Service

Medical Malpractice

Medical malpractice cases turn on what happened, when it happened, and what the people involved knew and said. All three of those questions increasingly have digital answers. The patient record is a database. The provider’s phone went everywhere with them. The facility’s internal communications are preserved in systems that most attorneys have never thought to request.

Cyber Agents, Inc. works medical malpractice matters for attorneys on both sides across nursing home neglect, surgical error, emergency department, and hospital administration cases in Kentucky and multiple other jurisdictions. The evidence we find does not favor either position by default — it tells the truth about what occurred. Our job is to make sure that truth is surfaced and presented accurately.

The patient record is not what it appears to be

The electronic health record as it appears on screen is a rendering. Behind it is a database with an audit log that records every interaction with that record — who accessed it, when, from which terminal, and what they changed. That audit trail is not visible through the normal clinical interface. It has to be requested separately, and the party requesting it has to know to ask for it.

We have examined EHR systems in which chart entries were modified after a patient event. Timestamps were adjusted. Notes were added. Entries that should have been documented in real time were created hours or days after the fact. None of that is visible in the printed chart or the standard record export. All of it is visible in the underlying database audit log.

If the medical record matters to your case — and in a malpractice matter, it almost always does — the question is not just what it says. The question is whether what it says is what was originally documented.

Communications between providers

Physicians, nurses, and administrators communicate through the same channels everyone else does. Text messages. Email. Messaging platforms. In the period before, during, and after a patient event, those communications frequently contain what the clinical record does not: what the provider actually knew, what they told colleagues, what they were concerned about, and what they chose not to document.

We collect and analyze provider communications in malpractice matters as a matter of routine. Deleted text messages can be recovered from the provider’s device. Deleted emails can be recovered from the server or from the cloud environment. Communication timestamps establish what the provider knew and when, which is often the most consequential factual question in the case.

We have examined cases in which a provider deleted communications from a device in the period following a patient event. That deletion does not necessarily eliminate the evidence — like a deleted file, it is gone to the user but still there to anyone who knows where to look — but it does create its own set of questions about what the provider was trying to remove and why.

Was the provider where they were supposed to be

Cell phone location data and Call Detail Records can establish where a provider’s device was during a critical treatment window. Was the attending physician in the facility? Was the nurse at the station or elsewhere in the building? Was the responding provider distracted by their phone at the time an alert was issued?

We have analyzed CDR and device location data in healthcare matters where the patient’s claim depended on whether the provider was present and attentive. Location data does not always answer that question definitively, but when it does, it is among the most difficult evidence in the case to dispute. Towers do not misremember. GPS logs do not forget.

See also: Cell Record Analysis.

Prior safety record and internal communications

Facilities that know about a safety problem before a patient event have often documented that knowledge — in emails, in internal messaging, in incident reports, in administrative communications that were never intended to become evidence. Finding those communications requires knowing where to look and how to collect them forensically.

We have worked matters in which the key evidence was not what happened to the plaintiff but what the facility had been told about similar problems before. That prior knowledge changes the character of the negligence claim and the damages calculation. It also tends to be the evidence that facilities most want to suppress and least effectively do so.

Incident reports are a specific area of concern. We examine the metadata of incident reports as a matter of course — when the document was created, when it was last modified, what the edit history shows. An incident report that was created two days after the event and backdated is not documentation. It is a problem. We find those problems.

When an incident report is produced as a PDF, preserving the native file can be essential to a defensible forensic report.

Data retention claims

Hospitals and medical facilities operate under data retention policies. When evidence is unavailable because it was destroyed, the question is whether the destruction was a routine operation of those policies or whether evidence was destroyed after the obligation to preserve it arose.

We have examined facilities’ claims that records were unavailable due to routine retention policies. In a number of those cases, the forensic record of the system itself contradicted those claims — showing targeted deletion activity rather than automated policy execution, or showing that the retention policy was selectively applied. A policy does not create immunity from a spoliation argument when the forensic evidence shows intentional removal.

See also: Cloud Analysis and Preservation for how cloud-based EHR and communications data can be preserved before litigation begins.

If you represent the patient or their family

The digital evidence most useful to you is often the evidence the facility assumed would not be found. The modified chart entry. The deleted provider communication. The incident report created after the fact. The internal email acknowledging the problem before your client was harmed.

We collect from the EHR system’s underlying database. We image provider devices and recover deleted communications. We request and analyze the audit trail that shows what the record looked like before it was changed. We find the internal communications the facility did not produce in discovery.

When we find evidence that the facility’s record has been altered or that communications were deleted, we document it in a form that holds up in court. Those findings do not require the jury to trust anything except the data.

If you represent the provider or facility

The same forensic tools that surface problems in a case where the record was altered confirm the record’s integrity in a case where it was not. If your client documented care accurately and contemporaneously, the audit log shows that. If the provider’s communications show nothing beyond routine clinical discussion, that record is available and presentable.

We also examine the patient-side evidence that plaintiffs introduce. Wearable device data, health app records, and personal communications from the patient’s own devices can establish the patient’s condition before and after the alleged event in ways that contradict the damages timeline. We have worked cases in which the patient’s own iPhone Health database and wearable records materially changed the damages picture.

If the plaintiff’s theory of the case requires a timeline that the data does not support, we find the places where it does not support it.

Case types we handle

  • Nursing home neglect and elder abuse matters requiring EHR audit log analysis and communication review
  • Surgical and procedural error cases where chart modification is at issue
  • Emergency department matters requiring provider location and response time analysis
  • Hospital administration and staffing cases where internal communications establish prior knowledge
  • Wrongful death in clinical settings requiring wearable and health data analysis
  • Cases requiring incident report authenticity review and metadata examination

Related services and litigation support

Contact Cyber Agents to discuss whether medical malpractice fits your matter.

Free consultation

Talk to an examiner before the evidence moves.

Digital evidence degrades, overwrites and expires. The earlier we are involved, the more of it survives to be examined.