Information Blocking Enforcement Alert: Front-Line Guide

Just over two years ago, the US Department of Health and Human Services (HHS) issued a Final Rule. It codified civil monetary penalties…

Read More

Jim Hook, MPH

By Jim Hook, MPH | September 29, 2025

Computer keyboard with stethoscope and gavel on it symbolizing ePHI Information Blocking Enforcement.

Just over two years ago, the US Department of Health and Human Services (HHS) issued a Final Rule. It codified civil monetary penalties against regulated actors who violate the Information Blocking regulations. On September 4, 2025, the Office of Inspector General (OIG) and the Assistant Secretary for Technology Policy (ASTP/ONC) issued an Enforcement Alert. It reminded regulated actors of penalties for violating Information Blocking regulations and warned of possible OIG enforcement actions.

Background on Information Blocking Regulations

The Information Blocking regulations were issued as part of the regulatory framework established to implement provisions of the 21st Century Cures Act. The penalties in the first regulations could only be imposed on health care providers and accountable care organizations (ACOs) that participated in the Medicare program. Regulators can now impose penalties on all actors. This includes developers of Certified Health IT, health information networks (HINs), health information exchanges (HIEs), health care providers, and ACOs.

What is Health Information Blocking?

The regulations define information blocking as an actor’s practice that interferes with access, exchange, or use of electronic health information. Such interference is allowed only when required by law or covered by an information blocking exception. Electronic health information (EHI) is defined as electronic protected health information (ePHI) maintained in a designated record set. 

Note that the regulations have been updated to adopt some of the same definitions found in HIPAA, which helps avoid cracks between regulations that can lead to protracted battles over small differences in regulatory language. On the other hand, the definition of an action “likely to interfere with access, exchange, or use of electronic health information” can very much be in the eye of the beholder. There will undoubtedly be legal cases that clarify this definition in the future.

What are the Information Blocking Exceptions?

The Information Blocking exceptions include nine provisions, most of which describe actions that developers, health care providers/ACOs or HIE/HINs can take that do not constitute information blocking.

For health care providers, there are exceptions for preventing harm to patients, maintaining the privacy and security of protected health information, and the infeasibility of complying with a request. Providers and other actors may also charge fees and make health data available in an alternative manner. Health care providers, HIEs, and HINs may get a pass on making health data available due to the unavailability of their health information technology.

Finally, regulated actors may negotiate to license interoperability elements with other organizations. Sharing health data between two entities that both belong to the Trusted Exchange Framework and Common Agreement (TEFCA) also does not count as information blocking.

What are the Penalties for Violating the Information Blocking Rules?

Penalties to hold information blockers accountable come in two flavors: 1) disincentives for health care providers/ACOs, and 2) civil monetary penalties (CMPs) for health IT developers, entities offering Certified HIT, HIEs, and HINs.

Disincentives (or penalties) for information-blocking practices initially apply only to healthcare providers who participate in the Medicare program

  • Medicare Promoting Interoperability Program (MIPS): Eligible hospitals and critical access hospitals (CAHS) will not be considered a meaningful user of electronic health records (EHR) in the reporting period during which the information blocking took place. Eligible hospitals will see a reduction of three-fourths of the annual market basket update. CAHs will receive only 100 percent of their reasonable costs, instead of 101 percent.
  • Quality Payment Program: MIPS-eligible clinicians will not be considered meaningful users of Certified EHR technology, receiving a zero score on Promoting Interoperability in the MIPS scoring system. In a group practice setting, the referral to the OIG may only concern an individual physician, depending on the facts and circumstances of the information-blocking event.
  • Medicare Shared Savings Program: ACOs, ACO participants, or ACO providers/suppliers may be deemed ineligible to participate in the ACO for a period of at least one year. Such a finding may even impact the ACO’s ability to participate in the Shared Savings Program.

Health IT developers of Certified Health IT, entities offering Certified Health IT, HIEs, and HINs who commit information blocking face significant civil monetary penalties. They may also face exclusion from the Certified Health IT certification program and other sanctions.

  • OIG may impose CMPs of up to $1 million per information blocking violation against the four entities listed above.
  • ASTP/ONC can ban a developer of certified health IT from the ONC Health IT Certification Program, and may also terminate the certification of the health IT involved in information blocking.

OIG notes it will prioritize enforcement where an actor’s practices can cause patient harm, significantly impact or impair a provider’s ability to deliver patient care, or result in financial loss to federal health care programs. ASTP/ONC promises to investigate information blocking claims and take swift action where warranted. 

The ASTP/ONC maintains the Report Information Blocking Portal. As of August 31, 2025, it has received over 1400 reports of claimed information blocking. The overwhelming majority of claims are filed by patients and their third-party representatives. But over 200 claims have been filed where the actor is a health IT developer. 

These Federal information blocking regulations represent a significant change in the health technology ecosystem and a renewed focus on enforcement. Health application programmers want patient data sharing to improve their applications. Healthcare providers, HIEs, and HINs are concerned about the security of their data when evaluating their information-sharing practices. And everyone has to keep looking over their shoulder at the federal enforcement authorities when there is a breach or a valid claim of information blocking.

Next Steps for Providers

If you are a health care provider and haven’t updated your policies on the release of information and processes, such as the release of diagnostic test results, you should review them now. At The Fox Group, we have assisted numerous clients in updating their policies and processes to ensure compliance with these regulations. The time to address this is before one of those complaints to ASTP/ONC has your name on it!