Skip to main content
Category: OCR Enforcement and Penalties

Information Blocking Penalties

Also known as: Information Blocking Civil Monetary Penalties, Cures Act Information Blocking Penalties
Simply put

Information blocking penalties are financial consequences that can be imposed on certain healthcare technology actors when they interfere with the access, exchange, or use of electronic health information without a valid reason recognized under the law. These penalties arise under the 21st Century Cures Act, and are enforced by the HHS Office of Inspector General (OIG), which may impose civil monetary penalties of up to $1 million per violation. This framework is separate from the HIPAA rules and is not enforced by the HHS Office for Civil Rights (OCR).

Formal definition

Under the 21st Century Cures Act, information blocking is defined generally as a practice that interferes with, prevents, or materially discourages the access, exchange, or use of electronic health information (EHI), except as required by law or covered by an established exception. The OIG has authority to impose civil monetary penalties of up to $1 million per violation for information blocking committed by certain regulated actors, specifically health IT developers of certified health IT and health information networks/exchanges (HINs/HIEs). Health care providers determined to have committed information blocking are generally not subject to these OIG civil monetary penalties but are instead subject to separate 'appropriate disincentives' established through other HHS mechanisms; readers should verify the current disincentive framework and enforcing agencies against current regulatory guidance. This regime is administered under the Public Health Service Act as amended by the Cures Act and is distinct from HIPAA enforcement carried out by HHS OCR. The specific penalty amount, per-violation methodology, and applicable exceptions are subject to change and should be confirmed against the current regulatory text and OIG guidance.

Why it matters

Information blocking penalties represent a significant enforcement mechanism that operates entirely outside the familiar HIPAA framework. Many compliance professionals are accustomed to thinking about electronic health information primarily through the lens of the HIPAA Privacy and Security Rules enforced by HHS OCR. However, the 21st Century Cures Act created a separate regime, enforced by the HHS Office of Inspector General (OIG), that penalizes interference with the access, exchange, or use of electronic health information (EHI). Conflating the two frameworks can lead organizations to overlook obligations and enforcement risks that HIPAA compliance alone does not address.

The stakes are substantial for the specific actors subject to these penalties. The OIG has authority to impose civil monetary penalties of up to $1 million per violation. As of the applicable regulatory guidance, this per-violation authority applies specifically to health IT developers of certified health IT and to health information networks and health information exchanges (HINs/HIEs). These are the only actor types for which OIG currently has civil monetary penalty authority under the Cures Act framework, which makes it especially important for those organizations to understand where the line falls between legitimate practices and information blocking.

Healthcare providers face a different, but related, set of consequences. Providers determined to have committed information blocking are generally not subject to these OIG civil monetary penalties; instead, they are subject to separate 'appropriate disincentives' established through other HHS mechanisms. Because the disincentive framework and the agencies administering it are subject to change, readers should confirm the current approach against current regulatory guidance rather than assume the penalty structure is uniform across all actor types.

Who it's relevant to

Health IT Developers of Certified Health IT
As of the applicable regulatory framework, developers of certified health IT are among the only actor types subject to OIG civil monetary penalties of up to $1 million per violation for information blocking. These organizations should carefully evaluate their product design, contractual terms, and operational practices against the information blocking definition and its recognized exceptions, and should confirm the current penalty methodology against OIG guidance.
Health Information Networks and Exchanges (HINs/HIEs)
HINs and HIEs are the other actor type currently subject to OIG civil monetary penalties for information blocking. Because these entities facilitate the exchange of electronic health information across many participants, practices that restrict or discourage access, exchange, or use of EHI can create significant exposure. They should review whether their practices are required by law or covered by an established exception.
Healthcare Providers
Providers are generally not subject to the OIG civil monetary penalties described here, but they can still be found to have committed information blocking and are subject to separate 'appropriate disincentives' established through other HHS mechanisms. The provider analysis typically involves whether the provider knew a practice was unreasonable and likely to interfere with EHI. The disincentive framework and enforcing agencies should be confirmed against current guidance.
Compliance, Privacy, and Legal Professionals
Compliance officers and counsel need to recognize that information blocking enforcement is distinct from HIPAA and is administered by the OIG (and, for provider disincentives, other HHS mechanisms) rather than by HHS OCR. Treating information blocking as though it were a HIPAA obligation risks misdirecting compliance efforts. These professionals should track the current exceptions, penalty amounts, and enforcing authorities, as these elements are subject to change.

Inside Information Blocking Penalties

Information Blocking (statutory basis)
Information blocking is a concept established under the 21st Century Cures Act, referring generally to practices by certain actors that are likely to interfere with the access, exchange, or use of electronic health information (EHI), except as required by law or covered by an applicable exception. This is distinct from HIPAA, which is enforced by HHS OCR; information blocking has its own enforcement structure and does not fall under the HIPAA Privacy, Security, Breach Notification, or Enforcement Rules.
Regulated Actors
The information blocking framework applies to defined categories of actors: health care providers, health IT developers of certified health IT, and health information networks/exchanges (HINs/HIEs). The applicable penalty or enforcement mechanism differs by actor type, so identifying which category an organization falls into is essential before assessing exposure.
OIG Civil Monetary Penalties
The HHS Office of Inspector General (OIG) has authority to impose civil monetary penalties on health IT developers of certified health IT and on health information networks/exchanges found to have committed information blocking, generally up to $1 million per violation. Practitioners should verify the current penalty amount and any inflation adjustments against the applicable regulatory text, as figures are adjusted over time.
Provider Disincentives (CMS/ONC)
Health care providers found to have committed information blocking are generally subject to appropriate disincentives established by other HHS agencies (such as CMS, working with ONC/ASTP) rather than OIG civil monetary penalties. These disincentives typically operate through affected federal programs and differ in nature from the per-violation CMPs applicable to developers and networks.
Enforcement Authority
Information blocking enforcement is assigned to the HHS Office of Inspector General for CMP-eligible actors and to CMS/ONC for provider disincentives. This is a separate enforcement track from HIPAA, which is enforced by HHS OCR. Conflating the two can lead to misdirected compliance efforts.
Exceptions Framework
The information blocking regulations include defined exceptions describing practices that, when conditions are met, are not treated as information blocking. Meeting an exception is generally a fact-specific determination, and readers should confirm the current set of exceptions and their conditions against the applicable regulatory text.

Common questions

Answers to the questions practitioners most commonly ask about Information Blocking Penalties.

Does HHS OCR enforce information blocking penalties?
Generally, no. Information blocking enforcement is not handled by HHS OCR, which enforces the HIPAA Privacy, Security, and Breach Notification Rules. Enforcement of information blocking is assigned to the HHS Office of Inspector General (OIG) for civil monetary penalties against certain actors, while provider disincentives are administered through CMS and ONC. Readers should keep information blocking enforcement conceptually separate from HIPAA enforcement, and verify the current allocation of authority against applicable regulations.
Are health IT developers and health information networks or exchanges exempt from monetary penalties?
No. Health IT developers of certified health IT and health information networks/exchanges are the actor types for which OIG generally has authority to impose civil monetary penalties for information blocking. Healthcare providers, by contrast, are generally subject to disincentives rather than these OIG civil monetary penalties. The specific penalty structure and any monetary caps are set by statute and regulation and are adjusted over time, so readers should confirm current figures against the applicable regulatory text.
How can an actor determine whether their conduct qualifies as information blocking or falls under an exception?
Actors generally assess whether a practice interferes with the access, exchange, or use of electronic health information and then evaluate whether it fits within one of the defined regulatory exceptions. Because the exceptions have specific conditions that must be met, actors typically document their rationale and how each condition is satisfied. Readers should review the current exception categories and their detailed requirements in the applicable regulation, as these determinations are fact-specific.
What documentation should an organization maintain to support its information blocking compliance posture?
Organizations generally maintain records of policies, procedures, and the specific reasoning behind practices that limit access, exchange, or use of electronic health information, including how any claimed exception's conditions were met. Contemporaneous documentation typically supports demonstrating good-faith compliance. The precise records that are advisable depend on the actor type and the practices at issue, so organizations should align their documentation with current regulatory guidance.
How does information blocking enforcement relate to HIPAA compliance obligations?
Information blocking requirements are separate from HIPAA and are not enforced by HHS OCR. A practice may be permissible under HIPAA yet still raise information blocking concerns, or vice versa. Because these frameworks have distinct scopes and enforcement authorities, organizations generally need to evaluate compliance under each separately. Note that state law and other frameworks may impose additional requirements beyond either regime.
Which actor faces disincentives rather than OIG civil monetary penalties?
Healthcare providers are generally subject to disincentives administered through CMS and ONC rather than the OIG civil monetary penalties that can apply to health IT developers of certified health IT and health information networks/exchanges. The nature and amount of these disincentives are established by regulation and may change over time, so providers should verify the current framework against applicable guidance.

Common misconceptions

Information blocking penalties are enforced by HHS OCR as part of HIPAA.
Information blocking is established under the 21st Century Cures Act and is separate from HIPAA. Civil monetary penalties for eligible actors are enforced by the HHS Office of Inspector General (OIG), and provider disincentives are handled through CMS/ONC. HHS OCR enforces the HIPAA rules, which is a distinct regulatory framework.
All information blocking actors face the same civil monetary penalties.
The consequence depends on the actor type. Health IT developers of certified health IT and health information networks/exchanges are subject to OIG civil monetary penalties (generally up to $1 million per violation), while health care providers are instead subject to appropriate disincentives established through other HHS agencies such as CMS.
Any practice that limits data sharing automatically constitutes information blocking.
A practice generally does not constitute information blocking if it is required by law or falls within a defined regulatory exception whose conditions are met. Determinations are typically fact-specific, and organizations should assess conduct against the current exceptions rather than assuming any restriction is a violation.

Best practices

Determine which regulated actor category your organization falls into (health care provider, health IT developer of certified health IT, or health information network/exchange), since this dictates whether OIG civil monetary penalties or CMS/ONC provider disincentives apply.
Do not treat information blocking as a HIPAA matter enforced by OCR; maintain separate compliance workflows recognizing that OIG and CMS/ONC hold the relevant enforcement authority.
Review data access, exchange, and use practices against the defined information blocking exceptions, documenting how the conditions of any relied-upon exception are met.
Verify current penalty amounts, disincentive mechanisms, and the applicable set of exceptions against the current regulatory text, as figures and provisions are adjusted over time.
Coordinate legal, compliance, and health IT teams so that decisions to restrict EHI sharing are evaluated for information blocking risk before they are implemented.
Remember that state law, the HITECH Act, and HIPAA may impose additional or overlapping obligations, so information blocking analysis should not be conducted in isolation from those frameworks.