News Archive 2006  
  News & Events >> News Archive 2006 | News Archive 2005 | News Archive 2004  
  Split Personality
Frank Hayes

July 17, 2006 (Computerworld) Call this a tale of two IT shops. For one, it's the best of times: Last week, the Department of Veterans Affairs won a prestigious innovation award for its electronic health records system, VistA -- the largest and most successful EHR implementation in the world, saving money and improving health care quality for more than 5 million military veterans.

For the other, it's the worst of times: Even though the VA has recovered the stolen laptop that contained personal data on 26.5 million vets and active-duty military personnel, the department still displays the IT security profile of Swiss cheese. New data losses and procedural lapses keep coming to light.

How can an IT outfit so good be so bad?

We all know the answer to that one. Obviously, the VA is g r eat at application development and lousy at operational security. They're two different IT functions.

Still, the contrast is jarring. And it should be.

The VA's Innovations in American Government award came from Harvard University's John F. Kennedy School of Government. Notably, it wasn't an award for a successful IT project, but for a successful government program. Six other programs also got innovation awards last week, but none of them were IT systems.

Even more impressive are the ROI numbers for VistA: Maintenance cost of just $87 per patient per year. Health care cost per patient reduced by 32% over 10 years. Medication errors reduced by two-thirds. For a single pneumonia vaccination program that VistA made possible, pneumonia hospitalizations were cut in half, reducing costs by $40 million annually.

Largely thanks to VistA, VA patient satisfaction has beaten the private sector for six straight years. And last year, when Hurricane Katrina knocked out the VA's medical centers in New Orleans and Gulfport, Miss., medical records for the 40,000 veterans in the area were still accessible, so the vets could resume treatments and get prescriptions refilled.

That's not just good. That's spectacular. It's everything we want IT to accomplish.

But then there's that other VA IT -- the security nightmare that left tens of millions of vets fearing identity thieves. The one in which sensitive data was left unencrypted and removed from the physical security of VA offices for years. The one where no one knew for weeks exactly what data had been exposed, and the loss wasn't even reported up the chain of command for 19 days.

That's everything we want IT not to be.

There's an irony here. What's made VistA so great is that its development has been relentlessly focused on what users actually do in the VA's hospitals and clinics.

Not what they're supposed to do. Not what some analyst believes they should do. But what they really do.

And what made that stolen VA laptop such a nightmare was that the VA's IT security has ignored what users really do with data. Instead of spotting users as they downloaded sensitive data they didn't need and carried it out the door unencrypted, the IT watchdogs missed it. They missed the problem, and they missed their chance to do something about it.

This isn't just two different IT functions. It's two completely different ways of thinking about users and IT.

Decades of paying attention to what users need have paid off in a big way with VistA. But years of failing to monitor what users do has created a security scandal so big that it could overshadow VistA for years to come.

So as this department slowly moves beyond its security mess, it's worth remembering that the VA is one of the biggest IT successes in all of government -- and also one of the greatest failures.

And it's worth keeping in mind that the VA doesn't really need two IT shops.

Just one.

The one that's focused on users.

Frank Hayes , Computerworld 's senior news columnist, has covered IT for more than 20 years. Contact him at frank_hayes@computerworld.com .

« back

 
 
About VSA  Get Involved   |  News & Events   |  What is VistA   |  Why use VistA   |  VistA Resources   |  Contact
Copyright © 2005. VistA Software Alliance. All Rights Reserved.