← Blog · MedLegal AI

How to Get the EHR Audit Trail in Discovery

Verify it yourself — free, no login

See how AI medical-record review links every fact to the exact Bates page that proves it — click any citation and jump straight to the record.

See the 60-second demo →
By John Mahoney · 2026-06-08 · MedLegal AI

The records a hospital produces in response to a standard request are the clinical record — notes, labs, orders. They are not the audit trail: the system log of who created or edited each entry, the exact timestamps, what changed, and who accessed the chart. That data exists, it is often dispositive on questions of timing and alteration, and it is produced only if you ask for it correctly.

The Legal Basis

Because the systems are required to keep this log, "we don't have it" is rarely an accurate objection.

The Case Law

Vargas v. Lee, 170 A.D.3d 1073 (N.Y. App. Div. 2d Dep't 2019), held the audit trail discoverable as relevant to when and by whom entries were made. Borum v. Smith (W.D. Ky. 2017) ordered production of the Epic audit trail. Gilbert v. Highland Hospital, 52 Misc.3d 555 (N.Y. Sup. Ct. 2016), addressed metadata discoverability. The trend is toward production; the variance is in scope and procedure by jurisdiction, which you must confirm locally.

Ask for It by Its Real Name

The single biggest reason an audit-trail request fails is vagueness. Each EHR calls its audit output something specific, and a request for "the metadata" invites a narrow or non-responsive production. Name the report and the system:

EHRWhat to ask for
Epicthe Audit Trail / Access Log report for the chart and date range
Oracle Health (Cerner)the P2Sentinel audit report
MEDITECH, athenahealth, eCW, othersthe system's named audit/access log per 45 CFR 170.315(d)(2)

(Confirm the exact branded report name for the specific version — vendors rename them, and an outdated label invites an objection.)

Generate the request — with the right report names

Our free EHR Audit-Trail Discovery Request generator assembles a request using each EHR's verified, system-specific terminology plus the legal hooks (45 CFR 164.312(b), 170.315(d)(2), ASTM E2147) and supporting case law — so the hospital gets a request it can't brush off as overbroad or unintelligible.

Generate an EHR Audit-Trail Request →

Pair It With the Chronology

The audit trail answers when and by whom; the clinical chronology answers what happened. Used together, a late-entry or post-hoc amendment that the chronology flags becomes a specific, provable fact once the audit trail confirms the system timestamps. Request the audit trail early — before depositions — so the timestamps are locked before testimony.

General information for attorneys, not legal advice. Audit-trail discoverability, scope, and procedure vary by jurisdiction — verify every statute, rule, and case against current authority in your venue.

Questions? [email protected] · (856) 979-6525

See the AI cite its source — no login
Most legal AI is wrong 17–33% of the time. Watch MedLegal AI pin every finding to the exact record page — click any citation and it jumps to the line that proves it.
Watch the 30-second demo →