By JENNIFER HARRISON
Jennifer Harrison is the Managing Shareholder in the Memphis law office of Hall Booth Smith, PC. She is a former CVICU nurse and occupational health nurse. She has a Master of Law in Trial Advocacy and is licensed to practice law in Tennessee, Arkansas and Mississippi. She is also a Certified Civil Mediator in Tenn. and Miss. She has been recognized as one of The Best Lawyers in America, Peer Reviewed by Martindale-Hubbell, and as a Tennessee Super Lawyer. Earlier this year, she was recognized and highlighted in the Memphis Business Journal as “Women Who Lead.” After more than 20 years protecting healthcare providers’ interests, she still enjoys integrating medicine and law and utilizing her combined experiences to be a staunch and zealous advocate for her clients.
This is a follow up to last September’s article
There was a very important “Don’t” that needs further addressing: (do not) ACCESS ANY RECORD THAT IS NOT YOURS AND IS NOT AT THE CLINIC. It’s law, not medicine, but it’s in your best interest to keep reading.
Just because you CAN access another provider or a hospital’s electronic medical record (EMR) doesn’t mean you SHOULD. Access and permission are not synonymous and do not always co-exist. Examples of when they do co-exist: 1. A provider is treating a hospital patient and has login access to the EMR. Of course, the provider has permission to access the patient’s hospital EMR for purposes of care and treatment. 2. A provider needs to access the hospital’s EMR to electronically sign behind another provider and/or document an Addendum. 3. Oftentimes, after care and treatment, a provider may need to access the EMR to review and sign a Death Certificate. In these examples, access and permission accompany each other.
An example/scenario of when they would not co-exist (again, for an individual physician in the context of a hospital patient): Provider’s care and treatment are over. Provider receives a Notice of Intent to Sue (NOI) letter and a medical authorization. Other providers and/or a hospital are identified in the NOI letter. Upon receipt of the NOI letter and thinking you may be sued for an act or omission that caused injury to a patient, one of your first burning desires may be to access the patient’s hospital EMR. Please don’t. You may still have access to the hospital EMR, but this does not mean you still have permission.
There are some options in this scenario and neither includes you accessing the EMR:
- Your attorney uses the medical authorization to request records directly from the hospital. If the receiving hospital determines the core elements of HIPAA are met (HIPAA-compliant), the hospital (or third-party vendor used by the hospital) should produce records. If your attorney obtains medical records that are necessary to investigate and evaluate the claim(s), the investigative function of the Tennessee Healthcare Liability (THCLA) is satisfied.
- If the receiving hospital determines that the medical authorization is not HIPAA-compliant, the request will be rejected in writing. Consequently, no records are produced or obtained, no investigation or evaluation is completed, and Defendant/provider is prejudiced.[1] Put a pin at “prejudiced”. The investigative function of the statute is frustrated, and Plaintiff’s lawsuit is subject to dismissal.
- The medical authorization is glaringly deficient/not HIPAA-compliant. Tennessee law does not require your attorney to test the validity of the authorization by requesting records and getting rejected. If the authorization is not HIPAA-compliant, Defendant/provider is prejudiced, the investigation function of the statute is frustrated, and Plaintiff’s lawsuit is subject to dismissal.
So, why does this matter TO THE PROVIDER? In scenario #1, whether you accessed the EMR may not become an issue. However, it will still be known. At a minimum, the hospital will know because it most likely has an audit trail showing every time you accessed the EMR, date and time you accessed it, the part of the record accessed, how long you were in the record, and (sometimes) what computer was used to access it.
In scenarios #2 and #3, your attorney will likely (and quickly) argue that Plaintiff did not substantially comply with the THCLA, you were not given the requisite permission to request and obtain the hospital’s complete records, you were prejudiced, and the investigation function of the statute is frustrated. Pin: “Prejudice is relevant to the determination of whether a plaintiff substantially complied with Section 121, but it is not a separate and independent analytical element.” Martin v. Rolling Hills Hospital, LLC, 600 S.W.3d, 322, 325 (Tenn. 2020).
If your burning desire got the best of you and you accessed the hospital’s EMR upon receipt of the NOI letter, your “prejudice” argument may have either lost some steam or disappeared altogether. Your opponent’s argument may be: Defendant reviewed the EMR so no harm, no foul. Turn the NOI letter over and let your attorney try to get the records.
Finally, your login/password is yours only, and accessing a patient’s EMR outside of care and treatment may violate HIPAA protections, be addressed in hospital Bylaws, policies and procedures, and/or an employment agreement. If you access a patient’s EMR outside of care and treatment, you are subject to inquiry as to why you accessed the patient’s EMR.
Key takeaways:
- Read the original article from September 1, 2025.
- Whether the statutory medical authorization is HIPAA-compliant or not is irrelevant in terms of accessing another provider or hospital’s EMR.
- Access and permission are not synonymous.
- If you are denied the opportunity to request and obtain complete records and then sued, your attorney may be successful in seeking dismissal of the case against you.
- If you get an NOI letter then access the EMR, you may blow your dismissal argument.
- Outside the context of a lawsuit, you are subject to provider or hospital inquiry if you access a patient’s EMR for a reason other than care and treatment.
- Just because you can access the EMR doesn’t mean you should.
The information provided in this article is for general informational purposes only and does not constitute legal, financial, or professional advice. While every effort has been made to ensure the accuracy and reliability of the content, the author and publisher make no representations or warranties of any kind, express or implied, about the completeness, accuracy, or suitability of the information contained herein. Any reliance you place on such information is strictly at your own risk. The views expressed are those of the author and do not necessarily reflect the official policy or position of any affiliated organization. Always consult with a qualified professional before making decisions based on this content.






