Why doctors hate their computers (2018)
newyorker.com
newyorker.com
Outside of healthcare if you see something broken then you can just fix it, maybe rope in your manager.
Inside healthcare regulations you have to start a massive change control process which involves several busy people to approve it. Those people are busy and focused on getting a few priority items approved. Starting a change control process without a customer request doesn’t make you any friends.
The reasons this process exists is so that patients are never harmed by changes. But patients are also harmed by software that’s difficult to use. They’re harmed if you don’t make a change.
The regulations were designed for blood pressure monitors and insulin pumps. A patient data portal is orders of magnitude more complex. Outside of healthcare teams iterate towards a good solution. Inside healthcare teams cannot iterate, because of the regulations. This stops healthcare teams from making good software and ultimately harms patient safety.
You’re partially correct that a fair bit of health software is stagnant and fixing bugs takes time (although not years) but when discussing EMRs, especially the biggest player (Epic), they fairly regularly change the UI and I’ve had to learn a new workflow at least once a year for the last decade.
But you are right, other things are certainly left to stagnate.
Then again, in US, EHR systems (epic and cerner comes to mind) are not regulated by FDA
It's a problem of too many unfounded opinions, and too little actual engineering.
This is true. If you talk to someone in insurance, fraud is a huge problem, and doctors providing expensive treatments for the wrong conditions is also a huge problem. They are society's defense against doctors prescribing exotic $20k/month cancer medicine for allergies because they heard a rumor it was 5% better than Claritin, and sending every patient with a cough to their brother-in-law's MRI clinic. And this is true to some extent (especially about the brother-in-law's MRI clinic.)
If you talk to a doctor, they won't outright say it, but they're committing insurance fraud on the daily so they can provide basic care. If they talk to a patient about how they've been eating differently since their spouse died, or they spend ten minutes coaxing details about pain from somebody who is reluctant to talk about it, they're going to bill that time as something they're 100% sure the insurance company will pay for. So it might go down as a consultation about blood pressure. Maybe they even think there's a good chance the insurance company will pay for it, but between the insurance companies constantly changing things and the doctor not having complete confidence in their office staff to figure out the right code, they just write down something that they're sure about.
I don't know what happens if you put a doctor and someone from an insurance company in a room together. They probably have a system of polite lies to tell each other.
This is a Stark law violation and there are clear rules against it
Your manager who then proceeds to ignore the request for improvement in favor of adding telemetry, dark patterns and advertising.
“Move fast, break things” is not how healthcare infrastructure should work.
- user error
- It’s expensive so people don’t get treated in the first place
- doctors making treatment errors because they couldn’t see the whole picture because they couldn’t work the software
Also the non-regulated software is observably better and more reliable than regulated software. The author even compares regulated software to non-regulated software in the article.
Paradoxically ensuring that an error is never made reduces the probability that the system will do the right thing.
There is a high correlation against "move fast, break things" and patient death.
> Outside of healthcare if you see something broken then you can just fix it, maybe rope in your manager.
For the sorts of software stuff the OP is discussing, you can do this inside of healthcare, too. I work in healthtech; in our company, a simple change can go from idea to deployed in prod in a few hours. (And a lot of that delay is our CI system or code reviews being slow, but not regulations.)
That's not to say regulations can't slow things down: I've seen some things take longer because of them. But it's things like "are we doing security adequately?" or "we need to retain these records", etc. Things that (speaking as a patient looking in) we should be slowed down to think about or do, frankly.
> Inside healthcare regulations you have to start a massive change control process which involves several busy people to approve it.
But this isn't entirely fiction: we integrate with a number of providers, and particularly there, these processes do exist. I've been on any number of calls ranging from 10pm to 2am where we're coordinating a production change, usually mostly on the provider's side. (We try to have our own change lined up so that, if at all possible, the 2am "change" is just "enable it". It's 2am, after all — you're basically already incapacitated due to sleep.) Moreover the changes are made frustrating by there usually being a whole pile of them: if you can only make changes once per month? quarter? at midnight, then everybody's changes get smushed together. It's not good, and SWE as a larger industry has (IME) moved on from this anti-pattern, but it persists in some places.
But HIPAA doesn't require this.
I can't speak to hardware.
> A patient data portal is orders of magnitude more complex.
It's funny, because as a patient, my data "portals" still routinely fail at seemingly basic functions. I cannot see accurate billing information, I cannot see forms I've signed, I can't obtain access, AFIACT, to my own data. (All this I've encountered in the last week, too.) AFAICT, data isn't transferred in standard formats. (I tried intercepting the AJAX calls to see … but nope, proprietary junk, AFAICT.)
> Outside of healthcare teams iterate towards a good solution. Inside healthcare teams cannot iterate, because of the regulations.
We do this same iterating at my company. (Which sometimes has its own dysfunction, but it's not unique to healthcare; you can see it in any HN thread about agile.)
HIPPA is something completely different. HIPPA is much more lightweight.
Probably your company has found a niche that manages to avoid requiring compliance with medical devices regulations. This is a great idea and it lets you make very good software quickly.
However, in US, these giant EHR systems (epic, cerner etc) are not regulated by FDA.
ISO-13485 really isn't that heavy in the grand scheme of things. Once you establish your policies you can automate most of it with Jira, which can provide good traceability.
It's really the testing requirements that are the most heavy, and whether you can do that in a few hours is 100% up to how good your testing setup is.
I suspect that the quality management system is often this way at any mature tech company anyways, but who knows.
When you need to perform a 510k, that's where the heaviness comes into play, even a special 510k can be considered heavy.
For those uninitiated, here's the FDA guidance on when to perform a 510k: https://www.fda.gov/regulatory-information/search-fda-guidan...
Rewriting a core piece of your software stack in a significantly different language is one such case (JavaScript to TypeScript? Probably not. Java to C++? Most certainly yes.).
Healthcare is like government in that they had to computerize billing to interact with Medicare and Medicaid first. So some policy decision made 30 years ago by a hospital acquired a decade ago may impact operations today.
A good case study is the NASA Space Shuttle program and how expensive it was especially when compared to SpaceX. Not to downplay the sheer achievements of NASA by any means, plenty of people there are much smarter than I am.
The solution isn't just "ignore the risk", you have to do something fundamentally different (with strong conviction, investment, and leadership) in order to restore symmetry to the risk-reward profile, such as a truly best-in-class testing infrastructure. Operating your business as a meritocracy doesn't hurt either (although I suspect pure meritocracies to be impossible/unfeasible to implement).
I am old enough to remember when it wasn’t like this; I would LOVE to just be able to go in and talk to a doctor like they and I are both human beings, with shared life experiences and understanding. Hell, have an audio recording going for butt covering purposes if they need it.
Going to the pediatrician with my new daughter has been a strange breath of fresh air. They look us in the eyes and talk to my wife and I like humans. Far less time spent playing stenographer. It’s such an interesting flip.
They follow the doctor around and write out everything.
It's fairly common, maybe explore a different doctor
On a side note I wish there was a way to communicate with (good) physicians asynchronously (via text for exemple) for non trivial issues, or something that allows them the time to research and think about an issue, which you don’t have the time during a consultation, without waiting months before the next appointment. Some try to get up to knowledge and read in front of me but, it doesn’t takes them more than 1 mn so they often have a shallow understanding. I’ve also met terrible ones who where annoyed that I knew more about the subject than they did and discouraged me from doing my own research (even from cochrane and serious meta-analysis), but I guess it is more a problem of the hubris of some french doctors than a process one (accordingly most of my issues stems from the fact that it is difficult to reliability avoid ignorants, that doesn’t care, or arrogant physicians that I could book, more than any other issues including software).
Why Doctors Hate Their Computers (2018) - https://news.ycombinator.com/item?id=24336039 - Aug 2020 (317 comments)
Why doctors hate their computers - https://news.ycombinator.com/item?id=18381969 - Nov 2018 (107 comments)
Unfortunately, it didn't last long. 6 months later, my GP was excited that their office was transitioning to Epic. Told her to be careful what she wished for. Another year later and her tone had changed completely.
Epic is the Blackboard of the medical industry.
I would love to see more wide spread adoption of FOSS EHR systems, once with actual feedback and development input from doctors. I don't think it will happen. Meaningful use and interoperability have basically made it so Epic and Cerner and the other big players have an advantage due to resources for development.
I had a glimmer of hope, Ohio (where I'm from) was considering allowing a companies to bid on a contract to to host a low-cost/subsidized OpenEMR instance and letting healthcare systems use it. Sadly nothing ever came to fruition.
For all that CPRS - the old VA EMR, paid for by the federal government and thus openly available - got a lot of flak from all angles, not least of which was IT (the whole thing is written in MUMPS and the CLI underneath the GUI could be charitably described as "arcane"), it was a fairly easy EMR to "get", and once you learned how to filter things, you could at least see everything going on.
With Epic, Cerner, and the others, you don't. You have a silo'ed role. Early on in our Epic migration, I discovered that I had been misclassified by the system. I was a doctor, yes, but I had a range of options open to me that were appropriate for an ICU doctor, not an anesthesiologist - I simply couldn't do a lot of things that were my bread and butter. Finding information outside your normal specialty is difficult and requires a very precise set of clicks (which are not in any way intuitive) to get to the information you want. I stunned one of the cardiac surgeons by showing him how to get access to the OR status board (which he had, just not as simply as we do) and how to customize it to show him everything going on in every cardiovascular surgery room and in the cardiac catheterization lab. Now, when a cardiologist calls him to say "I'd like to consult you about the patient I just did a cath on, think he needs bypass surgery instead of stents", he can skip getting a medical record number and just open the chart directly from the list.
I can't read nursing notes. I've tried, and I know the information is there somewhere, but unless I've been given access to a flowsheet that shows it (and that is another obscure thing), I can't see it. Labor and delivery nurses don't have access to anesthesia records, so they can't see what medications their patient got during a C-section, and end up having to call one of us to tell them precisely what was given and when. Most surgeons don't know how to look at the anesthesia records (it's not easy) for their own cases, let alone their partners' (when covering call), so again - they have to call us to ask. I had to open up one for the head of the peer review committee to show her what had happened in the operating room after a patient death.
There are always going to be privacy concerns, but these systems all have aliasing ability, and in any case retail-level, one-by-one accessing of sensitive people's info is going to raise a lot more flags than data breaches involving millions. Not letting me see what went on before, during, and after for a patient I have to care for is far worse.
Every hospital I’ve worked at has used Epic and every one has a different “custom” version with different UI and user role configuration.
Even within the same hospital the UI and default displays widely varies based on context and role selection when logging in.
Nursing notes are definitely accessible in every version I’ve used and I also read them fairly frequently (often more useful than MD progress notes) so your hospital may be hiding non-provider notes from you. It would be strange though, are you sure you don’t have “show provider notes only” checked off (or that box hidden)?
This limitation isn't an Epic default feature and must have been set by your institution or whoever created the anesthesia role for some inexplicable reason, there wasn't actually a justification or privacy concern for why this was set this way for radiologists at my institution and seemingly was set by someone in IT thinking it was extraneous to us.
Dunno, at this point I'd settle for being able to establish custom filters for my status board. But I've learned that a lot of weirdnesses have to do with interfacing with other software.
And if a guy who has their own IT staff telling them it can't/won't happen, despite actual onsite EPIC staff saying it's entirely possible, you see why. When you tell users to go away, and tell interested users that they can't share their improvements, not even privately, you are doing a disservice and you owe me at the least an explanation of why doing it is bad. Maybe there's a good reason that I should be allowed to mess my own system up but not let anyone else enjoy it that way, but I struggle to understand why. The whole thing can be re-imaged if I screw up too badly, after all.
Are you talking about custom chart review filters? Also not sure why that's blocked, I use those a lot and we can copy them from other user profiles without going through IT. But yes to have this be a default for new users we still need IT approval which no one has bothered with.
This sounds like draconian institutional policies are the limiting factor.
Draconian institutional policies are indeed an issue. WiFi calling is blocked, despite the fact that a significant part of our first floor has zero cell signal.
If you get bored, PM me and we'll set up a time where I can show you some samples. I'll need a few days to sanitize them of identifiable info.
There's a developer sandbox as well that's more feature rich but from what you're describing I doubt they would have enabled access for you although most hospitals do. I would ask someone in IT you know to either give you a superuser role in the playground or access to vendorservices.epic.com
You can't PM on here but my e-mail is in my profile. If you're hitting a dead-end shoot me an e-mail and I can add you to my developer playground to mess around with.
Still, sad that I have to go to HN and actual tech workers in completely different places to figure out how to use a system that is nominally under control of my own hospital. I don't blame you for not giving doctors admin access; I don't need it and quite a few would make a total hash of things, but I'm a lot more curious and a nice free playground where I could do things like schedule cases would be fun. If I break it, so what? It will reset tomorrow, and I'm fine with that. If I have a play day, I'll apply my notes for everything I have done and ask the IT team to make a snapshot.
Again, thanks.
Some places are better, most institutions I've been at have given me full access because I have a tech background and had a previous relationship with Epic but occasionally I've hit similar brick walls to you.
Hope it works out.
With all those requirements, even the smallest feedback might require many hours to implement so things don't break or piss someone else off.
A couple of sources, can be viewed with google translate: https://www.cw.no/debatt-helse-it-bransjen/helseplattformen-... https://tidsskriftet.no/2023/01/helseplattformen-en-it-skand...
Why? I'm assuming corruption and lobbying by Epic.
All of these entities had working EHR systems.
https://www.dagensmedisin.no/helse-midt-norge-rhf-helseokono...
To me this system just seems destined to fail because there is no chance the public entity is able to write comprehensive requirements. Creating the bid is also a huge undertaking, and large suppliers and consulting companies will have a large edge by having experience with creating such systems and with creating bids, so they usually win. I dont know how to solve this though.
They were the only vendor capable of submitting the «objective» tender that is madated by law, and the decisionmakers are too stupid and chickenshit to consider that this process is in itself guaranteed to produce a worse outcome than alternative approaches.
The funny thing is they started this project even though there were earlier catastrophic Epic implementation examples from Denmark and Finland.
As a physician, using Epic is a pre-requisite for me to consider working at a hospital.
Yes it has flaws (ordering and encounters are still very annoying but make sense for billing purposes), but it’s also incredibly powerful and once you learn how to use it there isn’t really a better alternative (in my opinion).
If you want to cut to the chase, pull up the archive link posted in the sister comment, then search for
* Revenge of the Ancillaries
* Sadoughi
* Jessica Jacobs
What you say differs between IT environments and clients. We usually just deploy EDR/MDR like S1 or Defender (Defender that comes with Windows) and deploy settings, so you cannot have a crazy long uptime and force Windows updates, yes you need those.
According to some standard body like NIST, you are now supposed to have a longer password or passphrase that never expires.
So much room for disappointment on both sides, I sure I hope I can help bridge this someday.
However, his office moved around a lot, probably 3 times in 15 years. His practice, previously independent, was acquired by a medical group. Shortly after that acquisition, he carried a new notebook computer around, and he sincerely apologized to me, saying that he would be forced to look mostly at the computer and not at me. Do you see how important this person-to-person rapport was to both of us? He always called me "my friend" and he was an expert chess player.
I will miss him, especially this week, as I visit a PCP of the opposite sex, who is not a physician, who recently disavowed ever meeting me before, and argues about every detail of my treatment.
Ted Kaczinski wasn't wrong.
My wife doesn’t do notes in front of patients, but as a consequence she spends several hours at home after her shift finishing up notes from memory. She does it because she works in the ER and it allows her to handle more patients (she hates it when patients have to wait 3+ hours so she does everything she can to get them seen quickly). It is definitely much more work for her to do it that way though.
Even if it did work, the notes for future doctors and insurance companies have very little overlap with what you’d say to a patient.
And physical exams have a ton of manual components where a doctor is just palpating things and asking if that hurts or this hurts or feeling if a lump is freely moving, or whether someone can rotate something at a specific angle etc…
Without the doctor annotating exactly what they are doing and what the patients response was every step of the way, the LLM would be missing too much data to really be useful.
It is still relevant because the obvious answer that jumps out at me is to either (1) have a person clean up the records, or (2) have a GPT AI try to clean them up.
The programmers and IT people would tune the AI but you could almost think of it as an "expert" in the Epic-like system.
It could be great! And then you run through the possiblity space and see how AI will destroy us, because once it works great, we'd start to rely on it and there would be no going back. We wouldn't even be capable of working with the lower layers.
But their software is insane.
Doctors have a stressful job.
But my friend the ER surgeon works 24 hour shifts.
Sleep is the best healer.
But it's impossible to sleep in the hospital.
There's a terrible malfunction here.
Or Google Workspace for that matter.
Aren't they just writing notes and ordering meds?
Why is it this mess that is Epic and Oracle Cerner?
*Sure being in the downvotes
Doing this in a Google or Microsoft cloud environment is going to get messy real fast, and legal will block this for being non-compliant.
Yes very secure.
The responsibility remains with the user rather than the cloud provider to ensure compliance but they will do their part if you set things up correctly.
For starters the data generated by a single hospital EHR is something like 10-20 TB/year.
The data is stored (essentially indefinitely) in multiple databases of varying availability, formats and interfaces. It is generally on prem, with multiple failover systems as well as long term backup and a read-only failover usually in the cloud.
Somewhere in this process the data is stored in a non-clinical use data warehouse which has strict physical and digital access restrictions and detailed logs.
Backups are obviously automated. Logs cannot disclose protected health information.
IT accessing individual records would always be flagged to the CIO and CPO offices and audited.
A % of providers are randomly audited by the same offices and certain accesses automatically trigger an audit (for example if I open my own chart, or if I open the chart of a patient who has restricted access - this is audited even if I’m part of their care team and state so in the prompt that comes up when I open the chart).
Physical access by infra providers is disclosed and audited as well.
It’s actually quite secure largely because the fines for failing to do so are quite hefty for the hospital.
Standardised workflows for entering diagnoses and treatments. Automated warnings when a treatment might be inappropriate, or drugs might interact.
The problem space is enormous.
This is something that is obscure to mostly young, mostly healthy people. When you think of "going to the doctor", you think of a checkup, or a UTI, or an annual gynecologist visit, or something else that happens in a clinic. Or maybe you think about your grandmother being admitted with pneumonia. And in that case, yes, it is largely writing a note and ordering meds (and a diet, and labs, and nursing order parameters for as-needed medications). But nurses are recording vital signs, and those should be searchable under vital signs. Ideally, they should flow directly from the machines taking those vitals - in anesthesia, for instance, we record vital signs at least every five minutes if not more often, which in a hairy case with a lot going on means treating the patient or treating the computer, with the understanding that you have ten or twenty minutes of data entry to follow an hour of actually treating the patient. EVERY code situation has a nurse (an RN, not an LPN or nurses' aide) whose entire job is to sit there and record the times that events occurred so that everyone else can go back after the fact and record meds given, interventions taken, etc., accurately. It takes much less time on a piece of paper than it does on a computer, because paper anesthetic records were designed to minimize cognitive workload and computer ones were not.
As for ordering meds, all of those orders have to be checked by a pharmacist and cross-referenced to ensure that there are no unexpected interactions. That's their legal obligation; they're not going to short-circuit it. And that has to be tied into billing (even in a national health system, you need to know what to order more of), and Medication Administration Records (the MAR). And every one of those notes needs to be classified by who wrote it and what department they were from, as well as the note type, so you can filter out the ones you don't need to see for one purpose or another. Intraoperative anesthetic records and surgical operative notes are the two most relevant to me as an anesthesiologist; what happened last time, and did they run into unexpected troubles? We don't like being surprised.
Billing is more complicated in the US than in most countries, but it's part of the game too (it factors into metrics, and you can't reasonably hold a neurosurgeon doing tumors to the pace of pediatricians doing well-baby visits).
The paper medical record, for all its faults, was a highly refined system, and it's not just a matter of "make a text file containing this note".
This is the mistaken assumption. There is a _lot_ more going on. Sibling comments have given some examples but here's some more: - appointment booking and scheduling - waiting lists - referrals to other institutions (which may use a different IT system) - communications with patient (including automatic appointment reminders, bulk contacts etc) - integrations with many, many other systems - reporting - billing - complex IAM: there are many different roles in a healthcare setting all with different access requirements
Fwiw a lot of institutions _do_ use office 365, sharepoint etc but those tools just don't do enough by themselves and aren't integrated in the way that EHR software typically is.
Just think of getting some labwork done. First it needs to be ordered. Then patient must go to nurse to get blood drawn either immediately or after not eating long enough. Nurse needs to know how many samples are needed and if there is something special. Then those needs to be tracked and delivered to lab. Lab needs to know what tests to run. And then results need to be available for years.
And you probably want some sort of alerts for values outside expected ranges and in cases where they are really off. This might consist of one or multiple systems, but all those should interoperate automatically.
And that isn't even imaging or treatments.