You are currently viewing Electronic Health Records and Patient Privacy, Medical Identity
Electronic health records patient privacy

Electronic Health Records and Patient Privacy, Medical Identity

Updated perspective: Electronic health records, patient privacy, and interoperability are not competing goals. They work best when identity, authentication, authorization, auditability, data integrity, and patient safety are designed into the healthcare workflow.

Electronic Health Records and Patient Privacy: HIPAA, HITECH, CEHRT and Medical Identity Theft

Electronic health records can improve patient safety, care coordination, medical billing accuracy, and patient access to information. However, EHR systems also create risks when identity, access control, audit logs, record amendments, data provenance, and privacy safeguards are weak. The 2009 concern about rushing into electronic records without addressing medical identity theft remains relevant, but the modern answer is not to avoid EHRs. The answer is to implement them with enforceable privacy, security, certification, and forensic controls.

Why EHR Privacy Still Matters

In 2009, the healthcare industry was moving quickly toward electronic health record adoption. The policy goal was sound: reduce fragmented paper records, improve access to clinical information, and support better care coordination. The risk was also real: if patient identity, authentication, access control, and auditability were not addressed, electronic records could amplify medical identity theft, privacy breaches, patient safety errors, and billing disputes.

Today, the better question is not whether healthcare should use electronic health records. The better question is whether each EHR implementation is reliable enough to support patient care, HIPAA compliance, medical billing integrity, regulatory review, and legal discovery. Patient privacy is not an obstacle to interoperability. It is one of the safeguards that makes interoperability trustworthy.

Medical Identity Theft and Comingled Records

Medical identity theft can create harm that is different from ordinary financial identity theft. When a false patient uses another person’s identity or insurance coverage, the result may be more than a fraudulent claim. The wrong allergies, medications, diagnoses, procedures, demographic information, insurance data, or clinical history may become associated with the real patient’s chart.

A comingled medical record can create three categories of risk:

  • Clinical risk: Clinicians may rely on inaccurate medication history, allergies, diagnoses, test results, or prior procedures.
  • Privacy risk: protected health information may be disclosed to the wrong person, payer, provider, portal account, or application.
  • Billing and claims risk: inaccurate identity, coverage, diagnosis, or procedure data may affect medical necessity, coding, claim submission, payer audits, and fraud investigations.

This is why patient identity management, access controls, record amendment workflows, and audit logs are not merely technical details. They are patient safety controls.

HIPAA, HITECH, and CEHRT: The Modern Framework

The modern privacy and security framework for electronic health records is built from several overlapping requirements and standards. HIPAA establishes privacy and security obligations for covered entities and business associates. The HITECH Act accelerated the adoption of health information technology and strengthened the importance of electronic protected health information safeguards. Certified Electronic Health Record Technology, often called CEHRT, provides a certification framework for health IT capabilities, including privacy and security controls.

For health systems, physicians, payers, EHR vendors, and legal teams, CEHRT is especially important because certification criteria can become relevant to whether a system was designed, configured, implemented, and monitored in a way that supports reliable records. Important privacy and security capabilities include authentication, access control, authorization, auditable events, tamper resistance, audit reports, amendments, automatic access timeout, emergency access, end-user device encryption, integrity controls, trusted connections, accounting of disclosures, and encryption of authentication credentials.

For additional analysis, see Expert in Electronic Health Record Certification Standards (CEHRT, or Certified Electronic Health Record Technology).

Electronic health records patient privacy 2009 to 2026 perspective
Electronic health records patient privacy 2009 to 2026 perspective

Patient Safety Controls in Electronic Health Records

Electronic health records can improve patient safety when the system is properly configured and governed. Important EHR patient safety controls may include:

  • Unique user identification: each user should be associated with a unique identity so access can be tied to a person, role, or authorized workflow.
  • Authentication and access control: the system should verify the user and limit access based on role, purpose, and authorization.
  • Audit logs and tamper resistance: the organization should be able to determine who accessed the record, when access occurred, what was viewed or changed, and whether audit data remained reliable.
  • Record amendment workflows: the EHR should support correction and amendment processes without destroying the evidentiary history of the record.
  • Clinical decision support: alerts, reminders, medication checks, and decision support should be configured in a way that supports actual clinical workflow.
  • Data integrity controls: the record should preserve reliable information about the source, timing, authorship, amendment history, and transmission of data.
  • Encryption and trusted connections: ePHI should be protected when stored, accessed, exchanged, or transmitted through connected systems.

These controls help explain why patient privacy and patient safety should be analyzed together. A privacy failure may become a patient safety failure when it affects the identity, integrity, or reliability of the medical record.

EHR Forensics, Audit Trails, and Litigation

In litigation, regulatory investigations, HIPAA breach disputes, medical malpractice cases, False Claims Act matters, and medical billing disputes, the EHR may be the system of record. However, a printed chart or PDF export may not tell the full story. The relevant evidence may include audit trails, access logs, event logs, metadata, amendment history, clinical decision support logs, e-prescribing records, medication administration records, portal access records, API access logs, user roles, and configuration settings.

Electronic Health Record Forensics can help determine whether the record is complete, whether access was authorized, whether data was changed, whether audit logs are reliable, whether the EHR was configured consistently with relevant standards, and whether the clinical documentation supports the billing or legal position being asserted.

For legal teams, EHR forensics is not simply a request for “the audit trail.” A complete discovery strategy may require understanding the specific EHR vendor, modules, audit log fields, retention settings, access-control model, health information exchange connections, patient portal activity, identity-provider logs, and business associate relationships.

Verifiable Credentials and Healthcare Digital Identity

Healthcare is moving toward stronger digital identity models. Verifiable credentials may become important for patient access, provider credentialing, consent management, payer-provider exchange, healthcare application access, and electronic health record interoperability.

A verifiable credential can be issued by a trusted party, held by a patient, provider, organization, or application, and presented to another party for validation. In healthcare, this model may apply to patient identity, provider licenses, board certifications, insurance coverage, consent preferences, access rights, and authorization to exchange protected health information.

Verifiable credentials do not replace HIPAA, HITECH, CEHRT, or EHR audit controls. They should be treated as a complementary identity and trust layer. The same practical questions remain: Who issued the credential? What identity proofing occurred? Was the credential valid at the time of use? Was the person or organization authorized? What PHI was accessed? What consent or purpose-of-use controls applied? What audit logs exist? Can those logs be independently reviewed?

Related topic: Verifiable Credentials in Healthcare.

Process Innovation for Payers, Providers, and Patients

One of the keys to improving life for payers, providers, and patients is process innovation. EHR privacy and patient safety problems are rarely solved by technology alone. They require documented workflows, governance, controls, training, monitoring, and accountability.

A strong EHR improvement effort should document both the current-state process and the desired future-state process. That work requires combined expertise from:

  • Technical experts who understand EHR configuration, audit logs, authentication, interoperability, APIs, and data architecture.
  • Healthcare operations experts who understand provider workflows, payer processes, claims adjudication, medical necessity, and clinical documentation.
  • Privacy and compliance experts who understand HIPAA, HITECH, CEHRT, business associate relationships, patient access, breach analysis, and regulatory expectations.
  • Legal and forensic experts who understand discovery, chain of custody, evidentiary reliability, and expert testimony.

Electronic health records can support better care and better evidence, but only when implementation is tied to the real workflow of physicians, nurses, billing teams, compliance officers, patients, payers, and technology vendors.

Healthcare Data Privacy, HIPAA, EHR Forensics and Medical Billing Expert Witness

No World Borders provides expert witness and consulting services involving healthcare data privacy, HIPAA compliance, electronic health records, EHR forensic analysis, medical billing, coding, payer-provider disputes, healthcare technology, and electronic health record certification standards.

Cases involving patient privacy, medical identity theft, EHR audit logs, CEHRT certification, verifiable credentials, access controls, billing integrity, or medical record chain of custody may require analysis from an expert who understands both the technology and the healthcare regulatory environment.

Contact No World Borders to discuss healthcare data privacy, HIPAA, EHR forensics, medical billing, or expert witness support.

Selected Sources

  1. U.S. Department of Health and Human Services: Summary of the HIPAA Privacy Rule
  2. U.S. Department of Health and Human Services: The HIPAA Security Rule
  3. 45 C.F.R. § 170.315: ONC Certification Criteria for Health IT
  4. World Wide Web Consortium: Verifiable Credentials Data Model v2.0


Michael F. Arrigo

Michael Arrigo, an expert witness, and healthcare executive, brings four decades of experience in the software, financial services, and healthcare industries. In 2000, Mr. Arrigo founded No World Borders, a healthcare data, regulations, and economics firm with clients in the pharmaceutical, medical device, hospital, surgical center, physician group, diagnostic imaging, genetic testing, health I.T., and health insurance markets. His expertise spans the federal health programs Medicare and Medicaid and private insurance. He advises Medicare Advantage Organizations that provide health insurance under Part C of the Medicare Act. Mr. Arrigo serves as an expert witness regarding medical coding and billing, fraud damages, and electronic health record software for the U.S. Department of Justice. He has valued well over $1 billion in medical billings in personal injury liens, malpractice, and insurance fraud cases. The U.S. Court of Appeals considered Mr. Arrigo's opinion regarding loss amounts, vacating, and remanding sentencing in a fraud case. Mr. Arrigo provides expertise in the Medicare Secondary Payer Act, Medicare LCDs, anti-trust litigation, medical intellectual property and trade secrets, HIPAA privacy, health care electronic claim data Standards, physician compensation, Anti-Kickback Statute, Stark law, the Affordable Care Act, False Claims Act, and the ARRA HITECH Act. Arrigo advises investors on merger and acquisition (M&A) diligence in the healthcare industry on transactions cumulatively valued at over $1 billion. Mr. Arrigo spent over ten years in Silicon Valley software firms in roles from Product Manager to CEO. He was product manager for a leading-edge database technology joint venture that became commercialized as Microsoft SQL Server, Vice President of Marketing for a software company when it grew from under $2 million in revenue to a $50 million acquisition by a company now merged into Cincom Systems, hired by private equity investors to serve as Vice President of Marketing for a secure email software company until its acquisition and multi $million investor exit by a company now merged into Axway Software S.A. (Euronext: AXW.PA), and CEO of one of the first cloud-based billing software companies, licensing its technology to Citrix Systems (NASDAQ: CTXS). Later, before entering the healthcare industry, he joined Fortune 500 company Fidelity National Financial (NYSE: FNF) as a Vice President, overseeing eCommerce solutions for the mortgage banking industry. While serving as a Vice President at Fortune 500 company First American Financial (NYSE: FAF), he oversaw eCommerce and regulatory compliance technology initiatives for the top ten mortgage banks and led the Sarbanes Oxley Act Section 302 internal controls I.T. audit for the company, supporting Section 404 of the Sarbanes Oxley Act. Mr. Arrigo earned his Bachelor of Science in Business Administration from the University of Southern California. Before that, he studied computer science, statistics, and economics at the University of California, Irvine. His post-graduate studies include biomedical ethics at Harvard Medical School, biomedical informatics at Stanford Medical School, blockchain and crypto-economics at the Massachusetts Institute of Technology, and training as a Certified Professional Medical Auditor (CPMA). Mr. Arrigo is qualified to serve as a director due to his experience in healthcare data, regulations, and economics, his leadership roles in software and financial services public companies, and his healthcare M&A diligence and public company regulatory experience. Mr. Arrigo is quoted in The Wall Street Journal, Fortune Magazine, Kaiser Health News, Consumer Affairs, National Public Radio (NPR), NBC News Houston, USA Today / Milwaukee Journal Sentinel, Medical Economics, Capitol ForumThe Daily Beast, the Lund Report, Inside Higher Ed, New England Psychologist, and other press and media outlets. He authored a peer-reviewed article regarding clinical documentation quality to support accurate medical coding, billing, and good patient care, published by Healthcare Financial Management Association (HFMA) and published in Healthcare I.T. News. Mr. Arrigo serves as a member of the board of directors of a publicly traded company in the healthcare and data analytics industry, where his duties include: member, audit committee; chair, compensation committee; member, special committee.

Leave a Reply