3.2 Interoperability Policy and Information Blocking
Key Takeaways
- The 21st Century Cures Act made sharing electronic health information the expected norm; information blocking is an actor’s practice that is likely to interfere with access, exchange, or use of EHI except as required by law or an ONC exception in 45 CFR Part 171.
- The three actor types are healthcare providers, health IT developers of certified health IT, and health information networks or exchanges; developers and HIN/HIEs are judged on a know-or-should-know standard, while providers are judged on whether they know a practice is unreasonable and likely to interfere.
- Exceptions such as Preventing Harm, Privacy, Security, Infeasibility, Health IT Performance, Manner, Fees, and Licensing are voluntary safe harbors that apply only when their documented conditions are met—they are not departmental slogans.
- TEFCA is the nationwide Trusted Exchange Framework and Common Agreement; Qualified Health Information Networks (QHINs) implement that common rule set for nationwide exchange and do not repeal HIPAA.
- The current CMS hospital and CAH program name is the Medicare Promoting Interoperability Program; eligible clinicians meet related requirements in the MIPS Promoting Interoperability performance category. Do not treat Meaningful Use as the current program name.
3.2 Interoperability Policy and Information Blocking
Quick Answer: The 21st Century Cures Act made sharing electronic health information the default. Know the three information-blocking actor types, the candidate-level exceptions, TEFCA and QHINs as the nationwide exchange frame, and that CMS’s current program name is Promoting Interoperability—not Meaningful Use.
Why interoperability policy is an operations problem
Privacy law tells you when you may not disclose. Interoperability policy tells you when you may not refuse. After Cures, a standing order to “hold all results until the physician calls,” a vendor surcharge that prices competitors out of an API, or a refusal to connect a patient-selected app can be as legally dangerous as an over-disclosure.
21st Century Cures Act: sharing as the expected norm
The 21st Century Cures Act (2016) directed HHS to deter information blocking and to advance certified health IT that supports access, exchange, and use of electronic health information (EHI). ONC’s Cures Act final rule and later Health Data, Technology, and Interoperability (HTI) rules operationalize that mandate.
For exam language:
- Information blocking is a practice by an actor that is likely to interfere with the access, exchange, or use of EHI, except as required by law or specified in an exception.
- EHI is electronic information from the designated record set (the full EHI definition applies after the earlier USCDI-only transition). If you are unsure whether a note, image, or device report is EHI, ask whether it is electronic designated-record-set information—not whether it is convenient to send.
- Interference includes delaying, degrading, or adding unnecessary friction—not only a hard refusal.
- Practices required by law are not information blocking. A state confidentiality statute that forbids a disclosure is a legal requirement, not an “exception workaround.”
Cures also pushed patient access via APIs using standardized, computable formats (FHIR-based certified APIs in certified health IT). Portal PDFs alone are no longer the policy vision.
Three actor types and two knowledge standards
ONC applies the prohibition to three actors:
| Actor | Typical organizations | Knowledge standard |
|---|---|---|
| Healthcare providers | Hospitals, clinicians, many facilities | Knows the practice is unreasonable and likely to interfere |
| Health IT developers of certified health IT | EHR and certified-module vendors | Knows or should know the practice is likely to interfere |
| Health information networks / exchanges (HIN/HIE) | Networks that enable exchange among more than two unaffiliated parties | Knows or should know the practice is likely to interfere |
A health system can wear more than one hat (provider and, if it operates a multi-entity exchange, HIN/HIE). CPHIMS items often hide the actor type in the stem. Identify the actor first; the knowledge standard and enforcement path follow.
Enforcement sketch at candidate level:
- HHS OIG may investigate claims across actor types.
- ONC can treat developer information blocking as a certification non-conformity.
- Provider disincentives established by HHS rule apply to providers OIG finds to have committed information blocking (CMS program impacts). Do not invent a single 2026 hospital dollar fine; developer and HIN civil monetary penalty authority and provider disincentives are different tools.
Claims can be submitted through ONC’s information-blocking portal. Claimant identity has statutory Freedom of Information Act protection.
Exceptions: safe harbors, not slogans
When an actor’s practice meets all conditions of an exception in 45 CFR Part 171, it is not information blocking. Exceptions are voluntary—they give certainty. Failure to fit an exception does not automatically prove blocking; HHS still evaluates the facts. For CPHIMS, memorize the purpose of the core exceptions and that each has conditions you must document.
Exceptions that can justify not fulfilling a request (in whole or in part):
- Preventing Harm — reasonable, tailored practices to reduce a risk of harm to a patient or another person. Not a blanket delay of all laboratory results because “patients get anxious.”
- Privacy — practices that protect an individual’s privacy consistent with applicable law (for example, a required authorization). Privacy is not a synonym for “legal is nervous.”
- Security — practices that protect EHI security, consistently applied and no broader than necessary.
- Infeasibility — the request cannot be fulfilled due to uncontrollable events, segmentation that cannot be performed, or another recognized infeasibility condition, with timely written notice.
- Health IT Performance — temporary unavailability for maintenance or to protect performance, consistently applied.
- Protecting Care Access — a later exception addressing certain practices related to reproductive health care information. Know that it exists and is condition-heavy rather than inventing its details on the exam.
Exceptions that govern how you fulfill a request:
- Manner (evolved from Content and Manner) — if you cannot fulfill in the requested manner, follow the exception’s alternative-manner conditions.
- Fees — certain objective, cost-based fees; not a tax that prices patients or competitors out of access.
- Licensing — reasonable, non-discriminatory licensing of interoperability elements.
- TEFCA manner — in specified conditions, fulfilling via TEFCA rather than every requested point-to-point method. Treat this as a current ONC exception and design to the live 45 CFR 171 text, because later HTI rulemaking can revise TEFCA-related exception language.
CPHIMS trap: citing “Preventing Harm” because a physician wants to counsel first. The exception requires a reasonable belief of harm that meets ONC’s conditions, not a departmental preference. Many organizations now release most results immediately and use a narrow, documented delay only where a genuine harm condition exists.
Patient access is a first-class duty
Patients and their personal representatives are intended beneficiaries of Cures. Operational controls include patient-portal access to EHI without unnecessary delay; certified APIs so patients can use apps of their choice, subject to registration and security that are not disguised blocking; USCDI as the certified data-class floor for standardized exchange (cite the version your CEHRT supports); and alignment with the HIPAA right of access. Cures does not shrink HIPAA rights.
A HIM director who still requires a paper release form and a 20-day wait for records the patient can already see in the portal is failing both customer service and policy. A vendor that “does not allow” third-party app registration without a partnership fee is in the information-blocking blast radius.
TEFCA at policy level
TEFCA is ONC’s nationwide network-of-networks policy: the Trusted Exchange Framework plus the Common Agreement. Qualified Health Information Networks (QHINs) are designated entities that agree to that common legal and technical framework so participants can query and push EHI across the country under shared rules, rather than a maze of one-off contracts.
What CPHIMS needs:
- TEFCA is policy and governance, not a new clinical terminology.
- Participation is a strategic exchange decision: fewer pairwise connections and support for purposes recognized in the Common Agreement.
- TEFCA does not repeal HIPAA. QHIN exchange still needs a lawful purpose and appropriate agreements.
- Local or regional HIE participation and TEFCA participation can coexist. Do not tell the exam that “TEFCA deleted regional HIEs.”
Promoting Interoperability is the current CMS name
HITECH created the Medicare and Medicaid EHR Incentive Programs, widely nicknamed Meaningful Use. That nickname is historical.
Current official names:
- Medicare Promoting Interoperability Program — eligible hospitals and critical access hospitals; still requires certified EHR technology and measure or attestation reporting. CMS currently organizes hospital and CAH objectives around electronic prescribing, health information exchange, provider-to-patient exchange, public health and clinical data exchange, and protecting patient health information, plus electronic clinical quality measures.
- MIPS Promoting Interoperability performance category — eligible clinicians in the Quality Payment Program.
- The Medicaid Promoting Interoperability Program ended December 31, 2021.
Objectives emphasize exchange and patient access, which is why this section sits next to Cures. Scoring details change in annual CMS rulemaking—do not freeze a stale measure threshold as eternal fact.
Scenarios and traps
A lab director wants to embargo all pathology for 14 days “so doctors can call first.” Unless a documented Preventing Harm condition applies to a defined subset, a blanket embargo is the exam’s idea of interference.
A certified EHR vendor charges a competitor HIE a punitive extraction fee while giving a preferred network free firehose access. That is a Fees and Licensing problem, not “market strategy.”
A CIO says, “We are not a developer, so information blocking does not apply.” Providers are actors.
A compliance officer says, “HIPAA minimum necessary means we never send the CCD.” Minimum necessary and information blocking must be reconciled: send what the request and law allow; do not use HIPAA as a pretext to lock EHI that the patient or a treating provider is entitled to receive.
An analyst still labels the hospital’s CMS attestation “Meaningful Use Stage 3.” Use Promoting Interoperability.
Additional exam traps
- Treating any delay as automatically lawful because a clinician prefers to counsel first.
- Confusing actor types and therefore the knowledge standard.
- Assuming exceptions apply without meeting their conditions or keeping evidence.
- Calling TEFCA a replacement for HIPAA or for every local interface.
- Using the retired program name Meaningful Use for current CMS reporting.
ONC’s information-blocking regulations apply to which set of actors?
A hospital policy holds every outpatient laboratory and imaging result for seven days so physicians can “message patients first,” including routine tests with no identified harm risk. Leadership calls this a Preventing Harm exception. What is the best CPHIMS assessment?
An eligible hospital is preparing its annual CMS attestation for certified EHR use, electronic prescribing, health information exchange, and patient electronic access. Which program name should the CPHIMS professional use?