Tag: telemedicine

Revision of the Swiss Data Protection Act: Conference for HCPs

This Thursday 24 October 2019, I will have the pleasure to present the current state of the revision of the Swiss Federal Data Protection Act (DPA), as currently discussed at the Federal Parliament. I will be discussing the consequences for doctors in private practice in a conference organised by FMH Services, at the Hotel Aquatis in Lausanne.

Since the GDPR become enforceable on May 25, 2018, data protection has become a hot topic and an area concern for many sectors, particularly in the healthcare sector. The various actors, whether healthcare institutions or organizations (HCOs), hospitals, clinics or doctors (HCPs), are particularly sensitive to the changes of the legal framework given the sensitivity of the data processed on a daily basis.

The objective of this conference is to review the updates that will likely pass and be introduced by the total revision of the Swiss Data Protection Act. We will discuss the challenges that doctors will face and the recommendations they will need to receive for preparing to the changes. This will be the opportunity to discuss how the GDPR applies to physicians and HCPs, as well as best practices for the use of technologies by doctors as data controllers of health-related personal data.

The revision of the Swiss DPA aims at strengthening the rights of the individuals, in this case patients, and at aligning on the European data privacy standards. We will examine to what extent the revision fulfils this objective.

________________________________

CONSEQUENCES ON THE DAILY PRACTICE OF HCPS

Generally, the daily practice of HCPs will not change drastically with the new Swiss Data Protection Act and the guidance will remain similar for a physician’s practice to the ones already issued by the Commissioner in the past.

In my previous article on outsourcing medical billing, I mentioned what guidance the Federal Commissioner issued in the context of healthcare, which contains exhaustive recommandations, examples and cases studies on security measures at the medical office, outsourcing, guidance on the use of cloud computing and how to respond to patients exercising their access right to medical records. The Federal Commissioner also issued a guidance on how to deal with data privacy generally at the office.

This being said, the major changes for processing of medical information is relating to the use of new technologies, where the risk for medical secrecy and data protection is the highest. This is also true because a very low number of HCPs are prepared to face digital transformation and have little measures in place or best practices for the use of ICTs. This requires an increased vigilance and diligence from health professionals and physicians to avoid being held liable from a civil or a criminal perspective.

Therefore, security and the application of data privacy principles of patient data at the medical office remains essential because of the increased risks associated with the use of information systems, social media, cloud computing, telemedicine and other similar technologies. In this context, all previous recommendations of the Federal Commissioner remain valid (see below) and must be followed, as must those issued by the Code of Ethics of the Swiss Federation of Physicians.

It should be noted that risks increase with the use of telemedicine systems and unsecured means of communication, as well as in the case of outsourcing (subcontracting) of services, such as invoicing or secretarial services.

________________________________

FINES IMPOSED ON HOSPITALS AND DOCTORS UNDER THE GDPR

In Europe, we have already seen hospitals sentenced by data protection authorities to administrative penalties of several hundred thousand euros.

Since the implementation of the GDPR, most breaches have consisted of deficiencies in appropriate security measures to protect patient data. Similarly, the violation of the duty to set up controls for the rights of access to the same data in patient files has often been the cause of sanctions and breaches by health institutions.

In this respect, the following European decisions are worth mentioning:

  • Portugal: my previous article and comments on the € 400,000.- fine imposed to a Portuguese hospital. Note that in this article, I also discuss other major fines under the GDPR (equifax, Cambridge Analytica) and the very first fine (ICANN) under the GDPR, as well the situation of Swiss hospitals with regard to privacy and data protection and some elements of the current revision of the Swiss Data Protection Act;
  • Pays-Bas: € 460,000 fine imposed to Haga Hospital (Netherlands) for allowing non-authorized access to employees and third parties to the medical record of a local celebrity. The fine was imposed as a result of inapropriate security measures, especially a weak access control mechanisms (art. 32 GDPR) with no double-factor authentication, which was considered the “ABC” of security;
  • Cyprus: € 14,000 imposed to a doctor for publishing health-related information of a patient on Instagram, mentioning the name of the patient without her consent. After investigations, the Data Protection Commissioner of Cyprus also imposed a €5,000 fine to the hospital for not being able to recover the medical record of the patient following an access request.

These examples demonstrate the importance of privacy and security compliance and data protection principles. Those basic principles have to be applied in medical offices and hospitals. Also to guarantee a good control over personal data, it is crucial to apply the principle of privacy-by-design, implement a complete data protection and management program for all types of health actors.

This should include training, rules of conduct for employees and managers, access controls, as well as appropriate organizational and technical measures to avoid data breaches, unauthorized access to personal data, data losses, alteration, and other violations protection. It also remains key, even for micro enterprise and medical offices to have an action plan in the event of a data breach in order to notify the authorities or the patient if necessary. Given those challenges, a light version of an data protection officer (external) would be welcome.

Even if the legal regime of the Swiss DPA will differ from the European sanctions under the GDPR (2% – 4% of the global turnover or €10 – €20 million), these basic rules and principles are essential and must be respected in order. This is key to avoid civil or criminal liability for violation of the Data Protection Act. Also, where applicable, such behavior may infringe the Criminal Code (Art. 321) for violation of medical secrecy.

Now, the Swiss sanctions system only offers the possibility for individuals to initiate a civiel or a criminal proceedings for violation of the Federal Data Protection Act. The maximum penalties amount to CHF 10k. However, the plan with the revision is to increase the level of criminal fine up to CHF 250,000 maximum. This still remains a criminal fine, based on a criminal trial initiated by a plaintiff or a data subject, where the individual will be held liable, excepting the data controller that cannot receive any direct administrative sanction from the Swiss authority.

Find my other articles relating to healthcare:

  • Article on the outsourcing of medical data
  • Non-economic physicians and the consequences of overbilling (in French: “polypragmasie”, in German “Überarztung”)
  • Videoconference: software and medical devices regulation
  • Conference on telemedicine

Conference on telemedicine

On 4 October 2018, I was invited by Planète santé to speak at the assises de la médecine romande on the topic of telemedicine. The title of my conference was:

Telemedicine : legal framework for physicians

The Swiss health forum 2018, including the “assises de la médecine romande”, is global conference and Forum where more thatn 1’000 healthcare professionals and doctors meet and participate during a few days. This forum held a practical conference on the ‘digitalisation of the medical profession‘. I had the pleasure to speak along with Dr Jean-Gabriel Jeannot and other healthcare experts, including lawyers and physicians on digital in the context of healthcare.

Dr Jean-Gabriel Jeannot and I had the pleasure to develop thoughts and highlights challenges with this specialized audience in the context of telemedicine. For those who do not know him, Dr Jeannot is a Swiss physician specialized in internal medicine known for his digital initiatives to medical care, his numerous websites Medicalinfo, Medplus.ch, cabinetmedical.ch and his large amount of articles on his blog hosted by the local newspaper “Le Temps”. He spoke about the practical aspects of telemedicine for physicians, while I tackled the legal part of the topic. I mainly oriented my presentation for global awareness to healthcare professionals and doctors about legal issues which they may not find obvious, while offering practical recommendations.

_____________________

ISSUES RAISED BY TELEMEDICINE

Telemedicine is a wide topic.

Physicians and healthcare professionals have issued a few guidelines. Just to name a few, in the US, the American Telemedicine Association (ATA) and, in Europe, the Standing Committee of European Doctors (CPME) have created a useful documents, containing best practices for telemedicine services and remote healthcare.

Those guidelines are a first step to understand what a telemedicine project requires as a minimum. But a telemedicine project or initiative, may remain very simple (such as online or telephone medical consultations) or become extremely complex. Healthcare remains a heavily regulated environment, where laws are different in each country, with different practices and particularities, especially for cross-border projects. Moreover, there are many other aspects to take into consideration, such as from a regulatory perspective. Other issues relates to how securing contracts with third parties and partners in distant healthcare, how to tackle protection of health data and personal data under local laws, including the GDPR, as well as liability issues and how insurer can recognize distance medical services and reimburse them to  patient and pay doctors.

Structure of my conference

The main points of my talk related to three main pillars:

(1) Acts of telemedicine

The first part consisted in presenting the different acts of telemedicine that healthcare professionals my do. For each act, I have explained the typical contract that needs to be in place, highlighting the problem what issues may arise in each different scenario. A physician may provide four types or acts of telemedicine :

  • teleconsultations, which relate to the distant telephone or videoconferencing to provide a medical evaluation, including e-prescribing;
  • teleexpertise, where one physician instruct another physician that is answering remotely as an expert;
  • teleassistance, which applies in the event a doctor is unable to examine a patient on the site (emergency, distance, etc.) and a third person that is not a doctor assists the patient while communicating with the remote doctor based on his instructions; and
  • telesurveillance, which may involves remote biomonitoring of vital functions of the body, where a doctor is not present, or because there is no need for medical examination directly on the patient.

(2) Legal framework for physicians

The second part of my presentation was about the legal issues of telemedicine for doctors. It consisted in answering to a few questions, such as:

  • does telemedicine require a particular legal framework and how law applies to it?
  • who can practice telemedicine?
  • how to manage protection of health data?
  • telemedicine  and liability: how to minimize the risks?
  • how does the social insurance reimbursement work for telemedicine services?

(3) Recommendations

Finally, the last part had a main goal to provide practical guidelines and checklist for doctors and healthcare professionals, including insurance companies and innovators (start-ups and hospitals).

_____________________

TELEMEDICINE IS NOT A NEW METHOD, BUT A GROWING MARKET

A bit of history. It is not obvious to realize that the practice of medical services remotely is pretty ancient. The system of emergency medical hotline that associations of doctors have set up is a proof of it, as has been working for decades.

We can already find acts of telemedicine provided at the early 20th century.  Since the telephone invention in the late 19th, and television in early 20th century, doctors have provided medical services through different means, such as telephone (ECG and EEG), videoconferences in the context of psychiatry, virtual reality and with more modern tools after the invention of TCP/IP, etc. Four days before 9/11, the famous remote “Lindberg” surgery was a success, which demonstrated that technology could bring promising solutions remotely even to perform extremely sensitive acts of medicine.

In Switzerland, two main centers of telemedicine are in place since early 21st century, created by, and based on the model of, insurance companies such as Medgate and Medi24. These 2 providers mainly offer acts of teleconsultation (medical telephone calls). Other insurer now propose remote medical services, such the software myguide that the CSS insurance company provides to its clients.

Private initiatives, such as “heal-me” ” (“soignez-moi” in French) offer non-synchronized models (compared to synchronized). This online telemedicine platform allow patient to only pay CHF 39.- per consultation, with a assurance to receive a call from a doctor with a timeframe of 60 minutes. If the response takes longer, the medical consultation becomes free of charge, which becomes an incentive for the platform to ensure performance and availability for patients.

With respect to private clinics, the Aevis Victoria Group has massively invested telemedicine with acquisition of 40% of the share in MedGate, the Swiss leader in telemedicine. The Group also increased its participation in “LifeWatch AG” with an IPO in 2017. THis company is specialized in developing tools and devices for distant medicine. The Aevis Victoria Group continues to invest in other institutions or projects in the area.

_____________________

NOW WHAT?

Potential, but a probable slow growth. With such investments, and the potential of telemedicine, this market is likely to grow and complement ordinary medical care. One thing is sure, telemedicine will never replace ordinary physical examinations on patients. But it appears that physicians remain careful with distant medicine, probably for liability matters, or not knowing that most remote medical acts can be reimbursed by social insurances, by not using electronic communications, such as e-mail or text messages, or simply because they do not have the time or the need to change the way the provide healthcare to patient.

There are many ongoing initiatives, but as we saw, regulatory, legal, political barriers and reluctance from doctors. So this market remains full of potential, but is likely to grow slowly before becoming more in the daily practice and complement traditional care.

Some elements to consider. Patients use more electronic communication means. They have few time to go and visit the doctor. Nowadays, it is common that both parents work and struggle to organize to find medical appointments either for themselves or for their kids. They also prefer not to go to the doctor unless it becomes urgent. Sometimes, they even perform medical care on themselves. Now patients change their doctor more easily, or even have not a general physician: therefore telemedicine has all potential to match with a true market.

Now the players arriving with new ideas on the market will have to demonstrate that it is worth it from an economical and quality standpoint, while being able to reduce the costs of healthcare.

But maybe, digital medical office are not so far to come on the market…

To know more:

___________________________________________

You are launching a project in the context of digital health or distant healthcare? If you have questions or want to meet, go and check out our platform and schedule a meeting with us on datalex.

___________________________________________