The Information Blocking Rule: What It Means and How to Stay Compliant

Colin Elsinga
June 15, 2026

Many healthcare organizations still treat data sharing like a privilege they grant when conditions are right. Under the information blocking rule, it's the opposite: you share by default, and you need a documented exception to decline.

That shift trips up even organizations with strong HIPAA programs, because the information blocking rule reaches well beyond privacy. Charging fees above cost recovery, delaying responses without a valid reason, and restricting API access without a qualifying exception are all information blocking examples that can trigger enforcement.

This blog walks through what the rule actually requires, how it interacts with HIPAA, and what compliance looks like when someone requests your EHI.

TLDR:

  • Information blocking is conduct that restricts access to electronic health information (EHI).
  • Penalties reach $1 million per violation; providers risk Medicare and Medicaid exclusion.
  • The rule applies to healthcare providers, health IT developers, and health information networks.
  • Ten exceptions permit withholding or limiting data under specific conditions, covering patient safety, privacy and security, technical infeasibility, licensing and fees, and reproductive health protection, among others.
  • HIPAA compliance does not protect you from information blocking violations.

What Is Information Blocking and Why Does It Matter

The 21st Century Cures Act formally defined it as conduct that is likely to impede the sharing of EHI, and the rule took full effect in 2022.

The stakes are real. When patients cannot access their own records, or when providers cannot receive data needed for care decisions, outcomes suffer. The rule pushes the entire healthcare system toward genuine interoperability instead of compliance theater. It sits alongside HIPAA but is enforced separately.

Who Is Subject to Information Blocking Rules

The information blocking rule applies to three categories of actors defined under the 21st Century Cures Act. Health IT developers of certified health IT, health information networks (HINs), and health information exchanges (HIEs) fall under one category. The second covers healthcare providers, a group that spans hospitals, physician practices, labs, pharmacies, and any other entity that furnishes health services and bills for them. The third covers health information networks and exchanges more broadly.

If your organization touches electronic health information in any of these roles, the rule applies to you. Non-compliance carries enforcement consequences for all three actor types: developers and networks face civil monetary penalties, while providers face separate disincentive-based enforcement through federal program participation.

Diagram showing the three actor categories subject to the information blocking rule under the 21st Century Cures Act: Health IT developers of certified health IT, including EHR vendors, API platforms, and certified modules; Networks and exchanges, including health information networks, health information exchanges, and TEFCA QHINs; and Healthcare providers that furnish and bill for services, including hospitals, practices, labs, and pharmacies.

Electronic Health Information (EHI) Covered Under the Rule

EHI refers to electronic protected health information (ePHI) as defined under HIPAA, but with a broader scope. The rule covers all ePHI that an actor has the ability to make available, which includes clinical notes, lab results, diagnoses, medications, imaging, and more.

Starting in October 2022, the scope expanded to cover all EHI instead of the limited data set tied to the USCDI v1. Health systems, clinics, and health IT developers must now make the full range of patient health data accessible when requested, beyond a narrow subset.

Key categories of EHI covered include:

  • Clinical documentation such as visit notes, discharge summaries, and care plans that inform ongoing treatment decisions
  • Diagnostic data including lab results, pathology reports, and radiology findings
  • Medication records covering prescriptions, administration history, and allergy information
  • Demographic and administrative data like insurance details and patient contact information

How Information Blocking Differs from HIPAA

HIPAA and the information blocking rule solve different problems. HIPAA is a privacy law built around permission: it defines when disclosure is allowed, not when it's required. Organizations raised on HIPAA compliance often default to caution, treating any data request as something to review carefully before acting.

The information blocking rule reverses that posture. Withholding or delaying EHI access is presumed problematic unless a recognized exception applies or sharing is expressly prohibited by law. The question changes from "are we allowed to share?" to "do we have a valid reason not to?"

Full HIPAA compliance offers no protection against an information blocking finding. Fee structures, technical barriers, and restrictive contract terms can all constitute blocking even when every HIPAA requirement is met.

Common Examples of Information Blocking Practices

Violations often look like routine policy decisions until measured against the rule. Common patterns include:

  • Charging fees that go beyond what is permitted under the information blocking regulations, such as requiring payment for records that should be provided at no cost.
  • Requiring patients to appear in person or submit requests through unnecessarily complex processes when simpler, standard methods exist.
  • Delaying responses to access requests without a valid, documented reason, even when the technical capability to respond quickly is already in place.
  • Configuring EHR systems to withhold certain data elements from third-party apps without a qualifying exception.
  • Refusing to share data with other providers or apps by citing vague security or liability concerns that do not meet any recognized exception.

The Ten Information Blocking Exceptions

The rule recognizes that some restrictions on EHI sharing serve legitimate purposes. Ten exceptions exist as compliant pathways, and each comes with specific conditions that must actually be met to qualify. The original eight were expanded by the HTI-1 final rule in December 2023, which added the TEFCA Manner Exception, and again in December 2024 with the Protecting Care Access Exception.

ExceptionCore Purpose
Preventing HarmWithhold or limit access when sharing creates a substantial risk of harm to a patient or third party
PrivacyCover privacy concerns that go beyond standard HIPAA requirements in specific circumstances
SecurityRespond to documented, legitimate security risks tied to a particular request or access method
InfeasibilityCover situations where legal, technical, or practical barriers genuinely prevent timely compliance
Health IT PerformanceAllow temporary unavailability during maintenance or activities needed to preserve system integrity
MannerProvide flexibility to respond using different formats or methods when the requested format is not supported
LicensingPermit actors to negotiate reasonable terms for accessing EHI through interfaces built on proprietary tech
FeesPermit actors to charge reasonable fees for accessing or exchanging EHI, provided the fees are based on objective, verifiable criteria and do not exceed the cost of providing access
TEFCA MannerPermit actors to fulfill EHI requests through TEFCA when the requestor is connected through TEFCA for the information they seek
Protecting Care AccessPermit actors to restrict access, exchange, or use of EHI containing reproductive health information when the actor has a good faith belief that sharing could expose a patient, provider, or facilitator of lawful reproductive healthcare to legal action

Enforcement: Penalties and Disincentives in Effect

The Office of the National Coordinator for Health IT (ONC) and the HHS Office of Inspector General (OIG) share enforcement authority. OIG can levy civil monetary penalties up to $1 million per violation against actors found to be blocking information. ONC handles disincentives for healthcare providers, which under 2024 rulemaking can include exclusion from Medicare and Medicaid programs. Repeat or egregious violations carry steeper consequences. Because complaints can be filed by any affected party, including patients, the exposure is broad. As of early 2026, enforcement is actively underway: ASTP has begun issuing notices of investigation to health IT developers, and regulators are working through a backlog of nearly 1,600 complaints filed since 2021. Compliance gaps that went unaddressed before 2024 are now being reviewed in formal investigations.

How Organizations Can Achieve and Maintain Compliance

Staying compliant with the information blocking rule requires more than a written policy. It calls for consistent day-to-day practices across the organization.

A few areas deserve particular attention:

  • Conduct regular staff training so that anyone who handles health information requests understands what constitutes a delay, denial, or interference under the rule.
  • Review your response workflows to confirm that requests for records are fulfilled within required timeframes and that any exception applied is properly documented.
  • Audit third-party agreements, including those with EHR vendors and health information exchanges, to verify they do not contain provisions that would restrict data sharing in ways the rule prohibits.
  • Keep documentation of every exception invoked, since ONC and OCR may request evidence that the exception was applied correctly.

Organizations should also assign clear ownership of information blocking compliance internally, whether that sits with a compliance officer, privacy officer, or a designated team, so accountability does not fall through the cracks.

Supporting Health Information Exchange with Interoperability Solutions

Staying compliant with information blocking rules requires more than policy updates. Health systems, clinics, and vendors need reliable infrastructure to actually share data when patients and providers request it. APIs built on HL7 FHIR standards are now the primary mechanism for meeting these obligations, letting organizations exchange structured clinical data across EHRs, apps, and care networks without manual workarounds. Providers that lack interoperability infrastructure face real exposure: ONC can investigate complaints and refer violations to the HHS Office of Inspector General for civil monetary penalties.

Final Thoughts on Preventing Information Blocking Violations

Information blocking compliance comes down to your day-to-day operations and written policies alike. Every delay, every fee structure, and every vendor contract can become a violation if it restricts access without a valid exception. Train your staff on what the rule actually prohibits and keep records of why you invoked any exception. The regulators are watching and complaints can come from anyone.

FAQ

What is information blocking under HIPAA?

Information blocking is a separate rule from HIPAA that prohibits practices interfering with the access, exchange, or use of electronic health information. While both laws apply to healthcare organizations, information blocking focuses on removing barriers to data sharing, whereas HIPAA governs when disclosure is permitted, and full HIPAA compliance does not protect against information blocking violations.

Can you be penalized for information blocking even if you follow HIPAA?

Yes. The information blocking rule assumes withholding or delaying EHI access is problematic unless a recognized exception applies, regardless of HIPAA compliance status. Fee structures, technical barriers, and restrictive contract terms can all constitute blocking even when every HIPAA privacy requirement is met.

What are information blocking examples that could trigger violations?

Common violations include charging fees beyond what regulations permit, requiring patients to submit requests through unnecessarily complex processes, delaying responses without documented reasons, configuring EHR systems to withhold data from third-party apps without valid exceptions, and refusing to share data by citing vague security concerns that don't meet any recognized exception criteria.

What's the penalty for information blocking vs HIPAA violations?

Information blocking penalties reach up to $1 million per violation for health IT developers and networks, enforced by the HHS Office of Inspector General. Healthcare providers face disincentives including potential exclusion from Medicare and Medicaid programs under 2024 rulemaking. HIPAA violations carry separate penalties ranging from $100 to $50,000 per violation depending on the level of culpability.

When should I invoke an information blocking exception?

Invoke one of the ten recognized exceptions only when specific conditions are genuinely met and you can document the justification. Each exception (from preventing harm to protecting care access) requires meeting particular criteria, and ONC or OCR may request evidence that you applied it correctly during investigations or audits.

Stay up-to-date with news from Metriport.

View Blog

Get the latest updates and blog posts from the Metriport team.

Metriport icon