Overview
The 21st Century Cures Act is a 2016 federal law with broad healthcare scope including drug-development reforms, NIH research funding, mental-health and substance-use disorder provisions, and — most significant for healthcare interoperability — mandates establishing the information-blocking prohibition and patient electronic-access-to-health-records requirements. The interoperability provisions are implemented through ONC and CMS regulations published between 2020 and 2024.
The key interoperability provisions include authorization for ONC to prohibit information blocking by providers, health IT developers, HIEs, and HINs; authorization for ONC to certify health IT with specific interoperability-related criteria; mandate that certified health IT expose standardized APIs for patient access; establishment of the Trusted Exchange Framework and Common Agreement (TEFCA) for nationwide data exchange; and authorization for HHS to require electronic prior authorization across Medicare programs.
ONC's implementing regulations include the Cures Act Final Rule (2020) establishing information-blocking definitions and exceptions, certified health IT API requirements (FHIR R4 Patient Access), and US Core version requirements. Subsequent rules (HTI-1 Final Rule, 2024) have expanded certification criteria, added certification for predictive decision support, and further strengthened interoperability requirements.
CMS's implementing regulations include the Interoperability and Patient Access Final Rule (CMS-9115-F, 2020) establishing the Patient Access API, Provider Directory API, and original Payer-to-Payer API; the Advancing Interoperability and Improving Prior Authorization Processes Final Rule (CMS-0057-F, 2024) mandating Da Vinci CRD, DTR, and PAS APIs for prior authorization and expanding payer-to-payer requirements.
For RCM and healthcare operations, the Cures Act's legacy is a fundamentally restructured data-sharing environment. What was once a patchwork of vendor-specific, state-specific, or relationship-specific data-exchange capabilities is now a federally-mandated baseline of FHIR-based interoperability with information-blocking prohibitions preventing practices that limit access. The regulatory framework has accelerated FHIR adoption, standardized API access patterns, and created app-developer ecosystems that were impractical in the pre-Cures era.
Enforcement of the Cures Act interoperability provisions has evolved gradually. OIG began accepting information-blocking complaints in 2021; first major enforcement actions came in 2024. CMS enforcement of Patient Access API and related CMS rules has been primarily through compliance reporting and Medicare participation consequences. Overall enforcement intensity continues to increase.
From a board-reporting standpoint, 21st Century Cures Act belongs in the compliance committee's quarterly dashboard. The reporting line should include volume, exception rate, and any open remediation action; reviewers tie 21st Century Cures Act metrics to the broader compliance program KPIs so an emerging 21st Century Cures Act risk surfaces before it becomes a formal finding. Pairing the 21st Century Cures Act trend with information blocking gives the committee a single view of whether the control environment is strengthening or drifting.
Compliance programs treat 21st Century Cures Act as a recurring audit trigger rather than a one-time policy exercise. The practical approach is a quarterly 21st Century Cures Act self-audit tied into the broader compliance calendar, with findings tracked against information blocking and fhir api so a 21st Century Cures Act gap cannot silently persist from one audit cycle to the next. Reviewers on this site pair every 21st Century Cures Act reference with the corresponding regulatory citation so the policy owner can trace the requirement back to its authoritative source.
Industry benchmark
Cures Act signed: December 2016. ONC Final Rule effective: April 2021 (information blocking). CMS-9115-F effective: 2021. CMS-0057-F effective: 2024 with rolling compliance dates through 2027. HTI-1 Final Rule: 2024.
Worked example
A patient requests electronic access to their hospital records via a third-party aggregation app. Under Cures Act implementing rules, the hospital must provide access via certified-EHR FHIR Patient Access API. The app uses SMART on FHIR to authenticate and US Core profiles to interpret returned data. No fee is charged because the access is patient-authorized app access that falls under the information-blocking patient-access provisions.
Frequently asked questions — 21st Century Cures Act
When was the Cures Act passed?
Signed into law December 2016. Implementing regulations from ONC and CMS have been published in stages from 2020 through 2024, with full compliance dates continuing to roll forward.
What are the main interoperability provisions?
Information-blocking prohibition, mandate for patient-access APIs using FHIR, authorization for ONC certification requirements, establishment of TEFCA, and authorization for electronic prior-authorization rules.
What is HTI-1?
The Health Data, Technology, and Interoperability Final Rule (HTI-1) published by ONC in 2024. Expands certification criteria, adds predictive decision-support certification, and strengthens interoperability requirements beyond the original Cures Act Final Rule.
Disclaimer
This glossary entry is operational reference for revenue-cycle and medical-billing professionals. It is not legal, clinical, or contractual advice. Industry benchmarks cite named public sources where available; always verify against the current guidance from the authority body before relying on a number in a contract, policy, or compliance filing.