m
Recent Posts
HomeGovHealthHHS Info Blocking: Law Becomes Real Enforcement

HHS Info Blocking: Law Becomes Real Enforcement

For years, information blocking was a policy problem with no real teeth. That era is over. The U.S. Department of Health and Human Services (HHS) has shifted from writing rules to issuing penalties — and healthcare organizations must act now to avoid serious consequences.

What Is Information Blocking?

Information blocking refers to any practice that interferes with, prevents, or discourages the access, exchange, or use of electronic health information (EHI). Congress banned it through the 21st Century Cures Act of 2016. Yet nearly a decade passed before regulators moved toward active enforcement.

Who Does the Law Cover?

The rules apply to three main groups:

  • Health IT developers of certified electronic health record (EHR) systems
  • Health information exchanges (HIEs) and networks (HINs)
  • Healthcare providers, including hospitals, clinics, and accountable care organizations (ACOs)

Each group faces a different type of penalty depending on their role in the healthcare ecosystem.

Why HHS Is Acting Now

In September 2025, HHS Secretary Robert F. Kennedy Jr. directed the agency to increase resources for enforcing information blocking rules. This marked a clear break from the Biden administration’s approach, which treated enforcement as a lower priority.

The September 2025 Enforcement Alert

HHS-OIG and ASTP/ONC issued a joint enforcement alert, signaling coordinated and fully resourced investigations. Acting Inspector General Juliet T. Hodgkins stated that HHS-OIG would deploy all available legal authorities to investigate violations and hold responsible parties accountable.

Notices of Nonconformity Begin

In February 2026, at the ASTP Annual Meeting, HHS Assistant Secretary Thomas Keane confirmed that notices of potential nonconformity were going out to certified health IT developers. Moreover, ASTP/ONC had already started sharing complaint data with the OIG for active investigation. Keane also stated directly: “We are a quarter of the way through the 21st century, and information blocking is unacceptable.”

This matters because, until that point, the government had taken zero formal enforcement actions since the complaint portal opened in 2021.

Who Faces Penalties and How Much

The stakes are significant. Penalties differ based on the type of organization involved.

Health IT Developers, HIEs, and HINs

These entities face civil monetary penalties (CMPs) of up to $1 million per violation. The OIG’s June 2023 final rule established this authority. Enforcement against this group became effective on September 1, 2023. Critically, violations can stack — meaning multiple acts of blocking can multiply the total penalty exposure dramatically.

Healthcare Providers

Providers do not face the same CMP structure. Instead, Congress directed HHS to establish financial “disincentives.” These took effect on July 1, 2024. Specifically, providers may face:

  • Hospitals and critical access hospitals (CAHs): Loss of meaningful EHR user status under the Medicare Promoting Interoperability Program, resulting in up to a 75% reduction in their annual market basket increase
  • MIPS participants: A score of zero in the Promoting Interoperability performance category, which typically accounts for 25% of the final composite score
  • ACO participants: A bar from the Medicare Shared Savings Program for at least one year

HHS previously calculated the median provider disincentive at approximately $394,353.

The HIPAA Comparison

For further context, HIPAA enforcement in 2025 produced settlements as high as $600,000 for failures to conduct risk assessments and protect EHI. Analysts expect information blocking enforcement to follow a similar trajectory — and possibly exceed it.

How the Complaint Portal Works

Since 2021, patients, providers, and innovators have submitted complaints through ONC’s Information Blocking Portal. By February 2026, the portal had received over 1,600 complaints, with most filed by individual patients.

Who Can Report?

Anyone can submit a report — no health IT expertise is required. Reports can also be anonymous. ONC shares portal complaints with OIG, which then decides whether to open a formal investigation.

OIG’s Enforcement Priorities

OIG will focus first on cases where information blocking causes:

  • Direct patient harm
  • Significant disruption to care delivery
  • Long-duration or repeat violations
  • Financial losses to federal healthcare programs

What Healthcare Organizations Must Do Next

Compliance is no longer optional. Organizations that wait risk becoming an early enforcement example. Here are four concrete steps every covered entity should take.

1. Assess Your Actor Status

Not every organization knows it qualifies as an information blocking “actor.” For example, a provider organization that offers certified health IT to others may meet the definition of a health IT developer. The modified definition of “offering certified health IT” could expand exposure beyond what many compliance teams assume.

2. Review and Update Policies

Existing data sharing policies must align with information blocking regulations. Internal processes should actively promote EHI exchange — not create friction. Review every patient data workflow for barriers that could constitute blocking.

3. Document Every Exception Claimed

The rules allow for specific exceptions (e.g., privacy, security, preventing harm). However, simply having an exception in mind is not enough. Organizations must formally document the basis for each exception they rely on — because the burden of proof falls on the organization, not the government.

4. Train Staff and Audit Technology

Workforce training on information blocking obligations should be current and documented. Additionally, IT teams should audit API performance and interoperability functions, since early ONC nonconformity notices focused specifically on API issues in certified EHR systems.

Key Takeaways

  • HHS enforcement of the 21st Century Cures Act’s information blocking rules is now active and coordinated.
  • Health IT developers and HIEs/HINs face CMPs up to $1 million per violation; providers face Medicare payment disincentives.
  • Over 1,600 complaints are already under review by OIG and ASTP/ONC.
  • The first formal penalties are expected soon and will likely set the tone for years of enforcement to come.
  • Healthcare organizations should act immediately to assess risk, update policies, document exceptions, and train staff.

Share

No comments

Sorry, the comment form is closed at this time.