The Current State of Information Blocking: What Healthcare Providers Need to Know Now
Since the enactment of the 21st Century Cures Act, the concept of information blocking has steadily moved from theory to operational reality. Over the past year, federal agencies have signaled a shift from education and guidance toward active enforcement. For healthcare providers, understanding where things stand today is important. The financial and programmatic consequences of non-compliance are now defined and in effect.
Below is a practical overview of the current landscape of information blocking, what has changed, and what your organization should be focused on now.
A Quick Refresher: What Is Information Blocking?
Information blocking is defined as a practice likely to interfere with access, exchange or use of electronic health information (EHI), except as covered by an exception or as the law requires otherwise.
This prohibition applies to three categories of "actors":
- Developers of certified health IT (including electronic health record [EHR] vendors)
- Health Information Exchanges (HIEs) and Health Information Networks (HINs)
The regulatory framework was established through the Office of National Coordinator's (ONC) Cures Act Final Rule (45 CFR Part 171), which also defined eight exceptions that allow for certain practices that otherwise would be considered information blocking when specific conditions are met (e.g., privacy, security, infeasibility, fees). Additional exceptions have since been added through subsequent regulations, such as the Protecting Care Access Exception in HTI-3.
The burden of meeting an exception rests with the actor. If your organization relies on an exception, you should be prepared to demonstrate how the exception's conditions were met.
Provider Disincentives Are Now in Effect
The Department of Health & Human Services (HHS) finalized a rule establishing "appropriate disincentives" for healthcare providers found to have engaged in information blocking. Effective July 31, 2024, providers referred by the Office of Inspector General (OIG) may face:
- Reductions in Medicare Promoting Interoperability payments
- Zero scores under MIPS Promoting Interoperability measures, which could reduce or eliminate the associated positive payment adjustment
- Ineligibility for participation in the Medicare Shared Savings Program
These consequences are defined in the 21st Century Cures Act: Establishment of Disincentives for Health Care Providers That Have Committed Information Blocking final rule and tied to Medicare reimbursement. Information blocking is not solely a technical or IT concern, it intersects directly with how providers participate in federal payment programs.
Enforcement Has Entered a New Phase
For several years, information blocking enforcement was described as forthcoming. That period has passed.
In September 2025, HHS, ONC, and the Office of Inspector General (OIG) jointly announced a coordinated enforcement strategy. The agencies have indicated they are actively investigating complaints and expect enforcement actions in the near term.
ONC also maintains a public complaint portal where patients, providers, payers or staff can report a potential information blocking concern. When a complaint is received, OIG investigates and substantiated findings can result in the disincentives described above.
Increased Scrutiny of Routine Practices
Under the information blocking regulation (45 CFR Part 171), the focus is on whether a practice interferes with access, exchange or use of EHI, not solely on whether your organization intended to block information. Areas receiving particular attention include:
- Delays in responding to patient access requests. Patients have a right to their EHI, and delays that lack documented justification can raise information blocking concerns.
- Not releasing records to other treating providers when electronic exchange is technically available through existing systems. For example, a referring provider requests a patient's medication list, and your system is connected to an HIE that could deliver it electronically, but staff directs them to fax a request instead, adding days of delay when the capability to share immediately already existed.
- Policies or workflows that add unnecessary friction. For example, requiring faxed authorizations when electronic exchange is available, or routing requests through processes that create avoidable delays.
- Staff unfamiliarity with obligations. Staff who default to declining a request without understanding what the law permits and requires may inadvertently create risk for the organization.
ONC has emphasized that the analysis focuses on whether a practice interfered with access, exchange or use of EHI, not solely on whether the organization intended to block information.
What Providers Should Be Doing Now
The current environment calls for attention to several areas:
- Review your data release and exchange processes. Walk through what happens when a patient requests their records, when another provider requests clinical data or when a health plan seeks information. Are there delays that could be shortened? Manual steps that could be streamlined? Processes that persist out of habit rather than necessity?
- Document your exception reliance. If your organization limits access or exchange in certain circumstances (e.g., for privacy, security or because a request is infeasible), make sure you can articulate which exception applies and how its conditions are met. Written documentation of your reasoning strengthens your position. (A complete list of the information blocking exceptions is available in the regulatory text at 45 CFR Part 171.)
- Train your staff. The people who handle records requests, manage patient portal access and respond to exchange inquiries should understand that information blocking carries defined federal consequences. Awareness at the operational level may help mitigate compliance risk that can arise from well-intentioned responses.
- Use your EHR's interoperability capabilities. If your technology supports electronic exchange, patient portal access and standardized data sharing, but your operational workflows aren't fully utilizing those capabilities, it's worth evaluating whether that gap creates risk.
- Respond to requests promptly. Timeliness matters. A process that provides access but takes significantly longer than necessary may still raise information blocking questions if the delay is not supported by an applicable exception.
How Technology Can Support Compliance
Netsmart offers capabilities aimed at supporting the access and exchange obligations that information blocking rules contemplate. Capabilities to consider when evaluating your organization's compliance readiness include:
- Patient portal access: giving patients self-service access to their EHI without requiring manual intervention from staff
- Standardized data exchange through C-CDA documents, FHIR APIs, and electronic referral workflows that enable information to flow to other providers and systems
- Audit trails that document when information was requested, provided or denied, supporting your ability to demonstrate compliance if questions arise
- Interoperability infrastructure including connections to HIEs, health plans and other networks that facilitate exchange without requiring staff to manually process every request
For Netsmart clients, these capabilities may be available as part of your current configuration or as additional modules and services. If your organization hasn't recently assessed which of these capabilities are in place and operational, reach out to your Netsmart representative to discuss what options are available to help support your compliance needs.
Looking Ahead
The current regulatory environment favors organizations that:
- Treat information sharing as the expected default rather than the exception
- Have staff who are trained on their obligations
- Can document their reasoning when an exception is relied upon
- Utilize the interoperability capabilities that are available
If you have questions about how information blocking requirements intersect with your organization's workflows, we encourage you to engage with your compliance team and your technology partners.