HIPAA and Information Blocking

HIPAA tells you when you may share. A different federal rule tells you when you may not refuse.

Signals that your organization has exposure

None of these is a violation on its own. Each one is a practice worth examining against Part 171 before somebody else examines it for you.
  • Results are held for a fixed period before patients can see them, regardless of the patient.
  • Staff decline requests verbally without recording the legal basis for the refusal.
  • Electronic requests are answered on paper because that is how the department works.
  • Patient-designated apps are refused without a written, tailored security rationale.
  • A per-page fee schedule is applied to an individual's electronic access request.
  • No written policy exists behind the refusals your team makes most often.

Most HIPAA training teaches staff to be careful about releasing information. That instinct is correct, and it is also incomplete. Since 2021 a separate federal regulation at 45 CFR Part 171 has made it unlawful for certain actors to interfere with the access, exchange, or use of electronic health information without a legal basis. The most common desk-level reflex in American health care, which is to say HIPAA and stop there, is now a compliance risk in its own right.

This guide explains who the rule reaches, what electronic health information means, all ten exceptions with their section numbers, how the rule interacts with the HIPAA Privacy Rule, and what the penalties look like for providers compared with developers and networks. It is written for privacy officers, release of information teams, and the people who actually answer the request.

10exceptions in Part 171eight original, plus TEFCA Manner and Protecting Care Access
3categories of actorproviders, certified health IT developers, and HIEs or HINs
$1Mmaximum civil penalty per violationapplies to developers, HIEs, and HINs, not to providers

Where the rule comes from

The prohibition is statutory. Section 4004 of the 21st Century Cures Act added a new section to the Public Health Service Act, codified at 42 U.S.C. 300jj-52, defining information blocking and directing the Secretary to identify practices that would be reasonable and necessary and therefore should not be treated as blocking. Those practices became the exceptions. The implementing regulation is 45 CFR Part 171.

The statutory definition is worth reading slowly, because two phrases do most of the work. A practice is information blocking when it is likely to interfere with, prevent, or materially discourage access, exchange, or use of electronic health information, and when it is except as required by law or covered by an exception. Everything difficult about this rule lives inside that second clause. A refusal is lawful when a law compels it or an exception covers it. Preference, habit, and administrative convenience are not on that list.

Note also that the definition reaches practices that materially discourage exchange. An organization does not have to refuse anything to be exposed. Making a request slow, expensive, confusing, or procedurally heavier than the law requires can be enough. Delay is interference.

What counts as electronic health information

EHI is defined at 45 CFR 171.102 as electronic protected health information as that term is defined in 45 CFR 160.103, to the extent it would be included in a designated record set as defined in 45 CFR 164.501, regardless of whether the group of records is used or maintained by or for a covered entity.

Three consequences follow, and each one surprises somebody. First, the boundary of EHI is the designated record set, which is the same boundary that governs the HIPAA right of access. If a record is inside the designated record set, it is generally EHI. Second, the phrase about whether records are used or maintained by or for a covered entity means an actor can hold EHI without being a HIPAA covered entity at all. Third, the definition carries the same carve-outs the designated record set does, so psychotherapy notes and information compiled in reasonable anticipation of, or for use in, a civil, criminal, or administrative action or proceeding sit outside it.

Teams that already maintain a clear, written definition of their designated record set for HIPAA access purposes have most of this work done. Teams that have never written it down tend to discover the gap during an information blocking question, which is a poor time to start.

Who Is Covered

The rule applies to actors, and the definition is broader than most teams assume

An organization can be more than one type of actor at once. The knowledge standard is the practical difference between them.

Actor 1

Health care providers

The definition reaches far beyond hospitals and physician practices. It picks up clinics, pharmacies, laboratories, nursing facilities, ambulatory surgery centers, therapists, and many other categories drawn from the Public Health Service Act. A provider commits information blocking only when it knows the practice is unreasonable and likely to interfere with access, exchange, or use of EHI.

Actor 2

Health IT developers of certified health IT

Any developer that has health IT certified under the ONC Health IT Certification Program, and that offers it to others, is an actor for all of its practices, not only the certified module. The knowledge standard is lower here: the developer commits information blocking if it knows, or should know, that a practice is likely to interfere.

Actor 3

Health information networks and exchanges

An entity that determines, controls, or has the discretion to administer any requirement or agreement that governs how two or more unaffiliated parties exchange EHI is an HIN or HIE. Many organizations that do not call themselves an exchange still meet this functional test. The know-or-should-know standard applies to them too.

The Core Conflict

HIPAA is a permission rule. Part 171 is a sharing rule. Staff collide with the gap.

The HIPAA Privacy Rule spends most of its length describing permitted uses and disclosures. With a small number of exceptions, chiefly an individual's right of access and disclosures to HHS, it does not compel a covered entity to disclose anything. That structure trained a generation of health care staff to treat declining as the conservative choice.

Part 171 inverts that default for actors. Where HIPAA permits a disclosure and no other law prohibits it, an actor is expected to provide access, exchange, or use. ONC has been explicit that the information blocking rules and the HIPAA rules work together rather than in conflict, and that the mechanism for genuine legal conflicts is the required by law carve-out and the precondition not satisfied sub-exception, not a general right to decline.

The practical takeaway for training is narrow and specific. Staff should stop asking whether HIPAA requires the disclosure. They should ask whether any law forbids it, and if not, whether a documented exception applies.

  • A law that prohibits the disclosure removes the practice from the definition entirely.
  • A law that permits disclosure only after a condition is met points to 45 CFR 171.202(b).
  • A law that simply permits disclosure is not a basis for refusing.
  • Silence in the record about why a request was refused is itself a problem.

Questions that should replace 'does HIPAA require this?'

  • Is there a law that prohibits this specific disclosure to this specific requester?
  • If a precondition applies, is it truly unmet, and did we help the requester satisfy it?
  • Which of the ten exceptions are we relying on, by section number?
  • Do we have a written policy that covers this situation, applied consistently?
  • How long has this request been open, and can we defend that interval?

Decision Framework

A four-step test your team can actually run at the desk

Memorizing ten exception names does not help under pressure. Sorting the request into the right bucket does.
01

Does a law prohibit this disclosure?

If federal or state law bars the release, withholding is not information blocking at all. The statutory definition only reaches practices that are not required by law. You never reach the exceptions, because you never reach the prohibition. Document which law applies and why.

02

Does a law permit it only once a precondition is met?

Many privacy laws allow a disclosure only after a consent, authorization, or other condition is satisfied. If the precondition is genuinely unmet, the precondition not satisfied sub-exception at 45 CFR 171.202(b) can cover the refusal, but only with written policies applied consistently and a good faith effort to help the requester satisfy the condition.

03

Is it simply that the law permits sharing and you would rather not?

This is the bucket that creates liability. HIPAA is largely permissive: it tells you when you may disclose, not when you must. The information blocking rule closes that gap. If nothing prohibits the sharing and no exception fits, declining, delaying, or making the request unreasonably difficult is information blocking.

04

If you are relying on an exception, can you prove every condition?

The exceptions are voluntary safe harbors, not general excuses. Each one carries specific conditions, and an actor that fails any condition loses the protection of that exception for that practice. Conduct that misses an exception is not automatically a violation, but it is then judged on the facts with no safe harbor.

Exceptions, Part One

Six exceptions that involve refusing to fulfill a request

Subpart B of 45 CFR Part 171. These cover situations where the actor does not fulfill the request at all.

45 CFR 171.201

Preventing Harm Exception

Covers practices reasonably necessary to reduce a risk of harm. The rule sets a type-of-harm standard, a level-of-harm standard, and conditions on who may make the determination. General discomfort at a patient reading a result before a clinician calls does not meet it. Blanket delays applied to every result are the classic failure here.

45 CFR 171.202

Privacy Exception

Four sub-exceptions: an unmet precondition under state or federal privacy law, a developer not covered by HIPAA following its disclosed privacy policy, a denial of an individual's own access request that satisfies 45 CFR 164.524(a)(2), and an individual's own unprompted request that their EHI not be shared. Each requires documented policy and consistent application.

45 CFR 171.203

Security Exception

Protects practices directly related to safeguarding the confidentiality, integrity, and availability of EHI. The practice must be tailored to specific security risks and either implemented under a written organizational security policy or supported by a documented case-by-case determination. Security cannot be an unwritten instinct after the fact.

45 CFR 171.204

Infeasibility Exception

Applies when an uncontrollable event, a genuine inability to segment the requested EHI, or a documented infeasibility determination prevents fulfillment. The actor must respond to the requester in writing within ten business days explaining why the request is infeasible.

45 CFR 171.205

Health IT Performance Exception

Covers making health IT temporarily unavailable for maintenance or improvements. Downtime must be for a period no longer than necessary, planned where possible, and consistent with existing service level agreements. Indefinite or convenient outages do not qualify.

45 CFR 171.206

Protecting Care Access Exception

Added on December 17, 2024. It covers practices intended to reduce the risk of legal exposure connected to lawful reproductive health care, for patients or for the people who provide or facilitate that care. It requires a good faith belief, appropriate tailoring, and either a written policy or a documented case-by-case determination.

Exceptions, Part Two

Four exceptions that involve how a request gets fulfilled

Subparts C and D. These cover situations where the actor does fulfill the request, but on particular terms, in a particular manner, or for a fee.

45 CFR 171.301

Content and Manner Exception

Establishes what an actor must provide and how. If the actor cannot fulfill the request in the manner asked, it must fulfill in an alternative manner following a defined order of priority, starting with standards-based technology. This is the exception that prevents an actor from answering an API request by mailing a stack of paper.

45 CFR 171.302

Fees Exception

Permits charging fees that meet strict conditions. The fees must be based on objective, uniformly applied criteria and reasonably related to costs actually incurred. Several categories are expressly excluded, including fees based on electronic access by an individual to their own EHI.

45 CFR 171.303

Licensing Exception

Allows an actor to license interoperability elements on reasonable and non-discriminatory terms. It sets a ten business day window to begin license negotiations and a further thirty business days to reach agreement, plus limits on royalties, scope, and collateral terms.

45 CFR 171.403

TEFCA Manner Exception

The tenth exception, sitting in its own subpart. Where both the actor and the requester are part of the Trusted Exchange Framework and Common Agreement, the actor may limit fulfillment to the TEFCA manner for that request. It is narrow and depends on shared participation, not on unilateral preference.

The privacy exception in detail, because this is where HIPAA teams land

Of the ten exceptions, the one at 45 CFR 171.202 is the one a HIPAA-trained team will reach for first, and the one most often misapplied. Its full title asks when an actor's practice of not fulfilling a request in order to protect an individual's privacy will not be considered information blocking. It has four operative sub-exceptions.

Precondition not satisfied, at 171.202(b). This applies when a state or federal privacy law permits the disclosure only if a condition is met, and that condition has not been met. Substance use disorder records under 42 CFR Part 2 are the textbook case, since the consent requirements there are genuine preconditions. The sub-exception is not self-executing. The actor needs written policies that are consistent with applicable law, applied in a non-discriminatory manner, and it must use reasonable efforts within its control to provide the individual with a way to satisfy the precondition where consent or authorization is what is missing.

Developer not covered by HIPAA, at 171.202(c). A health IT developer of certified health IT that is not itself a HIPAA covered entity or business associate may follow its own organizational privacy policy, provided that policy was disclosed in advance, is tailored to specific privacy risks, and is implemented consistently.

Denial of an individual's own request, at 171.202(d). Where an actor is required to comply with the HIPAA access rules, a denial that satisfies 45 CFR 164.524(a)(2) is not information blocking. That provision lists the unreviewable grounds for denying an individual access. It is a short list, and it does not include most of the reasons organizations actually give.

The individual's own request, at 171.202(e). An individual may ask that their EHI not be shared, and honoring that request is not information blocking. The condition that matters is that the actor must not have improperly encouraged or induced the request. An organization cannot suggest to patients that they opt out of exchange and then rely on their opt-out as cover.

The pattern across all four is documentation. Each sub-exception is conditioned on written policy or a documented determination, applied consistently. An actor that made a defensible decision but recorded nothing will struggle to demonstrate it qualified.

What actually goes wrong

The failures that draw attention are rarely exotic legal disputes. They are ordinary operational habits that predate the rule and were never revisited after it took effect. The ASTP and ONC information blocking materials, and the September 2025 enforcement alert, point at practices rather than at individual bad decisions, which means a standing habit is a larger exposure than a one-off refusal.

Holding results until a clinician calls the patient

A standing delay applied to every laboratory or imaging result is a practice, and practices are what the rule measures. The Preventing Harm Exception is built for individualized risk determinations, not for an organization-wide waiting period applied without regard to the specific patient.

Saying HIPAA forbids it when HIPAA merely allows a choice

This is the most common desk-level error. Staff hear a request they are not sure about and reach for HIPAA as a reason to decline. Under Part 171 the fact that HIPAA permits rather than requires the disclosure is not a reason to withhold.

Requiring a form the law does not require

Adding a notarization, an in-person visit, a proprietary release form, or a wet signature where none is legally required can materially discourage access. Extra procedure that serves administrative preference rather than a legal condition is interference.

Refusing an app the patient chose

Declining to send EHI to a patient-designated third party application because the organization distrusts the app is a documented sore point. The Security Exception requires a tailored, documented security rationale, not a general preference for the organization's own portal.

Letting requests sit in a queue

Delay is explicitly a form of interference. A request that is technically approved but functionally parked for weeks is not compliant simply because nobody said no. Turnaround time is part of the analysis.

Charging for a patient's electronic access

The Fees Exception expressly excludes fees for an individual's electronic access to their own EHI. Records departments accustomed to a per-page schedule sometimes apply it to electronic requests out of habit.

Penalties

Providers and developers face completely different consequences

This distinction is worth stating plainly, because a great deal of published commentary blurs it and leaves small practices believing they are exposed to a one million dollar penalty. They are not, at least not through this mechanism.

Health IT developers of certified health IT, entities offering certified health IT, health information exchanges, and health information networks are subject to civil monetary penalties of up to one million dollars per violation, imposed by HHS OIG. ONC can also ban a developer from the certification program and terminate the certification of health IT involved in blocking.

Health care providers are excluded from those civil monetary penalties by statute. Instead they face what the Cures Act calls appropriate disincentives, established in Subpart J of Part 171 by a final rule published in June 2024 and effective the following month. Those disincentives operate through Medicare programs, and they are referred by OIG to CMS after an OIG determination.

There is a further consequence that carries weight regardless of program participation. Subpart K of Part 171 addresses transparency for determinations and penalties, meaning a finding is not necessarily a private matter between the organization and the agency.

  • Developers, HIEs, and HINs: civil monetary penalties up to one million dollars per violation.
  • Hospitals and critical access hospitals: loss of meaningful EHR user status, cutting the annual market basket update by seventy five percent, or reducing critical access hospital payment from 101 percent to 100 percent of reasonable costs.
  • MIPS eligible clinicians and groups: a zero score in the Promoting Interoperability performance category.
  • ACOs, ACO participants, and ACO providers: possible ineligibility for the Medicare Shared Savings Program for at least one year.

Enforcement posture as of this writing

On September 4, 2025, HHS OIG and ASTP/ONC jointly issued an enforcement alert on information blocking.
  • The alert states that available authorities include civil monetary penalties, certification bans, and payment disincentives.
  • Complaints are accepted through the ONC information blocking portal.
  • Complaints are also accepted through the OIG hotline at 1-800-HHS-TIPS.
  • Reports may be made anonymously, and reporter identity carries legal protections.
  • Anyone can file, including patients, staff, competitors, and exchange partners.

Training

Who in your organization needs to know this, and what they each need

Information blocking is decided at the point where a request meets a person or a configuration setting. Policy alone does not reach either one.

Release of information and medical records staff

They make the withhold decision most often and usually under time pressure. They need the three-bucket test, not a memorized list of ten exception names.

Front desk and patient access teams

They field the first request and set the tone. A reflexive HIPAA refusal at the counter is where most exposure begins.

Clinicians and nursing staff

Result release timing, note content, and requests to suppress information from a patient's own record all run through clinical judgment. They need to know what the Preventing Harm Exception actually requires.

IT, informatics, and interface teams

Configuration choices are practices. Disabling an interface, throttling an export, or leaving a portal feature off can constitute interference even when no person ever refused a request.

Privacy officers and compliance leads

They own the written policies that most exceptions require. Without a documented, consistently applied policy, several exceptions are unavailable no matter how reasonable the underlying decision was.

Vendor and contract managers

Agreements that restrict how EHI moves can create exposure for the organization and for the counterparty. Licensing and fee terms deserve review against 45 CFR 171.302 and 171.303.

A practical way to start

You do not need a project to make meaningful progress here. Three pieces of work cover most of the realistic exposure, and all three are things a privacy officer can begin without a budget request.

Write down what you already refuse. For two weeks, log every request your organization declines, delays past a normal turnaround, or fulfills in a manner other than the one requested. Do not analyze them yet. The log itself usually reveals two or three standing practices nobody had examined, and standing practices are what the rule measures.

Map each practice to a section number or retire it. Take the log and try to name the exception. If a practice cannot be tied to a specific section of Part 171 or to a law that prohibits the disclosure, it is a candidate for change. This is also where you find the practices that were reasonable but undocumented, which is a fixable problem rather than a substantive one.

Fix the reflex, not just the policy. A written policy that staff never read does not change what happens at the counter. The specific thing to train is the substitution: replace the question of whether HIPAA requires the disclosure with the question of whether any law forbids it. That single change in framing prevents most improper refusals.

Primary sources

Regulatory summaries age badly, and a great many still describe eight exceptions. Read the current text where a decision matters.

This guide is educational material about federal regulations. It is not legal advice, it is not affiliated with or endorsed by HHS, ONC, ASTP, or OIG, and it does not establish an attorney client relationship. Regulatory text changes. Verify the current text and consult qualified counsel before making a decision about a specific request.

FAQs

Questions teams ask once they realize HIPAA is not the whole picture

Does the information blocking rule replace HIPAA?

No. They are separate federal rules with different jobs and they apply at the same time. HIPAA governs when protected health information may be used or disclosed and how it must be safeguarded. The information blocking rule, at 45 CFR Part 171, governs whether an actor may stand in the way of the access, exchange, or use of electronic health information. Complying with one does not excuse a failure under the other.

If HIPAA allows me to withhold something, can I still be penalized for withholding it?

Yes, and this is the central point of the rule. HIPAA is largely permissive, meaning it tells covered entities when they may disclose rather than when they must. The information blocking regulations require actors to provide access, exchange, or use of electronic health information unless the practice is required by law or fits an exception. The fact that HIPAA does not compel a disclosure is not, by itself, a defense.

How many information blocking exceptions are there?

Ten. The original eight took effect in 2020. The TEFCA Manner Exception at 45 CFR 171.403 was added later in its own subpart, and the Protecting Care Access Exception at 45 CFR 171.206 was added on December 17, 2024. Many summaries published before those additions still say eight, which is a useful signal that a source is out of date.

What are the penalties for information blocking?

They differ by actor type. Health IT developers of certified health IT, entities offering certified health IT, health information exchanges, and health information networks face civil monetary penalties of up to one million dollars per violation. Health care providers are not subject to those civil monetary penalties. They face appropriate disincentives set out in Subpart J of 45 CFR Part 171, which run through Medicare payment and participation programs.

What are the provider disincentives specifically?

Three, established by the final rule published in June 2024. An eligible hospital or critical access hospital found to have committed information blocking is not a meaningful electronic health record user, which reduces the hospital annual market basket update by seventy five percent and reduces critical access hospital payment from 101 percent to 100 percent of reasonable costs. A MIPS eligible clinician who is not a meaningful electronic health record user receives a zero score in the Promoting Interoperability performance category. An accountable care organization, ACO participant, or ACO provider may be ineligible for the Medicare Shared Savings Program for at least one year.

Is enforcement actually happening?

On September 4, 2025, HHS OIG and ASTP/ONC jointly issued an enforcement alert signaling active enforcement of the information blocking regulations, and stating that available authorities include civil monetary penalties, certification bans, and payment disincentives. Complaints can be submitted through the ONC information blocking portal or the OIG hotline, and reporters have identity protections.

Does this apply to a small practice that is not in a Medicare program?

The prohibition applies to any health care provider that meets the definition of an actor, regardless of program participation. The specific disincentives in Subpart J operate through Medicare programs, so a provider outside those programs may sit outside the reach of those particular consequences while still being subject to the underlying prohibition and to a public determination. Consult counsel about your own exposure.

Does completing training make my organization compliant?

No. Training is one control among many, and completing a course proves that a person completed training. Organizational compliance depends on written policies, configuration of your systems, contract terms, request workflows, response times, and documented decisions. Training records are evidence of workforce education, not a certification that an organization complies with HIPAA or with 45 CFR Part 171.

USA HIPAA

Train the reflex before a records request tests it

USA HIPAA provides online HIPAA training with verifiable certificates for individuals and organizations across the United States, so the workforce education behind your privacy and access decisions is straightforward to document.

Building the wider program? Pair this guide with the HIPAA compliance program guide, the release of information policy guide, and the HIPAA training log kit so access decisions, written policy, and training proof stay connected in one evidence file.