Get Compliance Tools

Information Blocking Rule & HIPAA: ONC Interoperability Guide

Last updated: March 2026 | Regulatory Deep Dive

Regulatory Background

The Information Blocking Rule (21st Century Cures Act Section 4004) prohibits healthcare providers, health information networks, and health information exchanges from blocking or unreasonably interfering with the exchange or use of electronic health information (EHI). Administered by the Office of the National Coordinator for Health Information Technology (ONC) and the Centers for Medicare & Medicaid Services (CMS), the rule aims to promote healthcare interoperability and patient access to their electronic health information. The rule is closely integrated with HIPAA but creates separate regulatory obligations and enforcement mechanisms.

Legislative Intent

Congress enacted the information blocking provisions to address documented cases where healthcare organizations were restricting patient access to records or preventing data exchange with other healthcare providers as a business practice. The rule ensures that patients have unfettered access to their health information and that the healthcare system can exchange data efficiently.

Key Context: While HIPAA governs privacy and security of health information, the Information Blocking Rule focuses on ensuring that health information is readily available and exchangeable. The two regulations complement each other: HIPAA protects how data is handled, while the Information Blocking Rule ensures the data is accessible.

Specific Information Blocking Provisions

Definition of Information Blocking

The rule prohibits practices, workflows, or technologies that reasonably result in:

Prohibited Practices

The rule specifically prohibits:

Required Interoperability Standards and Methods

Healthcare organizations must support specific standards for data exchange:

FHIR API Requirements

Electronic Exchange Standards

Patient Right to Copies

Enforcement and Exceptions

Enforcement Authority

Enforcement of the Information Blocking Rule is divided among federal agencies, with different mechanisms applying to health IT developers, health information networks and healthcare providers. Confirm which agency and which mechanism applies to your organization before relying on any specific enforcement path.

Penalties

Exceptions to Information Blocking Prohibition

The rule provides limited exceptions when information blocking may be permissible:

Burden of Proof

The regulation assumes information blocking occurred if practices reasonably result in blocking. The organization must prove the exception applies and was properly documented.

Implementation Guidance

System and Technology Assessment

  1. Interoperability Audit: Assess current systems for FHIR, Direct, and HL7 compliance
  2. API Inventory: Document all APIs exposing EHI and verify FHIR compliance
  3. Integration Review: Evaluate health information exchange (HIE) connections and standards used
  4. Vendor Assessment: Verify EHR and technology vendors support required interoperability standards
  5. Performance Testing: Test API response times and functionality

Policy and Procedure Development

Technical Implementation

Patient Access Process

Monitoring and Compliance

Exception Documentation

If claiming an exception to information blocking prohibition, documented must include:

Frequently Asked Questions

Does our organization need to implement a patient portal?

While the Information Blocking Rule doesn't explicitly require a patient portal, it requires that patients have electronic access to their EHI. A patient portal is a practical way to provide this access and is increasingly expected. Alternative methods include providing EHI on a USB drive, CD, or through email, but a portal is more patient-friendly and typically more practical. If your EHR vendor offers a patient portal, implementing it is advisable for compliance and avoiding information blocking accusations. The portal must allow patients to access, download, and transmit their EHI to third-party applications of their choice.

Can we charge for patient access to their EHI?

You can charge reasonable fees only for the actual cost of copying and delivering EHI. However, fees must not prevent or substantially impede access. For electronic copies in standard formats, fees should be minimal or nonexistent since the cost is negligible. For paper copies, you can charge for actual copying costs and postage. You cannot charge for "research," data compilation, or other inflated fees. If patients cannot afford fees, consider waiving them. Excessive fees that effectively prevent access violate the information blocking prohibition and can result in ONC enforcement actions and significant penalties.

What does FHIR compliance mean in practice?

FHIR (Fast Healthcare Interoperability Resources) Release 4 is a modern standard for exchanging healthcare data using REST APIs and JSON format. FHIR compliance means: (1) Your APIs conform to FHIR R4 specifications, (2) Clinical data elements are mapped to appropriate FHIR resources, (3) APIs respond within required timeframes, (4) APIs support standard authentication mechanisms, and (5) Patients and authorized third parties can access data through your FHIR APIs. Your EHR vendor should handle most of the technical FHIR implementation. Your role is ensuring your organization supports patient API access, configures your system to expose appropriate data, and monitors API availability and performance. Contact your vendor about their FHIR capabilities and timeline to full R4 compliance if not yet achieved.

How do we authorize third-party applications to access patient data?

The Information Blocking Rule requires supporting patient-authorized third-party application access to EHI. This means: (1) Patients can authorize apps (fitness trackers, personal health records, etc.) to connect to your APIs and access their data, (2) Your system uses standard authorization mechanisms like OAuth 2.0 to manage app access, (3) Patients retain control and can revoke app access at any time, (4) Your system requires patients to explicitly authorize each app before granting access, and (5) App access is limited to data the patient has authorized. Most modern patient portals support this through API app authorization features. Your EHR should provide developer documentation and tools for third parties to integrate with your FHIR APIs. Supporting third-party app integration demonstrates non-blocking compliance and provides value to patients by expanding their options for managing their health information.

Ensure Interoperability Compliance

Medcurity helps healthcare organizations assess information blocking risk, implement FHIR APIs, and ensure patient data accessibility in compliance with ONC requirements.

Assess Your Interoperability Status