Epic dismisses SelfRx from patient records lawsuit

Advertisement

Epic Systems and four health systems have voluntarily dismissed their claims against SelfRx, doing business as Myself.Health, in a case that has put national patient data interoperability frameworks under scrutiny since January.

The June 3 filing, submitted in the U.S. District Court for the Central District of California, comes alongside a sworn declaration from Martin Hensel, founder and managing member of SelfRx, in which he disputes the core premise of the allegations against his company.

The complaint alleged SelfRx used intermediary broker Unit 387 and Health Gorilla to pull more than 100,000 patient records through the Carequality interoperability framework. Mr. Hensel said the actual number was fewer than 100.

“During the lifetime of SelfRx’s connection to the Carequality framework, SelfRx requested medical records for only 21 patients and received records for 15 of those patients, for a total record count of fewer than 100 records for these 15 patients,” Mr. Hensel stated in the declaration.

He also said SelfRx had no knowledge of the broader pattern described in Epic’s complaint and denied authorizing any other entity to pull records on its behalf.

“SelfRx never provided authority or permission to Meredith Manak, Unit 387, Health Gorilla, or any other entity or person to request patient records from the Carequality framework on SelfRx’s behalf,” the declaration states. “I do not know who took those over 100,000 patient records.”

SelfRx is no longer in business. Mr. Hensel said the company shut down its servers in February 2025, ceased operations entirely in March 2025 and filed a certificate of cancellation with the Massachusetts Corporations Division in December 2025.

The underlying lawsuit, filed Jan. 13, names Health Gorilla, Unit 387 and more than a dozen other defendants. It alleges that Health Gorilla, as an on-ramp to Carequality and the Trusted Exchange Framework and Common Agreement, or TEFCA, enabled multiple health tech companies to fraudulently access nearly 300,000 patient records from Epic’s provider customers, including Trinity Health in Livonia, Mich., Reid Health in Richmond, Ind., and UMass Memorial Health in Worcester, Mass., as well as OCHIN’s healthcare provider customers.

The complaint alleges the records were pulled under the pretense of treatment but were funneled to law firms assembling mass tort lawsuits.

The dismissal of SelfRx is the second resolution to emerge from the case. In March, Epic reached a stipulated judgment with GuardDog Telehealth, another named defendant, permanently barring it from Carequality and TEFCA and requiring it to delete any patient health information obtained through those networks. GuardDog admitted in that filing that its business focused on requesting and summarizing medical records and providing them to law firms, rather than providing clinical care.

Health Gorilla has contested the lawsuit. The company filed a motion to dismiss in February, arguing Epic bypassed mandatory dispute resolution procedures and that the fraud claims require showing actual knowledge of wrongdoing — a standard the company said the complaint does not meet.

Health Gorilla CEO Bob Watson has called the lawsuit “the equivalent of shouting ‘fire’ in the middle of a crowded theater” and framed it as an attack on interoperability rather than a good-faith effort to protect patient privacy.

Epic has pushed back on that framing.

“Medical records are deeply personal and exploiting them is wrong,” an Epic spokesperson said in a statement to Becker’s. “In its motion, Health Gorilla asserts it should be dismissed as a defendant in the lawsuit because it had a ‘lack of actual knowledge’ of wrongdoing. That is not an acceptable reason — Health Gorilla had a responsibility to safeguard sensitive patient data and know why it was being taken.”

The case touches broader fault lines in health data interoperability. Carequality and TEFCA together support the exchange of roughly 1 billion clinical documents each month. Any provider that participates in either framework makes patient data available to other participants for treatment purposes, and technology implementers like Health Gorilla control which entities are permitted to enter those networks.

According to Epic’s original complaint, some defendants used clinical-sounding company names to conceal their actual purpose, a practice the company described as “clinical camouflage.” The complaint also described a pattern in which companies banned from the frameworks for misuse would dissolve and reemerge under different names to continue accessing records.

In his declaration, Mr. Hensel acknowledged that SelfRx’s connection to Carequality was published in a directory accessible to other framework participants and that neither Unit 387 nor Health Gorilla had SelfRx execute the required Carequality Connection Terms before it began participating in the network.

The dismissal was filed with prejudice, meaning Epic and the other plaintiffs cannot refile claims against SelfRx. The case against the remaining defendants is ongoing.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

Designing the intelligent hospital: Building hospitals around people, data and care

Tuesday, July 21
12:00 PM - 1:00 PM CDT

Presenters: Braheem Santos, Schneider ElectricJohn Donohue, Penn Medicine

Advertisement

Next Up in EHRs / Interoperability

Advertisement