PatientBank (YC S16) Is Creating a Unified Medical Record System
themacro.com
themacro.com
Let's find twins where one has the disease and the other doesn't and slap in the PlaidAPI to see their daily behavior to find potential drug targets. Something big coming up hopefully.
-----------------------
EMR Records Aggregation
-----------------------
HumanAPI
GetMedal
BloomAPI
UsePrime
ZweenaHealth
Doctrly
Carebox
GorillaHealth
NuskiHealth
PicnicHealth – If you’re developing an application and want to preview what records look like in here, message me. Happy to help you:
-----------------
HIPAA Compliance
-----------------
There’s a host of SDKs that revolve around spinning up HIPAA compliant applications. They’re each worth looking at.
Aptible
Catalyze
TrueVault
ClearData
Google & Amazon HIPAA Capabilities/Offerings to Developers There’s even large Fortune 500’s playing in the space of making HIPAA compliant backends more viable for the early stage innovator.
Google’s HIPAA Offering
Amazon’s HIPAA Offering
A lot of folks in silicon valley percieve that the FDA is holding back leviathan innovation for drugs. Just not the case.
How is it possible that the technologies that most people think are important for drug discovery have become hundreds, thousands, or billions of times cheaper, while the cost of R&D, per drug discovered, increased roughly 100 fold between 1950 and 2010.
Even with all those great advances. Eroom's law is still a pervasive thing. The proof is in the pudding and suggests that brute-force techniques don't relate to ROI.
Patent System as is. We have a patent system that encourages developing drugs that interact with a small number of enzymes and molecules that we already know and understand how they operate. Low if not zero risk.
It turns out that predicting a protein's structure from it's amino acid chain sequence is really tough.
I think it's stupid to patent pathways, treatment methodologies, research tools, and assays. This is a paralyzing bottleneck for the industry.
But anyways, yeah, I'm excited to see what comes out of the NIH and things like this ontology tool.
Is there anyone trying to compete with the giants in healthcare to make sure there is clean data to pull from in the first place?
I spend day and night manually reading CCD/CCDA's making sure they match the loose specifications that HL7 provides, but there seems to be so many disconnects between one vendor and another.
I am curious if your digitization of data is mostly pulling from these CCD documents themselves or actually performing OCR on physical data. Yes, there are also DICOM/PDF/etc that can act as attachments as well.
I saw in one of the comments you mentioned about integrating with hospital systems, I am curious to how that might correlate to what access you guys do have and to which patients as well. I am assuming you can piggy back on levels of consent and confidentiality that EMR's already have logic for.
Anyway good luck, if you guys are ever looking for remote (US-CA) let me know.
We are. :)
I empathize with your problem with CCD/HL7v2 as much as you can imagine; which is why we support FHIR infrastructure across a number of use-cases. Feel free to reach out, I always enjoy chatting with people experienced in the space.
In the future, we'll use whatever APIs we can to get records from hospitals. There's a lot of promising work going on in this space, and we're excited to see where the industry leads!
We also have a restful API that has a lot more traction with startups (honestly because it makes more sense). There is still so much legacy thinking around "documents" that we are more often trying to step back and think "is there a better paradigm we should be pushing here?".
As I wrote in a couple other questions, patients' privacy and their data security are our top priority at PatientBank. What that means is, in any product or business decision, patient satisfaction, happiness and their trust in our service are top things we consider.
So, we would not share patient data with any third party without patients' explicit consent!
Hope this clarifies things!
Is it really your top priority? Things like that always sound so disingenuous to me. Surely your top priority is building a profitable business, no? Otherwise there would be no data to even worry about.
When the response to the yes/no question of "Are you going to sell my data?" is "Your privacy is our top priority" instead of "No", run far far away.
House's rule number one, patients can't be trusted. You wouldn't believe how often patients give the hospital contradictory information to what they gave me, and on the most "innocuous things", past medical history, allergies, and so forth.
So it can be as simple as 'trust but verify', or 'clean slate'.
Many specialist doctors need to see previous medical records before evaluating and treating the patient. This is especially true in oncology. We work with the Smilow Cancer Hospital, part of the Yale-New Haven Hospital, to help ensure that all oncology patients present for their first visit with a complete medical record.
One final note that is my assessment of how physicians operate in the current system - doctors are accustom to working with incomplete information. PatientBank is striving to make previous medical information more accessible to your next doctor. My hope here is that increased access to information will cause doctors to pay more attention to your data and lead to better care.
Thanks for your question! I hope this clarifies things.
This also removes the need for a giant centralized database which would be a nice ripe target.
Junkies can go from doctor to doctor getting the same script and then deleting the record.
I was thinking more along the lines of a credstick or leveraging blockchain like tech where a prescription would be signed. So data is still held local in some sort of secure enclave but something that requires both a doctor and patient to sign...
If all your providers are in that RHIO, there will most likely be a central hub/repo where everyone posts their information to. There are a few localized initiatives in specific states, and there are larger statewide programs that try to consolidate all your records.
After all of that, some state funded RHIO's will get incentives for working with specific partners and even the Social Security Administration (SSA), which brings up a whole lot of headaches and having to meet their standards while at the same time meet all your local partners' standards as well.
Because the government has a high interest in ultimately getting everyone on one network they actual spend a lot of time and effort to try and better these connections and improve data transfer. One of those is this Blue Button initiative [1]. They even have multiple github repos [2] so you can see the underling logic of what a patient model comprises of. What they use is per the HL7 spec that was established in 2011/2013. (Every vendor references the same PDF spec. but there is still a lot of ambiguity in it. Essentially it is really hard to apply all the conditional logic of a clinical document into an XSD.) The funny thing is that with a stamped-and-sealed specification that people still fight over on calls, the HL7 organization are now pushing over to FHIR [3], a JSON based clinical item model. That will be interesting.
To answer your question/concern, there are definitely initiatives to try and make this better, but it will take time to get legacy systems up-to-speed and to meet new standards that are stagnated. You can reference my previous comment with my concerns about that [4].
Lastly, if anyone is new to the EMR/HIE/Medical field, Motorcycle Guy [5] will be your best friend.
[1] https://www.healthit.gov/patients-families/blue-button/about.... [2] https://github.com/blue-button [3] https://www.hl7.org/fhir/ [4] https://news.ycombinator.com/item?id=12264411 [5] http://motorcycleguy.blogspot.com/
But as you allude to, having a summary of pertinent medical information, compiled from patient records located in various hospitals, would be enormously valuable for a doctor seeing a new patient. For example, your emergency room doctor having a one page summary of your medical information to be reviewed quickly in an emergency.
It turned my 15 hour workday into an 18 hour workday, but I could not have slept without knowing the answer to this question because of the degree of impact it had on this patient.
That said, mostly these customers are interested in the US or Europe (for cancer and other serious operations) or Southeast Asia for lesser stuff. China is a HUGE and WEALTHY market just waiting for a decent player in this space. However, I am now focusing on another business (http://8-food.com/) and the focus of the business has shifted so that the average client has their medical records to be re-generated by foreign medical service providers. This is not ideal in some situations, such as remote second diagnosis (which I believe will grow steadily in popularity). If you would like a local partner for digitizing available records in China so that wealthy Chinese can access foreign medical service providers (high resolution film scanning, medical records translation, etc.), you could do worse than talking to us. Email in profile.
That said, I would definitely trust a private entity with specialized knowledge over the government or individual doctors offices, so I wish you the best of luck.
For example, I just had my medical records sent from an old doctor's office, and the only thing they required was a fax with my signature on it and an address to send the records to. Could have been sent by anybody to anywhere, and there were no checks whatsoever.
My employer used a service called NoMoreClipBoard. They enrolled everyone enrolled in a health plan, not just those who requested it.
When the inevitable data breach happened, everyone was affected not just those who had specifically enrolled for this service.
I don't ever want my medical records in any internet-facing system. I realize that's a fantasy but I'd never voluntarily help make that happen.
FTA: We use another YC company called Aptible. They’re experts in securing protected health information, and we follow best practices to make sure our servers are safe.
It's not just the security of the servers. Many data breaches are the result of careless handling of data (USB flash drives, laptops, email attachments) and social engineering attacks.
But, at PatientBank, security and privacy of our patients are our top priorities. So, we go above and beyond what HIPAA recommends in terms of security best practices. You can read more about that here: https://www.patientbank.us/legal/hipaa
The protection needs to be automatic. Training people is a "good intentions" solution, and will always result in failures. It should be mechanically impossible for the data to escape in a way you do not approve of.
And it's not like it expires. You can change your credit card number, you can change all your leaked passwords, but you can't change your past. Once it's breached it's out there until the end of tech.
This! I would pay even a premium for non-digitalization.
If you search for my previous comments in this thread, you can see my concerns about the general state of IHE's.
In one of the comments I mentioned about Blue Button, which allows patient's to pull their data. (To be fair, I haven't really seen the button in too many places out in the wild).
I guess ultimately in order to be able to get your charts from where ever you move, all those smaller IHE's need to feed into one repository and then have those scale up from county to county and even statewide.
The problem with that of course is how all the partner systems are queried or what profiles that have decided to use. i.e. will a data source being pushing documents to the repository every time there is a new patient or update, or will that network go out and ping every data source for their most up-to-date record.
If PatientBank is just dealing with Fax primarily and working with FHIR, I am curious how long they will work with Fax until there is a high adoption rate of FHIR for them to be able to get properly clinical items, that one of their clients could then pull their data and then push their data to their new provider.
With XCPD there's no real need for one central repository. Independent systems can interoperate on a peer-to-peer basis. In the USA a central patient chart repository would be a non-starter anyway for political and business competition reasons.
1) If the electronic signature on a given request doesn't match the name of the patient, we make sure that the patients are who they say they are before moving on with gathering the medical records.
2) If one tries to sign up on behalf of another patient, we require a Power of Attorney (POA) document!
Hope this answers your question!
2) How do you know they're trying to do that if they don't tell you? Your scenario looks like a regular situation, not an attack..
I'm assuming there's something I missed there.
This Safe Harbor Framework?: https://techcrunch.com/2015/10/06/europes-top-court-strikes-...
What we've optimized for is simplicity—while our process for getting medical records from hospital A may var from our process with hospital B, we abstract all of that away and make the ordering process the same for all U.S. hospitals.
We can certainly work on making that clearer up front though—thanks for the feedback!
There seems to be a couple options!
1) Once we gather your records, we will work on creating a shareable summary of your health history. In that case, the physician can look at that summary via our web portal.
2) In many cases, most EHRs support the upload of PDFs. So, the documents you share can be "integrated" to hospital's EHR. This already happens in large hospital networks when hospitals gather medical records on behalf of patients before their appointments! When hospitals receive the records via fax or mail, they scan the pages to the EHR. Obviously, in the future, easier ways to export data (via EHR integrations) could be extremely valuable to patients and physicians!
For example, Palo Alto Medical Foundation has hospitals spread across the Bay Area. Some of the hospitals don't offer all the services but if you walk into a new branch for a specialized treatment, your new doctor will simply look up your old record or order it internally if they are not yet on the network.
With that said, there are a number of startups that have struggled with similar ideas. How are you different from, say, PicnicHealth?
Haven't looked at that many immutable databases, but they seem interesting. Most of the time medical data does not require many writes (rarely are two doctors editing your record simultaneously), but the audit trail that datomic provides could be very useful as a built-in feature.
We make it super easy for patients to gather their medical information and make it even easier to manage (share with physicians, family members etc.) their information.