Skip to main content
Category: Regulatory Framework

Information Blocking Rule

Also known as: Information Blocking, 21st Century Cures Act Information Blocking Provisions, 45 CFR Part 171
Simply put

The Information Blocking Rule generally prohibits certain healthcare-related entities, called 'actors,' from engaging in practices that interfere with patients and others being able to access, exchange, or use electronic health information. In simple terms, it is intended to stop organizations from unreasonably restricting the flow of a patient's electronic health data. This rule arises under the 21st Century Cures Act and is distinct from HIPAA, though both may apply to the same organizations; readers should verify the current regulatory text for specifics.

Formal definition

The Information Blocking Rule, codified generally at 45 CFR Part 171 and stemming from the 21st Century Cures Act, defines information blocking as a practice by an 'actor' that, except as required by law or covered by an applicable exception, is likely to interfere with, prevent, or materially discourage the access, exchange, or use of electronic health information (EHI). The scope of covered 'actors' is defined by the regulation and typically includes health care providers, health IT developers of certified health IT, and health information networks or exchanges; this is a category distinct from HIPAA's 'covered entities' and 'business associates,' although an organization may be subject to both frameworks. Enforcement is administered by HHS, with penalties determined by the applicable authority and enforcement mechanism for the actor type (for example, civil monetary penalties for certain actors and separate provider disincentive processes); one evidence source notes penalties of up to $1 million per violation for applicable actors, but penalty amounts and enforcement structures are adjusted over time and should be confirmed against current HHS guidance and the current regulatory text. Compliance with the Information Blocking Rule is separate from, and does not by itself establish, HIPAA compliance; the rule's exceptions and definitions differ from HIPAA's permitted uses and disclosures, and state law or other frameworks may impose additional requirements.

Why it matters

The Information Blocking Rule reflects a significant policy shift toward ensuring patients and authorized parties can readily access, exchange, and use electronic health information (EHI). For compliance professionals, it introduces obligations that are separate from, and additional to, those under HIPAA. An organization that has historically focused its data governance on HIPAA's privacy and security requirements may find that practices it considered acceptable, such as delaying or restricting data sharing, could constitute information blocking under this distinct framework unless an applicable exception applies.

Enforcement carries real consequences. HHS has signaled an active enforcement posture; a September 2025 HHS communication indicated it would take an active enforcement stance against health care entities that restrict patients' engagement in their care by blocking access, exchange, or use of health information. According to OIG guidance from June 2023, certain actors determined to have committed information blocking may be subject to penalties of up to $1 million per violation. Penalty amounts, enforcement structures, and the disincentive processes applicable to providers are adjusted over time, so readers should confirm current figures and mechanisms against current HHS guidance and the regulatory text before relying on them.

Because the rule uses its own defined categories of 'actors' and its own set of exceptions, it does not map neatly onto HIPAA's concepts of covered entities, business associates, or permitted uses and disclosures. Complying with the Information Blocking Rule does not by itself establish HIPAA compliance, and vice versa. Organizations that fall under both frameworks must analyze their data-sharing practices against each set of requirements, and should also consider whether state law or other frameworks impose additional obligations.

Who it's relevant to

Health Care Providers
Providers are generally within the scope of covered 'actors' and must evaluate whether their data-sharing practices could interfere with the access, exchange, or use of EHI. Providers should note that the applicable enforcement mechanism for them may differ from that applied to other actor types, and that compliance here is separate from their HIPAA obligations.
Health IT Developers of Certified Health IT
Developers of certified health IT are typically included as actors under the rule and may be subject to civil monetary penalties, reportedly up to $1 million per violation per OIG guidance, though such figures should be confirmed against current HHS guidance. Their product design and data-exchange functionality should be assessed against the rule's requirements and exceptions.
Health Information Networks and Exchanges
Entities that operate health information networks or health information exchanges are generally covered actors. Because their core function is facilitating the flow of EHI, practices that restrict or condition access may draw particular scrutiny under the rule.
Compliance, Privacy, and Legal Officers
Professionals responsible for compliance must recognize that the Information Blocking Rule is distinct from HIPAA, uses its own defined actors and exceptions, and does not by itself establish HIPAA compliance. They should map organizational practices against both frameworks and monitor for additional requirements under state law or other frameworks.

Inside Information Blocking Rule

Statutory Basis and Scope
The Information Blocking Rule arises from the 21st Century Cures Act and its implementing regulations, and is administered separately from HIPAA. It generally prohibits practices likely to interfere with the access, exchange, or use of electronic health information (EHI), except where required by law or covered by a defined exception. Readers should verify the specific regulatory text and scope against current federal guidance, as this framework is distinct from the HIPAA Privacy and Security Rules.
Regulated Actors
The rule applies to defined categories of actors, generally including health care providers, health IT developers of certified health IT, and health information networks or exchanges. This population is defined differently from HIPAA's covered entities and business associates, so an organization's status under one framework does not automatically determine its status under the other.
Electronic Health Information (EHI)
The rule centers on interference with EHI. This concept has its own regulatory definition and should not be assumed identical to HIPAA's ePHI or PHI. Practitioners should confirm the current definition and any transitional scoping against the applicable regulatory text.
Exceptions to Information Blocking
The regulations set out categorical exceptions describing conduct that, when conditions are met, does not constitute information blocking. These generally address matters such as preventing harm, protecting privacy, ensuring security, infeasibility, and certain fee or licensing practices. The specific exceptions and their conditions should be verified against current guidance, as meeting an exception typically requires satisfying detailed criteria.
Relationship to HIPAA Privacy Practices
The Information Blocking Rule operates alongside HIPAA rather than replacing it. Where the HIPAA Privacy Rule permits but does not require a disclosure, the interaction with information blocking obligations can be nuanced, and certain exceptions are designed to accommodate privacy and security considerations. This is an area where organizations should reconcile both frameworks.
Enforcement Authority
Enforcement of the Information Blocking Rule is administered through federal mechanisms distinct from HIPAA's enforcement by HHS OCR, and consequences may differ by actor type. Specific penalty structures and enforcement processes should be confirmed against current federal guidance, as these provisions are subject to change over time.

Common questions

Answers to the questions practitioners most commonly ask about Information Blocking Rule.

Is the Information Blocking Rule part of HIPAA?
No. The Information Blocking Rule arises under the 21st Century Cures Act and is administered in connection with the Office of the National Coordinator for Health IT (ONC), not under the HIPAA rules enforced by HHS OCR. While both frameworks concern health information and can overlap in practice, they are distinct legal authorities with different scopes, definitions, and enforcement mechanisms. Compliance with HIPAA does not by itself establish compliance with the Information Blocking Rule, and readers should evaluate obligations under each framework separately and verify details against the current regulatory text.
Does the Information Blocking Rule mean I must always share electronic health information whenever it is requested?
Not necessarily. The rule generally discourages practices that interfere with the access, exchange, or use of electronic health information, but it recognizes defined exceptions under which not fulfilling a request may not be considered information blocking. These exceptions typically address concerns such as privacy, security, infeasibility, and preventing harm, subject to specific conditions. Because the applicability of any exception depends on the facts and on the current regulatory text, organizations should assess each situation carefully rather than assume disclosure is either always required or always optional. Confirm the current exceptions and their conditions against the applicable regulation.
How do I determine whether my organization is an actor subject to the Information Blocking Rule?
The rule generally applies to defined categories of actors, which typically include health care providers, health IT developers of certified health IT, and health information networks or exchanges. Determining your status generally requires reviewing how these categories are defined in the current regulatory text and mapping your organization's activities against them. Because a single organization may fall into more than one category or none, this analysis is fact-specific. This is separate from HIPAA's covered entity and business associate classifications, so an organization should evaluate its status under each framework independently and verify against current guidance.
How should we document our reliance on an information blocking exception?
In most cases, organizations find it useful to maintain records showing the basis for declining or limiting a request and how the relevant conditions of a claimed exception were met, since the exceptions generally have specific conditions that must be satisfied. Documenting the request, the analysis applied, and the outcome can support consistency and demonstrate good-faith decision-making. The specific documentation expectations depend on the current regulatory text and any applicable guidance, so organizations should confirm requirements against the current regulation rather than rely on a generalized process alone.
How does the Information Blocking Rule interact with our HIPAA privacy and security obligations?
The two frameworks can overlap but are not interchangeable. HIPAA governs the use and disclosure of protected health information and, under the Security Rule, the safeguarding of ePHI, while the Information Blocking Rule addresses practices that may interfere with the access, exchange, or use of electronic health information. In some situations a privacy or security consideration recognized under HIPAA may align with an information blocking exception, but the frameworks have separate definitions and conditions. Organizations should analyze a request under both frameworks rather than assume that satisfying one resolves the other, and should note that state law and other requirements may also apply. Verify specifics against current guidance for each framework.
What internal processes help an organization respond appropriately to requests under the Information Blocking Rule?
Many organizations establish a defined intake and review process for requests to access, exchange, or use electronic health information, including a way to route requests, evaluate whether any exception may apply, and document decisions. Assigning responsibility, training relevant staff, and coordinating between IT, privacy, and legal functions generally support consistent handling. Because the rule's applicability turns on specific definitions and exception conditions in the current regulatory text, these processes should be designed to reference current requirements. This description is general and does not substitute for confirming obligations against the applicable regulation and any current guidance.

Common misconceptions

The Information Blocking Rule is part of HIPAA and is enforced by HHS OCR.
The Information Blocking Rule stems from the 21st Century Cures Act and operates as a separate framework from the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules. Its enforcement mechanisms differ from HIPAA's, and organizations should not assume HIPAA compliance alone satisfies information blocking obligations. Readers should verify current enforcement details against applicable federal guidance.
If HIPAA permits withholding or not disclosing information, doing so can never be information blocking.
The two frameworks are related but distinct. HIPAA generally governs when disclosures are permitted or required, while the Information Blocking Rule addresses interference with access, exchange, or use of EHI subject to its own exceptions. A practice permissible under HIPAA is not automatically outside the scope of information blocking; the relevant exception conditions typically must be met.
The rule applies to every vendor or organization that handles health data.
The rule applies to specifically defined regulated actors, such as certain providers, developers of certified health IT, and health information networks or exchanges. These categories are defined differently from HIPAA's covered entities and business associates, so an entity's obligations depend on whether it falls within a defined actor category under the applicable regulatory text.

Best practices

Determine whether your organization qualifies as a regulated actor under the Information Blocking Rule, recognizing that this classification is defined separately from HIPAA covered entity or business associate status.
Reconcile Information Blocking Rule obligations with HIPAA Privacy and Security Rule requirements, since a practice permitted under HIPAA may still need to fit a recognized information blocking exception.
Review the defined exceptions and their specific conditions carefully before relying on any of them, documenting how each condition is satisfied for practices that limit access, exchange, or use of EHI.
Confirm the current regulatory definition of electronic health information and any scoping provisions against applicable federal guidance rather than assuming it matches HIPAA's ePHI or PHI.
Maintain documented policies and rationale for decisions that restrict information sharing, so that reliance on an exception can be demonstrated if questioned.
Monitor for updates to the rule, its exceptions, and enforcement mechanisms, and verify penalty and enforcement details against current federal guidance, since these provisions are subject to change over time.