Ask a hospital CIO in late 2019 what’s keeping them up at night, and there’s a good chance the answer involves three words: information blocking rule. That rule doesn’t exist yet — it’s still a proposal sitting in the Federal Register — but the law behind it has already reshaped how the health IT industry plans its next several years. That law is the 21st Century Cures Act, and its health IT provisions are arguably the most consequential change to federal health data policy since the HITECH Act created the EHR incentive programs a decade earlier.

This overview walks through what the Cures Act actually is, what it requires specifically for health information technology, and where implementation stands as of late 2019 — including the proposed rules that would put the law’s interoperability and information-blocking mandates into effect.

What Is the 21st Century Cures Act?

The 21st Century Cures Act is a wide-ranging federal law — Public Law 114-255 — signed on December 13, 2016. Most of the public attention around it at the time focused on its provisions for accelerating drug and medical device approvals and increasing funding for biomedical research initiatives like the Cancer Moonshot. But buried in Title IV of the law, titled “Delivery,” is a set of provisions specifically aimed at health information technology: how electronic health information gets created, certified, shared, and accessed.

Title IV directs the Office of the National Coordinator for Health Information Technology (ONC), an agency within the U.S. Department of Health and Human Services, to carry out most of this work. It also gives the Centers for Medicare & Medicaid Services (CMS) authority to advance related goals through its own payer-facing rules. Congress’s stated intent, reflected throughout Title IV, was to move the health care system away from information silos and toward a standard in which patients and their authorized providers can get to electronic health information without excessive friction.

Why Congress Took This Up

By the mid-2010s, the federal government had already spent billions of dollars through the HITECH Act’s Meaningful Use program to get hospitals and physician practices onto certified electronic health record systems. Adoption rates climbed sharply. But interoperability — the ability to move a patient’s data between different systems, organizations, and applications — lagged far behind adoption. Lawmakers, providers, and patient advocates had all raised concerns that some vendors and health systems were using technical and contractual practices to keep data locked inside particular platforms, sometimes for competitive reasons. The Cures Act’s health IT title was Congress’s response to that gap.

The Interoperability Mandate

Section 4003 of the Cures Act amended the Public Health Service Act to define “interoperability” in statute for the first time. Under that definition, health IT is interoperable if it enables the secure exchange of electronic health information without special effort on the part of the user, allows complete access to and exchange of that information, and does not constitute information blocking as defined elsewhere in the law.

Section 4003 also directs the HHS Secretary, through ONC, to take steps to advance a “trusted exchange framework” — a common set of technical and organizational agreements that would let separate health information networks connect with one another rather than operating as isolated islands. That concept became the basis for what ONC has been developing since 2018 as the Trusted Exchange Framework and Common Agreement, still in draft form as of late 2019.

Standardized APIs and Patient Access

A major thread running through the interoperability provisions is patient access via application programming interfaces (APIs). The law’s intent, as ONC has described it in public statements and rulemaking documents, is that patients should be able to use the smartphone app of their choosing to pull structured data out of their provider’s electronic health record — the same way a banking app can pull account data from multiple financial institutions.

To get there, ONC’s health IT certification program is expected to require certified health IT to support standardized, publicly published APIs “without special effort.” The proposed rule discussed below would tie this to a specific data standard, but as of late 2019 that standard has not been finalized in a rule.

What Counts as Information Blocking?

The Cures Act’s most closely watched health IT provision may be its prohibition on “information blocking.” Section 4004 defines information blocking as a practice by a health IT developer, health information exchange or network, or health care provider that is likely to interfere with the access, exchange, or use of electronic health information — unless required by law or covered by an exception that HHS is directed to identify through rulemaking.

Congress did not attempt to enumerate every possible blocking practice. Instead, it described categories, such as contractual or licensing terms that restrict data sharing, technical designs that limit interoperability, or business practices that make exchanging data unreasonably difficult or costly. Determining exactly which practices fall into these categories — and which fall into a lawful exception — has been left largely to ONC’s implementing regulations, which is one reason the proposed rule has drawn so much industry comment.

Who the Provision Applies To

The information-blocking prohibition, as written in the statute, reaches three categories of “actors”: health care providers, health IT developers of certified health IT, and health information exchanges and health information networks. The statute also directs HHS’s Office of Inspector General to investigate claims of information blocking and gives OIG authority to impose civil monetary penalties on health IT developers, exchanges, and networks found to have committed violations — reportedly up to $1 million per violation, per the statutory cap Congress wrote into the law. Penalties or other “appropriate disincentives” for health care providers were left for HHS to define through future rulemaking, and as of late 2019 that piece has not been finalized either.

EHR Usability and Reporting Requirements

Beyond interoperability and information blocking, Section 4002 of the Cures Act created a new EHR Reporting Program. It directs ONC to work with health IT developers to establish a program under which certified health IT would be measured and publicly reported on factors including interoperability, usability, security, and conformance to certification testing criteria. The idea is to give purchasers of EHR systems — hospitals and physician practices — better comparative information than marketing materials alone provide.

Section 4001 separately called on HHS to convene stakeholders and produce a strategy for reducing the regulatory and administrative burden that EHRs impose on clinicians, including burdens related to documentation, quality reporting, and prior authorization workflows. ONC published a draft strategy on this front in 2018 and has continued to refine it, but implementation is a matter of agency initiative rather than a self-executing statutory mandate.

Where the Rulemaking Stands as of Late 2019

It’s important to be precise about where things actually stand more than three years after the Cures Act became law: the core interoperability and information-blocking rules that will operationalize Title IV have been proposed but are not yet final.

On March 4, 2019, ONC published a Notice of Proposed Rulemaking in the Federal Register titled “21st Century Cures Act: Interoperability, Information Blocking, and the ONC Health IT Certification Program.” That proposed rule would, among other things, adopt the United States Core Data for Interoperability (USCDI) as a standardized set of data classes required for exchange, replacing the older Common Clinical Data Set; establish new Conditions and Maintenance of Certification requirements for health IT developers; and identify a set of “reasonable and necessary” activities that ONC proposes would not be treated as information blocking.

The same day, CMS published its own related proposed rule — “Interoperability and Patient Access” — aimed at Medicare Advantage organizations, state Medicaid and CHIP programs, and issuers on the federally facilitated exchanges. That proposal would require, among other things, that these payers make claims and clinical data available to enrollees through a standards-based patient access API.

Both proposals drew a substantial volume of public comments from hospital associations, EHR vendors, and patient advocacy groups, addressing questions such as how broadly “electronic health information” should be defined, how much time developers and providers should be given to comply, and how the proposed information-blocking exceptions should be scoped. As of this writing, neither rule has been finalized, and the effective dates, compliance timelines, and final scope of the information-blocking exceptions remain open questions pending final agency action.

What Health IT Stakeholders Should Watch

For hospital IT leaders, EHR vendors, and health information exchange operators, the practical takeaway in late 2019 is that the direction of travel is now much clearer than the specific compliance obligations. The statute itself is settled law — interoperability is defined, information blocking is prohibited, and ONC has clear rulemaking authority. What remains unsettled is the operational detail: which specific practices will be deemed information blocking, what the compliance and enforcement timelines will look like once rules are finalized, and how strictly the “reasonable and necessary” exceptions will be interpreted.

Organizations that have already begun evaluating their data-sharing agreements, API strategies, and patient-access workflows against the proposed rule’s framework will likely be better positioned once ONC and CMS issue final rules. Those still treating this as a distant compliance date may find the runway shorter than expected, particularly if the final rules track closely to what was proposed in March 2019.

Frequently Asked Questions

What is the 21st Century Cures Act?

It is a federal law, Public Law 114-255, signed December 13, 2016. While best known for provisions on drug approvals and medical research funding, Title IV of the law also created new federal requirements around health IT interoperability, information blocking, and EHR usability reporting.

What is information blocking under the Cures Act?

Information blocking is a practice by a health care provider, health IT developer, or health information exchange/network that is likely to interfere with the access, exchange, or use of electronic health information, unless required by law or covered by an exception still being defined through ONC rulemaking.

Has the ONC information blocking rule been finalized?

No. As of late 2019, ONC’s proposed rule implementing the Cures Act’s interoperability and information-blocking provisions was published for comment on March 4, 2019, but has not been finalized. Compliance dates and final exceptions are not yet set.

What is the USCDI in the context of the Cures Act?

The United States Core Data for Interoperability is a standardized set of health data classes and elements that ONC’s proposed rule would require certified health IT to support for exchange, replacing the older Common Clinical Data Set. It has been proposed but not yet formally adopted.

Does the Cures Act require patient access to health data via apps?

The law’s interoperability provisions and ONC’s proposed rule both point toward patients being able to access their electronic health information through standardized APIs, including third-party smartphone apps, but the specific technical and compliance requirements remain part of the pending rulemaking as of late 2019.

This article is provided for general informational purposes about federal health IT policy and does not constitute legal advice. Organizations evaluating compliance obligations under the 21st Century Cures Act should consult the primary rulemaking documents and qualified legal counsel. For the authoritative text of the law and current rulemaking status, see Public Law 114-255 on Congress.gov and ONC’s Cures Act resources at HealthIT.gov.