Friday, 25 September 2015

Pragmatic Advice For Would-Be Health Entrepreneurs From The Medicine X Conference

At this morning’s Health Innovation Summit – part of the Stanford Medicine Xconference now underway – I had the opportunity to listen to a number of compelling presentations, and to moderate an author panel with UCSF Professor of Medicine Bob Wachter (book: The Digital Doctor) and Athena Health co-founder and CEO Jonathan Bush (Where Does It Hurt? – my WSJ review here, additional Forbes commentaryhere).

Based on an informal “raise your hand” survey I did when I started my session, it seemed like the audience was about 40% tech people who had moved into healthcare, and 60% healthcare people who had embraced technology.  The majority of attendees reported trying to obtain their health records at some point, and many, it seemed had been successful (suggesting the audience was either particularly well-connected or unusually persistent).  A large number – perhaps half – had obtained consumer genetic information, via either 23andMe or Ancestry.com – suggesting, again, an unusually high level of interest and engagement.

(Disclosure/reminder: I work at a cloud genomics company in Mountain View, CA.)

Four points from this morning seemed especially relevant to aspiring healthcare entrepreneurs.

EMRs: Extract My Revenue

One highlight of the morning was a compelling interview of entrepreneur Christine Lemke (Chief Product Officer of Evidation Health) by Rock Health’s Managing DirectorMalay Gandhi.  One point made by Lemke, and echoed by some of the other speakers and attendees, is that the key factor driving EMR selection for major hospitals (Epic was often called out, but perhaps only because it are said by many to do this the best) is the capability to enhance “revenue-cycle management.”  Translation: – it’s all about the Benjamins.  Perhaps more than anything else, hospitals want to maximize their revenue, and ensure they capture, and extract the most (permissible) value for the services they provide.

This matters for two reasons.  First, if you are an entrepreneur selling into the healthcare system, then you really need to understand the business of healthcare, and more specifically, must appreciate how and why the money flows.  There are a lot of lofty words and lofty intentions in healthcare, but at the end of the day, hospitals executives – the folks who make the large purchasing decisions — are driven largely by the financialbottom line, and entrepreneurs need to understand this.

Second, media coverage of EMRs tend to focus on interoperability – the ability to connect with external EMRs; provider discussions of EMRs often focus on the endless, soul-crushing data entry and aggravating workflow.  While hospital executives would probably say happier staff represents a “nice to have,” and improved interoperability is a “nice to say we aspire to have” (see here), neither of these factors seem to truly drive decisions around EMR choice or EMR implementation (with some exceptions, of course).  Mostly, it seems to be about the ability of the EMR system to be implemented reliably, and then generate revenue for the hospital.  In the prophetic words of H. L. Mencken, “When somebody says it’s not about the money, it’s about the money.”

View the original content and more from this author here: http://ift.tt/1VcGFKW



from health IT caucus http://ift.tt/1YF2Ets
via IFTTT

AHIMA conference attendees stand at brink of ICD-10 transition

It seems almost uncanny how the health IT conference most associated with ICD-10 and all things medical coding is being held this year literally on the eve of the historic transition from ICD-9 to ICD-10.

Indeed, when the 2015 AHIMA Convention & Exhibit ends in New Orleans the afternoon of Sept. 30, the ICD-10 deadline will be only about eight hours away at midnight on Oct. 1.

While some worry about the changeover, the ICD-10 milestone is one that leadership of the American Health Information Management Association, and the majority of AHIMA’s members, overwhelmingly support, considering that AHIMA has been one of the strongest advocates for ICD-10.

“There’s going to be a celebratory atmosphere,” Sue Bowman, AHIMA’s senior director for coding policy and compliance, told SearchHealthIT. “I think the vast majority of the industry is ready.”

Even so, there is simmering unease in some quarters about the advent of the new and exponentially more complex coding system, particularly among physicians and physician practices.

For an up-to-the-minute expression of this ICD-9 to ICD-10 angst, check out this blog post from Merge Healthcare Incorporated, the VNA vendor recently acquired by IBM Watson Health.

A Merge poll of its medical enterprise imaging clients found that about half felt they were 80% ready for ICD-10, and another 40% felt they were 50% to 80% ready., Many of those polled were worried not so much about the switch itself, “but rather the interim period following the switch where they will likely have to use both code sets for billing,” the blog says.

All that said, the AHIMA conference — expected to draw several thousand health information management professionals and a few hundred vendors — will deal with more than just ICD-10, though there will be panels devoted to last-minute conversion tips and vendors selling ICD-10 accessory software.

High on the agenda is information governance, a field that has been prominent for years in information management in other industries, but only made its first real splash in health IT last year at the AHIMA conference in San Diego.

This year, AHIMA is rolling out a host of information governance resources, including consulting services, Bowman noted.

In the meantime, Bowman said she feels confident that individual practitioners and others who see adopting ICD-10 as daunting will ultimately come around to the coding system’s benefits: more than six times as many codes as ICD-9 and the resulting richer trove of health data for analysis and mining and clinical knowledge.

“I think even physicians will see that it’s not too hard to use and will give them better health data,” she said.

View the original content and more from this author here: http://ift.tt/1KGmHhE



from health IT caucus http://ift.tt/1Wmzptf
via IFTTT

Thursday, 24 September 2015

IOM Calls for Better Use of Health IT To Reduce Diagnostic Errors

The Institute of Medicine in a new report made several recommendations calling for better use of health IT to help hospitals reduce diagnostic errors, which are likely to affect nearly all U.S. residents in their lives, Health Data Management reports (Slabodkin, Health Data Management, 9/23).

Report Findings

The report, titled “Improving Diagnosis in Health Care,” concluded that most individuals will experience one or more diagnostic errors — defined as delayed or inaccurate diagnoses — in their lifetimes (Appleby, Kaiser Health News, 9/22).

Such errors affect one in 20, or about 12 million, patients annually (Health Data Management, 9/23). Further, they account for hundreds of thousands of adverse events and nearly 10% of all patient deaths.

However, IOM said that far too little attention has been paid to such errors as providers focus more on other safety concerns.

Health IT Findings

The report noted that electronic health records can act as barriers to correct diagnoses, noting:

  • “Auto-fill” functions can result in erroneous information being entered;
  • EHRs often lack interoperability; and
  • The volume of inputs and alerts can overwhelm staff (Kaiser Health News, 9/22).

According to the report, “Urgent change is warranted to address this challenge.”

Recommendations

Among other things, IOM recommended that vendors and the Office of the National Coordinator for Health IT work to ensure technologies:

  • Align with clinical workflows;
  • Demonstrate usability;
  • Facilitate the flow of information among patients and providers;
  • Incorporate human factors knowledge;
  • Integrate measurement capability; and
  • Provide clinical decision support (Health Data Management, 9/23).

IOM also recommended that:

  • ONC require health IT vendors by 2018 to comply with interoperability standards that facilitate the flow of patient information across care settings; and
  • Patient access to EHRs include clinical notes and diagnostic test results (Frieden, MedPage Today, 9/22).

In addition, IOM said HHS should require health IT vendors to:

  • “Notify users about potential adverse effects on the diagnostic process related to the use of their products”;
  • Submit their products for routine independent evaluation; and
  • Support the free exchange of information about real-time user experiences with health IT design and implementation that negatively affect the diagnostic process.

View the original content and more from this author here: http://ift.tt/1LyElI7



from health IT caucus http://ift.tt/1gQvGUG
via IFTTT

ONC releases health IT strategic plan

The plan that will govern the development and use of federal health IT through 2020 has been released. The Office of the National Coordinator for Health IT rolled out the plan Sept. 21, after months of considering and incorporating public feedback on the draft plan released in December 2014.

“This Plan outlines the commitments of all the agencies that use or influence the use of health IT across the nation for the next five years,” wrote ONC officials led by Karen DeSalvo, acting assistant secretary for health at the Department of Health and Human Services, in a blog post.

“The Plan is an action plan for federal partners, as they work to expedite high-quality, accurate, secure, and relevant electronic health information for stakeholders across the nation. The Plan’s strategies for achieving this aim focus on making electronic information available,” the entry reads.

The plan specifies four goals:

  1. Advance person-centered and self-managed health;
  2. Transform healthcare delivery and community health;
  3. Foster research, scientific knowledge and innovation;
  4. Enhance nation’s health IT infrastructure.

ONC received more than 400 pieces of feedback on the draft plan, according to the blog post, and solicited more through nearly two dozen listening sessions.

“The final Federal Health IT Strategic Plan reflects commenters’ recommendations that federal efforts, including government programs and policies, assist stakeholders as they use electronic information to improve health and support innovations that make health, care delivery, and research more effective,” wrote DeSalvo and her co-authors. “The Plan is a broad document that condenses the detailed work and strategic direction of many federal initiatives and plans. Its strategies and objectives support the use of health IT to accomplish these ongoing initiatives, such as precision medicine and delivery system reform.”

View the original content and more from this author here: http://ift.tt/1LyEnzV



from health IT caucus http://ift.tt/1gQvGUE
via IFTTT

Select produce by color to address specific health concerns

Fruits and veggies are important to include in your diet. But choosing which ones to grab can sometimes be overwhelming. Nutritionist Mary Pietras from Beyond Basics Health Coaching can help take the guess work out of grocery cart filling.

She recommends shopping for produce based on the color. Pietras said how it appears on the outside can tell you how it will make you feel inside.

Red-like beets and tomatoes-are great for cellular function, like anti- aging. Pietras said red veggies and fruits decrease inflammation. They’re also great for increasing energy.

Orange offers vitamin C, but it also boosts our immune system and also decreases inflammation.

But most produce might be green with envy of the color green. About 60% of your cart should be filled with greens.

“Because of the chlorophyll that’s in there and it actually is very close to what blood is like- the consistency the nutrients in there- so it allows your body to heal itself more and we can breathe better and get more oxygen into our system,” she said.

White produce is one of the most important in boosting your overall health. It has ECGC in it that stabilizes our hormones and also boosts our immune system. A lot of people don’t get that into their system- like garlic and ginger- can kill all the bad bacteria in the gut allowing the good to thrive which boosts immune system helps us be overall healthy.

View the original content and more from this author here: http://ift.tt/1LyElrP



from health IT caucus http://ift.tt/1gQvGUC
via IFTTT

Fixing Qld Health’s IT systems: start with the plumbing

Queensland Health will eschew a big bang transformation of its legacy systems in favour of a lower-risk, incremental approach to systems replacement in the hopes of reviving its IT fortunes. While much attention has been on the department’s disastrous implementation of an SAP payroll system …
View the original content and more from this author here: http://ift.tt/1gQvGUA



from health IT caucus http://ift.tt/1LyElrK
via IFTTT

Applying Data Science to Advanced Threats

The Problem

The cyber security industry is now over 30 years old. And just like people, with each passing decade, we realize that what worked for us in our 20s, simply won’t work for us now or going forward. In fact, carrying forward the mindset and behaviors of those first 20 years exposes us to countless problems in health and long term solvency. We learn that to survive in the world we must adapt and evolve to a higher form of existence. The antiquated and archaic practices of our past limit our visibility into the future in detecting, and thereby avoiding, maliciousness. Consequently they have given rise to a freight train sized hole of opportunity for the cyber criminals, nation states and cyber miscreants that wish to exploit our blindspots in the cyber world.

Blacklisting (and Signatures) Can Be Compromised

Blacklisting technologies rely almost 100% on signature based techniques for detecting bad files have been at the heart of our industry since the beginning when we had only rare outbreaks like Michelangelo, Stoned and the Morris Worm. The grossly unfortunate fact is that they remain the predominant form of detection (and thereby prevention) in the market today. Signature based approaches to security served us well then when the number of bad objects (files, network traffic, and vulnerabilities) was small and the techniques to alter those files to bypass detection were non-existent or at least non-trivial.

Today however, countless techniques exist to avoid these once stalwart protection technologies, including packers, mutation engines, obfuscators, encryption and virtualization bypass techniques.

Within milliseconds, a once easily detected malicious file can be altered to be completely invisible to even today’s best detection technologies while remaining functionally identical to its original maliciousness. This allows the bad guys to easily bypass security infrastructure that once detected them with ease.

The sheer numbers of files submitted to security vendors today for analysis (over 100k daily) is so overwhelming that most vendors simply cannot handle the volume. Their methods and manpower become easily avalanched over. The scale of the problem outnumbers the industry’s capacity for maintenance. As a result we have rampant miss rates.

Whitelisting Can Be Compromised

Whitelisting technologies developed in response to what the Blacklisting world is victim to: low detection rates. In other words, blacklisting alone detects only 5-10% of malicious files out there. The reason whitelisting was so promising for so long was that it effectively did the opposite of blacklisting: rather than stopping everything known bad (which is large and hard to do), whitelisting only allowed to run those files which are known good (which is much smaller and presumably easier to do). This technique has been applied to security through identification of permissible URLs and files that are known (or perceived) to be clean and safe. But these solutions have some fundamental problems as well.

The first challenge with solutions that rely heavily on whitelisting is that one must simply “trust” what the vendor (or your operations staff) has designated as “good”. We have seen this model fall down time and again with security and software vendors who have their development environments compromised and their private signing certificates stolen (e.g. Adobe, Bit9 and Opera Software). When these attacks occurred it allowed the thief to sign their own malicious files as if they came from the “trusted” vendor. And because whitelisting solutions rely so heavily on this “trust” model, it allows the bad guys to easily bypass the technology.

Trust Can Be Compromised

As a consequence to the identified gaps of blacklisting and whitelisting, numerous technologies have crept up to fill in the gaps of signature technology including host intrusion protection systems (HIPS), heuristics, behavioral, and both hardware and software sandboxing. But all of these techniques have two core weaknesses: 1) foundational signature elements, and 2) reliance on “trust”.

Technologies such as HIPS, heuristics and behavioral engines remain at their core, signature based. They rely on “knowing” what is bad and creating a signature for that “badness”. Even sandboxing technologies which claim no signatures are involved to autodetonate captured files and binaries, still rely on signatures to enable alerting and blocking the next time it sees it.

For these technologies to know if something is good or bad, they must map them to a list of known good or bad behaviors which can take minutes, hours, or days using manual verification. Even then, the attack has already happened and the detonation may not discern the maliciousness of the malware.

Can we simply “trust” our vendors to show us what is “good”?

Bad guys have the advantage in more resources and time to outwit the various detection schemes of security vendors. Additionally, many security models (like signatures) require the engagement of a human. Human involvement is fallible and limited in scale to the speed and sophistication of advanced threats.

Can we simply “trust” our security vendors to show us what is “bad”?

We as an industry must evolve from this outlived model to a new and ever-evolving technique; one that abandons signatures and blind trust; one that relies on a mathematical, algorithmic and scientific approach to better effectiveness and measurable accuracy. In short, we must evolve to “Trust the Math” and science of Cylance’s Infinity.

Introducing Cylance Infinity

Infinity is a fundamental and epic shift from traditional security methods of detecting good and bad. It is a highly intelligent, machinelearning, data analysis platform.

As battle tested security industry veterans, we know that the previous approaches can never cope with the volume and variety of advanced threats. So we designed Infinity to make intelligent decisions without relying on signatures. It does this by taking a predictive and actuarial approach to data on a network to determine good from bad.

This model exists in many other industries. Insurance companies use actuarial science to determine the likelihood of a risk event for the insured person at a surprisingly high rate of accuracy. This concept relies on advanced models of likely outcomes based on a variety of factors. For a standard insurance policy, they may consider twenty to thirty facts to determine the most likely outcome and charge appropriately. Infinity uses tens of thousands of measured facts harnessed across millions of objects to make its decisions, in near real-time.

Infinity, at its heart, is a massively scalable data processing system capable of generating highly efficient mathematical models for any number of problems.

Cylance uses these models applied to ‘big data’ to solve very hard security problems with highly accurate results at exceptionally rapid rates. It’s done by applying data science and machine learning on a massive scale. Coupled with world class subject matter experts, cyber security is able to leap ahead of threats.

While Infinity is problem agnostic, correctly designing solutions to hard problems takes time, knowledge and effort. The Cylance Infinity Labs team has focused all of their efforts on detecting advanced threats, in near real-time, correctly, without signatures.

While Infinity is problem agnostic, correctly designing solutions to hard problems takes time, knowledge and effort. The Cylance Infinity Labs team has focused all of their efforts on detecting advanced threats, in near real-time, correctly, without signatures.

What is Machine Learning?

Machine Learning (ML) is a formal branch of Artificial Intelligence and Computational Learning Theory that focuses on building computer systems that can learn from data and make decisions about subsequent data. In 1950, Alan Turing first proposed the question, “Can computers think?” However, rather than teaching a computer to “think” in a general sense, the science of machine learning is about creating a system to computationally do what humans (as thinking entities) do in specific contexts. Machine Learning (ML) and big data analytics go hand-in-hand so ML focuses on prediction, based on properties learned from earlier data. This is how Infinity identifies malicious versus safe or legitimate files. Data mining focuses on the discovery of previously unknown properties of data, so those properties can be used in future ML decisions. This means Infinity learns on a continual basis, even as attacker methodologies change over time!

How it Works

Infinity collects data, trains and learns from the data, and calculates likely outcomes based on what it sees. It’s constantly getting smarter from environmental feedback and a constant stream of new data from all around the world. To achieve its magic, Infinity performs the following steps. First it COLLECTS vast amounts of data from every conceivable source. Second, Infinity EXTRACTS FEATURES that we have defined to be uniquely atomic characteristics of the file depending on its type (.exe, .dll, .com, .pdf, .java, .doc, .xls, .ppt, etc.). Third, Infinity constantly adjusts to the realtime threatscape and TRAINS the machine learning system for better decisions. Finally, for each query to Infinity, we CLASSIFY the data as good or bad.

Infinity – The Rubber Meets the Road

Infinity be used to supercharge decision making at endpoints, and woven tightly into existing security systems via a variety of integration options. It is cloud enabled (but not cloud dependent) to support advanced detection on a global scale in limited form factor environments, or can operate autonomously while still achieving a stunning rate of protection.

The breadth of deployment options helps to solve several fundamental problem points on a modern network.

CylanceV and CylanceV Local

CylanceV is a REST SSL Application Programing Interface integration to Infinity’s intelligent cyber security decision making. Through the API and specially developed utilities, IT departments executing incident response and forensics can take the tedium out of tracking down malware and determining what is truly bad.

CylanceV enables a starting point for forensic analysis and timely remediation through an automated and highly efficient approach.

Tying other security tools like SIEM, Log analysis, host and network monitoring, HIPS/NIDS and investigation tools including anti-virus, anti-malware and forensics, into CylanceV provides contextual intelligence for more accurate and effective malware identification.

The CylanceV API allows utilities to be developed in most popular frameworks (.NET, Python, etc.) and invoked through HTTPS using tools such as CURL or WGET in order to make the data segmentation easier and more efficient.

CylanceV Local is an on-premise version of CylanceV that allows for use in restricted and sensitive environments.

Integrating 3rd party functionality, like Python scripts, Splunk, C# to Infinity quickly determines what is safe and what is a threat, making smart security smarter. Together, they reduce the total number of prospective compromised machines to something manageable.

Infinity On the Endpoint

CylancePROTECT is our host based security solution built on Infinity technology. It leverages algorithmic science to greatly increase the speed and accuracy of host protection without reliance on signatures, heuristics or behavior modeling. It offers a real-time protection layer on the endpoint that can make decisions about the nature of malware independent of connecting to Infinity and at a stunningly low performance impact. PROTECT offers a powerful front line of defense, whether your assets are behind your corporate firewall or in a coffee shop. Its extensive management capabilities easily blend the pervasive protection into your existing security workflow.

Summary

With Infinity, we can definitively determine good or bad file objects milliseconds, with extraordinarily high detection accuracy and extremely low false positive rates. Because the system is self-collecting, self-training, and selflearning, we always stay ahead of the changes and unknowns attempted by the bad guys. With such a mathematical approach, we may change the game of security… forever.

About Cylance

Cylance is a global cyber security products and services company headquartered in Irvine, California. Its founders, Stuart McClure and Ryan Permeh, know that today’s network and operations infrastructure is inadequately protected by flawed security.

Stuart is a leading authority in information security and lead-author of “Hacking Exposed: Network Security Secrets and Solutions”. Stuart launched the vulnerability assessment leader Foundstone, Inc. and served as Global CTO at McAfee as well as EVP/GM of the Security Management Business Unit.

Ryan is a leading expert in development of security technologies who, with Stuart, built TRACE, McAfee’s elite threat team, and unique detection technologies. Both have witnessed the security industry’s evolution firsthand over the past 25 years and know that the security infrastructure for today and tomorrow’s threats is fundamentally broken.

Cylance is driven by an impressive team of veteran Security executives, board of directors and advisors, and deeply talented security professionals to achieve a simple mission: Solve the world’s most difficult security problems

Cylance, Inc.

+1 (877) 973-3336

sales@cylance.com

www.cylance.com

West Coast Office: 46 Discovery, #200 Irvine, CA 92618 USA

East Coast Office: 11710 Plaza America Drive, # 2000 Reston, VA 20190 USA

To learn more about Cylance visit their website at www.cylance.com



from health IT caucus http://ift.tt/1R24m2R
via IFTTT