What a Complete Medical Record Contains — and How to Prove Something Is Missing
Verify it yourself — free, no login
See how AI medical-record review links every fact to the exact Bates page that proves it — click any citation and jump straight to the record.
See the 60-second demo →When a defense firm says it produced "the complete medical record," that claim is doing a lot of work. The legal benchmark isn't what's convenient to print — it's the designated record set: the records used to make decisions about the patient. Knowing what belongs in it is how you tell a complete production from a curated one.
What Belongs in the Set
HIPAA defines the designated record set at 45 CFR § 164.501 and gives the patient a right of access to it at 45 CFR § 164.524. For a hospital admission, a complete clinical record generally includes:
- Physician, nursing, and consult notes (including progress and discharge)
- Orders — medication, lab, imaging, nursing
- Medication administration record (MAR)
- Laboratory and pathology results
- Imaging reports and the underlying studies
- Operative and anesthesia records
- Flowsheets and vital-sign records
- Telemetry/monitoring strips
- Emergency-department records, including triage
- Consent forms and patient communications
The Parts Most Often Left Out
The omissions cluster in predictable places — the parts that live in separate systems or that the defense would rather not surface:
| Often missing | Why it matters |
|---|---|
| Nursing flowsheets / telemetry strips | Show the real-time deterioration a summary note smooths over |
| The audit trail / access log | Reveals when entries were made and who viewed the chart |
| Addenda and prior versions of amended notes | The printed chart usually shows only the final version |
| Messages, in-basket, and care-team communications | Often a separate module, rarely produced by default |
| Imaging studies (vs. just the report) | Lets your expert read the film, not the radiologist's summary |
Get the metadata and access log by name
Our free EHR Audit-Trail Discovery Request generator assembles a request for the audit/access log and metadata each EHR keeps — Epic, Oracle/Cerner, MEDITECH, athenahealth and others — using the verified system-specific report name plus the supporting law, so the request is precise enough to be answered.
Generate an EHR Audit-Trail Request →How to Prove a Piece Is Missing
Asserting a record is incomplete is weak; proving it is strong. Three moves:
- Request the designated record set by name (45 CFR § 164.524) so "we gave you the chart" can't mean a curated subset.
- Build the chronology and follow the cross-references — every "see consult" or ordered study that has no produced counterpart is a documented gap.
- Pull the access log — if it shows a document was viewed, printed, or exported but that document isn't in the production, you've proven it existed. The audit trail is discoverable (Vargas v. Lee, 170 A.D.3d 1073 (2019)); the underlying audit-control requirement is 45 CFR § 164.312(b).
Do this early — before depositions — so the timeline and the access log are locked before any witness explains the gap away.
General information for attorneys, not legal advice. Records-access rights, discovery scope, and spoliation remedies vary by jurisdiction — verify every statute, rule, and case against current authority in your venue.
Questions? [email protected] · (856) 979-6525