Regulation & Incentives

The Information Blocking Rule for Practices

The information blocking rule reshaped how practices handle electronic health information. Stemming from the 21st Century Cures Act, it generally prohibits covered actors from interfering with the access, exchange, or use of electronic health information — with a defined set of exceptions. Here is what practices should understand.

Who is covered

The rule applies to specific “actors”: health care providers, health IT developers of certified health IT, and health information networks/health information exchanges. Most physician practices fall under the health care provider category, so the rule's expectations apply to them.

What information is involved

The rule centers on electronic health information (EHI). Practically, this means the electronic protected health information in a designated record set that you maintain. If a patient or another permitted party requests access, exchange, or use of that information, you generally cannot interfere with it without a valid reason recognized by the rule.

Key idea: Information blocking is a practice or pattern likely to interfere with access, exchange, or use of EHI. The rule does not require you to do the impossible — but it does discourage unnecessary delays, vague refusals, and obstacles that are not justified by a recognized exception.

The exceptions

The regulations define exceptions describing activities that, when their conditions are met, are not considered information blocking. These include, among others, exceptions related to preventing harm, protecting privacy, ensuring security, infeasibility, and certain content and manner or fee-related practices. Each exception has specific conditions, so meeting one requires more than a general justification.

What practices should do

  • Adopt clear policies for responding to requests to access, exchange, or use EHI.
  • Default toward timely release of information through your portal and APIs unless an exception genuinely applies.
  • Document the basis when you rely on an exception, including the specific conditions you met.
  • Train staff so that front-line decisions align with your policies.
  • Review vendor configuration so the EHR is not silently creating barriers to access.

Enforcement context

Disincentives and penalties associated with information blocking have been established through federal rulemaking and apply differently depending on the type of actor. Because the enforcement framework and details continue to develop, confirm the current state of the rules through official ASTP/ONC and HHS resources, and consult counsel for specific situations.

Bottom line

The information blocking rule pushes practices toward openness with electronic health information. Build policies and EHR configurations that release information promptly, lean on exceptions only when their conditions are truly met, and keep documentation that shows your reasoning.

Common situations practices encounter

Some recurring scenarios help make the rule concrete:

  • A patient requests their records be sent to an app. Refusing simply because it is not your portal could be problematic; the rule and supporting APIs are designed to enable patient-chosen apps.
  • Test results are ready before the clinician has called. A blanket policy of delaying all results to avoid this is risky; a thoughtful, consistent release policy is the better path.
  • Another provider asks for records to treat your shared patient. Interfering without a valid reason can implicate the rule; timely exchange supports both compliance and care.

The role of your EHR vendor

Developers of certified health IT are themselves actors under the rule and have obligations around enabling access and exchange. If your EHR makes legitimate access difficult — for example, by making data export cumbersome or APIs hard to use — that is worth raising with the vendor. When evaluating systems, ask specifically how the product supports patient access via FHIR APIs and how it handles records requests, so you are not inheriting barriers you will later have to explain.

Practical posture

The most defensible posture is a consistent one: release electronic health information promptly by default, document the specific conditions whenever you rely on an exception, train staff so front-line decisions match policy, and revisit your approach as the enforcement framework continues to develop. Consistency and documentation are your best protection if a practice's handling of a request is ever questioned.