In UNITED STATES OF AMERICA ex rel. Alex Permenter, Chris Wheeler, and Eric Rodighiero, Plaintiffs/Relators v. eClinicalWorks, LLC. UNITED STATES DISTRICT COURT FOR THE MIDDLE DISTRICT OF GEORGIA, MACON DIVISION. Case No. 5:18-CV-382, a Qui Tam False Claims Act case.
Electronic Health Record Certification Expert, Privacy and Security
On June 4, 2025 U.S. District Judge Marc T. Treadwell DENIED Defendant’s motion to exclude the opinions of Relator’s Expert Michael Arrigo. Expert scope: Electronic Health Record certification standards, with focus on the privacy and security E.H.R. Certification Standards as set forth in 42 CFR 315 – ONC certification criteria:
- 170.315 (d)(1) Authentication, access control, authorization
- 170.315 (d)(2) Auditable Events and Tamper-Resistance
- 170.315 (d)(3) Audit Reports
- 170.315 (d)(4) Amendments
- 170.315 (d)(5) Automatic Access Timeout
- 170.315 (d)(6) Emergency Access
- 170.315 (d)(7) End-user Device Encryption
- 170.315 (d)(8) Integrity
- 170.315 (d)(9)(ii) Trusted Connection when transporting ePHI
- 170.315 (d)(11) Accounting of Disclosures
- 170.315 (d)(12) Encrypt Authentication Credentials
The Kennedy-Kassebaum Act of 1996, better known as the Health Insurance Portablity and Accountability Act or HIPAA and the Health Information Technology for Economic and Clinical Health (HITECH) Act, enacted in 2009, is a U.S. law designed to promote the adoption and meaningful use of health information technology, particularly electronic health records (EHRs). It also strengthened privacy and security protections for electronic protected health information (ePHI), building upon and expanding the HIPAA (Health Insurance Portability and Accountability Act).