Examples
Worked examples
- Is an instance
A university outpatient clinic's practice-management system recording visit notes, vitals, prescriptions, and lab orders for that clinic's own patients only -- a single-organization system that doesn't natively share data with other providers.
- Is an instance
A hospital's clinical informatics team extracting de-identified diagnosis and lab data from its EMR, under an approved IRB protocol, to build a feasibility cohort for a proposed retrospective study.
Counter-examples
Looks similar, but isn't
- Not an instance
A regional health information exchange (HIE) platform that lets authorized clinicians at multiple unaffiliated hospitals and clinics pull up a shared patient summary -- this is EHR-class, interoperable-by-design infrastructure, not an EMR, because cross-organization exchange is exactly the capability an EMR lacks.
Editorial commentary
An electronic medical record (EMR) is a digital version of the paper charts kept in a clinician’s office or a hospital department — the medical and treatment history of patients as recorded, stored, and used by one practice or healthcare organization. The Office of the National Coordinator for Health Information Technology (ONC), the U.S. federal agency responsible for health IT policy, draws a precise and commonly conflated distinction between EMR and its close relative, the electronic health record (EHR): an EMR’s data “doesn’t travel easily out of the practice,” while an EHR is built specifically to be “created, managed, and consulted by authorized clinicians and staff across more than one healthcare organization,” reaching beyond the organization that originally compiled it to share information with labs, specialists, and other members of a patient’s care team. In practice the terms are used loosely and often interchangeably in casual conversation and even in vendor marketing, but the operational distinction — single-organization clinical record versus multi-organization interoperable record — is the one that matters when a research administrator has to reason about what data a given system can and cannot supply, and under what governance.
Why this distinction matters for research administration
EMR data is increasingly used as a source outside its original clinical-care purpose, and each of those secondary uses carries governance implications specific to research administration:
- Recruitment and eligibility screening. Study teams increasingly query EMR data (diagnosis codes, lab values, medication lists, encounter history) to identify patients who may meet a protocol’s inclusion/exclusion criteria before any research-specific contact occurs. Because this uses a clinical-care record for a research purpose, it typically requires a defined institutional pathway — often a limited IRB review, an honest-broker or data-warehouse recruitment protocol, and a HIPAA authorization or waiver — rather than being treated as routine clinical activity.
- Real-world evidence (RWE) studies. The FDA’s Real-World Evidence framework explicitly names electronic health records among the real-world data (RWD) sources that can support regulatory decisions when analyzed as real-world evidence. FDA’s guidance Real-World Data: Assessing Electronic Health Records and Medical Claims Data To Support Regulatory Decision-Making for Drug and Biological Products (finalized July 2024, following a September 2021 draft) sets out considerations for data reliability and relevance when a sponsor proposes using EHR/EMR-sourced data in a study intended to support a regulatory submission — a fundamentally different evidentiary bar than data captured purpose-built for a trial.
- HIPAA and IRB considerations distinct from purpose-built research systems. An EMR is, by definition, a covered entity’s clinical system holding Protected Health Information (PHI) under HIPAA. Pulling data out of it for research — even for a single retrospective chart review — triggers the same HIPAA Privacy Rule and IRB (Institutional Review Board) review pathways that apply to any human-subjects use of PHI, and frequently requires de-identification or a documented limited data set/data use agreement before the data can move into a study database. This is a materially different compliance posture than data entered directly into a purpose-built research system, where consent and data-collection scope are usually defined by the protocol from the outset. See also HIPAA in Clinical Research for how these Privacy Rule pathways apply specifically to trial contexts.
EMR vs. EDC: two different systems, often confused
Research administrators should not conflate an EMR with an EDC (electronic data capture) system such as REDCap. An EMR is a clinical-care record, built and governed by a healthcare organization to document and support patient treatment; the organization that operates it is a HIPAA covered entity, and its primary legal and workflow purpose is care delivery. An EDC system is a purpose-built research data-capture platform, built and governed by a study team or sponsor specifically to collect protocol-defined data points for a clinical trial or other research study, typically under 21 CFR Part 11 electronic-records controls when the study supports an FDA submission. A single research participant may generate data in both systems for the same study — their EMR holds the ongoing clinical record of their care, while the study’s EDC system holds only the discrete, protocol-specified data points a case report form calls for, often transcribed or abstracted from the EMR by study staff. Confusing the two is a common but consequential error: it can lead a study team to assume an EMR extract is already research-ready (it usually needs cleaning, de-identification, and mapping to a data dictionary) or, conversely, to treat an EDC dataset as a full clinical record it was never designed to be.
Worked examples
Example 1 — single-practice EMR. A university-affiliated outpatient clinic uses a practice-management system to record visit notes, vitals, prescriptions, and lab orders for its own patients. The data lives on the clinic’s own server/EHR-vendor instance, is used to support that clinic’s care decisions, and does not automatically appear in a patient’s record at a hospital across town unless a separate interface or health information exchange connection is built. This is a textbook EMR: single-organization scope, not natively interoperable.
Example 2 — EMR data repurposed for research. A hospital’s clinical informatics team extracts de-identified diagnosis and lab data from its EMR to build a feasibility cohort for a proposed retrospective study, under an approved IRB protocol and a documented honest-broker process. The source system is still an EMR (the extraction doesn’t change what the underlying system is) — what has changed is the governance layer applied to a secondary use of that clinical data.
Counter-example — not an EMR. A regional health information exchange (HIE) platform that aggregates records from multiple unaffiliated hospitals and clinics so that any authorized provider in the network can pull up a shared patient summary is an EHR-class system, not an EMR, precisely because it is built for structured exchange across organizations — the defining feature an EMR lacks.
Related CASRAI terms
- REDCap (Research Electronic Data Capture) — a real EDC platform, distinct from an EMR
- HIPAA (Health Insurance Portability Act)
- HIPAA in Clinical Research
- IRB (Institutional Review Board)
- De-identification
- 21 CFR Part 11: Electronic Records & Signatures
- Clinical Trial Patient Recruitment: Methods, Screening, and Enrollment
- Clinical Research Administration (cluster pillar)
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="Electronic Medical Record (EMR)"
vocab-term-identifier="https://casrai.org/dictionary/term/electronic-medical-record-emr" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/electronic-medical-record-emr",
"name": "Electronic Medical Record (EMR)",
"identifier": "https://casrai.org/dictionary/term/electronic-medical-record-emr",
"description": "An electronic medical record (EMR) is the digital equivalent of a single healthcare provider's paper chart: a patient's medical and treatment history as captured, stored, and used within one clinical practice or healthcare organization. An artifact is an EMR (rather than an EHR) when its data model, access controls, and interoperability are scoped to a single organization's internal clinical workflow, not designed for structured exchange with external providers, payers, or research systems -- even if the underlying software vendor also sells EHR-branded products elsewhere.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
"url": "https://casrai.org/dictionary/term/electronic-medical-record-emr",
"sameAs": [],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"dateModified": "2026-07-17T17:22:56",
"inLanguage": "en"
}






