Almost no one can delete items from a medical record. Federal law and industry practice treat the chart as a permanent legal document, so the standard response to a wrong entry is to amend or correct it while the original stays visible. The only situation where something closer to deletion is even on the table is when data was filed in the wrong patient’s chart entirely. Outside that narrow case, patients, providers, and records custodians all operate under the same rule: add corrections, never erase.
Why the Record Cannot Simply Be Edited Away
A medical record does several jobs at once. It guides future clinical decisions, supports insurance claims, and functions as evidence in malpractice suits, audits, and fraud investigations. Deleting an entry breaks the chain of evidence that courts, regulators, and later treating providers rely on. That is why record integrity is treated as non-negotiable across the healthcare industry.
When a provider discovers an error, the expected response is correction, not removal. The original entry stays. A new note is added explaining what was wrong, what the accurate information is, who made the change, and when. Even information a patient finds embarrassing or disagrees with cannot be deleted if it is clinically accurate. The record reflects what the provider observed and documented at the time, and that documentation carries legal weight whether or not the patient likes what it says.
The One Narrow Exception: Wrong-Patient Entries
The one situation where something like deletion can happen is when clinical data ends up in the wrong person’s chart. If lab results, notes, or orders meant for one patient are attached to a different patient’s record, leaving that information in place creates a real safety risk, because a future provider might act on data that has nothing to do with the patient in front of them.
Even here, best practice stops short of permanently destroying the data. The recommended approach is to remove the erroneous information from the visible record while preserving it in the background through system versioning or metadata, so it can be retrieved if needed. Organizations are advised to avoid electronic health record systems that allow total elimination of documentation, because any deletion needs to remain traceable.1AHIMA Journal. Deleting Errors in the EHR If a system does permit full deletion, audit trails must capture the user’s identity, the specific document affected, a description of what was deleted, and the date and time of the action.
How Providers Actually Correct Errors
The mechanics depend on whether the chart is on paper or electronic. For paper records, the accepted practice is to draw a single line through the incorrect entry so the original text stays legible. The person making the change dates, times, and signs or initials it, and writes the correct information nearby. Whiting out, erasing, or otherwise obscuring the original is never acceptable, because it looks like an attempt to hide something.
Electronic health records handle corrections through addenda and versioning. When a provider corrects an entry, the system appends the new information while preserving the original in an audit log. Federal certification standards require EHR audit logs to record who made each change and when, and those logs cannot be altered, overwritten, or deleted by the software itself.2Centers for Medicare & Medicaid Services (CMS). Stage 2 Core Measures – Protect Electronic Health Information That tamper-resistant design is what makes electronic records defensible in court and during regulatory reviews.
Your Right to Request an Amendment
Under HIPAA, you have the right to ask a healthcare provider or health plan to amend information in your record if you believe it is inaccurate or incomplete.3HHS.gov. Your Rights Under HIPAA This is not a right to have anything deleted. It is a right to have a correction appended so that anyone reading the record sees the updated information alongside the original.
The request generally needs to be in writing and should explain why you believe the information is wrong. The provider then has 60 days to act on it, with a possible 30-day extension if they notify you in writing of the delay and give a specific completion date.4eCFR. 45 CFR 164.526 – Amendment of Protected Health Information If the provider accepts the amendment, they must append the correction to your record and make reasonable efforts to notify anyone who previously received the incorrect information, including business associates such as health information exchanges.5HHS.gov. Health Information Technology and HIPAA – Correction
When an Amendment Request Can Be Denied
Providers do not have to accept every request. Under 45 CFR 164.526, a covered entity may deny an amendment request on any of four grounds:
- The information was created by a different provider, and that originator is still available to handle the amendment.
- The information falls outside the designated record set used to make decisions about your care.
- The information is of a type you would not be entitled to inspect under HIPAA’s access rules.
- The provider determines the existing entry is accurate and complete as documented.4eCFR. 45 CFR 164.526 – Amendment of Protected Health Information
That last ground is where most disputes happen. A patient may feel a diagnosis is wrong, but if the provider stands behind it based on the clinical evidence, the request will be denied.
When a request is denied, the provider must give you a written explanation. You then have the right to submit a statement of disagreement, which gets permanently attached to your record alongside the entry you challenged. Anytime that record is disclosed in the future, your disagreement statement travels with it. The provider can also file a rebuttal to your disagreement, which likewise stays attached. This produces a documented dispute without altering the original clinical entry.
Records and Notes That Fall Outside the Amendment Process
Not everything in a provider’s files falls within HIPAA’s amendment framework. Psychotherapy notes, which are a therapist’s personal session-by-session observations kept separate from the main medical record, are excluded from the designated record set. Patients do not have a HIPAA right to access these notes, and the amendment process does not apply to them. A therapist may voluntarily share them, but HIPAA does not require it.
You do have a separate right to request restrictions on how your health information is used or disclosed. Under 45 CFR 164.522, you can ask a provider to limit disclosures for treatment, payment, or healthcare operations.6HHS.gov. Right to Request a Restriction The provider is not obligated to agree to most restriction requests. But if you paid for a service entirely out of pocket and ask the provider not to disclose that information to your health plan, the provider must honor the restriction. That gives you some control over who sees specific entries even though you cannot remove them.
What Happens to Providers Who Alter or Delete Records
Tampering with a medical record carries consequences at every level: financial penalties, criminal prosecution, and loss of licensure. The people most tempted to alter records are providers trying to cover up a mistake before litigation, and the penalties reflect how seriously regulators treat that behavior.
Civil Penalties Under HIPAA
HHS enforces a tiered penalty structure adjusted annually for inflation. As of the adjustment published in January 2026, the ranges per violation are:
- Unknowing violation: $145 to $73,011 per violation, with an annual cap of $2,190,294 for repeat violations of the same provision.
- Reasonable cause: $1,461 to $73,011 per violation, same annual cap.
- Willful neglect, corrected within 30 days: $14,602 to $73,011 per violation, same annual cap.
- Willful neglect, not corrected: $73,011 to $2,190,294 per violation, with a matching annual cap.7Federal Register. Annual Civil Monetary Penalties Inflation Adjustment
Deliberately altering or deleting records would almost certainly fall into the willful neglect category, putting the minimum penalty above $14,600 per violation and potentially reaching seven figures for a pattern of conduct.
Federal Criminal Exposure
Two federal criminal statutes apply directly to record tampering. Making false statements in connection with the delivery of or payment for healthcare services is a crime punishable by up to five years in prison.8Office of the Law Revision Counsel. 18 U.S. Code 1035 – False Statements Relating to Health Care Matters If the alteration is done to obstruct a federal investigation, the exposure jumps sharply: destroying, falsifying, or making a false entry in any record with intent to impede a federal investigation carries up to 20 years in prison.9Office of the Law Revision Counsel. 18 U.S. Code 1519 – Destruction, Alteration, or Falsification of Records in Federal Investigations and Bankruptcy
Professional Licensing Consequences
State medical boards treat record falsification as professional misconduct. The specific label varies by state, but filing a false report, making false statements in medical documents, and failing to comply with laws relating to medical records all qualify as grounds for discipline. Sanctions range from censure and mandatory retraining to suspension or outright revocation of a provider’s license. These licensing consequences often hit harder than fines because they can end a career.