. It certainly is not the weather. As Dr. Hester knows, we don't let weather like this bother us in Vermont. Anything under five inches is considered a dusting at best. And with a Minnesotan and a -- Senator Hatch, you get snow out in -- (laughter) -- Utah, don't you?

SEN. HATCH: We've been known to have snow, but it's --

SEN. LEAHY: I think you measure by the foot on occasion. And I'm delighted to see our new members here, Senator Klobuchar and Senator Kaufman.

And I'm going to say that Senator Klobuchar, like me, is a former prosecutor, and Senator Kaufman probably understands this committee better than I or anybody else here -- the years he's spent here, so thank you.

I had a delay in the doctor's office before coming here. That's what held me up. But -- (inaudible) -- about how you protect Americans' health privacy rights by going into this national health IT system, which I strongly support the idea.

I think you have to have innovation in American health. The only way we're going to make sure that we get health to everybody but we're also bringing the cost down. I'm pleased the President Obama has called for the immediate investment in health information technology works where we want America's medical records to be computerized within five years.

Today if you have a health record, you have a health privacy problem. My wife is a registered nurse, now retired, but she used to tell me how concerned she was to see health records around the hospital. If you can -- now you have electronic health records, digital databases, the Internet, and we have to protect people's privacy in that. If you can just click on a mouse and pull up records, that can obviously be helpful for cost-effective health care, but you have to make sure that personal privacy is protected.

And if you don't have adequate safeguards to protect health privacy, many Americans aren't going to seek medical treatment, which we have to worry about because of their fear that sensitive health information will be disclosed without their consent. And those who do seek medical treatment assume the risk of data security breaches and other privacy violations. And health care providers who think that it's privacy risk, they're going to see that as inconsistent with their professional obligations and they won't want to participate.

So it becomes good news, bad news. The good news, it's a very great thing if we can do it. The bad news is that if there's leaks in there health providers won't want to use it and patients won't want to use it.

Now, as Dr. Hester knows, in my home state of Vermont, we've formed a public-private partnership that's charged with developing Vermont's statewide electronic health information system, including a policy on privacy. I think in order for a national health IT system to succeed, we in Congress should follow Vermont's good example -- work together with public and private stakeholders to insure the privacy and security of electronic health records.

I worked for more than a decade with Senator Kennedy, tireless champion of health IT, and many other members, both Republicans and Democrats, on this. And I think some of us suggested addressing privacy in health IT legislation is too hard. We should put that issue off for another day. I disagree. If you don't have meaningful privacy safeguards, you're not going to get a health IT system.

In his inaugural address, President Obama eloquently noted in our new era of responsibility there was nothing so satisfying to the spirit, so defining of our character, than giving over -- giving our all to a difficult task.

This is a difficult task. Americans are up to it. The Congress had better be up to it. And we'll make it.

So, Mr. Chairman Whitehouse, I appreciate this and I'll stay and listen to the witnesses. I understand that Senator Hatch and Klobuchar and Kaufman made opening statements. Did you and Senator Cardin?

SEN. BENJAMIN L. CARDIN (D-MD): Well, Mr. Chairman, I don't - -

SEN. LEAHY: And I must say that Senator Cardin is from the great state of Maryland and we love Maryland. I have two grandchildren who live in Maryland, plus the parents, of course.

SEN. CARDIN: The roads between Baltimore and Washington were very clear today. I think Maryland did a good job in cleaning the roads. I got here on time.

SEN. LEAHY: And your wonderful hospital, Johns Hopkins, saved my wife's life, so I appreciate it. Go ahead.

SEN. CARDIN: Well, thank you. Appreciate you mentioning that because we are very proud in this country of the quality of health care. This nation leads the world in medical technology. And we're proud of the quality of care that some people and most people in this country can receive, but too many people are denied access to care because of the high cost of health care in America and because of the large number of people who don't have any third-party reimbursement for health care. And we need to do something about that and I agree with President Obama who has made health care reform one of his top priorities and a part of that it is to have a much more cost-effective system as far as medical information and administrative costs are concerned. I think we all agree with that. I agree with the chairman's comments about the goal that we clearly have, using information technology much more efficiently in this country so that those who are providing health care can get the necessary information to provide quality care and to avoid mistakes, and that all becomes a very important part of our health care system.

I do first want to acknowledge Senator Klobuchar and Senator Kaufman and welcome them to the Judiciary Committee. It's wonderful to have both on our committee. And I think we'll have Senator Wyden for at least a short period of time on our committee, maybe longer. But it's nice to have our new members and we welcome them. Senator Klobuchar is not a new member of Congress. We came to the Senate at the same time. And Senator Kaufman, as the chairman has already alluded to, has a great deal of experience, more than I think any other member of this committee.

And we welcome your help as we try to deal with some very complicated issues, including how to deal with protecting privacy and allowing to have an efficient system for sharing of information.

And I just want to make an observation. I served on the Ways and Means Committee for a number of years and was involved in privacy issues in health care. I think part of the problem is that those who collect health care information have not been as selective as I think they should be in trying to get consent from their patients on sharing of information, because in many cases this information does not need to be shared, or could be stored in a way that is encrypted or protects the personal identity of the individual. And yet, in so many cases, the collector of the information decides not to put it in that format because whatever.

So I do think we have to use some common sense here as to how we can protect the privacy of the information and avoid the cohesive practices that health care professionals can use in order to get waivers, including denying care unless you sign those forms, which don't have a lot of meaning to people who are stressed about getting health care. They're not going to read the information on signing the waivers.

So we have to come up with a better system to really have informed consent, because I think it's critically important that those who use our health care system know that their personal information will not be shared without their informed consent. And we have to come up with a way to figure out how to do that.

So to me, this hearing is critically important as we try to make sure that we do have a system that's efficient and one that allows health care professionals to have immediate access to information that they need in order to properly treat their patients but at the same time avoid the intentional or the negligent release of medical information that can compromise not only the rights of individuals but their confidence that our system is doing it in the right manner.

Thank you, Mr. Chairman.

SEN. WHITEHOUSE: Thank you.

We will now hear from our learned panel. We are very proud to have you with us.

And we'll begin with Dr. James Hester, who comes to us from the chairman's home state, the great Green Mountain state of Vermont, where he's the director of the Health Care Reform Commission for the Vermont state legislature, with 35 years' experience in the health care field. He's held senior management positions with MVP Health Care in Vermont, Choice Care in Cincinnati, Pilgrim Health Care in Boston and Tufts New England Medical Center in Boston.

Dr. Hester earned his Ph.D. in urban studies and his M.S. and B.S. degrees in aeronautics and astronautics all from the Massachusetts Institute of Technology. He also holds a master's of education degree from St. Michael's College. And we welcome him to the committee.

Dr. Hester?

MR. HESTER: Thank you, Mr. Chair.

Thank you for the opportunity to testify on this critical issue. I think my testimony will be supportive of several of the themes that the opening remarks that the committee members have made.

My testimony today does not reflect the official positions of the legislature or the commission. I want to be clear about that.

I come before you not as a privacy expert or an IT expert but rather as one with extensive experience in using information and information technology as a means to furthering effective health care reform. Health care reform in Vermont, which has been under way for almost eight years, is the most comprehensive state initiative in the country, built on an integrated strategy which includes, one, expanding affordable coverage in a sustainable way -- we've reduced the uninsurance rate in the state from 10 percent to 7.5 percent in the last two years in the face of declining economy; second, bending the medical cost curve by improving the prevention and treatment of chronic illnesses -- our Blueprint for Health has pilot programs in three Vermont communities, covering 10 percent of the Vermont population, which is showing some great results on this; and finally, using information technologies as a catalyst for performance improvement.

Sustainable improvements in coverage of chronic illness care can only be achieved with support of information technology. It is impossible to obtain the desired performance of our health care system as long as key clinical information is only available to providers and patients through paper charts sitting in filing cabinets.

As I mentioned, the primary vehicle for our IT strategy has been VITL. It's a new public/private organization. In the last three years it has completed a detailed IT plan, implemented several pilot programs and begun building the core infrastructure for the statewide health information exchange.

Last May, Vermont became the first state in the country to provide the long-term financing to pay for both the development of the statewide health information exchange network and for electronic medical records for all independent primary care practices in the state. This transition from creating a plan and implementing relatively small-scale finalists to full-scale statewide implementation has provided a major impetus for the review of privacy and security policies. Those efforts are in the final stages but are now on hold pending clarification of proposed privacy guidelines in the Economic Stimulus Act.

While the health IT financing goes far to reducing the financial barrier to widespread implementation of health IT, it is not sufficient by itself. Realizing the benefits of IT requires broad acceptance by both patients and providers of this new technology which deals with the most sensitive types of data. The processes that VITL has engaged in represents a delicate balancing act between sometimes conflicting interests of consumer control and needs, and provider accountability and responsibility. Unless consumers are confident that their information is secure and will be used appropriately, they will not participate in electronic health information exchange. Unless providers believe that the administrative burdens are reasonable and the information is reliable, they will not participate in such exchanges either.

Moving forward with our health care reform totally depends upon finding an initial balance point between these conflicting needs and interests in a way which will encourage broad-based participation of patients and providers. I'm confident that once the federal privacy guidelines and requirements in the stimulus act are finalized, VITL will be able to rapidly complete the revision of its guiding principles and operating policies.

However, this balance point is not static; it will evolve. We fully expect that the implementation of the initial privacy policies and the growing -- steadily growing set of pilot health reform initiatives will teach us important lessons over the next couple of years. We will have to return to these polices on a regular basis to update them based on what we have learned and new technical capabilities. The core security and privacy capabilities have been carefully thought through, however, and provide a sound foundation for beginning this expansion.

Vermont health care reform is built on scalable, community-level pilot programs which enable us to learn rapidly what works and what needs to be improved. We will use this model to evolve our privacy and security policies and capabilities as well. Given the strong feeling surrounding protected health information and the uncertainties that are inherent in the early strategies of the spread of EMRs, I fully expect that a significant minority of both patients and providers may not -- may elect not to participate.

A reasonable goal is to devise a program which will satisfy the needs of a large enough percentage of users to enable robust testing of capabilities, deliver value to the users and drive the next round of privacy and security technology. As capabilities mature and confidence grows, a hope and expectation is that our program will earn the trust of a steadily expanding percentage of both our population and the health care delivery system. The successful scaling up of our pilot programs into systemwide initiatives and the long-term success of our health reform efforts depend on it.

SEN. WHITEHOUSE: Thank you very much, Dr. Hester.

Our next witness this morning is Deven McGraw. She is the director of health privacy -- of the Health Privacy Project at the Center for Democracy and Technology. Prior to joining CDT, she was an associate in the public policy group at Patton Boggs LLP and in the health care group at Ropes & Gray. Ms. McGraw received her bachelor's degree from the University of Maryland. She earned her J.D. and LLM from Georgetown University Law Center. She also holds a Mater of Public Health degree from Johns Hopkins School of Hygiene and Public Health. We welcome her to the committee.

Ms. McGraw.

MS. MCGRAW: Thank you very much, Mr. Chairman, members of the committee. And thank you for holding this hearing today. It really could not be more timely or more important.

We have economic recovery legislation on the table that is $20 billion at least -- depending on what your looking at -- to promote the adoption of health IT, and this commitment is really laying the building blocks for health reform. It's going to help us create the information super highway for health that will improve health care quality and engage more consumers in their care. This is very good news. It's an important opportunity, and surveys consistently show the support of the American public for health IT.

But these very same surveys also show that the public is concerned about the risks to their privacy when medical information will be moved online. A system that makes greater volumes of information available for the right purposes -- to improve our care -- is also an attractive target for people who would seek it for commercial gain or for other inappropriate purposes. So building trust in these systems is absolutely critical to realizing the benefits of this technology.

Some say that privacy is an obstacle to achieving a digital health system. Senator Leahy mentioned that it is not always easy to figure out the right way to approach this. But really, it is not an obstacle. In fact, the opposite is true. Enhanced privacy and security built in to health IT will bolster consumer trust and spur the more rapid adoption of health IT and therefore allow us to realize these benefits.

So a commitment to spending significant dollars to advance health IT must be coupled with a strong commitment to privacy and security. One without the other is a job half done and will set us back significantly. Congress's roll is critical here and strong privacy protections must be part of any legislation that moves health IT. We can't do this later. We won't have another opportunity.

We've taken on privacy once before in HIPAA, but health care's really rapidly changing and the way we move information today is different than it was then, and it's going to be even more different tomorrow and in the decades to come.

So we really need a second generation of health privacy. A comprehensive, flexible privacy and security framework that sets clear rules for who can access personal health information and for what purposes that apply to all entities that are engaged in e-health.

That bill that is pending builds on HIPAA and takes some concrete steps forward to the realization of this comprehensive framework of protections. And we support them. They're like a down payment, a good first step. But they -- hopefully this won't be the last opportunity for us to talk about this.

As Dr. Hester aptly pointed out, you know, these conversations are going to, you know -- making sure we get this right is going to require an ongoing commitment from Congress, the administration and the private sector as well.

So in my testimony I have some detail about the privacy provisions that are in the stimulus package, at least the ones that I've seen in the House bill that got marked up the other day. And so I'll just touch on a few. It includes a federal right to be notified if your health information is breached; giving patients a right to an audit trail of disclosures from their medical record; ensuring that records or data can't be sold or used for marketing purposes without your authorization. It has provisions to improve enforcement. It tasks the HHS and the Federal Trade Commission to work to develop protections for personal health records with our consumer-based tool, which require a different set of protections. Again, my testimony has details on all of that.

I'll close by saying, you know, you might -- the one other thing that Congress might do is to task the secretary with ensuring that all entities adopt and implement both policies and technological solutions that address fair information practices of data stewardship and then holds funding recipients accountable for how they implement privacy protections. At the end of the day, whatever happens in the stimulus and having HIPAA, some folks will be covered adequately, some folks will not. Having the private sector develop policies will give us that extra measure of safeguard. And I think that if I were going to add one more thing to what is already a very strong package of protections, that would be it.

Thank you for the opportunity to testify today, and I'm happy to answer any questions you might have.

SEN. WHITEHOUSE: Thank you, Ms. McGraw.

Our next witness is Adrienne Hahn. She is a senior attorney and program manager for Consumers Union. As a health care advocate Ms. Hahn is an expert on medical privacy, health care financing, Medicaid, and patient safety efforts at the federal level. Previously Ms. Hahn served at the United States Department of Justice as an attorney in the Civil Rights Division. She earned her Bachelor of Arts degree form Colorado College, where she was a classmate of my sister, and her J.D. from Boston College Law School. We welcome Ms. Hahn to the committee.

MS. HAHN: Mr. Chairman, members of the committee, thank you for inviting me to testify today.

Consumers Union is the independent, nonprofit publisher of Consumer Reports magazine and we work on a wide range of health care issues.

There's widespread agreement to accelerate the use of health information technology. In our otherwise high-tech health care system, most hospitals and doctors' offices still store patient records on paper, making the history of medical care hard to transfer from one hospital to another or one doctor to another. The inefficiencies of this system can lead to medical errors and the loss and misplacement of vital information. As for patients, we rarely see our own fragmented records or track our own health histories.

Consumers Union therefore strongly supports the movement toward an electronics system of health records and information exchange. By harnessing the power of modern information, technology systems can improve the quality of American health care and moderate health care costs by the following: one, reducing errors; two, eliminating service duplication; three, promoting pay for performance; and four, providing the data necessary to evaluate the actual comparative effectiveness of various treatments and drugs.

A national system of electronic medical records has the potential to improve the quality of health care by reducing hospital-acquired infection rates through a network of electronic medical information. Families can identify the safest and the highest quality hospitals. As just one example of the tremendous improvements in quality and cost savings that are possible, Consumers Union has been conducting a national campaign to promote the disclosure of hospital infection rates, and you can find out more information about that at www.StopHospitalInfections.org

Each year, there are about 2 million patients who acquire infections in hospitals, about 100,000 who die. In 24 states, we have worked with state legislators to pass laws to require hospitals to report the rate of infection, basing on the idea that public disclosure will prompt hospitals to adopt effective methods to reduce their infection rates. Electronic medical records technology and a public disclosure of more types of patient care data where the patient is not identified will make it easier for consumers to reward those who provide quality.

While there can be important public and private benefit of creating an effective electronic medical records system, we believe polls demonstrate that quite effectively. From the great potential of such systems, unless more is done now to ensure privacy, there won't be the heart and soul of the American public in order to support that. In short, this requires enabling patients to participate in deciding when, with whom and to what extent their personally identified medical information is shared. It is important that we all recognize that there is now hack-proof database system, and (when ?) more medical data is moving electronically, it is subject to threats from hackers, identity thieves and others. That is simply a fact of life, reconfirmed almost daily by new stories of financial and medical record data violations.

Beyond a likely scenario of security breaches, the value of electronic health information is such that many organizations want to exploit secondary data sources for private financial gain, rarely, if ever, with the patient knowledge, let alone consent. It is imperative that policymakers take aggressive steps to protect privacy. Otherwise, security breaches could doom expanded use of health information technology.

Additionally, some will say that it's too complex or it's too expensive to allow people to control their medical information. Computers have the ability to handle the task. They've been designed to deal with huge numbers of variables like 50 states laws and to create special files while certain data are only available to designated providers on a need-to-know basis. If we don't stop, meaningfully address the privacy issue, polls show the public will not trust this system, and many will go off the grid to get medical care and we will just increase public cynicism about big government and big business controlling our lives.

In an age with the talk of this being a consumer-driven health care and ownership and empowerment, forcing people to share their most secret, personal medical information is not the path to take. Therefore, Consumers Union, along with a variety of different organizations, has joined eHealth Initiative, which includes AARP, AFL-CIO and other organizations that support this, and we've developed a set of principles that achieve an effective balance between promoting HIT and systematic privacy safeguards. Those safeguards and protections have been attached to my testimony and I would really encourage you to take a look at those. I think they provide an excellent framework to ensure that as we move down the road of health information technology, we ensure that the medical privacy records of consumers are well protected.

Thank you.

SEN. WHITEHOUSE: Thank you, Ms. Hahn. We appreciate you being with us.

Our next witness is Michael Stokes, the principal lead program manager for Microsoft's HealthVault team. In this role, he is responsible for policy compliance relating to privacy across Microsoft's Health Solution Group and Advanced Research and Strategy Group.

Before joining Microsoft, Mr. Stokes worked with the Hewlett- Packard Company, where he designed and provided architectural business development and strategy. Mr. Stokes earned a Master's of Science from the Rochester Institute of Technology and a Bachelor of Science in mathematics from the University of Texas at Austin. We welcome his testimony.

Mr. Stokes.

MR. STOKES: Thank you, Mr. Chairman and distinguished senators.

I am the principal program manager in Microsoft's Health Solutions Group. I am accountable to ensure that our products are in compliance with applicable regulations and corporate policies, including privacy. I am honored to share Microsoft's views on the importance of privacy in health IT. We commend the committee for holding this hearing today and for your efforts at the intersection of privacy, information and health care reform.

Microsoft's products, including HealthVault for consumers and Amalga for hospitals and health care systems, focus on improving health care outcomes. We recognize that health data needs to be exchanged back and forth so that everyone -- patients, hospitals, providers and clinicians -- have the right information at the right time to get the best health outcomes.

We also understand that everyone, from patients to clinicians, will only be comfortable sharing health data and using health IT if they trust that that data is protected. There are three components to this trust: transparency, control and security.

First, transparency: Participants in the health care ecosystem should be transparent about their data collection, use and disclosure practices. If patients do not understand what data is being collected, who has access to it or what it will be used for, they may decide not to provide any information at all, even to their own physicians. Health care providers need transparency too, so that they understand how health data is used, how it is protected and how their data will be disclosed to other third parties.

Second, control: Patients and other health care participants should be given control to manage health data effectively. Control allows patients to decide when and under what conditions they want to share health data. Control can help ensure that the patient's health data is shared only with the health care professionals who need to see it and that the patient's data is not inadvertently misplaced or deleted.

Third, security: The security of health data must be protected. Concerns about potential misuse of personal data threaten to erode public confidence in digital health solutions. Stakeholders will be more willing to adopt the innovative health IT solutions that can improve care and reduce costs if they feel confident that their data is secure.

By following these three principles of transparency, control and security, we can encourage greater adoption and use of health IT and bring real change to our health care system. Consumers will receive better information about appropriate treatments, medications, nutrition and exercise. Health care professionals will see a more complete picture of their patients' health, allowing them to eliminate unnecessary procedures, avoid harmful drug interactions and concentrate on providing better-quality care. And researchers can discover new therapies, new breakthroughs and new cures.

The principals of transparency, control and security underlie Microsoft's approach to its health IT products. At the same time, we recognize that technology is only a part of the comprehensive approach to improve our health care system. Education, leadership in health care organizations and meaningful public policy are also critical components to this success. We look forward to partnering with you and all participants in the health care ecosystem to move forward toward a dynamic, trusted and patient-centric health care solution system.

Thank you for the opportunity to testify and I look forward to your questions.

SEN. WHITEHOUSE: Thank you, Mr. Stokes.

Our next witness is John Houston. He is the vice president of information security and privacy and assistant counsel for the University of Pittsburgh Medical Center. In 2002, Mr. Houston was appointed by the secretary of the U.S. Department of Health and Human Services to the National Committee on Vital and Health Statistics. He holds a Bachelor of Science degree in computer science and history from the University of Pittsburgh and a J.D. from the Duquesne University School of Law.

Mr. Houston, welcome.

MR. HOUSTON: Thank you very much. I'm grateful for the opportunity to address this committee today regarding this important topic.

I'd like to start my comments by stating that the adoption of health care information technology is one of the most significant health care initiatives this nation can undertake. However, the widespread adoption of health IT will not be successful if our patients' privacy expectations are not met.

I am proud to say that UPMC has one of the most progressive and long-standing programs for the development and deployment of health IT in the world. Having been accountable for both privacy and information security at UPMC for the last eight years, I'm not only aware of the public policy considerations underlying privacy and information security but also the operational balance between a patient's right to privacy and providing timely and complete information that is necessary for the delivery of effective health care.

Unfortunately, this balance is neither precise nor clear. I have seen firsthand how information barriers established in the interest of privacy have detrimentally affected patient care.

I reviewed the current draft of the privacy legislation included in the Health Information Technology for Economics and Clinical Health Act. While the act attempts to address evolving privacy and security requirements that have arisen since the implementation of HIPAA, it falls short of providing the necessary and comprehensive and workable framework that we now need.

As the act is now being considered I believe it is important to raise a number of concerns regarding the privacy and security provisions in the act. These concerns are more fully discussed in my written testimony, but I'll highlight just a few.

Accounting of disclosures: The act provides that a patient is entitled to receive an accounting of disclosures of who accessed the patient's electronic record even if such access was for treatment, payment or health care operations. For an inpatient encounter, it would not be uncommon for more than 200 people to have access to various aspects of a patient's record. In practice this could result in substantial and costly efforts on behalf of the provider with little or no apparent benefit to the patient.

Health care operations: The act provides that the secretary will propose limitations on the use of identifiable health information for health care operations purposes. The burdens associated with de- identifying patient information must be considered, not only in terms of the time and effort associated with performing the de- identification but also in terms of the likelihood that a covered entity will simply choose not to perform important health care operations.

Fundraising: The act provides that fundraising will no longer be considered part of health care operations. In difficult economic times and in an era of shrinking reimbursements, fundraising is of critical importance to most providers. Any restrictions on fundraising will further frustrate a provider's ability to deliver quality health care.

Non-covered entities: The act attempts to address PHR providers, health information exchanges, regional health information organizations and other entities that have historically fallen outside the coverage of HIPAA. However, the act's treatment of each is neither comprehensive nor consistent. Rather than establishing an inconsistent privacy patchwork, a single framework needs to be established to accommodate not only today's requirements but can be extended to cover the rapidly evolving health IT environment.

Enforcement: While there has been much criticism of the current enforcement strategies, I believe that the manner in which enforcement is currently performed has been effective. The act must ensure that the opportunity to collaborate continues to exist for those covered entities that are dedicated to protecting patient's privacy.

With that, I'll close my comments. Thank you.

SEN. WHITEHOUSE: Thank you very much, Mr. Houston.

Our final witness this morning is David Merritt. Mr. Merritt is a project director at the Center for Health Transformation and the Gingrich Group. Mr. Merritt leads the center's projects on health information technology and expanding coverage to the uninsured. He earned his master's degree in political science and government from Loyola University Chicago and he earned his bachelor's degree from Western Michigan University. We happen to know him as the editor of "Paper Kills," a book that Mr. Gingrich provided an introduction for. And he has helped Mr. Gingrich co-author a article with me on health information technology, which proves that this is an issue upon which people at opposite ends of the political spectrum can find agreement.

Mr. Merritt.

MR. MERRITT: Thank you, Mr. Chairman. Thank you for the opportunity to testify this morning.

Privacy cannot be compromised, but neither can we compromise progress in pulling our health care system out of the technological stone age. We need to find the right balance between privacy at all costs and progress at any cost.

One of the key ways to accomplish this is by creating a common uniform framework to securely store and transmit personal health information.

The Healthcare Information Technology Standards Panel, known as HITSP, and the Certification Commission for Health Care Information Technology, known as CCHIT, are doing just that. HITSP has finalized a series of technological standards to protect privacy, and there are two that are worth highlighting. The access control standard allows for the secure authorization to personal health information, including role-based, entity-based and context-based access control.

The consent directive standard allows for the management of consumer rights as to who may access, collect, use or disclose personal health information. These standards were recently recognized in the Federal Register, meaning that any future procurement of a health It system by the federal government must include these protections. Now it is up to the IT vendors to actually implement them in their products. And one of the ways to drive this is through the certification process.

Now, in full disclosure, I'm on the board of commissioners for CCHIT, but these views are my own and do not represent the committee -- or the commission, excuse me.

CCHIT certifies a range of products, including electronic health records, to ensure that they meet functionality, interoperability and security standards. There are about 50 security standards, including the two that I mentioned before, that to be certified an electronic health record must meet 100 percent of them.

Now, on a general note, policymakers are currently debating the future of these two organizations and I cannot say it in stronger terms that replacing these organizations now or confusing the marketplace by creating parallel entities would literally turn the clock back five years when this discussion first started. They can certainly be improved, but I think that we will pay a huge opportunity cost in time and resources if we revisit this debate now.

Now, in the broad policy proposals that are under consideration by this committee and others, Speaker Gingrich has a belief that when you're presented with an idea that you should say "Yes, if," rather than "No, because." Now, I've tried to do that with some of these proposals on the table.

Yes, I think there should be an individual right of consent; consumers should be able to opt out of certain products, services or notifications, and they should be able to specify how their identifiable information can be shared outside the course of treatment or payment.

Consent must be balanced with health services research. I'm a strong believer in the power of data. It can reveal which treatments work, which treatments do not work, the effectiveness of drugs, devices and other vital information that really does benefit all of us. This is impossible to do without the identified data. And when all identifiable markers are stripped, personal privacy is indeed protected.

Yes, patients should be notified of egregious breaches of privacy, but these protections should incorporate risk-based notification so that physicians, health plans, health systems and others do not notify patients for harmless or inadvertent data sharing.

Yes, patients should have a private right of action for extreme breaches of privacy. We need to strike the right balance so that federal, not state, litigation is available for patients but only for clear, egregious cases.

In conclusion, we can find the right balance between privacy and progress if we are careful, judicious and realistic, and I think once we do, we will have succeeded in transforming health care into a system that saves lives, saves money, as well as protects privacy.

Thank you.

SEN. WHITEHOUSE: Thank you, Mr. Merritt.

For questions, we will now turn to the distinguished chairman of the committee, Senator Leahy.

SEN. LEAHY: Thank you. Thank you very much, Senator Whitehouse.

And I -- Dr. Hester, I understand the Vermont information technology leaders at VITL already have some successful pilot programs connecting electronic health records. Is that correct?

MR. HESTER: That's correct.

SEN. LEAHY: Given your experience with that, do you agree that -- basically the feeling I have -- and tell me if you disagree, of course, but -- that we have to have consumer confidence in the privacy of those records that they really -- if you really expect them to take part in it.

MR. HESTER: I would agree. We absolutely have to have consumer confidence. And I think it's important to differentiate between the different levels of use of the information. For example, we have a pilot that provides medication history to patients who are in the emergency room so that that physicians in the ER will know what medications have been filled in the last year.

Even in that situation where it's very contained, very specific, there's immediate need, we still find 5 percent, 3 to 5 percent of the people do not agree -- do not give the consent.

SEN. LEAHY: Even though they might be unconscious when they come in? (Laughter.)

MR. HESTER: They can break the glass if they're unconscious. There are provisions on that.

SEN. LEAHY: Okay.

MR. HESTER: At the other end of the spectrum, when you start having electronic medical records which are not just being used by the practice -- you know, by the providers within a specific practice but are connected into a regional health information exchange, the anxiety level and the requirements for earning the trust go up dramatically because the people just don't know who's involved in that.

So we have a survey of, you know -- for the population of Vermont. Half of the population of Vermont said that in that situation they really felt it was imperative that they could control or shape who gets their information to that network.

SEN. LEAHY: Let me ask -- and I'll ask the same question of Ms. McGraw and Ms. Hahn and Mr. Stokes -- do you find the same thing, that you have to have consumer confidence in the privacy if this is going to work?

MS. MCGRAW: Absolutely, Senator. You know, I think if there's been a consistent theme at this hearing, it has been that if people don't trust these health IT systems that we're trying to build, we will have spent a lot of money for naught.

Now, there's been also a lot of discussion at the hearing about the role of patient consent or control as a privacy protector. And I think the only thing that I would add is that that's an important component of privacy protection, but we can't use patient consent as the sole protector of information. We can't rely on the individual to read a form and completely understand all of the potential uses of their information, especially when you're talking about core health care functions like treatment or payment or the administrative tasks that are core to getting those things done.

Now, when you're talking about participation in networks, that's another story. That exposes people's information to more players than is the case when they go in to see their doctor. We actually published a paper just yesterday on what we think the right role is for patient consent.

SEN. LEAHY: If we were to put this medical IT in the stimulus bill, should we also have patient protections in there too?

MS. MCGRAW: Yes, absolutely. And in fact, the bill does take concrete steps toward those protections, again, looking at a set of rules.

SEN. LEAHY: Dr. Hester, do you agree?

MR. HESTER: Agreed that it's an essential part of that bill.

SEN. LEAHY: Thank you.

Ms. Hahn?

MS. HAHN: I would just echo what -- (of mike) --

SEN. LEAHY: Is your microphone on?

MS. HAHN: I would just add one other factor to that and that is that what we've been able to look at in terms of the data, it shows that, for instance, the lack of confidence regarding medical privacy actually differs based on race as well. And so what concerns us, as we know, is when the United States moves to 2032, where minorities will be in the majority, if this issue is not addressed appropriately now, we're actually going to be -- all the promise in terms of care coordination, quality of health care might actually come to demise because of the fact that the minority population right now really doesn't trust in the information --

SEN. LEAHY: So that's what your polling finds; it's the minority population that doesn't trust it.

MS. HAHN: No, we would say that there's a real concern for Americans generally, somewhere around 56 --

SEN. LEAHY: But you said there was a different level of distrust, I should say.

MS. HAHN: Yes, right. So if you break down that data and put it on -- look at in terms of race, it actually increases in terms of the level of distrust. To give you an example, even the chronically ill have greater trust in information remaining private as opposed to an African-American or a Latina. So I think that there are some real issues here in terms of we're going to be bringing all Americans along in insuring that we provide the type of privacy protections that people have confidence in it.

SEN. LEAHY: And Mr. Stokes, do you agree or disagree with what you've heard?

MR. STOKES: Thank you for that question, Senator. As I testified, our products are dependent upon consumer trust. We believe that without consumer trust in the system, they will not adopt a system. We also, through extensive discussions and interviews, believe this is just important for the providers. If the providers do not trust in the system, they will not adopt the system either.

We find with family doctors and primary care providers they are as concerned about maintaining the sanctity of their doctor-patient relationship and that privacy as many of the patients we talked to.

SEN. LEAHY: Thank you.

Mr. Chairman, I have other questions but if I might have your permission -- submit them for the record.

SEN. WHITEHOUSE: Of course, without objection.

Senator Klobuchar.

SEN. KLOBUCHAR: Thank you very much, Mr. Chairman.

Dr. Hester, your state of Vermont, like Minnesota, has gone beyond the HIPAA requirements. And as I mentioned, some of the things that Minnesota has included --what do you think would happen if other -- we now have sort of a patchwork where some states have gone beyond HIPAA, some haven't, people may seek treatment in multiple states. Do you think it would be easier to have this done on a federal level or to have this done state by state?

MR. HESTER: I think it's important to have clear federal standards and guidelines that set the framework, you know, for those policies. For example, the Office of Civil Rights framework for privacy and security that was issued last December has been a very helpful tool for us.

We have suspended the final development of our statewide policies, our operating policies, until we get the clarification from the, you know -- on what the federal standards -- and we're looking forward to that clarification; it's important.

SEN. KLOBUCHAR: And just one side note, Vermont also is a state, like Minnesota, that passed a law prohibiting the sale of patients' pharmacy records.

MR. HESTER: Yes.

SEN. KLOBUCHAR: Could you talk a little bit about how this came about? I think patients would be surprised to hear that their pharmacy records were at risk of being sold.

MR. HESTER: Pharmaceutical companies use histories on prescribing patterns to target physicians for detailing on how to use their products. And so there was concern of that being done in this case without the physician's knowledge or consent as well. So those restrictions have been passed and they're now being challenged. But it was an issue that was of great concern to the state legislature.

SEN. KLOBUCHAR: And this is also included in the House stimulus bill? It's one of the limitations -- the marketing limitations?

MR. HESTER: My understanding -- I have not reviewed the detailed language, but I understand they're trying to put restrictions in there, yes.

SEN. KLOBUCHAR: Okay. Thank you.

MR. HESTER: We do support that.

SEN. KLOBUCHAR: Mr. Houston, Chairman Leahy was going through the other witnesses with some questions and I saw you nodding your head, maybe the other way, about inclusions of these in this stimulus package. And I brought up deliberately this concern of state-by-state regulation.

MR. HOUSTON: Right.

SEN. KLOBUCHAR: Could you talk a little bit about the limitations proposed and how we can ease the potential burden of providers while trying to get these privacy concerns, which I think we've all agreed are an issue for consumers and we're not going to get the proper use of medical technology if we don't have that kind of confidence.

MR. HOUSTON: Absolutely. Again, we're all patients, so we all have the same concerns about the protection of our medical information. But I know Deven said it, and I said it, what we need is a comprehensive framework. And my biggest concern is when I read the privacy and security components of the act, the stimulation package, that what we end up with is a patchwork. And I don't think this patchwork works, in my mind.

And there's nothing worse than getting this wrong, because I have seen very directly the impact of trying to inappropriately implement privacy and what the impact potentially can be on patients' care. And so --

SEN. KLOBUCHAR: (Inaudible) -- a patchwork? And I'm --

MR. HOUSTON: Well, if you look at the way that -- right now that there's state preemption under -- even under HIPAA. But when you look at the act itself, it speaks about RHIOs would be handled one way and other types of organizations would be handled another way, about how they would potentially fit under HIPAA or otherwise have to deal with compliance with certain privacy and security rules.

I just want to get it right and get it right once, make sure that everybody is covered under the same framework. You know, PHRs today aren't covered under anything. If you have a personal health record system, you're not covered under HIPAA. Frankly, you might not be covered under anything. And so if we're going to develop an environment which we -- and we should be forward-looking because, you know, what we have today and what we're going to have in 10 years or 15 years is going to be dramatically different.

We need to develop a framework which allows us to progress and implement new and, you know, novel and progressive health IT but do it in a fashion where the consumer continues to feel like they're protected and so that -- you know, HIPAA was initially enacted in 1996. I think everybody would agree that it's got a lot of holes. There's a lot of things that because of when HIPAA was enacted really weren't covered. We didn't think about PHRs. We didn't think about the national health information network.

And so I just want to make sure we get it right the first time. And I'm concerned that we're not here and that we have one bite of the apple. And if we don't get it right, we may find that we're dealing with problems yet again in two or three or five years.

SEN. KLOBUCHAR: Ms. McGraw?

MS. MCGRAW: I think the only place I would disagree is we just don't think that HIPAA is the right set of protections for the personal health records, in part because HIPAA was designed to allow information to flow among traditional health care entities without necessarily having to ask the patient each and every time.

These PHRs are tools that are designed for consumers to have copies of their own records that they can then move, share, they can put their own data in there. That needs to have really a much higher level of consumer control about who can get it and for what purposes.

And so while I agree that we need sort of a common framework, a baseline, it's got to also be contextual. You don't need -- regulation for those products has to target the risks that consumers will face in those products, which are going to be different than when a health care entity holds your data.

So -- my testimony provides a little more detail, but it's the little -- sort of nuances of difference.

MR. HOUSTON: And I agree that HIPAA is not necessarily the appropriate vehicle, but we need to be forward-looking and come up with a good framework that really does meet all of our different needs, especially as we see health care IT really transforming.

SEN. KLOBUCHAR: Thank you.

SEN. WHITEHOUSE: Senator Kaufman.

SEN. KAUFMAN: Yes, I want to follow up on that question. I think this economic recovery bill is an incredible opportunity for us to do some things in health care and the testimony here has been directed towards that. But also it's going to be a lot of money and it's going to be spent; as Mr. Houston said, if it's not spent right, it can cause troubles.

I'd really like each one of the panel if they could kind of give their opinion on where we are in terms of the present status of the bills, making sure that we're protecting policy, at the same time having much more efficient health IT.

Mr. Hester, you got anything you want to say on that?

MR. HESTER: The question is the economic stimulus act --

SEN. KAUFMAN: Exactly.

MR. HESTER: -- the current status of that?

SEN. KAUFMAN: Exactly, and the provisions in it for health IT and privacy and where you think we are on that.

MR. HESTER: I'm going to --

SEN. KAUFMAN: You can pass.

MR. HESTER: I can pass. I'm going to have to pass.

SEN. KAUFMAN: Good.

I think -- Ms. McGraw?

MS. MCGRAW: Again, you know, we need a comprehensive framework of protections. HIPAA today doesn't get us there. What's in the bill takes some concrete steps forward to improving and filling in some of the holes. I think -- I liked David's "Yes, if." I don't have so many yes, if's, but if all we need to do is address the if's, then we're pretty close to the goal line. And we should concentrate on doing that rather than having these -- you know, wondering whether we can do privacy as part of health IT, because I think we are all pretty much on the same table, that you can't do health IT without privacy.

So we are supportive of those provisions. If there are issues that need to be worked out, we should move forward with doing that as quickly as possible.

SEN. KAUFMAN: I take it there's nothing -- no provision in the bill that you think are so onerous that they'd have to be struck before you would --

MS. MCGRAW: No, not in my opinion.

SEN. KAUFMAN: All right.

Ms. Hahn?

MS. HAHN: I would say that I agree with Deven. I feel that there's been a real willingness on the part of both the House and Senate to work with the e-partnership in terms of addressing our concerns, so we really appreciate -- sorry, I have a cold as well. We really appreciate moving forward.

MR. STOKES: Thank you for that question, Senator. Aside from some minor legal clarifications that I've understood from our lawyers, that the language might impact non-health-related entities, we see no significant difficulties in adoption of the language as it stands or as it's proposed.

But as Dr. Houston pointed out, one of our concerns is providing an ongoing framework or guideline, so this is why my testimony focused on the principles of transparency, control and security.

If we're very clear on what the required principles should be and have ongoing policy discussions as the technology evolves, as medical research evolves and as the health care ecosystem changes and evolves down the road, we're much better situated to dynamically address those in a basis, without coming back again and again for legislative fixes, that are able to have the foundations in the legislation for the regulatory bodies and industries to continue to make progress.

SEN. KAUFMAN: Thank you.

Mr. Houston?

MR. HOUSTON: I think that's -- absolutely I'm in support of the health care IT component of the bill. I think health care IT is vital and we need to move forward as fast as we can.

I do have serious concerns about the privacy components of the act, though, and I did outline those in my written testimony.

SEN. KAUFMAN: Yes, I got those, yes.

MR. HOUSTON: And I think there are some serious concerns that I have that could impact providers and their abilities to deliver care efficiently. And I also think that if you read the privacy components of the act, they talk about study and reports and guidelines that need to be established. I really think a lot of that needs to be done up front and then transform that into something that works.

I just -- from living in the trenches, I can tell you that you don't want to get things wrong, because you want to improve health care. You don't want to impact health care. And I've just seen too many things in this -- these provisions that just concern me and are going to get in the way of delivering efficient health care.

SEN. KAUFMAN: How long do you think it would take to develop that? I mean, really, we're facing an economic recovery bill. Clearly we have economic -- I mean, this is the big reason for doing this is to get the economy moving again.

MR. HOUSTON: Sure.

SEN. KAUFMAN: One of the big impetuses is "shovel-ready," and "shovel-ready" doesn't just apply to infrastructure; it applies to this. So you know, if we sit around and study this and come up with plans -- I mean, what do you -- I think you have some thoughts.

MR. HOUSTON: We've done a lot of study. There's a lot of really intelligent people that have great opinions on what we need to do. I think in a year's time, or even less, you could really, I think, put together a comprehensive framework that works.

You know, one of the things about privacy, though, that's different than most everything that's in the stimulus bill is everybody has an opinion in good faith as to what privacy means to them. And it's difficult often to bridge the gap between different people's opinions. And none of them are wrong, but we've got to come up with something that works and something that, again, doesn't impede health care delivery.

MR. KAUFMAN: Thank you.

Mr. Merritt, do you have comments?

MR. MERRITT: Thank you. The two areas that I would focus on that I think could be improved, I mentioned one in my oral remarks --

MR. KAUFMAN: Right.

MR. MERRITT: -- the issue of de-identified data and health services research. I don't think that there should be the right to opt-out of having your de-identified data used for health services research. If you ask anyone who has dealt with large data sets that if you have the ability for selection bias and opting out, you're just not going to have as valid and as reliable research.

And I think that as we move forward with comparative effectiveness and evidence-based medicine, we need as much data as possible. And I think you can balance it, again getting back to my point about balancing, you can balance privacy with progress if you can use de-identified data in that way.

The other point I would mention in the legislation that the House has considered is the impact on disease management or chronic care programs. There are restrictions on reaching out -- health plans and health systems on reaching out to members or patients who might qualify or benefit from these types of programs. And I think that when you're talking about individual health and improving individual health, that those data flows and those connection points still need to be protected. I think those can be best suited to be resolved through the rulemaking process at HHS.

And the last thing I'll mention that's currently not in the bill, or at least not in the packages that I've seen, is the idea of tying federal money to certification. When a health system or provider is going to receive a grant to either purchase a system or an incentive to invest in a system, I think there has to be the tie between the money and certification and specifically to CCHIT certification, because they do have those protections in place. They do go through a very rigorous process of testing and making sure that those products are up to snuff. So I think that those four components are very important.

MR. KAUFMAN: Thank you all.

Thank you, Mr. Chairman.

SEN. WHITEHOUSE: Thank you, Senator Kaufman.

I'd like to start my questions by -- with an observation that comes out of something that Ms. Hahn said when she mentioned that they were, according to -- I think it's the CDC statistic -- very close to 100,000 Americans who die every year as a result of hospital-acquired infections.

Those of us who have been watching this thing for a while have seen this number move. It began with the ILM report talking about 80,000 American deaths from all avoidable medical errors. And that was only seven or eight years ago, as I recall. And then we got to 100,000 and then we got to 100,000 actually just means hospital-based medical errors. And now we've really identified that the field is 100,000 people dying from hospital errors that are the result of hospital-acquired infections.

So the more that we learn about this and the more that we drill into it, the deeper the quality problem and the more astonishing and egregious the consequences for Americans seems to be. I don't think there's anybody in this room or behind this table or listening to this anywhere who has not had the experience of having a loved one in the hospital and has that terrible feeling that you really can't leave them alone there. Even in the best hospitals, somebody's got to be there to watch out and protect them.

And from that to these, I mean, astonishing consequences -- if 100,000 Americans were being killed every year by anything else, we'd be at war. And here we have, I think, an enormous amount of work and investment to make. So I really applaud all of you for your battles to try to get this right.

I think it's really -- I opened with my concerns about where this put us politically with respect to the health care reform that we need and what the consequences are of getting it wrong in that larger struggle. But for a lot of humans, this is really a truly human story about someone that they love who they lost, someone in the hospital who they can't leave alone there. And we just have to do this a lot better.

The discussion, as I've heard it, has focused on having a comprehensive framework, having -- getting it right, being fairly precise so that everybody knows kind of where they stand and what the rules are, and at the same time dealing with the ongoing nature of discovery. I think Mr. Stokes described it as an ecosystem and a dynamic environment. And as we talk about that, we in Congress, people who are legislators, think about different levels at which you can solve a problem.

At the very baseline, you can come in, particularly if it's a very static, simple problem, you pass a law, you set the standard, you wash your hands and you're done with it and off you can go and worry about something else. This strikes me as not being that kind of thing.

This strikes me as being a highly dynamic environment in which the standard-setting role is less important at a level of detail, if you will, than the architecture-building role.

And right now, I don't see in our health care system a good oversight architecture for solving this problem to begin with and then having somebody or something in place that can continue to adapt to changes through the regulatory environment, continue to correct -- to me this is like landing a plane. You know, you've got to be up, be down, you've got to make adjustments if the wind shifts. You've got to be -- that means there's got to be a pilot or a group of pilots, if you will, if it's an organization of some kind, but there has to be some entity that watches this. And I'm not comfortable that we have that entity now.

As much as I applaud what the CCHIT groups have done and what, you know, ARC is doing and what -- I mean, there are lots of entities that are out there doing it. One of the pieces of advice was don't mess with what's already happening. I think we kind of have to mess with what's already happening, because I don't see that we've got the ongoing architecture in place to manage this transformation. And I'd love all of your thoughts on that point.

What should we be -- what order of decisions should we be making here? Are we talking about actually setting up an organization of some kind that would cope with this or -- I know Tom Daschle is going to be our new director of Health and Human Services. He's written a book about the need for a federal health board. It seems to me to make a lot of sense that there should be a federal health board that has some oversight responsibility over protecting privacy and making sure that this gets done.

That's a long sort of a broad brush of a question, but I'd love to hear your responses to it.

MR. HESTER: I think it's an excellent question and a critical one. At the state level, you know, we've created this organization, VITL, which is our health information exchange and has funding to promote the development of the infrastructure, is putting out the privacy policy. But its role is education and promotion. And we've been asking whose role is it at the state level to do the oversight, because you don't want the policemen to also be the people who are promoting it. So I agree 100 percent, it's a gap, at least from our perspective at the state level, on how you do this.

The other thing I just want to mention is that you talk about getting it right. And I guess, you know Garrison Keillor talks about pretty good, you know, system and I think we want to have a pretty good system, because if you try getting it 100 percent, absolutely no -- zero tolerance for error, it's not going to happen. And what we have to talk about is the balancing of risk.

We have a huge job with the education of our public, the education of our consumers on -- there's a huge risk associated with not doing this, right, and what's the balance between an acceptable level of risk on the privacy and security in order to achieve the benefits of reducing the consequences on the delivery system you're talking -- that's a massive, massive job in terms of getting people comfortable with that balance and that trade-off.

MS. MCGRAW: I think notwithstanding the specifics on privacy that are in the bill, and I mentioned this in my testimony, I think the bill could benefit from a provision that specifically directs the secretary of HHS, because we don't have this federal health board that Senator Daschle, soon to be Secretary Daschle, is talking about. But you need to have accountability for putting these privacy and security protections in place and not just the ones that are regimented in law. But, you know, HIPAA's always been a baseline. You know, states have gone farther, institutions go farther with their policies. Anybody, I think, who gets this significant chunk of federal dollars should really commit to developing privacy and security policies that are coupled with good technological solutions that make them all work to move forward, not necessarily -- you know, because we want shovel in the ground, right? So having people submit detailed plans ahead of time but -- is probably not possible to get the impact that we want as soon as we want it. But if you put the secretary in the position and very specifically task him to hold people accountable, not just for how they spend this money, which they should be, but also what kind of privacy and security protections do you have in place? Do you have protections in place, for example, that meet all of what are common fair information practices in other contexts? We can do that. I mean, there are plenty of models out there to rely on.

SEN. WHITEHOUSE: Ms. Hahn?

MS. HAHN: I agree. There really isn't the type of infrastructure in place. And one key part of that public infrastructure is consumer education. Right now, consumers are clueless in terms of when they sign those HIPAA forms. I mean, most people actually think when you sign the form that if you don't sign it, you won't get health care. So of course, your first thought is, "Whatever I need to do to get immediate attention."

And in terms of what protections are provided to them, I mean, you see the whole gamut from people feeling that they have a private right of action to sue if information is made available to feeling that the federal government is somehow enforcing it for them. So whatever we do, we have to make sure the consumers have a clear understanding of what their medical privacy rights are. And in doing so, as we make sure that folks have that understanding, we'll remove some of the fear and distrust that we need to move in the direction of more health information technology.

I do think that's going to be one key component and then second is accountability. People need to see -- how many people can say here they've seen any entity held accountable for a breach of medical privacy? We only hear about the breaches, but we never find out what is the outcome, and that's going to be critical in moving in that direction.

SEN. WHITEHOUSE: Mr. Stokes.

MR. STOKES: Senator, thank you for that question.

I don't think we can wait one year or even one month or one day. As my vice president testified a week and a half ago in the HELP Committee, we have to start today. We're shipping products today to meet these. We hope that there will be regulations and legislation in a month to help provide more uniform support. We hope that there will be standards and certifications in a year to provide even better support, but we cannot wait and we cannot get it right, perfect. We must start today.

But the focus, we believe, should be on outcomes. If we get too caught up in the processes or the way to get there, we will forget that just like the researchers and the clinicians in the Mayo Clinic, what we really care about is improving health outcomes and reducing the costs. So all of the policies and the principles should focus on are we getting to those outcomes? What is our return on investment?

And finally, the privacy principles are outlined about transparency, control and security. These are actually the same technology principles required by the clinicians and by the researchers to improve quality and reduce cost, because for a clinician, I want to be able to have insight into all of the information. I want the transparency as a CIO in a hospital of all the information in my hospital to improve my quality.

And I want to be able to control that information so if the FDA sends me an alert, I know within hours or minutes what patients in my hospital system are on those medications, that I don't have to spend days or weeks, like it is today, to track down possible drug interactions. Thank you.

SEN. WHITEHOUSE: Mr. Houston?

MR. HOUSTON: We clearly need an organization to oversee privacy and security, and I think not from an enforcement perspective but from an oversight. I've said this for a long time that we're developing this architecture to pass information between entities, across state boundaries and across the United States, but there really isn't an entity in place that provides, I think, the necessary oversight to ensure that appropriate standards are in place, not just for privacy and security but otherwise. And I think we need that. If you look today, we have the Office of Civil Rights that's supposed to enforce privacy. Okay? You know, we all want to get this right, but right now there's no infrastructure in place to support trying to get it right.

You know, I don't want to be -- I hate to say this -- use the analogy of a pilot and ups and downs; you want to make sure you're on the right trajectory when you land, and I sure as -- you know, just like an airplane that's filled with people, you don't want anything coming down in the wrong place because a lot of people can get killed. And I think the same thing applies here, so I think what we need is again some type of oversight organization that provides the support, almost like an -- I can't say even say the word -- ombudsman -- to do as much support as an enforcement.

SEN. WHITEHOUSE: Mr. Merritt?

MR. MERRITT: If I could, I'd like to take a long, somewhat of a long view, like 2009 rather than the next three weeks. I think the three pillars that you identified earlier are exactly the right ones to focus on, health IT, quality improvement and payment reform. The one I'd like to focus on and urge the Congress to focus on this year is the issue of payment reform, because it can drive the other two.

I think it can drive financial incentives for health information technology, and the stimulus package actually has that provision in that -- spirit of that proposal. The second, payment reform can certainly drive quality improvements. We actually held an event at the National Press Club just yesterday that -- and it answered President Obama's call in his inauguration, which -- what he was looking for whatever works.

And so we were exploring health care that works. We released a paper that had 60 pages, 60-plus pages of examples of employers and health systems and others who are actually using information technology, best practices and other programs to improve health, lower costs, drive innovation and expand access. So I think payment reform can actually be implemented so you can drive others to adopt those best practices.

A federal health board -- while I don't support the outline that Secretary Daschle has put forth in his book, I do think that there is a role for some kind of entity to certify best practices, because there are many companies out there that are using data that can identify best practices, whether it's public or private data, and if there is a body that can actually tie best practices to payment reform, I think it really can be an engine to drive a lot of these innovations.

SEN. WHITEHOUSE: Senator Klobuchar.

SEN. KLOBUCHAR: Well, thank you very much, Senator Whitehouse, and I had promised Senator Whitehouse I wouldn't talk about Minnesota and the Mayo Clinic until my last round of questioning.

SEN. WHITEHOUSE: Somebody had to say Garrison Keillor and now there's no holding you back.

SEN. KLOBUCHAR: And I would say that Minnesota is the place to get your quote right, where the women are strong, the men are good looking and all the health care providers are above average. (Laughter.)

But Dr. Merritt, I wanted to follow up with what you said about the costs, which is very important to me, and the quality. As you know, there's been a study out showing that if all the hospitals in the country followed the protocol that Mayo uses for the last four years of a chronically ill patient's life, we could save $50 billion in Medicare payments over a four-year period.

And some of that has to do with the costs in certain parts of the country, but a lot has to do with the way Mayo is able to standardize their work variables, how they pay their doctors, but also how they share information and have a team of doctors working together. So what interests me about what you were talking about is, first of all, to make sure that in this -- the privacy provisions in the stimulus bill -- that nothing would stop us in there from going to this overarching framework that we're talking about. In fact, you intimated that there's some things in there that could help.

But I want to make sure that -- do you believe that there's anything of these provisions that are, you know, the three-week provisions we're putting in place that could stop us from going there in terms of making sure that we can move on to bundled payments and all kinds of things that will create these kinds of incentives?

MR. MERRITT: I'd go back to the two that I identified earlier, which were restrictions on de-identified data, because I know Mayo, just like Intermountain, has a very robust research department where they can actually take research from the clinical process, analyze it and then put it back into the process to identify --

SEN. KLOBUCHAR: Just to make sure, since this is my first day on the committee, by de-identified, you mean data that doesn't have people's names on it --

MR. MERRITT: Yes.

SEN. KLOBUCHAR: -- that goes out into it?

MR. MERRITT: Yes. So if you're working with a data set, it just means that you're dealing with the information, not identifiable information -- names, Social Security numbers, et cetera. So I think that the legislation really does have to be careful with lumping in activities that are used for -- with de-identified data with those that use clearly identifiable data.

SEN. KLOBUCHAR: So you want to make sure that any privacy language we have in the stimulus package that doesn't limit the ability of Mayo or other providers in sharing this de-identified data.

MR. MERRITT: Yes. The reason why are able to know that Mayo and Intermountain and others can provide care that would save Medicare 30 percent is because a team of researchers at Dartmouth has access to Medicare data, and it's de-identified Medicare claims data. And so those kinds of variations they can actually find when they have access to the research into those data sets. So I think there really has to be careful consideration on provisions that would impact researchers' ability to do that.

And then secondly, Mayo and others are very proactive in identifying patients who are -- who qualify for various chronic-care programs and they can focus on wellness before it becomes a disease.

SEN. KLOBUCHAR: This is what you talked about earlier, with being able to reach in and get the --

MR. MERRITT: Correct.

SEN. KLOBUCHAR: -- patients that you think need the help.

MR. MERRITT: Correct. And many of these fall under the current definition of health care operations. Some of the language, I think, could actually harm a health system's ability, whether it's a system like UPMC or Mayo or a health plan, to have the ability to actually connect with a patient and say, we've looked at your record; we understand that you have X, Y and Z; we think you're in danger of type 2 diabetes or you need to control your obesity, or whatever the condition may be.

If there are restrictions on the system or the entity reaching out to that consumer or patient, again, I think you have to be very careful because you want -- at the end of the day, we all want the patient to get the care that they need, but if there are privacy restrictions that don't allow the connection and the education, I think that could ultimately harm individual health.

SEN. KLOBUCHAR: So you're concerned there's language in there right now that could do this?

MR. MERRITT: Yes.

SEN. KLOBUCHAR: Limit it?

MR. MERRITT: Yes.

SEN. KLOBUCHAR: All right. Well, we'll have to look at that because I've found it very helpful -- I know it's helpful for Mayo and these other groups that have done so well to be able to have that research.

I also think in the end it would be nice if it was done the right way, with no security breaches and everything we've talked about to be able to have that data on a national basis so we can get the bright protocols in place, because there clearly has been a problem with decisions being made with the lack of research.

Thank you.

SEN. WHITEHOUSE: Before we proceed, just one piece of administrative housekeeping. Letters from the Vermont Information Technology Leaders, from the Coalition for Patient Privacy, and from the American Civil Liberties Union will be added to the record of this hearing, without objection.

And one of the things that I come across pretty frequently but I haven't really been able to source it, so I'll throw it to the expert panel and see if you have any information on this, is that when people have chronic or multiple illnesses and they have a lot of exposure to the health care system, their appetite for electronic health records is very high and their tolerance for privacy concerns is also quite high because they're living in the environment where they can see the value of the electronic health record and the communication, and the privacy concerns just don't matter as much to them when they are ill.

I see heads nodding. Is that anybody's experience out there and might it be helpful to focus initially in terms of trying to develop some of this, particularly for going forward in a dynamic environment on those very high-expense, very high-contact either chronic or multiple-illness patients in the system?

Mr. Merritt?

MR. MERRITT: If I may, one think the federal government could actually do to address that problem is through providing information for Medicare beneficiaries based on information that CMS actually has. For instance, we've talked a little bit about personal health records. Microsoft -- there are private companies, there are private payers that have been in this space for a long time.

CMS has a very small pilot in South Carolina and they just announced two others in Arizona and Utah, but what I would propose is that the federal government through CMS actually put up a consumer portal, so that any beneficiary who wants to can actually log on and see just a snippet of their information. And if they want to share that with their doctor, I think that would be incredibly valuable.

Some studies say that the average beneficiary is on six medications; that's the average. And the average beneficiary sees 13 different doctors throughout the course of the year, and there's no coordination between that. So having patient-controlled access to that information I think would be incredibly valuable. I'd certainly open it up for other comments as well.

SEN. WHITEHOUSE: Mr. Houston

MR. HOUSTON: I would agree with the proposition that people that have chronic illnesses absolutely would be more interested in having PHRs and I think the insurance companies would likely also want to manage that population much more aggressively to try to reduce inpatient admissions and improve quality of care, things and that sort.

But I don't believe that those people believe that their privacy is less important, because probably one of the primary types of chronic illness in the United States is behavioral health illnesses, depression and other things. And I think that those people could definitely be helped by having a PHR. But they're also a population that's probably more concerned about the privacy of their information, so I think privacy has to be done well throughout, regardless of what the population is, regardless --

SEN. WHITEHOUSE: Yeah, I couldn't agree with you more about that. My point was that if you're looking for early adopters who see the real value of this, there seems to be a kind of fortunate correlation between the people for whom this would be the most helpful and their willingness in --

MR. HOUSTON: Absolutely.

SEN. WHITEHOUSE: -- trying to achieve that value in their own health care.

MR. HOUSTON: Take diabetes alone. I think that that's probably a chronic illness for which having good tools to -- for patients would clearly benefit the patients and reduce costs, you know, improved quality of life. I mean, I think that's a clear winner. And you're right, I mean, those people are very concerned about trying to manage their condition.

SEN. WHITEHOUSE: Dr. Hester?

MR. HESTER: You're right on target. One of the main themes of the health care reform in the state of Vermont has been focusing on patients with chronic illness. I mean, we have sustained attention on that. Again, I mentioned in my testimony we have pilots, enhanced pilots in three communities which involve payment reform, the creation of community care teams and the provision of information technology tools for the practices and for the patient that will cover 10 percent of the Vermont population by the end of this quarter.

It's not just a matter of the benefit to the patient. You cannot do chronic illness care best practice, you cannot be proactive in reaching out to patients, to a diabetic who has not had their hemoglobin A1c in the last six months unless you have those tools in place and the patients understand that.

So from the standpoint of -- Ed Wagner has developed something called the chronic care model, which is sort of his approach to saying how do you do best practice. It involves the combination of a proactive care team of providers and engaged patients. The information technology is critical to supporting both the care team and patient engagement and we have found it to be a very rich area of collaboration and one reason that we focused -- you know, one of VITL's major pilot programs has been in providing those information tools, supporting those information tools in those pilot communities. So I'd be happy to provide you some additional information if you're interested.

SEN. WHITEHOUSE: Thank you. I'd appreciate that.

Mr. Stokes?

MR. STOKES: Senator, I agree that this is a critical area and very opportune areas for cost savings and improving quality. But as I pointed out before, there's no need to wait. We have cooperation with Cleveland Clinic today that pilots and targets chronic care disease, population within the Cleveland Clinic through a combination of different doctors and specialties within the clinic and the chronic patients at home because we found that if they're in a remote setting, they will take their blood glucose measurements more often.

There is a better compliance and better participation all through health -- (inaudible) -- without having to sacrifice any patient privacies, maintaining the transparency and control. So as was discussed, if we can move forward and have better foundations and better infrastructure and better guidance over time, that would be great. But even today, we're focusing on the outcomes to move this forward.

SEN. WHITEHOUSE: Dr. Hester again.

MR. HESTER: Just one more comment. The success of that chronic- care model is completely dependent upon payment reform as being discussed earlier. And there is a regional collaborative being formed in the New England states, including Rhode Island, sponsored by The Milbank Fund to have a regional demonstration in patient-centered medical home and to try to provide a vehicle for Medicare to participate and support.

What we're finding is the states are further ahead in terms of multipayer payment reform involving commercial insurers and Medicaid, but we're having difficulty in getting Medicare to the table in those and it's something that we could use some assistance in the new administration to move forward, and we're hoping this regional collaborative will be a vehicle.

SEN. WHITEHOUSE: Well, I think I'll take this opportunity to bring the hearing to a close. I want to thank all of you very much for your testimony and for your work in this area. I'll just re- emphasize what I said at the beginning. I think we are headed -- remember when the Clinton administration tried health care reform and they got Harry and Louise and that put an end to that particular effort?

SEN. KLOBUCHAR: But, Mr. Chair, now Harry and Louise are on Medicare Part D and now they support the effort. (Laughter.)

SEN. WHITEHOUSE: Yeah. And I think now the model is no longer Harry and Louise, now the model is Thelma and Louise -- (laughter) -- and we're all in the car -- (laughter) -- and the cliff is right in front of us and if we don't get this solved through technology, through systems reform, through better-quality care, through a more rational payment system, then we will get to the edge of that cliff.

And when we're there and we have to go into the other toolbox and throw people off of health coverage and thin out our already tragically thin benefits and put even more costs on our business community, which is already laboring uncompetitively under health care costs compared to their foreign competition, and tell providers who are already cross-subsidizing in order to stay in the federal health care system that we're going to pay them even less, it is going to be a nightmare.

And so your work to guide us through the privacy hazard to solving these problems the good way I think is really at the absolute apex of issues that our country faces. And I applaud you for it. I urge you to be as persistent and energetic as you can, and I think you've seen from the turnout in this committee and from how long people stayed that this is a matter that has great interest, and we truly look forward to working with you.

The record of the committee will stay open for an additional week in the event that anybody has anything they would care to add. And without anything else, I appreciate again that you've all come in here; I appreciate everybody's attention. And the hearing is adjourned. (Sounds gavel.)


Source
arrow_upward