Forensic EMR review for plaintiff attorneys

Do You Have the Complete Medical Record?

The chart you received may not reveal entries that were added later, changed, deleted, backdated, or omitted from production.

EMRCheck examines the electronic record, audit trail, and metadata to help determine what changed, what may be missing, and what you should request next.

  • What changed
  • What may be missing
  • What to request next
  • CHPSE-certified
  • 15+ years of healthcare IT experience
  • Nationwide litigation support
Illustration of a simulated EMR audit trail on a monitor, with a magnifying glass highlighting an example of deleted chart content. Sample data only — not a real patient record.

What an EMR check examines

  • Audit trail analysis

    Identify who did what, when it occurred, and which entries changed.

  • Timeline reconstruction

    Rebuild the sequence of events using system timestamps and activity.

  • Forensic chart review

    Compare the visible chart with the history behind the electronic record.

Start here

Three questions every EMR case starts with

  • How do I get the audit trail produced?

    What to ask for, in what format, and the request-for-production language that gets the log itself — not just the chart.

    EMR discovery guide

  • What do my state's rules require?

    Retention periods, authentication requirements, and spoliation posture differ by jurisdiction — state by state, with citations.

    State coverage

  • What does the defendant's system log?

    Each EMR logs — and can export — different things. Know what to demand from the system you're actually facing.

    Epic audit trails · eClinicalWorks

How it works

A clearer path from production to discovery

01

Discuss the production

Tell us what was produced and where you suspect a gap, discrepancy, or unexplained chronology.

02

Evaluate the electronic record

Review audit-trail activity, timestamps, metadata, amendments, and available system history.

03

Identify next steps

Receive findings that help counsel understand what changed and what additional material may need to be requested.

Why it matters

The PDF may not tell the whole story

An access log shows who viewed the chart; the audit trail can show what changed and when. A review evaluates the available system data against the record you were given, to help answer questions like these:

  • Was an entry created after the documented event?
  • Was text changed or removed?
  • Is audit data or amendment history absent from production?
  • Does the system timeline conflict with the printed chart?
  • Were all relevant components of the electronic record produced?
audit_trailEpic· Patient #—— · illustrative
Illustrative Epic audit-trail excerpt showing a late, back-dated entry.
Timestamp (UTC)UserActionDetail
2024-03-11 22:47:03RN J. DoeCREATEProgress note created — status: draft
2024-03-11 23:02:10RN J. DoeVIEWVitals flowsheet opened
2024-03-12 08:55:41Dr. A. RoeVIEWProgress note opened
2024-03-12 09:14:55RN J. DoeEDITFlagged: Progress note edited — entered late, back-dated to 03-11
2024-03-12 09:15:10RN J. DoeSIGNProgress note signed
FindingThe printed chart shows a single note dated the night of 03-11. The audit trail shows it was actually written — and back-dated — the next morning, roughly 10 hours after the event it describes.

Getting this data produced starts with the request — the EMR discovery guide covers what to ask for and the request-for-production language that gets it, and EMR metadata analysis covers the layers beyond the audit trail.

Every engagement

Six deliverables, built to file

  • 01

    EMR authenticity & completeness report

    Independent verification that the record produced in discovery is the complete, unaltered electronic record.

  • 02

    Audit-trail & metadata findings

    Late entries, post-event edits, backdating, deletions, and the access log — drawn from the system's own logs.

  • 03

    Annotated chronology

    An event timeline synced to exhibits and pleadings, annotated against the audit-trail evidence.

  • 04

    Standards-of-care cross-references

    Documented variances framed in terms a trier of fact can follow.

  • 05

    Provider background summary

    Licenses, board certifications, disciplinary actions, and publicly available history.

  • 06

    Filing-ready declaration template

    Declaration or affidavit language tailored to the jurisdiction, ready for your review and execution.

See a simulated demonstrative report or how the underlying EMR audit trail analysis works.

Why these logs exist — and get produced in discovery

The audit trail is a required record — and discoverable

Audit trails aren't a courtesy a provider chose to keep. Federal audit-control rules (45 CFR 164.312(b)) and state hospital regulations like 10 NYCRR 405.10 require providers to maintain them — and New York appellate courts have repeatedly compelled their production in discovery (Vargas v. Lee, 2d Dep't 2019; Harms v. Lewis, 4th Dep't 2026).

  1. HIPAA Security Rule

    Audit controls are required

    The Security Rule (45 CFR 164.312(b)) obligates providers to implement audit controls — mechanisms that record and examine activity in systems holding electronic protected health information. Paired with state hospital record-retention rules (for example, 10 NYCRR 405.10 in New York), the audit trail isn't optional; it's the output of a control the provider was already required to operate and retain.

  2. HITECH Act

    Enforcement with teeth

    HITECH strengthened HIPAA enforcement and raised the stakes for actually maintaining those controls. Practically, that means audit data is more likely to exist, be retained, and be retrievable than a 'we don't really keep that' objection suggests.

  3. 21st Century Cures Act

    Information blocking rules

    The Cures Act's information-blocking rules press providers and their EMR vendors toward making electronic health information available rather than withholding it. A 'too burdensome' objection runs against the direction of federal health-information policy.

This is technical and regulatory context, not legal advice — the application to your case is your call. Read more on HITECH records requests and Cures Act information blocking

Cross-vendor coverage

Every major EMR audits differently

What to demand in discovery — and where productions fall short — depends on the system. Start with the EMR discovery guide, then the platform-specific guides:

Service areas

Retention and spoliation rules differ by state

Record-retention periods, authentication requirements, and spoliation posture are set by jurisdiction. Each state guide cites the governing rules for that state.

Request an initial review

Start with what was produced

An initial review needs only enough to understand the matter: your name, firm, work email, and a general description of the concern — for example, that a note's timestamp appears inconsistent with the date of service.

  • No records or files are uploaded through this site.
  • Case specifics are shared securely after we connect.
  • Free case review — no obligation.

Warning: Do not include PHI, patient names, dates of birth, or privileged case details in this message. Share specifics securely after we connect.

The contact form collects only what's needed to reply. It is not a channel for protected health information or patient identifiers.

Request a review

FAQ

Common questions about EMR checks and audit trails

What is an EMR check?

An EMR check is an independent forensic audit of an electronic medical record's audit trail and metadata. It verifies that the record produced in discovery is complete and unaltered, and surfaces late entries, backdating, post-event edits, and deletions that don't appear on the face of the chart.

What is an EMR/EHR audit trail?

The audit trail is the electronic health record's time-stamped, action-level log of who created, viewed, modified, or deleted each entry, and when. Whether a system is called an EMR or an EHR, the log works the same way — and unlike an access log, which only shows who viewed a chart, it records what actually changed.

What is EMR forensics?

EMR forensics reconstructs a record's true history from its audit trail and metadata, translating raw system logs into a defensible timeline for discovery, deposition, and trial.

Can EMRCheck serve as an EMR expert witness?

Yes. Engagements include written findings, declarations and affidavits, and testimony explaining audit-trail and metadata evidence, provided by a CHPSE-certified (Certified HIPAA Privacy Security Expert) forensic EMR analyst.

How is an EMR check different from the records the hospital produces?

A standard production is the chart as it appears today. An EMR check examines the metadata underneath it to establish whether that chart is contemporaneous and unaltered.

Which EMR systems do you analyze?

Epic, Oracle Health (Cerner), MEDITECH, athenahealth, eClinicalWorks, Veradigm (Allscripts), and NextGen.

Need testimony? See EMR expert-witness services.

Free case review

Have a case that turns on the medical record?

A free, no-obligation case review. Send the production you've received and I'll tell you what the audit trail can — and can't — show.