Skip to main content
Category: Regulatory Framework

21st Century Cures Act

Also known as: Cures Act, CURES, H.R.34, Cures Act
Simply put

The 21st Century Cures Act is a wide-ranging U.S. federal law signed on December 13, 2016. It is designed to help accelerate medical product development and to give patients and their healthcare providers secure access to electronic health information. The law is broad in scope, spanning topics from medical research funding to health information access.

Formal definition

The 21st Century Cures Act (H.R.34, 114th Congress) is a U.S. federal statute signed into law on December 13, 2016. The Act is a 312-page, multi-topic law that, among other provisions, authorized funding for medical research (including funding directed largely to the National Institutes of Health), sought to accelerate medical product development, and addressed patient and provider access to electronic health information. Implementation of the Act's health information provisions is carried out in part through the ONC Cures Act Final Rule, which addresses secure electronic access to health information. Practitioners should note that the Cures Act is distinct from HIPAA and its rules; it may impose or enable requirements (such as those addressed in the ONC Final Rule concerning information access and information blocking) that operate alongside, rather than as part of, the HIPAA regulatory framework. Specific provisions, funding figures, and implementing regulations should be verified against the current statutory and regulatory text.

Why it matters

The 21st Century Cures Act matters to healthcare compliance professionals because it introduced a distinct set of obligations and expectations around electronic health information access that operate alongside, but separate from, the HIPAA regulatory framework. Where HIPAA (enforced by HHS OCR) governs the privacy and security of protected health information, the Cures Act and its implementing ONC Cures Act Final Rule focus on giving patients and their healthcare providers secure electronic access to health information. Understanding this distinction is essential: compliance with HIPAA does not automatically satisfy Cures Act expectations, and vice versa.

The practical significance lies in how the Cures Act reshapes the flow of electronic health information. The ONC Cures Act Final Rule addresses matters such as secure electronic access to health information and information blocking, which can affect how covered entities, developers of certified health IT, and other actors make information available. Because these provisions can impose or enable requirements that sit outside the HIPAA rules, organizations that have historically framed their obligations solely in HIPAA terms may find they have additional considerations to account for.

Given the breadth of the Act, a 312-page statute spanning medical research funding, medical product development, and health information access, compliance teams should treat the health information access provisions as their primary area of intersection with day-to-day privacy and security work. Specific provisions, funding figures, and implementing regulations change over time and should be verified against the current statutory and regulatory text rather than relied upon from summary descriptions.

Who it's relevant to

Privacy and Security Officers
Privacy and security officers need to recognize that the Cures Act and its ONC Final Rule create obligations around electronic health information access that are distinct from HIPAA. Satisfying HIPAA's Privacy and Security Rule requirements does not by itself address Cures Act information access or information blocking considerations, so these should be evaluated separately.
Compliance Officers
Compliance officers responsible for mapping regulatory obligations should account for the Cures Act as a separate legal framework that operates alongside HIPAA. Given the Act's breadth, the health information access provisions, implemented in part through the ONC Cures Act Final Rule, are typically the most directly relevant area, and current requirements should be verified against the applicable regulatory text.
Health IT Developers and Vendors
Developers of health IT and related vendors may be affected by the ONC Cures Act Final Rule's provisions concerning secure electronic access to health information and information blocking. These requirements can attach to actors in ways that differ from HIPAA's covered entity and business associate structure, so the specific applicability should be confirmed against current regulatory guidance.
Legal Counsel
Legal professionals advising healthcare organizations should treat the Cures Act as distinct from HIPAA and its rules. The Act may impose or enable requirements that operate alongside the HIPAA framework, and specific provisions, funding figures, and implementing regulations should be verified against the current statutory and regulatory text.

Inside Cures Act

Interoperability and Information Blocking Provisions
The Cures Act establishes provisions intended to promote the interoperability of electronic health information and to discourage practices that interfere with the access, exchange, or use of such information (commonly referred to as information blocking). These provisions are administered primarily through HHS, including the office responsible for health IT, rather than through the HIPAA rules themselves.
Information Blocking Framework
The Act generally defines information blocking as certain practices by actors, such as health care providers, health IT developers, and health information networks or exchanges, that are likely to interfere with the access, exchange, or use of electronic health information, subject to identified exceptions. Practitioners should verify the specific definitions, actor categories, and exceptions against the current regulatory text, as these details are set out in implementing regulations.
Patient Access to Electronic Health Information
The Cures Act framework generally supports patients' ability to access their electronic health information, which operates alongside but is distinct from the HIPAA Privacy Rule's right of access. The precise scope of information covered and applicable timelines are established in the implementing regulations and should be confirmed against current guidance.
Relationship to HIPAA
The Cures Act and its information blocking provisions are separate from HIPAA. HIPAA (enforced by HHS OCR) governs the privacy and security of protected health information, while the Cures Act addresses interoperability and information blocking through a different statutory and regulatory scheme. Compliance with one does not by itself establish compliance with the other, and the two frameworks may impose overlapping or additional obligations.

Common questions

Answers to the questions practitioners most commonly ask about Cures Act.

Does the 21st Century Cures Act replace or override HIPAA?
No. The 21st Century Cures Act does not replace HIPAA. It operates alongside HIPAA, and its information blocking provisions are administered separately (generally under HHS through ONC and enforced in coordination with other authorities), while HIPAA's Privacy, Security, Breach Notification, and Enforcement Rules remain enforced by HHS OCR. The two frameworks can impose overlapping and complementary obligations. HIPAA continues to govern the permitted uses and disclosures of PHI, and the Cures Act's information sharing expectations do not eliminate HIPAA's requirements. Readers should verify how the specific provisions interact against current regulatory text.
Does the Cures Act's information blocking rule require organizations to share protected health information even when HIPAA would prohibit it?
No. The information blocking provisions generally do not compel disclosures that HIPAA would not permit. Where a disclosure is prohibited by HIPAA or other applicable law, that is typically relevant to whether withholding information constitutes prohibited information blocking. In other words, the frameworks are intended to work together rather than force a covered entity to violate the HIPAA Privacy Rule. Because the interaction between permitted disclosures, exceptions, and information blocking is fact-specific, organizations should confirm the analysis against the current information blocking regulations and applicable HIPAA provisions, and note that state law may impose additional restrictions.
Which parts of our organization are most likely affected by the Cures Act's information sharing requirements?
In practice, functions that handle electronic health information for access, exchange, or use, such as health IT systems, patient portals, health information management, and interfaces with health information networks, are typically most affected. The scope of who is subject to the information blocking provisions is defined by the applicable regulations and generally includes certain health care providers, health IT developers of certified health IT, and health information networks or exchanges. Organizations should map their systems and roles against the current regulatory definitions rather than assume the requirements apply uniformly to every vendor or department.
How does the Cures Act intersect with HIPAA's individual right of access?
Both frameworks emphasize individuals' ability to obtain and use their health information, but they are distinct. HIPAA's Privacy Rule establishes an individual right of access to designated record sets held by covered entities, while the Cures Act's provisions focus more broadly on preventing practices that unreasonably interfere with the access, exchange, or use of electronic health information. When operationalizing patient access, organizations generally need to satisfy HIPAA access requirements and also avoid conduct that could be considered information blocking. Because the details differ, confirm the specific obligations against current HIPAA and information blocking guidance.
Do we need to update our HIPAA policies and business associate agreements because of the Cures Act?
Organizations commonly review their policies, workflows, and vendor arrangements to address information sharing expectations, but the Cures Act does not change the core HIPAA requirement that PHI-related obligations flow to business associates and subcontractors through business associate agreements. Where health IT vendors or exchange partners are involved, it can be prudent to confirm that agreements and technical capabilities support permitted electronic access and exchange without creating unnecessary barriers. Any policy updates should be validated against both the current HIPAA Rules and the current information blocking regulations, and legal review is advisable.
Does complying with the Cures Act's information sharing provisions mean we are also HIPAA compliant?
No. Addressing the Cures Act's information blocking and interoperability expectations does not by itself establish HIPAA compliance, and vice versa. HIPAA compliance generally requires meeting the applicable Privacy, Security, Breach Notification, and Enforcement Rule obligations, including the Security Rule's administrative, physical, and technical safeguards for ePHI. The frameworks address different objectives, so organizations should maintain a compliance approach that accounts for each separately and note that additional requirements may arise under the HITECH Act, state law, or other frameworks. No single measure guarantees compliance with either regime.

Common misconceptions

The 21st Century Cures Act is part of HIPAA or amends the HIPAA Privacy and Security Rules.
The Cures Act is a separate federal law addressing interoperability and information blocking, administered through HHS health IT authorities rather than the HIPAA rules enforced by HHS OCR. Its information blocking framework is distinct from the HIPAA Privacy Rule's right of access, though the two can overlap. Organizations should assess obligations under each framework independently and verify details against current regulatory text.
Information blocking rules apply equally to every vendor or organization that handles electronic health information.
The information blocking provisions generally apply to defined categories of actors, such as health care providers, health IT developers of certified health IT, and health information networks or exchanges. Whether a given organization is subject to these provisions depends on how it fits the defined actor categories, which readers should confirm against the current implementing regulations.
Satisfying HIPAA's right of access automatically means an organization is compliant with the Cures Act's information blocking requirements.
HIPAA compliance and Cures Act information blocking compliance are separate determinations. Meeting HIPAA obligations does not by itself establish compliance with the information blocking framework, and the applicable exceptions and requirements under the Cures Act should be evaluated on their own terms against current guidance.

Best practices

Treat the 21st Century Cures Act information blocking framework as a distinct compliance obligation separate from HIPAA, and assign responsibility for it accordingly rather than assuming HIPAA compliance efforts fully address it.
Determine whether your organization falls within the Act's defined actor categories (such as health care provider, health IT developer, or health information network or exchange), verifying the current definitions against the implementing regulations.
Review the identified information blocking exceptions against your access, exchange, and use practices, and document the basis for relying on any exception, confirming details with current regulatory text.
Coordinate patient access processes so that responses satisfy both the HIPAA Privacy Rule right of access and any applicable Cures Act expectations, while recognizing the two frameworks are distinct.
Confirm specific definitions, timelines, actor categories, and enforcement details against the current HHS regulations and guidance, since these are established in implementing rules that can be updated over time.
Consult legal counsel where state law, the HITECH Act, or other frameworks may impose obligations beyond both HIPAA and the Cures Act, to avoid gaps arising from overlapping requirements.