Press Release

Healthcare Providers and Epic Act to Safeguard Patients’ Health Information

Federal lawsuit targets companies that exploit confidential patient records for profit

VERONA, Wis. , Jan. 13, 2026 /PRNewswire/ — Today, Epic and a group of healthcare providers are taking legal action to defend patient privacy and protect sensitive medical information.

The lawsuit states that Health Gorilla, a health information network, enabled Mammoth, RavillaMed, and other companies to improperly access and monetize nearly 300,000 patient medical records from members of the Epic community. This is in addition to an unknown number of records taken from organizations nationwide, including from the VA and providers using other EHRs.

OCHIN, Reid Health, Trinity Health, UMass Memorial Health, and Epic have filed suit to stop conduct that threatens patient privacy and the integrity of care. The filing cites misconduct including that the defendants:

  • “Operate as organized syndicates to monetize patient records without patients’ knowledge or consent.”
  • “Request patient records for the purpose of treating patients but take patient records for other purposes including to market them to lawyers looking for potential claimants … to join mass tort or class action lawsuits.”
  • “Obscure their true purpose through fictitious websites, shell entities, and sham National Provider Identification (NPI) numbers … to create an illusion of legitimate patient treatment activity.”
  • Cover their tracks by inserting junk data into patient medical records “to give the false impression that they are treating patients, which risks patient safety and wastes valuable clinician time.”

The lawsuit continues, “when caught, rather than stopping their activity, the bad entity owners, operators and those in their inner circles simply create new companies. The scheme thus operates like a Hydra: when one fraudulent entity is exposed, the bad actors birth a new one” and “if not stopped, they will continue to inappropriately market the patient data they have already taken and will take more.”

“At stake are both the protection of medical records that contain some of a person’s most sensitive data, such as genetic, mental wellbeing, and reproductive information, and the ability of physicians to keep their promises to patients that their information will be kept private.”

“These actors are putting the enormous positive patient outcomes achieved through interoperability at imminent risk,” the legal filing explains. “When used appropriately, interoperability ensures that medical care is informed by a patient’s medical history, allowing healthcare providers to improve patient outcomes.”

Epic is a global healthcare software company that helps people get well, helps people stay well, and helps future generations be healthier. Founded in a basement in 1979 with three half-time employees, Epic is now the leading EHR software developer in the United States. Epic supports healthcare organizations in 16 countries, with more than 3,400 hospitals using Epic and over 195 million patients using Epic’s MyChart patient portal to manage their care online.

Contact: [email protected]

Cision View original content to download multimedia:https://www.prnewswire.com/news-releases/healthcare-providers-and-epic-act-to-safeguard-patients-health-information-302659956.html

SOURCE Epic

Author

Leave a Reply

Related Articles

Back to top button