Patient portals — the secure websites and apps where patients view records, message their care team, and access results — have moved from a nice-to-have to a regulatory expectation. A major driver of that shift is the 21st Century Cures Act and the rules that implement it.
What the Cures Act changed
The 21st Century Cures Act, enacted in 2016, included provisions to advance interoperability and to discourage “information blocking” — practices that interfere with the access, exchange, or use of electronic health information. ASTP/ONC issued rules to implement these provisions, establishing requirements that affect how providers, health IT developers, and health information networks handle electronic health information.
Information blocking, in brief
Under the information blocking regulations, actors covered by the rule generally may not engage in practices likely to interfere with access, exchange, or use of electronic health information, unless an exception applies. The rule defines a set of specific exceptions that describe reasonable and necessary activities that are not considered information blocking when their conditions are met.
The role of APIs
The Cures Act rules also require certified health IT to support standardized APIs based on HL7 FHIR. These APIs let patients use apps of their choice to retrieve their data, rather than being limited to the vendor's own portal. For practices, this means the portal is part of a larger ecosystem of patient-facing access.
What practices should do
- Understand that delaying or withholding access to electronic health information can implicate the information blocking rules unless an exception applies.
- Configure the portal so results and notes are released according to your policies and applicable law.
- Train staff on how to respond to patient and app access requests.
- Keep written policies that document how you handle access and any applicable exceptions.
A balanced view
Expanded access is generally good for patients, but it raises real workflow questions — for example, how to handle sensitive results released to a portal before a clinician has spoken with the patient. The rules anticipate some of this through exceptions, and many practices adopt thoughtful release policies. Because requirements and exceptions are detailed and have evolved over time, confirm current specifics with official ASTP/ONC and HHS resources.
Designing a humane release policy
Many practices wrestle with the timing of result release. Patients value seeing results quickly, and the information blocking rules discourage unnecessary delays — but some results are emotionally significant and benefit from a clinician's context. Practices typically address this by setting clear, consistent policies rather than ad hoc delays: deciding in advance how different categories of results are released, ensuring patients know they may see results before a call, and committing to prompt follow-up. The goal is to honor access while still supporting patients through difficult news.
Communicating with patients
Patient education smooths the transition to faster access. A short portal message or visit-time explanation can prepare patients for the possibility of seeing results early, tell them how to reach the care team with questions, and set expectations for follow-up. When patients understand the system, immediate access becomes a feature rather than a source of anxiety.
The bigger picture
The Cures Act rules reflect a broader policy direction in U.S. health care: patients should be able to get their electronic health information easily and use the apps they choose. Portals, FHIR APIs, and the information blocking provisions all push in the same direction. For practices, the practical task is to configure systems and policies so that openness is the default, exceptions are used only when genuinely warranted, and patients are supported along the way.