The Health Gorilla lawsuit is a January 2026 federal case in which Epic Systems and four healthcare organizations accuse health information network Health Gorilla of enabling a group of companies to pose as healthcare providers, pull nearly 300,000 patient medical records through national interoperability frameworks, and funnel that data to law firms recruiting plaintiffs for mass tort litigation.1Healthcare Dive. Epic, Health Systems Sue Health Gorilla Over Improper Medical Records Access The suit was filed in the U.S. District Court for the Central District of California and is assigned to Judge Fernando M. Olguin.2CourtListener. Epic Systems Corporation v. Health Gorilla, Inc.
What Epic Says Was Happening
The complaint describes an organized effort to exploit the trust that makes health data interoperability work. Frameworks like Carequality and TEFCA, the federal Trusted Exchange Framework and Common Agreement created under the 21st Century Cures Act, operate on the premise that when a provider requests a patient’s records for treatment, the request is legitimate and should be honored.3Fierce Healthcare. Epic’s Lawsuit Against Health Gorilla Raises Broader Issues About Future of Data Sharing
According to the plaintiffs, the defendants weaponized that assumption. Companies allegedly presented themselves as healthcare providers using fictitious websites, shell entities, and sham National Provider Identification numbers. They connected to interoperability networks through Health Gorilla and requested patient records under the banner of treatment. Instead of providing care, the complaint alleges, they harvested the data and marketed it to law firms looking for potential claimants in mass tort and class action cases.4Epic. What You Put Up With Is What You Stand For5Courthouse News. Health Care Software Service Accuses Competitor of Enabling Fraud
To keep up the appearance of active treatment, the defendants allegedly inserted “junk data” into patient records: documents with no real clinical content that simulated the back-and-forth of a treatment relationship. The plaintiffs say this cluttered medical records and wasted clinician time.4Epic. What You Put Up With Is What You Stand For
The complaint compares the operation to a Hydra. When one entity was exposed and cut off, the same operators allegedly stood up new companies to continue the same activity.6MedCity News. Epic Health Gorilla Lawsuit Data1Healthcare Dive. Epic, Health Systems Sue Health Gorilla Over Improper Medical Records Access7ISMG. Epic Systems v. Health Gorilla Complaint
Who Is Being Sued, and Why Health Gorilla Sits at the Center
Health Gorilla is the lead defendant. It is a health information network with a dual federal and state designation, serving as a Qualified Health Information Network under TEFCA and a Qualified Health Information Organization under California’s Data Exchange Framework.8Health Gorilla. Health Gorilla QHIN Its infrastructure lets clients query patient records across the hundreds of thousands of providers connected to networks like Carequality, CommonWell, and the eHealth Exchange. That intermediary role is what puts it at the center of the case: the plaintiffs allege Health Gorilla failed to adequately vet the companies it onboarded and ignored red flags that those companies were not actually treating patients.9HIPAA Journal. Epic Sues Health Information Exchange Network Over Improper Record Access
Alongside Health Gorilla, the complaint names a set of companies that allegedly used it as an on-ramp to patient records, including RavillaMed, LlamaLab, three Mammoth-branded entities, SelfRx, GuardDog Telehealth, Unit 387, and Hoppr, along with several of their founders and executives.2CourtListener. Epic Systems Corporation v. Health Gorilla, Inc.7ISMG. Epic Systems v. Health Gorilla Complaint10WorkComp Academy. Companies Allegedly Sell EHR Data to Mass Tort Plaintiff Lawyers
The four healthcare co-plaintiffs are OCHIN, Reid Health, Trinity Health, and UMass Memorial Health, whose patient records were allegedly among those improperly accessed. They joined to protect patient privacy and, they say, to stop conduct that threatens the interoperability ecosystem itself, with some providers reportedly considering withdrawing from data-sharing networks over the alleged abuses.3Fierce Healthcare. Epic’s Lawsuit Against Health Gorilla Raises Broader Issues About Future of Data Sharing
The Legal Claims and What Epic Wants
The plaintiffs assert five causes of action: fraud, aiding and abetting fraud, breach of contract, violations of the California Business and Professions Code, and violations of the federal Computer Fraud and Abuse Act.11Healthcare IT News. Epic and Health Systems Sue Health Gorilla and Data Companies They are asking for a jury trial, an injunction against further conduct of the kind alleged, and disgorgement of the defendants’ profits.5Courthouse News. Health Care Software Service Accuses Competitor of Enabling Fraud
How the Defendants Have Responded
Health Gorilla has denied all allegations. In a January 27, 2026 statement, CEO Bob Watson called the complaint “unfounded and wholly misleading” and “categorically” rejected it, describing the suit as an “irresponsible use of litigation as a weapon” and part of a broader pattern of exclusionary behavior by Epic in health data exchange.12PR Newswire. Health Gorilla Releases Statement in Response to Epic Lawsuit The company said it suspended the connections at issue and began investigating as soon as it learned of the allegations.13MedCity News. Epic Health Gorilla Lawsuit Interoperability Data
Health Gorilla, represented by Quinn Emanuel Urquhart & Sullivan, filed a motion to dismiss. Its main arguments: Epic failed to exhaust mandatory dispute resolution under the Carequality agreement; Epic lacks enforceable contract rights against Health Gorilla; the fraud claims lack specificity; the aiding-and-abetting claims allege only that Health Gorilla “should have known” rather than actually knew of fraud; and Epic’s claimed damages are voluntary investigation costs, not actual injuries.1Healthcare Dive. Epic, Health Systems Sue Health Gorilla Over Improper Medical Records Access
LlamaLab and founder Shere Saidon have also denied the allegations. In a February 26, 2026 press release, Saidon said, “We have never sold, stolen, or misused patient data, and we never will,” and called the lawsuit an attempt by “a market-dominant player to crush potential competition.” LlamaLab filed motions to dismiss and to sever, arguing Epic improperly lumped it in with more than a dozen unrelated defendants, and stated it is not a member of the Carequality or TEFCA networks at the heart of the complaint.14LlamaLab. LlamaLab Asks Court to Throw Out Epic Systems Lawsuit and to Sever Unrelated Companies
What Has Happened Since the Case Was Filed
GuardDog Telehealth Admits and Exits
In March 2026, GuardDog Telehealth entered a consent agreement to exit the case. In its court filing, GuardDog admitted that since beginning operations in 2024, its business had been exclusively focused on “requesting, reviewing, and summarizing medical records, and providing those medical records to law firms,” not clinical care. It acknowledged its predecessor, Critical Care Nurse Consulting, had engaged in similar practices since 2022, and said it initially accessed Carequality through Unit 387 before later gaining direct access via Health Gorilla.15Fierce Healthcare. GuardDog Telehealth, Epic Reach Agreement in Ongoing Fraud Lawsuit Over Health Records
Under the proposed stipulated judgment, GuardDog would be permanently barred from using TEFCA or Carequality and required to delete all patient data it obtained through them. An attorney for GuardDog said the company “always maintained that it acted in good faith” and believed its activities were permissible based on conversations with Unit 387 and Health Gorilla representatives.16Becker’s Hospital Review. Epic, Health Systems File Agreement to Bar GuardDog From Health Data Networks Health Gorilla called the consent judgment “incomplete at best and misleading,” saying GuardDog never disclosed a non-treatment use to it and failed to cooperate when Health Gorilla investigated.15Fierce Healthcare. GuardDog Telehealth, Epic Reach Agreement in Ongoing Fraud Lawsuit Over Health Records
SelfRx Dismissed
In early June 2026, Epic voluntarily dismissed its claims against SelfRx with prejudice, meaning they cannot be refiled. SelfRx had ceased operations in 2025. Epic had alleged the company accessed more than 100,000 patient records, but founder Martin Hensel contested those figures, stating in written testimony that SelfRx requested records for only 21 patients, received data for 15, and never authorized Unit 387 or Health Gorilla to request records on its behalf.17Healthcare Dive. Epic Dismisses SelfRx Claims in Medical Record Misuse Lawsuit
UPMC Breach Notice
On March 13, 2026, the University of Pittsburgh Medical Center issued a privacy alert disclosing that patient records had been improperly accessed through Health Gorilla’s network under false treatment pretenses. UPMC said the accessed information included encounter lists that could contain names, dates of birth, clinical notes, diagnoses, and medical history. The breach affected 687 individuals, and UPMC reported it to the HHS Office for Civil Rights.18UPMC. Privacy and Breach Alerts19HIPAA Journal. Trinity Health, UPMC HIE Unauthorized Access
Why This Case Matters for Health Data Sharing
TEFCA and Carequality were designed to make it easy for providers to share records for patient care, but that ease depends on a trust-based model. Participants are largely expected to police themselves and honestly represent the purpose of their data requests. Industry analysts have noted that these frameworks currently lack robust real-time identity verification and enforcement tools to catch bad actors before records are accessed.13MedCity News. Epic Health Gorilla Lawsuit Interoperability Data
Epic and the health systems argue that self-policing on these networks “is not working” and that their lawsuit was necessary to fill an enforcement gap.11Healthcare IT News. Epic and Health Systems Sue Health Gorilla and Data Companies Health Gorilla and LlamaLab counter that Epic is using litigation to entrench its dominance and restrict competitors’ access to health data. The case could set precedent on whether technology intermediaries bear liability for how their clients use the data they access, and whether disputes over what qualifies as a “treatment purpose” under interoperability rules can support fraud claims or should be routed through the networks’ own governance processes.
Current Status
As of mid-2026, the case is in its early stages before Judge Fernando M. Olguin in the Central District of California, with motions to dismiss pending from Health Gorilla and LlamaLab. No substantive rulings have been issued.2CourtListener. Epic Systems Corporation v. Health Gorilla, Inc.