How to Tamper With EHR

Horst Herb of the GNUmed project has written an essay on tampering with Electronic Health Records (EHR) and how vendors can claim they are secure when they are not: ‘…I will now demonstrate one by one how…naive countermeasures can be circumvented. Most software vendors are of course using a combination of…measures in the naive attempt to make it more difficult to “hack”. All they achieve is wasting a little more of a “hackers” time…’ Comments are welcome.

Guatemala: Final Day 5

Here is the final installment of Linux in a Guatemalan hospital. You can read the entire account here. I’ve been home from Antigua just a few hours and have my faithful Chihuahua Cindy asleep in my lap. I sit in a cluttered spare bedroom that I call LinuxMedNews World Headquarters because of the hilarity of just this one little news site with no budget attempting to shape events of something so large as medicine. I think back to the events of the last two days at Hermano Pedro hospital, beginning with Sunday morning.

I braced myself for Sunday’s surgery triage at Hermano Pedro which I remembered to be a frenetic chaos with approximately 100 people arriving to get scheduled for an operation. Today was no different. I spotted several children with cleft lips in the crowd and various other ailments before pushing through to the triage area. The triage area now held the resurrected computer Mateo and the good soldier Lucas.

Two of the newly arrived volunteers where working the machines. There was a tense moment when Mateo wouldn’t accept keyboard input as the lines of people formed. Instant relief occurred when it was found that the keyboard had merely become unplugged. The day passed swiftly and we where able to finish scheduling by about 5:00pm. Faith In Practice Director Vera Wiatt noted that with the two machines working in tandem things had gone smoothly.

Finally! All the work over the last year was actually resulting in something useful. I breathed a sigh of relief and moved on to get another machine (Marco) working in the Bodega which is the spanish word for supply storage. Marco will become more important as time goes on since inventory data will be entered and submitted to Faith In Practice for the acquisition of needed supplies.
The day ended with the timelessness that is Sunday afternoon.

Walking home I passed one of the religious processions unique to Antigua that are both majestic and mysterious. The processions consist of wooden floats of lifelike biblical figures voluntarily carried on the shoulders of Antigua’s citizens. After dinner I proceeded to the convent that I was staying in and got to bed early for the first time in days.

I awoke the next day and packed my bags for the trip home. My last duties consisted of protecting the machines with voltage regulators and UPS as well as contracting with a local computer supplier, Jorge Guillermo, to trouble shoot in my absence. I finished speaking with Jorge at 9:30am, then jumped into a car for a short drive to pick up some leather boots that I had ordered 3 days before. I retrieved the beautiful just made coffee colored boots in a little town called Pastores which many nickname ‘boot town’ because of the number of boot stores there. After trying them on and finding them a good fit, I hustled back to the hospital to shoot a little videotape tour of the computer network for future volunteers that have never been to Hermano Pedro. It was now 11:00am. My flight left at 1:30pm and I still had to drive to Guatemala City. There were several hurried goodbye’s, I jumped into the tour bus to get to the airport and I was on-board the flight five minutes to takeoff time, breathing hard.

Things had gone smoothly. Last year was more difficult because we were starting with nothing. Now there was a something, no matter how broken. One casualty occurred which was the recognition that Linux on the desktop isn’t there yet or at least the acceptance of Linux on the desktop isn’t there yet. Further that it will take Linux longer than I thought to get there because of the relative lack of business applications. Just about everyone has a passing knowledge of Windows applications. For Linux to succed this means that it will have to basically clone the Windows applications and user interface.

But aside from the technical aspects, Antigua teaches many lessons because it is a city of generations. Superimposing Antiguan history onto clinical computing, one can conjecture that this is the time of the Conquistadors. The open source
computing projects that are being undertaken now will be seen as the beginning of history to future generations for we are at the start of a
very long journey towards a future medical landscape.

But free and open source medical software is like the sheer impossibility of Antigua. Antigua is a city built on an earthquake fault line, built in the shadows of volcanoes and has been abandoned as the capital city only to be re-discovered years later as a colonial treasure. It is apparent that the possibility of achieving true success by making reality widely used, good clinical computing software is low. History says it always has been. But life is always an embracing of the impossible or else it truly isn’t lived. Out of impossibility and chaos beauty can result.

Antigua endures and so shall free and open source software because it belongs to generations.

Interactive Repository of Software Reviews

After exchanging many email with Ignacio Valdes (aka The Saint of LinuxMedNews) and tinkering with
the OIO Library software over the past few weeks, I am pleased to announce the
release of OIO Library v. 1.1 which now includes an interactive “Projects” repository.
The OIO Library makes use of the OIO server‘s “plug-and-play” web-forms technology and
runs on Zope and PostgreSQL.

As open source health systems rapidly progressed over the past year, it has become
apparent that a repository of up-to-date information about these promising efforts is
essential to the accelerating growth of our community. While proprietary systems may
thrive on secrecy and mis-information, timely and accurate information is the life
blood of open source projects.

Users can now submit descriptions of new projects/software and provide reviews that
document the strengths and weaknesses of these tools. In the future, reports from
more standarized testing originating from the likes of “Test Lab” at LinuxMedNews will
complement the reviews from users.

Since this repository will be constructed from the combined efforts of the community,
the repository will of course remain publicly available/downloadable without cost. As
soon as we integrate the OIO Library into the “look-and-feel” of LinuxMedNews, for
example, the content of the OIO Library will be available to the readers of LinuxMedNews. In the
future, hopefully more sites in addition to LinuxMedNews will be interested in using
data from the OIO Library.

Come see if you agree with the posted reviews of your favorite projects! FreePM, GEHR, and OIO are the three projects currently in the repository. Also, feel
free to add other projects (that have released reviewable code) and your insightful remarks to the repository.

Return to Guatemala

Updated: 3/14/01 Read Final Day 5 below: …One casualty occurred which was the recognition that Linux on the desktop isn’t there yet. Further that it will take longer than I thought to get there because of the relative lack of business applications….’

This Wednesday I’m off to Guatemala once again friends. You may recall that in May of 2000, when LinuxMedNews was barely a month old, I went on the road to report on the installation of a Linux network at the 300 year old Hermano Pedro hospital. The hospital is located in the historic city of Antigua and serves a large population of indigenous people’s. It is affiliated with Faith In Practice an energetic group that each spring supports weekly international medical teams that perform free treatment for the poor of Guatemala. I’ll be reporting on what has happened in the last year, how things have changed and what we hope to accomplish.

NAS Report: US Healthcare Substandard

The Reuters Health and others are reporting that the Institue of Medicine (IOM) a group that advises Congress on health care issues has issued a report with a press release on the Nation’s health care system, calling it ‘sub-standard’. The report makes information technology an integral part of reform: ‘…Health care organizations are only beginning to apply technological advances. For example, patient information typically is dispersed in a collection of paper records, which often are poorly organized, illegible, and not easy to retrieve, making it nearly impossible to manage various chronic illnesses that require frequent monitoring and ongoing patient support…A nationwide effort is needed to build a technology-based information infrastructure that would lead to the elimination of most handwritten clinical data within the next 10 years, the committee said. Congress, the executive branch, leaders of health care organizations, and public and private purchasers should work together toward this goal. Without a national pledge to create and fund such a technological framework, progress to enhance quality of care will be painfully slow…

NYTimes: 3 Companies to Send Rx’s Over the Net

The NY Times (free login required) is reporting that ‘Three companies that operate
most of the nation’s managed
care drug plans agreed yesterday to
establish a joint system to make it
easier for doctors to send
prescriptions to pharmacies
electronically or over the Internet.

The three companies –
AdvancePCS, Express Scripts and
the Merck-Medco unit of Merck &
Company – said the system would
improve patient safety by reducing
mistakes and misunderstandings…

OpenEMed Site Up and Running

OpenEMed has a new main web site at http://www.openemed.org/. The site proclaims: OpenEMed is a distributed healthcare information system built around the OMG distributed object specifications and the HL7 (and other) data standards and is written in Java for platform portability. OpenEMed includes sample implementations of the Person Identification Service, Clinical Observation Access Service, Resource Access Decision, and Terminology Query Service which have been adopted as international standards by the Object Management Group (http://www.omg.org) through the OMG’s

Healthcare Taskforce
.
The system requires a CORBA 2.2 compliant ORB to run, and works with
the ORBAcus 4.0 ORB, for example.
It includes a complete JSP client implementation of a infectious disease monitoring system (RSVP) for use in an Urgent Care setting.
It also has SSL security implemented for positive identification of the user and the servers.
We are inviting others to contribute to the development of additional modules, improvements of existing modules, or additional functionality and range of application.’

Review: Cryptography Decrypted

Cryptography Decrypted by H.X. Mel and Doris Baker (ISBN 0-201-61647-5) manages to explain security issues and algorithms in depth in a way that even my 12 year old son understands everything. Simple, plain english – a
pedagogic masterpiece. It is a joy to read which is the best thing about it. Rich in illustrations, full of humor. Although I did not learn anything new regarding cryptography (after going multiple times through the draft of “Handbook of Applied Cryptography” by Menezes et al (if you ever try, bring plenty of Aspirin and Coffee)), I learned that it is possible to explain it in lay terms to lay people. Wow.

Even better: the necessary math explained in the “appendix” is fun to read! Wish I had these chapters when I was in High School suffering from math books as exciting to read as a train time table.

So, if you always wanted to know how PGP or VPN work, – go for it. Costs U$29.95 / CAN$44.95 / AU$ 50, worth every single cent. (No,I am not commercially involved in any way with it, just excited)

Python Ported to Palm

Endeavors technology has a press release that it has ported the powerful Python programming language to Palm. MbizCentral also has an article about this new development. This is big news if the Python-based Z Object Publishing Environment (ZOPE) can also be made to run on the Palm. LinuxMedNews itself and two active free and open source medical software projects: FreePM and OIO are based on ZOPE. The real question however is not whether, but how quickly will OIO’s Andrew Ho put in a few words on this article, so check the date and time stamp of his eventual reply.

Skip to toolbar