9.5 Information Blocking Rules, 21st Century Cures Act & Compliance Audits
Key Takeaways
- The 21st Century Cures Act prohibits Information Blocking to ensure immediate, unhindered access to Electronic Health Information (EHI).
- Regulated actors include healthcare providers, certified health IT developers, and health information exchanges (HIEs).
- Ten regulatory exceptions authorize withholding EHI or altering fulfillment procedures under strict conditions, grouped into not fulfilling requests, procedures for fulfilling requests, and TEFCA participation.
- HHS OCR conducts desk and on-site compliance audits across Privacy, Security, and Breach Notification Rules.
- Civil monetary penalties run in four culpability tiers that HHS adjusts for inflation annually; for 2026 the top calendar-year cap is $2,190,294.
Information Blocking Rules, 21st Century Cures Act & Compliance Audits
The 21st Century Cures Act & Interoperability Mandate
Enacted by Congress and administered by the Assistant Secretary for Technology Policy / Office of the National Coordinator for Health Information Technology (ASTP/ONC), with enforcement authority at the HHS Office of Inspector General (OIG), the 21st Century Cures Act established sweeping rules to eliminate data silos, drive health IT interoperability, and guarantee patients immediate access to their Electronic Health Information (EHI) without delay or artificial fee barriers.
Information Blocking Defined
Information Blocking is defined as any practice by a regulated actor that is likely to interfere with, prevent, or materially discourage the access, exchange, or use of Electronic Health Information (EHI), when the actor knows (or, for IT developers and HIEs, should know) that such practice is unreasonable.
Regulated Actors Under Information Blocking Rules
- Healthcare Providers: Hospitals, physicians, clinics, skilled nursing facilities.
- Health IT Developers of Certified Health IT: EHR software vendors maintaining ONC-certified products.
- Health Information Exchanges (HIEs) / Health Information Networks (HINs): Regional or national data sharing networks.
Mandated Data Access: Standardized APIs (FHIR)
Actors must support EHI exchange using standardized Fast Healthcare Interoperability Resources (FHIR) Application Programming Interfaces (APIs). Provider policies that artificially delay releasing laboratory results, clinical notes, or imaging reports to patient portals constitute illegal Information Blocking.
The 10 Regulatory Exceptions to Information Blocking
On behalf of HHS, ASTP/ONC has defined ten regulatory exceptions, codified at 45 CFR part 171, where withholding EHI or altering fulfillment procedures does not constitute illegal information blocking. They fall into three groups.
Category 1: Exceptions Involving Not Fulfilling Requests for EHI
| Exception Name | Statutory Criteria | Clinical / Operational Scenario |
|---|---|---|
| 1. Preventing Harm Exception | The actor holds a reasonable belief that withholding EHI will substantially reduce a risk of physical harm to the patient or another person. | Temporarily withholding psychiatric notes when a physician determines immediate release poses a severe risk of self-harm. |
| 2. Privacy Exception | Withholding EHI is necessary to comply with state or federal privacy laws (e.g., mandatory patient consent rules). | Refusing to release adolescent reproductive health records without explicit minor consent mandated by state law. |
| 3. Security Exception | Action taken to safeguard the confidentiality, integrity, or availability of EHI under HIPAA Security Rule protocols. | Blocking access from an IP address actively launching a cyberattack or brute-force credentials assault. |
| 4. Infeasibility Exception | Fulfilling the request is unfeasible due to uncontrollable events (disaster), technical impossibility, or inability to reach content agreement. | Server infrastructure destroyed by a natural disaster rendering historical record retrieval temporarily impossible. |
| 5. Health IT Performance Exception | Temporarily degrading or disabling health IT systems for necessary system maintenance, upgrades, or repairs. | Scheduled EHR system maintenance window occurring overnight with advance notice. |
| 6. Protecting Care Access Exception | Added at 45 CFR 171.206 by the HTI-3 final rule (published December 17, 2024). Applies where the actor holds a good faith belief that sharing specific EHI could expose a person who seeks, obtains, provides, or facilitates lawful reproductive health care to legal action, and that restricting the sharing could reduce that risk. | Restricting release of records of lawfully furnished reproductive health care where disclosure could expose the patient or the treating clinician to legal action. |
Category 2: Exceptions Involving Procedures for Fulfilling Requests for EHI
| Exception Name | Statutory Criteria | Operational Scenario |
|---|---|---|
| 7. Manner Exception | Establishes the manner in which an actor must fulfill a request; permits fulfilling in an alternative manner when the requested manner is not possible or agreeable terms cannot be reached. | Fulfilling a request using a standard C-CDA export when a custom proprietary format is unavailable. |
| 8. Fees Exception | Authorizes charging reasonable, cost-based fees for EHI exchange (non-discriminatory and legally permitted). | Charging standard developer API access fees aligned with ONC fee rules. |
| 9. Licensing Exception | Permits licensing health IT interoperability elements on Fair, Reasonable, and Non-Discriminatory (FRAND) terms. | Licensing software interface code under fair market terms. |
Category 3: Exception Involving Participation in TEFCA
| Exception Name | Statutory Criteria | Operational Scenario |
|---|---|---|
| 10. TEFCA Manner Exception | Established by the HTI-1 final rule. Where the actor and the requestor are both part of the Trusted Exchange Framework and Common Agreement (TEFCA), the actor may fulfill certain requests only via TEFCA, provided the requestor is capable of TEFCA exchange, the request is not made using HL7 FHIR standards, and the Fees and Licensing Exceptions are satisfied. | A hospital that is a TEFCA participant routes a query-based request from another TEFCA participant exclusively through the network. |
Watch this one. In the HTI-5 proposed rule published December 29, 2025, ASTP/ONC proposed removing the TEFCA Manner Exception on the grounds that it is no longer needed to incentivize TEFCA participation and has been misapplied. As of August 2026 that rule is still a proposal and 45 CFR 171.403 is still in force, so ten exceptions remain in effect. Verify the current count against the ASTP/ONC information blocking exceptions fact sheet before relying on it.
OCR Compliance Audits & Enforcement
The HHS Office for Civil Rights (OCR) conducts compliance audits of Covered Entities and Business Associates. Audits evaluate adherence to Privacy, Security, and Breach Notification Rules via two formats:
- Desk Audits: Document reviews examining written policies, risk analysis reports, employee training logs, and BAAs submitted electronically.
- On-Site Audits: Physical inspections of facilities, server rooms, workstation setups, and staff interviews.
HIPAA Civil Monetary Penalty (CMP) Tier Structure
Violations of HIPAA regulations incur Civil Monetary Penalties enforced by HHS OCR based on culpability level:
| Penalty Tier | Culpability Standard | Minimum Per Violation | Maximum Per Violation | Annual Cap OCR Applies |
|---|---|---|---|---|
| Tier 1: Did Not Know | Violation occurred despite exercising reasonable diligence; entity did not know and could not have known. | $145 | $73,011 | $36,505 |
| Tier 2: Reasonable Cause | Entity knew or should have known with reasonable diligence; not willful neglect. | $1,461 | $73,011 | $146,053 |
| Tier 3: Willful Neglect (Corrected) | Conscious, intentional failure or reckless indifference; corrected within 30 days of discovery. | $14,602 | $73,011 | $365,052 |
| Tier 4: Willful Neglect (Uncorrected) | Conscious, intentional failure or reckless indifference; NOT corrected within 30 days of discovery. | $73,011 | $2,190,294 | $2,190,294 |
Read the last two columns carefully, because this is where secondary sources get it wrong. The underlying statutory amounts come from the HITECH Act ($100 / $1,000 / $10,000 / $50,000 minimums against a $1.5 million annual cap), and HHS adjusts every figure for inflation each year; the amounts above apply to penalties assessed on or after January 28, 2026. The codified calendar-year cap at 45 CFR 102.3 is $2,190,294 for all four tiers. The lower per-tier caps in the final column are not statutory — they come from OCR's 2019 Notification of Enforcement Discretion, under which OCR voluntarily limits annual exposure by culpability so that only Tier 4 faces the full calendar-year maximum. Because every one of these numbers moves annually, learn the four-tier structure and the 30-day correction rule, which do not change, rather than memorizing dollar figures.
Criminal Penalties (DOJ Enforcement)
Knowing theft or misuse of PHI for commercial advantage, personal gain, or malicious harm is prosecuted criminally by the Department of Justice (DOJ), incurring fines up to $250,000 and up to 10 years imprisonment.
A physician temporarily holds back a patient's diagnostic results because releasing them immediately would pose a substantial risk of physical harm to the patient. Which Information Blocking exception applies?
A covered entity committed a HIPAA Security Rule violation due to intentional reckless indifference (willful neglect) and failed to take any corrective action within 30 days of discovery. Under which penalty tier will HHS OCR assess fines?
What technological standard is mandated by the 21st Century Cures Act for data access via Application Programming Interfaces (APIs)?