
In today’s modern world, certain developments demand a wellspring of public outrage. A case in point should be the results of a study published last week in the Journal of the American Medical Association. Virtually unnoticed, the study found that between 2009 and 2013, more than 29 million medical records were hacked, stolen or otherwise compromised. Most of these were criminal breaches — with Illinois one of the top states where breaches took place.
The study’s lead author, Dr. Vincent Liu, estimated the actual number was even larger. He sees little reason to believe the trend of medical record theft will not continue unabated in the future. “Our study demonstrates that data breaches have been and will continue to be a persistent threat to patients, clinicians and health care systems,” Liu said.
In the last 20 years, the electronic medical record has been promoted by the government and health care industry as a way to improve care, save money and, not surprisingly, process payment. As the JAMA study indicates, an unforeseen consequence of the transition from paper to computerized records means that even with passwords, firewalls and encryption software, your medical file can be accessed anywhere in the world. This means not just your diagnoses, test results and insurance information but your home address, Social Security number, employment data, genetic profile and other confidential personal information.
Since the time of Hippocrates, about 2,500 years ago, medical confidentiality has been the cornerstone ensuring patients could communicate freely with their caregivers. Confidentiality guaranteed that the interests of patients and caregivers were aligned so patients could receive care, and doctors could render it without fear of divulging information publicly.
For decades, your medical records were reasonably secure. Hospitals, clinics and doctors maintained the traditional presumption of confidentiality; records were usually kept as paper charts stored in an office or hospital basement. Insurance company billing required only a few pages, not a complete set of medical records. It was certainly possible for an unauthorized person to examine or steal a patient’s chart but these were isolated occurrences. Those truly intent on mischief could do so only by surreptitiously removing a record and copying it. Even then, only a limited number of copies could be generated. The worst problems occurred due to the occasional improper disposal of paper medical records, where, at most, several hundred records might be breached. Nothing on the scale of millions of records being compromised was conceivable, let alone possible.
Enter the electronic medical record. Its introduction has provided undeniable advantages to medical care, including making health records immediately accessible to providers, avoiding duplicated testing, allowing doctors at distant centers to see information instantaneously and providing patients the ability to transfer their records to other providers easily. (These advantages unfortunately have not always included giving patients copies of their medical records without paying exorbitant sums).
Yet as the medical community is painfully finding out, the electronic medical record has not been an unalloyed benefit. Entering information into a computer while doing a medical interview has depersonalized the patient encounter, to the detriment of the patient and the profession. Standard software templates can make interviewers lazy and the right questions might not be asked (this may have played a part in the failure to quickly diagnose the first Ebola patient in the United States). “Cut and paste” entries are rampant and often perpetuate errors. In addition, reams of extraneous and duplicated information means a simple hospital stay of several days now results in a virtually unreadable thousand-page chart printout.
But the most serious unintended problem of the computerized record has been the sacrifice of patient privacy and security of personal health information. Records have been breached on levels undreamed of only several years ago. With a little expertise, almost any computerized patient chart can be copied and distributed over the Internet to anyone in seconds. And even a single stolen laptop can contain thousands of patient files. It would be hard to conceive of a more inviting platform to identity theft.
By themselves, patients have little recourse. Both the medical and legal communities, including the American Medical Association and the American Civil Liberties Union, must take a much stronger stand on patients’ behalf and make the safety of personal health information a higher priority. More state and federal legislation is necessary, because there are major holes in the way current laws are written. As experts have pointed out, digital information companies such as Apple, Google and Facebook, with the potential to access patients’ medical information, are not covered by most health care regulation. Further, computer outlaws, including offshore hackers, are hardly deterred by American law.
Welcome to the brave new world of health care. Computerized medical records have given your health care providers better access to your medical information than ever before, even while your medical history will never again be as secure as that of your grandparents. Most people in health care consider this progress. But as George Orwell once observed, progress is invariably disappointing.
Cory Franklin is a Wilmette physician.