Showing posts with label Hospital. Show all posts
Showing posts with label Hospital. Show all posts

Saturday, July 4, 2009

JCAHO Accreditation SealHOW THOUGHTLESS DECISION-MAKING & SLOPPY HOUSEKEEPING NEARLY HIJACKED A HOSPITAL’S JCAHO

In 2005, twenty servers running a critical application at the busiest hospital in Illinois were consolidated into one physical server. Instead of reaping the benefits of consolidation, disaster struck. (Its name will go unmentioned but you’ll find it out if you read on.)

Hospital management anticipated the usual benefits that virtualization brings:
  1. Easier administration. Caring for one server is easier than caring for 20.
  2. Greater confidence in the IT infrastructure. The storage that accompanies virtualization is likely to be more reliable than the distributed storage of standalone servers. This reliability is a product of newer technology and a more efficient design.
  3. Peace of mind. Virtualized storage complements or fits well with its business continuity features. VMware’s VMotion, for instance, empowers the human administrator to migrate virtual machines to backup servers in real time.
Unfortunately these benefits did not happen. They lost data and, for a time, they risked, first, losing JCAHO accreditation and, second, punitive action from CMS.

(Click here to learn why JCAHO accreditation is important to a hospital.)

How did this happen?

After the virtual environment was created, the IT staff added standard security controls to each new virtual server. This was fine as this is standard procedure. However, some of those virtual servers lay dormant. In fact, it appears that nearly a dozen servers were created for “testing” purposes. These were not removed after they had served their purpose. (I actually think that most of them were created for the novelty of it. How do you account for servers named “Tyrone” or “Michael Jordan?”) During the months that these servers lay dormant, Microsoft and the application vendor had issued patches. When these dormant servers were reactivated, they were not updated with those patches. The servers thus turned into potholes or, worse, security vulnerabilities waiting to be compromised. It didn’t take long for that to happen. Consequently, the hospital lost data.

We were brought in to sort out the mess.

LESSONS LEARNED

What did we take away from this incident?

First, virtual servers must be managed individually and managed from their creation to their removal.

Second, management of these servers consists of staying abreast of patches, installing them as needed and meticulously documenting the patches that were installed. These steps have to be done for the virtual environment, the guest operating system and the application. These steps are crucial especially because of staff turnover.

Finally, management of the virtualized data center should be handled by capable hands. The integrator may have configured the virtual environment properly when it was created. However, we all know that things change over time. Someone has to take ownership of staying abreast of these changes. In the hospital’s situation, the virtual environment unraveled in steps. Visualize these: (1) a new appliance was installed, (2) a new server was created, (3) a new application was implemented, and (4) Microsoft issued more security patches. All of these events most likely took place. Consequently, failing to update the relevant pieces or updating the pieces incorrectly would have caused problems. Note that there are two hurdles: (1) identify the pieces that need to be updated and (2) do the updates correctly. At the end, we discovered two network links that were dead ends. We think these links had prevented two or more virtual servers from communicating.

While that was a technical AHA!, the bigger picture shows the consequences of a thoughtless decision. The hospital had stopped paying maintenance fees to the integrator. It attempted to maintain the environment on its own. This was unwise since the IT staff did not have trained personnel. The VLAN’s configuration developed potholes and compromised security. This is how a combination of thoughtless decision-making and sloppy housekeeping nearly hijacked a hospital’s JCAHO accreditation and risked punitive action from CMS. (This was a major reason. During that period, the hospital was cited for numerous violations.)



Sphere: Related Content

Tuesday, January 27, 2009


CITY HOSPITAL No. 17
The paradox of US healthcare & photos of a community hospital in post-Soviet Ukraine

There’s a paradox that illustrates why the healthcare system in the US needs to be reformed.

You may or may not know that the US spends more for healthcare than any other country in the world. That's significant. But it can be like visualizing a trillion; how large is that number?

How do we make that fact meaningful?

Well can we agree that a relationship exists between the amount spent on healthcare and life expectancy? In other words, can we expect that spending more for health and medical care will prolong the average life expectancy? If we agree, then we should expect that, up to a certain limit, more money spent on healthcare should prolong life expectancy.

Let’s see if the facts support that hypothesis. Compare the following countries. The data came from the World Health Organization (WHO). This is the agency of the United Nations whose mission is to “provide leadership on global health matters, shape the health research agenda, set norms and standards, articulate evidence-based policy options, provide technical support to countries and monitor and assess health trends.” I used the latest figures (2001 and 2002) available on their website [1].

United States
Per-capita expenditure = $4,887
Life expectancy, Male = 75 years old
Life expectancy, Female = 80 years old

Switzerland
Per-capita expenditure = $3,322
Life expectancy, Male = 78 years old
Life expectancy, Female = 83 years old

Cuba
Per-capita expenditure = $229
Life expectancy = 75 years old
Life expectancy, Female = 79 years old

Ukraine
Per-capita expenditure = $176
Life expectancy = 62 years old
Life expectancy, Female = 73 years old


Let’s take a moment to review these numbers.

The US spent nearly $4,900 per person in 2001 for healthcare. Switzerland, the next big-spender, spent $3,300. Yet the average life expectancy of an American man (75) is less than his Swiss counterpart. The same holds true for American women (80) and her Swiss counterpart (83). It appears that the additional $1,600 did not prolong American lives.

Incidentally, that per-capita figure, $4,900 (per individual in 2001) represents the total expenditure on healthcare by both the government and private sector (i.e., companies and individuals).

Let’s take Cuba now. Cuba was chosen for comparison and contrast. For comparison, note that its men live as long as American men. Its women live only one year less than American women. And for contrast, note how little was spent by Cubans for healthcare? Only $229! That’s $4,700 less than Americans spent and the life expectancy for both countries is very similar!

Now let’s move to Ukraine.

Ukraine spent only $176 per head and that’s less than Cuba. Its men have a life expectancy of only 62 years and its women, 73 years. Ahhh… Now we see a correlation. Less money spent shortens life expectancy.

The facts above support the notion that extra expenditure on healthcare does not extend life expectancy. So why is the US spending so much and what can be done to reform the system?

The solution is complicated and I’d like to cover that in another blog entry but for now, let me show you a typical Ukrainian community hospital.

These photos show the facade of City Hospital No. 17 in Dnipropetrovsk.

Dnipro (“Dnepro” in Russian) is the third largest city in the Ukraine. It has a number of interesting secrets. For example, the first artificial satellite, Sputnik, was developed in this city [2]. In fact, the manufacturing facility that actually developed it, Yuzhmash, became the heart of the Soviet space and missile programs [3].

Yuzhmash owns an Olympic-standard swimming pool complex beside it. Before you’re allowed to swim in it, you have to get a medical note that declares that you don’t have any skin-related diseases [4]. And you can get one at Hospital No. 17.

REFERENCES:

[1] Per capita total expenditure on health at international dollar rate & Life expectancy at birth. Retrieved January 24, 2009 from the WHO website at http://www.who.int/whr/2004/annex/country/.

[2] Sputnik, the world’s first artificial satellite. Retrieved January 21, 2009 from the NASA website at http://history.nasa.gov/sputnik/.

[3] The product line (!) of the State Enterprise called “Production Association Southern Machine-Building Plant named after A. M. Makarov.” Retrieved from the Yuzhmash website at http://www.yuzhmash.com/index_en.htm. Also Wikipedia’s entry notes that:
The company has been the key missile producer for Soviet ICBM and space exploration programs. Yuzhmash launch systems included:
• the R-5M - the Soviet Union's first nuclear armed missile
• the R-12 Dvina theatre ballistic missile
• the R-14 Chusovaya theatre ballistic missile
• the R-16 - the first Soviet ICBM
• the R-36 ICBM (converted to Dnepr rocket)


[4] The medical note is called a "spravka." Refer to this entry from a Christian medical missionary's blog.



Sphere: Related Content

Wednesday, November 26, 2008

HOSPITAL ERP

Enterprise Resource Planning software like SAP's unifies traditional management functions within a coherent, integrated system. ERP software enables everyone in the company, for instance, to view a status report on operations at any given time. (And of course, the view depends upon the authorization of the viewer.) The report can present an overview and also dig in for more detail. When you visit the industry solutions page of SAP however you will see that there is none for the healthcare industry. Hospitals exemplify organizations that need specialized ERP. In the healthcare industry, the big ERP players are companies like Siemens and Hitachi. Presented below is a story about the way that Hitachi changed the information flow in one of the largest ER (emergency room) in the US.




Sphere: Related Content

Sunday, September 28, 2008

LESSONS FROM CONDUCTING A SECURITY GAP ANALYSIS

There are many reasons for ensuring that you have a secure information system. It becomes a question of how instead of why. How do you create and maintain a secure system?

I participated in my first security gap analysis project in 2006, blogged it that year, lost that blog, and found my notes again. It was an eye-opening experience especially since it was conducted in one of the largest hospitals—whether public or private—in the country. It serves the second most populous county in the U.S. According to 2006 US Census Bureau estimates, the county had 5.3 million residents—larger than the populations of 29 individual U.S. states or the combined populations of the six smallest US states.

There are many reasons for ensuring that you have a secure information system. It becomes a question of how instead of why. How do you create and maintain a secure system? Starting with what you have, the first step is to create a baseline—a model of your expectations about the security of your information system. If your business belongs to one of several industries that are governed by laws and regulations then you should start with the security requirements of those same laws and regulations.

A hospital, for instance, would be directly governed by the Health Insurance Portability & Accountability Act (HIPAA). It is also subject to other regulations like the eDiscovery rules but we will keep it simple by focusing on HIPAA alone.

The second step is to categorize the sensitivity of your data, identify its source, its location within the system, how its accessed, and who can access it.

Sensitive data can take the form of intellectual property. For a hospital, sensitive data is frequently legally protected. An example is the X-ray images of a patient.

Armed with this information, you can begin your gap analysis. Before this discussion goes further, it must be understood that gap analysis is an ongoing process. The environment is constantly changing. Your information system is constantly changing with it and, naturally, your security gaps are changing as well.

Comparing your actual practices with security requirements will identify the gaps in your system. Once identified, the gaps can be prioritized (by severity, for instance). Then a plan can be created for eliminating (or at least minimizing) those vulnerabilities.

Gap analysis is a specialized form of risk analysis. Risk analysis recognizes the fact that risks are everywhere and that you have limited resources to deal with them. The goal of risk analysis, therefore, is to learn how to deploy your resources in the most effective manner to eliminate or minimize the worst or most likely threats.

It is best to approach gap analysis as a project and like any project, senior management must support it. Security gap analysis must be conducted on a regular basis. It must be thorough and objective. The degree of thoroughness will establish the scope of the analysis. Will the project include physical as well as electronic security? Will it be limited to customer-facing applications?


Objectivity requires a fresh set of eyes. It wouldn’t make sense for an accountant to audit himself. It makes a lot of sense therefore to hire an outside firm to lead the project.

These are the lessons I learned when we conducted a security gap analysis at one of the largest hospitals—whether public or private—in the country.

Our presence was announced with a bang! When you stage a systems break-in, attack the system like a team of hackers would. A team attack is just as likely to happen in real life as a solitary attempt would. The ease and speed of our break-in convinced the hospital’s administration of the risks it faced.

Your project team should have members from different disciplines. I came away convinced that if the core team could only have two groups then the two should be your IT and your HR departments. Why HR? It’s because people will be the primary source of vulnerabilities.

Hospitals are very politicized organizations. In addition to having senior management’s blessing, we created a RACI matrix that was jointly accepted by all department heads.

RACI stands for Responsible-Accountable-Consulted-Informed. A RACI matrix will identify the authority and responsibility of all roles involved in the project. We had determined that our scope was going to be limited to electronic security and to customer-facing applications only. Due to the size of the hospital and the number of applications it ran, our gap analysis focused on the two most heavily implemented applications: lab and accounting.

This was the first gap analysis conducted on this hospital and the spotlight was on it. (And did it ever need it!)

WE ANALYZED THE GAP IN FIVE AREAS

FIRST AREA

AAA – Authorization, Access, and Accounting on an enterprise level. This included single sign-on, a primary aspect of federated identity. Our goal was to standardize the security infrastructure. We discovered numerous instances where Nurse-A could log in at Station-1, stay logged in while logging in again as herself at Station-2, and be granted a different access level.

All current authentication processes were reviewed. Possible vendor solutions were evaluated. A general implementation plan was developed.

SECOND AREA

Awareness. How security-conscious are the employees? Did they know about the different security levels of information?
  1. Unclassified
  2. Classified
  3. Confidential
  4. Restricted
  5. Secret
  6. Top Secret
Our goal was to heighten the security awareness of workers throughout the organization. Make it clear that this is everyone’s responsibility and request for their cooperation. A regular familiarization course was developed and all employees have to attend it every six months. A hotline was also established.

THIRD AREA

Incident Notification & Response. The security awareness course and the hotline are just two of the responsibilities of a new IT-based group. Our goal was to create a first-response team and proactive overseer of enterprise security. They did not make policy; instead they implemented it. At the same time, they tracked actual user practices, compared it to best practices, and submitted progress reports to the Chief Security Officer (a position that was newly created).

FOURTH AREA

Technical Security. We conducted a comprehensive review of the existing security framework. The framework covered firewalls, DMZs, intrusion detection & prevention tools, and the like. Security logs were audited. Patch management was taken seriously. Password policies were enacted. Our goal was to optimize the hospital’s technical security. These efforts were primarily focused at the hospital’s data center. Technical security briefly touched on Disaster Recovery but DR was going to be a separate project.

FIFTH AREA

Best Practices. Our objective was to train users to work using best practices. This was easier said than done since this was change management and most of the staff were lifers, i.e., employees of long tenure. We had to start over several times. In the end, we learned that the best way to coax them to accept change was to first listen to them. This is the area where our business analysts really proved their worth!

CONCLUSION

Several areas above, e.g., Technical Security and Best Practices, were longer and more difficult than expected. The entire project took eight months—two months past schedule and 40% over budget! The core project team consisted of three full-time members. I was one of them.

Would I consider it successful? Yes. We achieved the project's goals. Were the customers happy? The end-users were. Management was not. From the beginning, we articulated to senior management that they had an unrealistic schedule especially because they were ripping out an old application software system. Delays cost money.

At the project onset, they practiced an all too familiar but ill-advised tactic. They asked us for a "realistic" budget. We were outside consultants. Specifically we were the subcontractors of a (politically-connected) contractor. We used parametric and bottom-up estimates, got the agreement from our contractor, and we jointly submitted it to hospital management.

I remember the incident vividly. We were in the office of the hospital administrator. He glanced at it, asked us a few questions, crossed out our figure, deducted 30%, and wrote that down and signed off beside his scribbled amount. Furthermore, he slashed a month of our projected schedule.


Sphere: Related Content

Wednesday, June 11, 2008

HOW TO CHOOSE YOUR IT PRIORITIES WISELY

I ran recently across photos of co-workers from my early days in IT. We got in touch and over a cold one we reminisced about how the IT function has changed. The IT discipline has matured. Fifteen years ago IT’s primary function was to keep systems up and running. Today, that’s taken for granted. Today, IT performance is judged by the results it contributes towards the parent organization's goals. The measure of an effective IT manager is how s/he uses resources to satisfy the organization’s goals.

FIRST, PUT THE HOUSE IN ORDER

Among the first things an incoming IT manager must know are the expectations by the parent business of IT. Armed with that knowledge, he must assess the IT organization's capabilities and identify any gaps between what is expected and what can be delivered. He must perform a gap analysis in short.

Next, the analysis results should be prioritized. The priorities came from the business managers and are the same expectations he learned earlier. The outcome of this step is a prioritized list of the processes and activities that need to be improved.

KEEP THE CORPORATE CULTURE IN MIND

Any good marketing management book will explain at least three ways that companies differentiate themselves in the marketplace. They can position themselves as the best in:
  • Customer responsiveness
They excel at staying close to their customers. They can anticipate their customer needs more quickly.
  • Product or service innovation
They provide the latest and greatest. Their products or service speak for themselves.
  • Operational efficiency
They have the most efficient operations. Their efficiency means that they can sell you their goods and services at the least possible cost.
A former employer, Shared Medical Systems (SMS), is a good example of a company whose corporate focus was on exceptional customer responsiveness, the first item above. This was SMS’s competitive strength. That strength was emphasized at the cost of product innovation though. SMS has never been known for devising the most efficient solutions. Their solutions tended to be evolutionary improvements of existing products and, sometimes, that wasn’t enough. In my team’s area of responsibility-the Great Lakes region and Central Canada-I know we lost several accounts because our competitors were able to introduce superior solutions. This was SMS corporate culture though—conservative but steady and sure. This mindset had served them well. Founded in 1969 by three IBM salesmen, SMS provided time-sharing services to hospitals. Three decades later, SMS had grown to become the largest IT service provider for the healthcare industry. Siemens, the German conglomerate, acquired SMS in 2000. It turned SMS into the core component of its medical division, and renamed it Siemens Medical.

It was a wrenching change. Our regional VP—the highest-ranking officer at our regional office—had his title changed to… Senior Manager.

At any rate, the digression was meant to illustrate the importance of knowing the corporate culture of the parent organization in planning the IT functions.

THE RELATIONSHIP BETWEEN BUSINESS PROCESSES AND IT SYSTEMS

Business processes are supported by IT systems. Let’s understand that first. Consider this example of a business process:

In any modern supermarket, when it’s time to check out, you select a line and then place the items you’re buying on the conveyor belt. Once the items reach the cashier, she scans each piece and the item's description and price appears on the display terminal. That’s a business process. Behind it is information technology and clearly, the process is enabled or can only work through IT. The scanned bar code is converted into the data that is the item’s description and price. This data is pushed back to the cashier’s terminal which then displays it for both customer and cashier to see and verify.

¿SIX SIGMA OR NARROW CRITICAL GAPS?

A fast growing company doesn’t have much time to focus on improving its business processes. That task of improving its processes can’t be ignored in the long-term however. In a normal process transformation, the focus would be on the process side while IT adapts to the changes. In hospitals-this is the industry I’m most familiar with-processes have become more tightly integrated with IT. Consequently, process improvements require simultaneous improvements in IT systems. This holds true twice over for hospitals. The aging baby boomers have put healthcare on the fast track and hospitals are incorporating technology into its operations to just keep up.

In my opinion, this was the reality that our corporate did not or chose not to see. Our customers-at least the dynamic ones-were fast-tracking changes. For example, Six Sigma was in vogue with management during those days but Six Sigma is a change methodology that is very detail-oriented. Changes occur incrementally and, therefore, slowly. That’s fine if you’re fine-tuning a process. Six Sigma, however, is impractical to the point of actually being detrimental if you're making major changes to a process.

Our more dynamic customers adopted a different approach that I thought was more effective. They would work on the top three process capability gaps. Hospital administrators define these gaps differently. A growing hospital will choose gaps that hamper the business from scaling up (i.e., expanding). Narrowing those gaps deliver more immediate and observable results.

A typical hospital has a very uneven workflow pattern. A bottleneck occurs almost daily in the Emergency Room. Apart from being dangerous to the patients, it exposes the hospital to greater legal risk and it threatens the critical revenue-generating process. Clearly, this is a problem area.

A results-driven organization demands tangible contributions from IT (or any other business function) in short-term cycles. For example, if this year’s goal is to streamline the uneven workflow, hospital administrators may want to see tangible improvements every 90 days.

This kind of pressure makes communication and the task of change management very important. The IT manager must be able to explain his roadmap as well as progress and challenges regularly.

Generally speaking, any system that closes the care-giving loop between the patient and doctor or coordinates the different clinical departments better is desirable. And if the system gives the hospital a competitive edge then it becomes all that much better and more important to implement.


Sphere: Related Content

Saturday, May 19, 2007

PROTECT YOURSELF IN THE HOSPITAL

I recently read an excellent book by Tom Sharon, “Protect Yourself in the Hospital: Insider Tips for Avoiding Hospital Mistakes for Yourself or Someone You Love.” I’ve spent a lot of time in hospitals (doing my job as an IT expert and not as a patient!) and had heard about the number of unnecessary deaths that occurred in hospitals. The book’s back cover stated that hospitals are responsible for 100,000 accidental deaths and many more injuries each year. Medical News Today, a website for the medical community estimates the average to be closer to 195,000. Regardless of the number, there’s a good chance that you may have heard of or even personally know someone who has experienced a preventable tragedy. I know of several myself, including one who lost his mother to hospital error. One of my uncles suffered a severe stroke that left him a vegetable until he thankfully passed away.

Mr. Sharon is a registered nurse who started a second career as a legal consultant who advises attorneys on cases involving hospitals that have been accused of preventable deaths.

The book is a sobering view of hospitals. I now view hospitals more carefully since the book has peeled off the veil of ignorance that I used to share with the general public about hospitals. Most people don’t shop around for good hospitals and they should, says Mr. Sharon. For my part, I have worked in one hospital where I know I wouldn’t want to be rushed to in the event of an accident. The network office was located in the basement in a room that was obviously an after-thought. Best of all, it was adjacent to the morgue! We had to descend a rusted staircase and walk through a corridor that was lined with gurneys. A gurney is “a mobile bed with wheels designed for transport of patients in hospitals and ambulances.” If it came out of the morgue, it’s not transporting a live patient anymore.

The hospital has since been replaced by a more modern and larger one but who knows whether the personnel have also been replaced? I would rather be in a hospital that didn’t have the latest gadgets but had staff that cared than one with the newest technology but had a staff that was apathetic and impersonal. So my point about that hospital still stands. I wouldn’t want to be brought there.

I have reproduced three sections that might persuade you to read the book. The first section summarizes the things you should evaluate in a hospital. When you’re aware of these things you can evaluate the hospital intelligently. The second section does the same thing for a hospital floor. And the third section discusses the accreditation process. Accreditation is an important process by an industry that polices itself. The accrediting body is known as the Joint Commission on Accreditation of Healthcare Organizations, or JCAHO for short. I thought JCAHO certification was ample proof of the hospital’s quality until I read Sharon’s account. That’s why I thought it should be reproduced.

SECTION-1: HOW TO FIND THE SAFEST HOSPITAL

For those of you who live in urban areas where there is more than one hospital to choose from, here is a list of what to look for when you engage in comparison “shopping.” This is especially important if you move into a new area. You need to choose your hospital at least as carefully as you choose your schools and place of worship. They are not all the same.

Dangerous Hospital
  1. Cash-flow deficit
  2. Poor labor relations
  3. Equipment in corridors
  4. Odor of human excrement coming from rooms
  5. Care plan conferences exclude patient or family
  6. Operating room closed at night with on-call staff
  7. No formal nursing recruitment and retention program
  8. Supervisors scramble desperately to find nurses
  9. Some trauma seen as “unavoidable”
  10. No expression of interest in patient satisfaction
Acceptable Hospital
  1. Balanced budget
  2. Good labor relations
  3. All corridors clear
  4. Free of foul odors
  5. Care plan conferences include patient or family
  6. Operating room staffed twenty-four hours/day
  7. Nursing recruitment and retention program
  8. Staffing prescheduled with adequate numbers
  9. Zero tolerance for patient trauma
  10. Patient satisfaction survey forms provided
Here's what the author said about labor relations (the second item above):
…this important factor can determine the quality of your care. Disgruntled employees are not the people I would want to rely on for safe health-care services. Moreover, hospital managers who deal with strikes by importing personnel to cross picket lines are wreaking havoc with life and limb. I have seen many help wanted ads for nurses from agencies who specialize in this endeavor. The large print says, “Nurses desperately needed for critical care, operating rooms and other areas, one hundred dollars per hour.” The small print states, “Labor dispute exists.” The hospital managers are not going to properly screen such nurses because this is not a normal hiring situation with multiple interviews and reference checks. Any nurse with a license and a warm body who is willing to cross a picket line and lacks professional ethics will be standing at your bedside. It does not take much for a physician or a nurse to inadvertently transform an intravenous medication to a lethal injection. If there is any history of a nurse’s strike in your institution, call the Nurses’ Association of your state and find out what the issues were and how the managers conducted themselves during the dispute. Again, if you cannot stay away from such a place, you should know the kind of people who are in command.
SECTION-2: HOW TO TELL WHEN A HOSPITAL FLOOR IS DANGEROUS

Dangerous Hospital Floor
  1. There is one nurses' station for the entire floor. Some rooms are not within earshot.
  2. Emergency equipment is missing or broken.
  3. Emergency equipment is shared with another floor.
  4. Some supplies are missing or stored elsewhere.
  5. Skill level checks are not consistently checked.
  6. Nurses are filing “unsafe staffing” reports with the supervisors.
  7. Nurses refuse to answer questions.
  8. Call lights flash unanswered for more than two minutes.
  9. The attending physician rarely or never sees the patient.
  10. Medical care is fragmented-there is no coordination.
Reasonably Safe Hospital Floor
  1. All rooms are within earshot of a nurses’ station (circular design or substations).
  2. Each floor has what it needs.
  3. Emergency equipment is present and working.
  4. All required supplies are on hand.
  5. All nurses’ procedure skill levels are up to date.
  6. Nurses are satisfied with staffing levels.
  7. Nurses answer interview questions.
  8. All call lights are answered immediately.
  9. The attending physician visits with the patient daily.
  10. The primary physician coordinates all medical care.
SECTION-3: THE HOSPITAL ACCREDITATION PROCESS

This description of the process came from the website of the Rhode Island Department of Health.
Hospital Information for the Public about JCAHO Accreditation

By choosing to participate in the accreditation process, an organization asks to be measured against national standards that reflect what health care professionals agree is most conducive to providing quality care in organized health care delivery settings. Achieving accreditation means that an organization substantially complies with JCAHO standards and continuously makes efforts to improve the care and services it provides.

During an accreditation survey, specially trained JCAHO surveyors evaluate the level of an organization’s compliance to JCAHO standards and identify the organization's strengths and weaknesses.

Accreditation surveys result in performance reports, or report cards, which can be utilized by consumers and health care organizations to ascertain the performance of a given health care organization. The report lists:
  1. the accreditation status
  2. the date of the survey
  3. an evaluation of key areas reviewed during the accreditation survey
  4. the results of any follow-up activity
  5. areas needing improvement
The Performance Reports are available to the public. To facilitate access to these reports and comparison of hospitals with one another, the Division has created this web site. To further clarify any terms utilized on this site please visit the glossary of terms webpage.

Accreditation Duration

The time period (three-year) during which a health care organization, found to be in compliance with Joint Commission standards, is awarded accreditation. To maintain accreditation for a three-year or two-year period, satisfactory resolution of any identified issues is required.
Sounds impressive, doesn’t it?

In the last paragraph, note that the surveys are done on a triennial basis (every three years). Now, this is what the author, Mr. Sharon, said about it.

The Joint Commission Survey and What It Tells You

In most hospitals, when you enter the lobby you will see a large plaque on the wall stating that the facility was “accredited” or “accredited with commendation” by the Joint Commission on Accreditation of Healthcare Organizations. JCAHO is a not-for-profit organization whose members are hospitals, nursing homes, home-care agencies, and in-home surgical supply and medical equipment vendors. The surveyors thoroughly inspect all areas of the health-care facility for environmental safety, cleanliness, documentation, emergency procedures, patient care protocols, and credentialing of professional staff, just to name a few. They also work from a clearly delineated set of standards and rate the hospital as to its percentage of compliance with all the criteria. This system is one of self-regulation and based on the now known fact that accredited hospitals accidentally kill approximately 100,000 and injure about 300,000 people per year, it is an abject failure.

Notwithstanding the sophistication and meticulousness of these surveys, there is one major reason for the gargantuan letdown: in all cases JCAHO notifies the surveyed facilities about three months in advance of the inspection, which occurs once every three years. Therefore, any representation that a JCAHO accreditation assures quality of care is suspect. The accreditation only shows that the facility has been compliant with JCAHO standards for about thirty days before and during the survey once every three years.

Moving forward, the hospital scene during the three-month period prior to the inspection is a flurry of activity, with mock surveys, managers’ meetings, staff meetings, and scrambling to provide previously neglected in-service and to update personnel files and patient documentation. The level of management scrutiny and dedication to upholding the highest standards is at its peak during this period, and it is a time of high levels of stress and anxiety, long hours, and fear of job loss. The period that follows is one of celebration for the relief from the stress. Unfortunately, this is followed by the relaxation phase when everything slides back to the “normal” way of doing things, with the supervision becoming much less stringent. In many instances, the usual way of managing is blatantly substandard, with an illusion of propriety displayed for the surveyors during their stay. As soon as the survey is finished, the mirage evaporates.

For example, a hospital in New York City spent about $30 million building a high-tech emergency suite designated as a level I trauma center. The problem was that it was too small to serve the needs of the surrounding community. Consequently, the hospital management adopted a policy of placing two patients in each of the cubicles that were designed for only one. This was being done in violation of JCAHO standards and health department regulations. The CEO issued strict instructions prohibiting the diversion of patients to other facilities because diverting patients is equivalent to diverting revenue.

After a year of this state-of-the-art facility’s being continuously operated in the aforesaid substandard mode, JCAHO notified the hospital that the surveyors were coming in ninety days for the accreditation inspection. The management immediately instituted a hospital-wide program of mock surveys, in-service conferences, patient chart review, and examination of the professional credentialing files to bring everything up to standard. Not surprisingly, during the week that the surveyors were on the premises, the emergency department had only one patient per cubicle. This was accomplished by diverting ambulances to other hospitals during peak times and speeding up the process of admitting or discharging patients from the emergency room. In short, the hospital became generally more efficient during the survey with more staff people working overtime. The over-crowding and chaotic ambience [sic] resumed as soon as the inspectors were gone because the ambulances were no longer being diverted and the extra overtime was eliminated.
The contrast is striking, isn’t it? I strongly suggest you read the book.



Sphere: Related Content