🧬 We talk about “health data” as if it’s one thing, but it’s really hundreds of incompatible languages trying (and failing) to talk to each other. Every layer speaks a different dialect: • EHRs: HL7 v2, CDA, FHIR • Claims: X12 837, UB-04, CMS-1500 • Labs: LOINC, SNOMED CT • Devices: DICOM, IEEE 11073 • Genomics: VCF, FASTQ, BAM Each was built for a single purpose, not interoperability. The result? 🚑 A patient’s data is scattered across 40+ systems, each with its own schema, timestamps, and access controls. But things are shifting. Newer models are moving beyond formats to: • Graph-based data structures • Semantic layers • Federated architectures These approaches preserve context, not just content, across systems. FHIR paved the road. But the next frontier is semantic interoperability. That’s not just data exchange; it’s data understanding. 🧠 The future of healthcare intelligence isn’t in collecting more data, it’s in connecting meaning. #HealthTech #DataInteroperability #FHIR #HealthcareAI #KnowledgeGraphs #SemanticWeb
Healthcare IT Infrastructure
Explore top LinkedIn content from expert professionals.
-
-
When I say, ‘See you at 7’, do I mean 7 AM or 7 PM? ⏰ This is what we call, an interoperability problem - the inability for systems to exchange data and understand it in the same way. Why is interoperability in healthcare so hard? Because it’s not just a tech issue. It’s a stack of challenges And the hardest part isn’t connection, it's understanding. Let’s break this down. 1️⃣ Technical Interoperability - can systems connect and exchange data? Sounds simple, until: 🔸One system uses CSV, another wants XML 🔸Dates are DD/MM/YYYY vs MM/DD/YYYY 🔸Fields don’t match or exist Without standard formats, even basic connections break. Challenging - yes. But ironically, the easiest layer to fix. (Most teams stop here. That’s the issue.) 2️⃣ Semantic Interoperability - Can systems understand the data? Take “discharge date” as an example: 🔸One system uses the paperwork date 🔸Another, the bed exit time 🔸A third, the billing date Same label, different meanings. Now try running a report across all three. This is where projects quietly fail. Semantics needs shared meaning, clinical context, and governance. (And that’s just admin data, imagine lab values, diagnoses, or clinical notes. Get it wrong and it’s not just inefficiency, it’s a safety issue!) 3️⃣ Workflow Interoperability - do systems fit real care delivery? 🔸A patient sees a doctor in the morning, does a lab test in the afternoon 🔸Lab results are ready but not visible till the next day 🔸Why? The EHR and lab system don’t sync in real time, and no one flagged it. Digital isn’t fast if the workflow stays broken. 4️⃣ Organizational Interoperability - do institutions even want to collaborate? 🔸Hospitals, clinics, insurers, labs etc. have different systems, incentives, and vendors 🔸Even if tech and semantics align, nothing moves without shared ownership The real question isn’t “Can systems talk?” It’s “Do they understand each other and act together?” And more importantly - who’s responsible for making that happen? Because in healthcare, everyone is in charge, yet no one really is. Let’s stop treating interoperability like a checkbox and start treating it as a system-wide commitment: to shared meaning, coordinated action, and patient-centered design. What’s one interoperability headache you’ve seen that should’ve been solved by now? #Interoperability #SemanticStandards #SystemThinking #HealthData 💡This post is part of 'Rethinking Digital Health Innovation' (RDHI), empowering professionals to transform digital health beyond IT and AI myths. 💡The ongoing series and additional resources are available at http://www.enabler.xyz 💡Repost if this message resonates with you!
-
🚨 Listening to Richard Horne, CEO of the National Cyber Security Centre, on BBC Radio 4's Today Programme this morning (whilst navigating school run traffic!) was a stark reminder of the evolving cybersecurity landscape we face in healthcare. His scheduled first major speech today at NCSC headquarters couldn't be more timely. 🏥 The convergence of healthcare and technology brings unprecedented opportunities - but also unique vulnerabilities. Last year, my colleagues (Stephen Gilbert, Francesco Ricciardi, Constantinos Patsakis) and I explored this very theme in Nature Portfolio's digital medicine journal, examining the potentially catastrophic implications of cyber attacks on hospital-at-home platforms. (https://lnkd.in/dyEtNNtd) ⚡️ The reality? The most significant system failures don't have to arise from malicious exploitation but can originate from the mundane - a routine software update gone wrong - that can bring critical healthcare infrastructure to its knees. 📋 With Annex 1 of the EU MDR mandating state-of-the-art protection against unauthorised access, and the FDA's pre-market & post-market cybersecurity requirements under 21 CFR 820.30(g), regulatory bodies are crystal clear: robust cybersecurity isn't optional - it's a fundamental safety requirement for market access. 🔐 Cybersecurity isn't just an IT issue though - it's a patient safety imperative. 📋 Quick checklist to consider: - When did you last review your SBOM and vulnerability management processes? - Have you stress-tested your systems against unexpected scenarios? - Is your security risk management process integrated with ISO 14971? - Are your defence-in-depth strategies up to date with NIST frameworks? - Most importantly: when was the last time you ran a full simulation? 🛠️ Speaking of practical steps, kudos to my colleague Tarik Kobalas for sharing some brilliant GenAI security resources recently, including the new OWASP® Foundation LLM&GenAI Top 10 2025 (https://lnkd.in/e5gS5fEt). As we navigate the rapid evolution of AI in healthcare, these tools become increasingly crucial. 🪙 Let's treat cybersecurity with the same rigour as we do clinical safety - essentially two sides of the same coin. #DigitalHealth #Cybersecurity #PatientSafety #HealthTech #MedicalDevices #SaMD
-
I did my first Residential Aged Care Medication Round today after working as a doctor for 30 years- not by choice by rather by urgent circumstance. This morning, I hit a wall in patient care. Not a medical wall, but a digital one. A long-term patient, admitted urgently into a Residential Aged Care Facility with influenza and worsening heart failure. I needed to prescribe urgent medication. But I couldn't. 🚫 IT glitch. Couldn't access the aged care facility's electronic health record (EHR). 🚫 Remote system. No immediate IT support. 🚫 Policy barrier. Nurses, rightly following protocol, couldn't accept a verbal order. They could only administer what was on the locked EHR chart. My patient was deteriorating, and the system designed to help was blocking me. The solution? I did the medication round myself and recorded it in my *clinic's* separate, unconnected EHR under the watchful eye of the nurse in charge. I work across 2 hospitals, 2 clinics, and 2 aged care facilities. **Six different, siloed EHR systems.** This isn't efficiency; it's a patient safety risk waiting to happen. This isn't an IT problem. It's a **healthcare system problem**. How many other clinicians are facing this digital fragmentation daily? How do we advocate for connected care that puts the patient, not the platform, at the center? #DigitalHealth #HealthTech #Interoperability #PatientSafety #AgedCare #Healthcare #Medicine #LinkedInMedics #FutureOfHealth
-
It's time to get real: billions of dollars and 20+ years of health IT regulation has resulted in adoption of EHR systems with limited interoperability and data exchange capabilities, and has made it incredibly difficult to access complete patient records electronically. It's hard to convince providers to share across vendor networks by default, it's hard to break through digital roadblocks and end paper bridges, and it's hard to build new workflows that incorporate outside data and information. In a new article in the Journal of AMIA (American Medical Informatics Association) by Assistant Secretary for Technology Policy's Jordan Everson and Chelsea Richwine assesses the American Hospital Association's 2023 Health Information Technology Supplement survey, and find that most hospitals still experience at least one minor (81%) or major (62%) barrier to exchange, with the most common major barriers relating to different vendors and exchange partners’ capabilities. Rural and lower-resourced hospitals fared worse. Patient matching and cost to exchange were reported as major barriers. What works? Health Information Exchanges (HIEs), Health Information Service Providers (HISPs), and national networks. "...supplemental analysis indicated that use of HIEs was related to substantially lower rates of reporting barriers related to different vendor platforms, exchange partners, the need for customized interfaces, and data formatting. Use of national networks was related to lower rates of 6/8 barriers, with the strongest association with lower rates of barriers related to different vendor platforms, costs to exchange, and a need for customized interfaces."
-
Most "interoperability solutions" in healthcare aren’t interoperable. They’re branded workarounds. And they’re quietly killing progress. Here’s what I keep seeing: Startups, vendors, and even entire government programmes claiming interoperability. But scratch beneath the surface? It’s data-sharing theatre. Not real integration. Not real portability. Not real access at the point of care. Let’s break down what often gets called interoperability (but isn’t): 1. "We have a bulk API!" Translation: "We dump CSVs via SFTP." That’s not interoperability. That’s a document delivery service. 2. "We support HL7." Which version? For which endpoints? Is it bi-directional? Is it live? Or is it a once-a-week import with a FHIR sticker slapped on top? 3. "Our system integrates via API." Great. But who can access it? What’s the permission structure? Is it discoverable? Is it even documented? 4. "The data is available to those who need it." Except it’s trapped behind 6 login screens, a VPN, a fax machine, and two info governance meetings. This is the hard truth: Healthcare doesn’t have an interoperability problem. It has an honesty problem about interoperability. Because the second you define it properly - live, machine-readable, structured, bi-directional, and semantically meaningful data exchange - most platforms collapse. So why does this matter? Because the future of digital health depends on data liquidity. AI, remote care, population health, care coordination - none of it works without true interoperability. Right now, the system is flooded with APIs that aren’t accessible, standards that aren’t enforced, and vendors that preach openness while charging for every field. And until we fix that, we’re just building smart tools on dumb pipes. So here’s my test for whether you’re truly interoperable: Can another vendor build on your data without your sales team getting involved? Can a clinician use the data from another system without retyping or reinterpreting it? Can a patient’s information move with them - not just technically, but in real time and without friction? If not, it’s not interoperable. It’s just integrated enough to pass procurement. And that bar is far too low. Let’s stop treating "we have an API" as a badge of honour. And start treating real interoperability as the infrastructure it actually is. Because if we get this right? Every other promise in digital health becomes achievable. But if we don’t? We're just building prettier silos.
-
📢 Cybersecurity in Medical Devices: A Regulatory Perspective 🔐 As #medicaldevices become increasingly connected, #cybersecurity is now a key focus for regulatory bodies worldwide. The #EUMDR and #FDA both emphasize cybersecurity requirements to ensure patient safety and data protection. This week’s infographic provides a comprehensive analysis of cybersecurity requirements under both frameworks. 💠 Pathway for Cybersecurity Compliance per EU MDR ⚡ Design Phase: Incorporate cybersecurity into risk management activities and align with General Safety and Performance Requirements (#GSPRs) ⚡ Development & Manufacturing: Implement secure-by-design principles, conduct verification/validation, and document residual risks ⚡ Conformity Assessment: Engage a Notified Body to review and certify cybersecurity compliance ⚡ Pre-Market Submission: Include cybersecurity measures in technical documentation, such as risk files, validation reports, and user instructions ⚡ Post-Market Activities: Monitor risks, address vulnerabilities through timely updates, and incorporate cybersecurity findings into post-market surveillance (PMS) and clinical follow-up (PMCF) 💠 Pathway for Cybersecurity Compliance per FDA ⚡ Pre-Market Development: Follow the Security Product Development Framework (SPDF), integrating secure design and risk management ⚡ Risk Management: Conduct risk assessments to identify and mitigate vulnerabilities ⚡ Documentation: Prepare cybersecurity management plans, testing reports, architecture details, and labeling ⚡ Submission: Provide this documentation in 510(k), De Novo, or PMA submissions ⚡ Post-Market Monitoring: Evaluate cybersecurity risks from device use, incidents, and vulnerability sources; deploy patches and updates as necessary 🎇 Additional EU Regulations Supporting Cybersecurity ✔️ #GDPR: Protects patient data collected or processed by medical devices. ✔️ NIS 2 Directive: Strengthens cybersecurity for critical infrastructure, including healthcare. ✔️ EU Cybersecurity Act: Establishes a European certification framework for digital products. ✔️ #CyberResilience Act: Focuses on secure-by-design principles for connected devices. 📌 High-Level Comparison of Cybersecurity Requirements for EU MDR and FDA ✳️ Approach: 🏹 EU MDR: Prioritizes pre-market compliance with rigorous assessments. 🏹 FDA: Focuses more on post-market monitoring and risk mitigation. ✳️ Compliance Requirements: 🏹 EU MDR: Imposes stringent obligations, emphasizing transparency, detailed documentation, and adherence to best practices. 🏹 FDA: Ensures device safety with flexibility, allowing manufacturers to determine how to meet cybersecurity requirements. 📢 Engage with This Post 👉 Let’s discuss: How is your organization navigating cybersecurity challenges in medical devices? 👉 Share your strategies for compliance or ask questions in the comments!
-
🔴 Healthcare interoperability is not failing because of missing standards — it is failing in execution. The industry today has: ✔️ Mature standards ✔️ Clear regulatory direction ✔️ Proven technologies Yet, consistent outcomes remain difficult across payer, provider, and health tech ecosystems. The gap is no longer what to use — it’s how it is implemented and aligned. 1️⃣ Terminology Misalignment — The Most Underestimated Risk Healthcare data operates across two parallel code systems: Clinical terminologies - SNOMED CT - LOINC - RxNorm Administrative / billing codes - ICD-10 - CPT - HCPCS 👉 The challenge is not using them — it’s aligning them correctly. The same clinical concept is often: - Captured using SNOMED CT in clinical systems - Reported using ICD/CPT/HCPCS in claims 👉 If this mapping breaks, interoperability breaks — even if APIs are working perfectly. 2️⃣ Reducing FHIR to an API Layer FHIR is often treated as a transport mechanism. In reality, it defines: - Data structure - Terminology bindings - Interoperability workflows 👉 Without aligning internal data to FHIR semantics, systems become technically connected but semantically inconsistent. 3️⃣ Absence of Data Governance Interoperability increases data movement — but without governance, it increases inconsistency. Key gaps include: - Ownership and accountability - Data quality enforcement - Standard adherence 👉 The result is multiple versions of truth, reducing trust across systems. 4️⃣ Validation Limited to Technical Testing Most implementations validate: ✔️ API responses ✔️ Schema formats But miss: - Clinical accuracy - Business workflow correctness - Real-world scenarios 👉 In healthcare, a technically valid message can still be clinically incorrect. 5️⃣ Underestimating Transformation Complexity Transformations such as: EDI (837/835) ↔ FHIR …are not simple mappings. They require: - Context preservation - Business rule orchestration - Terminology normalization across systems 👉 This is where most interoperability failures originate. 🚦What This Signals Healthcare interoperability has moved beyond: ❌ Selecting standards ❌ Building APIs It now depends on: ✔️ Semantic consistency ✔️ Architectural discipline ✔️ Implementation depth 🔥 Bottom Line Interoperability is not achieved when systems connect. It is achieved when data retains meaning, integrity, and usability across those systems. Or simply: 👉 Interoperability breaks not at the API layer — but where clinical meaning and billing representation fail to align. The next phase of healthcare transformation will not be defined by new standards, but by how effectively existing standards are implemented together. #HealthIT #FHIR #Interoperability #HealthcareArchitecture #DigitalHealth #HealthTech #EDI #DataGovernance #HealthcareStandards #RCM
-
Cybersecurity in Healthcare: Your Weakest Link The Change Healthcare attack was a painful lesson. It wasn't just an IT system failure. It stopped pharmacies from filling prescriptions. It prevented providers from getting paid. The event showed everyone how a single security gap can disrupt the nation's healthcare system. It was a clear warning for every healthcare leader. Many executives think a firewall and updated software make them secure. That is a dangerous assumption. This "checklist security" approach creates a false sense of safety. The biggest threats often don't break down the door. They are invited in when an employee clicks on a phishing email or a remote worker logs in from an unsecured home network. The cost is more than money. It is measured in canceled appointments, delayed care, and a permanent loss of patient trust. A strong defense is a strategy, not a shopping list of tools. It requires focus on three areas. First, your people. They are your first and last line of defense. Regular, practical training on how to spot threats is more valuable than any software. Second, your processes. You need strict access controls and multi-factor authentication on every system. You must test your vulnerabilities and have a practiced incident response plan. Third, your technology. Encrypt all patient health information. Keep offline, encrypted backups that ransomware cannot reach. Your security is only as strong as its weakest point. Is that an old server, or is it a culture that treats cybersecurity as someone else’s job? Let’s talk with Digital Transformation Strategist on how to do it.