The 21st Century Cures Act makes certain interference with electronic health information access, exchange or use potentially unlawful. The Office of the National Coordinator for Health Information Technology (ONC) enforces information blocking prohibitions that apply to healthcare providers and health IT developers. Penalties include civil monetary fines, yet many organizations lack clear ownership of the compliance obligations that cut across clinical operations, legal interpretation, vendor contracts and technical controls.
This is not a technology project with a defined endpoint. It is an ongoing governance requirement where leadership is accountable for a security and compliance outcome without an obvious owner, a known sequence of steps or a way to measure progress against regulatory expectations.
What the Information Blocking Rule Prohibits
Information blocking occurs when a healthcare provider or health IT developer engages in practices that are likely to interfere with access, exchange or use of electronic health information, and the actor knows or should know that the practice is likely to interfere with that information.
The rule does not require organizations to create new capabilities or adopt particular technologies. It prohibits conduct that impedes the flow of electronic health information that patients, other providers or applications could otherwise lawfully access. This includes restrictive contracts, technical configurations that prevent interoperability, information-sharing fees not tied to reasonable costs, and procedures that delay or obstruct information requests without reasonable justification.
The standard is whether the practice interferes and whether the interference is justified by an applicable exception. Leadership is accountable for demonstrating that current practices, vendor agreements and technical configurations meet that standard.
The Eight Exceptions and What They Require
The rule recognizes eight exceptions to the information blocking prohibition. Meeting an exception requires documented evidence and reasonableness in application. The exceptions address:
- Preventing harm to patients or others
- Privacy protections required or permitted by law
- Promoting the security of electronic health information
- Infeasibility due to uncontrollable events or segmenting information
- Health IT performance improvements during limited maintenance windows
- Responding to requests that would place an unreasonable administrative or financial burden
- Licensing of interoperability elements on reasonable and non-discriminatory terms
- Recovering reasonable costs directly related to providing access, exchange or use
Each exception has specific conditions. The security exception, for instance, permits interference only to the extent necessary to protect against risks to the confidentiality, integrity or availability of electronic health information, and only when implemented in a consistent and non-discriminatory manner. Organizations must be able to demonstrate that reliance on any exception is reasonable, documented and applied consistently.
Who Owns Compliance and What Adequate Governance Looks Like
Information blocking compliance is an executive responsibility that spans clinical leadership, legal counsel, compliance officers, IT leadership and vendor management. In most organizations, no single role has end-to-end accountability for the intersection of patient access rights, interoperability obligations, security controls, contract terms and documentation of exception reliance.
Adequate ownership requires:
- A named executive accountable for information blocking compliance as a governance outcome, not a technical project
- Documented inventory of practices, policies, contracts and technical configurations that could interfere with information access, exchange or use
- Clear exception mapping: where interference exists, which exception applies, and what evidence supports reliance on that exception
- Vendor agreement review to identify and remedy contractual terms that constitute or require information blocking
- Security policy alignment to demonstrate that controls meet the security exception's conditions when they limit information flow
- A repeatable process for evaluating new information requests, system changes and vendor arrangements against information blocking standards
The requirement is not perfect interoperability. It is the ability to demonstrate that where information flow is restricted, the restriction is justified, documented and applied in a manner consistent with regulatory expectations.
Where vCISO Leadership Closes the Accountability Gap
Information blocking compliance fails when organizations attempt to distribute accountability across IT, legal and compliance without executive-level integration. The requirement spans regulatory interpretation, technical architecture, vendor governance and risk decisions that no operational role can own alone.
A virtual Chief Information Security Officer provides the executive ownership that bridges these domains: translating regulatory obligations into security and governance decisions, establishing accountability structures that clarify who decides what, and creating the documentation layer that demonstrates compliance to regulators, counsel and the board.
This role creates a single point of strategic accountability while working through the organization's existing structure. It answers the question: who ensures that security policy, vendor contracts and interoperability obligations are aligned, documented and defensible? For healthcare organizations navigating the Cures Act and related regulatory requirements, [vCISO leadership](/vciso/) provides the governance layer that operational teams require but cannot create from within their individual functions.
Relationship to Broader Regulatory and Framework Readiness
Information blocking compliance sits within the larger domain of regulatory and framework readiness. Organizations subject to HIPAA, FTC health breach notification requirements, state privacy laws and sector-specific security obligations face overlapping requirements that demand consistent governance.
The NIST Cybersecurity Framework provides a voluntary structure for managing cybersecurity risk that supports compliance across multiple regulatory regimes. The NIST Privacy Framework offers a parallel tool for identifying and managing privacy risk. Both frameworks help organizations translate regulatory obligations into actionable controls and governance decisions.
Where sources conflict or regulatory guidance is unclear, leadership must document the interpretive decisions made and the basis for those decisions. Readiness is not the absence of ambiguity. It is the presence of documented strategy, clear ownership and the ability to explain decisions to regulators and auditors.
Practical Next Steps for Leadership
Begin with accountability. Designate an executive owner responsible for information blocking compliance as a governance outcome. This role must have authority to convene legal, clinical, IT and vendor management stakeholders and drive decisions where their domains intersect.
Conduct an interference inventory. Document every practice, policy, contract term and technical control that limits or conditions access to electronic health information. For each, determine whether interference exists and, if so, which exception applies and what evidence supports that reliance.
Review vendor agreements. Identify contract terms that restrict interoperability, impose information-sharing fees beyond reasonable cost recovery, or require conduct that would constitute information blocking. Address these through renegotiation or documented exception analysis.
Align security policy. Ensure that security controls that limit information flow meet the security exception's requirements: necessary to protect against specific risks, implemented consistently and non-discriminatorily, and documented with a clear security rationale.
Establish an evaluation process. Create a repeatable procedure for assessing new information requests, system changes and vendor arrangements against information blocking standards before implementation. This prevents compliance gaps from being built into operations.
Document interpretive decisions. Where regulatory guidance is unclear or competing obligations create tension, document the interpretation adopted, the stakeholders consulted and the rationale. This record demonstrates good-faith compliance and supports consistent application.
If your organization lacks executive-level ownership of the intersection between regulatory compliance, security governance and vendor management, that gap is the starting point. Heights Consulting Group provides virtual CISO leadership that establishes the accountability structure, governance processes and documentation layer required to demonstrate compliance. A confidential consultation with our founder will clarify where your current structure leaves compliance accountability unowned and what specific governance capabilities would close that gap.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: Regulatory and Framework Readiness
Readiness for the frameworks and regulations that genuinely apply to you, NIST CSF, ISO 27001, SOC 2, CMMC, HIPAA, PCI DSS and SOX-related IT controls, with the evidence maintained between assessments.