Or Google Workspace for that matter.
Aren't they just writing notes and ordering meds?
Why is it this mess that is Epic and Oracle Cerner?
*Sure being in the downvotes
Or Google Workspace for that matter.
Aren't they just writing notes and ordering meds?
Why is it this mess that is Epic and Oracle Cerner?
*Sure being in the downvotes
Doing this in a Google or Microsoft cloud environment is going to get messy real fast, and legal will block this for being non-compliant.
Yes very secure.
The responsibility remains with the user rather than the cloud provider to ensure compliance but they will do their part if you set things up correctly.
For starters the data generated by a single hospital EHR is something like 10-20 TB/year.
The data is stored (essentially indefinitely) in multiple databases of varying availability, formats and interfaces. It is generally on prem, with multiple failover systems as well as long term backup and a read-only failover usually in the cloud.
Somewhere in this process the data is stored in a non-clinical use data warehouse which has strict physical and digital access restrictions and detailed logs.
Backups are obviously automated. Logs cannot disclose protected health information.
IT accessing individual records would always be flagged to the CIO and CPO offices and audited.
A % of providers are randomly audited by the same offices and certain accesses automatically trigger an audit (for example if I open my own chart, or if I open the chart of a patient who has restricted access - this is audited even if I’m part of their care team and state so in the prompt that comes up when I open the chart).
Physical access by infra providers is disclosed and audited as well.
It’s actually quite secure largely because the fines for failing to do so are quite hefty for the hospital.
This is the mistaken assumption. There is a _lot_ more going on. Sibling comments have given some examples but here's some more: - appointment booking and scheduling - waiting lists - referrals to other institutions (which may use a different IT system) - communications with patient (including automatic appointment reminders, bulk contacts etc) - integrations with many, many other systems - reporting - billing - complex IAM: there are many different roles in a healthcare setting all with different access requirements
Fwiw a lot of institutions _do_ use office 365, sharepoint etc but those tools just don't do enough by themselves and aren't integrated in the way that EHR software typically is.
Standardised workflows for entering diagnoses and treatments. Automated warnings when a treatment might be inappropriate, or drugs might interact.
The problem space is enormous.
This is something that is obscure to mostly young, mostly healthy people. When you think of "going to the doctor", you think of a checkup, or a UTI, or an annual gynecologist visit, or something else that happens in a clinic. Or maybe you think about your grandmother being admitted with pneumonia. And in that case, yes, it is largely writing a note and ordering meds (and a diet, and labs, and nursing order parameters for as-needed medications). But nurses are recording vital signs, and those should be searchable under vital signs. Ideally, they should flow directly from the machines taking those vitals - in anesthesia, for instance, we record vital signs at least every five minutes if not more often, which in a hairy case with a lot going on means treating the patient or treating the computer, with the understanding that you have ten or twenty minutes of data entry to follow an hour of actually treating the patient. EVERY code situation has a nurse (an RN, not an LPN or nurses' aide) whose entire job is to sit there and record the times that events occurred so that everyone else can go back after the fact and record meds given, interventions taken, etc., accurately. It takes much less time on a piece of paper than it does on a computer, because paper anesthetic records were designed to minimize cognitive workload and computer ones were not.
As for ordering meds, all of those orders have to be checked by a pharmacist and cross-referenced to ensure that there are no unexpected interactions. That's their legal obligation; they're not going to short-circuit it. And that has to be tied into billing (even in a national health system, you need to know what to order more of), and Medication Administration Records (the MAR). And every one of those notes needs to be classified by who wrote it and what department they were from, as well as the note type, so you can filter out the ones you don't need to see for one purpose or another. Intraoperative anesthetic records and surgical operative notes are the two most relevant to me as an anesthesiologist; what happened last time, and did they run into unexpected troubles? We don't like being surprised.
Billing is more complicated in the US than in most countries, but it's part of the game too (it factors into metrics, and you can't reasonably hold a neurosurgeon doing tumors to the pace of pediatricians doing well-baby visits).
The paper medical record, for all its faults, was a highly refined system, and it's not just a matter of "make a text file containing this note".
Just think of getting some labwork done. First it needs to be ordered. Then patient must go to nurse to get blood drawn either immediately or after not eating long enough. Nurse needs to know how many samples are needed and if there is something special. Then those needs to be tracked and delivered to lab. Lab needs to know what tests to run. And then results need to be available for years.
And you probably want some sort of alerts for values outside expected ranges and in cases where they are really off. This might consist of one or multiple systems, but all those should interoperate automatically.
And that isn't even imaging or treatments.