These are real barriers faced by patient-access API developers like Fasten Health, effectively blocking patients' access to their own medical records
659 karma · joined October 3, 2012
jason @ thesparktree.com
These are real barriers faced by patient-access API developers like Fasten Health, effectively blocking patients' access to their own medical records
- [0] https://www.fastenhealth.com/ - [1] https://www.fastenhealth.com/connect/
Fasten Health's PHR[0] and MereMedical[1] are both great examples of this. The trade off is that patients need to remember & search for each of their health systems & then login to each of their individual patient portals. It can be a pretty high friction experience.
- [0] https://www.fastenhealth.com/ - [1] https://meremedical.co/
- [0] https://www.fastenhealth.com/ - [1] https://www.fastenhealth.com/connect/
I've been thinking alot about the properties of viral open-source licenses and how this could be applied to other legal documents - like privacy policies.
As it becomes possible to share our medical records with caregivers and practitioners using apps, we have to trust that these apps are managing our data and respecting our privacy as we intend. But it's not only the app developers we need to care about, its also the third party services that they use (and share our data with), and the third party services that they then use.. its turtles all the way down.
What if we could create standardized "viral" privacy policy clauses, similar to the viral nature of open-source notice & attribution clauses.. which would "follow" Personally Identifiable Information (PII) and Protected Health Information (PHI).. ensuring it's used as we intend, no matter the degrees of separation?
In my experience patient portals vary from incredibly functional to almost worthless, which was a huge problem for me given that some of my important specialists were in the latter bucket.
Honestly, everything that I've read comes to the conclusion that EHR's aren't designed for patients, nor practitioners, they're built for the accounting dept. Patient portals have been tacked on-top to comply with govt regulation & certification programs [3], but UX/usability is almost universally lacking.
Thankfully the FHIR API's that Fasten leverages seem to be fairly consistent:
- the interoperability standard (FHIR) ensures that patient medical records are (somewhat) consistent.
- EHRs APIs are tested against an automated test suite before they are "approved" - its not comprehensive, but its better than the subjective UX rules.
[1] - Marketing - https://www.fastenhealth.com/
[2] - Source Code - https://github.com/fastenhealth/fasten-onprem
I hope to eventually support it with my open source personal health record (PHR) Fasten Health. IMO this would be a "killer app" for PHRs.
The thing that most people don't realize is that the legally enforced HIPAA protections they take for granted no longer apply when they request their medical data from a healthcare institution and store it in a third party app -- like Apple Health.
The only thing protecting your medical records from being data-mined and monetized is Apple Health's privacy policy and (current) technical architecture. You've seen examples of it in the news with women's period tracking apps, but it'll become even more common as apps start leveraging APIs opened by the 21st Century Cure's Act.
I'm not a tin-foil hat wearing engineer, but I can forsee a day when Apple's reputation of being "Privacy-conscious" might not be worth as much money as the medical data they've collected from their customers.
It's one of the reasons why I decided to build my own open-source PHR, so that the incentives between the software and me as an individual are kept in alignment.
The 21st Century Cures Act was signed 8 years ago (but compliance was only required as of 2023). It states that Healthcare Institutions (& EHR developers) must provide a mechanism for patients to access their health records electronically in a standardized format (FHIR).
It's what allowed my open-source startup Fasten Health to even exist. I was diagnosed with a chronic condition, and wanted a way to store my health records privately on my own devices. A bit of luck and a POC later, I was able to confirm that patients can access their own records with little-to-no barriers.
It doesn't matter that I've had 6 different insurance companies over my career, or that I've visited more than 2 dozen different healthcare institutions, as a Patient we have the unique ability to collate and generate our own longitudinal health record.
It's what allowed my open-source startup Fasten Health to even exist. I was diagnosed with a chronic condition, and wanted a way to store my health records privately on my own devices. A bit of luck and a POC later, I was able to confirm that patients can access their own records with little-to-no barriers.
It allows patients to pull their complete medical history from their various healthcare institutions, and store it locally without having to worry about some corporation monetizing and data-mining their health record
Hopefully with the Cures Act Final Rule, interoperability will become the norm
I'm a software engineer, so I ended up creating my Personal Health Record (PHR) application, which I eventually open-sourced - https://github.com/fastenhealth/fasten-onprem
It's still a work in progress (and definitely not ready to be used as the primary source-of-truth), but I'm always looking for actionable feedback/contributors. I'd love to hear your thoughts
- Epic: https://open.epic.com/MyApps/Endpoints - Cerner: https://github.com/cerner/ignite-endpoints
It will be open sourced (eventually) -- once I've cleaned up some test credentials that were inadvertently committed to the repo.
Hope that answers your question?
However, we'll make sure to update the README to make it clearer that international providers are not supported yet.
It's designed to automatically pull your medical records from your EMR -- but users can also enter their conditions, medications and procedures manually. We have plans to allow users to manually enter their lab results [2], however that feature has not been implemented yet.
Fasten is still a work-in-progress, but if you're willing to contribute we have a pretty active discord (linked in the README).
[1]: https://github.com/fastenhealth/fasten-onprem/ [2]: https://github.com/fastenhealth/fasten-onprem/issues/137
https://github.com/fastenhealth/fasten-onprem
If you're interested, I'd love to chat.
I started working on an open-source project to electronically pull my medical information from various healthcare providers, and store it locally (no cloud involvement at all).
https://github.com/fastenhealth/fasten-onprem
It's definitely an early beta, only 1500 healthcare providers are currently supported, but I'm working on a big update to bump that up to ~10k. The UI is also a work in progress. I'd love to hear your thoughts!
https://github.com/AnalogJ/scrutiny/blob/master/docker/examp...
Doing a cursory search of Broadcom + scrutiny doesnt yield many results - other than antitrust litigation
https://www.google.com/search?client=firefox-b-1-d&q=Broadco...
Do you have a direct link to the tool bychance?
Someone posted about some issues they're running into wiht ESXI & smartctl recently -- https://github.com/AnalogJ/scrutiny/issues/388
but that wasn't scrutiny related from what I can see.
Happy to answer any questions about Scrutiny you all may have
Airalo $3 off referral link for anyone who wants to check it out - https://ref.airalo.com/nLLz
I’ve been working on a tool to automate GDPR & CCPA deletion requests to data brokers - basically it’s a database of ~650 registered data brokers + email templates written in legalese. After the user provides some basic contact information, it does a simple mail merge.
https://github.com/AnalogJ/justvanish
Still a WIP