
The Department of Health and Human Services has finalized regulations imposing financial penalties on healthcare providers who obstruct access to electronic health information, fulfilling a major requirement under the 21st Century Cures Act. These measures establish consequences for providers that hinder the sharing of electronic health information (EHI), ensuring patients and care teams maintain access to essential data.
HHS Secretary Xavier Becerra described the policy as vital for advancing modern healthcare delivery. “When health information can be appropriately accessed and exchanged, care is more coordinated and efficient, allowing the health care system to better serve patients. But we must always take the necessary actions to ensure patient privacy and preferences are protected – and that’s exactly what this rule does,” he said. The regulations specifically target practices that impose unjustified restrictions on electronic health information access, even when unintentional, while preserving legally permitted exceptions.
New Penalty Programs Unveiled
The new rules introduce three major penalty programs for providers identified by the Office of Inspector General (OIG) as engaging in information blocking:
- Medicare Promoting Interoperability Program: Hospitals found guilty will forfeit three-quarters of their annual market basket increase, effective 30 days after publication. Critical access hospitals will see their payments reduced from 101% to 100% of reasonable costs.
- MIPS Promoting Interoperability: Clinicians will receive a zero score in this category, which typically accounts for 25% of their total MIPS score. CMS has clarified that the penalty applies only to individual offenders, even within group practices.
- Medicare Shared Savings Program: Providers in accountable care organizations may face at least one year of exclusion, losing potential shared savings revenue. These penalties will not take effect until after January 1, 2025, allowing time for corrective measures.
A separate OIG penalty already targets non-provider entities, including health IT developers, exchanges, and networks, with civil fines of up to $1 million per violation. While the Cures Act mandated these measures, provider groups have expressed concerns about the penalties’ impact.
Small Practices Fear Disproportionate Impact
Anders Gilberg, the Medical Group Management Association’s senior vice president for government affairs, stated that the penalties may disproportionately affect smaller practices already facing reporting challenges. He added that zero scores in MIPS could lead to negative payment adjustments across all Medicare claims for a year, while excluding accountable care organizations from shared savings undermines value-based care initiatives. “HHS could have chosen to work with providers to implement corrective action plans, but instead finalized unnecessarily punitive penalties that will financially damage practices and negatively impact Medicare patients. Preventing practices and ACOs from participating in MSSP runs counter to the transition to value-based care and undercuts the ability of providers within the ACO framework to succeed.”
Related Post: Trump pushes hospitals to release ER data
Providers now face immediate consequences for blocking electronic health information, though the regulations allow for future modifications. The OIG’s enforcement role ensures that violations are referred to CMS for penalties, creating a direct enforcement pathway. For the time being, compliance remains the central focus, though discussions about balancing enforcement with support for struggling providers persist.
Implementation Timeline and Delays
The regulations take effect 30 days after publication, with Shared Savings Program penalties delayed until 2025. CMS first proposed these measures in October 2023, following earlier OIG actions against non-provider actors.
The regulations apply only to providers who deliberately engage in practices they recognize as unreasonable and likely to interfere with electronic health information access. The definition excludes unintentional restrictions or actions required by law, such as privacy protections under HIPAA or state-specific mandates. Providers must justify any barriers to data exchange as necessary, such as safeguarding patient privacy, and not merely administrative oversights. Exceptions also apply when information blocking would violate other federal or state laws, including those governing mental health or substance use disorder records.
Two-Step Enforcement Process Explained
CMS has clarified that OIG determinations of information blocking must be referred to CMS before penalties are applied. This creates a two-step enforcement process: first, the OIG investigates and identifies violations; second, CMS imposes financial consequences based on the OIG’s findings. The rule does not introduce new reporting requirements beyond existing compliance obligations, though it requires providers to document any exceptions or legal justifications for restricted access. Those found in violation must also submit corrective action plans to CMS, though the rule does not specify deadlines for approval or implementation.