A call for national e-health clinical safety governance
Authors: Enrico W Coiera, Michael R Kidd and Mukesh C Haikerwal
Published online: 16 April 2012
The benefits of technology should not be overshadowed by avoidable patient harm
Well designed and implemented information technology (IT) can lead to safer and more effective clinical care.1 This rationale has triggered a rapid and unprecedented expansion in e-health investment globally, most recently in national-scale systems. However, e-health can sometimes lead to patient harm or death through problems in design or operation.2 Chances of harm increase with known risk factors such as poorly designed software or its implementation, including rapid deployment, and poor training and support.3 We have previously argued for regulation of clinical software to mitigate these hazards; a case echoed internationally.4-6
The United States Institute of Medicine recently issued a major report on e-health safety.7 It recommends the US Food and Drug Administration immediately develop a framework for regulating IT, including standards for e-health manufacture, and the establishment of a new federal entity to monitor, investigate and report patient harms. The US government has agreed to act rapidly on these recommendations.
It is time to ask what national clinical safety governance for e-health should look like in Australia. E-health is now pervasive. Almost every general practice and community pharmacy is computerised. Most public hospitals are in various stages of computerisation, and our first national-scale electronic record system, the personally controlled electronic health record (PCEHR), is due from 1 July 2012. The handful of studies of e-health safety in Australia all point to clear evidence of past harms and future risks.8-12 Yet there are few working international clinical safety governance examples to follow.
At present, e-health in Australia is unregulated and unmonitored. There is no organisation with either the expertise or mandate to govern system safety “from bits to bedside”. Our National E-health Transition Authority (NEHTA) develops health IT standards and specifications and assures their safety. Its Compliance, Conformance and Accreditation program defines the tests that should be applied to certify clinical systems using these standards and specifications. However, it is beyond NEHTA’s remit to actually test the safety or compliance of clinical systems or their operation. The Australian Commission on Safety and Quality in Health Care has an interest in the safety of clinical decision-support software but has no regulatory mandate. The Therapeutic Goods Administration, which does have regulatory power, considers clinical software beyond its scope. It may be that e-health clinical safety governance needs to fall under the remit of Australia’s Chief Medical Officer, or a specifically designated body.
As they are a new class of IT with an unknown hazard profile, national-scale systems like the PCEHR pose a particular challenge. We cannot quantify today what will result in terms of either benefit or risk. Our capacity to predict outcomes is also hindered because these systems will be used by both clinicians and consumers. What can be said is that there is some evidence that well targeted e-health systems can deliver significant benefits.1 We also know there is a finite risk of patient harm associated with the use of clinical IT, and that this grows with increased system complexity and usage.3
Given the systemic nature of national e-health, harm events will not be confined to individuals and may affect large groups of patients. What would a patient safety incident look like after the launch of the PCEHR? What would happen, for example, if drug allergies were incorrectly uploaded from local clinical systems, or if medication names and doses were somehow incorrectly imported and displayed? Most such informational errors lead to no harm or are picked up by system “defences”, such as clinician vigilance. At some point, however, patient harm will occur. How many cases need to occur before the problem is detected? Models from infectious disease surveillance suggest that harm events would first need to be recognised as a cluster, signifying an outbreak of public health importance. The duration of the window between the outbreak and its detection determines how many harm events occur before remedial action is undertaken.
The events most likely to harm patients will occur after IT systems are implemented, often from unpredictable chains of low-risk events involving people, technology and fickle circumstance. They may well result from safe components working in unsafe configurations. Certification that individual components meet standards thus does not guarantee that the overall system is safe. These are the clinical safety challenges for all national-scale systems.
As it is not possible to detect all potential risks during system development and implementation, we need risk management strategies for unforeseen risks. Oversight is needed to manage the tasks of monitoring, detection, investigation and remedial action.13,14 Monitoring may depend on a combination of adverse event notification and proactive automated and human surveillance. As with the airline industry, when harms eventuate, public confidence in the continued use of a system relies heavily on open disclosure, as well as rapid investigation and mitigation of the harms so they will not be repeated. We suggest some basic underlying principles for any national e-health clinical safety governance system (Box).
There is currently a gap, stretching from local to national, in safety governance for clinical information systems. While we know something about the risks associated with clinical desktop systems, it is not yet possible to make any definitive statement about whether the PCEHR is safe or not. There is no guarantee that harm events will be rapidly identified or remediated when it is in operation. It is not even clear what safety means for such a system. Even if short-term performance of the new national system turns out to be safe and effective, the international experience suggests that risks will emerge with time. Preventive action to avoid an e-health “air crash” now is a far better option than picking up the pieces after the event.
AddendumAs one of the National E-Health Transition Authority (NEHTA) Clinical Leads, and co-author of this editorial concerning regulation and monitoring of Australia’s e-health system, I wish to clarify that:
- Clinical safety and governance is everybody’s business in health information technology (IT) systems deployment.
- The work that NEHTA has undertaken to optimise clinical safety has matured to give confidence in the specifications, standards and other products that NEHTA builds. NEHTA-designed products have been assessed for safety, and this provides surety to users and software developers.
- NEHTA has incorporated several layers of defence for the e-health environment and, in particular, products it has built. These include clinical governance (incorporating safety) and the National E-Health Security and Access Framework.
- The focus of the editorial is to promulgate the notion that there is a way to provide clinical governance for IT in the health sector — it is necessary and possible.
- We are highlighting that as medical care involves more use of, and reliance upon, electronically recorded information, the same robust processes of clinical governance must apply to it as to all other products used in the health care sector.
- The need for e-health safety governance applies beyond the personally controlled electronic health record (PCEHR), which commences deployment in July 2012. As the PCEHR and other IT products build in richness of content and are used and relied on more widely in the community, they will need, and users will benefit from, assured clinical safety processes and parameters.
Head of Clinical Leadership, Engagement and Clinical Safety
mukesh.haikerwal@circlesurgery.com.au
Principles for national e-health clinical safety governance
E-health clinical safety governance must be national but independent of government or industry, to avoid conflicting interests that may lead to resisting change for commercial, professional or political reasons. It must be expert-based rather than organisationally representative.
Safety is an emergent property of a whole system. Certification of individual components does not guarantee that the whole system is safe.
E-health clinical safety governance should integrate with mainstream patient-safety processes. Harms arise from sequences of events involving both technical and non-technical elements.
Governance must assure all components are safe, both alone and in combination with pre-existing elements. Standards and regulatory processes such as accreditation should underpin this, with full legislative backing.
The safety of the whole system must be monitored in routine use to detect potential risks and actual harm events, as well as clusters. Open disclosure should be paramount.
Governance must build defences against harm, including safety processes, system redundancies and training, to minimise unsafe use or the creation of unsafe settings.
Any governance body must have a capability to investigate, analyse and act upon significant risks in the system.
Competing interests
Acknowledgements
References
- Bates DW, Gawande AA. Improving safety with information technology. N Engl J Med 2003; 348: 2526-2534. 0_i1139900
- Magrabi F, Ong MS, Runciman W, Coiera E. Using FDA reports to inform a classification for health information technology safety problems. J Am Med Inform Assoc 2012; 19: 45-53. 0_i1139902
- Coiera E, Aarts J, Kulikowski C. The dangerous decade. J Am Med Inform Assoc 2012; 19: 2-5. 0_i1139904
- Coiera EW, Westbrook JI. Should clinical software be regulated [editorial]? Med J Aust 2006; 184: 600-601. 0_i1139907
- Magrabi F, Coiera EW. Quality of prescribing decision support in primary care: still a work in progress [editorial]. Med J Aust 2009; 190: 227-228. 0_i1139909
- Sittig DF, Classen DC. Safe electronic health record use requires a comprehensive monitoring and evaluation framework. JAMA 2010; 303: 450-451. 0_i1139911
- Committee on Patient Safety and Health Information Technology; Institute of Medicine. Health IT and patient safety: building safer systems for better care. Washington, DC: The National Academies Press, 2012. 0_i1139913
- Makeham MAB, Saltman DC, Kidd MR. Lessons from the TAPS study — recall and reminder systems. Aust Fam Physician 2008; 37: 923-924. 0_i1139915
- Magrabi F, Ong MS, Runciman W, Coiera E. An analysis of computer-related patient safety incidents to inform the development of a classification. J Am Med Inform Assoc 2010; 17: 663-670. 0_i1139917
- Sweidan M, Reeve JF, Brien JE, et al. Quality of drug interaction alerts in prescribing and dispensing software. Med J Aust 2009; 190: 251-254. 0_i1139919
- Westbrook JI, Reckmann M, Li L, et al. Effects of two commercial electronic prescribing systems on prescribing error rates in hospital in-patients: a before and after study. PLoS Med 2012; 9: e1001164. 0_i1139921
- Magrabi F, Li SYW, Day RO, Coiera E. Errors and electronic prescribing: a controlled laboratory study to examine task complexity and interruption effects. J Am Med Inform Assoc 2010; 17: 575-583. 0_i1139923
- Singh H, Classen DC, Sittig DF. Creating an oversight infrastructure for electronic health record-related patient safety hazards. J Patient Saf 2011; 7: 169-174. 0_i1139927
- Jones SS, Koppel R, Ridgely MS, et al. Guide to reducing unintended consequences of electronic health records. Rockville, Md: Agency for Healthcare Research and Quality, 2011. 0_i1139928
Provenance: Not commissioned; externally peer reviewed.