US Medical BillingRevenue cycle solutions
Compliance and Regulations

The Information Blocking Rule

Most compliance rules a billing operation lives under tell it what it must not disclose. The information blocking rule runs the other way: it is a federal prohibition on getting in the way of health information that should move. Created by the 21st Century Cures Act and written into regulation at 45 CFR Part 171, it makes it unlawful for a health care provider, a health IT developer, or a health information network to engage in a practice that is likely to interfere with the access, exchange, or use of electronic health information — unless the practice is required by law or fits one of the rule's exceptions. A practice is an actor under this rule, its billing records are within the information the rule protects, and the everyday choices a billing office makes about sharing records electronically are exactly where it applies.

Updated 16 min read

On this page

Key takeaways

What the information blocking rule is

The information blocking rule is a federal prohibition on interfering with the flow of electronic health information. It comes from the 21st Century Cures Act, which directed the Department of Health and Human Services to define information blocking and to identify the reasonable and necessary activities that do not count as it (42 U.S.C. 300jj-52). The Office of the National Coordinator for Health Information Technology (ONC) — the HHS office responsible for health IT policy — wrote the implementing regulations, which live at 45 CFR Part 171. The rule became applicable on April 5, 2021.

The regulatory definition is compact. Information blocking is a practice that, except as required by law or covered by one of the rule's exceptions, is likely to interfere with access, exchange, or use of electronic health information — combined with a knowledge element that depends on who the actor is (45 CFR 171.103). Two things about that definition are worth pausing on. It reaches a practice that is merely likely to interfere — the rule defines interference as preventing, materially discouraging, or otherwise inhibiting access, exchange, or use — so a flat refusal is not required; a policy, a fee, or a delay that discourages sharing can qualify. And it is written as a prohibition on the actor, not as a right held by a requester, which is what distinguishes it from the HIPAA right of access.

Not the same as the HIPAA right of access

Who the rule applies to

The rule uses one word — actor — for the parties bound by it, and defines it as three kinds of entity (45 CFR 171.102):

Health care providers
This takes the broad statutory meaning of health care provider (42 U.S.C. 300jj) — the long list that includes hospitals, physicians, practitioners, and the other providers named there. A physician practice, and the billing operation inside it, is a health care provider actor. This is the category that matters most for the audience of this article.
Health IT developers of certified health IT
An entity that develops or offers health information technology and has at least one module certified under ONC's certification program. This is the electronic health record and health-IT vendor category — the developers whose systems providers use.
Health information networks and health information exchanges
An entity that determines or controls the policies or agreements governing how electronic health information is accessed, exchanged, or used among unaffiliated participants. These are the intermediaries that move information between organizations.

The distinction among the three is not cosmetic. As the enforcement section below explains, the consequence of committing information blocking is entirely different for a provider than for a developer or a network, and even the standard of knowledge the rule holds them to is different. So the first question in any information blocking analysis is which kind of actor is involved — and for a practice, the answer is a health care provider.

What counts as electronic health information — and why billing is in it

The rule protects a defined category of data called electronic health information, or EHI, and the definition is the reason a billing operation is in scope. Under 45 CFR 171.102, EHI is electronic protected health information to the extent it would be included in a designated record set — the same designated record set the HIPAA rules use. Two categories are carved out: psychotherapy notes, and information compiled in reasonable anticipation of, or for use in, a legal proceeding. Everything else in the set that is held electronically is EHI.

That matters because the designated record set expressly includes a provider's billing records, not only the clinical chart (45 CFR 164.501). So the electronic claim data a practice submits, the statements and remittances it holds, and the payment information in a patient's account are EHI when they sit in that set. A billing office is not on the edge of this rule; the records it works with every day are precisely the information the rule protects.

The EHI definition reached its full scope in stages

The knowledge standard, and why providers get a higher bar

Interfering with EHI is not, by itself, information blocking — the actor also has to have crossed a knowledge threshold, and the rule sets that threshold differently for the two sides (45 CFR 171.103(b)):

  • Developers, networks, and exchanges — knows or should know. For a health IT developer, health information network, or health information exchange, a practice is information blocking if the actor knows, or should know, that it is likely to interfere with access, exchange, or use of EHI. This is a constructive-knowledge standard: an actor cannot escape it by looking away from what it ought to have understood.
  • Health care providers — knows it is unreasonable. For a health care provider, the practice is information blocking only if the provider knows that the practice is unreasonable and is likely to interfere. This is a higher, actual-knowledge bar, and it includes the extra element that the provider knew the practice was unreasonable.

The higher provider bar reflects a deliberate policy choice carried down from the statute (42 U.S.C. 300jj-52(a)(1)(B)): a provider that makes a reasonable, good-faith decision about sharing information is not an information blocker just because the decision turned out to interfere. But the bar is not a shield for willful obstruction. A practice that adopts a policy it understands to be an unreasonable barrier to sharing — a blanket refusal to send records electronically, an access process engineered to be slow, a fee set to discourage requests — is the kind of conduct the standard is built to catch. Reasonableness is judged on the facts, which is why an exception, described next, is the safer place to stand than a bare claim that a practice was reasonable.

The exceptions: the room the rule builds in

The statute told the Secretary to identify the reasonable and necessary activities that do not constitute information blocking (42 U.S.C. 300jj-52(a)(3)), and the regulation does that through a set of exceptions. An exception is not a defense a practice raises after the fact so much as a safe course it can steer into: a practice that meets all of an exception's conditions is not information blocking at all. The exceptions are the mechanism that lets an actor decline or limit a request for a legitimate reason without violating the rule.

The exceptions are organized into two groups by what they excuse:

  • Exceptions for not fulfilling a request — reasons an actor may decline to provide access, exchange, or use of EHI at all: to prevent harm, to protect an individual's privacy, to protect the security of EHI, because the request is infeasible, and to maintain or improve health IT performance (45 CFR 171.201–171.205).
  • Exceptions for the procedures used to fulfill a request — reasons an actor may fulfill a request in a particular way rather than exactly as asked: limits on the manner in which it provides the information, the fees it charges, and the licensing of the interoperability elements needed to use the information (45 CFR 171.301–171.303).

Do not memorize a fixed count — check the current regulation

Where a billing operation runs into the rule

For a billing office the rule is not abstract, because the office is often the front door for the electronic information the rule protects. The practices most likely to raise an information blocking question are ordinary billing decisions made without the rule in mind:

  • Declining or delaying to share records electronically — insisting on paper, or on a slow manual process, when a practice can readily provide or transmit an electronic copy, can interfere with access or exchange. The point of the rule is that electronic information should move electronically when it can.
  • Fees that discourage access — a fee set high enough to deter a patient or another provider from obtaining EHI can be interference. This overlaps with, but is separate from, the HIPAA right-of-access fee limit; a practice charging for electronic records has to satisfy both the right-of-access fee standard and the information blocking Fees exception.
  • Conditioning sharing on the wrong things — refusing to release or transmit records because a balance is unpaid, or making a requester clear hurdles the rule does not permit, can interfere with access the requester is entitled to.
  • Not sharing for treatment and other permitted purposes — declining to send a patient's information to a treating provider, when no exception applies, is exactly the interference the rule was written to stop.

None of these is automatically a violation — a legitimate privacy, security, or infeasibility reason may fit an exception, and the provider knowledge standard is high. But each is a practice a billing office controls, which is why information blocking belongs in a practice's compliance thinking and not only in its IT department's. When a practice responds to a payer's request for records or a patient's request for a copy, the same question runs underneath: is anything about how the practice fulfills — or declines — that request likely to interfere with information that should be shared?

How the rule is enforced

The consequence of information blocking depends entirely on which kind of actor committed it — the statute created two separate enforcement tracks (42 U.S.C. 300jj-52(b)).

For health IT developers of certified health IT and for health information networks and exchanges, the HHS Office of Inspector General can impose civil monetary penalties of up to $1,000,000 per violation (42 U.S.C. 300jj-52(b)(2)(A)), under a final rule that added the penalties to OIG's civil-money-penalty regulations at 42 CFR Part 1003, with enforcement beginning September 1, 2023. OIG investigates selected complaints — it has said it prioritizes conduct such as that which caused patient harm, and that the top penalty is aimed at particularly egregious conduct — rather than pursuing every allegation.

Providers do not face the $1,000,000 penalty

Those provider disincentives were established by a CMS final rule and are built onto existing Medicare programs rather than imposed as a standalone fine. Under that rule, a provider found by OIG to have committed information blocking can be treated as not a meaningful user of certified electronic health record technology in the Medicare Promoting Interoperability Program (for eligible hospitals and critical access hospitals), receive a zero score in the Promoting Interoperability performance category of the Merit-based Incentive Payment System (MIPS) (for eligible clinicians), or be found ineligible to participate in the Medicare Shared Savings Program for a period. The common thread is that a provider's information blocking is felt through the Medicare payment and quality programs it already participates in — which is why this is a billing and revenue concern, not only a records-department one.

How a concern is reported

Building information blocking into the compliance program

A billing operation does not need to become an interoperability expert to stay on the right side of this rule. It needs a few defaults built into how it handles the electronic information it controls, and a place for the rule among the other duties in the Compliance and Regulations category — inside the practice's compliance program.

  1. Treat electronic sharing as the default

    When a practice can readily provide or transmit an electronic copy of EHI, do it electronically and promptly. A manual or paper process used where an electronic one is available is the pattern most likely to look like interference.
  2. Do not let an unpaid balance block sharing

    Conditioning the release or exchange of records on payment of a care bill can interfere with access the requester is entitled to — and it is already impermissible under the right of access. Keep the balance and the records on separate tracks.
  3. Ground any fee in the rules that limit it

    A fee for electronic records must satisfy both the HIPAA right-of-access fee standard and the information blocking Fees exception. Build the charge from what those rules allow, not from a number chosen to discourage requests.
  4. Use an exception on purpose, by its conditions

    When there is a legitimate reason to decline or limit a request — privacy, security, infeasibility, harm — identify the specific exception in 45 CFR Part 171 and confirm the practice meets every one of its conditions. A vague sense that a refusal was reasonable is weaker ground than an exception met on its terms.
  5. Route the hard calls, and document them

    Send a request that appears to require declining or limiting sharing to the person responsible for the practice's information-sharing policy, and record the reason and the exception relied on. As with the right of access, a biller's job is to recognize the issue and move it, not to decide it alone.

Educational, not legal advice

Common questions

Is the information blocking rule the same as the HIPAA right of access?

No. The HIPAA right of access is a patient's right to inspect and obtain a copy of their own records (45 CFR 164.524). Information blocking is a separate, broader prohibition from the 21st Century Cures Act (45 CFR Part 171): it bars an actor from a practice that is likely to interfere with the access, exchange, or use of electronic health information by any requester, including other providers and, for permitted purposes, health plans. A practice can meet a right-of-access request and still commit information blocking through a different practice — for example, a policy that makes electronic exchange with another provider unreasonably difficult.

Does the rule apply to a physician practice, or only to EHR vendors?

It applies to a physician practice. The rule reaches three kinds of actor: health care providers, health IT developers of certified health IT, and health information networks or exchanges (45 CFR 171.102). A physician practice is a health care provider actor. The consequences differ by actor type — providers face disincentives through Medicare programs rather than the civil monetary penalties that apply to developers and networks — but the prohibition itself covers the practice.

Are a practice's billing records covered by the rule?

They can be. The rule protects electronic health information (EHI), defined as electronic protected health information to the extent it is in a designated record set (45 CFR 171.102). The designated record set expressly includes a provider's billing records (45 CFR 164.501), so electronic claim data, statements, remittances, and payment information a practice holds are EHI when they sit in that set. Psychotherapy notes and information compiled for litigation are excluded.

What is the penalty for information blocking?

It depends on who commits it. A health IT developer, health information network, or health information exchange can be assessed a civil monetary penalty of up to $1,000,000 per violation by the HHS Office of Inspector General (42 U.S.C. 300jj-52(b)(2)). A health care provider does not face that penalty; instead a provider determined to have committed information blocking is subject to disincentives applied through existing Medicare programs — for example, losing meaningful-user status in the Promoting Interoperability Program, a zero score in the MIPS Promoting Interoperability category, or ineligibility to participate in the Shared Savings Program for a period.

Can we ever decline to share records without violating the rule?

Yes, when a recognized exception applies and the practice meets all of its conditions. The rule identifies exceptions for legitimate reasons to decline or limit sharing — preventing harm, protecting privacy, protecting security, infeasibility, and others — and a practice that satisfies an exception's conditions is not information blocking (45 CFR Part 171). The exceptions have specific, detailed conditions, and the set has been added to over time, so a practice should read the current text of the applicable exception rather than rely on a general summary. A practice is also never required to do something prohibited by law.

Authoritative sources

  • 42 U.S.C. § 300jj-52 — Information blocking (opens in a new tab)

    Office of the Law Revision Counsel (via the Cornell Legal Information Institute). Section 3022 of the Public Health Service Act, added by section 4004 of the 21st Century Cures Act. Defines information blocking and its two knowledge standards, directs the Secretary to identify activities that do not constitute it, authorizes civil monetary penalties of up to $1,000,000 per violation for developers, networks, and exchanges, and directs that providers be referred for appropriate disincentives.

  • 45 CFR § 171.103 — Information blocking (opens in a new tab)

    U.S. Department of Health and Human Services (via the Cornell Legal Information Institute). Defines information blocking as a practice, except as required by law or covered by an exception, that is likely to interfere with access, exchange, or use of electronic health information, with the knowledge standard set separately for developers/networks (knows or should know) and health care providers (knows the practice is unreasonable).

  • 45 CFR § 171.102 — Information blocking definitions (opens in a new tab)

    U.S. Department of Health and Human Services (via the Cornell Legal Information Institute). Defines the actors (health care provider, health IT developer of certified health IT, health information network or exchange), electronic health information (electronic PHI to the extent it is in a designated record set, excluding psychotherapy notes and litigation-compiled information), and the access, exchange, use, and interference terms the rule turns on.

  • Establishment of Disincentives for Health Care Providers That Have Committed Information Blocking (89 FR 42962) (opens in a new tab)

    HHS (Office of the National Coordinator) and the Centers for Medicare & Medicaid Services, via the Federal Register. The final rule establishing the disincentives that apply to a health care provider determined to have committed information blocking, through the Medicare Promoting Interoperability Program, the MIPS Promoting Interoperability performance category, and the Medicare Shared Savings Program.

  • Report Information Blocking — HealthIT.gov (opens in a new tab)

    U.S. Department of Health and Human Services. The federal portal for reporting a concern that an actor has engaged in information blocking; complaints inform the Office of Inspector General's enforcement.

Ready to improve your revenue cycle?

Explore our services and knowledge base to see how we can help.