How to Get the EHR Audit Trail in Discovery
Verify it yourself — free, no login
See how AI medical-record review links every fact to the exact Bates page that proves it — click any citation and jump straight to the record.
See the 60-second demo →The records a hospital produces in response to a standard request are the clinical record — notes, labs, orders. They are not the audit trail: the system log of who created or edited each entry, the exact timestamps, what changed, and who accessed the chart. That data exists, it is often dispositive on questions of timing and alteration, and it is produced only if you ask for it correctly.
The Legal Basis
- 45 CFR § 164.312(b) — HIPAA's audit-controls standard requires mechanisms to record and examine activity in systems that contain electronic PHI.
- 45 CFR § 170.315(d)(2) — certified EHR technology must record a defined set of auditable events (the ONC certification criterion).
- ASTM E2147-18 — the consensus standard specifying what an audit trail and disclosure log should contain.
Because the systems are required to keep this log, "we don't have it" is rarely an accurate objection.
The Case Law
Vargas v. Lee, 170 A.D.3d 1073 (N.Y. App. Div. 2d Dep't 2019), held the audit trail discoverable as relevant to when and by whom entries were made. Borum v. Smith (W.D. Ky. 2017) ordered production of the Epic audit trail. Gilbert v. Highland Hospital, 52 Misc.3d 555 (N.Y. Sup. Ct. 2016), addressed metadata discoverability. The trend is toward production; the variance is in scope and procedure by jurisdiction, which you must confirm locally.
Ask for It by Its Real Name
The single biggest reason an audit-trail request fails is vagueness. Each EHR calls its audit output something specific, and a request for "the metadata" invites a narrow or non-responsive production. Name the report and the system:
| EHR | What to ask for |
|---|---|
| Epic | the Audit Trail / Access Log report for the chart and date range |
| Oracle Health (Cerner) | the P2Sentinel audit report |
| MEDITECH, athenahealth, eCW, others | the system's named audit/access log per 45 CFR 170.315(d)(2) |
(Confirm the exact branded report name for the specific version — vendors rename them, and an outdated label invites an objection.)
Generate the request — with the right report names
Our free EHR Audit-Trail Discovery Request generator assembles a request using each EHR's verified, system-specific terminology plus the legal hooks (45 CFR 164.312(b), 170.315(d)(2), ASTM E2147) and supporting case law — so the hospital gets a request it can't brush off as overbroad or unintelligible.
Generate an EHR Audit-Trail Request →Pair It With the Chronology
The audit trail answers when and by whom; the clinical chronology answers what happened. Used together, a late-entry or post-hoc amendment that the chronology flags becomes a specific, provable fact once the audit trail confirms the system timestamps. Request the audit trail early — before depositions — so the timestamps are locked before testimony.
General information for attorneys, not legal advice. Audit-trail discoverability, scope, and procedure vary by jurisdiction — verify every statute, rule, and case against current authority in your venue.
Questions? [email protected] · (856) 979-6525