Information Blocking Penalties
Information blocking penalties are financial consequences that can be imposed on certain healthcare technology actors when they interfere with the access, exchange, or use of electronic health information without a valid reason recognized under the law. These penalties arise under the 21st Century Cures Act, and are enforced by the HHS Office of Inspector General (OIG), which may impose civil monetary penalties of up to $1 million per violation. This framework is separate from the HIPAA rules and is not enforced by the HHS Office for Civil Rights (OCR).
Under the 21st Century Cures Act, information blocking is defined generally as a practice that interferes with, prevents, or materially discourages the access, exchange, or use of electronic health information (EHI), except as required by law or covered by an established exception. The OIG has authority to impose civil monetary penalties of up to $1 million per violation for information blocking committed by certain regulated actors, specifically health IT developers of certified health IT and health information networks/exchanges (HINs/HIEs). Health care providers determined to have committed information blocking are generally not subject to these OIG civil monetary penalties but are instead subject to separate 'appropriate disincentives' established through other HHS mechanisms; readers should verify the current disincentive framework and enforcing agencies against current regulatory guidance. This regime is administered under the Public Health Service Act as amended by the Cures Act and is distinct from HIPAA enforcement carried out by HHS OCR. The specific penalty amount, per-violation methodology, and applicable exceptions are subject to change and should be confirmed against the current regulatory text and OIG guidance.
Why it matters
Information blocking penalties represent a significant enforcement mechanism that operates entirely outside the familiar HIPAA framework. Many compliance professionals are accustomed to thinking about electronic health information primarily through the lens of the HIPAA Privacy and Security Rules enforced by HHS OCR. However, the 21st Century Cures Act created a separate regime, enforced by the HHS Office of Inspector General (OIG), that penalizes interference with the access, exchange, or use of electronic health information (EHI). Conflating the two frameworks can lead organizations to overlook obligations and enforcement risks that HIPAA compliance alone does not address.
The stakes are substantial for the specific actors subject to these penalties. The OIG has authority to impose civil monetary penalties of up to $1 million per violation. As of the applicable regulatory guidance, this per-violation authority applies specifically to health IT developers of certified health IT and to health information networks and health information exchanges (HINs/HIEs). These are the only actor types for which OIG currently has civil monetary penalty authority under the Cures Act framework, which makes it especially important for those organizations to understand where the line falls between legitimate practices and information blocking.
Healthcare providers face a different, but related, set of consequences. Providers determined to have committed information blocking are generally not subject to these OIG civil monetary penalties; instead, they are subject to separate 'appropriate disincentives' established through other HHS mechanisms. Because the disincentive framework and the agencies administering it are subject to change, readers should confirm the current approach against current regulatory guidance rather than assume the penalty structure is uniform across all actor types.
Who it's relevant to
Inside Information Blocking Penalties
Common questions
Answers to the questions practitioners most commonly ask about Information Blocking Penalties.