Showing posts with label physician. Show all posts
Showing posts with label physician. Show all posts

Sunday, February 1, 2015

Drug Company Blames Doctor



It's not a pretty aspect of human nature.  In fact, if you've done it, you're probably ashamed of yourself.  An authority figure accuses you of breaking a rule or a law.  Fearful of the consequences, you look around for someone else to blame.  The other person is usually someone who is weaker than you.  It may be a little brother or some other person who can't fight back.  The following is a case in point.
In 2008, Dr. Benjamin prescribed Botox to treat his 2 year old patient for lower-limb spasticity caused by cerebral palsy.  Initially, he ordered 6 units per kilogram of body weight.  In 2012, he decided to increase the dosage to 12.33 units per kilogram of body weight.  The day after the first injection of the increased dose, the patient’s face began swelling and he experienced respiratory difficulties, slurred speech, and vomiting.  
After several hospitalizations, physicians discovered that the Botox injection may have triggered the epileptic seizures that caused these symptoms.

Prior to Dr. Benjamin’s treatment of this patient, Allergan, the manufacturer of Botox, had determined that the maximum dose for a child should not exceed 8 units per kilogram of body weight.   Because Allergan failed to convey that information to treating physicians, Dr. Benjamin was not aware of the dosage limit.  Arguing that Allergan had a duty to advise physicians of dosage recommendations, the patient’s parents sued the manufacturer.

In its effort to escape liability, Allergan argued that because the physician was a “learned intermediary,” he alone had the duty to determine the appropriate dosage for his patient.  It claimed that he alone had the duty to warn the patient of the risks of treatment.

Allergan is not the first drug company to urge the court to shift liability to the health care provider.  Upjohn successfully asserted the same argument in a case involving the death of a man who took Ansaid, a non-steroidal anti-inflammatory drug used to control pain.  Because the drug was a sample given by the physician, its packaging did not contain any drug warnings.  Abbott labs also successfully relied on the learned intermediary in a case involving its concentrated sodium chloride medication.   

Despite these earlier cases, the Court ruled against Allergan.  It held that the learned intermediary doctrine did not apply because Allergan had not warned the physician of “the dangers inherent in the product.”  Dr. Benjamin testified that he would have passed the dosage warning on to the plaintiffs if he had known about it.  He also said that he currently includes that warning in his informed consent procedure.  The plaintiffs testified that they would not have consented to the drug if they had known about the dosage issue.  They said that their son’s spasms were not severe and did not warrant taking the risk of contracting epilepsy.   Significantly, at the time of this case, the FDA had not approved Botox to treat lower-limb spasticity in children.  Accordingly, Dr. Benjamin’s use of the drug was “off-label.”

Health care providers should be certain that they convey in writing to their patients all relevant risks of recommended drugs.  This duty to warn is especially important when the provider’s use of the drug is “off-label.” It is also important when giving the patient a sample of the drug.  Because the packaging of drug samples does not include warnings of drug interactions, the patient does not receive a copy of the manufacturer’s warnings. 

While it is a compliment for the court to consider you “learned,” it can be very expensive for the court to decide that you are a “learned intermediary.”  Don’t become a scapegoat.


Monday, September 10, 2012

No More Mr. Nice Guy - July 2012



When I first read the regulations known as “HIPAA,” I worried about the stiff penalties that could be leveled against health care providers.  Apparently, I wasn’t the only one who thought the penalties were draconian.  To calm all of us “worriers” down, the government issued publications assuring us that the HIPAA police were there to help us come into compliance and not to penalize us.  Now, it is clear that things have changed.

A few years ago, two doctors opened a cardiac surgery clinic.  It was a small operation.  It got a lot smaller this year after the clinic had to pay a $100,000 HIPAA fine.  I’m sure the doctors also paid out many thousands of dollars to the lawyers who represented them during the HIPAA investigation – not to mention the cost of the time taken from their practice as they responded to the government investigation.  Reading the “Resolution Agreement” between the government and the doctors, I could see how easily any small practice could fall victim to a similar fate.  This is how it began.

In an effort to provide better patient care and more efficient services, the practice contracted with an Internet scheduling company so that patients could check the office surgery schedule on-line.  I’m sure that the doctors assumed that the service provider was aware of HIPAA and had taken necessary steps to provide security for the patient information posted on the surgery schedule.  Unfortunately, the clueless company made the on-line scheduling information available to the public.  Even worse, the doctors didn’t think about requiring the Internet company to sign a Business Associate Agreement.  HIPAA requires covered health care providers to have these agreements with people working for them who have access to patient information.  The contracts require those persons to treat the information confidentially.

Eventually, a patient learned that the “confidential” scheduling information was available to the general public and the HIPAA police rode in like the US Calvary in some corny western.  Like the Calvary, they destroyed the enemy.  Not a shot was fired, but the big guns of the U.S. government took their toll.

Ask yourself the following questions to see if you are also at risk for a HIPAA attack:

  1. Do I have a signed business associate agreement with every person or business  who has access to patient information in my possession?  For example, has my lawyer signed a business associate agreement?  My accountant?  My IT company?
  2. Have I provided HIPAA training to each of my employees who has access to patient information?  Do I have documentation of that training?
  3. Have I identified a “Security Official” and a “Privacy Officer” at my office?  Is that in writing?
  4. Do I have a written “Risk Assessment Process?”  Have I conducted a “risk assessment” to identify potential problems with maintaining privacy of patient information?  Is that assessment in writing?  Is it regularly updated in writing?  Does it contain an inventory of every system in the office that stores patient information?  Does it identify risks relating to each system?  
  5. Do I ever email patient charts?  If so, are those emails encrypted?

The HIPAA police also discovered that the clinic sometimes emailed confidential patient information to its doctors’ private email accounts.  This might happen if a physician got a call about a patient in the middle of the night.  The doctor might need to see the patient chart to respond to an emergency.  He could access it on his home computer.  The clinic had not given any thought to insuring the security of those home computers.

It is very important to be especially careful about patient information that your employees access away from the office.  Are your employees sending emails and texts to patients?  Is the content of the email or text put into the patient’s file?  By whom?  How quickly?  Are you sure that the cell phones your employees use to send those emails or texts are password protected?  Are your employees able to access patient information on their home computers?  What do you know about the security of those computers?

In my humble opinion, technology has rendered privacy illusory.  My mother’s advice remains the best I’ve heard concerning privacy.  She used to say, “Don’t ever do or say anything you would regret reading about on the front page of the News and Disturber!”   

Wednesday, February 1, 2012

Facebook and HIPAA: More Ways to Get In Trouble

After a rough day at work, an emergency room physician decided to let off some steam. She logged onto Facebook and wrote about an odd-ball patient. Because of confidentiality requirements imposed by her professional ethics and by HIPAA, the federal privacy regulations, the doctor knew better than to publish her patient’s name. Unfortunately, she put enough information about the patient in her post that her readers were able to figure out his identity. In the uproar that followed, the doctor lost her job and her staff privileges at the hospital. The Medical Board issued a formal reprimand and fined her. We don’t know yet whether the HIPAA police have taken action or whether the patient has filed an invasion of privacy lawsuit.

The case reminded me of a defamation suit from the 1950’s. It involved a book about a world-famous fashion store. (Note that I’m not telling you which one.) The author wrote that the models from New York and Paris were “call girls” and that wealthy men paid thousands of dollars to go out with the women. He wrote that the salesmen were homosexuals. He claimed that the saleswomen were cheaper than the models but were also available for hire. Of course, the store filed suit for defamation. The nine models employed by the store also filed suit. Of the store’s 25 salesmen, 15 filed suit. In addition, 30 of the 382 saleswomen filed a claim with the court.

The author asked the court to dismiss the employees’ suit. Because he had not published their names, he argued that he was not liable to them. The court ruled that even though the author had not identified the models by name, readers of the book could easily determine the models’ identities. Likewise, it ruled that readers would be able to figure out the names of the 25 salesmen. However, the court found that it would be very difficult to figure out the identities of the saleswomen mentioned in the book because the store had 382 saleswomen at the time. Accordingly, the court allowed the models and salesmen to go to the jury, but dismissed the claims of the saleswomen.

HIPAA prohibits unauthorized disclosure of protected “individually identifiable” information. In other words, if you can figure out the identity of the patient from the information disclosed, the information is protected. For example, if a physician says he is treating the Governor of North Carolina, most North Carolinians would know the name of the doctor’s patient.

Assume a nurse asks her Facebook prayer group to pray for “one of our beloved ministers and his wife.” She writes that the clinic where she works has diagnosed the preacher with a social disease. If there is more than one minister, the members of the prayer group wouldn’t know which minister the nurse had outed. Has the nurse violated HIPAA?

If a court were to look to the fashion store case for guidance, the answer might depend on how many ministers worked at the church. If there were 25 or fewer, the nurse would be liable. If the nurse belonged to a church with hundreds of ministers, she might not.

However, another recent case indicates that a health care provider might suffer punishment even when it is impossible to figure out the identity of the patient he writes about. The case involved two nurses who posted on a social media site cell phone pictures of a patient’s x-ray. The x-ray showed that the patient had a sex toy lodged in her body. Although the public couldn’t determine the patient’s name, the hospital fired the nurses. The hospital didn’t claim that the nurses had violated HIPAA. It fired them on the grounds that making fun of any patient in public was “unprofessional conduct.”

Clearly, businesses, especially health care facilities, need written social media policies and should educate employees about those policies. The policies should apply to any publication made by employees on Facebook, Twitter, MySpace and other social media sites. It should prohibit employees from identifying customers, patients, co-workers, suppliers, referral sources, supervisors, and others connected to the employer on those sites. It should also prohibit publishing photographs or x-rays related to work on the sites. Businesses should consider prohibiting posts that reflect poorly on the company, such as pictures showing employees in compromising situations. It may also require employees who post opinions on sensitive topics to include a note that the opinions do not reflect the views of the employer. Finally, the policies should specify how the employer will discipline employees who violate the regulations. Employees should sign a statement that they have a copy of the policies and agree to abide by their terms.

Meanwhile, we’ll all enjoy those wonderfully entertaining blogs, videos, and photos of ourselves and others at our worst – and best. And be glad that some of our parents still haven’t figured out how to turn on a computer.