9.5 Information Blocking Rules, 21st Century Cures Act & Compliance Audits

Key Takeaways

  • The 21st Century Cures Act prohibits Information Blocking to ensure immediate, unhindered access to Electronic Health Information (EHI).
  • Regulated actors include healthcare providers, certified health IT developers, and health information exchanges (HIEs).
  • Ten regulatory exceptions authorize withholding EHI or altering fulfillment procedures under strict conditions, grouped into not fulfilling requests, procedures for fulfilling requests, and TEFCA participation.
  • HHS OCR conducts desk and on-site compliance audits across Privacy, Security, and Breach Notification Rules.
  • Civil monetary penalties run in four culpability tiers that HHS adjusts for inflation annually; for 2026 the top calendar-year cap is $2,190,294.
Last updated: August 2026

Information Blocking Rules, 21st Century Cures Act & Compliance Audits

The 21st Century Cures Act & Interoperability Mandate

Enacted by Congress and administered by the Assistant Secretary for Technology Policy / Office of the National Coordinator for Health Information Technology (ASTP/ONC), with enforcement authority at the HHS Office of Inspector General (OIG), the 21st Century Cures Act established sweeping rules to eliminate data silos, drive health IT interoperability, and guarantee patients immediate access to their Electronic Health Information (EHI) without delay or artificial fee barriers.

Information Blocking Defined

Information Blocking is defined as any practice by a regulated actor that is likely to interfere with, prevent, or materially discourage the access, exchange, or use of Electronic Health Information (EHI), when the actor knows (or, for IT developers and HIEs, should know) that such practice is unreasonable.

Regulated Actors Under Information Blocking Rules

  1. Healthcare Providers: Hospitals, physicians, clinics, skilled nursing facilities.
  2. Health IT Developers of Certified Health IT: EHR software vendors maintaining ONC-certified products.
  3. Health Information Exchanges (HIEs) / Health Information Networks (HINs): Regional or national data sharing networks.

Mandated Data Access: Standardized APIs (FHIR)

Actors must support EHI exchange using standardized Fast Healthcare Interoperability Resources (FHIR) Application Programming Interfaces (APIs). Provider policies that artificially delay releasing laboratory results, clinical notes, or imaging reports to patient portals constitute illegal Information Blocking.


The 10 Regulatory Exceptions to Information Blocking

On behalf of HHS, ASTP/ONC has defined ten regulatory exceptions, codified at 45 CFR part 171, where withholding EHI or altering fulfillment procedures does not constitute illegal information blocking. They fall into three groups.

Category 1: Exceptions Involving Not Fulfilling Requests for EHI

Exception NameStatutory CriteriaClinical / Operational Scenario
1. Preventing Harm ExceptionThe actor holds a reasonable belief that withholding EHI will substantially reduce a risk of physical harm to the patient or another person.Temporarily withholding psychiatric notes when a physician determines immediate release poses a severe risk of self-harm.
2. Privacy ExceptionWithholding EHI is necessary to comply with state or federal privacy laws (e.g., mandatory patient consent rules).Refusing to release adolescent reproductive health records without explicit minor consent mandated by state law.
3. Security ExceptionAction taken to safeguard the confidentiality, integrity, or availability of EHI under HIPAA Security Rule protocols.Blocking access from an IP address actively launching a cyberattack or brute-force credentials assault.
4. Infeasibility ExceptionFulfilling the request is unfeasible due to uncontrollable events (disaster), technical impossibility, or inability to reach content agreement.Server infrastructure destroyed by a natural disaster rendering historical record retrieval temporarily impossible.
5. Health IT Performance ExceptionTemporarily degrading or disabling health IT systems for necessary system maintenance, upgrades, or repairs.Scheduled EHR system maintenance window occurring overnight with advance notice.
6. Protecting Care Access ExceptionAdded at 45 CFR 171.206 by the HTI-3 final rule (published December 17, 2024). Applies where the actor holds a good faith belief that sharing specific EHI could expose a person who seeks, obtains, provides, or facilitates lawful reproductive health care to legal action, and that restricting the sharing could reduce that risk.Restricting release of records of lawfully furnished reproductive health care where disclosure could expose the patient or the treating clinician to legal action.

Category 2: Exceptions Involving Procedures for Fulfilling Requests for EHI

Exception NameStatutory CriteriaOperational Scenario
7. Manner ExceptionEstablishes the manner in which an actor must fulfill a request; permits fulfilling in an alternative manner when the requested manner is not possible or agreeable terms cannot be reached.Fulfilling a request using a standard C-CDA export when a custom proprietary format is unavailable.
8. Fees ExceptionAuthorizes charging reasonable, cost-based fees for EHI exchange (non-discriminatory and legally permitted).Charging standard developer API access fees aligned with ONC fee rules.
9. Licensing ExceptionPermits licensing health IT interoperability elements on Fair, Reasonable, and Non-Discriminatory (FRAND) terms.Licensing software interface code under fair market terms.

Category 3: Exception Involving Participation in TEFCA

Exception NameStatutory CriteriaOperational Scenario
10. TEFCA Manner ExceptionEstablished by the HTI-1 final rule. Where the actor and the requestor are both part of the Trusted Exchange Framework and Common Agreement (TEFCA), the actor may fulfill certain requests only via TEFCA, provided the requestor is capable of TEFCA exchange, the request is not made using HL7 FHIR standards, and the Fees and Licensing Exceptions are satisfied.A hospital that is a TEFCA participant routes a query-based request from another TEFCA participant exclusively through the network.

Watch this one. In the HTI-5 proposed rule published December 29, 2025, ASTP/ONC proposed removing the TEFCA Manner Exception on the grounds that it is no longer needed to incentivize TEFCA participation and has been misapplied. As of August 2026 that rule is still a proposal and 45 CFR 171.403 is still in force, so ten exceptions remain in effect. Verify the current count against the ASTP/ONC information blocking exceptions fact sheet before relying on it.


OCR Compliance Audits & Enforcement

The HHS Office for Civil Rights (OCR) conducts compliance audits of Covered Entities and Business Associates. Audits evaluate adherence to Privacy, Security, and Breach Notification Rules via two formats:

  • Desk Audits: Document reviews examining written policies, risk analysis reports, employee training logs, and BAAs submitted electronically.
  • On-Site Audits: Physical inspections of facilities, server rooms, workstation setups, and staff interviews.

HIPAA Civil Monetary Penalty (CMP) Tier Structure

Violations of HIPAA regulations incur Civil Monetary Penalties enforced by HHS OCR based on culpability level:

Penalty TierCulpability StandardMinimum Per ViolationMaximum Per ViolationAnnual Cap OCR Applies
Tier 1: Did Not KnowViolation occurred despite exercising reasonable diligence; entity did not know and could not have known.$145$73,011$36,505
Tier 2: Reasonable CauseEntity knew or should have known with reasonable diligence; not willful neglect.$1,461$73,011$146,053
Tier 3: Willful Neglect (Corrected)Conscious, intentional failure or reckless indifference; corrected within 30 days of discovery.$14,602$73,011$365,052
Tier 4: Willful Neglect (Uncorrected)Conscious, intentional failure or reckless indifference; NOT corrected within 30 days of discovery.$73,011$2,190,294$2,190,294

Read the last two columns carefully, because this is where secondary sources get it wrong. The underlying statutory amounts come from the HITECH Act ($100 / $1,000 / $10,000 / $50,000 minimums against a $1.5 million annual cap), and HHS adjusts every figure for inflation each year; the amounts above apply to penalties assessed on or after January 28, 2026. The codified calendar-year cap at 45 CFR 102.3 is $2,190,294 for all four tiers. The lower per-tier caps in the final column are not statutory — they come from OCR's 2019 Notification of Enforcement Discretion, under which OCR voluntarily limits annual exposure by culpability so that only Tier 4 faces the full calendar-year maximum. Because every one of these numbers moves annually, learn the four-tier structure and the 30-day correction rule, which do not change, rather than memorizing dollar figures.

Criminal Penalties (DOJ Enforcement)

Knowing theft or misuse of PHI for commercial advantage, personal gain, or malicious harm is prosecuted criminally by the Department of Justice (DOJ), incurring fines up to $250,000 and up to 10 years imprisonment.

Test Your Knowledge

A physician temporarily holds back a patient's diagnostic results because releasing them immediately would pose a substantial risk of physical harm to the patient. Which Information Blocking exception applies?

A
B
C
D
Test Your Knowledge

A covered entity committed a HIPAA Security Rule violation due to intentional reckless indifference (willful neglect) and failed to take any corrective action within 30 days of discovery. Under which penalty tier will HHS OCR assess fines?

A
B
C
D
Test Your Knowledge

What technological standard is mandated by the 21st Century Cures Act for data access via Application Programming Interfaces (APIs)?

A
B
C
D