(C) Center for Economic & Policy Research This story was originally published by Center for Economic & Policy Research and is unaltered. . . . . . . . . . . Financialization through Health IT, Part I: Lessons from Electronic Health Systems [1] [] Date: 2025-02 Executive Summary The heightened role of private equity in extracting wealth from healthcare services has captured national attention in the media and academic research – with the massive bankruptcy of the Steward Healthcare System the poster child for 2024. Private equity firm Cerberus bought out Steward in 2011, sold off its property, cut staffing and supplies, extracted over $1 billion, and ran it into bankruptcy by 2024. Much less sensational and hidden from view are many other financial actors who own and operate other parts of the healthcare sector. In this two-part report, we examine the federal laws governing health IT and the cluster of firms that create, own, and operate the information infrastructure that healthcare providers depend on. These include venture capitalists, health IT vendors, and ‘Big Tech’ firms from Silicon Valley as well as private equity firms and other Wall Street actors. While health IT systems have become embedded in provider organizations as essential to decision-making processes, little attention has been paid to whether or how this change has increased healthcare financialization. By financialization we mean the extent to which actors with primarily financial interests penetrate the industry and shift the logic of decision-making and its outcomes away from its healthcare mission and towards financial goals. The answers to these questions are important for the current debates over what standards and guardrails should be adopted for AI and machine learning in healthcare. The empirical question is whether these financial actors are creating value for healthcare more than they are extracting value from it. We begin with the observation that health IT may create value for clinicians and patients and enrich the firms best situated to profit from the technology. Whether this financial relationship enhances or limits the technology’s potential to improve healthcare delivery systems depends on the laws and regulations put in place to set standards and enforce them, the conditions under which it is implemented, and who has the relative power to set prices and quality. We are interested in the extent to which health IT has improved healthcare relative to its potential, how much external financial actors have extracted wealth from it, and whether this has come at the expense of healthcare organizations, employees, patients, and taxpayers. This question is particularly salient now as the issue of artificial intelligence (AI) and machine learning (ML) in healthcare has come center stage and policymakers are debating how to regulate them. There is great enthusiasm that these technologies will cut costs and improve health care quality, while there also is great concern about accountability and the ability to regulate their use. The current public debate echoes that of thirty years ago over whether electronic health records (EHR) would achieve cost and quality improvements. In Part I, we examine the evolution of electronic health record systems and their adoption based on an analysis of the laws, regulations, and empirical evidence on their use and outcomes over several decades. We reconsider the widespread assumption that health IT has reduced healthcare costs and improved efficiencies. Who are the leading actors in this domain? What are the relationships between health IT financiers, vendors, and healthcare provider organizations? Who has benefited, and who has borne the risks and costs of EHR implementation? To what extent have regulatory guardrails succeeded in providing transparency, accountability, and protections against EHR system failures or deficiencies? Part II of the report considers a broader set of developments in health IT, including the role of venture capital, private equity, IT vendors, and Big Tech companies in the development of integrated health IT systems that healthcare organizations increasingly depend on. EHR platforms became the foundation for layering on software systems for claims and revenue cycle management (RCM), data analytics, algorithmic decision-making, and AI and machine learning applications. The rapid development of these ‘end-to-end’ management systems that integrate patient data into financial accounting systems has positioned them to serve as the infrastructure for embedding AI and machine learning tools into healthcare decision processes – without prior safeguards or input from patients and healthcare workers and without regulatory standards, transparency, or safeguards. The federal government’s late-stage efforts to weigh in on AI applications in healthcare face a powerful set of financial players with deep stakes already planted in healthcare. Again, the empirical question is who benefits, and who absorbs the risks and pays the costs? Our analysis of the evolution and unintended consequences of health IT informs the current debates over regulating these recent developments in health IT. In Part I, the findings from this research point to the important role that the federal government has played in mandating and subsidizing the adoption of health IT systems, but without providing sufficient guardrails or oversight to ensure that taxpayer dollars have been used to benefit clinicians, patients, payers, or the Medicare Trust fund. As a result, the evidence suggests that health IT financiers and vendors often have benefited at the expense of other stakeholders. The evidence suggests that these outcomes are the result of an underlying faith that information technology, now including AI, is the key to reducing costs and streamlining the delivery of healthcare services. This belief took off as the digital revolution emerged in the 1980s and 1990s. The Clinton administration pushed through the 1996 HIPAA legislation in order to protect patient data privacy and support healthcare portability, which set the stage for standardized electronic patients records as well as billing systems. George W. Bush institutionalized federal support for health IT by establishing the Office of the National Coordinator for Health Information Technology (ONC); and in 2009, the Obama Administration mandated that healthcare organizations adopt EHR systems, providing billions of dollars of subsidies to do so under the HITECH Act. Features of the Affordable Care Act (ACA), as well as the federal push to adopt value-based care (VBC), have added incentives for the adoption of EHR systems. But none of these laws and regulations provided guidelines for testing, monitoring, or regulating the use of IT in healthcare, nor did they offer protections for workers’ rights or funding to train employees in the use of health IT. Taxpayer dollars that subsidize the adoption and upgrading of health IT flow like water through healthcare organizations to a host of tech vendors, private equity firms, data mining and marketing companies, revenue cycle management firms, data analytics firms, and others. The strengths and limitations in the HIPAA privacy rules, as amended under the HITECH Act, produced intended and unintended consequences. The HIPAA privacy regime offered major protections for patient electronic data privacy, limiting access to healthcare providers and payers; but it also allowed access to patient data by ‘business associates’ that provided services to providers and payers. As the health IT ‘ecosystem’ grew, hundreds of enterprises gained access to private patient health information, without patients’ full knowledge and often without any strong justification for their ‘need to know.’ The assumed cost effectiveness of health IT that fueled passage of the HITECH Act did not receive sufficient empirical scrutiny before federal adoption mandates were in place and billions of taxpayer dollars had been spent. While the mandates successfully ushered in rapid adoption of EHR systems, the systems were flawed, user-unfriendly, and lacked interoperability (the ability of EHR systems to share information), which was one of the central requirements of the HITECH law. As a result, healthcare organizations became laboratory sites for experimentation in which providers and patients often bore the costs of health IT glitches, inaccuracy, and lack of interoperability. Health IT lacks public oversight and guardrails, allowing venture capitalists and IT vendors to make billions on the adoption of unproven technologies by health provider organizations. The HITECH adoption mandates led to ‘a rush to adopt’ EHRs, which also privileged the legacy IT vendors – allowing them to acquire asymmetric market power (and in some market subsegments, monopoly power), which has allowed them to charge high prices. Federal subsidies to support innovative startups, by contrast, did not emerge. The market leaders often maintained their dominance through anti-competitive strategies such as information blocking, through which they undercut federal guidelines for interoperability or charged high fees to physicians, clinics, or other users to link to their systems. It wasn’t until 2016 that Congress passed the 21st Century Cures Act, which mandated standards for interoperability for health IT developers and put in motion a national framework for health data exchange under the Trusted Exchange Framework and Common Agreement (TEFCA). Final regulations for the Cures Act were posted in May 2020, while those for TEFCA took until 2024. Fifteen years after the HITECH Act, 30 years after HIPAA, and 60 years after EHR innovations emerged, interoperability is viewed as ‘promising.’ Empirical evidence shows that EHRs have led to better billing processes and internal communications in provider organizations, but not necessarily cost savings. That is because few studies calculate total economic costs that include the hidden costs of installing, maintaining, and upgrading systems, as well as hiring, training, and retraining the entire healthcare workforce to be proficient in data management as these systems continually change. Large healthcare systems spend billions of dollars on EHRs while smaller hospitals are pressed for resources to install or maintain them. A primary expectation among medical practitioners and EHR advocates was that EHRs would substantially reduce or eliminate medical errors due to human data input and updating. But hundreds of empirical studies from the 1990s to the present have found that inaccurate or outdated information is often embedded in patients’ EHRs. While both manual and electronic systems are subject to human errors of data entry, EHR systems encourage widespread use of cut-and-paste features, which may lead to the persistence of outdated information in patient records, information overload for physicians, delays in care, or more serious threats to patients’ lives. The unanticipated negative outcomes of EHRs for physicians, nurses, and frontline workers are also well documented since the 1990s. As EHR systems became more complex, the data entry requirements for physicians and healthcare workers also increased, leading to excessive time spent by physicians on computers rather than direct patient care – with additional hours at home finishing up documentation. Physicians and nurses continue to report that systems are onerous, usability is low, much information is irrelevant or redundant, and the inefficient use of their time for clerical work has grown immensely – leading to high and growing quit rates. Information overload leads to cognitive overload, at times undermining patient care or safety. None of these costs are well-understood or integrated into cost-benefit analyses of the value of health IT. The findings in Part II of this report identify the process through which EHR systems became the platforms for integrating claims and financial management systems, or end-to-end revenue cycle management. While the legacy IT vendors, Epic and Oracle Cerner, diversified their revenue streams into claims and financial management systems, private equity firms bought out independent RCM companies, accelerating their acquisitions in the 2020s as the potential to further automate systems via AI and machine learning took shape. In addition to collecting medical debt via revenue cycle management companies, private equity firms have also bought up medical loan and credit card companies that often result in low-income patients paying more than they otherwise would have. The unanticipated developments in health IT over three decades have had – and continue to have – consequential outcomes for patients, clinicians, healthcare provider organizations, and the costs and quality of care. Thus, a direct line of sight exists between the creation of EHR systems in the 1990s, their mandated use in 2008, their linkage to financial management systems in the 2010s, and their position today as laboratories for testing data-driven decision-making. Venture capital, private equity, and Big Tech have financed a range of firms using data analytics to experiment with cost management, risk management, algorithmic decision-making, ‘value-based care enablement’, and more recently AI and machine learning. The platforms are virtually unregulated, with no independent process to scrutinize them before they are used in healthcare systems, and no guardrails against potential downside risks for patients. They are non-transparent, making it extremely difficult to assess whether AI is being used for cost saving or cost-shifting from insurers or healthcare systems to employees and patients. Early research has identified several major concerns over algorithmic and AI-driven decision-making systems. These include the inaccuracy and biases of data that AI uses, leading to improper diagnoses or care recommendations; racial and economic bias embedded in AI systems; the use of AI ‘recommendations’ as strict rules to be implemented; the hidden ways that data analytics may be used to shift costs from hospitals and insurance companies to healthcare providers and patients. In the meantime, Wall Street, Silicon Valley, and Big Tech actors are making billions selling data and AI systems that lack sufficient testing, transparency, or regulation. The proprietary ownership of massive databases of patient health data also has raised major concern over its use for marketing purposes and private gain. While HIPAA privacy rules were designed to protect individual patient data, they also allowed ‘de-identified’ data (stripped of personal identifiers) to be used for secondary purposes, such as medical research or population health management. Following passage of HIPAA, however, large ad agencies and data mining companies that pre-dated HIPAA were well-positioned to take advantage of de-identified data to monetize it for marketing and private research. The unintended consequence is the growth of an unregulated multibillion-dollar industry in monetizing patient data for private gain without patients or healthcare providers’ knowledge. Because deidentified data is costly and held by large EHR vendors and insurance corporations, academic medical researchers often do not have access to it. Instead, it is often sold to large data analytics and private research or pharmaceutical companies that do not have to follow traditional medical ethics standards and clinical research protocols. Given the proprietary nature of the data, studies cannot be replicated — and it is unclear whether this research meets scientific standards or not. The complete lack of transparency means that the public cannot assess the extent to which patient data is being used for private gain versus the public good. A related and ongoing concern is patients’ privacy rights. As EHR has become the basis for integrating end-to-end revenue cycle management, hundreds or thousands of entities now have access to a patient’s personal health information: The ecosystem of healthcare organizations, providers, insurers, tech vendors, and related businesses with access to personally identifiable information has grown substantially over time. These actors can sidestep the protections in the well-intentioned but flawed HIPAA and HITECH Acts. Patients’ rights advocates are particularly concerned about the extent to which sensitive mental health and other personal information can be accessed by entities without a clear ‘need to know.’ A related concern is that de-identified information may be re-identified, as shown in a growing number of empirical studies using advanced data analytic techniques. Moreover, the linkage of medical and financial records in end-to-end systems has made healthcare by far the most vulnerable industry to cyberattacks due to the high value of this sensitive information on the black market. Between 2009 and December 2024, data breaches affected some 748.5 million individual healthcare records. The number of data breaches of 500+ health records in provider organizations more than doubled between 2018 and 2023, and the 2024 Change Healthcare breach alone affected over 100 million individuals. Since 2020 the costs of healthcare data breaches have increased by 53.3 percent. In sum, the unregulated expansion of health IT infrastructure by financial actors has launched unparalleled demand for cybersecurity systems. Healthcare organizations must now invest billions more in cybersecurity systems, which are owned and operated by venture capital, private equity, and Big Tech firms. [END] --- [1] Url: https://cepr.net/publications/financialization-through-health-it-part-1/ Published and (C) by Center for Economic & Policy Research Content appears here under this condition or license: Creative Commons 4.0 Int'l.. via Magical.Fish Gopher News Feeds: gopher://magical.fish/1/feeds/news/cepr/