For years, information blocking was a policy problem with no real teeth. That era is over. The U.S. Department of Health and Human Services (HHS) has shifted from writing rules to issuing penalties — and healthcare organizations must act now to avoid serious consequences.
What Is Information Blocking?
Information blocking refers to any practice that interferes with, prevents, or discourages the access, exchange, or use of electronic health information (EHI). Congress banned it through the 21st Century Cures Act of 2016. Yet nearly a decade passed before regulators moved toward active enforcement.
Who Does the Law Cover?
The rules apply to three main groups:
- Health IT developers of certified electronic health record (EHR) systems
- Health information exchanges (HIEs) and networks (HINs)
- Healthcare providers, including hospitals, clinics, and accountable care organizations (ACOs)
Each group faces a different type of penalty depending on their role in the healthcare ecosystem.
Why HHS Is Acting Now
In September 2025, HHS Secretary Robert F. Kennedy Jr. directed the agency to increase resources for enforcing information blocking rules. This marked a clear break from the Biden administration’s approach, which treated enforcement as a lower priority.
The September 2025 Enforcement Alert
HHS-OIG and ASTP/ONC issued a joint enforcement alert, signaling coordinated and fully resourced investigations. Acting Inspector General Juliet T. Hodgkins stated that HHS-OIG would deploy all available legal authorities to investigate violations and hold responsible parties accountable.
Notices of Nonconformity Begin
In February 2026, at the ASTP Annual Meeting, HHS Assistant Secretary Thomas Keane confirmed that notices of potential nonconformity were going out to certified health IT developers. Moreover, ASTP/ONC had already started sharing complaint data with the OIG for active investigation. Keane also stated directly: “We are a quarter of the way through the 21st century, and information blocking is unacceptable.”
This matters because, until that point, the government had taken zero formal enforcement actions since the complaint portal opened in 2021.
Who Faces Penalties and How Much
The stakes are significant. Penalties differ based on the type of organization involved.
Health IT Developers, HIEs, and HINs
These entities face civil monetary penalties (CMPs) of up to $1 million per violation. The OIG’s June 2023 final rule established this authority. Enforcement against this group became effective on September 1, 2023. Critically, violations can stack — meaning multiple acts of blocking can multiply the total penalty exposure dramatically.
Healthcare Providers
Providers do not face the same CMP structure. Instead, Congress directed HHS to establish financial “disincentives.” These took effect on July 1, 2024. Specifically, providers may face:
- Hospitals and critical access hospitals (CAHs): Loss of meaningful EHR user status under the Medicare Promoting Interoperability Program, resulting in up to a 75% reduction in their annual market basket increase
- MIPS participants: A score of zero in the Promoting Interoperability performance category, which typically accounts for 25% of the final composite score
- ACO participants: A bar from the Medicare Shared Savings Program for at least one year
HHS previously calculated the median provider disincentive at approximately $394,353.
The HIPAA Comparison
For further context, HIPAA enforcement in 2025 produced settlements as high as $600,000 for failures to conduct risk assessments and protect EHI. Analysts expect information blocking enforcement to follow a similar trajectory — and possibly exceed it.
How the Complaint Portal Works
Since 2021, patients, providers, and innovators have submitted complaints through ONC’s Information Blocking Portal. By February 2026, the portal had received over 1,600 complaints, with most filed by individual patients.
Who Can Report?
Anyone can submit a report — no health IT expertise is required. Reports can also be anonymous. ONC shares portal complaints with OIG, which then decides whether to open a formal investigation.
OIG’s Enforcement Priorities
OIG will focus first on cases where information blocking causes:
- Direct patient harm
- Significant disruption to care delivery
- Long-duration or repeat violations
- Financial losses to federal healthcare programs
What Healthcare Organizations Must Do Next
Compliance is no longer optional. Organizations that wait risk becoming an early enforcement example. Here are four concrete steps every covered entity should take.
1. Assess Your Actor Status
Not every organization knows it qualifies as an information blocking “actor.” For example, a provider organization that offers certified health IT to others may meet the definition of a health IT developer. The modified definition of “offering certified health IT” could expand exposure beyond what many compliance teams assume.
2. Review and Update Policies
Existing data sharing policies must align with information blocking regulations. Internal processes should actively promote EHI exchange — not create friction. Review every patient data workflow for barriers that could constitute blocking.
3. Document Every Exception Claimed
The rules allow for specific exceptions (e.g., privacy, security, preventing harm). However, simply having an exception in mind is not enough. Organizations must formally document the basis for each exception they rely on — because the burden of proof falls on the organization, not the government.
4. Train Staff and Audit Technology
Workforce training on information blocking obligations should be current and documented. Additionally, IT teams should audit API performance and interoperability functions, since early ONC nonconformity notices focused specifically on API issues in certified EHR systems.
Key Takeaways
- HHS enforcement of the 21st Century Cures Act’s information blocking rules is now active and coordinated.
- Health IT developers and HIEs/HINs face CMPs up to $1 million per violation; providers face Medicare payment disincentives.
- Over 1,600 complaints are already under review by OIG and ASTP/ONC.
- The first formal penalties are expected soon and will likely set the tone for years of enforcement to come.
- Healthcare organizations should act immediately to assess risk, update policies, document exceptions, and train staff.
