Skip to main content
Call
Complianceaka Info Blocking, ONC Information Blocking Rule, Cures Act Information Blocking

What is Information Blocking? Definition, Formula, and Benchmark

Reviewed by QuickIntell RCM Editorial Team · Last reviewed

Updated

Definition

Information blocking is any practice by a healthcare provider, health IT developer, or HIE that interferes with the access, exchange, or use of electronic health information except as required by law. The ONC Information Blocking Rule prohibits such practices with defined exceptions, effective since 2021.

Overview

Information Blocking is a federal regulatory concept defined by the 21st Century Cures Act and ONC's implementing regulations as any practice by a healthcare provider, health IT developer of certified health IT, health information exchange, or health information network that is likely to interfere with the access, exchange, or use of electronic health information, except as required by law or as permitted by an exception.

The concept was codified in response to longstanding industry concerns that data-sharing frictions — vendor-created or provider-created — were limiting interoperability despite technical standards being available. Information Blocking regulations make such frictions potentially illegal, with enforcement mechanisms including CMS Medicare participation, OIG civil monetary penalties, and specific technical-certification consequences.

Practices that potentially constitute information blocking include fees that charge patients or other providers for electronic access beyond regulatory allowances, requirements for business-associate or data-use agreements that are disproportionate, configuration choices that prevent use of certified FHIR APIs, contractual provisions that restrict data-sharing, and delays or refusals without a defined exception.

The rule defines specific exceptions under which behavior that might otherwise constitute information blocking is permitted. These include preventing harm (withholding data that could cause physical harm to the patient or another person), privacy (honoring patient requests for restrictions), security (preventing access that would compromise data security), infeasibility (technical inability to fulfill requests), health IT performance (temporary unavailability for maintenance), content and manner (reasonable restrictions on content type and delivery method), fees (reasonable cost-recovery within defined limits), and licensing (appropriate intellectual property protections).

Compliance requires providers and vendors to carefully evaluate practices. A provider refusing to share records with a competing practice due to a business dispute is likely information blocking. A provider charging a fee exceeding cost-recovery limits for patient-access records is likely information blocking. A vendor configuring FHIR APIs in ways that prevent app access is likely information blocking. Each of these situations requires analysis against the specific exception criteria.

Enforcement mechanisms vary by entity type. Health IT developers and HIEs face OIG civil monetary penalties (up to $1M per violation). Healthcare providers face Medicare participation consequences. The specific enforcement infrastructure continues to develop as CMS and OIG operationalize the statutory authorities.

For RCM and healthcare-operations leaders, information-blocking compliance has become a top-of-mind regulatory topic. Routine practices around data-sharing fees, release-of-information delays, vendor-contract terms, and API-access configuration should be audited against the rule. Missteps can be consequential. Several high-profile enforcement actions in 2024 have clarified enforcement direction.

Industry benchmark

ONC Information Blocking Rule effective: April 2021. OIG enforcement authority for HIT developers and HIEs: $1M per violation. First major enforcement actions in 2024.

Worked example

A health system charges patients $25 per request for electronic-format records transferred to a third-party aggregator app. After information-blocking review, the fee is found to exceed cost-recovery limits and constitute information blocking. The system changes policy to zero fee for FHIR-API access and documents cost-recovery limits for other channels.

Frequently asked questions — Information Blocking

Who does the rule apply to?

Healthcare providers, health IT developers of certified health IT, health information exchanges, and health information networks. The definitions are broad and capture most entities in the US healthcare data ecosystem.

What are the main exceptions?

Preventing harm, privacy, security, infeasibility, health IT performance, content and manner, fees, and licensing. Each has specific criteria that must be met to qualify as a legitimate exception.

What are the penalties?

Health IT developers and HIEs face OIG civil monetary penalties up to $1M per violation. Healthcare providers face Medicare participation consequences. Enforcement continues to develop as the program matures.

Disclaimer

This glossary entry is operational reference for revenue-cycle and medical-billing professionals. It is not legal, clinical, or contractual advice. Industry benchmarks cite named public sources where available; always verify against the current guidance from the authority body before relying on a number in a contract, policy, or compliance filing.