Forensic medical record review for plaintiff attorneys
Do You Have the Complete Medical Record?
The chart you received may not show what was entered late, changed, backdated, deleted — or never produced. Find out what is present, what may be missing, what changed, and what you should request next.
Late entries · Undisclosed changes · Missing audit data · Production gaps
CHPSE-certified · 15+ years healthcare IT · Nationwide litigation support

Start here
Three questions every EMR case starts with
How do I get the audit trail produced?
What to ask for, in what format, and the request-for-production language that gets the log itself — not just the chart.
What do my state's rules require?
Retention periods, authentication requirements, and spoliation posture differ by jurisdiction — state by state, with citations.
What does the defendant's system log?
Each EMR logs — and can export — different things. Know what to demand from the system you're actually facing.
What the audit trail reveals
The discrepancy the chart hides
An access log shows who viewed the chart; the audit trail shows what changed and when. Here's the kind of timing conflict the metadata makes provable:
| Timestamp (UTC) | User | Action | Detail |
|---|---|---|---|
| 2024-03-11 22:47:03 | RN J. Doe | CREATE | Progress note created — status: draft |
| 2024-03-11 23:02:10 | RN J. Doe | VIEW | Vitals flowsheet opened |
| 2024-03-12 08:55:41 | Dr. A. Roe | VIEW | Progress note opened |
| 2024-03-12 09:14:55 | RN J. Doe | EDIT | Flagged: Progress note edited — entered late, back-dated to 03-11 |
| 2024-03-12 09:15:10 | RN J. Doe | SIGN | Progress note signed |
Getting this data produced starts with the request — the EMR discovery guide covers what to ask for and the request-for-production language that gets it, and EMR metadata analysis covers the layers beyond the audit trail.
Every engagement
Six deliverables, built to file
- 01
EMR authenticity & completeness report
Independent verification that the record produced in discovery is the complete, unaltered electronic record.
- 02
Audit-trail & metadata findings
Late entries, post-event edits, backdating, deletions, and the access log — drawn from the system's own logs.
- 03
Annotated chronology
An event timeline synced to exhibits and pleadings, annotated against the audit-trail evidence.
- 04
Standards-of-care cross-references
Documented variances framed in terms a trier of fact can follow.
- 05
Provider background summary
Licenses, board certifications, disciplinary actions, and publicly available history.
- 06
Filing-ready declaration template
Declaration or affidavit language tailored to the jurisdiction, ready for your review and execution.
See a simulated demonstrative report or how the underlying EMR audit trail analysis works.
How it works
From production to discovery-ready findings
Send the production
Forward the records and any audit-trail or access-log data the provider produced. I'll tell you what's present, what's missing, and what to demand next.
Forensic analysis
I reconstruct the record's history from the audit trail and metadata — entry timing, edits, deletions, copy-forward cloning, and the gap between when documentation was authored and when events occurred.
Findings memo + discovery language
You get a clear written findings memo and model request-for-production language tuned to the specific EMR — ready to drop into discovery, motion practice, or deposition prep.
Why these logs exist — and get produced in discovery
The audit trail is a required record — and discoverable
Audit trails aren't a courtesy a provider chose to keep. Federal audit-control rules (45 CFR 164.312(b)) and state hospital regulations like 10 NYCRR 405.10 require providers to maintain them — and New York appellate courts have repeatedly compelled their production in discovery (Vargas v. Lee, 2d Dep't 2019; Harms v. Lewis, 4th Dep't 2026).
HIPAA Security Rule
Audit controls are required
The Security Rule (45 CFR 164.312(b)) obligates providers to implement audit controls — mechanisms that record and examine activity in systems holding electronic protected health information. Paired with state hospital record-retention rules (for example, 10 NYCRR 405.10 in New York), the audit trail isn't optional; it's the output of a control the provider was already required to operate and retain.
HITECH Act
Enforcement with teeth
HITECH strengthened HIPAA enforcement and raised the stakes for actually maintaining those controls. Practically, that means audit data is more likely to exist, be retained, and be retrievable than a 'we don't really keep that' objection suggests.
21st Century Cures Act
Information blocking rules
The Cures Act's information-blocking rules press providers and their EMR vendors toward making electronic health information available rather than withholding it. A 'too burdensome' objection runs against the direction of federal health-information policy.
This is technical and regulatory context, not legal advice — the application to your case is your call. Read more on HITECH records requests and Cures Act information blocking
Cross-vendor coverage
Every major EMR audits differently
What to demand in discovery — and where productions fall short — depends on the system. Start with the EMR discovery guide, then the platform-specific guides:
FAQ
Common questions about EMR checks and audit trails
What is an EMR check?
An EMR check is an independent forensic audit of an electronic medical record's audit trail and metadata. It verifies that the record produced in discovery is complete and unaltered, and surfaces late entries, backdating, post-event edits, and deletions that don't appear on the face of the chart.
What is an EMR/EHR audit trail?
The audit trail is the electronic health record's time-stamped, action-level log of who created, viewed, modified, or deleted each entry, and when. Whether a system is called an EMR or an EHR, the log works the same way — and unlike an access log, which only shows who viewed a chart, it records what actually changed.
What is EMR forensics?
EMR forensics reconstructs a record's true history from its audit trail and metadata, translating raw system logs into a defensible timeline for discovery, deposition, and trial.
Can EMRCheck serve as an EMR expert witness?
Yes. Engagements include written findings, declarations and affidavits, and testimony explaining audit-trail and metadata evidence, provided by a CHPSE-certified (Certified HIPAA Privacy Security Expert) forensic EMR analyst.
How is an EMR check different from the records the hospital produces?
A standard production is the chart as it appears today. An EMR check examines the metadata underneath it to establish whether that chart is contemporaneous and unaltered.
Which EMR systems do you analyze?
Epic, Oracle Health (Cerner), MEDITECH, athenahealth, eClinicalWorks, Veradigm (Allscripts), and NextGen.
Need testimony? See EMR expert-witness services.