Showing posts with label EMR. Show all posts
Showing posts with label EMR. Show all posts

Thursday, October 26, 2023

Digital Personal Data Protection Act 2023: Impact On Indian Healthcare Industry


The Digital Personal Data Protection Act, 2023 (DPDP Act) is a new law regulating personal data processing in India. It aims to protect the privacy rights of individuals and create a framework for data governance and accountability. The DPDP Act will significantly impact the Indian healthcare industry, which is still in its early stages of digital evolution. Some of the key impacts are:

  • The DPDP Act will require healthcare providers and entities to obtain explicit consent from data principals (individuals whose data is processed) before collecting, using, or sharing their personal health data, which is classified as sensitive personal data under the law

  • The DPDP Act will also mandate healthcare providers and entities to implement appropriate security measures, conduct data protection impact assessments, appoint data protection officers, and comply with the codes of practice and standards issued by the Data Protection Board of India

  • The DPDP Act will enable data principals to access, correct, erase, port, and restrict the processing of their personal health data and seek redressal for any grievances or violations of their rights

  • The DPDP Act will create new opportunities for innovation and collaboration in the healthcare industry, as it will facilitate the use of personal health data for research, public health, emergency response, and other purposes, subject to certain conditions and safeguards

Implications of Digital Personal Data Protection Act 2023 in Healthcare Sector

The Digital Personal Data Protection Act, 2023 (DPDP Act) will have various implications in the healthcare sector in India, such as:

  • It will require healthcare providers and entities to adopt privacy-conscious and data-responsible practices, such as obtaining explicit consent, implementing security measures, conducting data protection impact assessments, and appointing data protection officers

  • It will enhance patient trust and confidence in using their personal health data, which is classified as sensitive personal data under the law.

  • It will create new opportunities for innovation and collaboration in using personal health data for research, public health, emergency response, and other purposes, subject to certain conditions and safeguards

  • It will also create challenges for developing and adopting data-driven technologies, such as artificial intelligence and machine learning, which may require balancing the protection of patient privacy and the potential of these technologies.

It will interact with other existing or proposed laws and policies related to health data, such as the Ayushman Bharat Digital Mission (ABDM), which aims to create a unique health ID named ABHA and a digital health record for each person. 

Government Initiatives to Protect Patient Data

The Information Technology Act 2000 governs provisions related to Protected Health Information (PHI) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. 

Patient data, including health information, is treated as sensitive personal data or information and, under the IT Actoffers some degree of protection to the collection, disclosure, and transfer of sensitive personal data. 

Also, long before DPDP Act 2023, the Government introduced the Digital Information Security in Healthcare Act (DISHA), India’s counterpart of the Health Insurance Portability and Accountability Act (HIPAA), aimed at providing healthcare data privacy, security, confidentiality, and standardization and establishment of the National Electronic Health Authority (NeHA) and Health Information Exchanges. While this act aims to encourage the pan-India adoption of e-health standards, DISHA has not yet come into force. 

Penalties in Digital Personal Data Protection Act 2023 

Under the DPDP Act, 2023, you have the right to file a complaint with the Data Protection Board of India (DPB), which is the enforcement body established under the act, if you suspect or experience any non-compliance by a third party that collects or processes your personal data. The DPB can inquire into the complaint, direct any remedial or mitigation measures, inspect any document, summon and enforce the attendance of any person, and impose penalties for non-compliance. 

The act allows only monetary penalties for breaches or non-compliance, ranging from INR 50 crore to INR 250 crore, with a maximum penalty of INR 500 crore for significant data breaches. You can also seek compensation from the DPB for any harm caused to you due to the non-compliance by the third party. However, the act does not provide criminal liability or imprisonment for non-compliance. 

Data Principal

A key ingredient in laws in other countries is the power to impose penalties up to a particular amount as prescribed for offenses or as a percentage of total worldwide turnover, whichever is higher.

A data principal is under an obligation to not register a false or frivolous complaint with a data fiduciary or the Board, not to furnish any false particulars or suppress any material information. 

DPDP Act 2023 has introduced a penalty of up to ₹10,000/- (Rupees Ten Thousand) on the data principal for failure to comply with its proposed obligations.

The proposed DPDP Act 2023 introduces the concept of Deemed Consent’, where the data principal is deemed to have given consent for processing their personal data. 

Consensual processing of personal data may be done in case of medical emergencies involving a threat to life or an immediate threat to the health of the Data Principal. In the context of such processing, a parallel may be drawn with India’s draft Health Data Management Policy by ABDM released in April 2022, which also envisages provisions relating to the processing of Personal Data in case of medical emergencies. 

Notably, the ABDM contemplates the appointment of a nominee to provide valid consent on behalf of the Data Principal in case such Data Principal becomes seriously ill or mentally incapacitated or where the Data Principal is facing a threat to life or a severe threat to health and is unable to give valid consent. 

Unlike the DPDP Act 2023, the ABDM does not propose Deemed Consent in the absence of a nominee but instead shifts the right to give valid consent on behalf of the Data Principal to an adult member of the family of the Data Principal.

Despite the recommendation under the JPC Report, the DPDP Act 2023 has kept the 'Non-Personal Data' of the individuals, such as information collected by the Government, NGOs, and other private sector entities, outside its ambit. The usage of phrases 'as it may be considered necessary' and 'as may be prescribed' can lead to administrative ambiguities. The autonomy of the Data Protection Board, which is entrusted with overseeing the protection of individual's personal data and ensuring compliance with the provisions of the law, is not reassuring. Further, the Government and its instrumentalities can retain personal data for an indefinite period irrespective of whether the purpose for which data was processed has been fulfilled. 

Conclusion

By 2030 India is projected to be the world’s third-largest economy and will have one of the world’s largest digital personal data footprints in motion and at rest. 

The DPDP 2023 Act’s essentiality shines in our strengthening role in the global order. With the G20 Presidency and multiple Free Trade and Regional Trade Agreements in place, we must find solutions for Data Free Flow with Trust and cross-border data flows.

Saturday, July 18, 2020

Digital Healthcare – Laws & Regulations in India


Digital health is using technologies to help improve individuals' health and wellness. These technologies include both hardware and software solutions and services, including telemedicine, web-based analysis, email, mobile phones and applications, text messages, wearable devices and clinic or remote monitoring sensors. Really it's about applying digital transformation, through disruptive technologies and cultural change, to the healthcare sector. Digital health is a multi-disciplinary domain involving many stakeholders, including clinicians, researchers and scientists with a wide range of expertise in healthcare, engineering, social sciences, public health, health economics and data management.

Digital Healthcare has been around in India since long but COVID-19 pandemic has put it in the spotlight and we are noticing mass adoption as 5 crore Indians accessed healthcare online in the last three months (Practo’s Insights Report, 18 Jun3 2020). In a significant move, the Ministry of Health and Family Welfare (“MoHFW”) on March 25, 2020, has issued the Telemedicine Practice Guidelines to provide healthcare using telemedicine and that is another major reason behind surge in online consultations. Also these Guidelines are one of the best guidelines ever published and the reason that telemedicine practice will stay in India. The Guidelines have made the practice of text/audio/video based medical care legal and regulated and thus have given platforms (mobile apps, web portals & social media) as well as doctors the standards to follow.

The legal and regulatory framework in India is/will be govern by following relevant acts / bills –
  • Telemedicine Practice Guidelines by MCI & NITI Aayog, 2020
  • Personal Data Protection Bill, 2019
  • Information Technology Act, 2000 & Information Technology Rules 2011
  • Clinical Establishment Act, 2010
  • MCI Act, 1956 & MCI Regulations 2002
  • Indian Medical Council Act, 1956 and Indian Medical Council Regulations 2002
  • Drugs & Cosmetics Act, 1940 and Rules 1945
  • Other Service Providers Regulations under the New Telecom Policy 1999

In September 2013, MoHFW notified the EHR Standards (Electronic Health Record Standards) for India.  Those standards were chosen from the best available & previously used standards applicable to International EHRs, keeping in view their suitability to and applicability in India.  Accordingly the EHR Standards 2016 document is notified and is placed herewith for adoption in IT systems by healthcare institutions and providers across the country.  The MoHFW facilitated its adoption by making available standards such as the Systematized Nomenclature of Medicine Clinical Terminology (SNOMED CT) free-for-use in India, as well as appointing the interim National Release Centre to handle the clinical terminology standard that is gaining widespread acceptance among healthcare IT stakeholder communities worldwide.

In addition, the MoHFW has proposed a new bill named DISHA (Digital Information Security in Healthcare Act) to govern data security in the healthcare sector.  The purpose of this Act will be to provide for electronic health data privacy, confidentiality, security and standardization.  The MoHFW, through the proposed DISHA, plans to set up a statutory body in the form of a national digital health authority for promoting and adopting: e-health standards; enforcing privacy and security measures for electronic health data; and regulating the storage and exchange of electronic health records.

One of the most immediate changes that health tech companies may need to be prepared for is the cost of compliance – with the Personal Data Protection (PDP) Bill 2019. As of the current interpretation of the text of the PDP Bill, 2019 (which effectively can get signed into law at any time) there is no period provided to affected companies to comply with the data protection measures in the Bill. The requirement of having a privacy-by-design system in place means that for a lot of companies the cost of compliance will go up as they would have to upgrade/overhaul their data protection systems and software. This change would be akin to the one experienced by European companies when they needed to comply with the General Data Protection Regulation (GDPR), but at least, in that case, there was a period prescribed within which companies were permitted to overhaul their security systems.


If any IT company or startup into Digital Healthcare plans to offer and add telemedicine/telehealth software to already existing software like healthcare CRMs, clinical software and patient management systems, have to incorporate all the relevant Acts & guidelines. It will not only help their clients but also will help companies because as per Telemedicine Practice Guidelines, technology platforms are obligated to ensure many instructions otherwise can be blacklisted.

Monday, May 11, 2020

Digital Health: Why Digital Health will become the new normal


During COVID-19 pandemic, terms like telehealth, telemedicine, remote-patient monitoring, virtual care and digital health are thrown around very commonly, though these terms have been around for years, but the recent situation is accelerating patient awareness and physician adoption of these technologies.

With a growing need for social isolation, healthcare organizations are actively seeking ways to provide health services to patients with both COVID-19 and other conditions remotely.
Start-up investing is not a new phenomenon in the financial world, but one sector, in particular, has seen a veritable boom in investors since the beginning of the COVID-19 pandemic. While many industries plummeted in the first quarter of the year, digital health companies closed the first quarter of 2020 with unprecedented levels of funding. Private equity and venture capital financing of digital health start-ups reached an all-time high of just over $3 billion in Q1 2020

Digital health seeks to enhance administrative tools, clinical tools and patient interaction to make the healthcare experience more effective, efficient, and positive for patients. Healthcare is far behind in technology, and this industry is looking to fill that gap. Those of us who work in the digital health space want to take current healthcare experience, which is something like Blockbuster Video in the early 2000s and turn it into Netflix.

The Board of Governors in supersession of the Medical Council of India (MCI) issued Telemedicine Practice Guidelines on March 25 to strengthen delivery in a post-Covid-19 world, with a focus on Health and Wellness Centres (HWCs) that provide preventive and primary healthcare within a 5 km radius at the grassroots level.

Telemedicine is being used by doctors to connect with patients, and by mid-level provider/health workers to connect patients with doctors without patients having to physically visit a hospital or clinic. Even post lockdown, it will help reduce the burden on the secondary hospitals and improve documentation, data-collection, diagnosis and care without risking the safety of the patients or the health workers. It is already being used with success in some states for reproductive and child health and tuberculosis notification and outreach.

There is a persistent shortage of doctors, health workers and hospital beds in the country, especially in rural areas and densely populated underserved states. India has 1.1 million allopathic doctors registered with the Board of Governors/State Medical Councils in December 2019, according to the National Health Profile 2019.

India’s public health expenditure is just 1.28% of its GDP, with the per capita public health expenditure being Rs 1,657 in 2017-18. The rising cost of treatment has led to inequities in access, with people in under-served rural areas and urban slums among the worst hit. For people living in rural areas completely dependent on government hospitals and clinics, the government allopathic doctor-patient ratio is 1:10,926, shows NHP 2019 data.

For a population of 1.36 billion, this makes the doctor-population ratio 1:1,457, which is lower than the WHO recommended norm of 1:1,000. In addition to doctors, India has a little more than two million registered nurses and midwives, many of whom need infection control training to care for patients with communicable diseases, such as Covid-19 and tuberculosis. The WHO estimates there is a deficit of 6 lakh doctors and 20 lakh nurses in India. Further, doctors often have to perform many routine tasks like data entry, patient management; pharmacy interfacing, ensuring the right gear and equipment are present in the required quantities at the point-of-need, and so on—over and above their medical and caregiving duties.

Before Telemedicine Practice Guidelines, there was no legislation or guidelines on the practice of telemedicine through video, phone, and online platforms, which include the web, apps, chats, etc. The existing provisions under the MCI Act, 1956, MCI Regulations 2002, Drugs & Cosmetics Act, 1940 and Rules 1945, Clinical Establishment Act, 2010, Information Technology Act, 2000 and the Information Technology Rules 2011 primarily governed only the practice of medicine and information technology.

With such a large rural population and insufficient trained medical staff and rural healthcare facilities, India can rapidly adopt telemedicine capabilities to make up for the gap. E-consultations, which took off during the lockdown, can vastly improve access to healthcare in rural areas. Mobile and internet penetration in rural areas is accelerating, and telehealth can piggyback on this trend. A quick e-consultation can determine whether the person has a simple problem or needs to access a facility for a physical check-up. We may find that 50-60% of cases could be diagnosed in this manner, and the remaining might have to travel for a consultation—largely reducing the healthcare burden in the country.

Tuesday, December 26, 2017

Big Data in Healthcare - Hype or Reality




The Big Data Questions

Big data is generating a lot of hype in every industry including healthcare. People are looking for answers to questions like:

    When will I need big data?
    What should I do to prepare for big data?
    What’s the best way to use big data?
    What is Health Catalyst doing with big data?

It’s important to separate the reality from the hype and clearly describe the place of big data in healthcare today, along with the role it will play in the future.

Big Data in Healthcare Today



A number of use cases in healthcare are well suited for a big data solution.
Some academic- or research-focused healthcare institutions are either experimenting with big data or using it in advanced research projects.
This presentation will examine what’s being done to simplify big data and make it more accessible.

A Brief History of Big Data in Healthcare

In 2001, Doug Laney, now at Gartner, coined the term “the 3 V’s” to define big data:
  • Volume
  • Velocity
  • Variety
Other analysts argued that this is too simplistic but for this purpose let’s start here.









EMRs alone collect huge amounts of data, but according to Brent James of Intermountain Healthcare most of the data is for recreational purposes.
Our work with health systems shows that only a small fraction of the tables in an EMR database (perhaps 400 to 600 tables out of 1000s) are relevant to the current practice of medicine and its corresponding analytics use cases.

There is certainly variety in the data, but most systems collect very similar data objects with an occasional tweak to the model.
That said, new use cases that support genomics will certainly require a big data approach.



Health Systems Without Big Data

Most health systems can do plenty today without big data, including meeting most of their analytics and reporting needs.
We haven’t come close to stretching the limits of what healthcare analytics can accomplish with traditional relational databases—and using these databases effectively is a more valuable focus than worrying about big data.



Most healthcare institutions are swamped with some very pedestrian problems such as regulatory reporting and operational dashboards.
As basic needs are met and some of the initial advanced applications are in place, new use cases will arrive (e.g. wearable medical devices and sensors) driving the need for big-data-style solutions.

Barriers Exist for Using Big Data

Expertise and Security

Several challenges with big data have yet to be addressed in the current big data distributions.
Two roadblocks to the general use of big data in healthcare are the technical expertise required to use it and a lack of robust, integrated security surrounding it.



Expertise  

The value for big data in healthcare today is largely limited to research because using big data requires a very specialized skill set.
Hospital IT experts familiar with SQL programming languages and traditional relational databases aren’t prepared for the steep learning curve and other complexities surrounding big data.

Data scientists are usually Ph.D.-level thinkers with significant expertise.
These experts are hard to come by and expensive, and only research institutions usually have access to them.
Data scientists are in huge demand across industries like banking and internet powers with deep pockets.

The good news is, thanks to changes with the tooling, people with less-specialized skillsets will be able to easily work with big data in the future.
Big data is coming to embrace SQL as the lingua franca for querying. And when this happens, it will become useful in a health system setting.