Think about the last time one of your patients asked for a copy of their records or to have their results sent to a specialist across town. If the response from your office was some version of, “That will take a few weeks” or, “You’ll have to come in a fill out a form,” you initiated the everyday friction that federal regulators now have in their sights. For years, these delays were simply the way a busy practice operated. Today, it can put you on the wrong side of a federal rule called information blocking that after five idle years, the government has finally started enforcing.
What information blocking actually means
At its simplest, information blocking is anything a healthcare organization does that creates obstacles for patients or other providers receiving, sending or using electronic health information. Congress created the prohibition in a 2016 law called the 21st Century Cures Act on the idea that there must be a free flow of health information among providers, patients and supporting entities, like billing and IT services. While HIPAA had some protections in place to assist patients obtaining their own health information, they did not assure the flow of information among the other players in the healthcare system and sometimes did not even adequately ensure timely access by patients.
The Information Blocking rules reach three kinds of players: healthcare providers; companies that build the electronic health record software that providers use; and the networks that connect one system to another. A single organization can be considered more than one of these simultaneously, which matters more than most providers realize.
The rule does not require providers to hand over all information, always. It recognizes a set of legitimate reasons, or exceptions, to say “no” or “slow down,” including: (1) protecting a patient from harm, (2) safeguarding privacy, (3) keeping systems secure, or (4) handling a request that is genuinely not feasible – among others. The catch is that these exceptions are narrow and specific. It is not enough to have a good reason to delay the delivery of information in a general sense. Each provider must meet the detailed conditions of a particular exception, and ideally, document at the time why it applied. A reason recorded after a complaint arrives is worth far less than one recorded when the decision was made.
From a dormant rule to active enforcement
For most of the Information Blocking rule’s existence, not meeting its requirements carried no real-world consequences. The penalties existed on paper—fines of up to $1 million per violation for software developers and data-exchange networks and Medicare payment penalties for providers—but no company or provider had ever been publicly penalized. The rule functioned more as a warning than an active risk.
Over the past year, this has changed. In the fall of 2025, the U.S. Department of Health and Human Services publicly announced a “crackdown” on data blocking and urged patients and others to report it. A few months later, in early 2026, federal regulators began sending formal notices to electronic health record developers whose products or practices appeared to fall short of the rule. Those were the first real enforcement steps the program had taken. The message to the rest of the industry was that regulators are now opening cases, not just talking about them.
The surprising part: providers are being named most
Here is the detail that should get every provider’s attention: The emerging complaints and related enforcement actions are not generally against the software vendors for whom the rule was originally directed. Rather, complaints are being lodged against providers.
The government maintains an online portal where anyone can report suspected information blocking. As of July 31, 2026, it had logged more than 2,500 submissions. Healthcare providers were the target in the majority of the submissions (1,938), far more than the software companies. And the single biggest group filing complaints was patients themselves (1,554).
A complaint is only an allegation, not a final determination, and does not mean an investigation will happen. But the pattern is hard to ignore. Patients are noticing when they cannot get their information and they are pointing at their doctors and hospitals as a result.
A second front: the federal fraud crackdown
Running alongside all of this is a broader federal push against healthcare fraud. In early 2026, an executive order directed federal agencies to tighten anti-fraud controls across programs like Medicare and Medicaid, and the Department of Justice created a new division that has named healthcare as one of its top enforcement priorities.
Information blocking and fraud enforcement are legally separate. Being found to have blocked information is not the same as being found to have committed fraud. But regulators have specifically said that information blocking can be one piece of a larger fraud scheme, for example, when a company misrepresents what its software can do. That connection is why a provider caught up in one kind of scrutiny would be wise to pay attention to the other.
What is still up in the air
A few important details remain unsettled:
- No one has been publicly penalized yet for information blocking, but it is coming soon. Investigations stay confidential until they resolve, so lack of communication does not mean nothing is happening, but there is no benchmark case yet showing how these penalties will actually be applied.
- If a provider discovers a possible problem in their own practice, the path for voluntarily coming forward is not fully built. Regulators have said they will create a dedicated path to self-report information blocking, but it has not yet launched.
- The rules themselves are still evolving. A pending rule would change some of the software-certification requirements and adjust several of the adjustments; so what qualifies today may look different once it is finalized.
What you can do now
None of the above calls for panic. It calls for a little preparation.
- Consider your office’s typical responses when a patient or provider requests records or results rather than your written policies.
- Determine if you qualify as more than simply “a provider.” If you offer patients a portal or share your health-record technology with outside providers, you may fall into an additional category that carries the larger fines, and you would want to know that before a regulator tells you.
- Before you withhold or delay information, consult with legal counsel. In addition, if information cannot be delivered immediately, document the reason at the time it occurs, and ensure the reason fits one of the rule’s specific exceptions.
- Ensure privacy and information-sharing rules are not pulling your staff in opposite directions. State medical records laws and federal substance use privacy rules can require reserving information. Your team should have one clear instruction on how to handle these conflicts.
- Train the people on the front lines: schedulers, medical records staff and anyone who fields these requests. They are the ones most likely to create or prevent a complaint.
- Be aware of pending rule changes.
The bottom line
For five years, information blocking was a rule with no bite. That era is over. Notices are being issued; patients are filing complaints in growing numbers; and the broader fraud-enforcement climate is sharpening its focus. No one has been assessed a public penalty yet, but the direction is clear. The providers who take a little time now to understand where they stand and to document how they handle patient information will be in a far better position if a complaint, or an investigator, ever comes knocking.
This article is provided for informational purposes and does not constitute legal advice. Our health care team is available to help organizations assess information blocking compliance and prepare for federal enforcement.

